by wellwelwel
π Blue Spec is a toolkit for Security-Driven Hardening, a defensive workflow to help AI agents detect what a system does and harden the defenses that matter.
# Add to your Claude Code skills
git clone https://github.com/wellwelwel/blue-specblue-spec is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by wellwelwel. π Blue Spec is a toolkit for Security-Driven Hardening, a defensive workflow to help AI agents detect what a system does and harden the defenses that matter. It has 56 GitHub stars.
blue-spec's catalog security scan is still queued. You can run an instant dependency and prompt-injection check now with the "Scan for vulnerabilities" button above.
Clone the repository with "git clone https://github.com/wellwelwel/blue-spec" and add it to your Claude Code skills directory (see the Installation section above).
blue-spec is primarily written in TypeScript. It is open-source under wellwelwel on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh blue-spec against similar tools.
No comments yet. Be the first to share your thoughts!
Unlocks once the catalog security scan passes (runs nightly).
The deep catalog scan for this skill is still queued. Run an instant dependency check now instead.
Blue Spec helps your AI agent make a project more secure. You point it at your code, and the agent figures out what your system actually does, then guides you through the security work that matters for it.
Blue Spec adapts to your environment, whether it is a new project or an existing one.
npx -y blue-spec@latest init
Once Blue Spec is set up in your project, your AI agent unlocks a set of slash commands:
| # | Command | What it does for you |
|---|---|---|
| 1 | /bluespec.charter | Sets your project's security rules, proposed for you or shaped by what you say |
| 2 | /bluespec.detect | Reads your code and maps what your system does and where the risks are |
| 3 | /bluespec.plan | Turns what detect found into a defense plan, with a fix for each finding |
| 4 | /bluespec.harden | Applies the plan's fixes to your code, safely and one at a time |
| 5 | /bluespec.verify | Proves each applied fix holds and closes out the ones that do |
Each command builds on the previous, so following the list top to bottom is all it takes.
| Command | What it does |
|---|---|
| /bluespec.specialize | Specializes Blue Spec in a new security sub-skill from articles, exploits, or topics |
| /bluespec.skills | Loads an on-demand security sub-skill |
| /bluespec.repair | Repairs Blue Spec's internal tracking |
| /bluespec.list | Lists all finding Blue Spec is tracking, by name |
[!TIP]
Security is not a cost, it is an investment: what you put in upfront, you save many times over in the incidents you never have ππ»ββοΈ
[!IMPORTANT]
See the full documentation for usage examples and more.
You will need these tools installed on your system:
Please check the SECURITY.md.
π§ Coming Soon.
Really thanks to everyone who has supported and keeps supporting my work.
Blue Spec is under the MIT License. Copyright Β© 2026-present Weslley AraΓΊjo and contributors.