Agent skill

Verify

by cwinvestments in cwinvestments/memstack

Runs this project's check chain through scripts/verify.py and reads the receipt it writes.

MITAuto-check passedDocuments & Office

Install Verify

skills CLI
$ npx skills add cwinvestments/memstack --skill verify -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cwinvestments/memstack verify --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cwinvestments/memstack.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/verify .claude/skills/verify && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
verify
GitHub stars
423
Token cost
~2.2k tokens
SKILL.md length
1,312 words
Files
1
Skills in repo
87
Repo updated
First seen
Licence
MIT

At a glance

Runs this project's check chain through scripts/verify.py and reads the receipt it writes.

  • Works in 3 steps: Run the chain → Read the receipt → Act on the verdict
  • Asks whether work passes
  • SKILL.md covers Activation, Context Guard, What the CLI actually detects and Protocol, plus 6 more sections
  • Calls python, npm and ruff

What it does

Verify is an agent skill from cwinvestments/memstack. Runs this project's check chain through scripts/verify.py and reads the receipt it writes. Fires when tracked changes are finished, when the user asks whether work passes, before a commit, and before reporting a task done. Stays dormant in repositories with no detectable check chain, during read-only audits, and for edits that leave no tracked change behind.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Documents & Office, covering Word documents. It works with Ruff, npm and pytest. The repository describes itself as: Structured skill framework for Claude Code. 130 skills, persistent memory, TokenStack compression, localhost dashboard with 3-agent runner, real-time streaming, MCP tools. The licence is MIT.

When your agent uses it

  • Asks whether work passes
  • Before a commit
  • Before reporting a task done

Example prompts

  • “/verify”

Requirements

  • Python 3

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Run the chain
  2. Read the receipt
  3. Act on the verdict

What it can do on your machine

Read from SKILL.md and the folder at commit 00370ce. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python
    • npm
    • ruff
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Verify loads about 2.2k tokens when it runs. Until then it costs about 92 tokens; SKILL.md has 1,312 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~92
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cwinvestments/memstack at commit 00370ce, republished under its MIT licence (© cwinvestments). 1,312 words, ~2,232 tokens.

Download SKILL.mdSave it as .claude/skills/verify/SKILL.md (or your agent's skills folder).
name
verify
description
Runs this project's check chain through scripts/verify.py and reads the receipt it writes. Fires when tracked changes are finished, when the user asks whether work passes, before a commit, and before reporting a task done. Stays dormant in repositories with no detectable check chain, during read-only audits, and for edits that leave no tracked change behind.
version
2.0.0

✅ Verify: Checking Work...

Run the project's checks, write a receipt, read what it says.

Activation

When this skill activates, output:

✅ Verify: running the check chain...

Then follow the protocol below.

Context Guard

ContextStatusPriority
Tracked changes are finished and about to be reported doneACTIVE, run the chainP1
User asks "does it pass", "verify this", "is this ready"ACTIVE, run the chainP1
About to commitACTIVE, a receipt costs less before the commit than afterP1
User is mid-task, still editingDORMANT, a receipt for a half-finished tree ages out the moment the next edit landsn/a
Read-only audit or investigationDORMANT, nothing changed, so there is nothing to verifyn/a
Edits left no tracked change (new untracked files only)DORMANT, the gate does not see untracked files and neither does the chainn/a
Repo where verify list detects nothingDORMANT, but read NOTHING_DETECTED below before concluding thisn/a

What the CLI actually detects

scripts/verify.py detects three families and nothing else. Anything outside this list goes unchecked, so a passing receipt is not a claim that the project is sound:

FamilyDetected whenRuns
npmpackage.json has a scripts entry named test, lint, typecheck or buildnpm run <script>, one check per script, in that order
pytestpytest.ini, or pyproject.toml with a [tool.pytest] section, or a tests/ directorypython -m pytest -q
ruffruff.toml, .ruff.toml, or pyproject.toml with a [tool.ruff] sectionruff check .

A detected check that cannot run becomes a SKIP carrying its reason: npm missing from PATH, node_modules absent, pytest not importable, ruff not installed. A SKIP is not a pass, because nothing ran.

Run python scripts/verify.py list to see the chain without executing it.

Protocol

Step 1: Run the chain
bash
python scripts/verify.py run --task-id <session-id>

Use the session id as the task id. The receipt is named after it, so one session overwrites its own receipt on a re-run instead of littering the directory, and the Stop gate's block message names this exact command with this exact id.

Each check gets 900 seconds before it is recorded as a FAIL with a timeout note.

Step 2: Read the receipt

It lands at .memstack/receipts/<task-id>.json under the repo root. That directory writes a .gitignore holding * the first time it is created, so the evidence never asks to be committed and never appears in git status.

The receipt is evidence, not paperwork. Read these fields before saying anything about the outcome:

  • verdict: PASS, FAIL or NOTHING_DETECTED for the chain as a whole.
  • checks: one record per check, each with its status, exit code, duration, and the last 2000 characters of combined output. The failing output is in here, so quote it rather than paraphrasing it.
  • dirty: true when tracked changes exist on top of HEAD. Untracked files are excluded, so this matches what the gate measures.
  • untracked_count: how many untracked files the tree carries, recorded separately so a pile of backups stays visible without being mistaken for work.
  • tree_fingerprint: sha256 over HEAD plus every tracked-change line. This is the receipt's identity, and it is what the gate compares.
  • can_fail_demonstrated: true only when the selftest has passed against this exact copy of verify.py, matched by file hash. When it is false the receipt comes from a verify that has never been shown to report a failure, so a PASS from it carries less weight. Re-earn it with python scripts/verify.py selftest.
Step 3: Act on the verdict
ExitVerdictWhat it means for the session
0PASSAt least one check ran and none failed. Safe to report the work done and to commit.
1FAILA check failed. The session is not done. Fix it and re-run rather than narrating around it.
3NOTHING_DETECTEDNothing was detected, or everything detected was skipped. Nothing was verified, so nothing is confirmed. Say that plainly instead of calling it a pass.
64usage errorThe command line was wrong. Fix the invocation and re-run.

Exit 2 never comes from run. It belongs to the gate alone, so a 2 always means a Stop event was blocked, not that a check failed.

Show full SKILL.md (637 more words)Show less

The Stop gate

The same file runs as a Stop hook, deciding once per turn whether unverified work is sitting in the tree.

  • Armed only by .verify-required at the repo root, found from the git toplevel. Without that file the gate allows silently every turn, because a note on a session that never asked for a gate is noise. The marker stays untracked on purpose: committing it would arm every clone.
  • Honors one kind of receipt. The newest receipt whose verdict is PASS and whose kind is run, and only when its tree_fingerprint equals the tree's fingerprint right now. A selftest receipt is refused even though it says PASS, because selftest proves the tool works and never runs the project's checks.
  • Allows when there is nothing to verify. No tracked changes plus a receipt for this same HEAD means no unverified edit exists.
  • Blocks with exit 2 and a message naming the exact run command that clears it.
  • Yields after two blocks. It counts consecutive blocks per session against one unchanged fingerprint, and on the third it allows with a YIELDING note instead. A block that has repeated twice has stopped carrying information.
  • Allows on its own failures. Unparseable payload, git unable to describe the tree, internal error: each one allows, loudly where there is something worth saying. A gate that kills the session it protects gets deleted.

Editing a tracked file changes the fingerprint, which is what stops a stale receipt from clearing new work.

The repair cap

After a FAIL, take two rounds of fixing. If a third round is still not producing a passing receipt, stop and tell the user what is failing and what has been tried.

This mirrors the gate's own cap, for the same reason: by the third round the evidence says the problem is not the one being fixed, and further rounds spend the user's tokens confirming that.

Known Gotchas

GotchaWhy it matters
Untracked files never countThe fingerprint drops every ?? line, so a pile of .bak files is not why a block happened. Look at the tracked changes instead of tidying scratch files.
A FAIL that predates the edits is still the session's to surfaceThe receipt records what the chain reports now. A pre-existing failure gets reported, not skipped, because the user cannot act on a problem nobody mentioned.
NOTHING_DETECTED is not a passIt is exit 3 precisely so it cannot be mistaken for exit 0. It means nothing was verified, which is a different claim from nothing being wrong.
A SKIP with a reason is not a pass eitherA chain where everything skipped resolves to NOTHING_DETECTED for the same reason: an unrun check confirms nothing.
A selftest receipt cannot clear the gateSelftest never touches the project's own checks, so honoring it would let a green result from a chain that never read the project unlock the project's work.
can_fail_demonstrated: false weakens a PASSIt marks a verify that has not proven it can report failure against this exact file. Run the selftest before leaning on that receipt.
Doc-only edits to tracked files still arm the gateNo check reads prose, so the chain has nothing to say about it, but the fingerprint changed and a run receipt is still what clears it.

Inputs

  • The repository at the current working directory
  • The session id, used as the receipt's task id

Outputs

  • A receipt at .memstack/receipts/<task-id>.json
  • A verdict and an exit code, reported to the user as they came back

Level History

  • Lv.1 Base: Pre-commit verification with automated + manual checks, structured report output, framework-agnostic detection. (Origin: MemStack v3.1, Feb 2026)
  • Lv.2 CLI and gate: Rewritten around scripts/verify.py. Detection is bounded and named, results are receipts carrying a tree fingerprint, and a Stop gate blocks unverified tracked work when armed. (Origin: MemStack Session 2, Sep 2026)

© cwinvestments, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/verify of cwinvestments/memstack.

Open the folder on GitHubat commit 00370ce

Compare with similar skills

Verify next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Verify compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Verify this skillcwinvestments/memstack423—~2.2kAutomated safety check: PassMIT
Django Verification Loopaffaan-m/ECC275k7 repos~2.9kAutomated safety check: PassMIT
Opendocsioteverythin/OpenDocs233—~746Automated safety check: NotesMIT
OfficeCLIofficecli/officecli106—~3.8kAutomated safety check: PassMIT
OpenClaw OfficeCLI Bridgeofficecli/officecli106—~2.2kAutomated safety check: PassMIT
Kedro Babysitkedro-org/kedro11k—~4kAutomated safety check: PassCustom licence

Similar skills

  • Runs a phased pre-PR and pre-deploy check on a Django project: environment, linting, migrations, tests with coverage, security scans and settings review.

    275k GitHub starsUsed in 7 repos~2.9k tokens
    DevelopmentAuto-check passed
  • Opendocs

    ioteverythin/OpenDocs

    Generates multi-format documentation (Word, PDF, PPTX, Markdown blog post, JIRA ticket, FAQ, changelog, LaTeX, social snippet, architecture diagram) from a GitHub README, npm package, local Markdown…

    233 GitHub stars~746 tokensUpdated 1 mo ago
    Documents & OfficeAuto-check: notes
  • OfficeCLI

    officecli/officecli

    Routes Office document and image tasks to the OfficeCLI tool for creating, editing and converting PPTX, DOCX, XLSX, reports and generated images, after checking it supports the workflow.

    106 GitHub stars~3.8k tokensUpdated 1 mo ago
    Documents & OfficeAuto-check passed
  • OpenClaw OfficeCLI Bridge

    officecli/officecli

    Generates local PPTX, DOCX, XLSX, report and image files for an OpenClaw agent through officecli agent-bridge, then sends the finished file back to the channel.

    106 GitHub stars~2.2k tokensUpdated 1 mo ago
    Documents & OfficeAuto-check passed
  • Kedro Babysit

    kedro-org/kedro

    Run Kedro's local lint / format / type-check / tests on changed files (uses the project's pre-commit hooks, ruff, mypy, pytest, lint-imports, detect-secrets, Make targets — in the right venv), or…

    11k GitHub stars~4k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Experiment Iterative Coder

    EvoScientist/EvoSkills

    Iterative code refinement through plan → code → evaluate → refine cycles.

    475 GitHub starsUsed in 3 repos~2.5k tokens
    DevelopmentAuto-check passed

More from cwinvestments/memstack

All 87 skills in this repo
  • Memstack SEO Site Audit

    cwinvestments/memstack

    A skill your agent uses when the user says 'SEO audit', 'site audit', 'check SEO', 'audit my site', 'SEO check', 'technical SEO', or is evaluating a website's search engine optimization health, meta…

    423 GitHub stars~3.5k tokensUpdated 12 days ago
    Auto-check passed
  • Memstack SEO Schema Markup

    cwinvestments/memstack

    A skill your agent uses when the user says 'add schema', 'schema markup', 'JSON-LD', 'structured data', 'rich results', 'rich snippets', or is adding or fixing schema.org structured data for better…

    423 GitHub stars~2.7k tokensUpdated 12 days ago
    Auto-check passed
  • Compress

    cwinvestments/memstack

    A skill your agent uses when the user says 'tokenstack', 'compression', 'token savings', 'proxy status', or asks about context window usage.

    423 GitHub stars~1.2k tokensUpdated 12 days ago
    Auto-check passed
  • Diary

    cwinvestments/memstack

    A skill your agent uses when the user says 'save diary', 'log session', 'wrapping up', or at end of a productive session.

    423 GitHub stars~5k tokensUpdated 12 days ago
    Auto-check passed
  • Echo

    cwinvestments/memstack

    A skill your agent uses when the user references past sessions, asks 'what did we do', 'do you remember', 'last session', 'recall', or 'continue from'.

    423 GitHub stars~1.7k tokensUpdated 12 days ago
    Auto-check passed
  • Familiar

    cwinvestments/memstack

    A skill your agent uses when the user says 'dispatch', 'send familiar', 'split task', or needs work split across parallel CC sessions.

    423 GitHub stars~556 tokensUpdated 12 days ago
    Auto-check passed

Works with

Questions about Verify

What does Verify do?

Runs this project's check chain through scripts/verify.py and reads the receipt it writes. Verify is an agent skill from cwinvestments/memstack.py and reads the receipt it writes.

When should I use Verify?

Verify fits situations like: asks whether work passes; before a commit; before reporting a task done.

How do I install Verify in Claude Code?

Run `npx skills add cwinvestments/memstack --skill verify -a claude-code`. Or copy the skill folder (skills/verify in cwinvestments/memstack) into .claude/skills/verify in your project. Claude Code loads it when a task matches its description.

How do I install Verify in Codex?

Run `npx skills add cwinvestments/memstack --skill verify -a codex`. Or copy the skill folder (skills/verify in cwinvestments/memstack) into .agents/skills/verify in your project. Codex loads it when a task matches its description.

Can I use Verify in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cwinvestments/memstack --skill verify -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/verify, .gemini/skills/verify, .github/skills/verify and .opencode/skills/verify in your project.

What does Verify need to run?

Going by SKILL.md and its folder, Verify needs the command-line tools its instructions call (python, npm, ruff and git). Our summary lists: Python 3.

Does Verify access the network?

SKILL.md contains no URLs. Its commands use npm and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Verify safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Verify use?

Verify is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Verify use?

About 2.2k tokens (SKILL.md is roughly 8.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Verify?

Skills that share tags, products or a category with Verify: Django Verification Loop (affaan-m/ECC, 275k stars), Opendocs (ioteverythin/OpenDocs, 233 stars), OfficeCLI (officecli/officecli, 106 stars) and OpenClaw OfficeCLI Bridge (officecli/officecli, 106 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Verify?

cwinvestments (a GitHub user) maintains it in cwinvestments/memstack, which has 423 GitHub stars. The repository holds 87 skills in this directory. The repository was last updated on September 26, 2026.

Source: cwinvestments/memstack on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.