Agent skill

Anti Cheating

by elliothux in elliothux/open-compute

Audit the current Lynx branch and working tree for test-, fixture-, demo-, page-, domain-, or scenario-tuned production logic.

Apache-2.0Auto-check passedTesting & QA

Install Anti Cheating

skills CLI
$ npx skills add elliothux/open-compute --skill anti-cheating -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install elliothux/open-compute anti-cheating --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/elliothux/open-compute.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/anti-cheating .claude/skills/anti-cheating && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
anti-cheating
GitHub stars
1.7k
Token cost
~1.1k tokens
SKILL.md length
567 words
Files
3
Skills in repo
7
Repo updated
First seen
Licence
Apache-2.0

At a glance

Audit the current Lynx branch and working tree for test-, fixture-, demo-, page-, domain-, or scenario-tuned production logic.

  • Works in 7 steps: Resolve the branch base from @{upstream}… → Identify changed tests, prompts, skills,… → Extract distinctive scenario literals… → …
  • Anti-cheating reviews of code
  • SKILL.md covers Invariant, Exclusions, Workflow and Decision Tests, plus 3 more sections
  • Calls git

What it does

Anti Cheating is an agent skill from elliothux/open-compute. Audit the current Lynx branch and working tree for test-, fixture-, demo-, page-, domain-, or scenario-tuned production logic. Use for anti-cheating reviews of code, prompts, skills, tool descriptions, or e2e-related changes; do not use for general code review.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files (for example `agents/openai.yaml` and `patterns.md`).

It sits in Testing & QA, covering End-to-end testing and Test data and fixtures. It works with Cloudflare Workers. The repository describes itself as: Self-hosted Cloudflare Workers-compatible platform with Workers、KV、D1、R2、DO、Queues、Workflows、Cron、Cache、Images、Vectorize、AI Search、Artifacts、Static Assets、Service… The licence is Apache-2.0.

When your agent uses it

  • Anti-cheating reviews of code
  • Tool descriptions
  • E2e-related changes
  • Do not use for general code review

Example prompts

  • “/anti-cheating”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Resolve the branch base from @{upstream} and its merge base with HEAD. Inventory three scopes separately
  2. Identify changed tests, prompts, skills, tool descriptions, routing/policy, workflows, and production branches.
  3. Extract distinctive scenario literals from changed tests or examples: prompts, labels, selectors, URLs, app/page names, expected response…
  4. Cross-search those literals against production surfaces, then reverse-search new production guidance against tests.
  5. Inspect conditionals and constants for behavior keyed to scenario identity rather than runtime contracts.
  6. Classify every candidate with the decision tests below.
  7. Return only evidence-backed findings. If none remain, state that the audit is clean and name the scope reviewed.

What it can do on your machine

Read from SKILL.md and the folder at commit 2648182. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Anti Cheating loads about 1.1k tokens when it runs. Until then it costs about 69 tokens; SKILL.md has 567 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~69
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from elliothux/open-compute at commit 2648182, republished under its Apache-2.0 licence (© elliothux). 567 words, ~1,114 tokens.

Download SKILL.mdSave it as .claude/skills/anti-cheating/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
anti-cheating
description
Audit the current Lynx branch and working tree for test-, fixture-, demo-, page-, domain-, or scenario-tuned production logic. Use for anti-cheating reviews of code, prompts, skills, tool descriptions, or e2e-related changes; do not use for general code review.

Anti-Cheating Audit

Audit committed branch changes, tracked working-tree changes, and untracked files by default. Expand only to call sites needed to prove or disprove a candidate. Report findings; do not edit unless the user also asks for fixes.

Invariant

Production behavior must follow runtime inputs, schemas, observed UI state, persisted data, generic algorithms, or real product/platform contracts. Test and example literals belong only in tests, fixtures, or explicit user input.

Exclusions

Do not flag these without evidence of production coupling:

  • e2e/**, specs, tests, fixtures, snapshots, and e2e/output/**
  • generated files
  • platform/API contracts, connector manifests, bundle IDs, and regional product domains
  • legitimate specialization contained inside its owning domain skill or connector
  • clearly illustrative documentation examples
  • literals supplied or persisted at runtime

Workflow

  1. Resolve the branch base from @{upstream} and its merge base with HEAD. Inventory three scopes separately:
    • committed changes from the upstream merge base through HEAD
    • staged and unstaged tracked changes against HEAD
    • untracked files from git ls-files --others --exclude-standard If no upstream exists, do not guess a base. Audit the working tree immediately; ask for the intended base before judging committed changes. If the user requested only a working-tree audit, state that committed history is excluded and continue.
  2. Identify changed tests, prompts, skills, tool descriptions, routing/policy, workflows, and production branches.
  3. Extract distinctive scenario literals from changed tests or examples: prompts, labels, selectors, URLs, app/page names, expected response fragments, and ordered steps.
  4. Cross-search those literals against production surfaces, then reverse-search new production guidance against tests.
  5. Inspect conditionals and constants for behavior keyed to scenario identity rather than runtime contracts.
  6. Classify every candidate with the decision tests below.
  7. Return only evidence-backed findings. If none remain, state that the audit is clean and name the scope reviewed.

Use patterns.md for repo paths, smell patterns, approved exceptions, and grep recipes. Treat grep hits only as candidates.

Show full SKILL.md (258 more words)Show less

Decision Tests

Apply all four:

  1. Removal: If the triggering spec/example vanished, would the production behavior still belong?
  2. Duplication: Is the same scenario rule repeated across a test, global prompt, domain skill, tool description, or production branch?
  3. Generalization: Could the requirement be expressed from runtime state or a generic contract without scenario vocabulary?
  4. Input: Does behavior depend on a literal copied from a test/example instead of runtime input, schema, state, or a product contract?

A suspicious match is not a finding until the evidence shows scenario tuning.

Severity

  • Blocker: Production logic or global guidance encodes a specific test, fixture, e2e prompt, or scenario identity.
  • Major: A global prompt, skill, or tool description contains a scenario playbook that belongs in an owning domain surface or only in tests.
  • Minor: Duplicated or misleading scenario guidance creates drift risk but does not currently control production behavior.

Output

Lead with the verdict and scope. Sort findings by severity and include:

  • path:line
  • exact evidence
  • the matched test/example or scenario source
  • why it violates a decision test
  • the smallest root-cause fix

Include a compact cross-reference table when multiple literals or surfaces are involved. Do not include empty severity sections. Preserve raw evidence and distinguish facts from inference.

Fix Direction

When fixes are requested:

  • delete scenario shaping from global prompts and tool descriptions
  • keep domain behavior only in its owning skill or connector
  • replace literal branches with schema-, input-, state-, or contract-driven logic
  • keep qualitative assertions limited to stable lifecycle signals
  • never add test-only hooks, bridges, fake tools, or mock agent surfaces

© elliothux, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files in .agents/skills/anti-cheating of elliothux/open-compute.

  • SKILL.md
  • agents/openai.yaml
  • patterns.md

Open the folder on GitHubat commit 2648182

Compare with similar skills

Anti Cheating next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Anti Cheating compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Anti Cheating this skillelliothux/open-compute1.7k—~1.1kAutomated safety check: PassApache-2.0
Java SDK E2E Test with Replay Snapshotgithub/copilot-sdk11k—~1.8kAutomated safety check: PassMIT
source-mssql E2E Test Harnessairbytehq/airbyte22k—~4.4kAutomated safety check: PassCustom licence
Airbyte source-mysql E2E Testsairbytehq/airbyte22k—~2.6kAutomated safety check: PassCustom licence
Airbyte Postgres Source E2E Testsairbytehq/airbyte22k—~2.5kAutomated safety check: PassCustom licence
MSSQL CDC Bug Reproduction Harnessairbytehq/airbyte22k—~3.3kAutomated safety check: PassCustom licence

Similar skills

  • Official

    Creates a Java SDK end-to-end test for the Copilot SDK that runs against a recorded YAML snapshot through a replay proxy, so CI needs no real authentication.

    11k GitHub stars~1.8k tokensUpdated yesterday
    Testing & QAAuto-check passed
  • Official

    Stands up a throwaway local SQL Server 2022 backend, applies SQL fixtures and runs Airbyte spec, check, discover and read against source-mssql images.

    22k GitHub stars~4.4k tokensUpdated yesterday
    Testing & QAAuto-check passed
  • Official

    Stands up a throwaway local MySQL 8.0 backend, applies SQL fixtures and sweeps the Airbyte spec, check, discover and read commands against a source-mysql image.

    22k GitHub stars~2.6k tokensUpdated yesterday
    Testing & QAAuto-check passed
  • Official

    Starts a local PostgreSQL 16 container, loads SQL fixtures and runs the Airbyte spec, check, discover and read commands against a chosen source-postgres image.

    22k GitHub stars~2.5k tokensUpdated yesterday
    Testing & QAAuto-check passed
  • Official

    Reproduces change-data-capture bugs in the source-mssql Airbyte connector by enabling CDC on a local SQL Server backend and replaying per-bug SQL fixtures.

    22k GitHub stars~3.3k tokensUpdated yesterday
    Testing & QAAuto-check passed
  • ClickUp CLI Testing

    krodak/clickup-cli

    Explains how to run and extend the clickup-cli tests: unit tests with a mocked client, e2e tests against a real ClickUp workspace, and the fixture data they rely on.

    121 GitHub stars~1.4k tokensUpdated 2 days ago
    Testing & QAAuto-check: notes

More from elliothux/open-compute

  • Kumo Design

    elliothux/open-compute

    Cloudflare product design guidance. An agent skill from elliothux/open-compute.

    1.7k GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Grok Executor

    elliothux/open-compute

    Delegate a concrete, locally authorized implementation or read-only web research task from Codex to the official Grok Build CLI.

    1.7k GitHub stars~1.8k tokensUpdated yesterday
    Auto-check: warnings
  • Cf Compatibility Check

    elliothux/open-compute

    Review branch and working-tree implementation changes for conformance with open-compute's Cloudflare Workers runtime target under explicit single-machine self-host exclusions.

    1.7k GitHub stars~3.5k tokensUpdated yesterday
    Auto-check passed
  • Simplify

    elliothux/open-compute

    Simplify recently modified Lynx business code while preserving behavior.

    1.7k GitHub stars~984 tokensUpdated yesterday
    Auto-check passed
  • Update Workerd Upstream

    elliothux/open-compute

    Update open-compute's workerd fork onto current Cloudflare upstream, minimize fork-owned code, regroup fork commits by capability, and coordinate the submodule, pin, tests, and docs.

    1.7k GitHub stars~922 tokensUpdated yesterday
    Auto-check passed
  • Product Surface Check

    elliothux/open-compute

    Manually review changed open-compute behavior for drift across maintained user, operator, API, SDK, configuration, deployment, capability, CLI, Dashboard, and release surfaces.

    1.7k GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Anti Cheating

What does Anti Cheating do?

Audit the current Lynx branch and working tree for test-, fixture-, demo-, page-, domain-, or scenario-tuned production logic. Anti Cheating is an agent skill from elliothux/open-compute. Audit the current Lynx branch and working tree for test-, fixture-, demo-, page-, domain-, or scenario-tuned production logic.

When should I use Anti Cheating?

Anti Cheating fits situations like: anti-cheating reviews of code; tool descriptions; E2e-related changes; do not use for general code review.

How do I install Anti Cheating in Claude Code?

Run `npx skills add elliothux/open-compute --skill anti-cheating -a claude-code`. Or copy the skill folder (.agents/skills/anti-cheating in elliothux/open-compute) into .claude/skills/anti-cheating in your project. Claude Code loads it when a task matches its description.

How do I install Anti Cheating in Codex?

Run `npx skills add elliothux/open-compute --skill anti-cheating -a codex`. Or copy the skill folder (.agents/skills/anti-cheating in elliothux/open-compute) into .agents/skills/anti-cheating in your project. Codex loads it when a task matches its description.

Can I use Anti Cheating in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add elliothux/open-compute --skill anti-cheating -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/anti-cheating, .gemini/skills/anti-cheating, .github/skills/anti-cheating and .opencode/skills/anti-cheating in your project.

What does Anti Cheating need to run?

Going by SKILL.md and its folder, Anti Cheating needs the command-line tools its instructions call (git).

Does Anti Cheating access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Anti Cheating safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Anti Cheating use?

Anti Cheating is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Anti Cheating use?

About 1.1k tokens (SKILL.md is roughly 4.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Anti Cheating?

Skills that share tags, products or a category with Anti Cheating: Java SDK E2E Test with Replay Snapshot (github/copilot-sdk, 11k stars), source-mssql E2E Test Harness (airbytehq/airbyte, 22k stars), Airbyte source-mysql E2E Tests (airbytehq/airbyte, 22k stars) and Airbyte Postgres Source E2E Tests (airbytehq/airbyte, 22k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Anti Cheating?

elliothux (a GitHub user) maintains it in elliothux/open-compute, which has 1,710 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on October 7, 2026.

Source: elliothux/open-compute on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.