Django Verification Loop
affaan-m/ECC
Runs a phased pre-PR and pre-deploy check on a Django project: environment, linting, migrations, tests with coverage, security scans and settings review.
Runs this project's check chain through scripts/verify.py and reads the receipt it writes.
$ npx skills add cwinvestments/memstack --skill verify -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install cwinvestments/memstack verify --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/cwinvestments/memstack.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/verify .claude/skills/verify && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "verify" agent skill from https://github.com/cwinvestments/memstack/tree/master/skills/verify into .claude/skills/verify/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "verify", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/cwinvestments/memstack/tree/master/skills/verifyType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add cwinvestments/memstack --skill verify -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install cwinvestments/memstack verify --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cwinvestments/memstack.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/verify .agents/skills/verify && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "verify" agent skill from https://github.com/cwinvestments/memstack/tree/master/skills/verify into .agents/skills/verify/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "verify", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add cwinvestments/memstack --skill verify -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install cwinvestments/memstack verify --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cwinvestments/memstack.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/verify .cursor/skills/verify && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "verify" agent skill from https://github.com/cwinvestments/memstack/tree/master/skills/verify into .cursor/skills/verify/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "verify", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/cwinvestments/memstack.git --path skills/verify--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add cwinvestments/memstack --skill verify -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install cwinvestments/memstack verify --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cwinvestments/memstack.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/verify .gemini/skills/verify && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "verify" agent skill from https://github.com/cwinvestments/memstack/tree/master/skills/verify into .gemini/skills/verify/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "verify", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install cwinvestments/memstack verifyInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add cwinvestments/memstack --skill verify -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/cwinvestments/memstack.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/verify .github/skills/verify && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "verify" agent skill from https://github.com/cwinvestments/memstack/tree/master/skills/verify into .github/skills/verify/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "verify", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add cwinvestments/memstack --skill verify -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install cwinvestments/memstack verify --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cwinvestments/memstack.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/verify .opencode/skills/verify && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "verify" agent skill from https://github.com/cwinvestments/memstack/tree/master/skills/verify into .opencode/skills/verify/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "verify", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
verifyRuns this project's check chain through scripts/verify.py and reads the receipt it writes.
Verify is an agent skill from cwinvestments/memstack. Runs this project's check chain through scripts/verify.py and reads the receipt it writes. Fires when tracked changes are finished, when the user asks whether work passes, before a commit, and before reporting a task done. Stays dormant in repositories with no detectable check chain, during read-only audits, and for edits that leave no tracked change behind.
Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Documents & Office, covering Word documents. It works with Ruff, npm and pytest. The repository describes itself as: Structured skill framework for Claude Code. 130 skills, persistent memory, TokenStack compression, localhost dashboard with 3-agent runner, real-time streaming, MCP tools. The licence is MIT.
3 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 00370ce. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
pythonnpmruffgitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm and git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Verify loads about 2.2k tokens when it runs. Until then it costs about 92 tokens; SKILL.md has 1,312 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from cwinvestments/memstack at commit 00370ce, republished under its MIT licence (© cwinvestments). 1,312 words, ~2,232 tokens.
.claude/skills/verify/SKILL.md (or your agent's skills folder).Run the project's checks, write a receipt, read what it says.
When this skill activates, output:
✅ Verify: running the check chain...
Then follow the protocol below.
| Context | Status | Priority |
|---|---|---|
| Tracked changes are finished and about to be reported done | ACTIVE, run the chain | P1 |
| User asks "does it pass", "verify this", "is this ready" | ACTIVE, run the chain | P1 |
| About to commit | ACTIVE, a receipt costs less before the commit than after | P1 |
| User is mid-task, still editing | DORMANT, a receipt for a half-finished tree ages out the moment the next edit lands | n/a |
| Read-only audit or investigation | DORMANT, nothing changed, so there is nothing to verify | n/a |
| Edits left no tracked change (new untracked files only) | DORMANT, the gate does not see untracked files and neither does the chain | n/a |
Repo where verify list detects nothing | DORMANT, but read NOTHING_DETECTED below before concluding this | n/a |
scripts/verify.py detects three families and nothing else. Anything outside this list goes unchecked, so a passing receipt is not a claim that the project is sound:
| Family | Detected when | Runs |
|---|---|---|
| npm | package.json has a scripts entry named test, lint, typecheck or build | npm run <script>, one check per script, in that order |
| pytest | pytest.ini, or pyproject.toml with a [tool.pytest] section, or a tests/ directory | python -m pytest -q |
| ruff | ruff.toml, .ruff.toml, or pyproject.toml with a [tool.ruff] section | ruff check . |
A detected check that cannot run becomes a SKIP carrying its reason: npm missing from PATH, node_modules absent, pytest not importable, ruff not installed. A SKIP is not a pass, because nothing ran.
Run python scripts/verify.py list to see the chain without executing it.
python scripts/verify.py run --task-id <session-id>Use the session id as the task id. The receipt is named after it, so one session overwrites its own receipt on a re-run instead of littering the directory, and the Stop gate's block message names this exact command with this exact id.
Each check gets 900 seconds before it is recorded as a FAIL with a timeout note.
It lands at .memstack/receipts/<task-id>.json under the repo root. That directory writes a .gitignore holding * the first time it is created, so the evidence never asks to be committed and never appears in git status.
The receipt is evidence, not paperwork. Read these fields before saying anything about the outcome:
status, exit code, duration, and the last 2000 characters of combined output. The failing output is in here, so quote it rather than paraphrasing it.verify.py, matched by file hash. When it is false the receipt comes from a verify that has never been shown to report a failure, so a PASS from it carries less weight. Re-earn it with python scripts/verify.py selftest.| Exit | Verdict | What it means for the session |
|---|---|---|
| 0 | PASS | At least one check ran and none failed. Safe to report the work done and to commit. |
| 1 | FAIL | A check failed. The session is not done. Fix it and re-run rather than narrating around it. |
| 3 | NOTHING_DETECTED | Nothing was detected, or everything detected was skipped. Nothing was verified, so nothing is confirmed. Say that plainly instead of calling it a pass. |
| 64 | usage error | The command line was wrong. Fix the invocation and re-run. |
Exit 2 never comes from run. It belongs to the gate alone, so a 2 always means a Stop event was blocked, not that a check failed.
The same file runs as a Stop hook, deciding once per turn whether unverified work is sitting in the tree.
.verify-required at the repo root, found from the git toplevel. Without that file the gate allows silently every turn, because a note on a session that never asked for a gate is noise. The marker stays untracked on purpose: committing it would arm every clone.verdict is PASS and whose kind is run, and only when its tree_fingerprint equals the tree's fingerprint right now. A selftest receipt is refused even though it says PASS, because selftest proves the tool works and never runs the project's checks.Editing a tracked file changes the fingerprint, which is what stops a stale receipt from clearing new work.
After a FAIL, take two rounds of fixing. If a third round is still not producing a passing receipt, stop and tell the user what is failing and what has been tried.
This mirrors the gate's own cap, for the same reason: by the third round the evidence says the problem is not the one being fixed, and further rounds spend the user's tokens confirming that.
| Gotcha | Why it matters |
|---|---|
| Untracked files never count | The fingerprint drops every ?? line, so a pile of .bak files is not why a block happened. Look at the tracked changes instead of tidying scratch files. |
| A FAIL that predates the edits is still the session's to surface | The receipt records what the chain reports now. A pre-existing failure gets reported, not skipped, because the user cannot act on a problem nobody mentioned. |
| NOTHING_DETECTED is not a pass | It is exit 3 precisely so it cannot be mistaken for exit 0. It means nothing was verified, which is a different claim from nothing being wrong. |
| A SKIP with a reason is not a pass either | A chain where everything skipped resolves to NOTHING_DETECTED for the same reason: an unrun check confirms nothing. |
| A selftest receipt cannot clear the gate | Selftest never touches the project's own checks, so honoring it would let a green result from a chain that never read the project unlock the project's work. |
can_fail_demonstrated: false weakens a PASS | It marks a verify that has not proven it can report failure against this exact file. Run the selftest before leaning on that receipt. |
| Doc-only edits to tracked files still arm the gate | No check reads prose, so the chain has nothing to say about it, but the fingerprint changed and a run receipt is still what clears it. |
.memstack/receipts/<task-id>.jsonscripts/verify.py. Detection is bounded and named, results are receipts carrying a tree fingerprint, and a Stop gate blocks unverified tracked work when armed. (Origin: MemStack Session 2, Sep 2026)© cwinvestments, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/verify of cwinvestments/memstack.
Open the folder on GitHubat commit 00370ce
Verify next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Verify this skillcwinvestments/memstack | 423 | — | ~2.2k | Automated safety check: Pass | MIT | |
| Django Verification Loopaffaan-m/ECC | 275k | 7 repos | ~2.9k | Automated safety check: Pass | MIT | |
| Opendocsioteverythin/OpenDocs | 233 | — | ~746 | Automated safety check: Notes | MIT | |
| OfficeCLIofficecli/officecli | 106 | — | ~3.8k | Automated safety check: Pass | MIT | |
| OpenClaw OfficeCLI Bridgeofficecli/officecli | 106 | — | ~2.2k | Automated safety check: Pass | MIT | |
| Kedro Babysitkedro-org/kedro | 11k | — | ~4k | Automated safety check: Pass | Custom licence |
affaan-m/ECC
Runs a phased pre-PR and pre-deploy check on a Django project: environment, linting, migrations, tests with coverage, security scans and settings review.
ioteverythin/OpenDocs
Generates multi-format documentation (Word, PDF, PPTX, Markdown blog post, JIRA ticket, FAQ, changelog, LaTeX, social snippet, architecture diagram) from a GitHub README, npm package, local Markdown…
officecli/officecli
Routes Office document and image tasks to the OfficeCLI tool for creating, editing and converting PPTX, DOCX, XLSX, reports and generated images, after checking it supports the workflow.
officecli/officecli
Generates local PPTX, DOCX, XLSX, report and image files for an OpenClaw agent through officecli agent-bridge, then sends the finished file back to the channel.
kedro-org/kedro
Run Kedro's local lint / format / type-check / tests on changed files (uses the project's pre-commit hooks, ruff, mypy, pytest, lint-imports, detect-secrets, Make targets — in the right venv), or…
EvoScientist/EvoSkills
Iterative code refinement through plan → code → evaluate → refine cycles.
cwinvestments/memstack
A skill your agent uses when the user says 'SEO audit', 'site audit', 'check SEO', 'audit my site', 'SEO check', 'technical SEO', or is evaluating a website's search engine optimization health, meta…
cwinvestments/memstack
A skill your agent uses when the user says 'add schema', 'schema markup', 'JSON-LD', 'structured data', 'rich results', 'rich snippets', or is adding or fixing schema.org structured data for better…
cwinvestments/memstack
A skill your agent uses when the user says 'tokenstack', 'compression', 'token savings', 'proxy status', or asks about context window usage.
cwinvestments/memstack
A skill your agent uses when the user says 'save diary', 'log session', 'wrapping up', or at end of a productive session.
cwinvestments/memstack
A skill your agent uses when the user references past sessions, asks 'what did we do', 'do you remember', 'last session', 'recall', or 'continue from'.
cwinvestments/memstack
A skill your agent uses when the user says 'dispatch', 'send familiar', 'split task', or needs work split across parallel CC sessions.
Categories
Runs this project's check chain through scripts/verify.py and reads the receipt it writes. Verify is an agent skill from cwinvestments/memstack.py and reads the receipt it writes.
Verify fits situations like: asks whether work passes; before a commit; before reporting a task done.
Run `npx skills add cwinvestments/memstack --skill verify -a claude-code`. Or copy the skill folder (skills/verify in cwinvestments/memstack) into .claude/skills/verify in your project. Claude Code loads it when a task matches its description.
Run `npx skills add cwinvestments/memstack --skill verify -a codex`. Or copy the skill folder (skills/verify in cwinvestments/memstack) into .agents/skills/verify in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cwinvestments/memstack --skill verify -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/verify, .gemini/skills/verify, .github/skills/verify and .opencode/skills/verify in your project.
Going by SKILL.md and its folder, Verify needs the command-line tools its instructions call (python, npm, ruff and git). Our summary lists: Python 3.
SKILL.md contains no URLs. Its commands use npm and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Verify is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.2k tokens (SKILL.md is roughly 8.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Verify: Django Verification Loop (affaan-m/ECC, 275k stars), Opendocs (ioteverythin/OpenDocs, 233 stars), OfficeCLI (officecli/officecli, 106 stars) and OpenClaw OfficeCLI Bridge (officecli/officecli, 106 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
cwinvestments (a GitHub user) maintains it in cwinvestments/memstack, which has 423 GitHub stars. The repository holds 87 skills in this directory. The repository was last updated on September 26, 2026.
Source: cwinvestments/memstack on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.