Use when the user asks to install, initialize, integrate, upgrade, or document GitHub Spec Kit. Creates a repository-specific constitution and SPECKITINIT.md with complete copy-paste workflows using the public workflow catalog. Do NOT use to implement application features; use the installed Spec Kit implementation command.
71
86%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Low
Low-risk findings worth noting
Low
Low-risk findings.
1 low severity finding. Worth noting, but not necessarily harmful.
The skill exposes the agent to untrusted, user-generated content from public third-party sources, creating a risk of indirect prompt injection. This includes browsing arbitrary URLs, reading social media posts or forum comments, and analyzing content from unknown websites.
The skill’s workflow reads only the target repository’s existing guidance/docs and local project files (e.g., `.specify/`, `specs/`, `SPECKITINIT.md`) and uses first-party provider content plus a fixed public workflow catalog URL as a reference, so there is no runtime ingestion of outsider-authored free text from an external user-submitted feed without the agent explicitly selecting repo-local evidence.
129253e
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.