ExploitSpec is a free, local-first CLI and GitHub Action for preserving a confirmed HTTP exploit as a deterministic regression test. Define isolated actors, capture dynamic values, assert the security boundary, and calibrate the same invariant RED on the vulnerable baseline, GREEN after the fix, and STABLE across repeated runs. Plain YAML, Apache-2.0, no account, no telemetry, and no hosted service.