Spec Kit adds a process to AI coding agents. A small CLI called specify sets up a project with templates and agent skills, and you then work in your agent's chat: /speckit-constitution records the project's principles once, and for each feature /speckit-specify writes down what to build and why, /speckit-plan turns that into a technical plan, /speckit-tasks breaks it into steps, and /speckit-implement and /speckit-converge build the work and check it against the spec until they match. Everything lands as Markdown in the repository, so the reasoning behind a change can be reviewed later.
Two optional extensions reuse the same structure for other work: a bug process that keeps assessment, fix and verification separate, and an idea assessment that ends in a go, clarify or stop decision before anything is built. It works with GitHub Copilot by default and with Claude Code, Gemini CLI, Cursor, Codex CLI, Qwen Code, opencode, Amp, Kiro and other agents through integration keys.
It is an official GitHub project, MIT-licensed, and at about 139,900 stars one of the most-starred developer tools of the past year, with walkthrough videos widely shared on YouTube. It needs Python 3.11 or later and uv, and runs on Linux, macOS and Windows.
- Repository: github.com/github/spec-kit
- Licence: MIT (MIT License)
- Language: Python. Stars: 139.9K. Forks: 12.5K. Last push: Oct 2, 2026.
- Scan: safe, Oct 2, 2026, commit e1fa857
Who it is for
Developers who use AI coding agents on anything larger than a one-file script and want the agent to agree on requirements and a plan before it starts editing, and teams that want those decisions written down in the repo.
Getting started
1. Install the specify CLI (Python 3.11+ and uv required)
uv tool install specify-cli2. Create a project for your agent (swap copilot for claude, gemini, cursor-agent and so on)
specify init my-project --integration copilot3. Open your agent in the project folder and set the principles in its chat
/speckit-constitution Create principles focused on code quality, testing, and maintainability.4. Describe a feature, then run /speckit-plan, /speckit-tasks, /speckit-implement and /speckit-converge in turn, reviewing each result
/speckit-specify Build a photo organizer with albums grouped by date and a tile preview of each album.The /speckit commands are skills typed into your coding agent's chat, not terminal commands, and some agents use a different invocation syntax. Spec Kit makes no model calls itself; the agent you pair it with does, on whatever plan or API key that agent uses.
Safety scan
We cloned github/spec-kit at commit e1fa857 on Oct 2, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.
- No secrets and no suspicious code patterns in 873 files and about 272,000 lines, most of it Python and the Markdown templates the CLI copies into projects.
- The three bare-IP URLs are test inputs: 00.00.00.00 and 192.0.2.1, a reserved documentation address, used to check that the extension and preset downloader refuses internal and private hosts.
- The four installer scripts are setup-plan and setup-tasks in Bash and PowerShell, which your coding agent runs to create spec folders and files. None uses sudo, touches your shell profile or fetches anything. specify extension add does download extension packages, and community extensions and presets are third-party code, so read one before installing it.
- No lockfile, so no advisories were queried: uv tool install resolves the CLI's small set of Python dependencies at install time.
- 18 workflows, none using pull_request_target, and all 9 third-party actions pinned to commits. Security policy, Dependabot, CodeQL, licence, contributing guide and code of conduct all present.
What the scanner counted
| Check | Result |
|---|---|
| Secrets | None found. |
| Suspicious code | None found. |
| Install-time code | 4 installer scripts |
| Committed binaries | None. |
| CI workflows | 18 workflows. None use pull_request_target. 0 of 9 third-party actions pinned to a tag rather than a commit. |
| Network hosts | 40 distinct hosts referenced from source; most often github.com, api.github.com, ghes.example, raw.githubusercontent.com. 3 URLs to a bare IP address, listed under the raw findings. |
| Known vulnerabilities | No lockfile to check: dependencies are declared as ranges, so what gets installed is whatever is current on the day. |
| Project hygiene | Has security policy, automated dependency updates, CodeQL, licence file, contributing guide. |
| OpenSSF Scorecard | Not scored: the project is not in Scorecard's weekly index. |
The raw findings
Every hit the scanner wrote out, with a link to the exact line at the scanned commit. Secrets candidates are redacted.
URLs to bare IP addresses (3)
| Where | Rule | Match |
|---|---|---|
| tests/specify_cli/authentication/test_authentication.py:1481 | ip-literal-url | "https://00.00.00.00/internal", |
| tests/test_download_security.py:45 | ip-literal-url | ("http://192.0.2.1/preset.zip", False), |
| tests/test_download_security.py:115 | ip-literal-url | "https://00.00.00.00/internal", |
Installer scripts (4)
- scripts/bash/setup-plan.sh, 86 lines
- scripts/bash/setup-tasks.sh, 95 lines
- scripts/powershell/setup-plan.ps1, 89 lines
- scripts/powershell/setup-tasks.ps1, 94 lines
By the numbers
| Stars | 139.9K |
|---|---|
| Forks | 12.5K |
| Contributors | 310 |
| Commits | 2,117 |
| Open issues | 127 |
| Open pull requests | 142 |
| Releases | 228 |
| Latest release | v1.1.0 |
| Licence | MIT |
| Main language | Python |
| Project age | 1 year |
| Last push | Oct 2, 2026 |
| Tracked files | 873 |
| Lines of code | 271.9K |
| Checkout size | 14 MB |
Lines by language: Python 207.7K, Markdown 30.4K, YAML 17.5K, JSON 8,994, Shell 3,740, PowerShell 3,276.
Questions
Is Spec Kit free?
Yes. Spec Kit is MIT-licensed and free, with no account. It does not include a model: the coding agent you use with it, such as GitHub Copilot, Claude Code or Gemini CLI, is billed or rate-limited under that agent's own terms.
What is spec-driven development?
Writing down what you want and why before deciding how to build it. In Spec Kit that means a specification, then a technical plan, then a task list, and only then implementation, followed by a convergence check that compares the result with the spec. It trades some speed for fewer surprises on larger changes.
Can I use Spec Kit on an existing codebase?
Yes. The documentation has an existing-project guide, and the bug-fixing and idea-assessment extensions do not need the full spec workflow first. specify extension add bug and specify extension add assess install them from the project folder.
This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.
