Agent skill

Verify

by marketcalls in marketcalls/openalgo

Verify a claim before stating it, and verify a test before trusting it.

AGPL-3.0Auto-check passedBusiness, Finance & HR

Install Verify

skills CLI
$ npx skills add marketcalls/openalgo --skill verify -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install marketcalls/openalgo verify --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/marketcalls/openalgo.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/verify .claude/skills/verify && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
verify
GitHub stars
2.8k
Token cost
~1.5k tokens
SKILL.md length
847 words
Files
2
Skills in repo
8
Repo updated
First seen
Licence
AGPL-3.0

At a glance

Verify a claim before stating it, and verify a test before trusting it.

  • Reporting audit
  • SKILL.md covers Rule 1 - execute the pattern,…, Rule 2 - break the code to…, Rule 3 - grep for the sink,… and Rule 4 - baseline before and…, plus 3 more sections
  • Runs Python scripts from its folder; calls uv and git
  • Scanner findings

What it does

Verify is an agent skill from marketcalls/openalgo. Verify a claim before stating it, and verify a test before trusting it. Use before asserting that a security control holds, that a pattern is safe, that a bug is fixed, or that a test guards a fix. Also use when reporting audit or scanner findings, when a grep "found nothing", when a lint or test count looks clean, and before telling a user that something is or is not a vulnerability.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `redaction_check.py`).

It sits in Business, Finance & HR, covering Trading and backtesting. It works with Python. The repository describes itself as: Open Source Algo Trading Platform for Everyone. The licence is AGPL-3.0.

When your agent uses it

  • Reporting audit
  • Scanner findings
  • A grep found nothing
  • Test count looks clean

Example prompts

  • “found nothing”
  • “/verify”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit 1dcfff5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • uv
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use uv and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Verify loads about 1.5k tokens when it runs. Until then it costs about 99 tokens; SKILL.md has 847 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~99
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from marketcalls/openalgo at commit 1dcfff5, republished under its AGPL-3.0 licence (© marketcalls). 847 words, ~1,489 tokens.

Download SKILL.mdSave it as .claude/skills/verify/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
verify
description
Verify a claim before stating it, and verify a test before trusting it. Use before asserting that a security control holds, that a pattern is safe, that a bug is fixed, or that a test guards a fix. Also use when reporting audit or scanner findings, when a grep "found nothing", when a lint or test count looks clean, and before telling a user that something is or is not a vulnerability.

Verify before claiming

Every high-severity finding this repo has produced came from executing something. Every wrong claim came from reading something and reasoning about it.

The rules below are cheap. Skipping them is what produces a confident, wrong answer that a maintainer then acts on.

Rule 1 - execute the pattern, never read it

A regex, a redaction filter, a permission mask or a capability gate is code. Run it against a realistic value and look at the output.

What happens when you don't. utils/logging.py redacts key-value shapes. Reading the pattern suggested "Feed Token: {t}" leaked, so nine call sites were reported as leaks. Executing it showed the alternation contains a bare token, which matches Token: and redacts the value. The finding was wrong in the direction that wastes a maintainer's time.

The same run showed "Access Token obtained: {t}" genuinely leaks, because a word sits between the keyword and the colon. Neither result was predictable by inspection.

bash
uv run python .claude/skills/verify/redaction_check.py \
  "Access Token obtained: {t}" "eyJhbGciOiJIUzI1NiJ9.SEKRET.sig"

Prints LEAKS or redact and exits non-zero when the secret survives, so it drops into a loop or a test.

Corollary: whether a log line leaks depends on data you have not read yet. ?susertoken= and ?token= redact; ?Value1= and ?jKey= do not. You cannot judge a logged URL without opening the code that builds it and learning the real parameter name.

Rule 2 - break the code to validate the test

A test that passes proves nothing until you have seen it fail. Revert the fix, or neuter the guard it depends on, and confirm the test goes red. Then restore.

What happens when you don't. A StrategyBuilder test asserted a tile was absent after an identity reset. It passed. It also passed against the exact bug it was written to catch, because the assertion raced a 400ms debounce that legitimately re-rendered the tile.

Two ways this goes wrong, both seen here:

  • Tautological assertion. The test re-implements the predicate inline (is_stale = qty != 0 and updated_at < boundary) instead of calling the function under test. It is then testing Python's < operator.
  • Vacuous pass. The assertion is true for a reason unrelated to the fix, so it holds whether or not the fix is present.

When disabling a guard to prove a test, target the exact line. A blind replace(..., 1) hits the first match, which may be a different, pre-existing guard, and then the "proof" proves nothing.

Rule 3 - grep for the sink, not the variable name

A grep that returns nothing is not evidence of absence. It is evidence about your pattern.

What happens when you don't. Searching broker/ for credential variable names inside f-strings found and fixed the direct cases. It was structurally incapable of seeing the larger class, where the secret rides inside something else that gets logged:

  • a URL assembled with the token in the query string
  • an auth request or response body
  • a headers dict
  • an exception message (httpx.HTTPStatusError embeds the full URL, so a credential in the URL path leaked on every 4xx, exactly the wrong-credential case)

Before concluding a class is clear, ask what a leak would look like if the secret were never named in the log statement, then search for that.

Show full SKILL.md (322 more words)Show less

Rule 4 - baseline before and after

A tool's output is meaningless without its prior value. Capture the count on HEAD, apply the change, capture it again.

bash
uv run ruff check <paths> | grep -oE "Found [0-9]+ errors"
git stash -q && uv run ruff check <paths> | grep -oE "Found [0-9]+ errors"; git stash pop -q

Two traps specific to this repo:

  • F401 is in the ruff ignore list (pyproject.toml). An orphaned import logging will not be flagged. Verify unused imports by grep.
  • Windows checkouts fail Biome on CRLF. Every .tsx reports a format error, including files you never touched. Run the check on an untouched file first to establish that the error is environmental.

Rule 5 - distinguish "already safe" from "fixed"

Reporting a safe site as fixed inflates the apparent severity of your work and teaches the reader that the report cannot be trusted.

Of seven sites reported as leaking WebSocket URLs, two leaked and five were already redacted. The fix touched the two. The other five were left alone and named as false positives in the review. Churning them would have produced a diff that looked like a fix and taught nobody anything.

State plainly which of the reported items were real. When a scanner is the source, expect false positives and triage each one:

  • A substring check can match the documentation that warns against the defect. The NullPool check failed on engine_factory.py's own docstring.
  • A decorator check misses an inline guard. Routes calling is_session_valid() in the function body read as unprotected.
  • POSIX permission bits are synthesized on Windows. Every file reports 0o666.

Rule 6 - an unrun check is not a pass

If a tool times out, is not installed, or is skipped, say so and treat the area as unverified. detect-secrets timing out means secret scanning did not happen, regardless of the exit code of the run that contained it.

When you are wrong

Correct it in one plain sentence with the evidence, and carry on. A wrong claim that gets quietly dropped is worse than one that gets corrected, because the maintainer may already have acted on it.

© marketcalls, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .claude/skills/verify of marketcalls/openalgo.

  • SKILL.md
  • redaction_check.py

Open the folder on GitHubat commit 1dcfff5

Compare with similar skills

Verify next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Verify compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Verify this skillmarketcalls/openalgo2.8k—~1.5kAutomated safety check: PassAGPL-3.0
Tushare Datazillionare/zillionare3212 repos~2.3kAutomated safety check: PassNone
Kalshi Traderyanfrigo/kalshi-ai-trading-bot614—~3.4kAutomated safety check: PassMIT
Polymarket Tennislivetennisapi/livetennisapi-mcp152—~3kAutomated safety check: PassMIT
Quant Backtestjoemccann/market-data-warehouse183—~2.1kAutomated safety check: PassNone
Qmt Inner Backtestdfkai/xtquantai164—~1.8kAutomated safety check: PassMIT

Similar skills

  • Tushare Data

    zillionare/zillionare

    面向中文自然语言的 Tushare 数据研究技能。用于把“看看这只股票最近怎么样”“帮我查财报趋势”“最近哪个板块最强”“北向资金在买什么”“给我导出一份行情数据”这类请求,转成可执行的数据获取、清洗、对比、筛选、导出与简要分析流程。适用于 A 股、指数、ETF/基金、财务、估值、资金流、公告新闻、板块概念与宏观数据等研究场景。

    321 GitHub starsUsed in 2 repos~2.3k tokens
    Business, Finance & HRAuto-check passed
  • Kalshi Trade

    ryanfrigo/kalshi-ai-trading-bot

    The disciplined process for autonomously and profitably trading the live Kalshi account on each /loop tick, with Claude as the decision-maker.

    614 GitHub stars~3.4k tokensUpdated yesterday
    Business, Finance & HRAuto-check passed
  • Polymarket Tennis

    livetennisapi/livetennisapi-mcp

    Build observe-only Polymarket and Kalshi tennis market tooling on the polymarket-tennis Python package (MIT) plus the Live Tennis API free tier.

    152 GitHub stars~3k tokensUpdated 3 days ago
    Business, Finance & HRAuto-check passed
  • Quant Backtest

    joemccann/market-data-warehouse

    Institutional-grade Python backtesting framework builder for Codex.

    183 GitHub stars~2.1k tokensUpdated 6 mo ago
    Business, Finance & HRAuto-check passed
  • Qmt Inner Backtest

    dfkai/xtquantai

    根据策略描述、研报 PDF 或截图,解读因子/选股逻辑,基于 scripts/daily-factors-backtest.py 框架生成 QMT 内置日频因子回测脚本。用户提到 QMT 内置回测、因子选股回测、截面因子、 研报复现、handlebar 回测、afterinit 预计算信号时使用。

    164 GitHub stars~1.8k tokensUpdated 4 mo ago
    Business, Finance & HRAuto-check passed
  • Backtesting

    gauss314/skills

    Academic backtesting framework for quantitative research. An agent skill from gauss314/skills.

    247 GitHub stars~2.4k tokensUpdated 3 mo ago
    Business, Finance & HRAuto-check passed

More from marketcalls/openalgo

All 8 skills in this repo
  • Broker Integration

    marketcalls/openalgo

    Integrate a new Indian broker into OpenAlgo, or modify an existing broker plugin.

    2.8k GitHub stars~4.7k tokensUpdated today
    Auto-check: notes
  • Fd Audit

    marketcalls/openalgo

    Audit a change for resource leaks in OpenAlgo — file descriptors AND unbounded memory growth.

    2.8k GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Flow Builder

    marketcalls/openalgo

    Build, edit or debug an OpenAlgo Flow workflow - the no-code node graph at /flow.

    2.8k GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Openscript

    marketcalls/openalgo

    Write an OpenScript study or strategy for OpenAlgo, and install it into strategies/openscript/ only after it compiles.

    2.8k GitHub stars~2.3k tokensUpdated today
    Auto-check: notes
  • Security Audit

    marketcalls/openalgo

    Run OpenAlgo's periodic security audit across backend, frontend, database, cache, routes and dependencies, producing a dated xlsx report.

    2.8k GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Version Bump

    marketcalls/openalgo

    Bump a version in the OpenAlgo repo. An agent skill from marketcalls/openalgo.

    2.8k GitHub stars~1.8k tokensUpdated today
    Auto-check passed

Works with

Questions about Verify

What does Verify do?

Verify a claim before stating it, and verify a test before trusting it. Verify is an agent skill from marketcalls/openalgo. Verify a claim before stating it, and verify a test before trusting it.

When should I use Verify?

Verify fits situations like: reporting audit; scanner findings; A grep found nothing; test count looks clean.

How do I install Verify in Claude Code?

Run `npx skills add marketcalls/openalgo --skill verify -a claude-code`. Or copy the skill folder (.claude/skills/verify in marketcalls/openalgo) into .claude/skills/verify in your project. Claude Code loads it when a task matches its description.

How do I install Verify in Codex?

Run `npx skills add marketcalls/openalgo --skill verify -a codex`. Or copy the skill folder (.claude/skills/verify in marketcalls/openalgo) into .agents/skills/verify in your project. Codex loads it when a task matches its description.

Can I use Verify in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add marketcalls/openalgo --skill verify -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/verify, .gemini/skills/verify, .github/skills/verify and .opencode/skills/verify in your project.

What does Verify need to run?

Going by SKILL.md and its folder, Verify needs Python for the scripts in its folder and the command-line tools its instructions call (uv and git). Our summary lists: Python 3.

Does Verify access the network?

SKILL.md contains no URLs. Its commands use uv and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Verify safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Verify use?

Verify is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Verify use?

About 1.5k tokens (SKILL.md is roughly 6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Verify?

Skills that share tags, products or a category with Verify: Tushare Data (zillionare/zillionare, 321 stars), Kalshi Trade (ryanfrigo/kalshi-ai-trading-bot, 614 stars), Polymarket Tennis (livetennisapi/livetennisapi-mcp, 152 stars) and Quant Backtest (joemccann/market-data-warehouse, 183 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Verify?

marketcalls (a GitHub user) maintains it in marketcalls/openalgo, which has 2,808 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on October 9, 2026.

Source: marketcalls/openalgo on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.