Install
$ agentstack add skill-ash1794-vibe-engineering-spec-vs-code-audit ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
vibe-spec-vs-code-audit
Specs drift from code. Code drifts from specs. This skill catches the gaps.
When to Use This Skill
- Implementation of a spec/design doc is claimed complete
- After a major refactor that should still conform to a spec
- During periodic compliance checks
- When debugging unexpected behavior (maybe the code doesn't match the spec)
When NOT to Use This Skill
- No spec or design doc exists (nothing to compare against)
- The spec is explicitly marked as aspirational/future
- Code was intentionally diverged with documented reasons
Steps
- Identify the spec — Find the specification document (design doc, PRD section, API spec, etc.)
- Identify the implementation — Find the code files that implement this spec
- Line-by-line comparison — For each requirement/section in the spec:
- Find the corresponding code
- Check: Does the code match the spec exactly?
- If divergent: Record as a GAP
- Classify each gap:
- ID: GAP-[section]-[number] (e.g., GAP-AUTH-001)
- Type: Missing (spec says X, code has nothing) / Incorrect (spec says X, code does Y) / Extra (code has X, spec doesn't mention it)
- Severity: Critical (breaks core functionality) / High (wrong behavior) / Medium (incomplete) / Low (cosmetic)
- Report:
Output Format
Spec vs Code Audit
Spec: [document name/path] Implementation: [code path(s)] Gaps Found: X (Y critical, Z high)
| GAP ID | Type | Severity | Spec Says | Code Does | |--------|------|----------|-----------|-----------| | GAP-AUTH-001 | Missing | Critical | "Tokens expire after 24h" | No expiration logic found |
Top 3 Risks
- [Most dangerous gap]
Recommended Fix Order
- [Fix critical gaps first]
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: ash1794
- Source: ash1794/vibe-engineering
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.