A collection of sample Spec-Driven Development (SDD) specifications generated with MySpec.dev.
Each sample under specs/ is a complete specification set for a software project, written before any code exists. Every sample contains the same four documents:
| File | Purpose |
|---|---|
constitution.md |
Project vision, non-negotiable principles, and technology constraints |
requirements.md |
What the system must do: functional and non-functional requirements |
solution.md |
How it will be built: architecture, design decisions, and module layout |
tasks.md |
An ordered, milestone-grouped implementation task list with acceptance criteria |
-
binance-trading-bot-optimiser — A local, non-interactive Python CLI that ingests Binance public historical market data into DuckDB and backtests or optimises Spot Grid and Futures Grid bot configurations using walk-forward validation. The design centres on discounting its own optimism: it reports fee-accurate results, applies deflation for search size, and never executes live orders or touches an account.
-
carbon-removal-mrv-registry — A carbon dioxide removal (CDR) Measurement, Reporting & Verification (MRV) platform and serialized credit registry aligned with the EU Carbon Removals and Carbon Farming (CRCF) Regulation and ICVCM Core Carbon Principles across biochar, DACCS, BECCS, and enhanced rock weathering. Computes conservative net removals (
$R_{\text{gross}} - R_{\text{baseline}} - E_{\text{LCA}} - E_{\text{leakage}}$ ) with Monte Carlo uncertainty discounts and risk-scored reversal buffer pools, runs ISO 14064-3 VVB verification workflows, and issues 1 tCO2e serial ranges with transfer, retirement, and cancellation on a hash-chained ledger, with Paris Agreement Article 6 corresponding-adjustment flags to prevent double counting. -
clinical-trial-ctms-etmf — A compliant Clinical Trial Management System (CTMS) and Electronic Trial Master File (eTMF) for decentralized and site-based clinical research. Built to FDA 21 CFR Part 11 and ICH GCP standards, it enforces cryptographic dual-factor digital signatures, Merkle-hashed computer-generated audit trails, complete DIA TMF Reference Model v3.2 taxonomy (Zones 01–11), automated protocol deviation tracking, and a 24-hour Serious Adverse Event (SAE) escalation engine with CIOMS I / MedWatch 3500A exports.
-
cloud-erp-mes — A modular cloud ERP and shop-floor Manufacturing Execution System (MES) designed for precision discrete manufacturing. Enforces a strict double-entry general ledger invariant (
$\sum \text{Debits} = \sum \text{Credits}$ ), multi-level recursive Bill of Materials (BOM) cost rollups, and Engineering Change Order (ECO) locks, coupled with an offline-tolerant edge gateway running MQTT/OPC-UA machine telemetry and real-time Overall Equipment Effectiveness (OEE) calculation. -
cra-sbom-vulnerability-hub — A product security and vulnerability handling hub for manufacturers under the EU Cyber Resilience Act (CRA, Regulation (EU) 2024/2847). Seals a CycloneDX 1.6 / SPDX SBOM to every release, continuously matches components against OSV, NVD, GitHub Advisories, CISA KEV, and EPSS, records exploitability as append-only CycloneDX VEX / OpenVEX with CSAF 2.0 advisories, and runs a durable Article 14 reporting clock (24h early warning, 72h notification, 14-day final report) to ENISA's single reporting platform, plus ISO/IEC 29147/30111 coordinated disclosure intake and support-period tracking.
-
csrd-esrs-sustainability — A statutory sustainability reporting and corporate governance platform built for mandatory EU Corporate Sustainability Reporting Directive (CSRD) and CSDDD compliance. Automates two-dimensional quantitative Double Materiality Assessments (DMA) across all 10 topical ESRS standards (E1–E5, S1–S4, G1), Scope 1–3 GHG Protocol carbon accounting with versioned emission factor databases, cryptographic raw evidence lineage DAGs, and ESEF-compliant Inline XBRL (iXBRL) digital taxonomy filing exports for statutory external assurance (ISAE 3000 / ISSA 5000).
-
dora-ict-resilience-platform — An ICT risk and operational resilience platform for EU financial entities under the Digital Operational Resilience Act (DORA, Regulation (EU) 2022/2554). A versioned RTS classification engine flags major ICT incidents and a watchdog enforces the 4h / 72h / 1-month initial, intermediate, and final reporting clocks, alongside the ITS Register of Information (
B_01.01–B_07.01) with LEI validation and xBRL-CSV export, HHI concentration-risk analysis of critical or important functions, TIBER-EU threat-led penetration testing (TLPT) tracking, and hash-chained WORM evidence. -
dscsa-pharma-traceability — A serialization and package-level traceability platform for the US Drug Supply Chain Security Act (DSCSA) enhanced drug distribution security requirements, with EU Falsified Medicines Directive (FMD) support. Captures GS1 EPCIS 2.0 / CBV events for every SGTIN encoded in a GS1 DataMatrix, enforces an aggregation conservation invariant across unit → case → pallet SSCC hierarchies, and gates Transaction Information / Transaction Statement exchange on Authorized Trading Partner checks, with VRS saleable-returns verification (
$\le 1\text{s}$ p99), suspect product quarantine with a 24-hour FDA Form 3911 countdown, and 6-year WORM retention. -
enterprise-ai-gateway — A high-performance, zero-trust streaming reverse proxy and policy enforcement platform for enterprise LLM traffic and autonomous agent tools. Built for EU AI Act, ISO 42001, and SOC 2 compliance, it adds
$\le 15\text{ms}$ latency overhead while executing inline PII/PHI redaction, prompt injection defense, dynamic provider failover, semantic caching, token-level FinOps budgets, and an MCP agent execution sandbox with Human-in-the-Loop authorization and tamper-evident WORM audit logs. -
eu-battery-passport — A Digital Battery Passport platform for the EU Battery Regulation (EU) 2023/1542, mandatory for EV, LMT, and industrial batteries above 2 kWh from 18 February 2027. Mints a unique identifier per battery resolved via GS1 Digital Link QR codes, serves ~70 data attributes through deny-by-default access tiers (public, legitimate interest, authorities), requires W3C Verifiable Credential signatures for supplier claims (carbon footprint, recycled Co/Li/Ni/Pb content, due diligence), ingests BMS State of Health telemetry, and enforces a one-way lifecycle state machine that links a successor passport on repurposing or remanufacturing.
-
eudr-deforestation-due-diligence — A due-diligence and traceability platform for the EU Deforestation Regulation (EUDR, Regulation (EU) 2023/1115) covering cattle, cocoa, coffee, oil palm, rubber, soya, and wood ahead of the 30 December 2026 deadline for large and medium operators. Captures plot geolocation as WGS84 GeoJSON (points ≤ 4 ha, polygons > 4 ha), screens every plot by satellite against the 31 December 2020 cut-off (JRC GFC2020, Hansen loss-year, RADD/GLAD alerts), applies EU country risk benchmarking, tracks segregated and controlled-blend custody across supplier tiers and HS codes, and submits Due Diligence Statements to EU TRACES with 5-year hash-chained evidence retention.
-
ev-charging-csms-ocpp — A Charging Station Management System (CSMS) for a charge point operator managing 50,000 chargers over OCPP 2.1 (IEC 63584) and OCPP 2.0.1 with OCPP 1.6J backward compatibility and Security Profiles 1–3 (Basic Auth, TLS, mTLS). Covers the device model, staged firmware rollouts, ISO 15118-2/-20 Plug & Charge V2G PKI, grid-capped smart charging ($\sum P_i + P_{\text{building}} \le P_{\text{grid}}(1 - m)$) via composite schedules, OCPP 2.1 bidirectional V2G and DER control, Eichrecht OCMF signed meter values, and OCPI 2.2.1 roaming with eMSPs.
-
fhir-prior-authorization-payer — A health-plan interoperability and electronic prior authorization platform for the US CMS Interoperability and Prior Authorization Final Rule (CMS-0057-F), delivering HL7 FHIR R4 Patient Access, Provider Access, Payer-to-Payer, and Prior Authorization APIs ahead of the 1 January 2027 deadline. Runs the Da Vinci CRD (CDS Hooks) → DTR (Questionnaire + CQL via SMART launch) → PAS (
Claim/$submit, X12 278 translation) workflow under SMART on FHIR / OAuth 2.0, with a decision-clock engine enforcing 72-hour expedited and 7-day standard decisions, specific denial reasons, and public prior-authorization metrics reporting. -
go-htmx-template-engine —
.ghtmx, an open source Go template engine hard-forked fromtemplthat makes htmx a first-class, compile-checked language concept. Bindings such ashx-getreference Go handler symbols resolved against a statically derived route table, page fragments get dual render entry points at build time, andHX-Triggerevents are declared with typed payloads. Ships a CLI, runtime, LSP, dev server, and adapters for common Go routers. -
open-banking-consent-hub — A bank-side (ASPSP / data provider) open finance API gateway and consent management hub serving account information, payment initiation, and funds-confirmation APIs to licensed third parties under PSD2 RTS-SCA and the US CFPB Section 1033 rule, designed to carry forward to PSD3/PSR. Enforces the FAPI 2.0 Security Profile (PAR, PKCE,
private_key_jwt, DPoP/mTLS sender-constrained tokens), eIDAS QWAC/QSealC validation, and dynamic client registration, with granular consents, 180-day re-authentication, sub-5-second revocation, signed consent receipts, SCA dynamic linking, per-TPP rate limiting, and API performance parity reporting. -
payment-reconciliation-engine — A high-throughput financial reconciliation and dispute defense engine processing tens of millions of records across heterogeneous payment rails (card schemes, ACH, FedNow, SEPA Instant, and ISO 20022 camt.053 / MT940). Features tiered deterministic 1:1, 1:N, and N:M matching algorithms, automated zero-float suspense break aging, balanced ERP journal postings, and automated chargeback evidence assembly with statutory representment deadline tracking.
-
virtual-power-plant-derms — A Virtual Power Plant (VPP) and DER aggregation platform that turns 100,000+ residential and C&I batteries, solar inverters, heat pumps, and EV chargers into dispatchable portfolios for wholesale, ancillary service, and demand response markets, including FERC Order 2222 aggregations. Integrates devices over IEEE 2030.5 / CSIP, OpenADR 3.0, SunSpec Modbus, and vendor clouds, sizes bids from P10/P50/P90 availability forecasts, and runs an LP dispatch optimiser that respects ramp rates, SoC limits, and customer backup reserves without breaching utility feeder operating envelopes (
$\text{OE}^{\min}_f \le \sum P_d \le \text{OE}^{\max}_f$ ), with 10-of-10 baseline settlement and customer incentive payouts. -
warehouse-management-wms — A high-velocity Warehouse Management System (WMS) and multimodal freight logistics platform. Combines 3D coordinate bin addresses, GS1-128 License Plate Numbering (LPN), and traveling salesperson pick-path optimization with an intermodal freight state machine across ocean, air, rail, and drayage legs, complete with an automated demurrage/detention countdown watchdog and bi-directional ANSI X12 (204, 214, 304) and UN/EDIFACT (IFTMIN, IFTSTA, DESADV) bridges.