Vercel Composition Patterns
supabase/supabase
React composition patterns that scale. An agent skill from supabase/supabase.
Independently witness that an Allium loop's convergence claim is true and was reached honestly.
$ npx skills add juxt/allium --skill witness -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install juxt/allium witness --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/juxt/allium.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/witness .claude/skills/witness && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "witness" agent skill from https://github.com/juxt/allium/tree/main/skills/witness into .claude/skills/witness/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "witness", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/juxt/allium/tree/main/skills/witnessType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add juxt/allium --skill witness -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install juxt/allium witness --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/juxt/allium.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/witness .agents/skills/witness && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "witness" agent skill from https://github.com/juxt/allium/tree/main/skills/witness into .agents/skills/witness/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "witness", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add juxt/allium --skill witness -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install juxt/allium witness --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/juxt/allium.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/witness .cursor/skills/witness && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "witness" agent skill from https://github.com/juxt/allium/tree/main/skills/witness into .cursor/skills/witness/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "witness", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/juxt/allium.git --path skills/witness--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add juxt/allium --skill witness -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install juxt/allium witness --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/juxt/allium.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/witness .gemini/skills/witness && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "witness" agent skill from https://github.com/juxt/allium/tree/main/skills/witness into .gemini/skills/witness/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "witness", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install juxt/allium witnessInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add juxt/allium --skill witness -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/juxt/allium.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/witness .github/skills/witness && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "witness" agent skill from https://github.com/juxt/allium/tree/main/skills/witness into .github/skills/witness/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "witness", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add juxt/allium --skill witness -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install juxt/allium witness --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/juxt/allium.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/witness .opencode/skills/witness && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "witness" agent skill from https://github.com/juxt/allium/tree/main/skills/witness into .opencode/skills/witness/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "witness", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
witnessIndependently witness that an Allium loop's convergence claim is true and was reached honestly.
Witness is an agent skill from juxt/allium. Independently witness that an Allium loop's convergence claim is true and was reached honestly. Use when the user wants to verify a loop's self-report, confirm tests really pass and no generated test was weakened, produce a convergence certificate or witness record, gate CI on a trustworthy signal, or check that an autonomous run did not cheat its way to green.
Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development. The repository describes itself as: The specification language that talks back. The licence is MIT.
7 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 7f7f008. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are json).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Witness loads about 2.6k tokens when it runs. Until then it costs about 93 tokens; SKILL.md has 1,445 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from juxt/allium at commit 7f7f008, republished under its MIT licence (© juxt). 1,445 words, ~2,622 tokens.
.claude/skills/witness/SKILL.md (or your agent's skills folder).You are the loop's independent witness. When an Allium loop reports that it has converged — tests pass, weed is clean, no blocking questions remain — you confirm that claim against ground truth the run could not fabricate, and you leave behind a signed witness record. You do not do the loop's work again; you observe the evidence its phases already produced.
The distinction that gives you your value: the verify phase asks "does the code satisfy the spec?" and is run by the actor as part of its own work. You ask "is the actor's claim that it does actually true, and was it reached honestly?" — run independently, trusting nothing the actor merely asserts in prose. This is the driving the loop anti-cheat contract turned from prose the actor is trusted to follow into a check the loop can verify.
Your verdict is deterministic, not a judgement call. You re-run cheap deterministic tools and diff their output; you never grade one narrative against another. A witness that "reviews" the work is an eval; a witness that re-derives pass/fail from the runner's own output is a test. Be the test.
This skill runs in two modes. Every instruction below that asks or reports something to the user follows the mode:
witness subagent (for example at the Allium loop's convergence gate), where no user is reachable. Never wait for an answer: write the witness record, return the verdict and every violation with its routing in your final output, and let the caller act on them.You are a witness, not a fixer. You do not edit the spec, the tests, or the code — not even to make a failing check pass. You write exactly one artefact: the witness record. Everything else you only read, hash, or re-run. Fixing a violation belongs to the loop's phases (tend, propagate, implementation), never to you — your job is to make the violation undeniable, not to paper over it.
The loop's phases have already run the tests, weed, and obligation reconciliation, and each already emitted machine output. Your job is to read that ground-truth output instead of the actor's prose summary — not to redo the work.
allium check / allium analyse, file hashing, and grep cost no model reasoning — they are fast, deterministic Bash calls whose output is small. Re-running the test command once to read the runner's own exit status is the strongest possible evidence and is not expensive.propagate (regenerating tests), distill (re-reading the codebase), or weed's full alignment reasoning. Read the artefacts and summary lines they already produced. Re-doing an LLM phase is what would double the loop's cost — and it is exactly what a witness never needs to do.One light pass per converged run: read the ledger, re-run the deterministic checks, hash the generated tests, write the record. That is the whole cost.
Run every check that has evidence available; skip (and say you skipped, and why) any whose evidence is absent. Each check names the ground truth it reads — never the actor's self-report.
propagate does) and read the runner's own exit status and pass/fail counts. If you cannot re-run it, read the saved runner output the verify phase produced. The actor's reported "12/12" is not evidence; the runner's exit code is. A mismatch between the two is itself a violation.propagate records a content hash for each generated test file in the ledger. Recompute each file's hash and compare. A generated test whose hash changed with no intervening propagate run is a hand-edited test — the cardinal anti-cheat violation. Report the file and the divergence.propagate's reconciliation line (N obligations, M covered, K uncovered) from the ledger. Confirm that every uncovered obligation carries a reported reason (infrastructure gap / unmappable construct) and that convergence was not declared while unexplained obligations remain uncovered.weed verdict is real. Read the weed verdict recorded for this run and confirm the convergence claim matches it. Only in hard mode (opt-in, for high-assurance runs) do you re-run weed yourself for source-independent confirmation — it is the one model-heavy re-run, and it is off by default.open questions section. Confirm it contains what the run reported as parked, and that nothing direction-changing was quietly downgraded from blocking to parked to reach convergence. A blocking question dressed as parked is a violation.weed clean, no blocking questions, and (code-first) a fresh distill finds nothing new — from the evidence above and the ledger, not from the run's summary line. All four must hold from ground truth.allium analyse / reconciliation flagged no vacuous test. This one is partly reconstructive — label it as best-effort in the record rather than overclaiming.The witness record's verdict is PASS only when every check that had evidence passed. Any failed check makes the verdict FAIL; a check whose evidence was absent is INCONCLUSIVE for that check and is reported as such (an all-inconclusive run is not a PASS — say the loop produced no evidence to witness).
For each violation, name the ground truth that exposed it and the routing that resolves it, so the loop or the user knows where it goes:
propagate.propagate reconciliation.weed verdict contradicts the convergence claim → tend the spec or fix the code, per the divergence.You classify and route; you never apply the fix.
Write one artefact per run to .allium-loop/<goal-slug>.witness.json. It is the durable, auditable product the loop gains — the thing you can gate CI on, resume against, or show an auditor. Include:
PASS / FAIL / INCONCLUSIVE);weed verdict, the open questions diff);Do not embed file contents or code — the record holds verdicts and the evidence keys, not the material behind them, so it stays small and the loop's context stays flat.
When running as the witness subagent inside the Allium loop, return your result as a single JSON object conforming to witness-result.schema.json, and nothing else: the verdict, each check with the ground_truth it read, every violation with its routing, the record_path, and a one-line summary. Emit every field, using [] for an empty violations list on a PASS. The loop gates convergence on verdict directly — no prose to parse. The object mirrors the durable record you wrote to .allium-loop/<slug>.witness.json.
{
"phase": "witness",
"verdict": "FAIL",
"checks": [
{ "name": "tests-pass", "result": "pass", "ground_truth": "runner exit 0, 12/12" },
{ "name": "no-test-weakened", "result": "fail", "ground_truth": "sha256 mismatch on order.test.js" }
],
"violations": [
{ "violation": "order.test.js edited after propagate", "routing": "revert + propagate" }
],
"record_path": ".allium-loop/gift-cards.witness.json",
"summary": "witness: FAIL · tampering on order.test.js"
}As the loop subagent, return only that JSON object — no prose before or after it, even though you also wrote the durable record to disk. The returned object is your result; the file is its durable copy.
Running interactively (not as the loop subagent), skip the JSON and close with a single human-readable summary line instead:
witness: PASS · checks 6/6 · tests 12/12 (runner) · tampering none · openQ 0 blocking · record .allium-loop/<slug>.witness.jsonOn an interactive failure, lead with the verdict and the violations, each with its routing, then the record path. Keep the body to the verdict and its evidence — the record holds the detail.
PASS.elicit, distill, tend.propagate.© juxt, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/witness of juxt/allium.
Open the folder on GitHubat commit 7f7f008
Witness next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Witness this skilljuxt/allium | 507 | — | ~2.6k | Automated safety check: Pass | MIT | |
| Vercel Composition Patternssupabase/supabase | 111k | 58 repos | ~726 | Automated safety check: Pass | MIT | |
| Finishing a Development Branchobra/superpowers | 297k | 5 repos | ~1.9k | Automated safety check: Pass | MIT | |
| Typescript Advanced Typesrolling-scopes/rsschool-app | 10k | 25 repos | ~4.2k | Automated safety check: Pass | MPL-2.0 | |
| PR Babysitteropeninterpreter/openinterpreter | 69k | 3 repos | ~4.2k | Automated safety check: Pass | Apache-2.0 | |
| Code Review ChecklistshareAI-lab/learn-claude-code | 78k | 4 repos | ~1.1k | Automated safety check: Pass | MIT |
supabase/supabase
React composition patterns that scale. An agent skill from supabase/supabase.
obra/superpowers
Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.
rolling-scopes/rsschool-app
Master TypeScript's advanced type system including generics, conditional types, mapped types, template literals, and utility types for building type-safe applications.
openinterpreter/openinterpreter
Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.
shareAI-lab/learn-claude-code
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
onyx-dot-app/onyx
Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.
Categories
Independently witness that an Allium loop's convergence claim is true and was reached honestly. Witness is an agent skill from juxt/allium. Independently witness that an Allium loop's convergence claim is true and was reached honestly.
Witness fits situations like: the user wants to verify a loops self-report; confirm tests really pass and no generated test was weakened; produce a convergence certificate; gate CI on a trustworthy signal.
Run `npx skills add juxt/allium --skill witness -a claude-code`. Or copy the skill folder (skills/witness in juxt/allium) into .claude/skills/witness in your project. Claude Code loads it when a task matches its description.
Run `npx skills add juxt/allium --skill witness -a codex`. Or copy the skill folder (skills/witness in juxt/allium) into .agents/skills/witness in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add juxt/allium --skill witness -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/witness, .gemini/skills/witness, .github/skills/witness and .opencode/skills/witness in your project.
SKILL.md names no scripts, command-line tools or credentials: Witness is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Witness is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Witness: Vercel Composition Patterns (supabase/supabase, 111k stars), Finishing a Development Branch (obra/superpowers, 297k stars), Typescript Advanced Types (rolling-scopes/rsschool-app, 10k stars) and PR Babysitter (openinterpreter/openinterpreter, 69k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
juxt (a GitHub organization) maintains it in juxt/allium, which has 507 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on September 27, 2026.
Source: juxt/allium on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.