Agent skill

Host Contract Verification

by devcodex-labs in devcodex-labs/devcodex

宿主契约验证规范 — 为 Hook / CLI / bootstrap / visible envelope / workspace guard / LinkCapabilityDecision / MCP fallback 定义 direct replay、fixture replay、部署同步与证据路线

AGPL-3.0Auto-check passed

Install Host Contract Verification

skills CLI
$ npx skills add devcodex-labs/devcodex --skill host-contract-verification -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install devcodex-labs/devcodex host-contract-verification --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/devcodex-labs/devcodex.git skills-src && mkdir -p .claude/skills && cp -r skills-src/content/skills/host-contract-verification .claude/skills/host-contract-verification && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
host-contract-verification
GitHub stars
439
Token cost
~2.6k tokens
SKILL.md length
791 words
Files
2
Skills in repo
70
Repo updated
First seen
Licence
AGPL-3.0

At a glance

宿主契约验证规范 — 为 Hook / CLI / bootstrap / visible envelope / workspace guard / LinkCapabilityDecision / MCP fallback 定义 direct replay、fixture replay、部署同步与证据路线

  • Works in 12 steps: 报告必须说明证据来自 direct replay、fixture… → 无法直接读取最终 assistant 内容时,只能落为… → workspace guard… → …
  • SKILL.md covers 职责, 触发条件, HostContractRoute and 最小验证矩阵, plus 4 more sections
  • Calls node and npm

What it does

Host Contract Verification is an agent skill from devcodex-labs/devcodex. 宿主契约验证规范 — 为 Hook / CLI / bootstrap / visible envelope / workspace guard / LinkCapabilityDecision / MCP fallback 定义 direct replay、fixture replay、部署同步与证据路线

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `intent.json`).

It works with Model Context Protocol. The repository describes itself as: Intent-driven AI coding workflow runtime for consistent context, skills, approvals, validation, and handoffs across six AI coding hosts. The licence is AGPL-3.0.

Example prompts

  • “/host-contract-verification”

Workflow steps

12 steps, taken from the first numbered list in SKILL.md.

  1. 报告必须说明证据来自 direct replay、fixture replay、现有 targeted test,还是 validate probe 推断。
  2. 无法直接读取最终 assistant 内容时,只能落为 unverified,不能伪造 verified-present。
  3. workspace guard 场景必须写清“唯一项目继续沿用”“真实歧义重新提示”“workspace profile 路径”三类边界是否覆盖。
  4. 若宿主不支持某类硬拦,只能记录为能力差异或 fallback,不得把缺失能力写成已验证通过。
  5. 产物链接必须区分“Markdown 主链接已生成”“当前宿主可点击已实测”“绝对路径 copy fallback 已提供”三种证据;不得把第一项等同于后两项。
  6. profile_load / MCP 工具出现 Cannot read properties of undefined (reading 'invoke') 时,若 DevCodex MCP server direct replay 通过,应记录为宿主 MCP bridge…
  7. Turn Liveness 声明必须分别标注 host-native-verified / hook-event-verified / sidecar-observed / unsupported / unverified;PostToolUse…
  8. CheckpointValidationResultV1 缺失 post-execution evidence 时只能是 unverified 或 incomplete-timeout;只有实际 Hook terminal evidence 才能通过,禁止把等待或…
  9. LocalTaskTraceV1 只保留当前 turn 的 typed data projection;replay 不得 dispatch payload、重放 mutation、改 lifecycle state、唤醒宿主或控制进程。
  10. workspace-namespace 下项目根存在 generated .grok/AGENTS.md 是作用域异常而不是部署成功证据;只有 workspace plugin、用户注册、两 cwd 同 identity 与工作区外 no-op 同时通过,才能升级 Grok…
  11. plain host 与显式 launcher fallback 必须分别记录 commands/evidenceMode/evidenceCeiling;任何一方通过都不能替另一方升级结论。
  12. Grok HostParity partial 闭环(PF-165):doctor/status 的 hostParity 必须能给出 failedChecks + 可执行 repairSteps(command + detail);宣称已修复…

What it can do on your machine

Read from SKILL.md and the folder at commit 1dd4525. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • node
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Host Contract Verification loads about 2.6k tokens when it runs. Until then it costs about 45 tokens; SKILL.md has 791 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~45
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from devcodex-labs/devcodex at commit 1dd4525, republished under its AGPL-3.0 licence (© devcodex-labs). 791 words, ~2,567 tokens.

Download SKILL.mdSave it as .claude/skills/host-contract-verification/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
host-contract-verification
description
宿主契约验证规范 — 为 Hook / CLI / bootstrap / visible envelope / workspace guard / LinkCapabilityDecision / MCP fallback 定义 direct replay、fixture replay、部署同步与证据路线

Host Contract Verification Skill

职责

当任务涉及宿主事件契约、Hook 可见回复、workspace 项目识别、bootstrap 护栏、产物链接可点击性、MCP bridge fallback 或部署副本同步时,本 Skill 负责把“怎么证明宿主行为真的成立”收口为可复审的验证路线。

它不替代 test-router、report 或 runtime tests,而是为这些产物提供统一的宿主证据模型。

触发条件

场景是否触发
Hook runtime / 宿主适配 / Hook 输出契约变更🔴 必须
Stop / PreCompact 可见回复验证语义变更🔴 必须
sticky activeProject / mode / workspace guard 变更🔴 必须
Bootstrap、部署副本、父链同步口径变更🔴 必须
EntryCheckModelV3 / DevCodexVisibleEnvelopeV3 / V1/V2 只读兼容 / PostCompletionActionSetV1 / UserFacingArtifactSetV1 / LinkCapabilityDecisionV1 / HostLinkCapabilityDecisionV2 / ArtifactDeliveryAttemptV1 变更🔴 必须
Copilot / Codex MCP bridge 报错、profile_load fallback、invoke undefined 恢复链变更🔴 必须
ContextReadPlanV2 / ContextReadReceiptV2(含 V1 兼容)、Pre/Post 相关性、内容身份/复用、上下文读取 allowlist 或 fallback 语义变更🔴 必须
公开本地 probe、checkpoint 证据语义或 trace show/replay 变更🔴 必须
仅普通业务代码改动N/A

HostContractRoute

字段必填说明
hostSurface✅Copilot / Claude Code / Codex / instruction-fallback 中本轮实际验证的宿主面
eventScope✅UserPromptSubmit / PreToolUse / PostToolUse / PreCompact / Stop / bootstrap / deploy-sync
evidenceMode✅direct replay / fixture replay / targeted test / validate probe / manual trace
fixtureSource条件使用 fixture replay 时记录脚本、payload 或样例来源
visibleReplyEvidence条件verified-present / verified-missing / unverified,以及证据来源
workspaceGuard条件多项目 workspace、sticky project、workspace profile 提示等边界验证
bootstrapScope条件父链部署体、入口检查块、adapter 初始化或 update 部署验证
artifactLinkMatrix条件presentationSurface + capability evidence 主选 renderer,hostSurface 只验 adapter 匹配;记录 ArtifactDeliveryAttemptV1 的 actionId/attempted/actionStatus/readback/status/fallbackReason 与 renderer parity
mcpFallback条件MCP bridge 失败时是否降级到同计划有界文件读取 / instruction-fallback;记录错误文本、fallback 路线和是否停止重试
contextAcquisition条件plan/epoch/target/source 相关性、Pre attempted、Post success receipt、fallback 与完成状态
turnLiveness条件长任务/无续接场景的 host-native、Hook-event、sidecar 能力边界,以及 lease、ACK、terminal、checkpoint 证据
localProbe条件LocalProbeDescriptorV1/ResultV1 的 ID、依赖、local-only、同步只读和 zero-write 证据
checkpointValidation条件response-time / post-execution 的 evidence、deadline、status 与 incomplete/timeout 处理
localTaskTrace条件LocalTaskTraceV1 的 sequence、duplicate、terminal、restart 与只读 replay 边界
commands✅本轮实际执行命令或 targeted tests

最小验证矩阵

变更类型最小验证
Hook 输出契约targeted test + direct replay
可见回复三态fixture replay 或 direct replay,报告中写明 visibleReplyEvidence
sticky project / workspace guardmulti-project fixture + follow-up replay
bootstrap / 部署副本node scripts/validate.js + 部署同步后的落点复核
managed deployment manifestlegacy 多 owner + workspace-namespace fixture、规范化 destination 单一 current owner、project current host=0、workspace missing/mismatch/stale/duplicate=0、V8 direct replay
workspace 宿主作用域HostAdapterScopeV1 owner/activation 一致 + 子项目五类 generated host artifact=0 + Grok workspace plugin/用户登记正向 + uninstall/repeat/reinstall 配置保真 + status/doctor 同 owner + root native kernel + child plain partial + devcodex grok --rules full 路线 + --cwd/nested workspace/Windows path identity + outside-workspace no-op 负向
visible set / 产物打开manifest/projection property test + Codex Desktop、VS Code、Zed、WebStorm、Codex CLI、Claude/unknown renderer fixture;renderer-only 必须 fallback,opened 必须同时具备 action success + readback success;若声称当前 presentationSurface 已打开,需 direct replay 或用户实测证据
MCP bridge fallbackMCP server no-args direct replay + 非 Full 宿主 fallback 文案探针;若错误来自宿主桥接层,只能声明 fallback 已覆盖,不能声明宿主 bug 已修复
意图驱动上下文获取ContextAcquisitionToolAllowlistProbe + plan/receipt direct replay + Pre/Post fixture + hidden-full-read 负例 + fallback no-deadlock
Turn Liveness / orphaned turnstate-machine fault matrix + Hook direct replay + restart rehydrate;事件停止后的 proactive 检测只能由 host-native watchdog 或 gray read-only sidecar 证明
本地 probedescriptor/dependency/error fixture + CLI JSON/human replay + state hash zero-write;不得联网、启动 watcher 或写 telemetry
checkpoint / local tracefixed-clock 双阶段 fixture + Hook terminal replay + sequence/duplicate/restart/terminal 负例;trace replay 必须证明 payload 不执行且源 state hash 不变
仅文档声明变更source-consumer-sync + validate probe;若声称宿主行为改变则不得只改文档

证据要求

VisibleOutputHostEvidenceGate

Stop/PreCompact 对最终回复证据必须使用 verified-present / verified-missing / unverified:只有观察到可解析 assistant 内容和当前 DevCodexVisibleEnvelopeV3 marker、合法动作标题、语义 item 才能判定 present/missing;V1/V2 marker 只记录 legacy-v1-read-only / legacy-v2-read-only,不得把它当作新写入证据。未观察到只能 unverified。记录 evidenceSource / missingItems / semanticDigest,不得保存不必要的完整回复正文。

legacy “主要产物 + 绝对路径”最多为 unverified-legacy。能力未 direct 验证时保持 portable/plain;Rich clickable 只显示单个语义链接。session、daily、SUMMARY、task/checkpoint 和 raw ledger 默认 internal-only,但宿主验证仍要核对它们已进入 internal manifest 和 ECR。

HostPermissionAuthorityInvariant

PreToolUse 与 PermissionRequest 的文件、命令、删除及工具调用权限完全归当前宿主和用户宿主配置。DevCodex 只能记录风险 advisory、telemetry 或 typed workflow-invalid;runtime、输出 builder 和每个宿主 adapter 均不得发出或转译 allow / deny / ask / block / continue:false 操作权限载荷。Stop、PreCompact 等非操作生命周期完成门禁不受此条影响。验证必须向 Codex、Claude、Gemini、Copilot、Grok、Cursor 注入遗留允许/拒绝载荷,并证明最终操作事件投影不含任何 permission carrier。

Show full SKILL.md (336 more words)Show less
ContextAcquisitionHostEvidenceGate
  • ContextAcquisitionToolAllowlistProbe 只允许已注册的只读 Profile / memory 查询工具推进 source state;普通文件搜索、写工具、legacy no-args 全文读取或未知工具不得伪造完成。
  • PreToolUse 只记录 correlated attempted;只有 PostToolUse 中可解析的成功结果,且 invocation planId、planContentId、contextEpoch、activeRoot、tool/source/query 全部匹配时,才生成或推进 ContextReadReceiptV2(V1 兼容)。
  • ContextDeliveryReuseHostProbe 必须分别证明 computation reuse 与 delivery reuse:跨进程只允许复用内容身份绑定的计算元数据;正文省略还必须同 host session、同 epoch、同 source identity 且当前模型已有成功 body observation。宿主无法提供稳定 session 或 Post body 证据时 delivery reuse 必须降级为 false。
  • 需覆盖结构化 MCP、path-observable 与 instruction-only 三种宿主能力;后两者缺少可验证结果时必须保持 unverified,不能由提示文案升级为 relevant-complete/completed。
  • MCP bridge 失败只允许一次同计划 bounded fallback 并停止重试;fallback 失败或证据不可观察时输出 warnings / missing sources,但不得形成死循环或跳过后续安全与 CP 门禁。
  • Progressive SkillRoute enforcement policy 缺失、损坏或字段非法时必须使用受控 fail-safe:所有宿主的 PreToolUse/PermissionRequest 保持 advisory-only;Stop 等非操作生命周期事件可按宿主能力恢复 hard default。bootstrap 与 observe 均保持。
  • direct/fixture replay 至少覆盖 success、tool error、mismatched epoch/target/source、duplicate/stale Post、legacy projection 和 hidden full-read mutation;报告区分 server direct success 与 host bridge verified。
  1. 报告必须说明证据来自 direct replay、fixture replay、现有 targeted test,还是 validate probe 推断。
  2. 无法直接读取最终 assistant 内容时,只能落为 unverified,不能伪造 verified-present。
  3. workspace guard 场景必须写清“唯一项目继续沿用”“真实歧义重新提示”“workspace profile 路径”三类边界是否覆盖。
  4. 若宿主不支持某类硬拦,只能记录为能力差异或 fallback,不得把缺失能力写成已验证通过。
  5. 产物链接必须区分“Markdown 主链接已生成”“当前宿主可点击已实测”“绝对路径 copy fallback 已提供”三种证据;不得把第一项等同于后两项。
  6. profile_load / MCP 工具出现 Cannot read properties of undefined (reading 'invoke') 时,若 DevCodex MCP server direct replay 通过,应记录为宿主 MCP bridge 失败并启用 mcpFallback=used,禁止反复重试同一 MCP 调用。
  7. Turn Liveness 声明必须分别标注 host-native-verified / hook-event-verified / sidecar-observed / unsupported / unverified;PostToolUse 落盘只能证明工具结果已观察,不能证明模型续接或 turn 已终态。
  8. CheckpointValidationResultV1 缺失 post-execution evidence 时只能是 unverified 或 incomplete-timeout;只有实际 Hook terminal evidence 才能通过,禁止把等待或 PreCompact 当完成。
  9. LocalTaskTraceV1 只保留当前 turn 的 typed data projection;replay 不得 dispatch payload、重放 mutation、改 lifecycle state、唤醒宿主或控制进程。
  10. workspace-namespace 下项目根存在 generated .grok/AGENTS.md 是作用域异常而不是部署成功证据;只有 workspace plugin、用户注册、两 cwd 同 identity 与工作区外 no-op 同时通过,才能升级 Grok workspace 结论。
  11. plain host 与显式 launcher fallback 必须分别记录 commands/evidenceMode/evidenceCeiling;任何一方通过都不能替另一方升级结论。
  12. Grok HostParity partial 闭环(PF-165):doctor/status 的 hostParity 必须能给出 failedChecks + 可执行 repairSteps(command + detail);宣称已修复 registration/plugin 缺口时,证据须含再次 doctor --json 的 checks 回读,不得只写「建议 update」。
  13. GrokTurnChecklist:声称「Grok 完整工作流已执行」时,报告/回执须覆盖 entry-pc0-pc7、skill-bundle、report-memory 与 honest-ceiling;负向探针见 classifyGrokTurnOmissionSample(scripts/lib/host-parity-scorecard.js)。
NativeCommandExitCodeGate 可执行适配
  • 仓库内需要串行执行原生命令并保留证据的维护脚本优先复用 scripts/lib/checked-command.js 的 runChecked / runSequenceChecked,统一记录 command、cwd、exitCode、signal、duration 与 stdout/stderr 摘要。
  • 默认 shell:false;只有调用方记录 allowShellReason 时才允许 shell。positional path 中的字面 glob 必须在 spawn 前拒绝,显式 --glob/-g 等 option value 除外。
  • 适配器只是实现路径,不替代 direct replay / fixture replay;必须用 nonzero、ENOENT、失败短路和 literal-glob 负向 fixture 证明不会假绿。

与其他 Skill 的关系

  • test-router:决定宿主验证是否进入 direct replay / fixture replay / targeted test。
  • execution-contract:记录 verificationEvidence,说明本轮要收集哪些宿主证据。
  • source-consumer-sync:当宿主契约变化会影响 README / website / Profile / 部署副本时,负责同步消费链。
  • report:把 HostContractRoute 的结果写入实施报告或审查报告。

输出格式

markdown
## HostContractRoute

| 字段 | 内容 |
|------|------|
| hostSurface | |
| eventScope | |
| evidenceMode | |
| fixtureSource | |
| visibleReplyEvidence | |
| workspaceGuard | |
| bootstrapScope | |
| artifactLinkMatrix | |
| mcpFallback | |
| contextAcquisition | plan/epoch/target/source、allowlist、Pre/Post、receipt、fallback 与完成状态 |
| turnLiveness | capability layer、lease/ACK/terminal/checkpoint、fault matrix 与证据状态 |
| localProbe | descriptor/dependency/local-only/zero-write 与 CLI 证据 |
| checkpointValidation | response-time/post-execution 结果、deadline 与证据状态 |
| localTaskTrace | ordered events、terminal、restart、read-only replay 与 source hash |
| commands | |

禁止

  • 禁止仅凭 README / prompt 文案就断言宿主契约已验证。
  • 禁止把 npm test 通过等价为 direct replay 已覆盖。
  • 禁止在需要 direct replay 的场景下只保留人工口头判断。
  • 禁止把 Hook 下一事件到达时的 stale 检测写成无事件时可自唤醒;禁止用 sidecar 观察授权自动进程或宿主状态 mutation。
  • 禁止把 trace replay 写成 operation replay,或执行 payload 中的命令、文件动作和工具调用。

© devcodex-labs, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in content/skills/host-contract-verification of devcodex-labs/devcodex.

  • SKILL.md
  • intent.json

Open the folder on GitHubat commit 1dd4525

Compare with similar skills

Host Contract Verification next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Host Contract Verification compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Host Contract Verification this skilldevcodex-labs/devcodex439—~2.6kAutomated safety check: PassAGPL-3.0
MCP Server Builderanthropics/skills180k62 repos~2.3kAutomated safety check: PassApache-2.0
MCP Server BuildershareAI-lab/learn-claude-code78k5 repos~1.2kAutomated safety check: PassMIT
MCP Integration for Pluginsanthropics/claude-plugins-official37k11 repos~3.1kAutomated safety check: PassApache-2.0
Figma use_figma Plugin API Ruleswarpdotdev/warp65k4 repos~4.4kAutomated safety check: PassAGPL-3.0
Stitch to Remotion Walkthrough Videosgoogle-labs-code/stitch-skills8.4k6 repos~3.2kAutomated safety check: NotesApache-2.0

Similar skills

  • MCP Server Builder

    anthropics/skills

    Official

    Guides the design and implementation of Model Context Protocol servers in TypeScript or Python, from tool naming and error messages to evaluation.

    180k GitHub starsUsed in 62 repos~2.3k tokens
    Agent WorkflowsAuto-check passed
  • MCP Server Builder

    shareAI-lab/learn-claude-code

    Walks through building MCP servers in Python or TypeScript that expose tools, resources and prompts to Claude, with templates, registration and testing.

    78k GitHub starsUsed in 5 repos~1.2k tokens
    Agent WorkflowsAuto-check passed
  • MCP Integration for Plugins

    anthropics/claude-plugins-official

    Official

    Explains how to bundle Model Context Protocol servers in a Claude Code plugin, covering config files, stdio, SSE, HTTP and WebSocket server types, and authentication.

    37k GitHub starsUsed in 11 repos~3.1k tokens
    Agent WorkflowsAuto-check passed
  • Required groundwork before any use_figma call: the rules and reference files for running JavaScript in a Figma file through the Plugin API without common failures.

    65k GitHub starsUsed in 4 repos~4.4k tokens
    Frontend & DesignAuto-check passed
  • Stitch to Remotion Walkthrough Videos

    google-labs-code/stitch-skills

    Official

    Builds walkthrough videos from Stitch design projects using Remotion, with transitions, zoom effects and text overlays on each screen.

    8.4k GitHub starsUsed in 6 repos~3.2k tokens
    Media & CreativeAuto-check: notes
  • MCP Development

    coollabsio/coolify

    A skill your agent uses for Laravel MCP development. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 1 repo~949 tokens
    Frontend & DesignAuto-check passed

More from devcodex-labs/devcodex

All 70 skills in this repo
  • Accessibility I18n

    devcodex-labs/devcodex

    无障碍与国际化专家 Owner — 当任务涉及可访问性、键盘操作、焦点、屏幕阅读器、ARIA、语言地区、本地化、RTL、翻译资源、用户可见文案或多语言文档时使用;要求把包容性体验和本地化验证绑定到真实用户路径。

    439 GitHub stars~718 tokensUpdated 20 days ago
    Auto-check passed
  • AI Agent System Architecture

    devcodex-labs/devcodex

    AI Agent 系统架构专家 Owner — 当任务涉及 Agent 路由、工具调用、上下文管理、记忆、状态机、权限、人机协作、可观测性、回放验证或模型辅助治理时使用;要求把 Agent 行为设计成可解释、可恢复、可审计。

    439 GitHub stars~2.4k tokensUpdated 20 days ago
    Auto-check passed
  • API Contract Architecture

    devcodex-labs/devcodex

    API 契约架构专家 Owner — 当任务涉及 public API、HTTP/SDK/CLI 契约、版本兼容、错误模型、分页过滤、幂等、Schema、类型、迁移或消费者影响时使用;要求先冻结消费者契约,再设计实现与验证。

    439 GitHub stars~865 tokensUpdated 20 days ago
    Auto-check passed
  • Architecture Design

    devcodex-labs/devcodex

    架构设计文档编排 Owner — 当用户要求架构设计、系统设计、技术架构或可指导开发、Review 与任务拆分的完整方案时使用;要求从业务流程反推节点、状态、数据、一致性、异常补偿、ADR 与实施任务。

    439 GitHub stars~1.1k tokensUpdated 20 days ago
    Auto-check passed
  • Audit Common

    devcodex-labs/devcodex

    审查公共维度 G0~G5 + Profile Freshness Check — 所有 audit 子类型必先执行的基础维度层

    439 GitHub stars~4.1k tokensUpdated 20 days ago
    Auto-check passed
  • Audit Session

    devcodex-labs/devcodex

    审计工作流的跨会话状态机 — 在 <audit-root/.audit-state/<session-id.json 持久化轮次/发现项/收敛状态,支持 Token 中断后精准恢复

    439 GitHub stars~1.8k tokensUpdated 20 days ago
    Auto-check passed

Questions about Host Contract Verification

What does Host Contract Verification do?

宿主契约验证规范 — 为 Hook / CLI / bootstrap / visible envelope / workspace guard / LinkCapabilityDecision / MCP fallback 定义 direct replay、fixture replay、部署同步与证据路线. Host Contract Verification is an agent skill from devcodex-labs/devcodex.

How do I install Host Contract Verification in Claude Code?

Run `npx skills add devcodex-labs/devcodex --skill host-contract-verification -a claude-code`. Or copy the skill folder (content/skills/host-contract-verification in devcodex-labs/devcodex) into .claude/skills/host-contract-verification in your project. Claude Code loads it when a task matches its description.

How do I install Host Contract Verification in Codex?

Run `npx skills add devcodex-labs/devcodex --skill host-contract-verification -a codex`. Or copy the skill folder (content/skills/host-contract-verification in devcodex-labs/devcodex) into .agents/skills/host-contract-verification in your project. Codex loads it when a task matches its description.

Can I use Host Contract Verification in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add devcodex-labs/devcodex --skill host-contract-verification -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/host-contract-verification, .gemini/skills/host-contract-verification, .github/skills/host-contract-verification and .opencode/skills/host-contract-verification in your project.

What does Host Contract Verification need to run?

Going by SKILL.md and its folder, Host Contract Verification needs the command-line tools its instructions call (node and npm).

Does Host Contract Verification access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Host Contract Verification safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Host Contract Verification use?

Host Contract Verification is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Host Contract Verification use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Host Contract Verification?

Skills that share tags, products or a category with Host Contract Verification: MCP Server Builder (anthropics/skills, 180k stars), MCP Server Builder (shareAI-lab/learn-claude-code, 78k stars), MCP Integration for Plugins (anthropics/claude-plugins-official, 37k stars) and Figma use_figma Plugin API Rules (warpdotdev/warp, 65k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Host Contract Verification?

devcodex-labs (a GitHub organization) maintains it in devcodex-labs/devcodex, which has 439 GitHub stars. The repository holds 70 skills in this directory. The repository was last updated on September 17, 2026.

Source: devcodex-labs/devcodex on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.