sdd-specify — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited sdd-specify (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Use to turn an idea, feature, bug, or existing system into a behavior-first spec.
Prefer the repo shape: Spec Kit specs/<feature>/spec.md; Kiro .kiro/specs/<feature>/requirements.md or bugfix.md; OpenSpec openspec/specs/<capability>/spec.md plus openspec/changes/<change>/; fallback .sdd/<feature>/requirements.md.
Keep specs at what/why level:
Avoid stack, classes, schemas, framework choices, and file paths unless bugfix/retrofit/design-first and explicitly labeled.
Proceed with labeled low-risk assumptions. Clarify, constrain, or convert to non-goal when ambiguity changes scope, security/privacy, UX, data retention, integration contracts, compliance, or delivery risk. [TO VERIFY] needs owner, risk, next action. LLM-drafted requirements are drafts until checked against user input, code truth, or project context.
Ask at most three concrete questions only when needed.
Feature spec:
Bugfix spec:
Retrofit spec:
[TO VERIFY]No placeholders; buildable requirements are testable or deferred; success criteria measurable; non-goals constrain scope; assumptions/sources/review gaps visible; stable IDs support traceability; next step is clarify, plan, tasks, or direct implementation.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.