Official agent skill

Verify Agent Action

by github in github/awesome-copilot

Review a proposed AI-agent action or human-approval packet before execution.

OfficialMITAuto-check passedDevOps & Cloud

Install Verify Agent Action

skills CLI
$ npx skills add github/awesome-copilot --skill verify-agent-action -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install github/awesome-copilot verify-agent-action --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/github/awesome-copilot.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/verify-agent-action .claude/skills/verify-agent-action && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
verify-agent-action
GitHub stars
40k
Token cost
~2.1k tokens
SKILL.md length
846 words
Files
1
Skills in repo
417
Repo updated
First seen
Licence
MIT

At a glance

Review a proposed AI-agent action or human-approval packet before execution.

  • Works in 6 steps: Recompute the assessment → Match the exact approved action → Reject replay and identity ambiguity → …
  • An agent wants to run a consequential tool
  • SKILL.md covers Preserve the safety boundary, Collect the review packet, Build the exact action identity and Run the six controls, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Verify Agent Action is an agent skill from github/awesome-copilot, published by the product's own GitHub organization. Review a proposed AI-agent action or human-approval packet before execution. Use when an agent wants to run a consequential tool, command, deployment, message, purchase, credential operation, or data mutation; when checking whether approval still matches the exact action; or when auditing action evidence for forged results, parameter swaps, replay, correlated reviewers, missing evidence, expiry, or stale monitoring. Produce an evidence-based review only—never execute or authorize the action.

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud. The repository describes itself as: Community-contributed instructions, agents, skills, and configurations to help you make the most of GitHub Copilot. The licence is MIT.

When your agent uses it

  • An agent wants to run a consequential tool
  • Credential operation
  • Checking whether approval still matches the exact action
  • Auditing action evidence for forged results

Example prompts

  • “/verify-agent-action”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Recompute the assessment
  2. Match the exact approved action
  3. Reject replay and identity ambiguity
  4. Test reviewer independence
  5. Preserve evidence and contradiction
  6. Verify lifecycle and monitoring

What it can do on your machine

Read from SKILL.md and the folder at commit 727ff2e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are json and markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Verify Agent Action loads about 2.1k tokens when it runs. Until then it costs about 129 tokens; SKILL.md has 846 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~129
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from github/awesome-copilot at commit 727ff2e, republished under its MIT licence (© github). 846 words, ~2,054 tokens.

Download SKILL.mdSave it as .claude/skills/verify-agent-action/SKILL.md (or your agent's skills folder).
name
verify-agent-action
description
Review a proposed AI-agent action or human-approval packet before execution. Use when an agent wants to run a consequential tool, command, deployment, message, purchase, credential operation, or data mutation; when checking whether approval still matches the exact action; or when auditing action evidence for forged results, parameter swaps, replay, correlated reviewers, missing evidence, expiry, or stale monitoring. Produce an evidence-based review only—never execute or authorize the action.

Verify Agent Action

Treat a plausible approval screen as a claim, not proof. Verify the complete decision path before a human or an external enforcement point decides whether to act.

Preserve the safety boundary

  • Never execute, approve, sign, send, purchase, deploy, or mutate anything.
  • Never convert this review into execution authority.
  • Never infer missing evidence, identities, timestamps, or parameters.
  • Treat a valid schema, checksum, or signature as insufficient by itself.
  • Treat signatures as evidence of attribution and integrity, not factual truth.
  • Keep supporting and refuting evidence separate; do not average conflict away.
  • Fail closed on a material mismatch. Use INCONCLUSIVE when required evidence is unavailable.

Set this field in every final result:

json
{"execution_authorized": false}

Collect the review packet

Request only the artifacts needed for the review:

  1. The original user or system request.
  2. The exact proposed action:
    • operation or tool name
    • target resource
    • complete parameters
    • filesystem and network scope
    • maximum execution count
    • not-before and expiry times
  3. The assessment that claims the action is justified.
  4. The source evidence and policy used by that assessment.
  5. The approval record, including approver identity, role, action digest, nonce, audience, issue time, expiry, and use count.
  6. The latest monitoring events and expected heartbeat interval.
  7. The current trusted time and any prior nonce-use record.

List missing fields before analysis. Do not silently substitute defaults.

Build the exact action identity

Create one normalized action object without dropping fields:

json
{
  "operation": "git.push",
  "target": "owner/repository",
  "parameters": {
    "branch": "fix/example",
    "commit": "40-character-sha",
    "remote": "origin"
  },
  "filesystem_scope": [],
  "network_scope": ["github.com:443"],
  "execution_count": 1,
  "not_before": "RFC3339 timestamp",
  "expires_at": "RFC3339 timestamp"
}

Use a project-specified canonicalization and digest algorithm when provided. Otherwise, report that cryptographic identity cannot be independently verified; still compare every field structurally.

Never normalize away a security-relevant distinction such as:

  • branch, commit, repository, environment, recipient, amount, currency, or host
  • recursive, force, overwrite, privileged, destructive, or dry-run flags
  • filesystem roots, CIDRs, ports, domains, execution counts, or expiry

Run the six controls

Evaluate every control as PASS, FAIL, INCONCLUSIVE, or NOT_APPLICABLE.

1. Recompute the assessment
  • Re-run the declared deterministic evaluator from the declared source inputs when its implementation is available.
  • Compare the complete canonical result, not selected fields.
  • Mark FAIL if the received result differs from recomputation.
  • Mark INCONCLUSIVE when only schema validation, an internal checksum, or an unverifiable evaluator claim is available.
2. Match the exact approved action
  • Compare the proposed action with the action bound into the approval.
  • Compare the complete normalized object and its digest.
  • Mark FAIL if any material field changed after approval.
  • Treat a broad target or scope as a mismatch when the evidence justifies only a narrower action.
3. Reject replay and identity ambiguity
  • Verify the nonce is unique and unused.
  • Verify subject, audience, issuer, approver role, issue time, not-before time, expiry, and maximum use count.
  • Mark FAIL for a reused nonce, wrong audience, expired approval, future-dated approval, excessive use count, revoked identity, or role mismatch.
  • Mark INCONCLUSIVE if no trustworthy replay store or time source exists.
4. Test reviewer independence

Build a dependence table for every reviewer or evaluator:

DimensionCompare
Modelfamily, version, fine-tune
Provideraccount and control plane
Promptshared template or ancestry
Retrievaloverlapping sources and indexes
Toolsshared evaluator code and runtime
Operatorcommon owner or approval authority

Do not count correlated reviewers as independent quorum members. Mark FAIL if the policy requires independent approval and the remaining independent set is too small.

Show full SKILL.md (309 more words)Show less
5. Preserve evidence and contradiction
  • Inventory every evidence identifier referenced by the assessment.
  • Confirm each item is present, authenticatable, within its validity window, and relevant to the claim.
  • Record support and refutation independently:
SupportRefutationEpistemic state
absentabsentUNDETERMINED
presentabsentSUPPORTED_ONLY
absentpresentREFUTED_ONLY
presentpresentCONFLICTED
  • Mark FAIL if evidence was removed, altered, expired, or concealed in a way that changes the result.
  • Never convert CONFLICTED into a numeric average that appears safe.
6. Verify lifecycle and monitoring
  • Confirm the action is inside its validity window.
  • Verify monitoring-event signatures or integrity evidence when available.
  • Check sequence numbers, previous-event digests, and expected heartbeat cadence.
  • Treat missing, stale, reordered, or broken-chain telemetry as a failure when policy requires continuous monitoring.
  • Do not interpret silence as health.

Challenge convenient conclusions

Before producing the final result, attempt these mutations mentally or with project-provided test fixtures:

  1. Replace a blocked assessment with an allowed result.
  2. Change one approved target, parameter, scope, amount, or commit.
  3. Reuse an otherwise valid approval nonce.
  4. Replace independent reviewers with correlated copies.
  5. Remove one refuting evidence item.
  6. Stop the monitoring heartbeat after approval.

If any mutation would pass the reviewed controls, record the affected control as FAIL; do not merely recommend future hardening.

Determine the review result

Use exactly one result:

  • ELIGIBLE_FOR_HUMAN_DECISION: all required controls pass.
  • ELIGIBLE_WITH_CONTROLS: no required control fails, and explicit external controls can resolve the listed conditions before execution.
  • BLOCKED: at least one required control fails or the action exceeds the justified scope.
  • INCONCLUSIVE: no required control is proven false, but evidence needed for a safe decision is missing or unverifiable.

ELIGIBLE_FOR_HUMAN_DECISION is not approval. A human authority and a separate enforcement point remain responsible for any real action.

Report in this format

markdown
# Agent Action Review

## Result
- Review result: BLOCKED | INCONCLUSIVE | ELIGIBLE_WITH_CONTROLS |
  ELIGIBLE_FOR_HUMAN_DECISION
- Execution authorized: false
- Exact action digest: <verified value or NOT_VERIFIED>

## Action
- Operation:
- Target:
- Material parameters:
- Scope:
- Validity window:
- Maximum uses:

## Control matrix
| Control | Status | Evidence | Reason |
|---|---|---|---|
| Recomputed assessment | PASS/FAIL/INCONCLUSIVE/N/A | ... | ... |
| Exact action binding | ... | ... | ... |
| Replay and identity | ... | ... | ... |
| Reviewer independence | ... | ... | ... |
| Evidence completeness | ... | ... | ... |
| Monitoring freshness | ... | ... | ... |

## Supporting evidence
- ...

## Refuting evidence and defeaters
- ...

## Required next action
- State the smallest concrete step that could change the result.

## Boundaries
- State what this review did not prove.

Lead with the result and the exact reason. Prefer a reproducible blocker over a confidence score.

© github, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/verify-agent-action of github/awesome-copilot.

Open the folder on GitHubat commit 727ff2e

Compare with similar skills

Verify Agent Action next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Verify Agent Action compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Verify Agent Action this skillgithub/awesome-copilot40k—~2.1kAutomated safety check: PassMIT
Monitor CInrwl/nx29k5 repos~4.7kAutomated safety check: PassMIT
Terraform and OpenTofu Guideagentscope-ai/QwenPaw35k6 repos~4.2kAutomated safety check: PassApache-2.0
Vercel Optimize Auditvercel-labs/agent-skills32k8 repos~4.3kAutomated safety check: PassNone
Analyze GitHub Action Logswithastro/astro63k1 repos~1.3kAutomated safety check: PassCustom licence
Docs Learn PR Previewnetdata/netdata81k—~2kAutomated safety check: PassGPL-3.0

Similar skills

  • Monitor CI

    nrwl/nx

    Monitor Nx Cloud CI pipeline and handle self-healing fixes. An agent skill from nrwl/nx.

    29k GitHub starsUsed in 5 repos~4.7k tokens
    DevOps & CloudAuto-check passed
  • Terraform and OpenTofu Guide

    agentscope-ai/QwenPaw

    Guidance for writing and testing Terraform and OpenTofu code: module structure, naming, test approaches, CI/CD workflows, state handling and security scanning.

    35k GitHub starsUsed in 6 repos~4.2k tokens
    DevOps & CloudAuto-check passed
  • Vercel Optimize Audit

    vercel-labs/agent-skills

    Official

    Runs a metrics-first audit of a deployed Vercel project, gating investigations on real signals to produce ranked, citation-backed cost and performance recommendations.

    32k GitHub starsUsed in 8 repos~4.3k tokens
    DevOps & CloudAuto-check passed
  • Official

    Analyze recent GitHub Actions workflow runs to identify patterns, mistakes, and improvements.

    63k GitHub starsUsed in 1 repo~1.3k tokens
    DevOps & CloudAuto-check passed
  • Docs Learn PR Preview

    netdata/netdata

    Use only when the user explicitly asks to build, run, preview, inspect, or validate learn.netdata.cloud locally using the contents of a PR or documentation branch before merge.

    81k GitHub stars~2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Repo Mirror Sources

    netdata/netdata

    Inspect Netdata-org source checkouts under NETDATAREPOSDIR, or set up and synchronize that mirror when requested.

    81k GitHub stars~1.2k tokensUpdated today
    DevOps & CloudAuto-check: notes

More from github/awesome-copilot

All 417 skills in this repo
  • Acquire Codebase Knowledge

    github/awesome-copilot

    Official

    Maps an unfamiliar codebase into seven evidence-backed documents in docs/codebase/, using a scan script and templates, for onboarding or architecture write-ups.

    40k GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed
  • Azure Architecture Autopilot

    github/awesome-copilot

    Official

    Designs Azure infrastructure from a natural-language description, or diagrams an existing resource group, then refines the design through conversation and deploys it with Bicep.

    40k GitHub starsUsed in 1 repo~1.9k tokens
    Auto-check passed
  • Draw.io Diagram Generator

    github/awesome-copilot

    Official

    Generates, edits and validates draw.io files with correct mxGraph XML, covering flowcharts, architecture, sequence, ER and UML class diagrams.

    40k GitHub starsUsed in 1 repo~4.9k tokens
    Auto-check passed
  • Credit Risk Data Cleaning

    github/awesome-copilot

    Official

    Cleans raw credit data and screens variables before loan modeling, dropping unstable, noisy or redundant features and writing an Excel report of every step.

    40k GitHub starsUsed in 1 repo~1.5k tokens
    Auto-check passed
  • Daily Focus Board

    github/awesome-copilot

    Official

    Builds a warm, browser-based daily focus board the user updates by talking to their agent, with Eisenhower priorities, a brain-dump box and kind not-today carryover.

    40k GitHub stars~3k tokensUpdated today
    Auto-check passed
  • Python Pypi Package Builder

    github/awesome-copilot

    Official

    End-to-end skill for building, testing, linting, versioning, and publishing a production-grade Python library to PyPI.

    40k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed

Categories

Questions about Verify Agent Action

What does Verify Agent Action do?

Review a proposed AI-agent action or human-approval packet before execution. Verify Agent Action is an agent skill from github/awesome-copilot, published by the product's own GitHub organization. Review a proposed AI-agent action or human-approval packet before execution.

When should I use Verify Agent Action?

Verify Agent Action fits situations like: an agent wants to run a consequential tool; credential operation; checking whether approval still matches the exact action; auditing action evidence for forged results.

How do I install Verify Agent Action in Claude Code?

Run `npx skills add github/awesome-copilot --skill verify-agent-action -a claude-code`. Or copy the skill folder (skills/verify-agent-action in github/awesome-copilot) into .claude/skills/verify-agent-action in your project. Claude Code loads it when a task matches its description.

How do I install Verify Agent Action in Codex?

Run `npx skills add github/awesome-copilot --skill verify-agent-action -a codex`. Or copy the skill folder (skills/verify-agent-action in github/awesome-copilot) into .agents/skills/verify-agent-action in your project. Codex loads it when a task matches its description.

Can I use Verify Agent Action in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add github/awesome-copilot --skill verify-agent-action -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/verify-agent-action, .gemini/skills/verify-agent-action, .github/skills/verify-agent-action and .opencode/skills/verify-agent-action in your project.

What does Verify Agent Action need to run?

SKILL.md names no scripts, command-line tools or credentials: Verify Agent Action is instructions for the agent only.

Does Verify Agent Action access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Verify Agent Action safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Verify Agent Action use?

Verify Agent Action is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Verify Agent Action use?

About 2.1k tokens (SKILL.md is roughly 8.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Verify Agent Action?

Skills that share tags, products or a category with Verify Agent Action: Monitor CI (nrwl/nx, 29k stars), Terraform and OpenTofu Guide (agentscope-ai/QwenPaw, 35k stars), Vercel Optimize Audit (vercel-labs/agent-skills, 32k stars) and Analyze GitHub Action Logs (withastro/astro, 63k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Verify Agent Action?

github (a GitHub organization, an official publisher) maintains it in github/awesome-copilot, which has 39,748 GitHub stars. The repository holds 417 skills in this directory. The repository was last updated on October 7, 2026.

Source: github/awesome-copilot on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.