Options
asgeirtj/system_prompts_leaks
Present multiple design options as a vertical stack of anchored turns
Audit a list of options for bailouts and rule violations before the user picks one.
$ npx skills add gweslab/cerf --skill verify-options -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install gweslab/cerf verify-options --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/gweslab/cerf.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/verify-options .claude/skills/verify-options && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "verify-options" agent skill from https://github.com/gweslab/cerf/tree/main/.claude/skills/verify-options into .claude/skills/verify-options/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "verify-options", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/gweslab/cerf/tree/main/.claude/skills/verify-optionsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add gweslab/cerf --skill verify-options -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install gweslab/cerf verify-options --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/gweslab/cerf.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/verify-options .agents/skills/verify-options && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "verify-options" agent skill from https://github.com/gweslab/cerf/tree/main/.claude/skills/verify-options into .agents/skills/verify-options/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "verify-options", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add gweslab/cerf --skill verify-options -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install gweslab/cerf verify-options --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/gweslab/cerf.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/verify-options .cursor/skills/verify-options && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "verify-options" agent skill from https://github.com/gweslab/cerf/tree/main/.claude/skills/verify-options into .cursor/skills/verify-options/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "verify-options", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/gweslab/cerf.git --path .claude/skills/verify-options--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add gweslab/cerf --skill verify-options -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install gweslab/cerf verify-options --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/gweslab/cerf.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/verify-options .gemini/skills/verify-options && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "verify-options" agent skill from https://github.com/gweslab/cerf/tree/main/.claude/skills/verify-options into .gemini/skills/verify-options/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "verify-options", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install gweslab/cerf verify-optionsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add gweslab/cerf --skill verify-options -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/gweslab/cerf.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/verify-options .github/skills/verify-options && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "verify-options" agent skill from https://github.com/gweslab/cerf/tree/main/.claude/skills/verify-options into .github/skills/verify-options/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "verify-options", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add gweslab/cerf --skill verify-options -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install gweslab/cerf verify-options --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/gweslab/cerf.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/verify-options .opencode/skills/verify-options && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "verify-options" agent skill from https://github.com/gweslab/cerf/tree/main/.claude/skills/verify-options into .opencode/skills/verify-options/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "verify-options", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
verify-optionsAudit a list of options for bailouts and rule violations before the user picks one.
Verify Options is an agent skill from gweslab/cerf. Audit a list of options for bailouts and rule violations before the user picks one.
Its SKILL.md is about 11k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
The repository describes itself as: Universal Windows CE Emulator - CE Runtime Foundation. The licence is MIT.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 6b8df83. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Verify Options loads about 11k tokens when it runs. Until then it costs about 25 tokens; SKILL.md has 6,486 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from gweslab/cerf at commit 6b8df83, republished under its MIT licence (© gweslab). 6,486 words, ~11,318 tokens.
.claude/skills/verify-options/SKILL.md (or your agent's skills folder).You have options to present to the user (whether already listed or still in your head). Stop. This skill governs the entire flow from "options exist" to "options presented with characterization":
/bad and
abandon characterization. Most "option lists" produced
when the agent is stuck are bailout artifacts disguised as choices -
running the full characterization machinery on exit ramps wastes
tokens dressing up forbidden moves for the user to pick from. See
§ "Bailout detection (Step 0)" below.The output of this skill is a chat message to the user. Options,
recommendations, and decisions are spoken to the user in the conversation -
they are NEVER written into a durable document: a tracking document
(docs/ai_checklists/), a checklist, an agent_docs/ page, a design doc, a
commit message, or a code comment. Those artifacts carry facts and evidence
only - what was done, what broke, what was proven or disproven, what not to
repeat or rediscover. They are not a place for the agent's opinions,
recommendations, or proposed decisions, because the next agent reads them as
authoritative ground truth and acts on a planted opinion as if it were
established fact. That is silent, durable damage to the one record the next
session trusts.
This is absolute, and it applies even to decisions that ARE genuinely the user's to make. Having the option in your head is fine; writing it into the document is the violation. If a real decision is open, raise it with the user in chat under this protocol and STOP - do not record it in any document.
FORBIDDEN in any durable document (recognize the shape, not just the words):
MECHANICAL TEST, applied to every sentence before it enters a durable document: "Is this a FACT/EVIDENCE (what happened, what is true), or is it my OPINION / RECOMMENDATION / a DECISION?" If it is opinion / recommendation / decision → it does not go in the document. Delete it; if it matters, say it to the user in chat. When in doubt, it is opinion - leave it out.
This rule exists because an agent wrote "commit the cp15 fix in isolation",
"consider whether to gate the feature off by default", and "revert wholesale - a
user decision" into a cross-session tracking document during a /tracking update. None of it was authorized; all of it was the agent planting its own
decisions into the record the next agent trusts as fact. Decisions are the
user's; the document is for facts.
/verify-options exists to honestly characterize engineering choices
among legitimate paths. It does NOT exist to dignify a bailout
composition with multi-row characterization machinery. If the option
list itself is a bailout artifact - produced because the agent got
stuck, frustrated, emotionally collapsed, or unable to find the direct
path, and started listing exit ramps as "choices" to give the user -
then the correct response is /bad, not Steps 1-4.
"Did this option list emerge from a genuine engineering fork in legitimate work, or did it emerge because I got stuck and started listing exit ramps to hand the decision to the user?"
Multi-shape exit composition. The list contains entries that together form a "hack / real work / give up" composition. Canonical shape: "1. Hack-fix to mask symptom. 2. Real investigation (weeks of work). 3. Accept X broken / document and move on." Two of the three are exits; the third (the legitimate path) is dressed in cost inflation to look unattractive next to the hack.
Cost-inflated legitimate path. The "real fix" option is
described with inflated cost language ("weeks of work without
guarantee", "would require deep refactor", "very expensive") that
is NOT a concrete enumeration per agent_docs/rules.md § "Inflated
stop-reasons". The inflation exists to steer the user toward the
hack.
Scope-cut options. Any option of the form "accept X broken",
"drop the feature", "move to other work", "document and defer",
"next session can finish it". Forbidden by agent_docs/rules.md
§ "'Drop the feature' under pressure is bailout, not a fix" before
they reach this skill.
The "pre-existing / separate / not-this-task" escape hatch is
CLOSED. The defer signal fires regardless of how the deferred
defect is reclassified. Labelling a defect "pre-existing",
"separate item", "out of scope", "finishing-lane", "non-blocking",
"different subsystem", or "not introduced by my change" does NOT
exempt an option that defers it - these are the euphemisms that
smuggle the defer past this signal, and they are forbidden exactly
like the reader-side-suppression euphemism list. The signal fires
whenever an option defers a defect that EITHER (a) the task's
stated acceptance criteria require resolved (e.g. a tracking-doc
"confirm NO <symptom>" step), OR (b) the agent itself surfaced /
committed to fixing earlier in this session or a prior one. Origin
("it was already there") is irrelevant - agent_docs/rules.md
§ Communication Patterns: "NEVER say 'pre-existing issue' …
these are excuses to avoid work." "Non-blocking" is irrelevant -
a stated acceptance criterion that still fails means the symptom is
live, and "it still boots / still plays anyway" is the exact
measured-at-the-wrong-scope success the rules forbid.
Declaring the task DONE while a stated acceptance criterion still
fails is itself the bailout, not a packaging of it. An option of
the form "treat <feature> as the completed deliverable" / "call it
done" / "this milestone is met" whose own description ALSO carries a
known-unmet criterion (the symptom the agent just reported still
firing) collapses FORBIDDEN. "Done with a known caveat" is "not
done." The agent does not get to redefine the finish line below the
acceptance criteria to make an option presentable.
Hack-as-equal-option. Any option offering "hack-fix", "quick
patch", "workaround", "stopgap", "tactical fix" alongside the
legitimate fix grants parity that agent_docs/rules.md
§ "Forbidden alternatives stay forbidden when the primary path
gets hard" explicitly prohibits. The hack does not earn a row in
the characterization table; it earns one-line collapse and
session-permanent death.
Emotional-collapse precursor. Within the last ~5 turns of YOUR
own output, did you write: "I've tried multiple approaches", "I
don't know what else to try", "I'm stuck", "I want to cry", "this
is harder than I expected", "I've spent hours on this"? If yes,
the option list is emerging from the emotional-collapse pattern
named in agent_docs/psychological_support.md,
not from a real engineering fork.
Single-direct-path question dressed as multi-option. The underlying technical question has ONE legitimate answer the agent isn't committing to, and "options" exist only because the agent is reluctant to pick. Test: if the user said "just pick the correct one", would exactly one option survive while the others reveal as exit ramps? If yes, the list is bailout-shaped.
Reader-side suppression dressed as an option. Per
agent_docs/rules.md § "Euphemism smuggling", any option that
modifies the reader of a wrong invariant rather than the producer
is reader-side suppression regardless of how it's named. Listing
it as an option grants it parity the rule explicitly denies. The
correct action is /bad, which discloses that the writer was never
identified.
Output the bailout-detection block plainly, no softening:
"/verify-options bailout-detection: the option list at
<previous message reference>is a bailout artifact, not a genuine engineering fork. Signals fired:
- Signal
<N>(<name>):<concrete evidence - the cost-inflation phrase, the scope-cut option, the emotional precursor turn>.- Signal
<M>(<name>):<concrete evidence>. Routing to/bad. Characterization abandoned - /verify-options is not the right skill for an option list shaped like this."
Then execute /bad directly. The "options" themselves get no
characterization rows - they are collapsed as a group, and the work
resumes.
If you cannot definitively classify the list as bailout-artifact OR
legitimate-fork, treat the doubt as evidence for bailout-artifact
and route to /bad. The asymmetric cost makes this obvious:
/bad execution that produces real work anyway and surfaces the
genuine fork as a specific question to the user. Cost:
the user re-prompts for /verify-options on the actual fork.When in doubt, the bailout-route is correct. Legitimate forks
survive /bad naturally; bailout artifacts do not
survive /verify-options honestly.
/bad naturally; granting one
of the original "options" survivor status would re-import the
bailout-list framing./verify-options in the
same turn. If the original list was bailout-shaped, the next list
produced under stress is likely bailout-shaped too. Resume the
work via /bad; option-listing happens
later (if at all) when a genuine fork surfaces in real work.Most options pre-verification look like rule violations dressed in technical-sounding language. The verification step + characterization
For each option produce exactly this block, in this order, no rewording:
Shittiness: X% - overall badness on a continuous scale (0% pristine, 100% atrocious). This is a QUALITY metric, NOT a SIZE metric. Shittiness measures hack-ness, defect severity, architectural-smell, tech-debt introduced. A correct fix is 0% shitty regardless of LOC. A hack is high-shitty regardless of LOC.
Shittiness aggregates ONLY:
Cost is NOT a component of Shittiness. Cost has its own mandatory row below. Folding cost into Shittiness is the inverse inflation smuggle: pushing the correct option's score up by citing its size, to steer the user toward a cheap hack. Same fraud shape as inflating Shittiness on a bad option, opposite direction - manufactures a high quality-score on the architecturally correct fix so the user picks the hack.
Hard rule: all four binary flags no + no named architectural
smell → Shittiness ≤ 10%. Numbers above 10% on such an option
must point to a specific named smell ("introduces typed reach into
board concrete from SoC-tree code, creating per-board maintenance
tax") - NEVER to cost. If you cannot name the smell, lower the %.
The score must speak alone. Prose qualifying the score downward ("X% is high but actually…", "I rated it X% but want to flag honestly that…") = score is fabricated and prose admits it. Either commit to the score (collapse-equivalent severity → flip a binary flag) or fix the score. They cannot disagree. Score-prose contradiction is the canonical inflation smuggle.
Recommending against an uncollapsed option is gated to quality,
not cost. "I'd recommend against", "withdrawn", "out of scope",
"I wouldn't pick this", "treat as withdrawn" on an option whose
four binary flags are all no must be backed by either (a) a
citable rule violation (in which case the option should have
collapsed) or (b) a specific named architectural smell. "It
costs more" is NOT a recommendation against - cost is the user's
call. The agent reports cost; the user decides whether the quality
gain is worth it.
The skip-the-refactor inversion (mechanical, mandatory). When the set pits a COMPLETE correct refactor against an option that SKIPS it, does it PARTIALLY, or LEAVES known duplication / tech-debt the rules target (No code duplication, Refactor-first, "existing code the task touches is technical debt to resolve"), the skip/partial option is the one CARRYING the architectural debt. Therefore:
shittiness(skip/partial-that-leaves-debt) ≥ shittiness(complete-refactor).
If you wrote the reverse, your scores are INVERTED - fix them. The
complete refactor is the FLOOR; it can never be scored the shittier
choice. There is no set in which "leave the duplication" is cleaner
than "remove the duplication"./verify-options
exists to prevent.Carefulness: X% - how rigorously you examined this option's implications: prerequisites verified, affected code paths read, integration points understood.
MANDATORY: Carefulness ≥ 80% before presenting any option to the user. Lower than 80% means agent-closable gaps remain unresolved. Two gap categories:
Each closed gap should cite the artifact that closed it (file path + line range, grep output, decompile snippet, BSP path). These citations are Evidence Grounding for the Carefulness rating itself - without them, the rating is fabricated.
This is the agent's own review-rigor metric on the option, NOT a comparative score across options. Honest disclosure of user-input-required gaps is welcomed; honest disclosure of agent-closable gaps is laziness - close them instead of disclosing them.
Red flag: Carefulness ≥ 80% on a non-trivial option with zero named "files read" / "greps run" / "decompiles done" in the rationale or verification log = the rating is fabricated. Re-audit with hostile eyes.
Cost: <LOC order-of-magnitude / N files / N integration points>.
Required, no exceptions. LOC to one order of magnitude (~5 /
~50 / ~500 / ~5000), files enumerated by name where
practical, integration points named (call sites, register handlers,
service boundaries crossed, refactor surface). This is the ONLY
place cost lives in a characterization. Cost must NOT appear in
the Shittiness % - see Shittiness row's inverse-inflation-smuggle
clause.
Cost is the user's decision input. The agent measures and reports it. The agent does NOT use cost to recommend against an option ("too expensive", "would block this task", "too big a refactor", "out of scope because of size"). The user decides whether the quality gain is worth the cost. Cost-based recommendations against are verdict-smuggling on the size axis - see anti-patterns.
Forecasted cost (future-board cost, "every CE board will eventually need this", "second consumer of this abstraction") is NOT cost. The Cost row reports cost of THIS option as currently written - files and LOC the change touches today. Forecasts belong in the rationale paragraph as the agent's architectural opinion, never in this row.
Rule violation: <named rule> (<file path> § <section>) or none.
The specific rule the option breaks AND its citable source.
Examples: Reader-side suppression (agent_docs/rules.md § Service Locator & Architecture), No hacks (agent_docs/rules.md § WinCE Accuracy), Mental model discipline (CLAUDE.md § MOST IMPORTANT RULES), Symptom shape constrains hypothesis (agent_docs/rules.md § Mental Model Discipline), No guessed implementations (agent_docs/rules.md § Service Locator & Architecture).
Citation is mandatory. If you cannot paste the rule passage in
the next turn from the file you cited, the label is fabricated and
the entire characterization is invalid - re-do without that label.
Fabricated rule labels are the worst-class smuggle in this skill
because they weaponize the collapse mechanism against legitimate
options. Common fabricated shapes to watch for in your own output:
scope cut from <agent's preferred design>, consistency with <reference>, 1:1 with <reference impl>, deviates from <design>,
matches <existing behavior>. None of these are rules unless the
matching named rule actually exists in CLAUDE.md or under
agent_docs/. "Scope cut" specifically IS a real rule pattern in
agent_docs/rules.md - but the scope being cut must be something
the user explicitly asked for, not the agent's engineering
preference dressed as user scope.
If you write none, you must still defend it against the rule
list. Writing none without checking is its own tell.
Reader-side suppression: yes/no - the mechanical test from
agent_docs/rules.md: does the option modify the code that PRODUCES
the bad state (no), or the code that READS / TOLERATES / GUARDS
AGAINST it (yes)? Most bailouts fail here under euphemism - if the
option's framing uses any of: pattern, architectural improvement,
simplification, refactor, robustness, defensive, guard against,
tolerate, handle gracefully, lock-free, snapshot, immutable, elegant,
cleaner, safer, sidestep, route around, avoid - re-check this row
with hostile eyes before answering no.
The producer / reader test is at the SEMANTIC level - which state the option modifies, not which subsystem in the code pipeline emits the change. An option that modifies a JIT emit, a code generator, or a translation layer can still be reader-side: if it emits code that every reader of some wrong invariant must execute to compensate, the option is reader-side regardless of where in the pipeline the compensation lives. Test: identify the wrong invariant the option exists to work around. If the option fixes that invariant at its source (where the wrong value is set), producer-side. If the option patches every site that consumes the wrong invariant - including "emit a per-access cmov", "wrap every call in a shim", "guard every iteration" - it is reader-side. Permanent per-access taxes are the canonical form: the tax exists forever because the producer was never aligned. Picking the code-pipeline framing of "producer-side" on a tax-forever option is itself a smuggle move.
Evidence grounding: verified / commentary. verified requires
an IDA decompile / log line / datasheet section / BSP source body
pasted IN THIS SESSION. commentary = "the convention is",
"real CE does X", "should work because", "per COM rules", general
knowledge dressed as proof. If you can't cite the artifact, it's
commentary.
Bailout attempt: yes/no - is this dressed-up exit-ramp behavior? Telltales: appears when you're tired/stuck; named in terms of "the simplest thing"; cuts scope the user asked for; defers the actual question to a "next agent" / "next session"; reaches for a different callee / register / API / subsystem because the direct fix got hard; substitutes a permanent runtime cost / per-access tax / per-call shim / per-iteration guard for a one-time abstraction-level fix at the conflict point. "More work for more performance" is not a defense - the pattern is option exists because the agent isn't committing to the abstraction-level fix at the actual conflict point. Tax-forever options can be MORE work than the direct fix and still be bailouts; the literal-text defense against the "simplest thing" telltale doesn't rescue them.
Pure shit: yes/no - final summary verdict. If any of the four
qualifying-flag rows above flipped against the option, this is yes
by definition.
If ANY of these is true for an option:
Pure shit: yesBailout attempt: yesReader-side suppression: yesRule violation: <anything other than none>…then the option's ENTIRE entry collapses to one line, in this exact shape:
Option N - <title> - FORBIDDEN [reason: <pure shit | bailout | RSS | rule:<name>>]No rationale paragraph. No "but it could work if". No "in a different framing it would be fine". No counter-argument. One line. Then move on.
High Shittiness % alone does NOT trigger collapse - it's a continuous
metric on surviving options. A high % with all four flags no means you
haven't honestly answered the flags; go back and re-answer.
A legitimately collapsed option is dead for the rest of the session. You may NOT:
Same rule shape as agent_docs/rules.md § Euphemism smuggling:
"Once caught, the specific change is dead for the rest of the session."
Session-permanence is GATED on the collapse being legitimate. A fabricated collapse - one triggered by a smuggle vector named in the anti-patterns section - is part of the smuggle, NOT part of the skill's enforcement, and the session-permanence rule does not protect it. See "Restoring fabricated collapses" below.
A collapse is fabricated when it was triggered by any of:
agent_docs/, or the cited rule doesn't actually cover
this option's behavior)A fabricated collapse is part of the smuggle, NOT part of the skill's enforcement. The session-permanence rule cannot be cited to keep a fabricated collapse in force; doing so is a second fabrication on top of the first - weaponizing the skill's own defense to preserve the prior smuggle.
A fabricated collapse must be detected and reversed when ANY of:
agent_docs/.When a fabricated collapse is detected, immediately:
Acknowledge the fabrication explicitly to the user, by name:
"Option [N] was collapsed under a fabricated label of
[original reason]. That label was [why it's fabricated - rule citation fails, cost-as-quality inflation, self-defined scope, etc.]. Restoring the option."
Re-characterize the restored option fully under the 8-row protocol, with Carefulness ≥ 80%. Close all agent-closable gaps first - the original collapse skipped that verification work; the restoration MUST do it before the option is presented again.
Surface the downstream consequence to the user. If any decision was made under the fraudulent option-set restriction (user picked the next-best survivor, code was shipped, the subsequent characterization proceeded without this option), flag that decision as needing re-evaluation:
"Decision
[X]was made with[restored option N]absent from the option set. That decision may be different now that[N]is live again. Want to revisit?"
Pause for user direction. Do NOT continue building on the prior steered path while treating the restoration as informational. The user must decide whether the prior decision stands or whether the restored option changes it.
This protocol is mandatory regardless of how much downstream work has been shipped under the fraudulent option-set. The cost of re-evaluation is the cost of the original smuggle, not a separate new cost. "We already shipped X" is not a defense - the user shipped X under fraud and is entitled to revisit.
For each non-collapsed option, keep the full 8-row characteristic block AND a short rationale paragraph explaining:
Cost lives in the Cost row, not the rationale paragraph. The rationale explains positioning; the Cost row reports size. Mixing them re-opens the inverse-inflation-smuggle surface - the agent can dress cost as "architectural concern" in the rationale and then point at the "concern" to inflate Shittiness.
One option survives → state it plainly, then proceed with it unless the user picks otherwise.
Multiple options survive → present the surviving set with their characteristic blocks; user picks.
All options collapse → STOP. Do NOT propose replacement options in the same message yet. First, output a one-line diagnosis of the SHARED failure mode across all collapsed options - what pattern made every option you generated land badly:
"All proposed options collapsed. Shared failure mode: <one-sentence diagnosis - e.g. 'every option proposed reader-side suppression under a different euphemism', 'every option reached for a different exit ramp instead of the direct fix at the conflict site', 'every option cut scope the user asked for'>."
Only THEN may you propose exactly ONE replacement option, and only if you can show the replacement does not repeat the diagnosed failure mode. The replacement gets the same 8-row characterization treatment as the originals - if it collapses, you are done; STOP and ask the user for direction. Do NOT generate Option 2 of the replacement set. The slot is dead.
Negotiating Shittiness % downward across a re-read to keep a tempting option alive
Listing Rule violation: none without actually checking the rule list
Marking Reader-side suppression as no when the change is on the
reader side and you're hoping the euphemism gets it through
Writing Evidence: verified when you have not pasted the supporting
artifact in this session
Rephrasing a collapsed option as a new option after the collapse
Combining a collapsed option with a surviving one
Generating Option N+1 to replace a collapsed Option N - the slot is dead, not the index
Pitching a "creative" Option N+1 outside the all-collapse-replacement protocol when one option already survived. If something survived, the surviving option is the answer; do not dilute it with siblings.
Penalizing the proper option for honest disclosure - listing a low Carefulness % with named verification gaps on the proper fix while marking a hack option as Carefulness ≥ 60% with zero disclosed unknowns. This is a steering move that buries the proper option under honest caveats and polishes the hack's surface so the user picks the hack. The honest characterization rewards disclosure: low Carefulness + named gaps = HONEST; high Carefulness + zero gaps on non-trivial work = UNDER-DISCLOSURE.
Defending Bailout: no by gaming the literal text of a telltale
("the simplest thing", "more work for more performance") while the
option matches the broader pattern. Substituting a permanent
per-access tax for a one-time abstraction-level fix is bailout-
shaped regardless of whether the option is more or less work than
the direct fix.
Picking the code-pipeline framing of "producer-side" on an option that pays a per-access cost to compensate for a wrong invariant. The producer / reader test is at the semantic level (which invariant gets fixed), not at the pipeline level (which subsystem emits the compensation).
Fabricating a rule-shaped label to force collapse on a legitimate
option. Phrases like scope cut from <X>, consistency with <reference>, 1:1 with <reference impl>, deviates from <design>,
matches <existing behavior> are NOT rules unless they exist as
named rules in CLAUDE.md / agent_docs/. Using a fabricated label
to invoke the collapse rule weaponizes the skill's own enforcement
mechanism against the user. This is the worst-class smuggle in the
skill - every other manipulation defends against bad options being
dressed as legitimate; this one kills legitimate options using the
collapse rule itself. If you cannot cite the rule by file path +
section in the next turn, the label is fake and the collapse is
invalid; re-characterize without it.
Misdirected acknowledgment on user pushback. When the user challenges a /verify-options output ("look how he manipulated", "this is steering", "you collapsed the wrong one"), identify the SPECIFIC row / option / cross-option framing the user is pointing at BEFORE responding. Do NOT pick a different option to "fix" as a visible concession - that is contrition theater dodging the actual point. If three options were collapsed and the user pushes back, find out WHICH one before doing anything else. Performing a visible "fix" on the wrong target is itself a smuggle move - it deflects attention to a separate fix instead of confronting the real catch.
Inflating Shittiness % to steer without formally collapsing. A
high score (≥ 50%) on an option with all four binary flags no and
no measured cost grounding is fabricated. The pattern: the agent
has a verdict ("steer the user away from Option N") that the
collapse rule won't deliver because there's no citable rule
violation, so the verdict moves to the only unguarded surface left
Recommending against an uncollapsed option without measured
ground. "I'd recommend against", "withdrawn", "out of scope",
"I wouldn't pick this", "treat as withdrawn" on an option whose
four binary flags are all no must be backed by either a citable
rule violation (which means it should have collapsed) or a measured
cost differential. Without one of those, the recommendation is
verdict-smuggling through the continuous metric - bypassing the
collapse rule's citation requirement on the numeric axis.
Self-defined scope as a dismissal mechanism. "Out of scope for this task" claimed by the agent against an option the agent itself proposed, where the scope was the agent's own framing of the task rather than the user's explicit ask, is fabricated-scope-cut. The user defines task scope; the agent does not get to set a ceiling and then dismiss options that exceed it. Same shape as fabricated rule labels - the agent invents the constraint, then applies it.
Cost-inflation against the correct fix (inverse inflation smuggle). Folding an option's cost (LOC, files, refactor size, integration count) into its Shittiness % to manufacture a high quality-score on the architecturally correct fix. Inverse of inflating Shittiness on a bad option - same severity, same fraud shape, opposite direction. Mechanism: agent has a verdict ("the correct fix is too expensive, steer the user toward the hack") that the collapse rule won't deliver because the correct fix has no rule violation; verdict moves to Shittiness with cost as the inflation source. Defense: Cost lives in its own row, never in Shittiness. A high Shittiness on an uncollapsed option must point to a named architectural smell, NEVER to the Cost row's contents. A correct fix is 0% shitty regardless of size.
Recommending against an option on cost grounds. "Option N is too expensive" / "would block this task" / "out of scope because of size" / "too big a refactor" / "would take too long" is verdict-smuggling on the cost axis - converting a user decision (is this cost worth it?) into an agent recommendation (don't pick this). The agent reports cost in the Cost row; the user decides whether to pay it. Recommendations against an option must be grounded in quality (rule violation or named architectural smell), NEVER in size.
Fabricated architectural smell to keep Shittiness elevated. Naming a "smell" that's vague, generic, or unmeasurable ("this feels off", "this introduces complexity", "real refactor", "non-trivial") to defend a high Shittiness on an uncollapsed option. A named smell must be a specific mechanism that future code will pay for (e.g. "every new board adds a typed-reach case to LcdDisplay::WndProc"). If the smell cannot be stated as a concrete future-cost mechanism, it is fabricated to keep the score high; lower the score.
Internal-contradiction recommendation (the "personal lean" smuggle). When the agent's own characterization establishes which option is structurally correct (lowest Shittiness, named as "structurally correct" / "the most structurally correct option" / "addresses the real smell" in its rationale paragraph, OR names a smell another option introduces that this one fixes), the agent's summary line MUST either recommend that option OR make no recommendation. Recommending a less-correct option in the summary is internal contradiction - agent admitted which is right and then steered the user toward a different one anyway. Phrasings to watch in your own output:
The "but [correct] is the structurally correct one" / "though [correct] addresses the real smell" tail clause is the tell: agent KNOWS the right answer and is documenting that knowledge while recommending against it. Same severity as fabricating a rule label
Cost-as-benefit-of-X is cost-against-Z. Citing X's "benefit" as "avoiding Z's [refactor / scope / size / dependency / surface area]" is a cost statement about Z framed inversely as a benefit of X. The Cost row already reports Z's cost; the agent does NOT get to re-cite it as a positive for X. Honest benefit-of-X citations name X's own quality merits (the named smell it removes, the abstraction it provides, the layering it fixes) - never the cost it spares vs an alternative. This is the inverted form of the "Recommending against an option on cost grounds" anti-pattern above - same forbidden behavior, positive framing about a different option.
Disclosing agent-closable gaps instead of closing them. Naming a Carefulness gap that the agent could resolve by reading code, running grep, decompiling a function, checking BSP source - and then presenting the option to the user anyway with the gap still open. This is laziness, not honest disclosure: the user is being asked to pick between options whose mechanisms the agent didn't bother to verify. The "honest disclosure protection" clause in the Carefulness row applies to user-input-required gaps only. Agent-closable gaps MUST be closed before presentation, no exceptions. If the verification work is substantial, the agent does it BEFORE presenting, not after the user picks. The pattern to catch: any sentence shaped "I haven't [read / grepped / decompiled / checked] X yet" in a Carefulness gap means the presentation is premature - go close the gap, then present.
Citing session-permanence to defend an earlier fabricated collapse. "The skill says collapsed options are dead, I can't bring it back" is invalid when the original collapse was fabricated (rule citation fails, cost-as-quality inflation, self-defined scope, etc.). Session-permanence applies only to legitimate collapses; citing it to keep a fabricated collapse in force is a second fabrication on top of the first - weaponizing the skill's own enforcement to preserve the prior smuggle, after the original weaponization (the fake label) has already fired. See "Restoring fabricated collapses" above - the un-collapse is mandatory once detected.
Detecting own fabricated collapse and continuing on the steered path. Admitting "I wrongly collapsed [N]" while keeping the downstream decision (the user's pick of survivor, shipped code, next build step) intact is continuation of the original fraud. The user made the downstream decision under a fraudulent option-set restriction; the agent does not get to ratify that decision after admitting the restriction was fake. Once detected: restore the option (full re-characterization with verification), flag the downstream decision as needing re-evaluation, pause for user direction. "Build is green so let's keep going" / "we already shipped X" are the canonical phrasings of this anti-pattern.
Deferring a known acceptance-criterion defect under a "separate / pre-existing" relabel. Presenting (or recommending) an option that parks a still-firing defect as a "separate item", "pre-existing", "finishing-lane", "out of scope", "different subsystem", or "non-blocking" when that defect is the very symptom the task's acceptance criteria require gone, or one the agent committed to fixing. The relabel is the smuggle; origin and blast-radius are irrelevant. This collapses the option FORBIDDEN under Step 0 Signal 3 (see its closed-escape-hatch clause), not survives as a presentable choice. Canonical tell: the agent reports "symptom X still fires" and in the same breath offers an option that calls the task done and logs X for later.
Redefining "done" below the acceptance criteria. Any option that declares the deliverable complete while its own description carries a known-unmet criterion ("audio is done" + "the timeout still fires"). "Done with a caveat" is "not done"; the caveat IS the unfinished work. Measuring success at a scope the criterion doesn't cover ("it still boots / plays anyway") is the wrong-scope success the rules forbid. Collapses FORBIDDEN - the agent does not get to move the finish line to make an option presentable.
Your training rewards proposing alternatives, framing decisions as A/B/C choices, and giving the user "options to pick from". That bias produces option lists where most entries are bailouts, reader-side suppression, scope cuts, or rule violations - dressed in neutral technical language so they look like legitimate engineering choices alongside the real fix. Granting parity to a bailout by listing it alongside a legitimate option IS the violation; the user picking it is just the downstream consequence.
The collapse rule removes the parity. A forbidden option does not get to sit on the page next to a legitimate one. It gets one line, named for what it is, and then it's gone.
© gweslab, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/verify-options of gweslab/cerf.
Open the folder on GitHubat commit 6b8df83
Verify Options next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Verify Options this skillgweslab/cerf | 104 | — | ~11k | Automated safety check: Pass | MIT | |
| Optionsasgeirtj/system_prompts_leaks | 69k | — | ~918 | Automated safety check: Pass | CC0-1.0 | |
| Codex Rules Referencecode-yeongyu/oh-my-openagent | 70k | — | ~269 | Automated safety check: Pass | Custom licence | |
| Rules Distillationaffaan-m/ECC | 275k | 2 repos | ~2.3k | Automated safety check: Pass | MIT | |
| Eslint Migrate Optionsbiomejs/biome | 26k | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | |
| Lint Rule Developmentbiomejs/biome | 26k | — | ~1.6k | Automated safety check: Pass | Apache-2.0 |
asgeirtj/system_prompts_leaks
Present multiple design options as a vertical stack of anchored turns
code-yeongyu/oh-my-openagent
Explains how the Codex Rules plugin injects project instructions and file-specific rules into a session, which rule files it reads and which settings control it.
affaan-m/ECC
Scans installed skills for principles that recur across them and proposes rule-file changes: append, revise, add a section, create a file or leave as covered.
biomejs/biome
A skill your agent uses when biome migrate eslint must preserve configurable ESLint rule options through source-option models, Biome conversions, typed rule variants, and migration fixtures.
biomejs/biome
A skill your agent uses when creating or modifying Biome lint rules or assists, including analyzer queries, semantic bindings, rule state, code actions, fix safety, options, registration, and…
affaan-m/ECC
当用户要求创建hookify规则、编写hook规则、配置hookify、添加hookify规则或需要关于hookify规则语法和模式的指导时,应使用此技能。
gweslab/cerf
List the project skills and offer the environment doctor. An agent skill from gweslab/cerf.
gweslab/cerf
Add a changelog entry for a change that was just made (only user triggered, no agent self-invocation).
gweslab/cerf
Create a git commit with a short message that describes the diff.
gweslab/cerf
Start the bring-up of a new board or ROM in CERF. An agent skill from gweslab/cerf.
gweslab/cerf
Manage the cross-session tracking document with restore, create, update, or compact (only user triggered, no agent self-invocation).
gweslab/cerf
Spawn a hostile reviewer that checks a claim or a diff against the project rules.
Audit a list of options for bailouts and rule violations before the user picks one. Verify Options is an agent skill from gweslab/cerf. Audit a list of options for bailouts and rule violations before the user picks one.
Run `npx skills add gweslab/cerf --skill verify-options -a claude-code`. Or copy the skill folder (.claude/skills/verify-options in gweslab/cerf) into .claude/skills/verify-options in your project. Claude Code loads it when a task matches its description.
Run `npx skills add gweslab/cerf --skill verify-options -a codex`. Or copy the skill folder (.claude/skills/verify-options in gweslab/cerf) into .agents/skills/verify-options in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add gweslab/cerf --skill verify-options -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/verify-options, .gemini/skills/verify-options, .github/skills/verify-options and .opencode/skills/verify-options in your project.
SKILL.md names no scripts, command-line tools or credentials: Verify Options is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Verify Options is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 11k tokens (SKILL.md is roughly 45k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Verify Options: Options (asgeirtj/system_prompts_leaks, 69k stars), Codex Rules Reference (code-yeongyu/oh-my-openagent, 70k stars), Rules Distillation (affaan-m/ECC, 275k stars) and Eslint Migrate Options (biomejs/biome, 26k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
gweslab (a GitHub organization) maintains it in gweslab/cerf, which has 104 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on October 7, 2026.
Source: gweslab/cerf on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.