Agent skill

Validate

by boshu2 in boshu2/agentops

Freshly judge whether a finished change and its claims meet original acceptance: PASS, FAIL or NOTPROVEN.

Apache-2.0Auto-check passedProduct & Project Management

Install Validate

skills CLI
$ npx skills add boshu2/agentops --skill validate -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install boshu2/agentops validate --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/boshu2/agentops.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/validate .claude/skills/validate && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
validate
GitHub stars
447
Used in
1 other repo
Token cost
~2.7k tokens
SKILL.md length
1,373 words
Files
9 (incl. scripts, references)
Skills in repo
31
Repo updated
First seen
Licence
Apache-2.0

At a glance

Freshly judge whether a finished change and its claims meet original acceptance: PASS, FAIL or NOTPROVEN.

  • Works in 4 steps: The subject changed during judgment,… → A criterion is proven failed, or a… → Any in-scope criterion lacks evidence:… → …
  • : asked for a go/no-go
  • SKILL.md covers Rules that decide the verdict, Establish intent first, When a fresh judgment is worth… and Subject, plus 4 more sections
  • Runs Python and Shell scripts from its folder; calls git

What it does

Validate is an agent skill from boshu2/agentops. Freshly judge whether a finished change and its claims meet original acceptance: PASS, FAIL or NOTPROVEN. Use when: asked for a go/no-go, sign-off or independent verdict.

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 11 other files, including scripts and reference files (for example `references/mechanics.md`, `scripts/validate.sh` and `tests/check_contract_corpus.py`).

It sits in Product & Project Management, covering Feature launches and release readiness. The repository describes itself as: DevOps discipline for AI coding agents: shape the work, track it as a graph, and get each change judged by a context that didn't write it. The licence is Apache-2.0.

When your agent uses it

  • : asked for a go/no-go
  • Independent verdict

Example prompts

  • “/validate”

Requirements

  • Python 3
  • A Bash shell

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. The subject changed during judgment, changed-path coverage is incomplete,
  2. A criterion is proven failed, or a change is proven out of scope: FAIL, even
  3. Any in-scope criterion lacks evidence: NOT_PROVEN.
  4. Every criterion is verified with evidence, checked scope is nonempty and

What it can do on your machine

Read from SKILL.md and the folder at commit 3bdbfed. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python and Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Validate loads about 2.7k tokens when it runs, and up to ~6.4k if it reads all its reference files. Until then it costs about 45 tokens; SKILL.md has 1,373 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~45
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from boshu2/agentops at commit 3bdbfed, republished under its Apache-2.0 licence (© boshu2). 1,373 words, ~2,745 tokens.

Download SKILL.mdSave it as .claude/skills/validate/SKILL.md (or your agent's skills folder). This skill also uses 8 other files; get the full folder from GitHub.
name
validate
description
Freshly judge whether a finished change and its claims meet original acceptance: PASS, FAIL or NOT_PROVEN. Use when: asked for a go/no-go, sign-off or independent verdict.
practices
design-by-contract, llm-eval-harness, content-addressed-storage
hexagonal_role
driving-adapter
consumes
subject-manifest.v1
produces
subject-manifest.v1, validation-result, verdict.v2
skill_api_version
1
user-invocable
true
metadata.graph_root
true
metadata.tier
judgment
metadata.capabilities
compute_subject_identity, judge_acceptance, return_validation_result, persist_verdict
metadata.effects
write_verdict_artifact

Validate

Freshly judge one finished candidate against its original acceptance, return PASS, FAIL, or NOT_PROVEN with criterion-level evidence, and stop. Neighbours: advice or a second look is Review; whether a stated claim holds is Reality Check. This file carries every rule the judgment needs. Linked files, including RPI boundaries and mechanics, add depth only: if one cannot be read, judge from this file and say which was unavailable.

Rules that decide the verdict

  • The author cannot issue a binding PASS, and advisory findings cannot stand in for this judgment. An author's summary, confidence or assurance is a claim to check, not evidence; explanation alone is not proof.
  • Each criterion needs its own evidence on the exact candidate. A criterion nobody demonstrated goes in not_checked and never counts toward PASS.
  • A changed test, tolerance, golden, suppression or acceptance text must still satisfy the original intent. Green obtained by weakening the oracle is FAIL for the criterion it was meant to prove, and that green is not evidence.
  • Read receipts; do not re-run checks the author ran on this exact subject or that CI will run. Re-execute only a risk-critical claim that has no receipt.
  • A necessary finding never becomes an optional caveat or non-goal.

Decide in this order:

  1. The subject changed during judgment, changed-path coverage is incomplete, or author and validator identity or freshness is missing, colliding or unattested: NOT_PROVEN.
  2. A criterion is proven failed, or a change is proven out of scope: FAIL, even when other criteria are unverified.
  3. Any in-scope criterion lacks evidence: NOT_PROVEN.
  4. Every criterion is verified with evidence, checked scope is nonempty and not_checked is empty: PASS.

Establish intent first

An explicit request for Validate, an acceptance verdict or independent proof that original acceptance is met selects this skill, even when phrased as "review this". Generic checking or readiness questions, even with criteria supplied, do not: ask once whether the caller wants advice or an acceptance judgment, and wait. Issue no verdict or readiness approval meanwhile; missing intent is not a NOT_PROVEN verdict. Shared routing: advice or acceptance.

When a fresh judgment is worth it

Spend validation where a mistake is costly. For an ordinary change the author's checks and CI are the gate, and no fresh judgment is owed. Use Validate when:

  • the caller asks for an acceptance verdict or independent proof;
  • a mistake cannot be cheaply undone after it lands: a published release or instructions users will follow, a security boundary, destroying data or tracker state, deleting a check that protects the product; or
  • no deterministic check covers the behavior that changed.

Judge once. Report NOT_PROVEN with its gaps and stop; do not request or wait for another round. After the author repairs findings, the affected checks confirm the repair; a second judgment happens only when the caller asks for one. Keep the judgment's cost a fraction of the cost of the work: when it approaches that cost, stop and return what is unchecked.

Subject

The subject is a nonempty implementation candidate, held unchanged after required checks and known repairs; plans, audits and reviews are subjects only when the caller requested document review. Supplied failed-acceptance evidence means FAIL on that subject; do not review a moving repair. Bind its identity at the start and again at the end of judgment:

  • With AgentOps installed: ao provenance manifest --root "$REPO_ROOT" --include "$CHANGED_PATH", one --include per changed path.
  • In any Git repository: the commit SHA (git rev-parse HEAD) and the changed paths (git diff --name-only <base>...HEAD); for uncommitted work, the git status --porcelain listing and a shasum -a 256 of each changed file.
  • A subject supplied only in the conversation, such as a pasted diff or a described change, is exactly what was supplied; anything it does not show is unverified.

A requested retrospective follows the code judgment and is not evidence for it. When intent bundles both, judge the code criteria separately and keep the overall request incomplete until the retrospective exists; issue no overall PASS early. An explicitly requested review of the retrospective judges that document on its own scope.

Identity and freshness

Author and validator identities must be explicit and distinct, and freshness must be attested by the runtime or the caller, naming the attester. An attestation is a declared trust fact, not cryptographic isolation. In ordinary use these count:

  • Author: the identity the caller gives for whoever produced the candidate: a person, a session or agent ID, or the commit author.
  • Validator: this context's runtime ID when the runtime exposes one, such as a subagent or session ID; otherwise the handle the dispatcher holds for it, such as the agent ID returned at launch, or "this conversation" when the caller opened it for the judgment.
  • Freshness: a statement from the runtime, the dispatcher or the caller, naming who makes it, that this context did not produce the candidate and was given intent, subject and evidence rather than the author's working history. When the caller opened this conversation for the judgment and supplied the candidate, the caller is the attester.

A role name, a persona switch inside the author's conversation, or the validator vouching for itself does not count. Never invent an identity. An identity gap makes the result NOT_PROVEN; keep every finding in the report.

Show full SKILL.md (498 more words)Show less

Reviewers

Default to one fresh reviewer in the author's model family: Codex/OpenAI for Codex/OpenAI, Claude/Anthropic for Claude/Anthropic, on the runtime's configured capable model unless pinned. Supply task-specific intent, scope, exact subject and relevant evidence, without full author history, desired verdict or peer conclusions. Concise input must not omit necessary evidence; retrieve more source when a criterion requires it.

Cross-model review is opt-in: --cross-model [model] is a skill prompt selection, not an AO flag, adding a fresh other-family reviewer through model-dispatch. A required leg that cannot run yields diversity_unsatisfied and NOT_PROVEN for the combined request, even if another leg passed; optional diversity that is unavailable is disclosed without erasing findings. Delivered FAILs and dissent stand; neither voting nor model preference makes a split PASS, and agreement is not proof of truth. No fixed ten-minute cap applies; respect real caller/native bounds without renewing them. A timeout is missing judgment, not FAIL.

Judgment

  1. Bind the subject. Verify continuity with the exact caller-owned intent, cited evidence and complete changed-path coverage; missing integrity is NOT_PROVEN.
  2. Revisit the original accepted behavior examples, including those in the conversation or bead, and check each observable result and its domain meaning on the exact candidate. A new test or renamed concept cannot replace an unfulfilled scenario. Inspect the actual diff against every criterion; publication or provenance claims in docs need verifiable evidence too. Risk sets depth: acceptance, permissions, tests and gates, stopping, disclosure, hooks and executable controls warrant deeper reading, including prose policy. Unknown risk merits examination, not extra reviewers.
  3. Classify commands before running any. Regeneration, synchronization, formatting and --force mutate the subject until proven otherwise; run them only on a disposable copy or a committed subject, never the judged tree.
  4. Bind the subject again; a mismatch is NOT_PROVEN.
  5. Return one result in the shape below, promptly, and stop.

Report

text
Verdict: PASS | FAIL | NOT_PROVEN
Subject: <manifest digest, or commit SHA and changed paths>; unchanged start to end: yes | no
Criteria:
  1. <criterion> - verified | failed | not verified - <evidence: file:line, receipt, observed output>
Findings: <class> - <what and where> - <consequence>   (or "none")
Notes (optional, do not change the verdict): <...>
Checked: <what was inspected, and how>
Not checked: <in-scope acceptance not verified>   (empty only for PASS)
Identity: author <id>; validator <id>; freshness attested by <runtime | caller>: <attester>

A finding fails an acceptance criterion or would mislead a user, break install or the CLI, or remove protection for the product; anything else is an optional note the author may ignore. Give each new finding a short stable class, reused on recurrence, and say whether it is pre-existing, introduced or unknown from before/after evidence; counts and timestamps alone do not establish cause. Keep prior findings visible. not_checked holds in-scope acceptance that was not verified; other limits stay in criterion reasoning, declared non-goals or residual-risk prose, never hidden to obtain PASS. Delivery inside acceptance stays unverified until its evidence exists; never remove that criterion to reach PASS. Mechanics covers report proportion and where each scope limit lives.

Validate is the sole semantic author of verdict.v2. Only when the caller requests machine-readable evidence or a declared consumer requires it, persist through ao provenance store-verdict (mechanics); Go verifies structure and storage, not truth. Otherwise return the result through the caller's existing channel, without hidden machine artifacts. Validate owns no repair, retry, delivery or tracker transition: known findings go back to the author for direct repair, and a causal stall uses the RPI single-helper rule.

© boshu2, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 8 other files (scripts, references) in skills/validate of boshu2/agentops.

  • SKILL.md
  • references/mechanics.md
  • references/validate.feature
  • scripts/validate.sh
  • tests/check_contract_corpus.py
  • tests/test_evidence_cli.py
  • tests/test_validate.py
  • tests/validate.py
  • tests/validate.sh

Open the folder on GitHubat commit 3bdbfed

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in boshu2/agentops, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Validate next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Validate compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Validate this skillboshu2/agentops4471 repos~2.7kAutomated safety check: PassApache-2.0
.NET MAUI Release Readinessdotnet/maui23k—~15kAutomated safety check: PassMIT
Release ValidationMesh-LLM/mesh-llm3.5k—~2.6kAutomated safety check: PassApache-2.0
Final Release Reviewopenai/openai-agents-python30k—~5.4kAutomated safety check: PassMIT
Final Release Reviewopenai/openai-agents-js3.9k—~4kAutomated safety check: PassMIT
Acceptance Demo GeneratorChachamaru127/claude-code-harness3.2k—~3.4kAutomated safety check: NotesMIT

Similar skills

  • Official

    Produces evidence-backed ship-readiness verdicts for .NET MAUI Servicing Releases and Previews, and drafts public-safe release handoff pages from the result.

    23k GitHub stars~15k tokensUpdated today
    Product & Project ManagementAuto-check passed
  • Release Validation

    Mesh-LLM/mesh-llm

    A skill your agent uses when validating a MeshLLM release candidate or current HEAD against the last GitHub release, assembling the canonical feature/fix/modification inventory, testing locally…

    3.5k GitHub stars~2.6k tokensUpdated today
    Product & Project ManagementAuto-check passed
  • Final Release Review

    openai/openai-agents-python

    Official

    Assess a Python SDK release candidate or release plan against the previous release and recommend ship or block.

    30k GitHub stars~5.4k tokensUpdated today
    Product & Project ManagementAuto-check passed
  • Final Release Review

    openai/openai-agents-js

    Official

    Assess a JS SDK release candidate or release plan against the previous release and recommend ship or block.

    3.9k GitHub stars~4k tokensUpdated today
    Product & Project ManagementAuto-check passed
  • Acceptance Demo Generator

    Chachamaru127/claude-code-harness

    Renders a single HTML page showing each acceptance criterion as verified or not, with a ship, wait, or reject recommendation for non-engineers.

    3.2k GitHub stars~3.4k tokensUpdated 3 days ago
    Product & Project ManagementAuto-check: notes
  • Schematic

    blader/schematic

    Reverse engineer a detailed product and technical specification document from a git branch's implementation.

    240 GitHub stars~2.2k tokensUpdated 7 mo ago
    Product & Project ManagementAuto-check passed

More from boshu2/agentops

All 31 skills in this repo
  • Agent Native

    boshu2/agentops

    Dispatch independent tasks to parallel workers or subagents without write collisions.

    447 GitHub starsUsed in 1 repo~1.9k tokens
    Auto-check passed
  • Council

    boshu2/agentops

    Compare independent opinions from several models or contexts without inflating agreement.

    447 GitHub starsUsed in 1 repo~3k tokens
    Auto-check passed
  • Craft Goal

    boshu2/agentops

    Draft or lint a bounded long-running goal prompt with a finish line and hard limits.

    447 GitHub starsUsed in 1 repo~2.7k tokens
    Auto-check passed
  • Doc

    boshu2/agentops

    Write or update READMEs, docs, repo instructions and handoff notes, checked against source.

    447 GitHub starsUsed in 1 repo~1.9k tokens
    Auto-check passed
  • Idea Genie

    boshu2/agentops

    Brainstorm evidence-backed options for what to build, or stress-test an idea.

    447 GitHub starsUsed in 1 repo~1.8k tokens
    Auto-check passed
  • Implement

    boshu2/agentops

    Change or repair code, config or services without weakening tests; report what ran and what did not.

    447 GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed

Questions about Validate

What does Validate do?

Freshly judge whether a finished change and its claims meet original acceptance: PASS, FAIL or NOTPROVEN. Validate is an agent skill from boshu2/agentops. Freshly judge whether a finished change and its claims meet original acceptance: PASS, FAIL or NOTPROVEN.

When should I use Validate?

Validate fits situations like: : asked for a go/no-go; independent verdict.

How do I install Validate in Claude Code?

Run `npx skills add boshu2/agentops --skill validate -a claude-code`. Or copy the skill folder (skills/validate in boshu2/agentops) into .claude/skills/validate in your project. Claude Code loads it when a task matches its description.

How do I install Validate in Codex?

Run `npx skills add boshu2/agentops --skill validate -a codex`. Or copy the skill folder (skills/validate in boshu2/agentops) into .agents/skills/validate in your project. Codex loads it when a task matches its description.

Can I use Validate in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add boshu2/agentops --skill validate -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/validate, .gemini/skills/validate, .github/skills/validate and .opencode/skills/validate in your project.

What does Validate need to run?

Going by SKILL.md and its folder, Validate needs Python and a shell for the scripts in its folder and the command-line tools its instructions call (git). Our summary lists: Python 3; A Bash shell.

Does Validate access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Validate safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Validate use?

Validate is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Validate use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.6k tokens, read only when the agent opens those files.

What are the alternatives to Validate?

Skills that share tags, products or a category with Validate: .NET MAUI Release Readiness (dotnet/maui, 23k stars), Release Validation (Mesh-LLM/mesh-llm, 3.5k stars), Final Release Review (openai/openai-agents-python, 30k stars) and Final Release Review (openai/openai-agents-js, 3.9k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Validate?

boshu2 (a GitHub user) maintains it in boshu2/agentops, which has 447 GitHub stars. The repository holds 31 skills in this directory. The repository was last updated on October 7, 2026.

Source: boshu2/agentops on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.