Agent skill

App Verification

by mblode in mblode/agent-skills

Builds and maintains a repo's own verification harness (verify CLI, doctor, worktree isolation, feature map, seed data) and a reproduce-first bug handoff.

MITAuto-check passedTesting & QA

Install App Verification

skills CLI
$ npx skills add mblode/agent-skills --skill app-verification -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mblode/agent-skills app-verification --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mblode/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/app-verification .claude/skills/app-verification && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
app-verification
GitHub stars
142
Token cost
~2.3k tokens
SKILL.md length
1,163 words
Files
8 (incl. references)
Skills in repo
28
Repo updated
First seen
Licence
MIT

At a glance

Builds and maintains a repo's own verification harness (verify CLI, doctor, worktree isolation, feature map, seed data) and a reproduce-first bug handoff.

  • Asked to build a verification harness
  • SKILL.md covers Invocation, Contents, Modes and The harness contract, plus 6 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Add a doctor command

What it does

App Verification is an agent skill from mblode/agent-skills. Builds and maintains a repo's own verification harness (verify CLI, doctor, worktree isolation, feature map, seed data) and a reproduce-first bug handoff. Use when asked to "build a verification harness", "add a doctor command", "prove every feature still works", or "reproduce this bug report".

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including reference files (for example `evals/evals.json`, `references/bug-handoff.md` and `references/create-mode.md`). Compatibility notes: Create mode needs a shell and the target repo's own toolchain (whatever starts, seeds, and drives that app). Native and desktop proof paths need a…

It sits in Testing & QA, covering Test data and fixtures, Git worktrees and QA and bug reports. The repository describes itself as: Nobody ships AI slop on purpose. These skills make sure you don’t. The licence is MIT.

When your agent uses it

  • Asked to build a verification harness
  • Add a doctor command
  • Prove every feature still works
  • Reproduce this bug report

Example prompts

  • “build a verification harness”
  • “add a doctor command”
  • “prove every feature still works”
  • “/app-verification”

Requirements

  • Compatibility (from SKILL.md): Create mode needs a shell and the target repo's own toolchain (whatever starts, seeds, and drives that app). Native and desktop proof paths need a computer-use tool as the last-resort method. Runs only when called by name; see Invocation below.

What it can do on your machine

Read from SKILL.md and the folder at commit cef4cfa. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Create mode needs a shell and the target repo's own toolchain (whatever starts, seeds, and drives that app). Native and desktop proof paths need a computer-use tool as the last-resort method. Runs only when called by name; see Invocation below.

    From compatibility in the SKILL.md frontmatter.

Context cost

App Verification loads about 2.3k tokens when it runs, and up to ~12k if it reads all its reference files. Until then it costs about 78 tokens; SKILL.md has 1,163 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~78
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~12k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from mblode/agent-skills at commit cef4cfa, republished under its MIT licence (© mblode). 1,163 words, ~2,337 tokens.

Download SKILL.mdSave it as .claude/skills/app-verification/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
app-verification
description
Builds and maintains a repo's own verification harness (verify CLI, doctor, worktree isolation, feature map, seed data) and a reproduce-first bug handoff. Use when asked to "build a verification harness", "add a doctor command", "prove every feature still works", or "reproduce this bug report".
compatibility
Create mode needs a shell and the target repo's own toolchain (whatever starts, seeds, and drives that app). Native and desktop proof paths need a computer-use tool as the last-resort method. Runs only when called by name; see Invocation below.

App Verification

Builds, inside a product's own repository, the harness every agent uses to run that product and prove a claim about it: a verify CLI, a doctor command, an isolated instance per worktree, a feature map written from the user's point of view, seed data and test accounts, and a reproduce-first bug handoff. The harness lives in the target repo, not in this skill; this skill scaffolds and then maintains it, so every agent that opens that repo runs the app the same way instead of writing a throwaway script each session.

  • IS: scaffolding a project-local verification harness (Create mode) and running or extending one that already exists (Maintain mode): the verify CLI's contract, the feature-map format, the proof record, per-worktree isolation and seed data, the cheapest-method ladder up to computer use, and the bug-handoff format.
  • IS NOT: ad hoc browser probes against a fixed catalogue of UI rules (ui-verification; this skill's verify can call those probes as one check among several), repo-wide module boundaries and enforcement tooling (codebase-architecture; this skill's CI wiring follows its enforcement order), pruning an existing test suite (test-audit), or a plan for one feature (planning).

Invocation

Create mode edits the target repo and Maintain mode drives a real running instance of it; both run only when named, not from a loose "check the app" prompt a lighter skill might serve better. On a host that supports it, add disable-model-invocation: true to the installed copy's frontmatter. It is a host extension, not a portable field, so it is not shipped in this source (agent-skills-creator's references/format-specification.md explains why). Hosts with an equivalent explicit-invocation setting should apply it the same way.

Contents

Modes

Pick by what exists, and say which you picked.

ModeYou are here whenOutput
CreateThe repo has no verify CLI, doctor command, or feature map yetA working harness, proven once end to end against a real feature, handed off to Maintain mode
MaintainA harness already exists and needs to run this session, gain a feature, or investigate a bug reportA clean / changed / blocked outcome, or a reproduce-first bug handoff

Copy this to track progress:

text
App verification progress:
- [ ] Mode chosen and stated (Create / Maintain)
- [ ] doctor run first, read-only, before any drive
- [ ] Isolation confirmed: own port, own database, own browser profile; refused (not fell back to) the main instance
- [ ] Every path in scope checked or named as a skip with a reason
- [ ] Native/desktop paths, if any, verified with computer use as the last-resort method, not the first
- [ ] Outcome stated: clean / changed / blocked, or a reproduce-first handoff

The harness contract

Both modes build toward the same three commands, kept inside a skill folder in the target repo (for example .claude/skills/verify-<app>/ or that host's equivalent project-skill location) so the commands live at one path every session finds the same way.

CommandDoesMust
doctorOne read-only pass answering "is this instance worth driving": toolchain, isolation, ports, database, migrations, seed, build freshness, and whichever driver (browser, computer-use) the harness needsChanges nothing. Exits non-zero on any failure, each failure line naming the exact fix. Prints blocked by <id> for a check whose dependency already failed instead of a cascade of unrelated-looking failures. Offers --json for a caller that branches on the result
seedLoads fixed test accounts and demo dataIdempotent: safe to run twice, safe against a database that already has the seed. Refuses a non-local or main-instance database rather than seeding it
verifyRuns the checks the feature map lists for the change, cheapest method first, and writes a proof record of what ran, what it covered, what it skipped, and whyEvery path a feature lists gets a check or a named skip. Exits non-zero on a failed check or a changed source file no feature owns

doctor and verify are separate commands: one is read-only triage, the other drives and reports. Merging them hides the read-only fast check behind the slow one every time.

Create mode

references/create-mode.md. Interview the repo (surface, run, drive, observe, isolate), scaffold doctor, seed, verify and the feature map per the contract above, wire isolation before writing the first feature file, seed the top three to five features, then prove the generated harness end to end before calling it done. A harness nobody has run is a draft, not a deliverable.

Show full SKILL.md (505 more words)Show less

Maintain mode

references/maintain-mode.md. Run doctor first, every session, before the first drive and after any failed one. Pick one outcome and say which: clean (nothing needed changing), changed (one PR or commit of proven corrections to the harness itself, never to product code), or blocked (name exactly what blocked it). A maintenance run that finds a real product bug reports it; it does not quietly patch around it inside the harness.

Two things this mode owns that a lighter probe skill does not: scoped proof (every listed path checked or skipped with a reason, recorded in the proof file; references/maintain-mode.md) and the reproduce-first bug handoff, whose first line is exactly Reproduced, Reproduced but already fixed on main or Could not reproduce (references/bug-handoff.md).

References

Load only when the condition applies.

ReferenceModeRead when
references/create-mode.mdCreateBootstrapping a harness where none exists, or reshaping doctor or verify
references/maintain-mode.mdMaintainRunning or extending an existing harness, reading or writing the proof record, or auditing the harness for drift
references/feature-map-format.mdBothWriting or reading a feature file, renaming a feature id, or building the map's completeness check
references/verification-ladder.mdBothChoosing a method for a path, marking a path manual, or deciding whether a native/desktop path needs computer use
references/worktree-isolation.mdBothSetting up or checking port, database, env-file, and browser-profile isolation, or seeding test accounts and a sign-in shortcut
references/bug-handoff.mdMaintainInvestigating a bug report

Gotchas

  • A dev-only sign-in shortcut or a fixed test-account secret is a production backdoor the moment it ships enabled; gate it and verify the guard per references/worktree-isolation.md before adding one.
  • verify --fast (cli checks only) is a development convenience, never a merge gate on its own; a run that skipped every browser and computer-use check is not the same proof as a full one, and the proof record says which mode ran.
  • Two feature maps drift the moment a second one exists. Keep one canonical map per app; if a lighter probe skill also tracks routes or components, point at this map rather than growing a parallel one.
  • ui-verification: scoped browser probes against a fixed UI rule catalogue, one finding at a time. This skill's verify can call those probes for the paths they cover; it does not replace them for a rule-by-rule audit.
  • codebase-architecture: repo-wide module boundaries, CI guardrails, and the enforcement order this skill's own CI wiring follows.
  • test-audit: suite-wide pruning of a durable test suite, a different asset from the feature map here. Gating a new test in a diff is tidy.
  • planning: a plan for one feature; a new feature's plan is where its eventual feature file starts.

Maintenance only: evals/evals.json holds the behavioural scenarios and routing prompts for anyone changing this skill. It never loads during a verification run.

Credit

Builds on Lauren Tan's pstack create-verification-skill and maintain-verification-skill (MIT): the interview-then-generate method, the outcome-based maintenance loop, and the reproduce-first handoff are hers. This skill generalizes that method past one company's conventions and adds a machine-checkable proof contract. Credit them; this is not a copy of either file.

© mblode, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (references) in skills/app-verification of mblode/agent-skills.

  • SKILL.md
  • evals/evals.json
  • references/bug-handoff.md
  • references/create-mode.md
  • references/feature-map-format.md
  • references/maintain-mode.md
  • references/verification-ladder.md
  • references/worktree-isolation.md

Open the folder on GitHubat commit cef4cfa

Compare with similar skills

App Verification next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

App Verification compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
App Verification this skillmblode/agent-skills142—~2.3kAutomated safety check: PassMIT
Validate Stylebotankit/stylebot1.6k—~780Automated safety check: PassMIT
Dev Tenant APInightscout/nocturne139—~1.4kAutomated safety check: PassNone
Robotics Testingarpitg1304/robotics-agent-skills368—~4.7kAutomated safety check: PassApache-2.0
QA Sessiongetlago/lago-front163—~3.8kAutomated safety check: PassAGPL-3.0
DevSpace Manual QA SetupWaishnav/devspace5.2k—~440Automated safety check: PassMIT

Similar skills

  • Validate Stylebot

    ankit/stylebot

    Launch Stylebot in a real, headed Chrome window (via yarn dev:chrome) so the user can manually eyeball a change — in whatever checkout the current session is in, worktree or main.

    1.6k GitHub stars~780 tokensUpdated today
    Testing & QAAuto-check passed
  • Dev Tenant API

    nightscout/nocturne

    Interact with Nocturne's local dev-only API: seed a loginable tenant preloaded with realistic sample data, obtain a browser session (loginLink) or bearer token headlessly, export/re-seed the dev…

    139 GitHub stars~1.4k tokensUpdated 2 days ago
    Testing & QAAuto-check passed
  • Robotics Testing

    arpitg1304/robotics-agent-skills

    Testing strategies, patterns, and tools for robotics software.

    368 GitHub stars~4.7k tokensUpdated 1 mo ago
    Testing & QAAuto-check passed
  • QA Session

    getlago/lago-front

    A skill your agent uses when the operator wants to verify in the browser that a change works — asks "how do I test this locally?", "give me the steps", "QA this", references a worktree/PR/ticket…

    163 GitHub stars~3.8k tokensUpdated today
    Testing & QAAuto-check passed
  • DevSpace Manual QA Setup

    Waishnav/devspace

    Prepares the current DevSpace checkout or worktree for isolated local manual QA, covering QA state seeding, UI asset builds and snapshot resets.

    5.2k GitHub stars~440 tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Mock Cache Check-In

    warp-drive-data/warp-drive

    Ensures `.mock-cache` fixture directories under `tests/*` are staged and committed whenever a change adds or modifies a test that uses…

    3.2k GitHub stars~264 tokensUpdated today
    DevelopmentAuto-check passed

More from mblode/agent-skills

All 28 skills in this repo
  • Agent Ready

    mblode/agent-skills

    Implements agent-readiness on public sites and docs from Mintlify Agent Score, AFDocs, Is Agentic, Is It Agent Ready, or url-discovery-bench reports, or from server logs of agents 404ing on guessed…

    142 GitHub stars~2.1k tokensUpdated yesterday
    Auto-check passed
  • Agent Skills Creator

    mblode/agent-skills

    Creates and improves portable Agent Skills with a validator, routing scenarios, and evidence-based keep, cut, merge, or retire decisions.

    142 GitHub stars~2.8k tokensUpdated yesterday
    Auto-check passed
  • Chat History

    mblode/agent-skills

    Recovers decisions, previous fixes, research, and what followed a prompt from past AI conversations, with source evidence.

    142 GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • CI Speedup

    mblode/agent-skills

    Cuts the wait from push to green by measuring a pipeline's critical path from run timestamps, then splitting, sharding, trimming setup and sharing test module state, with a before/after ledger.

    142 GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed
  • PR Babysitter

    mblode/agent-skills

    Monitors or repairs an open GitHub PR: CI failures, conflicts, review threads, and merge readiness, reporting state changes.

    142 GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • UI Animation

    mblode/agent-skills

    Builds, reviews, and measures UI motion, including springs, gestures, scroll effects, curve fitting from recordings, and sparse interface sound.

    142 GitHub stars~5.7k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about App Verification

What does App Verification do?

Builds and maintains a repo's own verification harness (verify CLI, doctor, worktree isolation, feature map, seed data) and a reproduce-first bug handoff. App Verification is an agent skill from mblode/agent-skills. Builds and maintains a repo's own verification harness (verify CLI, doctor, worktree isolation, feature map, seed data) and a reproduce-first bug handoff.

When should I use App Verification?

App Verification fits situations like: asked to build a verification harness; add a doctor command; prove every feature still works; reproduce this bug report.

How do I install App Verification in Claude Code?

Run `npx skills add mblode/agent-skills --skill app-verification -a claude-code`. Or copy the skill folder (skills/app-verification in mblode/agent-skills) into .claude/skills/app-verification in your project. Claude Code loads it when a task matches its description.

How do I install App Verification in Codex?

Run `npx skills add mblode/agent-skills --skill app-verification -a codex`. Or copy the skill folder (skills/app-verification in mblode/agent-skills) into .agents/skills/app-verification in your project. Codex loads it when a task matches its description.

Can I use App Verification in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mblode/agent-skills --skill app-verification -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/app-verification, .gemini/skills/app-verification, .github/skills/app-verification and .opencode/skills/app-verification in your project.

What does App Verification need to run?

SKILL.md names no scripts, command-line tools or credentials: App Verification is instructions for the agent only. Compatibility (from SKILL.md): Create mode needs a shell and the target repo's own toolchain (whatever starts, seeds, and drives that app). Native and desktop proof paths need a computer-use tool as the last-resort method. Runs only when called by name; see Invocation below..

Does App Verification access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is App Verification safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does App Verification use?

App Verification is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does App Verification use?

About 2.3k tokens (SKILL.md is roughly 9.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 9.5k tokens, read only when the agent opens those files.

What are the alternatives to App Verification?

Skills that share tags, products or a category with App Verification: Validate Stylebot (ankit/stylebot, 1.6k stars), Dev Tenant API (nightscout/nocturne, 139 stars), Robotics Testing (arpitg1304/robotics-agent-skills, 368 stars) and QA Session (getlago/lago-front, 163 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains App Verification?

mblode (a GitHub user) maintains it in mblode/agent-skills, which has 142 GitHub stars. The repository holds 28 skills in this directory. The repository was last updated on October 6, 2026.

Source: mblode/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.