Monitor CI
nrwl/nx
Monitor Nx Cloud CI pipeline and handle self-healing fixes. An agent skill from nrwl/nx.
Normative verification-first policy for all change intents. An agent skill from macalbert/envilder.
$ npx skills add macalbert/envilder --skill common-verification-first -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install macalbert/envilder common-verification-first --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/macalbert/envilder.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/common-verification-first .claude/skills/common-verification-first && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "common-verification-first" agent skill from https://github.com/macalbert/envilder/tree/main/.github/skills/common-verification-first into .claude/skills/common-verification-first/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "common-verification-first", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/macalbert/envilder/tree/main/.github/skills/common-verification-firstType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add macalbert/envilder --skill common-verification-first -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install macalbert/envilder common-verification-first --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/macalbert/envilder.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.github/skills/common-verification-first .agents/skills/common-verification-first && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "common-verification-first" agent skill from https://github.com/macalbert/envilder/tree/main/.github/skills/common-verification-first into .agents/skills/common-verification-first/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "common-verification-first", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add macalbert/envilder --skill common-verification-first -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install macalbert/envilder common-verification-first --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/macalbert/envilder.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.github/skills/common-verification-first .cursor/skills/common-verification-first && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "common-verification-first" agent skill from https://github.com/macalbert/envilder/tree/main/.github/skills/common-verification-first into .cursor/skills/common-verification-first/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "common-verification-first", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/macalbert/envilder.git --path .github/skills/common-verification-first--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add macalbert/envilder --skill common-verification-first -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install macalbert/envilder common-verification-first --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/macalbert/envilder.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.github/skills/common-verification-first .gemini/skills/common-verification-first && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "common-verification-first" agent skill from https://github.com/macalbert/envilder/tree/main/.github/skills/common-verification-first into .gemini/skills/common-verification-first/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "common-verification-first", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install macalbert/envilder common-verification-firstInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add macalbert/envilder --skill common-verification-first -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/macalbert/envilder.git skills-src && mkdir -p .github/skills && cp -r skills-src/.github/skills/common-verification-first .github/skills/common-verification-first && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "common-verification-first" agent skill from https://github.com/macalbert/envilder/tree/main/.github/skills/common-verification-first into .github/skills/common-verification-first/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "common-verification-first", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add macalbert/envilder --skill common-verification-first -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install macalbert/envilder common-verification-first --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/macalbert/envilder.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.github/skills/common-verification-first .opencode/skills/common-verification-first && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "common-verification-first" agent skill from https://github.com/macalbert/envilder/tree/main/.github/skills/common-verification-first into .opencode/skills/common-verification-first/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "common-verification-first", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
common-verification-firstNormative verification-first policy for all change intents. An agent skill from macalbert/envilder.
Common Verification First is an agent skill from macalbert/envilder. Normative verification-first policy for all change intents. Defines independent verification contracts, strategy selection, evidence rules, role ownership, and final evaluation without prescribing microscopic implementation steps.
Its SKILL.md is about 4.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud. The repository describes itself as: One secret mapping for local dev, CI/CD, and runtime. Envilder resolves cloud secrets from your own vaults without SaaS middlemen, duplicated config, or .env drift. The licence is MIT.
9 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit b6a0327. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Common Verification First loads about 4.8k tokens when it runs. Until then it costs about 64 tokens; SKILL.md has 2,222 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from macalbert/envilder at commit b6a0327, republished under its MIT licence (© macalbert). 2,222 words, ~4,817 tokens.
.claude/skills/common-verification-first/SKILL.md (or your agent's skills folder).This is the normative policy for planning, implementing, reviewing, and verifying repository changes across every Envilder stack.
The implementation must not define its own success criteria.
Expected results derive from approved requirements, invariants, acceptance criteria, architecture constraints, and stable external contracts. Control the correctness of the result without prescribing the microscopic process used to produce it.
A passing command is evidence. It is not proof that the requirement was interpreted correctly.
The goal is reliable evidence of correctness, not the maximum number of tests.
Classify every task by both intent and verification strategy. Neither dimension mechanically determines the other.
Choose exactly one:
| Intent | Meaning |
|---|---|
NEW_BEHAVIOR | Introduces an observable capability or system property |
BEHAVIOR_CHANGE | Intentionally changes an existing observable contract |
BUG_FIX | Restores expected behavior by correcting a confirmed defect |
PURE_REFACTOR | Changes structure while preserving observable behavior |
NON_BEHAVIORAL_CHANGE | Changes artifacts without changing system behavior |
Infrastructure, configuration, migrations, generated artifacts, and test infrastructure are subjects of work, not extra intents. Classify what the change means, not which directory it touches.
Select one or more strategies justified by the requirement:
| Strategy | Typical use |
|---|---|
| New, updated, or reused behavioral tests | Observable behavior and regressions |
| Existing-suite baseline | Pure refactors and already protected behavior |
| Consumer or direct-workflow evidence | Test infrastructure and operational workflows |
| Compiler, type, or static validation | API shape, type safety, architecture, lint, generated consistency |
| Schema, policy, migration, or contract validation | Configuration, data evolution, and external contracts |
| Explicit limitation | No meaningful executable oracle is available |
Prefer the fastest deterministic strategy that directly exercises the important boundary. Add broader gates when a narrow oracle cannot expose integration risk.
BLOCKED when required final evidence needs command execution that
the read-only profile cannot perform.candidate-review for one orchestrated candidate and
change-set-review for a staged, unstaged, branch, commit-range, or
pull-request diff.Verification-contract artifacts encode success criteria: behavioral, regression, contract, architecture, or acceptance tests; expectation snapshots; and dedicated validation scripts or specifications created to express the approved contract.
Solution artifacts include production code, configuration, documentation, migrations, refactors, fixtures, builders, seeders, mocks, containers, data loaders, runner setup, and other test infrastructure.
The Contract Verifier may edit only verification-contract artifacts while establishing a contract. The Implementer may edit only solution artifacts. The Reviewer and Final Verifier edit nothing.
On filtering hosts, a descendant's effective tools are limited by its own
profile and every ancestor's exposed tools. Change Orchestrator, Content
Designer, and PR Resolver therefore each declare the explicit inheritance
envelope [read, search, edit, execute, agent]. Every ancestor must expose all
required descendant tools, including agent for nested delegation.
Exposure does not grant semantic authority: coordinators never edit artifacts, and Change Orchestrator never executes repository commands. Contract Verifier owns verification-contract edits; Implementer owns solution edits. Host approval gates remain in force; never use wildcard tool grants or bypass approvals to repair propagation.
Workers retain their own limits: Contract Verifier and Implementer use
[read, search, edit, execute], Reviewer uses [read, search, execute], and
Final Verifier uses [read, search]. None delegates. A broader ancestor
envelope must not expand a worker's effective boundary.
These common aliases are portability defaults, not universal host tool names
or support guarantees. Preflight actual tool exposure, nested delegation, and
worker boundaries; return BLOCKED with the missing capability when required
support cannot be established. Implementer diagnoses missing read/edit/execute
and may use execute-based search when no dedicated search tool is exposed.
Fresh contexts provide separation of responsibilities and independent evaluation. Fresh does not mean starved of context.
Every worker receives the approved semantic inputs it needs:
VerificationContract;ImplementationResult, ReviewResult, or
FinalVerificationResult.Do not propagate transcripts, raw command logs, failed attempts, temporary hypotheses, private reasoning, or obsolete result histories. Communicate semantic results, not full working trajectories.
VerificationContract derives from approved semantics and uses
the narrowest credible oracle.candidate-review mode unless the strict
omission rule applies.Final result: PASS in FinalVerificationResult for the
exact current reviewed candidate permits Change Orchestrator completion
judgment. PASS is necessary, not sufficient: all existing acceptance
conditions still apply.If any candidate artifact changes after review or final verification, invalidate the affected results and rerun the necessary review and final verification against the new candidate.
FAIL prevents acceptance. Route implementation defects to a fresh
Implementer and contract defects to a fresh Contract Verifier, then repeat
affected downstream stages. Changes to approved semantics, invariants, scope,
or requirements require human approval.BLOCKED propagates a reason-bearing ChangeResult with final judgment
BLOCKED; callers must not claim successful completion, publish PR replies,
or resolve threads. Unavailable required evidence alone is not an instruction
to edit the solution.PASS or waive FAIL or
BLOCKED. A legitimately approved limitation strategy can still receive
PASS when the approved contract is actually satisfied and assessable.PASS reopens judgment.PASS.Callers must require this qualifying final PASS for each artifact-changing
action, even if its ChangeResult nominally claims success. All approved actions
must succeed before batch publication; prepared but held replies are not
published success. Aggregate validation and remote availability are additional
gates, not substitutes for final PASS. Direct no-artifact answers and approved
skips retain their existing workflow and applicable exemptions.
Candidate review may be omitted only when every condition is true:
NON_BEHAVIORAL_CHANGE;Record the rationale, evidence, and residual risk. Any uncertainty requires review. A lifecycle-level or complete change-set review may still be required by the caller.
NEW_BEHAVIORBEHAVIOR_CHANGEBUG_FIXPURE_REFACTORNON_BEHAVIORAL_CHANGEClassify by intent first, then choose the natural oracle. Appropriate evidence can include workflow or configuration schema validation, policy validation, migration checks, API or event contract validation, compiler checks, type checking, lint, and generated-code consistency.
Do not force infrastructure behavior into a shallow unit test when policy, contract, plan, or migration evidence expresses the real system property more directly.
Fixtures, builders, mocks, stubs, seeders, containers, data loaders, and test-runner configuration are solution artifacts.
Use this order:
The focused support test is diagnostic instrumentation, not a coverage target. Record why consumer or workflow evidence was insufficient.
Physical test-first ordering is only a proxy for independence. The stronger question is:
Can the verification meaningfully reject an incorrect or previous behavior?
Useful effectiveness evidence may include:
A failing signal counts only when its observed reason matches the expected absent, previous, or defective behavior. Compilation, setup, dependency, and environment failures are limitations to resolve or report, not evidence that the behavioral oracle is effective.
Do not require visible Red merely as ritual. For critical behavior, consider stronger techniques such as property-based testing, mutation testing, boundary analysis, concurrency scenarios, contract validation, and independent review.
Inside-out and outside-in are both valid ways to discover behavioral verification. Neither dictates how the Implementer must construct the solution.
Use the lowest test level that can prove the requirement without mocking away the risk:
| Level | Select when |
|---|---|
| Unit | Pure behavior has no I/O and a small stable boundary |
| Integration | Behavior crosses layers, persistence, HTTP, queues, or framework wiring |
| Acceptance | A stakeholder use case needs full application-path evidence |
| E2E | A small number of critical flows require real user and deployed-style boundaries |
Behavioral verification should be isolated, order-independent, deterministic, readable as a requirement, specific enough to localize failure, insensitive to private structure, and maintainable in proportion to the protected risk.
Coverage and test count are diagnostics, not goals. Prefer observable results and required side effects over private methods, trivial storage, framework registration in isolation, or mock interactions as ends in themselves.
These are the canonical workflow envelopes. Role agents may add task-specific detail but must not rename, remove, or contradict these fields.
VerificationContract
Intent and strategy:
Behaviors and invariants:
Verification artifacts:
Targeted commands:
Pre-state effectiveness evidence:
Broader gates:
Assumptions:
Result:
Risks or limitations:ImplementationResult
Intent and strategy:
VerificationContract received:
Solution artifacts changed:
Candidate paths:
Design decisions:
Targeted command and result:
Broader gates and results:
Contract status: SATISFIED | UNSATISFIED | BLOCKED
Unresolved concerns or risks:ReviewResult
Mode and scope:
Summary:
Prioritized findings:
No-finding rationale:
Verification observations and commands:
Contract assessment: <assessment | NOT_PROVIDED>
Verdict: APPROVE | COMMENT | REQUEST_CHANGES | BLOCKED
Remaining risks:FinalVerificationResult
Candidate paths assessed:
Approved semantics assessed:
Review disposition assessment:
Behaviors and invariants assessed:
Targeted command results:
Broader gate results:
Contract assessment:
Final result: PASS | FAIL | BLOCKED
Risks or limitations:ChangeResult
Approved specification:
Intent and strategy:
VerificationContract:
Changed paths and candidate scope:
Latest ImplementationResult:
Latest ReviewResult or ReviewOmission:
FinalVerificationResult:
Final judgment:
Limitations and residual risks:Never require a new test, a failing test, or a separate cleanup phase merely to satisfy a ritual. Require independent criteria, appropriate evidence, sound architecture, and a credible final judgment.
© macalbert, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .github/skills/common-verification-first of macalbert/envilder.
Open the folder on GitHubat commit b6a0327
Common Verification First next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Common Verification First this skillmacalbert/envilder | 138 | — | ~4.8k | Automated safety check: Pass | MIT | |
| Monitor CInrwl/nx | 29k | 5 repos | ~4.7k | Automated safety check: Pass | MIT | |
| Terraform and OpenTofu Guideagentscope-ai/QwenPaw | 35k | 6 repos | ~4.2k | Automated safety check: Pass | Apache-2.0 | |
| Vercel Optimize Auditvercel-labs/agent-skills | 32k | 8 repos | ~4.3k | Automated safety check: Pass | None | |
| Analyze GitHub Action Logswithastro/astro | 63k | 1 repos | ~1.3k | Automated safety check: Pass | Custom licence | |
| Docs Learn PR Previewnetdata/netdata | 81k | — | ~2k | Automated safety check: Pass | GPL-3.0 |
nrwl/nx
Monitor Nx Cloud CI pipeline and handle self-healing fixes. An agent skill from nrwl/nx.
agentscope-ai/QwenPaw
Guidance for writing and testing Terraform and OpenTofu code: module structure, naming, test approaches, CI/CD workflows, state handling and security scanning.
vercel-labs/agent-skills
Runs a metrics-first audit of a deployed Vercel project, gating investigations on real signals to produce ranked, citation-backed cost and performance recommendations.
withastro/astro
Analyze recent GitHub Actions workflow runs to identify patterns, mistakes, and improvements.
netdata/netdata
Use only when the user explicitly asks to build, run, preview, inspect, or validate learn.netdata.cloud locally using the contents of a PR or documentation branch before merge.
netdata/netdata
Inspect Netdata-org source checkouts under NETDATAREPOSDIR, or set up and synchronize that mirror when requested.
macalbert/envilder
Five independent analysis perspectives for code review: correctness, architecture, security, conventions, and complexity.
macalbert/envilder
Index of Architecture Decision Records (ADRs) for cross-cutting technical decisions.
macalbert/envilder
Git commit messages, PR workflow, and branching strategy using Conventional Commits and Semantic Versioning.
macalbert/envilder
Mandatory testing conventions including the narrow diagnostic exception for testing test-only code, AAA pattern, test naming, and assertions across all stacks (.NET, TypeScript, Python).
macalbert/envilder
Workflow for maintaining changelogs, READMEs, and documentation files.
macalbert/envilder
Audit and synchronize documentation across website, READMEs, and docs/.
Categories
Normative verification-first policy for all change intents. An agent skill from macalbert/envilder. Common Verification First is an agent skill from macalbert/envilder. Normative verification-first policy for all change intents.
Common Verification First fits situations like: devOps & Cloud work in your project.
Run `npx skills add macalbert/envilder --skill common-verification-first -a claude-code`. Or copy the skill folder (.github/skills/common-verification-first in macalbert/envilder) into .claude/skills/common-verification-first in your project. Claude Code loads it when a task matches its description.
Run `npx skills add macalbert/envilder --skill common-verification-first -a codex`. Or copy the skill folder (.github/skills/common-verification-first in macalbert/envilder) into .agents/skills/common-verification-first in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add macalbert/envilder --skill common-verification-first -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/common-verification-first, .gemini/skills/common-verification-first, .github/skills/common-verification-first and .opencode/skills/common-verification-first in your project.
SKILL.md names no scripts, command-line tools or credentials: Common Verification First is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Common Verification First is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.8k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Common Verification First: Monitor CI (nrwl/nx, 29k stars), Terraform and OpenTofu Guide (agentscope-ai/QwenPaw, 35k stars), Vercel Optimize Audit (vercel-labs/agent-skills, 32k stars) and Analyze GitHub Action Logs (withastro/astro, 63k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
macalbert (a GitHub user) maintains it in macalbert/envilder, which has 138 GitHub stars. The repository holds 30 skills in this directory. The repository was last updated on October 5, 2026.
Source: macalbert/envilder on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.