Agent skill

Validate Config

by lidofinance in lidofinance/diffyscan

Reviews an existing Diffyscan YAML or JSON config for load errors, runtime prerequisites, pinned sources, address mappings and broad exceptions.

MITAuto-check passedBackend & APIs

Install Validate Config

skills CLI
$ npx skills add lidofinance/diffyscan --skill validate-config -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install lidofinance/diffyscan validate-config --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/lidofinance/diffyscan.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/validate-config .claude/skills/validate-config && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
validate-config
GitHub stars
142
Token cost
~1.1k tokens
SKILL.md length
478 words
Files
1
Skills in repo
5
Repo updated
First seen
Licence
MIT

At a glance

Reviews an existing Diffyscan YAML or JSON config for load errors, runtime prerequisites, pinned sources, address mappings and broad exceptions.

  • Works in 3 steps: Load and inspect → Review overrides and exceptions → Report
  • Preflight validation
  • SKILL.md covers 1. Load and inspect, 2. Review overrides and… and 3. Report
  • Calls uv

What it does

Validate Config is an agent skill from lidofinance/diffyscan. Reviews an existing Diffyscan YAML or JSON config for load errors, runtime prerequisites, pinned sources, address mappings and broad exceptions. Use for config review or preflight validation; failed live runs belong to debug-diff and new deployment setup to new-config.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Smart contracts and Deployment. It works with Solidity. The repository describes itself as: Diffyscan detects deployment drift by comparing GitHub source with explorer-verified source and on-chain bytecode across EVM networks. The licence is MIT.

When your agent uses it

  • Preflight validation
  • Failed live runs belong to debug-diff and new deployment setup to new-config

Example prompts

  • “Use the validate-config skill to review an existing Diffyscan YAML or JSON config for load errors, runtime prerequisites, pinned sources, address…”
  • “/validate-config”

Requirements

  • Python 3

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Load and inspect
  2. Review overrides and exceptions
  3. Report

What it can do on your machine

Read from SKILL.md and the folder at commit 9fd6833. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • uv

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use uv, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Validate Config loads about 1.1k tokens when it runs. Until then it costs about 71 tokens; SKILL.md has 478 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~71
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from lidofinance/diffyscan at commit 9fd6833, republished under its MIT licence (© lidofinance). 478 words, ~1,105 tokens.

Download SKILL.mdSave it as .claude/skills/validate-config/SKILL.md (or your agent's skills folder).
name
validate-config
description
Reviews an existing Diffyscan YAML or JSON config for load errors, runtime prerequisites, pinned sources, address mappings and broad exceptions. Use for config review or preflight validation; failed live runs belong to debug-diff and new deployment setup to new-config.
argument-hint
[config-path]

Validate the requested config without claiming static checks prove a deployment matches. Run commands from the repository root.

1. Load and inspect

Read the config, configuration reference, diffyscan/utils/common.py and diffyscan/utils/custom_types.py. TypedDicts describe structure; they do not enforce it at runtime. Check the actual loader:

sh
uv run python - path/to/config.yaml <<'PY'
import sys
from diffyscan.utils.common import load_config
load_config(sys.argv[1])
print("Config load passed")
PY

Then inspect what the loader does not fully validate:

  • Nonempty contracts, string names and valid 20-byte hexadecimal addresses. Quote YAML hex keys and values, including nested overrides.
  • github_repo and each dependency have url, a full commit SHA and relative_root. Dependency prefixes match published source paths. Repository config tests require dependencies, including when empty.
  • An explicit explorer hostname or explorer_hostname_env_var; the runtime resolves the latter when the explicit hostname is absent. network, audit_url and metadata are optional descriptive fields.
  • get_explorer_chain_id in diffyscan/utils/explorer.py converts the configured value with int(). Check that it identifies the intended chain; conversion alone does not validate a chain ID. Confirm the API and RPC agree; the CLI does not compare their chain IDs.
  • Credential variable names and availability without printing values. Explorer token fallback is supported; an omitted token variable name is not inherently invalid. A token value is loaded even for adapters that do not send it.
  • Boolean flags and enabled comparisons. source_comparison: false combined with --skip-binary-comparison is rejected.

2. Review overrides and exceptions

Read bytecode comparison. Cross-check per-contract keys against contracts; flag unused entries. Preserve exact address spelling for constructor_args and constructor_calldata: their runtime lookup is case-sensitive, unlike allowed-diff rules. Check calldata hex, argument list shapes, mutually exclusive constructor overrides, deployment_from addresses and extra_sources paths. Library keys identify the definition file and apply to all contracts in the config.

load_config validates allowed_diffs through diffyscan/utils/allowed_diffs.py. Schema validity does not justify a rule: inspect reason and scope. Use allowed-diffs when tightening or adding exceptions.

Show full SKILL.md (187 more words)Show less

With bytecode comparison enabled, fail_on_bytecode_comparison_error: false lets outer per-contract errors continue, including explorer/source errors. With --skip-binary-comparison, that config flag is not applied. Caught bytecode errors produce failed results, except that a bytecode any: true rule marks DeploymentSimulationError as allowed.

For changes under configs/, run:

sh
uv run pytest -q tests/test_configs.py tests/test_no_wildcard_regression.py

These tests inspect repository configs, not arbitrary files outside configs/. Loader success alone does not cover all schema fields, source availability, compiler reproduction or on-chain correctness.

3. Report

List concrete errors with config keys and locations, then evidence gaps or recommendations. Separate loader success, repository tests and live verification. If live verification was requested, run it with --json and inspect status, errors and coverage using JSON output; otherwise report the static verdict and its limits. Edit the config only when the task includes fixes.

Treat placeholder-looking addresses and commits as unverified inputs, not proof that a fetch will fail. An empty dependencies map is not an error without evidence of unresolved imports: those sources may belong to the primary repository. Report supported defaults as defaults rather than missing-field findings, and keep a review-only answer focused on findings instead of rewriting a valid config.

© lidofinance, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/validate-config of lidofinance/diffyscan.

Open the folder on GitHubat commit 9fd6833

Compare with similar skills

Validate Config next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Validate Config compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Validate Config this skilllidofinance/diffyscan142—~1.1kAutomated safety check: PassMIT
Foundry Deploy Fixturesaviggiano/security144—~634Automated safety check: PassMIT
function Object() { [native code] } Patternsccashwell/evm-cortex131—~1.7kAutomated safety check: PassMIT
Test Fixturesccashwell/evm-cortex131—~1.9kAutomated safety check: PassMIT
Foundry Differential Testsaviggiano/security144—~613Automated safety check: PassMIT
Cross Chain Securityccashwell/evm-cortex131—~1.7kAutomated safety check: PassMIT

Similar skills

  • Foundry Deploy Fixtures

    aviggiano/security

    Create or refactor Foundry deployment fixtures for Solidity tests.

    144 GitHub stars~634 tokensUpdated 23 days ago
    Backend & APIsAuto-check passed
  • Test Fixtures

    ccashwell/evm-cortex

    A skill your agent uses when setting up test environments for Solidity protocols.

    131 GitHub stars~1.9k tokensUpdated 8 days ago
    Backend & APIsAuto-check passed
  • Foundry Differential Tests

    aviggiano/security

    Create Foundry differential tests comparing production Solidity contracts against an independent reference model.

    144 GitHub stars~613 tokensUpdated 23 days ago
    Backend & APIsAuto-check passed
  • Cross Chain Security

    ccashwell/evm-cortex

    Cross-chain security patterns for multi-chain Solidity deployments and bridge interactions.

    131 GitHub stars~1.7k tokensUpdated 8 days ago
    Backend & APIsAuto-check passed
  • Library Patterns

    ccashwell/evm-cortex

    Library design patterns for reusable Solidity code. An agent skill from ccashwell/evm-cortex.

    131 GitHub stars~1.6k tokensUpdated 8 days ago
    DevelopmentAuto-check passed

More from lidofinance/diffyscan

  • Add Explorer

    lidofinance/diffyscan

    Adds or repairs Diffyscan explorer API routing and response adapters for a new host, chain or payload format.

    142 GitHub stars~1k tokensUpdated 2 days ago
    Auto-check passed
  • Allowed Diffs

    lidofinance/diffyscan

    Adds, reviews or tightens Diffyscan alloweddiffs rules for explained source or bytecode differences, including replacing any wildcards with granular rules.

    142 GitHub stars~1.2k tokensUpdated 2 days ago
    Auto-check passed
  • New Config

    lidofinance/diffyscan

    Creates or extends a Diffyscan verification config for a deployed contract or deployment.

    142 GitHub stars~1k tokensUpdated 2 days ago
    Auto-check passed
  • Debug Diff

    lidofinance/diffyscan

    Diagnoses failed or incomplete Diffyscan runs, unexpected source or bytecode differences, compilation failures and explorer or RPC errors.

    142 GitHub stars~1.2k tokensUpdated 2 days ago
    Auto-check passed

Works with

Questions about Validate Config

What does Validate Config do?

Reviews an existing Diffyscan YAML or JSON config for load errors, runtime prerequisites, pinned sources, address mappings and broad exceptions. Validate Config is an agent skill from lidofinance/diffyscan. Reviews an existing Diffyscan YAML or JSON config for load errors, runtime prerequisites, pinned sources, address mappings and broad exceptions.

When should I use Validate Config?

Validate Config fits situations like: preflight validation; failed live runs belong to debug-diff and new deployment setup to new-config.

How do I install Validate Config in Claude Code?

Run `npx skills add lidofinance/diffyscan --skill validate-config -a claude-code`. Or copy the skill folder (.claude/skills/validate-config in lidofinance/diffyscan) into .claude/skills/validate-config in your project. Claude Code loads it when a task matches its description.

How do I install Validate Config in Codex?

Run `npx skills add lidofinance/diffyscan --skill validate-config -a codex`. Or copy the skill folder (.claude/skills/validate-config in lidofinance/diffyscan) into .agents/skills/validate-config in your project. Codex loads it when a task matches its description.

Can I use Validate Config in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add lidofinance/diffyscan --skill validate-config -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/validate-config, .gemini/skills/validate-config, .github/skills/validate-config and .opencode/skills/validate-config in your project.

What does Validate Config need to run?

Going by SKILL.md and its folder, Validate Config needs the command-line tools its instructions call (uv). Our summary lists: Python 3.

Does Validate Config access the network?

SKILL.md contains no URLs. Its commands use uv, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Validate Config safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Validate Config use?

Validate Config is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Validate Config use?

About 1.1k tokens (SKILL.md is roughly 4.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Validate Config?

Skills that share tags, products or a category with Validate Config: Foundry Deploy Fixtures (aviggiano/security, 144 stars), function Object() { [native code] } Patterns (ccashwell/evm-cortex, 131 stars), Test Fixtures (ccashwell/evm-cortex, 131 stars) and Foundry Differential Tests (aviggiano/security, 144 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Validate Config?

lidofinance (a GitHub organization) maintains it in lidofinance/diffyscan, which has 142 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on October 6, 2026.

Source: lidofinance/diffyscan on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.