Audit Correctness Proof
ben-manes/caffeine
Attempt formal correctness proofs for all public cache methods
Generate Isabelle or Coq proofs establishing partial or total correctness of imperative programs from code and formal specifications.
$ npx skills add ArabelaTso/Skills-4-SE --skill program-correctness-prover -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ArabelaTso/Skills-4-SE program-correctness-prover --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ArabelaTso/Skills-4-SE.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/program-correctness-prover .claude/skills/program-correctness-prover && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "program-correctness-prover" agent skill from https://github.com/ArabelaTso/Skills-4-SE/tree/main/skills/program-correctness-prover into .claude/skills/program-correctness-prover/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "program-correctness-prover", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ArabelaTso/Skills-4-SE/tree/main/skills/program-correctness-proverType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ArabelaTso/Skills-4-SE --skill program-correctness-prover -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ArabelaTso/Skills-4-SE program-correctness-prover --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ArabelaTso/Skills-4-SE.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/program-correctness-prover .agents/skills/program-correctness-prover && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "program-correctness-prover" agent skill from https://github.com/ArabelaTso/Skills-4-SE/tree/main/skills/program-correctness-prover into .agents/skills/program-correctness-prover/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "program-correctness-prover", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ArabelaTso/Skills-4-SE --skill program-correctness-prover -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ArabelaTso/Skills-4-SE program-correctness-prover --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ArabelaTso/Skills-4-SE.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/program-correctness-prover .cursor/skills/program-correctness-prover && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "program-correctness-prover" agent skill from https://github.com/ArabelaTso/Skills-4-SE/tree/main/skills/program-correctness-prover into .cursor/skills/program-correctness-prover/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "program-correctness-prover", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ArabelaTso/Skills-4-SE.git --path skills/program-correctness-prover--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ArabelaTso/Skills-4-SE --skill program-correctness-prover -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ArabelaTso/Skills-4-SE program-correctness-prover --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ArabelaTso/Skills-4-SE.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/program-correctness-prover .gemini/skills/program-correctness-prover && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "program-correctness-prover" agent skill from https://github.com/ArabelaTso/Skills-4-SE/tree/main/skills/program-correctness-prover into .gemini/skills/program-correctness-prover/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "program-correctness-prover", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ArabelaTso/Skills-4-SE program-correctness-proverInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ArabelaTso/Skills-4-SE --skill program-correctness-prover -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ArabelaTso/Skills-4-SE.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/program-correctness-prover .github/skills/program-correctness-prover && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "program-correctness-prover" agent skill from https://github.com/ArabelaTso/Skills-4-SE/tree/main/skills/program-correctness-prover into .github/skills/program-correctness-prover/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "program-correctness-prover", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ArabelaTso/Skills-4-SE --skill program-correctness-prover -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ArabelaTso/Skills-4-SE program-correctness-prover --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ArabelaTso/Skills-4-SE.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/program-correctness-prover .opencode/skills/program-correctness-prover && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "program-correctness-prover" agent skill from https://github.com/ArabelaTso/Skills-4-SE/tree/main/skills/program-correctness-prover into .opencode/skills/program-correctness-prover/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "program-correctness-prover", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
program-correctness-proverGenerate Isabelle or Coq proofs establishing partial or total correctness of imperative programs from code and formal specifications.
Program Correctness Prover is an agent skill from ArabelaTso/Skills-4-SE. Generate Isabelle or Coq proofs establishing partial or total correctness of imperative programs from code and formal specifications. Use when users need to: (1) Prove program correctness using Hoare logic, (2) Generate verification conditions from pre/postconditions, (3) Construct loop invariants and termination arguments, (4) Verify imperative programs with assignments, conditionals, and loops. Supports both partial correctness (if terminates, postcondition holds) and total correctness (terminates and…
Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/hoare_logic.md` and `references/verification_patterns.md`).
The repository describes itself as: A curated list of 180+ useful Claude Skills for Software Engineering and resources for customizing AI for SE workflows. The licence is Apache-2.0.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 4f38503. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are isabelle and coq).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Program Correctness Prover loads about 2.5k tokens when it runs, and up to ~6.8k if it reads all its reference files. Until then it costs about 147 tokens; SKILL.md has 743 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from ArabelaTso/Skills-4-SE at commit 4f38503, republished under its Apache-2.0 licence (© ArabelaTso). 743 words, ~2,452 tokens.
.claude/skills/program-correctness-prover/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.Generate formal proofs establishing correctness of imperative programs.
This skill takes imperative program code with formal specifications (preconditions and postconditions) and generates complete correctness proofs in Isabelle or Coq using Hoare logic. It handles loop invariant generation, verification condition generation, and proof construction for both partial and total correctness.
Provide:
The skill will generate:
Identify program components:
x := EC1; C2if B then C1 else C2while B do CFor each loop, construct an invariant that:
{I ∧ B} C {I}I ∧ ¬B ⟹ QStrategies:
Apply Hoare logic rules to generate VCs:
Assignment: {P[E/x]} x := E {P}
Sequence: Chain intermediate conditions
Conditional: Prove both branches
Loop: Prove initialization, preservation, and termination
Build formal proof in target system:
Provide variant function V that:
Program:
sum := 0;
i := 0;
while i < n do
sum := sum + a[i];
i := i + 1
doneSpecification:
n ≥ 0sum = Σ(a[0..n-1])Analysis:
Loop Invariant:
I: sum = Σ(a[0..i-1]) ∧ 0 ≤ i ≤ nVerification Conditions:
Initialization: n ≥ 0 ⟹ 0 = Σ(a[0..-1]) ∧ 0 ≤ 0 ≤ n
n ≥ 0 ⟹ 0 = 0 ∧ 0 ≤ n ✓Preservation: {I ∧ i < n} sum := sum + a[i]; i := i + 1 {I}
sum + a[i] = Σ(a[0..i]) ∧ 0 ≤ i + 1 ≤ nPostcondition: I ∧ ¬(i < n) ⟹ sum = Σ(a[0..n-1])
Termination (total correctness): V = n - i
Isabelle Proof (abbreviated):
lemma sum_array_partial:
"⦃λs. s ''n'' ≥ 0⦄
sum := 0;; i := 0;;
While (λs. s ''i'' < s ''n'')
Do (sum := (λs. s ''sum'' + s ''a'' (s ''i''));;
i := (λs. s ''i'' + 1))
⦃λs. s ''sum'' = (∑j<s ''n''. s ''a'' j)⦄"
proof -
define I where "I = (λs. s ''sum'' = (∑j<s ''i''. s ''a'' j) ∧
0 ≤ s ''i'' ∧ s ''i'' ≤ s ''n'')"
(* Initialization *)
have "⦃λs. s ''n'' ≥ 0⦄ sum := 0;; i := 0 ⦃I⦄"
unfolding I_def by (auto intro: hoare_seq hoare_asgn)
(* Loop body preserves invariant *)
moreover have "⦃λs. I s ∧ s ''i'' < s ''n''⦄
sum := (λs. s ''sum'' + s ''a'' (s ''i''));;
i := (λs. s ''i'' + 1)
⦃I⦄"
unfolding I_def by (auto intro: hoare_seq hoare_asgn)
(* Apply while rule *)
ultimately have "⦃λs. s ''n'' ≥ 0⦄
sum := 0;; i := 0;;
While (λs. s ''i'' < s ''n'')
Do (sum := (λs. s ''sum'' + s ''a'' (s ''i''));;
i := (λs. s ''i'' + 1))
⦃λs. I s ∧ ¬(s ''i'' < s ''n'')⦄"
by (auto intro: hoare_seq hoare_while)
(* Postcondition follows from invariant *)
then show ?thesis
unfolding I_def by (rule hoare_conseq) auto
qedCoq Proof (abbreviated):
Theorem sum_array_partial : forall n a,
n >= 0 ->
{{ fun st => st N = n /\ n >= 0 }}
sum ::= 0;;
i ::= 0;;
while i < N do
sum ::= sum + a[i];;
i ::= i + 1
done
{{ fun st => st sum = sum_array a n }}.
Proof.
intros n a Hn.
remember (fun st => st sum = sum_array a (st i) /\
0 <= st i /\ st i <= st N) as I.
(* Initialization *)
eapply hoare_seq. apply hoare_asgn.
eapply hoare_seq. apply hoare_asgn.
(* Loop *)
eapply hoare_consequence_post.
- apply hoare_while.
(* Loop body *)
eapply hoare_seq. apply hoare_asgn.
eapply hoare_consequence_pre.
+ apply hoare_asgn.
+ intros st [HI Hcond]. subst I. simpl.
destruct HI as [Hsum [Hi1 Hi2]].
split; [|split]; try lia.
rewrite Hsum. unfold sum_array. lia.
- (* Postcondition *)
intros st [HI Hcond]. subst I.
destruct HI as [Hsum [Hi1 Hi2]].
assert (st i = n) by lia.
rewrite H. exact Hsum.
Qed.Program:
if x >= y then
max := x
else
max := ySpecification:
truemax = max(x, y)Analysis:
Verification Conditions:
Then branch: {x ≥ y} max := x {max = max(x, y)}
x = max(x, y)Else branch: {x < y} max := y {max = max(x, y)}
y = max(x, y)Isabelle Proof:
lemma max_correct:
"⦃λs. True⦄
If (λs. s ''x'' ≥ s ''y'')
Then max := (λs. s ''x'')
Else max := (λs. s ''y'')
⦃λs. s ''max'' = max (s ''x'') (s ''y'')⦄"
proof (rule hoare_if)
show "⦃λs. s ''x'' ≥ s ''y''⦄
max := (λs. s ''x'')
⦃λs. s ''max'' = max (s ''x'') (s ''y'')⦄"
by (rule hoare_conseq[OF hoare_asgn]) simp
next
show "⦃λs. ¬(s ''x'' ≥ s ''y'')⦄
max := (λs. s ''y'')
⦃λs. s ''max'' = max (s ''x'') (s ''y'')⦄"
by (rule hoare_conseq[OF hoare_asgn]) simp
qedCoq Proof:
Example max_correct :
{{ fun st => True }}
if x >= y then
max ::= x
else
max ::= y
{{ fun st => st max = max (st x) (st y) }}.
Proof.
apply hoare_if.
- eapply hoare_consequence_pre.
+ apply hoare_asgn.
+ intros st H. simpl. lia.
- eapply hoare_consequence_pre.
+ apply hoare_asgn.
+ intros st H. simpl. lia.
Qed.Program: x := E1; y := E2; z := E3
Strategy: Work backwards with weakest precondition
Program: result := init; while i < n do result := f(result, a[i]); i := i + 1
Invariant: result = fold(f, init, a[0..i-1]) ∧ 0 ≤ i ≤ n
Program: found := false; while i < n && !found do if a[i] == target then found := true else i := i + 1
Invariant: (∀j. 0 ≤ j < i ⟹ a[j] ≠ target) ∧ 0 ≤ i ≤ n
Program: Outer loop with inner loop
Invariants: Outer invariant + inner invariant (may depend on outer variables)
Definition: If precondition holds and program terminates, postcondition holds
Hoare triple: {P} C {Q}
What to prove:
Definition: If precondition holds, program terminates AND postcondition holds
Hoare triple: [P] C [Q] (square brackets)
What to prove:
Variant requirements:
Detailed guides for program verification:
Load these references when:
© ArabelaTso, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (references) in skills/program-correctness-prover of ArabelaTso/Skills-4-SE.
Open the folder on GitHubat commit 4f38503
Program Correctness Prover next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Program Correctness Prover this skillArabelaTso/Skills-4-SE | 253 | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | |
| Audit Correctness Proofben-manes/caffeine | 18k | — | ~275 | Automated safety check: Pass | Apache-2.0 | |
| Correctcursor/plugins | 10k | 3 repos | ~612 | Automated safety check: Pass | None | |
| CorrectionNxcoreAI/EverRoom | 3k | — | ~290 | Automated safety check: Pass | Custom licence | |
| Implementing Zero Knowledge Proof For Authenticationmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~858 | Automated safety check: Pass | Apache-2.0 | |
| Rigorous Math Prooftradecatlabs/vibe-coding-cn | 17k | — | ~571 | Automated safety check: Pass | MIT |
ben-manes/caffeine
Attempt formal correctness proofs for all public cache methods
cursor/plugins
Find the mistakes agents keep repeating in this repo and make each one impossible.
NxcoreAI/EverRoom
Compute Room overview corrections—citation corrections as per-claim edits and general corrections as a single proposal.
mukul975/Anthropic-Cybersecurity-Skills
Implements the Schnorr identification protocol and a simplified Zero-Knowledge Password Proof (ZKPP) over the discrete logarithm problem, letting a prover authenticate by demonstrating knowledge of…
tradecatlabs/vibe-coding-cn
Writes and audits natural-language math proofs as checkable packages, with explicit assumptions, proof obligations and counterexample hunting, refuting or repairing weak claims.
wanshuiyin/Auto-claude-code-research-in-sleep
Rigorous mathematical proof verification and fixing workflow.
ArabelaTso/Skills-4-SE
Generate prioritized CVE watchlists and actionable security recommendations for repositories.
ArabelaTso/Skills-4-SE
Automatically migrate Python web applications between frameworks (Flask → FastAPI, Django → FastAPI).
ArabelaTso/Skills-4-SE
Generate test cases using metamorphic testing by applying transformations based on metamorphic properties.
ArabelaTso/Skills-4-SE
Instruments programs to capture execution traces specifically for reproducing reported bugs, enabling consistent replay and diagnosis of failures.
ArabelaTso/Skills-4-SE
Automatically migrate Spring MVC applications to Spring Boot.
ArabelaTso/Skills-4-SE
Instrument programs (Python, C/C++, Java) to capture snapshots of key program states at runtime, including variables, memory, and call stacks.
Generate Isabelle or Coq proofs establishing partial or total correctness of imperative programs from code and formal specifications. Program Correctness Prover is an agent skill from ArabelaTso/Skills-4-SE. Generate Isabelle or Coq proofs establishing partial or total correctness of imperative programs from code and formal specifications.
Program Correctness Prover fits situations like: prove program correctness using Hoare logic; generate verification conditions from pre/postconditions; construct loop invariants and termination arguments; verify imperative programs with assignments.
Run `npx skills add ArabelaTso/Skills-4-SE --skill program-correctness-prover -a claude-code`. Or copy the skill folder (skills/program-correctness-prover in ArabelaTso/Skills-4-SE) into .claude/skills/program-correctness-prover in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ArabelaTso/Skills-4-SE --skill program-correctness-prover -a codex`. Or copy the skill folder (skills/program-correctness-prover in ArabelaTso/Skills-4-SE) into .agents/skills/program-correctness-prover in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ArabelaTso/Skills-4-SE --skill program-correctness-prover -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/program-correctness-prover, .gemini/skills/program-correctness-prover, .github/skills/program-correctness-prover and .opencode/skills/program-correctness-prover in your project.
SKILL.md names no scripts, command-line tools or credentials: Program Correctness Prover is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Program Correctness Prover is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.5k tokens (SKILL.md is roughly 9.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.3k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Program Correctness Prover: Audit Correctness Proof (ben-manes/caffeine, 18k stars), Correct (cursor/plugins, 10k stars), Correction (NxcoreAI/EverRoom, 3k stars) and Implementing Zero Knowledge Proof For Authentication (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ArabelaTso (a GitHub user) maintains it in ArabelaTso/Skills-4-SE, which has 253 GitHub stars. The repository holds 151 skills in this directory. The repository was last updated on August 21, 2026.
Source: ArabelaTso/Skills-4-SE on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.