Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
juxt avatar

Allium

  • 3.1k installs
  • 442 repo stars
  • Updated July 22, 2026
  • juxt/allium

allium is an agent skill for the Allium behavior specification language covering entities, rules, surfaces, contracts, and modular .allium file syntax.

About

Allium is a formal language for specifying observable software behavior between informal feature descriptions and code. It models entities, relationships, rules with when-requires-ensures clauses, surfaces at system boundaries, contracts, invariants, transition graphs, and modular imports without prescribing language, database, or UI choices. The skill documents entity syntax with projections and derived fields, trigger types from external stimuli to temporal and chained events, ensures patterns for state changes and Entity.created, and surface exposes-provides-related vocabulary. A routing table delegates elicitation, distillation, tending, weed alignment checks, and test propagation to companion skills. Allium targets integration and end-to-end tests, surfaces ambiguities early, and stays implementation agnostic. When the allium CLI is installed, a hook validates files after edits. Use it when authoring .allium files, reviewing domain specs, or choosing the right companion skill for eliciting, distilling, or generating tests from specifications.

  • Formal .allium syntax for entities, rules, surfaces, contracts, and invariants.
  • Implementation-agnostic specs focused on observable behavior, not frameworks.
  • Routing table to elicit, distill, tend, weed, and propagate companion skills.
  • Trigger and ensures patterns including chained events and Entity.created.
  • Generates integration and end-to-end tests, not unit tests.

Allium by the numbers

  • 3,090 all-time installs (skills.sh)
  • +153 installs in the week ending Aug 4, 2026 (Skillselion tracking)
  • Ranked #312 of 2,153 Testing & QA skills by installs in the Skillselion catalog
  • Security screen: MEDIUM risk (skills.sh audit)
  • Data as of Aug 4, 2026 (Skillselion catalog sync)
At a glance

allium capabilities & compatibility

Capabilities
entity, relationship, and projection modeling in · rule triggers and ensures clause authoring · surface boundary contracts with exposes and prov · contract and invariant declarations · modular spec imports with qualified names · routing to elicit, distill, tend, weed, and prop
Use cases
testing · documentation · planning
From the docs

What allium says it does

Describes observable behaviour, not implementation
SKILL.md
Generates integration and end-to-end tests (not unit tests)
SKILL.md
Forces ambiguities into the open before implementation
SKILL.md
npx skills add https://github.com/juxt/allium --skill allium

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs3.1k
repo stars442
Security audit3 / 3 scanners passed
Last updatedJuly 22, 2026
Repositoryjuxt/allium

How do I specify domain behavior precisely enough to generate tests without locking in implementation details?

Write and read .allium behavior specs that capture domain logic, surfaces, and rules before implementation or test generation.

Who is it for?

Teams defining observable behavior specs that feed integration tests and alignment checks.

Skip if: Skip when you only need unit tests, UI mockups, or database schema design without behavioral rules.

When should I use this skill?

User writes or reads .allium files, mentions Allium specs, or needs language syntax and routing to companion skills.

What you get

Validated .allium specifications with clear entities, rules, surfaces, and routing to the right companion workflow.

  • Domain questions from findings
  • Spec gap clarification prompts

Files

SKILL.mdMarkdownGitHub ↗

Allium

Allium is a formal language for capturing software behaviour at the domain level. It sits between informal feature descriptions and implementation, providing a precise way to specify what software does without prescribing how it's built.

The name comes from the botanical family containing onions and shallots, continuing a tradition in behaviour specification tooling established by Cucumber and Gherkin.

Key principles:

  • Describes observable behaviour, not implementation
  • Captures domain logic that matters at the behavioural level
  • Generates integration and end-to-end tests (not unit tests)
  • Forces ambiguities into the open before implementation
  • Implementation-agnostic: the same spec could be implemented in any language

Allium does NOT specify programming language or framework choices, database schemas or storage mechanisms, API designs or UI layouts, or internal algorithms (unless they are domain-level concerns).

Routing table

TaskToolWhen
Writing or reading .allium filesthis skillYou need language syntax and structure
Building a spec through conversationelicit skillUser describes a feature or behaviour they want to build
Extracting a spec from existing codedistill skillUser has implementation code and wants a spec from it
Modifying an existing spectend skillUser wants targeted changes to .allium files
Checking spec-to-code alignmentweed skillUser wants to find or fix divergences between spec and implementation
Generating tests from a specpropagate skillUser wants to generate tests, PBT properties or state machine tests from a specification

Quick syntax summary

Entity

entity Candidacy {
    -- Fields
    candidate: Candidate
    role: Role
    status: pending | active | completed | cancelled   -- inline enum
    retry_count: Integer

    -- Relationships
    invitation: Invitation with candidacy = this         -- one-to-one
    slots: InterviewSlot with candidacy = this           -- one-to-many

    -- Projections
    confirmed_slots: slots where status = confirmed
    pending_slots: slots where status = pending

    -- Derived
    is_ready: confirmed_slots.count >= 3
    has_expired: invitation.expires_at <= now
}

External entity

external entity Role { title: String, required_skills: Set<Skill>, location: Location }

Value type

value TimeRange { start: Timestamp, end: Timestamp, duration: end - start }

Sum type

A base entity declares a discriminator field whose capitalised values name the variants. Variants use the variant keyword.

entity Node {
    path: Path
    kind: Branch | Leaf              -- discriminator field
}

variant Branch : Node {
    children: List<Node?>
}

variant Leaf : Node {
    data: List<Integer>
    log: List<Integer>
}

Lowercase pipe values are enum literals (status: pending | active). Capitalised values are variant references (kind: Branch | Leaf). Type guards (requires: or if branches) narrow to a variant and unlock its fields.

Module given

Declares the entity instances a module's rules operate on. All rules inherit these bindings. Not every module needs one: rules scoped by triggers on domain entities get their entities from the trigger. given is for specs where rules operate on shared instances that exist once per module scope.

given {
    pipeline: HiringPipeline
    calendar: InterviewCalendar
}

Imported module instances are accessed via qualified names (scheduling/calendar) and do not appear in the local given block. Distinct from surface context, which binds a parametric scope for a boundary contract.

Rule

rule InvitationExpires {
    when: invitation: Invitation.expires_at <= now
    requires: invitation.status = pending
    let remaining = invitation.proposed_slots where status != cancelled
    ensures: invitation.status = expired
    ensures:
        for s in remaining:
            s.status = cancelled
    @guidance
        -- Non-normative implementation advice.
}

Trigger types

  • External stimulus: when: CandidateSelectsSlot(invitation, slot) — action from outside the system
  • State transition: when: interview: Interview.status transitions_to scheduled — entity changed state (transition only, not creation)
  • State becomes: when: interview: Interview.status becomes scheduled — entity has this value, whether by creation or transition
  • Temporal: when: invitation: Invitation.expires_at <= now — time-based condition (always add a requires guard against re-firing)
  • Derived condition: when: interview: Interview.all_feedback_in — derived value becomes true
  • Entity creation: when: batch: DigestBatch.created — fires when a new entity is created
  • Chained: when: AllConfirmationsResolved(candidacy) — subscribes to a trigger emission from another rule's ensures clause

All entity-scoped triggers use explicit var: Type binding. Use _ as a discard binding where the name is not needed: when: _: Invitation.expires_at <= now, when: SomeEvent(_, slot).

Rule-level iteration

A for clause applies the rule body once per element in a collection:

rule ProcessDigests {
    when: schedule: DigestSchedule.next_run_at <= now
    for user in Users where notification_setting.digest_enabled:
        let settings = user.notification_setting
        ensures: DigestBatch.created(user: user, ...)
}

Ensures patterns

Ensures clauses have four outcome forms:

  • State changes: entity.field = value
  • Entity creation: Entity.created(...) — the single canonical creation verb
  • Trigger emission: TriggerName(params) — emits an event for other rules to chain from
  • Entity removal: not exists entity — asserts the entity no longer exists

These forms compose with for iteration (for x in collection: ...), if/else conditionals and let bindings.

Entity creation uses .created() exclusively. Domain meaning lives in entity names and rule names, not in creation verbs.

In state change assignments, the right-hand expression references pre-rule field values. Conditions within ensures blocks (if guards, creation parameters, trigger emission parameters) reference the resulting state.

Surface

surface InterviewerDashboard {
    facing viewer: Interviewer

    context assignment: SlotConfirmation where interviewer = viewer

    exposes:
        assignment.slot.time
        assignment.status

    provides:
        InterviewerConfirmsSlot(viewer, assignment.slot)
            when assignment.status = pending

    related:
        InterviewDetail(assignment.slot.interview)
            when assignment.slot.interview != null
}

Surfaces define contracts at boundaries. The facing clause names the external party, context scopes the entity. The remaining clauses use a single vocabulary regardless of whether the boundary is user-facing or code-to-code: exposes (visible data, supports for iteration over collections), provides (available operations with optional when-guards), contracts: (references module-level contract declarations with demands/fulfils direction markers), @guarantee (named prose assertions about the boundary), @guidance (non-normative advice), related (associated surfaces reachable from this one), timeout (references to temporal rules that apply within the surface's context).

The facing clause accepts either an actor type (with a corresponding actor declaration and identified_by mapping) or an entity type directly. Use actor declarations when the boundary has specific identity requirements; use entity types when any instance can interact (e.g., facing visitor: User). For integration surfaces where the external party is code, declare an actor type with a minimal identified_by expression. Actors that reference within in their identified_by expression must declare the expected context type: within: Workspace.

Surface-to-implementation contract

The exposes block is the field-level contract: the implementation returns exactly these fields, the consumer uses exactly these fields. Do not add fields not listed. Do not omit fields that are listed.

Contract

contract Codec {
    serialize: (value: Any) -> ByteArray
    deserialize: (bytes: ByteArray) -> Any

    @invariant Roundtrip
        -- deserialize(serialize(value)) produces a value
        -- equivalent to the original for all supported types.
}

Contracts are module-level declarations referenced by name in surface contracts: clauses (demands Codec, fulfils EventSubmitter). See Contracts for declaration syntax and referencing rules.

Expressions

Navigation: interview.candidacy.candidate.email, reply_to?.author (optional), timezone ?? "UTC" (null coalescing). Collections: slots.count, slot in invitation.slots, interviewers.any(i => i.can_solo), for item in collection: item.status = cancelled, permissions + inherited (set union), old - new (set difference). Comparisons: status = pending, count >= 2, status in {confirmed, declined}, provider not in providers. Boolean logic: a and b, a or b, not a, a implies b.

Modular specs

use "github.com/allium-specs/google-oauth/abc123def" as oauth

Qualified names reference entities across specs: oauth/Session. Coordinates are immutable (git SHAs or content hashes). Local specs use relative paths: use "./candidacy.allium" as candidacy.

Config

config {
    invitation_expiry: Duration = 7.days
    max_login_attempts: Integer = 5
    extended_expiry: Duration = invitation_expiry * 2              -- expression-form default
    sync_timeout: Duration = core/config.default_timeout           -- config parameter reference
}

Rules reference config values as config.invitation_expiry. For default entity instances, use default.

Defaults

default Role viewer = { name: "viewer", permissions: { "documents.read" } }

Invariant

invariant NonNegativeBalance {
    for account in Accounts:
        account.balance >= 0
}

Expression-bearing invariants (invariant Name { expression }) assert properties over entity state. They are logical assertions, not runtime checks. Distinct from prose annotations (@invariant Name) in contracts, which use the @ sigil to mark content the checker does not evaluate. See Invariants.

Transition graph (v3)

entity Order {
    status: pending | confirmed | shipped | delivered | cancelled

    transitions status {
        pending -> confirmed
        confirmed -> shipped
        shipped -> delivered
        pending -> cancelled
        confirmed -> cancelled
        terminal: delivered, cancelled
    }
}

State-dependent field presence (v3)

entity Order {
    status: pending | confirmed | shipped | delivered | cancelled
    customer: Customer
    total: Money
    tracking_number: String when status = shipped | delivered
    shipped_at: Timestamp when status = shipped | delivered

    transitions status {
        pending -> confirmed
        confirmed -> shipped
        shipped -> delivered
        pending -> cancelled
        confirmed -> cancelled
        terminal: delivered, cancelled
    }
}

Deferred specs

deferred InterviewerMatching.suggest    -- see: detailed/interviewer-matching.allium

Open questions

open question "Admin ownership - should admins be assigned to specific roles?"

Verification

When the allium CLI is installed, a hook validates .allium files automatically after every write or edit. Fix any reported issues before presenting the result. If the CLI is not available, verify against the language reference.

References

  • Language reference — full syntax for entities, rules, expressions, surfaces, contracts, invariants and validation
  • Test generation — generating tests from specifications
  • Patterns — 9 worked patterns: auth, RBAC, invitations, soft delete, notifications, usage limits, comments, library spec integration, framework integration contract

Related skills

How it compares

Pick allium over generic code-review skills when input is Allium analyse output that must become product spec questions.

FAQ

Does Allium prescribe a programming language?

No. It describes observable behavior and stays implementation agnostic.

What tests does Allium generate?

Integration and end-to-end tests via the propagate skill, not unit tests.

How do I build a spec through conversation?

Use the elicit companion skill; this skill covers syntax and structure.

Is Allium safe to install?

skills.sh reports 3 of 3 security scanners passed. Review the Security Audits panel on this page before installing in production.

Testing & QAtestingdocs

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.