check
Read-only drift detector. Diffs SPEC.md against current code and reports violations grouped by severity. Writes nothing — suggests remedies via the spec or build skills but never invokes them. Triggers when the user asks to check drift, audit the spec, verify invariants, or ask whether code still matches the spec. Phrasings: "check drift", "audit the spec", "does the code still match §V", "check invariants", "spec vs code".
Security Assessment
About check
A read-only drift detector that diffs SPEC.md against the current code and reports violations grouped by severity. It writes nothing—no SPEC.md edits and no code edits—and instead leaves the remedy to the user, suggesting (but never invoking) the spec or build skills. It is meant to be run after each build and before each ship, on the premise that a spec silently drifting from code is the primary spec-driven-development failure mode and that drift caught as a diff is far cheaper than drift caught in production. Triggers include "check drift", "audit the spec", "verify invariants", and "does the code still match §V".
On load it reads SPEC.md (stopping with "no spec, nothing to check" if absent) and parses arguments to scope the check: `§V` for invariants (the default), `§I` for interfaces, `§T` for task status, or `--all` for all three. For each invariant it translates the rule into a verifiable claim, greps or reads the relevant files, and classifies the result as HOLD, VIOLATE, or UNVERIFIABLE with file:line evidence. For each interface item it locates the implementation and classifies it as MATCH, DRIFT (shape differs), MISSING (absent), or EXTRA (code exposes a surface not in the spec). For each task it verifies that work claimed complete actually exists, marking checked rows with no evidence as STALE.
The report is written in the caveman style and grouped by severity, with a per-section breakdown and a summary line tallying violations, missing items, stale tasks, and unverifiable items. It ends with one-line remedy hints per class—for example, routing VIOLATE or DRIFT toward the spec skill with a `bug:` argument or a code fix, MISSING toward the build skill or a spec amendment, STALE toward un-checking a task, and EXTRA toward documenting or deleting code—while never performing the fixes itself. It runs on the main thread with no sub-agents, produces no scores or grades, and renders a binary holds-or-drifts judgment per item.
FAQ
Does this skill modify any files?
No. It is purely diagnostic: zero writes, no SPEC.md edits, and no code edits. It only reports drift and the user decides on the remedy.
What can it check?
Invariants (§V, the default), interfaces (§I), and task status (§T), or all three with `--all`. It classifies each item by severity with file and line evidence.
When should I run it?
After each build and before each ship. The premise is that drift caught as a diff is cheap, while drift caught in production becomes a recorded bug.
What happens if there is no SPEC.md?
It reports "no spec, nothing to check" and stops.
Will it fix the problems it finds?
No. It only ends the report with one-line remedy hints per class—such as routing violations to the spec skill with a `bug:` argument or fixing the cited code lines—but it never invokes those fixes.
Install check
Quick Setup:
- Copy the skill folder to
.claude/skills/ - Claude will automatically detect and use the skill
Repository
juliusbrussee/cavekit