Agent skill

Imperative To Coq Model Extractor

by ArabelaTso in ArabelaTso/Skills-4-SE

Extract abstract mathematical models from imperative code (C, C++, Python, Java, etc.) suitable for formal reasoning in Coq.

Apache-2.0Auto-check passed

Install Imperative To Coq Model Extractor

skills CLI
$ npx skills add ArabelaTso/Skills-4-SE --skill imperative-to-coq-model-extractor -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ArabelaTso/Skills-4-SE imperative-to-coq-model-extractor --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ArabelaTso/Skills-4-SE.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/imperative-to-coq-model-extractor .claude/skills/imperative-to-coq-model-extractor && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
imperative-to-coq-model-extractor
GitHub stars
253
Token cost
~2.6k tokens
SKILL.md length
634 words
Files
2 (incl. references)
Skills in repo
170
Repo updated
First seen
Licence
Apache-2.0

At a glance

Extract abstract mathematical models from imperative code (C, C++, Python, Java, etc.) suitable for formal reasoning in Coq.

  • Works in 6 steps: Analyze Imperative Code → Design Coq Model Structure → Extract Core Model → …
  • The user asks to model imperative code in Coq
  • SKILL.md covers Overview, Extraction Workflow, Common Extraction Patterns and Examples, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Imperative To Coq Model Extractor is an agent skill from ArabelaTso/Skills-4-SE. Extract abstract mathematical models from imperative code (C, C++, Python, Java, etc.) suitable for formal reasoning in Coq. Use when the user asks to model imperative code in Coq, create Coq specifications from imperative programs, extract mathematical models for verification, or translate imperative algorithms to Coq for formal reasoning and proof.

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/extraction_patterns.md`).

It works with C++, Java and Python. The repository describes itself as: A curated list of 180+ useful Claude Skills for Software Engineering and resources for customizing AI for SE workflows. The licence is Apache-2.0.

When your agent uses it

  • The user asks to model imperative code in Coq
  • Create Coq specifications from imperative programs
  • Extract mathematical models for verification
  • Translate imperative algorithms to Coq for formal reasoning and proof

Example prompts

  • “/imperative-to-coq-model-extractor”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Analyze Imperative Code
  2. Design Coq Model Structure
  3. Extract Core Model
  4. Add Specifications
  5. Verify and Test
  6. Refine and Document

What it can do on your machine

Read from SKILL.md and the folder at commit 4f38503. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are coq, c, bash, python, java and cpp).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • coq.inria.fr
    • softwarefoundations.cis.upenn.edu

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Imperative To Coq Model Extractor loads about 2.6k tokens when it runs, and up to ~5.5k if it reads all its reference files. Until then it costs about 97 tokens; SKILL.md has 634 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~97
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ArabelaTso/Skills-4-SE at commit 4f38503, republished under its Apache-2.0 licence (© ArabelaTso). 634 words, ~2,603 tokens.

Download SKILL.mdSave it as .claude/skills/imperative-to-coq-model-extractor/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
imperative-to-coq-model-extractor
description
Extract abstract mathematical models from imperative code (C, C++, Python, Java, etc.) suitable for formal reasoning in Coq. Use when the user asks to model imperative code in Coq, create Coq specifications from imperative programs, extract mathematical models for verification, or translate imperative algorithms to Coq for formal reasoning and proof.

Imperative to Coq Model Extractor

Overview

Extract abstract mathematical models from imperative code that can be used for formal reasoning and verification in Coq. This skill transforms imperative programs into functional Coq definitions with explicit state modeling, enabling formal proofs about program behavior.

Extraction Workflow

Step 1: Analyze Imperative Code

Understand the program structure and semantics:

  1. Identify components:

    • Functions and their signatures
    • Data structures and types
    • State and mutable variables
    • Control flow (loops, conditionals)
    • Side effects and I/O
  2. Understand semantics:

    • What does the program compute?
    • What state does it maintain?
    • What are the invariants?
    • What are preconditions and postconditions?
  3. Note modeling challenges:

    • Mutable state
    • Imperative loops
    • Pointers and memory
    • Side effects
Step 2: Design Coq Model Structure

Plan the Coq representation:

  1. Choose appropriate types:

    • Z for arbitrary precision integers
    • nat for natural numbers
    • bool for booleans
    • list for sequences
    • Record for structured state
    • Inductive types for enumerations
  2. Model state explicitly:

    • Pure functions: Direct translation
    • Mutable state: State transformation functions
    • Side effects: Explicit state passing
  3. Plan control flow translation:

    • Conditionals → Pattern matching or if-then-else
    • Loops → Recursive functions (Fixpoint)
    • Early returns → Conditional expressions
Step 3: Extract Core Model

Translate imperative constructs to Coq:

Pattern: Pure function

c
// Imperative
int add(int a, int b) {
    return a + b;
}
coq
(* Coq Model *)
Definition add (a b : Z) : Z := a + b.

Pattern: Function with state

c
// Imperative
int counter = 0;
void increment() {
    counter++;
}
coq
(* Coq Model *)
Definition counter_state : Type := Z.
Definition increment (c : counter_state) : counter_state := c + 1.

Pattern: Loop → Recursion

c
// Imperative
int sum(int n) {
    int total = 0;
    for (int i = 0; i < n; i++) {
        total += i;
    }
    return total;
}
coq
(* Coq Model *)
Fixpoint sum_aux (n i total : nat) : nat :=
  match n with
  | 0 => total
  | S n' =>
      if i <? n then
        sum_aux n (S i) (total + i)
      else
        total
  end.

Definition sum (n : nat) : nat := sum_aux n 0 0.
Step 4: Add Specifications

Enhance the model with formal specifications:

  1. Function specifications:

    coq
    Definition abs (n : Z) : Z :=
      if n <? 0 then -n else n.
    
    Lemma abs_nonneg : forall n : Z, abs n >= 0.
    Proof.
      intros n. unfold abs.
      destruct (n <? 0) eqn:E.
      - apply Z.ltb_lt in E. lia.
      - apply Z.ltb_ge in E. lia.
    Qed.
  2. Loop invariants:

    coq
    (* Invariant: sum = sum of first i elements *)
    Lemma sum_invariant : forall n i total,
      i <= n ->
      sum_aux n i total = total + (sum of 0..i-1).
    Proof.
      (* Proof by induction *)
    Admitted.
  3. Correctness properties:

    coq
    Lemma sum_correct : forall n,
      sum n = n * (n - 1) / 2.
    Proof.
      (* Proof *)
    Admitted.
Step 5: Verify and Test

Ensure the model is correct:

  1. Type check:

    bash
    coqc model.v
  2. Test with examples:

    coq
    Compute add 2 3.        (* Should output 5 *)
    Compute sum 5.          (* Should output 10 *)
  3. Compare semantics:

    • Run original imperative program
    • Evaluate Coq model
    • Verify outputs match
Step 6: Refine and Document

Improve the extracted model:

  1. Simplify definitions:

    • Use standard library functions
    • Remove redundant constructs
    • Factor out common patterns
  2. Add documentation:

    coq
    (* Computes the absolute value of an integer *)
    Definition abs (n : Z) : Z := ...
  3. Organize proofs:

    • Group related lemmas
    • Add proof sketches
    • Document proof strategies

Common Extraction Patterns

For detailed patterns, see extraction_patterns.md.

Quick Reference
ImperativeCoq Model
int x = 10Definition x : Z := 10
x = x + 1x + 1 (functional update)
if (x > 0)if x >? 0 then ... else ...
for (i=0; i<n; i++)Fixpoint loop (i : nat) ...
while (cond)Fixpoint loop ... if cond then ...
struct S { int x; }Record S := { x : Z }
int arr[5]list Z or Definition arr := [...]
return xx (last expression)
Show full SKILL.md (270 more words)Show less

Examples

Example 1: Simple Algorithm

Imperative Input (C):

c
int factorial(int n) {
    int result = 1;
    while (n > 1) {
        result *= n;
        n--;
    }
    return result;
}

Coq Model:

coq
Fixpoint factorial (n : nat) : nat :=
  match n with
  | 0 => 1
  | S n' => n * factorial n'
  end.

Lemma factorial_positive : forall n,
  factorial n >= 1.
Proof.
  induction n.
  - simpl. lia.
  - simpl. lia.
Qed.
Example 2: Array Processing

Imperative Input (Python):

python
def find_max(arr):
    max_val = arr[0]
    for i in range(1, len(arr)):
        if arr[i] > max_val:
            max_val = arr[i]
    return max_val

Coq Model:

coq
Require Import List.
Import ListNotations.

Fixpoint find_max (l : list Z) (default : Z) : Z :=
  match l with
  | [] => default
  | [x] => x
  | x :: xs => Z.max x (find_max xs default)
  end.

Lemma find_max_in_list : forall l default,
  l <> [] ->
  In (find_max l default) l.
Proof.
  (* Proof by induction *)
Admitted.

Lemma find_max_is_max : forall l default x,
  In x l ->
  x <= find_max l default.
Proof.
  (* Proof by induction *)
Admitted.
Example 3: Stateful Program

Imperative Input (Java):

java
class Counter {
    private int count = 0;

    public void increment() {
        count++;
    }

    public int getCount() {
        return count;
    }
}

Coq Model:

coq
Record CounterState : Type := mkCounter {
  count : nat
}.

Definition init_counter : CounterState := {|
  count := 0
|}.

Definition increment (s : CounterState) : CounterState := {|
  count := S s.(count)
|}.

Definition getCount (s : CounterState) : nat :=
  s.(count).

(* Specification *)
Lemma increment_increases : forall s,
  getCount (increment s) = S (getCount s).
Proof.
  intros s. unfold increment, getCount. simpl. reflexivity.
Qed.

Imperative Input (C++):

cpp
int binary_search(int arr[], int n, int target) {
    int left = 0, right = n - 1;
    while (left <= right) {
        int mid = (left + right) / 2;
        if (arr[mid] == target)
            return mid;
        else if (arr[mid] < target)
            left = mid + 1;
        else
            right = mid - 1;
    }
    return -1;
}

Coq Model:

coq
Require Import List.
Import ListNotations.

Fixpoint binary_search_aux (l : list Z) (target : Z)
                            (left right : nat) : option nat :=
  match right - left with
  | 0 =>
      match nth_error l left with
      | Some v => if v =? target then Some left else None
      | None => None
      end
  | S _ =>
      if left <=? right then
        let mid := (left + right) / 2 in
        match nth_error l mid with
        | Some v =>
            if v =? target then Some mid
            else if v <? target then
              binary_search_aux l target (S mid) right
            else
              binary_search_aux l target left (mid - 1)
        | None => None
        end
      else None
  end.

Definition binary_search (l : list Z) (target : Z) : option nat :=
  binary_search_aux l target 0 (length l - 1).

(* Specification: if result is Some i, then l[i] = target *)
Lemma binary_search_correct : forall l target i,
  binary_search l target = Some i ->
  nth_error l i = Some target.
Proof.
  (* Proof *)
Admitted.

Best Practices

  1. Model state explicitly: Make all state transformations visible in function signatures
  2. Use appropriate types: Choose nat for non-negative values, Z for integers
  3. Preserve semantics: Ensure the Coq model computes the same results as the original
  4. Add specifications: Document expected behavior with lemmas and theorems
  5. Test incrementally: Verify small pieces before combining
  6. Use standard library: Leverage existing Coq definitions and tactics
  7. Document assumptions: Make implicit assumptions explicit in the model
  8. Handle edge cases: Explicitly model boundary conditions

Key Differences: Imperative vs Coq Model

  1. Mutability: Imperative code mutates variables; Coq models use functional updates
  2. Loops: Imperative loops become recursive functions in Coq
  3. State: Imperative state is implicit; Coq models make state explicit
  4. Side effects: Imperative side effects become explicit state transformations
  5. Types: Imperative types may be implicit; Coq requires explicit types
  6. Verification: Coq models enable formal proofs about program behavior

Limitations and Considerations

  1. Abstraction level: Models abstract away low-level details (memory layout, performance)
  2. Undefined behavior: Imperative undefined behavior must be handled explicitly
  3. Concurrency: Multi-threaded code requires more sophisticated modeling
  4. I/O: Input/output operations need special treatment in pure models
  5. Pointers: Pointer arithmetic requires explicit memory modeling
  6. Complexity: Some imperative patterns are complex to model functionally

Resources

© ArabelaTso, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/imperative-to-coq-model-extractor of ArabelaTso/Skills-4-SE.

  • SKILL.md
  • references/extraction_patterns.md

Open the folder on GitHubat commit 4f38503

Compare with similar skills

Imperative To Coq Model Extractor next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Imperative To Coq Model Extractor compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Imperative To Coq Model Extractor this skillArabelaTso/Skills-4-SE253—~2.6kAutomated safety check: PassApache-2.0
Fory Releaseapache/fory4.6k—~2.9kAutomated safety check: PassApache-2.0
CodeQL Security Scantrailofbits/skills7.5k—~4.6kAutomated safety check: NotesCC-BY-SA-4.0
Fory Version Bumpapache/fory4.6k—~1.1kAutomated safety check: PassApache-2.0
Fory Performance Optimizationapache/fory4.6k—~2.2kAutomated safety check: PassApache-2.0
Dbgtheodo-group/debug-that158—~2.5kAutomated safety check: PassMIT

Similar skills

  • Fory Release

    apache/fory

    Prepare an Apache Fory release candidate from a clean release branch, including the version bump, RC tag, JVM staging, ASF source artifacts, SVN upload, and vote email.

    4.6k GitHub stars~2.9k tokensUpdated yesterday
    Auto-check passed
  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.5k GitHub stars~4.6k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Bump Apache Fory release or post-release development versions across Java, Kotlin, Scala, Python, Rust, Go, C++, C, Dart, JavaScript, Swift, integration tests, examples, and source docs.

    4.6k GitHub stars~1.1k tokensUpdated yesterday
    MobileAuto-check passed
  • Run profile-driven bottleneck optimization across Apache Fory implementations (Java, C++, Python/Cython, Go, Rust, Swift, C, JavaScript/TypeScript, Dart, Kotlin, Scala).

    4.6k GitHub stars~2.2k tokensUpdated yesterday
    MobileAuto-check passed
  • Dbg

    theodo-group/debug-that

    Debug applications using the dbg CLI debugger. An agent skill from theodo-group/debug-that.

    158 GitHub stars~2.5k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Rsid SDK

    realsenseai/RealSenseID

    RealSenseID face authentication SDK reference. An agent skill from realsenseai/RealSenseID.

    122 GitHub stars~4.1k tokensUpdated 4 days ago
    Backend & APIsAuto-check passed

More from ArabelaTso/Skills-4-SE

All 170 skills in this repo
  • Framework Migration Assistant

    ArabelaTso/Skills-4-SE

    Automatically migrate Python web applications between frameworks (Flask → FastAPI, Django → FastAPI).

    253 GitHub stars~1.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Metamorphic Test Generator

    ArabelaTso/Skills-4-SE

    Generate test cases using metamorphic testing by applying transformations based on metamorphic properties.

    253 GitHub stars~798 tokensUpdated 1 mo ago
    Auto-check passed
  • Reproduction Trace Instrumenter

    ArabelaTso/Skills-4-SE

    Instruments programs to capture execution traces specifically for reproducing reported bugs, enabling consistent replay and diagnosis of failures.

    253 GitHub stars~2.4k tokensUpdated 1 mo ago
    Auto-check passed
  • Spring Mvc To Boot Migrator

    ArabelaTso/Skills-4-SE

    Automatically migrate Spring MVC applications to Spring Boot.

    253 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check passed
  • State Snapshot Instrumenter

    ArabelaTso/Skills-4-SE

    Instrument programs (Python, C/C++, Java) to capture snapshots of key program states at runtime, including variables, memory, and call stacks.

    253 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Questions about Imperative To Coq Model Extractor

What does Imperative To Coq Model Extractor do?

Extract abstract mathematical models from imperative code (C, C++, Python, Java, etc.) suitable for formal reasoning in Coq. Imperative To Coq Model Extractor is an agent skill from ArabelaTso/Skills-4-SE.) suitable for formal reasoning in Coq.

When should I use Imperative To Coq Model Extractor?

Imperative To Coq Model Extractor fits situations like: the user asks to model imperative code in Coq; create Coq specifications from imperative programs; extract mathematical models for verification; translate imperative algorithms to Coq for formal reasoning and proof.

How do I install Imperative To Coq Model Extractor in Claude Code?

Run `npx skills add ArabelaTso/Skills-4-SE --skill imperative-to-coq-model-extractor -a claude-code`. Or copy the skill folder (skills/imperative-to-coq-model-extractor in ArabelaTso/Skills-4-SE) into .claude/skills/imperative-to-coq-model-extractor in your project. Claude Code loads it when a task matches its description.

How do I install Imperative To Coq Model Extractor in Codex?

Run `npx skills add ArabelaTso/Skills-4-SE --skill imperative-to-coq-model-extractor -a codex`. Or copy the skill folder (skills/imperative-to-coq-model-extractor in ArabelaTso/Skills-4-SE) into .agents/skills/imperative-to-coq-model-extractor in your project. Codex loads it when a task matches its description.

Can I use Imperative To Coq Model Extractor in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ArabelaTso/Skills-4-SE --skill imperative-to-coq-model-extractor -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/imperative-to-coq-model-extractor, .gemini/skills/imperative-to-coq-model-extractor, .github/skills/imperative-to-coq-model-extractor and .opencode/skills/imperative-to-coq-model-extractor in your project.

What does Imperative To Coq Model Extractor need to run?

SKILL.md names no scripts, command-line tools or credentials: Imperative To Coq Model Extractor is instructions for the agent only. Our summary lists: Python 3.

Does Imperative To Coq Model Extractor access the network?

SKILL.md names 2 domains. As links in the text: coq.inria.fr and softwarefoundations.cis.upenn.edu. This is read from the text; nothing was executed.

Is Imperative To Coq Model Extractor safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Imperative To Coq Model Extractor use?

Imperative To Coq Model Extractor is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Imperative To Coq Model Extractor use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.9k tokens, read only when the agent opens those files.

What are the alternatives to Imperative To Coq Model Extractor?

Skills that share tags, products or a category with Imperative To Coq Model Extractor: Fory Release (apache/fory, 4.6k stars), CodeQL Security Scan (trailofbits/skills, 7.5k stars), Fory Version Bump (apache/fory, 4.6k stars) and Fory Performance Optimization (apache/fory, 4.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Imperative To Coq Model Extractor?

ArabelaTso (a GitHub user) maintains it in ArabelaTso/Skills-4-SE, which has 253 GitHub stars. The repository holds 170 skills in this directory. The repository was last updated on August 21, 2026.

Source: ArabelaTso/Skills-4-SE on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.