Agent skill

Verify

by kdlbs in kdlbs/kandev

Run a broad local verification audit only when the user explicitly requests it or PR/CI remediation requires it.

AGPL-3.0Auto-check passedTesting & QA

Install Verify

skills CLI
$ npx skills add kdlbs/kandev --skill verify -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install kdlbs/kandev verify --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/kdlbs/kandev.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/verify .claude/skills/verify && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
verify
GitHub stars
909
Token cost
~2.7k tokens
SKILL.md length
1,260 words
Files
3 (incl. references)
Skills in repo
45
Repo updated
First seen
Licence
AGPL-3.0

At a glance

Run a broad local verification audit only when the user explicitly requests it or PR/CI remediation requires it.

  • Explicitly requests it
  • SKILL.md covers What to do, Resource-safe frontend… and Verification Procedure
  • Calls make, node and pnpm
  • PR/CI remediation requires it

What it does

Verify is an agent skill from kdlbs/kandev. Run a broad local verification audit only when the user explicitly requests it or PR/CI remediation requires it.

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/hook-evidence.md` and `references/impact-matrix.md`).

It sits in Testing & QA. The repository describes itself as: AI Kanban & Development Environment. Orchestrate multiple agents, review changes, open PRs. Multi-provider, self-hostable, no telemetry. The licence is AGPL-3.0.

When your agent uses it

  • Explicitly requests it
  • PR/CI remediation requires it

Example prompts

  • “/verify”

What it can do on your machine

Read from SKILL.md and the folder at commit b734113. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • make
    • node
    • pnpm
    • git
    • gh
    • rg
    • rustc

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pnpm, git and gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Verify loads about 2.7k tokens when it runs, and up to ~4.6k if it reads all its reference files. Until then it costs about 30 tokens; SKILL.md has 1,260 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~30
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from kdlbs/kandev at commit b734113, republished under its AGPL-3.0 licence (© kdlbs). 1,260 words, ~2,672 tokens.

Download SKILL.mdSave it as .claude/skills/verify/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
verify
description
Run a broad local verification audit only when the user explicitly requests it or PR/CI remediation requires it.

Verify

/verify is opt-in. Do not invoke it automatically before push or PR creation: the default pre-PR evidence is TDD plus the exact task-defined tests and E2E commands. Use this skill only when the user explicitly asks for a broad local audit or when a PR/CI finding needs it. Supply the /commit hook receipt and last successfully verified SHA when available.

What to do

Run the selected commands once in the primary session. Avoid overlapping full suites in the same checkout; wait for a running command to finish before starting another. Capture targeted failure evidence instead of repeatedly rerunning a broad suite.

If the execution relay terminates an otherwise healthy long-running check, rerun that check once in one named, monitored tmux session with an exit sentinel. Do not run a parallel retry. Record the log path and result, then close the session after collecting the sentinel. If that retry fails or its result cannot be recovered, return the evidence as a blocked or failed verification report.

  • If verify passes cleanly: report success.
  • If verify fails: fix the reported cause in the same conversation, rerun the relevant targeted checks, commit if needed, and restart verification.
  • If verify reports that required sandbox capabilities could not be authorized, stop before push or PR delivery and surface its required user action. On Codex, tell the user exactly: "Switch the mode selector to Agent (full access), then retry verification." Explain that push and PR delivery are waiting on mandatory verification; do not imply that Codex or GitHub cannot create PRs or ask whether to proceed unverified.

Resource-safe frontend verification

Before a broad web test or E2E run, read the E2E resource-safety reference. The local Vitest configuration clamps unsafe worker overrides, and the E2E wrappers cap local shards and workers. Do not bypass those limits or overlap full suites unless the task is a deliberate, monitored resource experiment.

Verification Procedure

Resolve the PR base and verification scope base, then collect scope-base...HEAD, staged, unstaged, and untracked paths. The supplied last verified SHA may be the scope base only when it is an ancestor of HEAD; otherwise use the PR base. Report PR base/head, scope base, paths/categories, hook-receipt eligibility and omissions, exact commands, and coverage limits. If base/diff is unavailable or impact is ambiguous, use mode=full; use full mode for explicit requests, releases, shared build or toolchain changes, and unusually broad work. PR CI is the authoritative full matrix. Read impact-matrix.md and, when a receipt is supplied, hook-evidence.md before commands. A scoped pass is changed-scope PASS, never full PASS.

In mode=full, run the pipeline below and ignore hook omissions. In mode=changed, run only uncovered matrix commands for impacted categories; do not run unrelated suites or repeat eligible hook-covered formatting/lint. Evaluate the narrowly scoped pure-web-helper row in the impact matrix before the generic apps/web/** row; use the generic row whenever any eligibility condition is not proven.

bash
# Fresh worktrees share .git/ but not apps/node_modules.
if [ ! -d apps/node_modules ]; then
  (cd apps && pnpm install --frozen-lockfile)
fi

# Resolve the current PR base; stacked PRs may not target main.
PR_BASE="$(gh pr view --json baseRefName --jq .baseRefName 2>/dev/null || true)"
if [ -n "$PR_BASE" ]; then
  git fetch origin "$PR_BASE"
  git merge-base --is-ancestor "origin/$PR_BASE" HEAD || echo "branch is behind origin/$PR_BASE"
else
  echo "No PR base resolved; skipping rebase to avoid rewriting a stacked branch."
fi

# Keep verbose output out of the main agent context. The helper prints the log
# path and extracts targeted failure lines when a command fails.
scripts/run-quiet format -- make fmt
git status --short

# make typecheck uses the top-level Makefile path and can bypass package
# pretypecheck hooks, so generate web metadata before typecheck.
node apps/web/scripts/generate-release-notes.mjs
node apps/web/scripts/generate-changelog.mjs
scripts/run-quiet typecheck -- make typecheck
scripts/run-quiet test -- make test
scripts/run-quiet lint -- make lint

After quiet formatting, inspect the intended diff because formatter changes still require review. When a quiet command fails, use its returned log path for targeted inspection instead of rerunning the command with streamed output.

Large Go package output can bury the actual failure in the execution relay, especially when tests emit expected simulated-error logs. Keep the command's exit status and capture its output with scripts/run-quiet or an explicit temporary log, then extract targeted markers before reading the surrounding context:

bash
rg -n -- '--- FAIL|^FAIL[[:space:]]|panic:|DATA RACE|WARNING: DATA RACE' <log>

Treat truncated tool output as incomplete evidence. Use the extracted package and test names to inspect the focused log section, and report the log path with the verification result.

Disk-constrained runners

If format, typecheck, tests, lint, or E2E reports ENOSPC, cache initialization/lock errors, or an apparently unrelated secondary failure, inspect free space on the temp and cache filesystems before changing code:

bash
df -h /tmp /var/tmp "$PWD"

Keep reusable caches shared. In particular, preserve an existing absolute GOCACHE injected by Kandev's managed Go-cache provider, and preserve an existing GOLANGCI_LINT_CACHE. Create an invocation-owned directory only for scratch files and command logs. For example, replace /var/tmp below if a different filesystem has the available space:

bash
VERIFY_SCRATCH_ROOT="$(mktemp -d /var/tmp/kandev-verify.XXXXXXXX)"
mkdir -p "$VERIFY_SCRATCH_ROOT/tmp" "$VERIFY_SCRATCH_ROOT/logs"
export TMPDIR="$VERIFY_SCRATCH_ROOT/tmp"
export KANDEV_RUN_QUIET_DIR="$VERIFY_SCRATCH_ROOT/logs"

In a managed sandbox, request the normal filesystem escalation when the chosen root is outside the writable roots; do not work around sandbox permissions. If the cache filesystem itself is full or unwritable, relocate only the affected cache to an explicit persistent, agent-owned path outside every worktree and reuse that path on later verification runs. Never fall back to .verify-cache, .tmp, or another directory inside the repository. Re-run the original failing command before diagnosing source code. After verification, remove only $VERIFY_SCRATCH_ROOT; do not clear shared caches or unrelated temp files.

Show full SKILL.md (507 more words)Show less
Restricted remote-environment failures

If Go tests fail from httptest.NewServer with an error such as listen tcp6 [::1]:0: socket: operation not permitted, treat the first result as a sandbox limitation. Rerun the exact command with the runtime's normal network or loopback escalation. Diagnose test code only if the escalated rerun still fails.

If that escalation is unavailable, denied, cancelled, or interrupted, stop and return a blocked verification report with a Required user action section. State that mandatory verification must pass before push and PR delivery can continue. On Codex, the action must say exactly: "Switch the mode selector to Agent (full access), then retry verification." On other runtimes, tell the user to enable the runtime's full filesystem, network, or loopback access as needed, then retry verification. Do not offer to proceed with an unverified PR or describe the blocker as an inability of Codex or the repository host to create one. Recommend full access only after normal escalation could not authorize the required capability in the current mode.

For desktop Rust changes, compare rustc --version with the rust-version in apps/desktop/src-tauri/Cargo.toml before running the Rust suite. Activate an installed matching rustup toolchain, extending PATH rather than replacing it and losing Node/pnpm. If no matching toolchain is installed, report the exact requirement or request installation instead of silently skipping Rust tests.

When a PR base was resolved, report whether origin/$PR_BASE is already an ancestor of HEAD. Do not rebase, stash, or resolve conflicts while a verification command is running. Resolve them in the same primary conversation before restarting verification.

For source, test, type, or lint failures, stop after capturing targeted failure evidence. Report the command, quiet-log path and relevant lines, likely files, and a concise remediation recommendation. Fix only after the failure is understood, then rerun the selected checks.

When the evidence points to a test-owned resource release/reacquisition race (for example, loopback-port rebinding), report a deterministic-test remediation packet. Do not retry indefinitely and do not edit the test in the verify role.

If formatting changes files after commit, review and report the formatter diff, invalidate the hook receipt and verified-commit state, then continue only to collect useful evidence. Commit the formatter result and run fresh verification before push. If a later command fails, capture targeted evidence and stop for remediation.

make test includes backend, web, CLI, and test-scripts; do not silently skip test-scripts or its desktop smoke coverage while reporting full verification as green. Claim full verification only after the complete format, typecheck, test, and lint targets pass, plus the scoped Rust suite when Rust/Tauri code changed.

If make typecheck still fails because apps/web/generated/changelog.json or apps/web/generated/release-notes.json is missing, regenerate them and rerun make typecheck:

bash
(cd apps/web && node scripts/generate-release-notes.mjs)
(cd apps/web && node scripts/generate-changelog.mjs)

When verifying the web package directly, prefer:

bash
(cd apps/web && pnpm run typecheck)

That package script runs pretypecheck and regenerates generated/changelog.json / generated/release-notes.json. If troubleshooting the web package directly, prefer the package-local script over workspace-filter forms so TypeScript runs in the intended package context.

If the aggregate make lint wrapper stalls or does not provide useful progress, run the backend and frontend lint checks directly instead and record the substitution in your result:

bash
make lint-backend
cd apps && pnpm --filter @kandev/web lint

© kdlbs, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in .agents/skills/verify of kdlbs/kandev.

  • SKILL.md
  • references/hook-evidence.md
  • references/impact-matrix.md

Open the folder on GitHubat commit b734113

Compare with similar skills

Verify next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Verify compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Verify this skillkdlbs/kandev909—~2.7kAutomated safety check: PassAGPL-3.0
Electron App Screenshotkeybase/client9.3k—~476Automated safety check: PassBSD-3-Clause
Playwright MCP Browser ControlHainrixz/editor-pro-max261—~2kAutomated safety check: PassCustom licence
E2E Verifyjh941213/my-cc-harness126—~940Automated safety check: NotesNone
E2E Flow Verifierproffesor-for-testing/agentic-qe494—~1.1kAutomated safety check: PassMIT
Dogfood Exploratory QAvercel-labs/agent-browser44k8 repos~2.7kAutomated safety check: PassApache-2.0

Similar skills

  • Takes a screenshot of a running Electron desktop app through playwright-cli over remote debugging, shrinks it and shows it so you can check the UI visually.

    9.3k GitHub stars~476 tokensUpdated today
    Testing & QAAuto-check passed
  • Playwright MCP Browser Control

    Hainrixz/editor-pro-max

    Drives a live browser through the Playwright MCP server to navigate, inspect, fill forms and screenshot pages, with snapshot-first habits and output-size care.

    261 GitHub stars~2k tokensUpdated 6 mo ago
    Testing & QAAuto-check passed
  • E2E Verify

    jh941213/my-cc-harness

    API/CLI-level E2E test writing and execution after development, for E2E that needs no browser automation.

    126 GitHub stars~940 tokensUpdated 2 mo ago
    Testing & QAAuto-check: notes
  • E2E Flow Verifier

    proffesor-for-testing/agentic-qe

    A skill your agent uses when verifying complete user flows end-to-end with the qe-browser skill (Vibium), recording session evidence, and asserting state at each step.

    494 GitHub stars~1.1k tokensUpdated 3 days ago
    Testing & QAAuto-check passed
  • Dogfood Exploratory QA

    vercel-labs/agent-browser

    Official

    Explores a web app with the agent-browser CLI to find bugs and UX problems, then writes a report with screenshots, repro videos and step-by-step reproduction for each issue.

    44k GitHub starsUsed in 8 repos~2.7k tokens
    Testing & QAAuto-check passed
  • Web Application Testing

    anthropics/skills

    Official

    Tests local web applications with Python Playwright scripts, checking frontend behavior, capturing screenshots and reading browser console logs.

    180k GitHub starsUsed in 51 repos~966 tokens
    Testing & QAAuto-check passed

More from kdlbs/kandev

All 45 skills in this repo
  • PR Walkthrough

    kdlbs/kandev

    Generate a single-file HTML walkthrough that explains a PR's purpose, user impact, interface changes, compatibility risks, and implementation.

    909 GitHub stars~6.2k tokensUpdated today
    Auto-check passed
  • Debug

    kdlbs/kandev

    Diagnose Kandev bugs, running-instance issues, UI/browser failures, and runtime behavior.

    909 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Improve Kandev's AI harness from session learnings or explicit requests.

    909 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Diagram Design

    kdlbs/kandev

    Create branded architecture, IT current-state, flowchart, sequence, state machine, ER/data model, timeline, swimlane, quadrant, radar/spider, polar chart (polar/radial lollipop), loop/flywheel…

    909 GitHub starsUsed in 1 repo~8k tokens
    Auto-check passed
  • TDD

    kdlbs/kandev

    Implement changes using Test-Driven Development (Red-Green-Refactor).

    909 GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • Acp Debug

    kdlbs/kandev

    Debug an ACP agent CLI by spawning it, speaking raw JSON-RPC, and capturing every frame to a JSONL file.

    909 GitHub stars~2.1k tokensUpdated today
    Auto-check passed

Questions about Verify

What does Verify do?

Run a broad local verification audit only when the user explicitly requests it or PR/CI remediation requires it. Verify is an agent skill from kdlbs/kandev. Run a broad local verification audit only when the user explicitly requests it or PR/CI remediation requires it.

When should I use Verify?

Verify fits situations like: explicitly requests it; PR/CI remediation requires it.

How do I install Verify in Claude Code?

Run `npx skills add kdlbs/kandev --skill verify -a claude-code`. Or copy the skill folder (.agents/skills/verify in kdlbs/kandev) into .claude/skills/verify in your project. Claude Code loads it when a task matches its description.

How do I install Verify in Codex?

Run `npx skills add kdlbs/kandev --skill verify -a codex`. Or copy the skill folder (.agents/skills/verify in kdlbs/kandev) into .agents/skills/verify in your project. Codex loads it when a task matches its description.

Can I use Verify in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kdlbs/kandev --skill verify -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/verify, .gemini/skills/verify, .github/skills/verify and .opencode/skills/verify in your project.

What does Verify need to run?

Going by SKILL.md and its folder, Verify needs the command-line tools its instructions call (make, node, pnpm, git, gh and rg).

Does Verify access the network?

SKILL.md contains no URLs. Its commands use git and gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Verify safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Verify use?

Verify is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Verify use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2k tokens, read only when the agent opens those files.

What are the alternatives to Verify?

Skills that share tags, products or a category with Verify: Electron App Screenshot (keybase/client, 9.3k stars), Playwright MCP Browser Control (Hainrixz/editor-pro-max, 261 stars), E2E Verify (jh941213/my-cc-harness, 126 stars) and E2E Flow Verifier (proffesor-for-testing/agentic-qe, 494 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Verify?

kdlbs (a GitHub organization) maintains it in kdlbs/kandev, which has 909 GitHub stars. The repository holds 45 skills in this directory. The repository was last updated on October 8, 2026.

Source: kdlbs/kandev on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.