Agent skill

Validate

by boshu2 in boshu2/agentops

Freshly judge exact subject content against bead or caller acceptance, optionally persist verdict.v2 for a declared consumer, and stop.

Apache-2.0Auto-check passed

Install Validate

skills CLI
$ npx skills add boshu2/agentops --skill validate -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install boshu2/agentops validate --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/boshu2/agentops.git skills-src && mkdir -p .claude/skills && cp -r skills-src/packs/agentops-executor/agents/validator/skills/validate .claude/skills/validate && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
validate
GitHub stars
447
Token cost
~1.8k tokens
SKILL.md length
750 words
Files
6 (incl. scripts, references)
Skills in repo
31
Repo updated
First seen
Licence
Apache-2.0

At a glance

Freshly judge exact subject content against bead or caller acceptance, optionally persist verdict.v2 for a declared consumer, and stop.

  • Works in 7 steps: Recompute and compare… → Confirm the intent-source digest has not… → Adjudicate the actual diff, not a… → …
  • SKILL.md covers Preconditions, Cross-model fresh validator…, Mutating-check quarantine and Workflow, plus 2 more sections
  • Runs Python and Shell scripts from its folder; calls python3

What it does

Validate is an agent skill from boshu2/agentops. Freshly judge exact subject content against bead or caller acceptance, optionally persist verdict.v2 for a declared consumer, and stop. Triggers: "validate", "independently validate", "vibe".

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts and reference files (for example `scripts/check_contract_corpus.py`, `scripts/test_validate.py` and `scripts/validate.py`).

The repository describes itself as: DevOps discipline for AI coding agents: shape the work, track it as a graph, and get each change judged by a context that didn't write it. The licence is Apache-2.0.

Example prompts

  • “validate”
  • “independently validate”
  • “/validate”

Requirements

  • Python 3
  • A Bash shell

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Recompute and compare subject-manifest.v1 using
  2. Confirm the intent-source digest has not changed since implementation. If
  3. Adjudicate the actual diff, not a declared path list: compare
  4. Inspect the exact subject and factual evidence. Reported exit codes are
  5. Choose exactly one semantic result: PASS, FAIL, or NOT_PROVEN. Return
  6. Only when the caller requests machine-readable evidence or a declared
  7. Return the semantic result and, when persisted, the artifact path and digest.

What it can do on your machine

Read from SKILL.md and the folder at commit 3bdbfed. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 4 files in scripts/ (Python and Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Validate loads about 1.8k tokens when it runs, and up to ~2.3k if it reads all its reference files. Until then it costs about 50 tokens; SKILL.md has 750 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~50
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from boshu2/agentops at commit 3bdbfed, republished under its Apache-2.0 licence (© boshu2). 750 words, ~1,754 tokens.

Download SKILL.mdSave it as .claude/skills/validate/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
validate
description
Freshly judge exact subject content against bead or caller acceptance, optionally persist verdict.v2 for a declared consumer, and stop. Triggers: "validate", "independently validate", "vibe".
practices
design-by-contract, llm-eval-harness, content-addressed-storage
hexagonal_role
driving-adapter
consumes
subject-manifest.v1
produces
subject-manifest.v1, validation-result, verdict.v2
skill_api_version
1
user-invocable
true
metadata.graph_root
true
metadata.tier
judgment
metadata.capabilities
compute_subject_identity, judge_acceptance, return_validation_result, persist_verdict
metadata.effects
write_verdict_artifact

Validate

Independently judge one exact subject against the acceptance in its existing bead or caller source, return one semantic result, and stop. Validate is the sole verdict.v2 writer when persistence is requested. It never asks the model to reconstruct Plan or Candidate packets.

Preconditions

  • The subject is a nonempty implementation candidate: the manifest lists at least one entry, and store-verdict refuses an empty one. Plans, audits, reviews, and other control artifacts are not completion subjects unless the caller explicitly requested document review.
  • The intent source is available as a caller-owned artifact or runtime-owned content-addressed snapshot; its acceptance digest is derived automatically.
  • The subject manifest still matches the subject.
  • Author and validator context IDs are explicit.
  • Freshness is explicitly attested with source: runtime | caller and an attester identity.

Missing, colliding, or unattested identities produce NOT_PROVEN. This is a declared trust fact, not cryptographic proof that contexts were isolated.

Cross-model fresh validator (caller-elected)

A caller may request that the fresh validator run on a different model than the author. Dispatch via the controller-session recipe in the agent-native model-dispatch recipe (codex-exec and/or NTM panes, probed at runtime). Record author and validator model_identity in evidence refs and freshness attestation notes — do not change verdict.v2 schema. If the requested validator model has no live adapter, disclose the unsatisfied diversity request and proceed same-model. Single fresh validator remains the default shape.

Mutating-check quarantine

Before running any acceptance-listed command, classify it as read-only or subject-mutating. Regen scripts, sync scripts, formatters, and anything with --force are subject-mutating until proven otherwise. Never run a subject-mutating check against an uncommitted subject: on 2026-07-15, scripts/test-ci-deterministic-gates.sh regenerated skills-codex/ from HEAD mid-validation and destroyed the uncommitted subject, forcing NOT_PROVEN (verdict b6e759dd...cb6a); only restoring the subject and revalidating in a fresh context produced the PASS (e9b6cdb8...37b9). If a mutating check is genuinely required by acceptance, run it against a disposable copy or a committed subject, never the judged working tree.

Workflow

  1. Recompute and compare subject-manifest.v1 using python3 skills/validate/scripts/validate.py manifest. The helper uses only filesystem content; Git commit/tree IDs are optional metadata. Derive the manifest at the start of validation and re-derive it at the end; any mismatch between the two is subject mutation and returns NOT_PROVEN.
  2. Confirm the intent-source digest has not changed since implementation. If the subject changed or complete changed-path coverage cannot be derived, return NOT_PROVEN.
  3. Adjudicate the actual diff, not a declared path list: compare runtime-derived actual changed paths against the intent's scope classes. A proven out-of-scope path returns FAIL; incomplete scope evidence returns NOT_PROVEN.
  4. Inspect the exact subject and factual evidence. Reported exit codes are claims, not evidence: re-execute the claimed proofs that bear on acceptance (see the freshness rules below for when a digest-bound receipt suffices). Judge every acceptance criterion and record criterion-level results, findings, evidence references, checked, and not_checked.
  5. Choose exactly one semantic result: PASS, FAIL, or NOT_PROVEN. Return it with criterion results, findings, evidence references, checked, not_checked, the acceptance and subject identities, distinct author and validator context IDs, and the freshness attestation. PASS requires distinct identities, explicit freshness, nonempty checked scope, top-level evidence, and evidence for every criterion.
  6. Only when the caller requests machine-readable evidence or a declared downstream consumer requires it, persist canonical verdict.v2 with store-verdict --draft <draft.json> --intent-source <resolved-intent> --subject-manifest <manifest.json> --author-context-id <id> --validator-context-id <id> --freshness-source <runtime|caller> --freshness-attester-id <id> --scope-result <PASS|FAIL|NOT_PROVEN>. The helper snapshots the exact resolved intent under <workspace>/.agents/ao/intents/sha256/<digest>.intent, then computes and injects intent and subject digests plus author, validator, and freshness facts. Identity and changed-path facts come from runtime-derived inputs and receipts, not model transcription. Storage defaults to <workspace>/.agents/ao/verdicts/sha256/<digest>.json; callers may provide verdict_dir.
  7. Return the semantic result and, when persisted, the artifact path and digest. Stop.
Show full SKILL.md (140 more words)Show less

The digest is SHA-256 over canonical JSON with artifact_digest omitted. Writes use a same-directory temporary file, flush, fsync, and atomic rename. Identical existing content is idempotent success; conflicting content is an integrity failure represented by NOT_PROVEN.

Freshness without duplication

Fresh validation means independent judgment over the exact subject. It does not require mechanically replaying every author command. Verify intent identity, scope, evidence digests, and every acceptance criterion; independently rerun the risk-critical, uncertain, or insufficiently evidenced checks. A digest-bound deterministic receipt may prove routine facts. Replay an expensive full suite only when acceptance requires that result or the supplied receipt cannot establish it.

Boundary

Validate emits no WARN, confidence, disposition, briefing learning, owner, next action, repair, retry, replan, helper, escalation, tracker, Git, release, closure, or delivery state. Generic provenance may record a verdict later, but ledger availability cannot change its validity.

© boshu2, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (scripts, references) in packs/agentops-executor/agents/validator/skills/validate of boshu2/agentops.

  • SKILL.md
  • references/validate.feature
  • scripts/check_contract_corpus.py
  • scripts/test_validate.py
  • scripts/validate.py
  • scripts/validate.sh

Open the folder on GitHubat commit 3bdbfed

Compare with similar skills

Validate next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Validate compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Validate this skillboshu2/agentops447—~1.8kAutomated safety check: PassApache-2.0
Content Freshness Signalsthedaviddias/Front-End-Checklist74k—~741Automated safety check: PassMIT
JudgeNeoLabHQ/context-engineering-kit1.7k—~2kAutomated safety check: PassGPL-3.0
Beads Task Memorygastownhall/beads28k—~1.2kAutomated safety check: PassMIT
Beads Documentation Style Guidegastownhall/beads28k—~3.2kAutomated safety check: PassMIT
Do And JudgeNeoLabHQ/context-engineering-kit1.7k—~14kAutomated safety check: PassGPL-3.0

Similar skills

  • Content Freshness Signals

    thedaviddias/Front-End-Checklist

    Audits article pages for freshness signals, covering the Last-Modified header, Article JSON-LD dateModified and a visible last-updated date, and fixes mismatches.

    74k GitHub stars~741 tokensUpdated yesterday
    Marketing & SEOAuto-check passed
  • Judge

    NeoLabHQ/context-engineering-kit

    Launch a meta-judge then a judge sub-agent to evaluate results produced in the current conversation

    1.7k GitHub stars~2k tokensUpdated 1 mo ago
    Agent WorkflowsAuto-check passed
  • Beads Task Memory

    gastownhall/beads

    Tracks multi-session work with dependencies in the bd issue tracker so the agent can find ready tasks and recover its context after conversation compaction.

    28k GitHub stars~1.2k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Sets the house style for the beads user docs: the canonical concept model, required terminology, prose and diagram conventions, and checks before docs work is done.

    28k GitHub stars~3.2k tokensUpdated today
    Writing & ContentAuto-check passed
  • Do And Judge

    NeoLabHQ/context-engineering-kit

    Execute a task with sub-agent implementation and LLM-as-a-judge verification with automatic retry loop

    1.7k GitHub stars~14k tokensUpdated 1 mo ago
    Agent WorkflowsAuto-check passed
  • Implementing Gdpr Data Subject Access Request

    mukul975/Anthropic-Cybersecurity-Skills

    Automates GDPR Data Subject Access Request (DSAR) workflows including identity verification, PII discovery across databases and files using regex and NER, data mapping, response templating per…

    34k GitHub stars~2.5k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed

More from boshu2/agentops

All 31 skills in this repo
  • Agent Native

    boshu2/agentops

    Dispatch independent tasks to parallel workers or subagents without write collisions.

    447 GitHub starsUsed in 1 repo~1.9k tokens
    Auto-check passed
  • Council

    boshu2/agentops

    Compare independent opinions from several models or contexts without inflating agreement.

    447 GitHub starsUsed in 1 repo~3k tokens
    Auto-check passed
  • Craft Goal

    boshu2/agentops

    Draft or lint a bounded long-running goal prompt with a finish line and hard limits.

    447 GitHub starsUsed in 1 repo~2.7k tokens
    Auto-check passed
  • Doc

    boshu2/agentops

    Write or update READMEs, docs, repo instructions and handoff notes, checked against source.

    447 GitHub starsUsed in 1 repo~1.9k tokens
    Auto-check passed
  • Idea Genie

    boshu2/agentops

    Brainstorm evidence-backed options for what to build, or stress-test an idea.

    447 GitHub starsUsed in 1 repo~1.8k tokens
    Auto-check passed
  • Implement

    boshu2/agentops

    Change or repair code, config or services without weakening tests; report what ran and what did not.

    447 GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed

Questions about Validate

What does Validate do?

Freshly judge exact subject content against bead or caller acceptance, optionally persist verdict.v2 for a declared consumer, and stop. Validate is an agent skill from boshu2/agentops.v2 for a declared consumer, and stop.

How do I install Validate in Claude Code?

Run `npx skills add boshu2/agentops --skill validate -a claude-code`. Or copy the skill folder (packs/agentops-executor/agents/validator/skills/validate in boshu2/agentops) into .claude/skills/validate in your project. Claude Code loads it when a task matches its description.

How do I install Validate in Codex?

Run `npx skills add boshu2/agentops --skill validate -a codex`. Or copy the skill folder (packs/agentops-executor/agents/validator/skills/validate in boshu2/agentops) into .agents/skills/validate in your project. Codex loads it when a task matches its description.

Can I use Validate in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add boshu2/agentops --skill validate -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/validate, .gemini/skills/validate, .github/skills/validate and .opencode/skills/validate in your project.

What does Validate need to run?

Going by SKILL.md and its folder, Validate needs Python and a shell for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3; A Bash shell.

Does Validate access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Validate safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Validate use?

Validate is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Validate use?

About 1.8k tokens (SKILL.md is roughly 7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 499 tokens, read only when the agent opens those files.

What are the alternatives to Validate?

Skills that share tags, products or a category with Validate: Content Freshness Signals (thedaviddias/Front-End-Checklist, 74k stars), Judge (NeoLabHQ/context-engineering-kit, 1.7k stars), Beads Task Memory (gastownhall/beads, 28k stars) and Beads Documentation Style Guide (gastownhall/beads, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Validate?

boshu2 (a GitHub user) maintains it in boshu2/agentops, which has 447 GitHub stars. The repository holds 31 skills in this directory. The repository was last updated on October 7, 2026.

Source: boshu2/agentops on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.