Agent skill

Verify

by MartinStyk in MartinStyk/apk-analyzer

Unified IDE-local verification gate for ApkAnalyzer. An agent skill from MartinStyk/apk-analyzer.

GPL-3.0Auto-check passedAgent Workflows

Install Verify

skills CLI
$ npx skills add MartinStyk/apk-analyzer --skill verify -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install MartinStyk/apk-analyzer verify --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/MartinStyk/apk-analyzer.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/verify .claude/skills/verify && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
verify
GitHub stars
369
Token cost
~2.8k tokens
SKILL.md length
1,245 words
Files
1
Skills in repo
18
Repo updated
First seen
Licence
GPL-3.0

At a glance

Unified IDE-local verification gate for ApkAnalyzer. An agent skill from MartinStyk/apk-analyzer.

  • Works in 10 steps: Parse arguments → Skip check → Context discovery (orchestrator,… → …
  • Tasks that involve Subagents
  • SKILL.md covers Arguments, Sub-agent registry, Stage 0 — Parse arguments and Stage 1 — Skip check, plus 9 more sections
  • Calls git

What it does

Verify is an agent skill from MartinStyk/apk-analyzer. Unified IDE-local verification gate for ApkAnalyzer. Diff-vs-base review pipeline — skip-check → context discovery → parallel reviewers (bug + convention + security) → issue-validator → local build gates (spotlessApply, per-module compile, conditional validateAgentContext/full whole-app check) → verify-audit → high-signal report (HIGH-confidence BLOCKER/MAJOR only).

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Agent Workflows, covering Subagents. The repository describes itself as: The most downloaded APK analysis app on Google Play. Detailed reports of every app on your device. No root, no ads, nothing leaves the phone. The licence is GPL-3.0.

When your agent uses it

  • Tasks that involve Subagents

Example prompts

  • “/verify”

Workflow steps

10 steps, taken from the step headings in SKILL.md.

  1. Parse arguments
  2. Skip check
  3. Context discovery (orchestrator, sequential reads)
  4. Diff summary (orchestrator, no sub-agent)
  5. Parallel review fan-out (SINGLE MESSAGE, MANY AGENT CALLS)
  6. Local build gates
  7. Per-issue validation (SINGLE MESSAGE, PARALLEL)
  8. Aggregate initial verdict + write report to /tmp
  9. Verify-audit discipline pass (SINGLE AGENT CALL)
  10. Apply audit + emit final output

What it can do on your machine

Read from SKILL.md and the folder at commit d807559. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Verify loads about 2.8k tokens when it runs. Until then it costs about 94 tokens; SKILL.md has 1,245 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~94
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from MartinStyk/apk-analyzer at commit d807559, republished under its GPL-3.0 licence (© MartinStyk). 1,245 words, ~2,792 tokens.

Download SKILL.mdSave it as .claude/skills/verify/SKILL.md (or your agent's skills folder).
name
verify
description
Unified IDE-local verification gate for ApkAnalyzer. Diff-vs-base review pipeline — skip-check → context discovery → parallel reviewers (bug + convention + security) → issue-validator → local build gates (spotlessApply, per-module compile, conditional validateAgentContext/full whole-app check) → verify-audit → high-signal report (HIGH-confidence BLOCKER/MAJOR only).
argument-hint
[--base=<ref>] [--full]
user-invocable
true
disable-model-invocation
false

/verify — orchestrated IDE-local code-review + build gate

You are the main agent. You orchestrate all sub-agent dispatches. Sub-agents under .claude/agents/ cannot dispatch further sub-agents (Claude Code architectural constraint). All parallel fan-out happens from your context.

This command is the single verification gate for any finished piece of work in this repo — a module addition, a bug fix, a scratch experiment. It diffs the working branch against a base ref and runs a tight, high-signal review grounded in this repo's AGENTS.md files. Only issues that any contributor who knows AGENTS.md would say "yes, that has to be fixed before this is pushed" reach the final report.

This is heavier than the "don't run these after every edit" guidance in root AGENTS.md — that guidance is about not gating local iteration. /verify is what you run once, deliberately, before opening a PR, in place of running the gates by hand.

Arguments

The user invoked: /verify $ARGUMENTS

$ARGUMENTS is optional. Recognized flags (any order, both optional):

  • --base=<ref> — git ref to diff against. Default: develop (this repo's main branch).
  • --full — also run the whole-app check (spotlessCheck detektDebug :build-logic:convention:detektMain lintDebug :app:assembleDebug) in Stage 5, matching what CI gates on. Without it, Stage 5 only runs spotlessApply plus a compile of the touched modules — fast, matching the "iterate on a single-module compile" guidance in root AGENTS.md.

Any other token, any malformed flag, or any unrecognized form → emit INVALID_INVOCATION (Stage 8 format) with the offending token in Notes and stop.

Sub-agent registry

namemodelrole
skip-checkerhaikuStage 1 — decides SKIP yes/no
bug-revieweropusStage 4 — logic bug pass over the diff
convention-reviewersonnetStage 4 — convention compliance grounded in AGENTS.md / docs/engineering/
security-revieweropusStage 4 — security and behavior deviation
issue-validatoropusStage 6 — confirms each emitted issue independently
verify-auditsonnetStage 9 — discipline pass over the initial report; emits per-finding KEEP / CUT / UNSURE

Dispatch them with subagent_type: "<name>" on the Agent tool.


Stage 0 — Parse arguments

  1. Tokenize $ARGUMENTS. Empty → defaults (base=develop, full=false).
  2. For each token, match --base=<ref> or --full. Anything else → INVALID_INVOCATION (Stage 8 format) and stop.

Stage 1 — Skip check

Compute changed_files = git diff <base>...HEAD --name-only. If empty, emit SKIPPED (Stage 8 format) with reason "no diff vs <base>" and stop.

Otherwise dispatch one skip-checker Agent call. Pass diff_command (e.g. git diff <base>...HEAD) and changed_files (newline-separated).

If the agent returns {"skip": true, ...}, jump straight to Stage 8 with verdict SKIPPED and the agent's reason in Notes. Do not proceed past Stage 1.

Stage 2 — Context discovery (orchestrator, sequential reads)

Read into your context (these are ground truth for downstream leaves). Collect their absolute paths in a discovered_files list:

  • Root AGENTS.md (always).
  • docs/engineering/coding-standards.md and docs/engineering/architecture.md (always — these expand the root AGENTS.md rules with the worked examples reviewers can quote).
  • For every file in changed_files, the nearest module-scoped AGENTS.md: walk up from the changed file's directory until you find an AGENTS.md other than the root one (same algorithm validateAgentContext uses to bind a Gradle module to its AGENTS.md). Deduplicate.

Also record, from the same scan:

  • changed_modules — the set of Gradle module directories touched (walk up from each changed .kt/.kts file to the nearest directory containing a build.gradle.kts).
  • context_files_touched — true if any changed file is an AGENTS.md, a CLAUDE.md, anything under .claude/skills/, .github/copilot-instructions.md, anything under build-logic/, settings.gradle.kts, or a library/plugin/bundle entry (not just a version bump) in gradle/libs.versions.toml.

Stage 3 — Diff summary (orchestrator, no sub-agent)

Run git diff <base>...HEAD <files> and produce a 5–10 line factual summary of what changed. Keep it short — it's an aid for the reviewers, not user output.

Stage 4 — Parallel review fan-out (SINGLE MESSAGE, MANY AGENT CALLS)

In one assistant turn, dispatch the following in parallel — separate Agent tool calls within the same message:

  1. bug-reviewer × 1. Payload: diff, diff_summary, discovered_files.
  2. convention-reviewer × 1. Payload: same.
  3. security-reviewer × 1. Payload: same.

If any *Test.kt file is in the diff (an explicitly-requested exception to the "no test infrastructure" rule), it's part of diff and is reviewed by all three under the same rules as production code.

Hard rule: parallel Agent calls in one assistant turn. Sequential dispatch is a bug.

Collect every JSON response. Build a single findings list of issues (each tagged with its origin category).

Stage 5 — Local build gates

  1. Always: ./gradlew spotlessApply — the one gate root AGENTS.md requires before every commit. If it rewrites files, note which ones in Notes; those rewrites are not separately re-reviewed by Stage 4.
  2. Always, per module in changed_modules: ./gradlew <module>:compileDebugKotlin (use <module>:compileKotlin for a module with no Android debug variant).
  3. Conditional — context_files_touched is true OR --full was passed: ./gradlew validateAgentContext.
  4. Conditional — --full was passed: the whole-app check — ./gradlew spotlessCheck detektDebug :build-logic:convention:detektMain lintDebug :app:assembleDebug.

Capture PASS / FAIL and the full failing-task output verbatim for every task actually run.

Show full SKILL.md (459 more words)Show less

Stage 6 — Per-issue validation (SINGLE MESSAGE, PARALLEL)

Dedupe findings by (file, line, title). For every surviving issue, dispatch one issue-validator Agent call in a single turn — passing only that one issue object (not the full diff, not other findings).

Filter the validated set to HIGH-confidence + severity ∈ {BLOCKER, MAJOR}. Everything else is dropped (any MEDIUM- or LOW-confidence result, and any MINOR / NIT severity, even when validated). The surviving set is what you report and what feeds the verdict.

Stage 7 — Aggregate initial verdict + write report to /tmp

Initial verdict priority (first match wins):

  1. INVALID_INVOCATION — Stage 0 rejected args.
  2. SKIPPED — Stage 1 said skip or empty diff.
  3. GATES_FAILED — any Stage 5 task failed.
  4. FIXES_REQUIRED — Stage 6 surviving findings include any BLOCKER or MAJOR.
  5. PASS — none of the above.
Write the initial report to /tmp (input for Stage 8)

If the initial verdict is SKIPPED or INVALID_INVOCATION, skip the rest of Stage 7 and skip Stage 8 entirely — there are no findings to audit. Emit the final output (Stage 9 format) directly using the initial verdict and the Notes reason.

Otherwise:

bash
mkdir -p /tmp/apkanalyzer-verify.$$

Write the following to /tmp/apkanalyzer-verify.$$/report.md:

## Verdict
<initial verdict>

## Gates
<one line per Gradle task actually run: `PASS <task>` or `FAIL <task>` + indented failing output>

## Findings
<numbered list; each item: severity, category, file:line, title, evidence, explanation, rule_citation if convention>

## Notes
<anything else, including any spotlessApply rewrites from Stage 5>

Number every finding sequentially across categories (1, 2, 3, …). The numbers are what Stage 8's audit table references.

Stage 8 — Verify-audit discipline pass (SINGLE AGENT CALL)

Skipped when Stage 7 short-circuited at SKIPPED or INVALID_INVOCATION.

Dispatch one verify-audit Agent call. Payload:

  • report_path — /tmp/apkanalyzer-verify.$$/report.md.
  • audit_output_path — /tmp/apkanalyzer-verify.$$/audit.md.
  • changed_files — the Stage 1 changed_files list (newline-separated).
  • discovered_files — the Stage 2 discovered_files list (newline-separated absolute paths).
  • worktree_root — the repo root absolute path (output of git rev-parse --show-toplevel).

The agent will Write the audit table to audit_output_path and reply with that path. Read the file. It contains a markdown table:

| # | Finding | Verdict | Trigger | Reason |
|---|---|---|---|---|
| 1 | <finding 1 title> | KEEP | none | ... |
| 2 | <finding 2 title> | CUT | quoted rule doesn't exist | ... |
| 3 | <finding 3 title> | UNSURE | bug finding requires out-of-diff context | ... |

Stage 9 — Apply audit + emit final output

Apply the audit row-by-row to the Stage 7 findings list (numbers match):

  • KEEP → finding stays in the final report unchanged.
  • CUT → finding is removed from the final report.
  • UNSURE → finding stays, but prefix its title with [UNVERIFIED] so the user knows the audit couldn't confirm it cheaply.

Recompute the verdict from the post-audit findings list using the Stage 7 vocabulary. The verdict can downgrade for reviewer findings — e.g. if every BLOCKER was CUT, FIXES_REQUIRED can become PASS. The verdict does not downgrade past GATES_FAILED, which is immune to audit filtering: a failing Gradle task is a fact about the codebase, not a subjective reviewer finding.

Emit the final user-facing output:

## Verdict
<recomputed verdict>

## Gates
<one line per Gradle task actually run: `PASS <task>` or `FAIL <task>` + indented failing output>

## Findings
<post-audit findings: KEEP-rated and UNSURE-rated (prefixed `[UNVERIFIED]`). Grouped by category. Omit section if empty.>

## Audit
<the full markdown table from Stage 8, including CUT rows so the user sees what was filtered and why>

## Notes
<anything noteworthy; reason for SKIPPED / INVALID_INVOCATION; brief comment if the audit changed the verdict>

Omit sections that are empty / not applicable. Stop after emitting.

Re-invocation contract

If the recomputed verdict is FIXES_REQUIRED or GATES_FAILED, address every surviving finding (or document why a finding is rejected by quoting the discovered rule that contradicts it), then re-run /verify with the same args. Only consider a piece of work shippable / mergeable once /verify returns PASS or SKIPPED.

© MartinStyk, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/verify of MartinStyk/apk-analyzer.

Open the folder on GitHubat commit d807559

Compare with similar skills

Verify next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Verify compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Verify this skillMartinStyk/apk-analyzer369—~2.8kAutomated safety check: PassGPL-3.0
O2 Review Loopopenobserve/openobserve22k—~3.7kAutomated safety check: PassAGPL-3.0
Kimi Code DelegationCherryHQ/cherry-studio52k1 repos~504Automated safety check: PassAGPL-3.0
V2 Perf Iterationmirage-project/mirage2.5k—~4kAutomated safety check: PassApache-2.0
Clone App Pat Proper-simmons/clone-app-pat-pro-public259—~1.9kAutomated safety check: NotesNone
Swarm Orchestrationruvnet/ruflo74k2 repos~779Automated safety check: PassMIT

Similar skills

  • O2 Review Loop

    openobserve/openobserve

    Splits a change into planner, coder and independent reviewer roles: you confirm a spec, a subagent implements it, and a separate reviewer checks each round's local WIP commit.

    22k GitHub stars~3.7k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Kimi Code Delegation

    CherryHQ/cherry-studio

    Delegates one bounded repository task to Kimi Code in non-interactive prompt mode and reads back the final result from its JSON event stream.

    52k GitHub starsUsed in 1 repo~504 tokens
    Agent WorkflowsAuto-check passed
  • V2 Perf Iteration

    mirage-project/mirage

    Runtime-V2 performance-iteration workflow. An agent skill from mirage-project/mirage.

    2.5k GitHub stars~4k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Clone App Pat Pro

    per-simmons/clone-app-pat-pro-public

    Clones any web app pixel-for-pixel from a URL. An agent skill from per-simmons/clone-app-pat-pro-public.

    259 GitHub stars~1.9k tokensUpdated 4 mo ago
    Agent WorkflowsAuto-check: notes
  • Coordinates a hierarchical swarm of specialized agents through the claude-flow CLI for work that spans several files or modules at once.

    74k GitHub starsUsed in 2 repos~779 tokens
    Agent WorkflowsAuto-check passed
  • Team Mode

    oil-oil/codex-team-mode

    A skill your agent uses when a task may benefit from a bounded subagent for implementation, large-codebase discovery at task start, independent review, requested or pre-commit code simplification…

    216 GitHub stars~1.3k tokensUpdated 7 days ago
    Agent WorkflowsAuto-check passed

More from MartinStyk/apk-analyzer

All 18 skills in this repo
  • Triage Crashes

    MartinStyk/apk-analyzer

    A skill your agent uses to review production Crashlytics crashes and non-fatals for the latest release and file a GitHub issue for each one that isn't tracked yet.

    369 GitHub stars~4.3k tokensUpdated 3 days ago
    Auto-check passed
  • Analyze CI Failure

    MartinStyk/apk-analyzer

    A skill your agent uses to check GitHub Actions build status or diagnose why a workflow run failed and propose a fix.

    369 GitHub stars~1.9k tokensUpdated 3 days ago
    Auto-check passed
  • Capture App Flow Media

    MartinStyk/apk-analyzer

    A skill your agent uses to record or convert ApkAnalyzer app flows into screenshots or GIFs for the README or product docs.

    369 GitHub stars~1.7k tokensUpdated 3 days ago
    Auto-check passed
  • Create Compose Component

    MartinStyk/apk-analyzer

    A skill your agent uses when creating a new reusable Compose UI component that should live in core:ui-library.

    369 GitHub stars~885 tokensUpdated 3 days ago
    Auto-check passed
  • Create Core Module

    MartinStyk/apk-analyzer

    A skill your agent uses when creating a new core or shared library module for domain logic, data access, repositories, managers, or utilities.

    369 GitHub stars~1.7k tokensUpdated 3 days ago
    Auto-check passed
  • Create Feature Module

    MartinStyk/apk-analyzer

    A skill your agent uses when creating a new feature module, screen, or feature area.

    369 GitHub stars~1.6k tokensUpdated 3 days ago
    Auto-check passed

Questions about Verify

What does Verify do?

Unified IDE-local verification gate for ApkAnalyzer. An agent skill from MartinStyk/apk-analyzer. Verify is an agent skill from MartinStyk/apk-analyzer. Unified IDE-local verification gate for ApkAnalyzer.

When should I use Verify?

Verify fits situations like: tasks that involve Subagents.

How do I install Verify in Claude Code?

Run `npx skills add MartinStyk/apk-analyzer --skill verify -a claude-code`. Or copy the skill folder (.claude/skills/verify in MartinStyk/apk-analyzer) into .claude/skills/verify in your project. Claude Code loads it when a task matches its description.

How do I install Verify in Codex?

Run `npx skills add MartinStyk/apk-analyzer --skill verify -a codex`. Or copy the skill folder (.claude/skills/verify in MartinStyk/apk-analyzer) into .agents/skills/verify in your project. Codex loads it when a task matches its description.

Can I use Verify in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add MartinStyk/apk-analyzer --skill verify -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/verify, .gemini/skills/verify, .github/skills/verify and .opencode/skills/verify in your project.

What does Verify need to run?

Going by SKILL.md and its folder, Verify needs the command-line tools its instructions call (git).

Does Verify access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Verify safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Verify use?

Verify is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Verify use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Verify?

Skills that share tags, products or a category with Verify: O2 Review Loop (openobserve/openobserve, 22k stars), Kimi Code Delegation (CherryHQ/cherry-studio, 52k stars), V2 Perf Iteration (mirage-project/mirage, 2.5k stars) and Clone App Pat Pro (per-simmons/clone-app-pat-pro-public, 259 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Verify?

MartinStyk (a GitHub user) maintains it in MartinStyk/apk-analyzer, which has 369 GitHub stars. The repository holds 18 skills in this directory. The repository was last updated on October 5, 2026.

Source: MartinStyk/apk-analyzer on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.