Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsCommunityBlog
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Product Spec

ASecurity

Authors the product specification (goals, users, scope, NFRs, risks, MVP acceptance) section by section with the user. Produces docs/specs/product-spec.md. Required before feature specs.

3 stars
0 votes
0 copies
1 views
Added 9/22/2026
ai-agentsgosecurity

Security Analysis

A100/100

Scanned 9/22/2026

Install to Claude Code

$npx -y skills add gonimar/claude-web-studio --skill product-spec --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Product Spec?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Product Spec
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/gonimar-product-spec/badge)](https://www.skillsdirectory.com/skills/gonimar-product-spec)

More formats (shields.io, HTML) on the badges page.

Download with Pro
Files
SKILL.md
---
name: product-spec
description: "Authors the product specification (goals, users, scope, NFRs, risks, MVP acceptance) section by section with the user. Produces docs/specs/product-spec.md. Required before feature specs."
argument-hint: "[product name] [--review full|lean|solo]"
user-invocable: true
allowed-tools: Read, Glob, Grep, Write, Edit, AskUserQuestion, Task
model: sonnet
agent: product-director
---

# Product Spec

Reply in the project conversation language (CLAUDE.md → Language); code, identifiers, paths and commit messages stay in English.

Template: `.claude/docs/templates/product-spec.md`. Section by section: questions → section draft → edits → next.
The file is written once at the end (or per section, the user's choice), always after "May I write?".

## Phase 1: Context
Read `docs/specs/concept-brief.md` (if any), `technical-preferences.md`, `production/roadmap.md`.
If the stack is not configured — suggest `/setup-stack` before or after (not blocking).

## Phase 2: Sections 1–10
Per section: 1–3 `AskUserQuestion`s → draft → "like this?". Section 6 always answers localisation, SEO and product analytics explicitly (`n/a — reason` is an answer; silence is not). Non-functional requirements get the studio defaults
(CWV, WCAG 2.2 AA, OWASP baseline) — the user confirms. Scope: insist on In/Later/Out; every Out item has a reason.

## Phase 3: Review
Mode (`--review` or `production/review-mode.txt`, default `lean`):
- `full`: `technical-director` (feasibility, stack risks) and `security-lead` (data, jurisdiction) in parallel via Task, verdict PASS/CONCERNS/FAIL with reasons.
- `lean`: `technical-director` only if there are non-trivial NFRs/integrations.
- `solo`: no review.
CONCERNS/FAIL — show, propose edits, never advance the stage automatically. **The edits are re-reviewed by the same verifier** (same contract, ≤ N lines, only "do the findings still stand?"), and the document's verdict is the verdict of the **last** review — not the first one with a list of fixes claimed against it. A spec that went out as `FAIL` and comes back rewritten "according to all eight comments" has been checked by nobody; say so plainly when the second review is skipped by the user's choice, and record the verdict as `FAIL (edits unverified)`.
Then, for every BLOCKING and HIGH item of the verdict, one `AskUserQuestion`: record it in `production/findings.md`
(template `findings.md`; id `ARCH-NNN`, severity, area/feature, the decision needed) (Recommended) · story stubs now
via `/create-stories` · keep it in the spec only. A BLOCKING that is neither recorded nor turned into a story is
named as such in the verdict line — it must not silently stay in the document (`/create-stories`, `/sprint-plan`
and `/help` read `production/findings.md`, nobody reads §8 of the spec for open decisions).

## Phase 4: Write
"May I write `docs/specs/product-spec.md`?" — one `AskUserQuestion`: write (Recommended) · show the draft/diff first · not now; propose `production/stage.txt` = `specification` **only when the current stage is earlier than `specification` in the catalog** — on a project already in `build`/`operate` the stage is never proposed backwards. After the "write" answer: `touch .claude/.write-consent` (rule 7 — the consent-guard hook checks the marker).

**Retrofit mode** (stage `build` or later, code and deployment exist): the spec documents what runs, not what is planned — sources are `CLAUDE.md`, the roadmap, the deployed configuration and the code; one pass with the draft shown as a whole, questions only where the facts are silent (goals, audience, out-of-scope), and the review verifies claims against the repository (a claimed fact the repository contradicts is BLOCKING).

Verdict: `APPROVED` | `NEEDS REVISION`. Next step — one `AskUserQuestion`: `/feature-spec` for the Must features (Recommended) · `/game-concept` (game) · revise the spec.

Attribution

gonimargonimar
View sourceMore from gonimar →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Ultra-compressed communication mode that cuts output tokens while keeping technical accuracy. Levels: lite, full, ultra and the wenyan variants. Use for /caveman, "caveman mode", "talk like caveman", "be brief" or "less tokens".

1074701 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

693621 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3351 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

691 votes

math-skill

A comprehensive mathematical reasoning skill for AI assistants — handles arithmetic to research-level problems with rigorous step-by-step reasoning, systematic verification, and transparent uncertainty handling

381 votes
View all in ai-agents →