Spec to Repo
Turn a natural-language project specification into a complete, runnable starter repository. Not a template filler — a spec interpreter that generates real, working code for any stack.
When to Use
- User provides a text description of an app and wants code
- User has a PRD, requirements doc, or feature list and needs a codebase
- User says "build me an app that...", "scaffold this", "bootstrap a project"
- User wants a working starter repo, not just a file tree
Not this skill when the user wants a SaaS app with Stripe + Auth specifically — use product-team/saas-scaffolder instead.
Core Workflow
Phase 1 — Parse & Interpret
Read the spec. Extract these fields silently:
| Field |
Source |
Required |
| App name |
Explicit or infer from description |
yes |
| Description |
First sentence of spec |
yes |
| Features |
Bullet points or sentences describing behavior |
yes |
| Tech stack |
Explicit ("use FastAPI") or infer from context |
yes |
| Auth |
"login", "users", "accounts", "roles" |
if mentioned |
| Database |
"store", "save", "persist", "records", "schema" |
if mentioned |
| API surface |
"endpoint", "API", "REST", "GraphQL" |
if mentioned |
| Deploy target |
"Vercel", "Docker", "AWS", "Railway" |
if mentioned |
Stack inference rules (when user doesn't specify):
| Signal |
Inferred stack |
| "web app", "dashboard", "SaaS" |
Next.js + TypeScript |
| "API", "backend", "microservice" |
FastAPI (Python) or Express (Node) |
| "mobile app" |
Flutter or React Native |
| "CLI tool" |
Go or Python |
| "data pipeline" |
Python |
| "high performance", "systems" |
Rust or Go |
After parsing, present a structured interpretation back to the user:
## Spec Interpretation
**App:** [name]
**Stack:** [framework + language]
**Features:**
1. [feature]
2. [feature]
**Database:** [yes/no — engine]
**Auth:** [yes/no — method]
**Deploy:** [target]
Does this match your intent? Any corrections before I generate?
Flag ambiguities. Ask at most 3 clarifying questions. If the user says "just build it", proceed with best-guess defaults.
Phase 2 — Architecture
Design the project before writing any files:
- Select template — Match to a stack template from
references/stack-templates.md
- Define file tree — List every file that will be created
- Map features to files — Each feature gets at minimum one file/component
- Design database schema — If applicable, define tables/collections with fields and types
- Identify dependencies — List every package with version constraints
- Plan API routes — If applicable, list every endpoint with method, path, request/response shape
Present the file tree to the user before generating:
project-name/
├── README.md
├── .env.example
├── .gitignore
├── .github/workflows/ci.yml
├── package.json / requirements.txt / go.mod
├── src/
│ ├── ...
├── tests/
│ ├── ...
└── ...
Phase 3 — Generate
Write every file. Rules:
- Real code, not stubs. Every function has a real implementation. No
// TODO: implement or pass placeholders.
- Syntactically valid. Every file must parse without errors in its language.
- Imports match dependencies. Every import must correspond to a package in the manifest (package.json, requirements.txt, go.mod, etc.).
- Types included. TypeScript projects use types. Python projects use type hints. Go projects use typed structs.
- Environment variables. Generate
.env.example with every required variable, commented with purpose.
- README.md. Include: project description, prerequisites, setup steps (clone, install, configure env, run), and available scripts/commands.
- CI config. Generate
.github/workflows/ci.yml with: install, lint (if linter in deps), test, build.
- .gitignore. Stack-appropriate ignores (node_modules, pycache, .env, build artifacts).
File generation order:
- Manifest (package.json / requirements.txt / go.mod)
- Config files (.env.example, .gitignore, CI)
- Database schema / migrations
- Core business logic
- API routes / endpoints
- UI components (if applicable)
- Tests
- README.md
Phase 4 — Validate
After generation, run through this checklist:
Run scripts/validate_project.py against the generated directory to catch common issues.
Examples
Example 1: Task Management API
Input spec:
"Build me a task management API. Users can create, list, update, and delete tasks. Tasks have a title, description, status (todo/in-progress/done), and due date. Use FastAPI with SQLite. Add basic auth with API keys."
Output file tree:
task-api/
├── README.md
├── .env.example # API_KEY, DATABASE_URL
├── .gitignore
├── .github/workflows/ci.yml
├── requirements.txt # fastapi, uvicorn, sqlalchemy, pytest
├── main.py # FastAPI app, CORS, lifespan
├── models.py # SQLAlchemy Task model
├── schemas.py # Pydantic request/response schemas
├── database.py # SQLite engine + session
├── auth.py # API key middleware
├── routers/
│ └── tasks.py # CRUD endpoints
└── tests/
└── test_tasks.py # Smoke tests for each endpoint
Example 2: Recipe Sharing Web App
Input spec:
"I want a recipe sharing website. Users sign up, post recipes with ingredients and steps, browse other recipes, and save favorites. Use Next.js with Tailwind. Store data in PostgreSQL."
Output file tree:
recipe-share/
├── README.md
├── .env.example # DATABASE_URL, NEXTAUTH_SECRET, NEXTAUTH_URL
├── .gitignore
├── .github/workflows/ci.yml
├── package.json # next, react, tailwindcss, prisma, next-auth
├── tailwind.config.ts
├── tsconfig.json
├── next.config.ts
├── prisma/
│ └── schema.prisma # User, Recipe, Ingredient, Favorite models
├── src/
│ ├── app/
│ │ ├── layout.tsx
│ │ ├── page.tsx # Homepage — recipe feed
│ │ ├── recipes/
│ │ │ ├── page.tsx # Browse recipes
│ │ │ ├── [id]/page.tsx # Recipe detail
│ │ │ └── new/page.tsx # Create recipe form
│ │ └── api/
│ │ ├── auth/[...nextauth]/route.ts
│ │ └── recipes/route.ts
│ ├── components/
│ │ ├── RecipeCard.tsx
│ │ ├── RecipeForm.tsx
│ │ └── Navbar.tsx
│ └── lib/
│ ├── prisma.ts
│ └── auth.ts
└── tests/
└── recipes.test.ts
Example 3: CLI Expense Tracker
Input spec:
"Python CLI tool for tracking expenses. Commands: add, list, summary, export-csv. Store in a local SQLite file. No external API."
Output file tree:
expense-tracker/
├── README.md
├── .gitignore
├── .github/workflows/ci.yml
├── pyproject.toml
├── src/
│ └── expense_tracker/
│ ├── __init__.py
│ ├── cli.py # argparse commands
│ ├── database.py # SQLite operations
│ ├── models.py # Expense dataclass
│ └── formatters.py # Table + CSV output
└── tests/
└── test_cli.py
Anti-Patterns
| Anti-pattern |
Fix |
Placeholder code — // TODO: implement, pass, empty function bodies |
Every function has a real implementation. If complex, implement a working simplified version. |
| Stack override — picking Next.js when the user said Flask |
Always honor explicit tech preferences. Only infer when the user doesn't specify. |
| Missing .gitignore — committing node_modules or .env |
Generate stack-appropriate .gitignore as one of the first files. |
| Phantom imports — importing packages not in the manifest |
Cross-check every import against package.json / requirements.txt before finishing. |
| Over-engineering MVP — adding Redis caching, rate limiting, WebSockets to a v1 |
Build the minimum that works. The user can iterate. |
| Ignoring stated preferences — user says "PostgreSQL" and you generate MongoDB |
Parse the spec carefully. Explicit preferences are non-negotiable. |
Missing env vars — code reads process.env.X but .env.example doesn't list it |
Every env var used in code must appear in .env.example with a comment. |
| No tests — shipping a repo with zero test files |
At minimum: one smoke test per API endpoint or one test per core function. |
| Hallucinated APIs — generating code that calls library methods that don't exist |
Stick to well-documented, stable APIs. When unsure, use the simplest approach. |
Validation Script
scripts/validate_project.py
Checks a generated project directory for common issues:
# Validate a generated project
python3 scripts/validate_project.py /path/to/generated-project
# JSON output
python3 scripts/validate_project.py /path/to/generated-project --format json
Checks performed:
- README.md exists and is non-empty
- .gitignore exists
- .env.example exists (if code references env vars)
- Package manifest exists (package.json, requirements.txt, go.mod, Cargo.toml, pubspec.yaml)
- No .env file committed (secrets leak)
- At least one test file exists
- No TODO/FIXME placeholders in generated code
Progressive Enhancement
For complex specs, generate in stages:
- MVP — Core feature only, working end-to-end
- Auth — Add authentication if requested
- Polish — Error handling, validation, loading states
- Deploy — Docker, CI, deploy config
Ask the user after MVP: "Core is working. Want me to add auth/polish/deploy next, or iterate on what's here?"
Cross-References
- Related:
product-team/saas-scaffolder — SaaS-specific scaffolding (Next.js + Stripe + Auth)
- Related:
engineering/spec-driven-workflow — spec-first development methodology
- Related:
engineering/database-designer — database schema design patterns
- Related:
engineering-team/senior-fullstack — full-stack implementation patterns
1---2name: spec-to-repo3description: Spec to Repo4---56# Spec to Repo78Turn a natural-language project specification into a complete, runnable starter repository. Not a template filler — a spec interpreter that generates real, working code for any stack.910## When to Use1112- User provides a text description of an app and wants code13- User has a PRD, requirements doc, or feature list and needs a codebase14- User says "build me an app that...", "scaffold this", "bootstrap a project"15- User wants a working starter repo, not just a file tree1617**Not this skill** when the user wants a SaaS app with Stripe + Auth specifically — use `product-team/saas-scaffolder` instead.1819## Core Workflow2021### Phase 1 — Parse & Interpret2223Read the spec. Extract these fields silently:2425| Field | Source | Required |26|-------|--------|----------|27| App name | Explicit or infer from description | yes |28| Description | First sentence of spec | yes |29| Features | Bullet points or sentences describing behavior | yes |30| Tech stack | Explicit ("use FastAPI") or infer from context | yes |31| Auth | "login", "users", "accounts", "roles" | if mentioned |32| Database | "store", "save", "persist", "records", "schema" | if mentioned |33| API surface | "endpoint", "API", "REST", "GraphQL" | if mentioned |34| Deploy target | "Vercel", "Docker", "AWS", "Railway" | if mentioned |3536**Stack inference rules** (when user doesn't specify):3738| Signal | Inferred stack |39|--------|---------------|40| "web app", "dashboard", "SaaS" | Next.js + TypeScript |41| "API", "backend", "microservice" | FastAPI (Python) or Express (Node) |42| "mobile app" | Flutter or React Native |43| "CLI tool" | Go or Python |44| "data pipeline" | Python |45| "high performance", "systems" | Rust or Go |4647After parsing, present a structured interpretation back to the user:4849```50## Spec Interpretation5152**App:** [name]53**Stack:** [framework + language]54**Features:**551. [feature]562. [feature]5758**Database:** [yes/no — engine]59**Auth:** [yes/no — method]60**Deploy:** [target]6162Does this match your intent? Any corrections before I generate?63```6465Flag ambiguities. Ask **at most 3** clarifying questions. If the user says "just build it", proceed with best-guess defaults.6667### Phase 2 — Architecture6869Design the project before writing any files:70711. **Select template** — Match to a stack template from `references/stack-templates.md`722. **Define file tree** — List every file that will be created733. **Map features to files** — Each feature gets at minimum one file/component744. **Design database schema** — If applicable, define tables/collections with fields and types755. **Identify dependencies** — List every package with version constraints766. **Plan API routes** — If applicable, list every endpoint with method, path, request/response shape7778Present the file tree to the user before generating:7980```81project-name/82├── README.md83├── .env.example84├── .gitignore85├── .github/workflows/ci.yml86├── package.json / requirements.txt / go.mod87├── src/88│ ├── ...89├── tests/90│ ├── ...91└── ...92```9394### Phase 3 — Generate9596Write every file. Rules:9798- **Real code, not stubs.** Every function has a real implementation. No `// TODO: implement` or `pass` placeholders.99- **Syntactically valid.** Every file must parse without errors in its language.100- **Imports match dependencies.** Every import must correspond to a package in the manifest (package.json, requirements.txt, go.mod, etc.).101- **Types included.** TypeScript projects use types. Python projects use type hints. Go projects use typed structs.102- **Environment variables.** Generate `.env.example` with every required variable, commented with purpose.103- **README.md.** Include: project description, prerequisites, setup steps (clone, install, configure env, run), and available scripts/commands.104- **CI config.** Generate `.github/workflows/ci.yml` with: install, lint (if linter in deps), test, build.105- **.gitignore.** Stack-appropriate ignores (node_modules, __pycache__, .env, build artifacts).106107**File generation order:**1081. Manifest (package.json / requirements.txt / go.mod)1092. Config files (.env.example, .gitignore, CI)1103. Database schema / migrations1114. Core business logic1125. API routes / endpoints1136. UI components (if applicable)1147. Tests1158. README.md116117### Phase 4 — Validate118119After generation, run through this checklist:120121- [ ] Every imported package exists in the manifest122- [ ] Every file referenced by an import exists in the tree123- [ ] `.env.example` lists every env var used in code124- [ ] `.gitignore` covers build artifacts and secrets125- [ ] README has setup instructions that actually work126- [ ] No hardcoded secrets, API keys, or passwords127- [ ] At least one test file exists128- [ ] Build/start command is documented and would work129130Run `scripts/validate_project.py` against the generated directory to catch common issues.131132## Examples133134### Example 1: Task Management API135136**Input spec:**137> "Build me a task management API. Users can create, list, update, and delete tasks. Tasks have a title, description, status (todo/in-progress/done), and due date. Use FastAPI with SQLite. Add basic auth with API keys."138139**Output file tree:**140```141task-api/142├── README.md143├── .env.example # API_KEY, DATABASE_URL144├── .gitignore145├── .github/workflows/ci.yml146├── requirements.txt # fastapi, uvicorn, sqlalchemy, pytest147├── main.py # FastAPI app, CORS, lifespan148├── models.py # SQLAlchemy Task model149├── schemas.py # Pydantic request/response schemas150├── database.py # SQLite engine + session151├── auth.py # API key middleware152├── routers/153│ └── tasks.py # CRUD endpoints154└── tests/155 └── test_tasks.py # Smoke tests for each endpoint156```157158### Example 2: Recipe Sharing Web App159160**Input spec:**161> "I want a recipe sharing website. Users sign up, post recipes with ingredients and steps, browse other recipes, and save favorites. Use Next.js with Tailwind. Store data in PostgreSQL."162163**Output file tree:**164```165recipe-share/166├── README.md167├── .env.example # DATABASE_URL, NEXTAUTH_SECRET, NEXTAUTH_URL168├── .gitignore169├── .github/workflows/ci.yml170├── package.json # next, react, tailwindcss, prisma, next-auth171├── tailwind.config.ts172├── tsconfig.json173├── next.config.ts174├── prisma/175│ └── schema.prisma # User, Recipe, Ingredient, Favorite models176├── src/177│ ├── app/178│ │ ├── layout.tsx179│ │ ├── page.tsx # Homepage — recipe feed180│ │ ├── recipes/181│ │ │ ├── page.tsx # Browse recipes182│ │ │ ├── [id]/page.tsx # Recipe detail183│ │ │ └── new/page.tsx # Create recipe form184│ │ └── api/185│ │ ├── auth/[...nextauth]/route.ts186│ │ └── recipes/route.ts187│ ├── components/188│ │ ├── RecipeCard.tsx189│ │ ├── RecipeForm.tsx190│ │ └── Navbar.tsx191│ └── lib/192│ ├── prisma.ts193│ └── auth.ts194└── tests/195 └── recipes.test.ts196```197198### Example 3: CLI Expense Tracker199200**Input spec:**201> "Python CLI tool for tracking expenses. Commands: add, list, summary, export-csv. Store in a local SQLite file. No external API."202203**Output file tree:**204```205expense-tracker/206├── README.md207├── .gitignore208├── .github/workflows/ci.yml209├── pyproject.toml210├── src/211│ └── expense_tracker/212│ ├── __init__.py213│ ├── cli.py # argparse commands214│ ├── database.py # SQLite operations215│ ├── models.py # Expense dataclass216│ └── formatters.py # Table + CSV output217└── tests/218 └── test_cli.py219```220221## Anti-Patterns222223| Anti-pattern | Fix |224|---|---|225| **Placeholder code** — `// TODO: implement`, `pass`, empty function bodies | Every function has a real implementation. If complex, implement a working simplified version. |226| **Stack override** — picking Next.js when the user said Flask | Always honor explicit tech preferences. Only infer when the user doesn't specify. |227| **Missing .gitignore** — committing node_modules or .env | Generate stack-appropriate .gitignore as one of the first files. |228| **Phantom imports** — importing packages not in the manifest | Cross-check every import against package.json / requirements.txt before finishing. |229| **Over-engineering MVP** — adding Redis caching, rate limiting, WebSockets to a v1 | Build the minimum that works. The user can iterate. |230| **Ignoring stated preferences** — user says "PostgreSQL" and you generate MongoDB | Parse the spec carefully. Explicit preferences are non-negotiable. |231| **Missing env vars** — code reads `process.env.X` but `.env.example` doesn't list it | Every env var used in code must appear in `.env.example` with a comment. |232| **No tests** — shipping a repo with zero test files | At minimum: one smoke test per API endpoint or one test per core function. |233| **Hallucinated APIs** — generating code that calls library methods that don't exist | Stick to well-documented, stable APIs. When unsure, use the simplest approach. |234235## Validation Script236237### `scripts/validate_project.py`238239Checks a generated project directory for common issues:240241```bash242# Validate a generated project243python3 scripts/validate_project.py /path/to/generated-project244245# JSON output246python3 scripts/validate_project.py /path/to/generated-project --format json247```248249Checks performed:250- README.md exists and is non-empty251- .gitignore exists252- .env.example exists (if code references env vars)253- Package manifest exists (package.json, requirements.txt, go.mod, Cargo.toml, pubspec.yaml)254- No .env file committed (secrets leak)255- At least one test file exists256- No TODO/FIXME placeholders in generated code257258## Progressive Enhancement259260For complex specs, generate in stages:2612621. **MVP** — Core feature only, working end-to-end2632. **Auth** — Add authentication if requested2643. **Polish** — Error handling, validation, loading states2654. **Deploy** — Docker, CI, deploy config266267Ask the user after MVP: "Core is working. Want me to add auth/polish/deploy next, or iterate on what's here?"268269## Cross-References270271- Related: `product-team/saas-scaffolder` — SaaS-specific scaffolding (Next.js + Stripe + Auth)272- Related: `engineering/spec-driven-workflow` — spec-first development methodology273- Related: `engineering/database-designer` — database schema design patterns274- Related: `engineering-team/senior-fullstack` — full-stack implementation patterns