spec-superflow — security grade SAFE, quality 62/100

Security audit verdict: SAFE · quality 62/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by MageByte-Zero · Codex Skill · ★ 809

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is spec-superflow safe to install? View the security audit →

About spec-superflow

spec-superflow 源码级融合 OpenSpec 规划引擎 + Superpowers 执行纪律的 AI 编程工作流插件 为什么需要它 | 使用方式 | English | Showcase | Skills | 快速开始 | 工作流 | FAQ 为什么需要它 用 AI 写代码时,最常碰到两个失控点: 还没想清楚要做什么,AI 就开始写代码。 你说了句"帮我加个权限控制",它就开始改几十个文件。改到一半才发现 —— 到底要 RBAC 还是 ABAC? 规划文档写得明明白白,但执行阶段还是会跑偏。 proposal 写了、design 画了,但实现过程中没人盯着测试、没人卡 review,等到合并才发现行为不对。 spec-superflow 在两个失控点之间用源码级的引擎 + 桥接协议建立起一道硬墙: 先把需求问清楚 - 把意图沉淀为正式工件(Schema 引擎验证格式)- 把规划压缩成执行契约 - 以 TDD + SDD + Review Gate 三重纪律强制执行 - 处理执行中的阻塞 - 审查每批产出 - 验证后收口 - 同步 delta spec 防止规范腐烂。 它不是把 OpenSpec 和 Superpowers 并排安装再手工拼接,而是把两者的核心引擎和能力吸收进一个自包含的工作流 ow

ai-codingamazon-qclaude-codeclinecodexcopilot-clicursorgemini-cliopencodeopensource

Quick Facts

Stars809
Forks81
LanguageJavaScript
CategoryCodex Skill
LicenseMIT
Quality Score62.3698151356239/100
Open Issues7
Last Updated2026-09-20
Created2026-06-26
Platformsclaude-code, cli, codex, gemini, node
Est. Tokens~17k

Compatible Skills

These tools work well together with spec-superflow for enhanced workflows:

  • speccoding-template — semantic(0.62)+complementary+rare_topics+similar_pop+shared_platform (71%)
  • superpowers-zh — semantic(0.38)+complementary+rare_topics+same_lang+shared_platform (62%)

spec-superflow alternative? Top 6 similar tools

Looking for a spec-superflow alternative? If you're comparing spec-superflow with other codex skill tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • ccmanager by kbwo · ⭐ 1.2k

    Coding Agent Session Manager for Claude Code / Gemini CLI / Codex CLI / Cursor Agent / Copilot CLI / Cline CLI

  • memorix by AVIDS2 · ⭐ 791

    Open-source cross-agent memory layer for coding agents via MCP. Compatible with Claude Code, Codex, Cursor, Wi

  • openspec-plus by sudokar · ⭐ 166

    OpenSpec Plus — Agentic skills that enhance OpenSpec's Spec-Driven Development through better discovery, requi

  • cc-sdd by gotalab · ⭐ 3.7k

    Turn approved specs into long-running autonomous implementation. A minimal, adaptable SDD harness with Agent S

  • pro-workflow by rohitg00 · ⭐ 2.8k

    Claude Code learns from your corrections: self-correcting memory that compounds over 50+ sessions. Context eng

  • agent-of-empires by njbrake · ⭐ 2.4k

    Manage multiple Claude Code, OpenCode agents from either TUI or Web for easy access on mobile. Also supports M

More Codex Skill Tools

Explore other popular codex skill tools:

View all Codex Skill tools →

Popular JavaScript Agent Tools

Frequently Asked Questions

What is spec-superflow?

spec-superflow is 源码级融合 OpenSpec 规划引擎 + Superpowers 执行纪律的 AI 编程工作流插件。17 平台支持,9 skills,Spec-first,契约驱动。. It is categorized as a Codex Skill with 809 GitHub stars.

What programming language is spec-superflow written in?

spec-superflow is primarily written in JavaScript. It covers topics such as ai-coding, amazon-q, claude-code.

How do I install or use spec-superflow?

You can find installation instructions and usage details in the spec-superflow GitHub repository at github.com/MageByte-Zero/spec-superflow. The project has 809 stars and 81 forks, indicating an active community.

What license does spec-superflow use?

spec-superflow is released under the MIT license, making it free to use and modify according to the license terms.

What are the best alternatives to spec-superflow?

The top alternatives to spec-superflow on Agent Skills Hub include ccmanager, memorix, openspec-plus. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse Codex Skill tools