Agent skill

Audit Public Operation Contracts

by morluto in morluto/jacobian

Design or audit a Jacobian operation’s mathematical contract, boundedness, exact results, and composition.

MITAuto-check passedResearch & Science

Install Audit Public Operation Contracts

skills CLI
$ npx skills add morluto/jacobian --skill audit-public-operation-contracts -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install morluto/jacobian audit-public-operation-contracts --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/morluto/jacobian.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/audit-public-operation-contracts .claude/skills/audit-public-operation-contracts && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
audit-public-operation-contracts
GitHub stars
220
Token cost
~2k tokens
SKILL.md length
965 words
Files
3 (incl. references)
Skills in repo
11
Repo updated
First seen
Licence
MIT

At a glance

Design or audit a Jacobian operation’s mathematical contract, boundedness, exact results, and composition.

  • Tasks that involve Math and symbolic computation
  • SKILL.md covers Design before implementation, Trace the contract, Follow shared interpretations… and Probe the plausible failures, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Audit Public Operation Contracts is an agent skill from morluto/jacobian. Design or audit a Jacobian operation’s mathematical contract, boundedness, exact results, and composition.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `agents/openai.yaml` and `references/scale-and-backends.md`).

It sits in Research & Science, covering Math and symbolic computation. It works with Model Context Protocol. The repository describes itself as: Composable mathematics tools for agents. The licence is MIT.

When your agent uses it

  • Tasks that involve Math and symbolic computation

Example prompts

  • “/audit-public-operation-contracts”

What it can do on your machine

Read from SKILL.md and the folder at commit 9dc2aaf. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Audit Public Operation Contracts loads about 2k tokens when it runs, and up to ~3.7k if it reads all its reference files. Until then it costs about 35 tokens; SKILL.md has 965 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~35
When it runs · the whole SKILL.md, loaded when a task matches
~2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from morluto/jacobian at commit 9dc2aaf, republished under its MIT licence (© morluto). 965 words, ~1,975 tokens.

Download SKILL.mdSave it as .claude/skills/audit-public-operation-contracts/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
audit-public-operation-contracts
description
Design or audit a Jacobian operation’s mathematical contract, boundedness, exact results, and composition.

Audit Public Operation Contracts

Determine whether an operation is a bounded, truthful, composable mathematical instrument. Record the revision, operation IDs, inspected scope, and whether the request includes implementation. Audit-only work does not authorize repository or external mutations.

Design before implementation

Before adding a public operation or library abstraction, apply the vocabulary audit to the proposed boundary. Keep concise evidence in the existing issue or PR, reusing what is already established rather than creating a mandatory review form:

  • State the exact mathematical postcondition and essential hypotheses.
  • Name the nearest existing operation or composition and the specific result it cannot supply. Give a smallest separating example and a nearby case the proposal deliberately does not solve.
  • Walk one input through its canonical result to an intended consumer. Decide only relevant questions about source identity, multiplicity, ordering, empty or degenerate carriers, finite versus infinite solution sets, and one witness versus exhaustive output.
  • Choose the appropriate disposition: public operation, native-only function, shared representation, private helper, regression fixture, or caller reasoning. A composition or no-gap finding is a successful outcome, not a reason to manufacture another operation.

A justified boundary has one stable mathematical result, not a whole-proof API, assurance wrapper, workflow state, or compatibility metadata. Keep the existing composition and scale-first obligations below; a separating example motivates investigation but does not establish an admitted implementation.

Trace the contract

Treat request representation, canonical values, semantic admission, kernel, trusted result construction, and downstream consumers as one execution path. Inspect schemas, declarations, examples, and MCP errors when public projection is in scope. The implementation alone does not define the advertised contract.

Use the applicable sections of the operation library. For public admission, consult the admission contract; for a backend boundary, consult the backend contract. Record applicable evidence in the requested audit or existing issue/PR description; do not create a universal review form.

Follow shared interpretations through their consumers

When changing field/domain recognition, shape resolution, codec parsing or canonical conversion, identify the semantic owner and trace the actual callers that rely on its interpretation. Do not infer every possible producer-consumer pair from annotations. Similar-looking code may have different mathematical meanings: share an implementation when semantics are genuinely identical, or state and test a legitimate contextual difference instead of forcing reuse.

Run the same owner-local fixture through the relevant recognizer, resolver and consumer, with a useful accepted case and an invalid case that stays rejected. Cover alternate supported spellings, aliases/qualified forms, nesting and empty/zero/singleton cases only where they belong to that contract. For static checks, include binding and scope: unrelated guards, reassignment, destructured names and shadowing must not falsely establish the required property.

For example, the three-level annotation fixture in tests/tooling/test_before_validator_containers.py checks container recognition, nested shape resolution and the projection consumer together, including shallow projection, unrelated-guard and destructured-rebinding controls. Keep this at the owner boundary; add no duplicate runtime validation layer, generic ledger, transport abstraction or catalog-wide generated matrix.

Probe the plausible failures

Use small deterministic reproductions to test the suspected mechanism:

  • accepted requests beyond the backend domain or admitted work/growth bounds;
  • useful structured requests rejected by an ambient-size or expansion-based limit;
  • repeated admission or computation during validation and result construction;
  • lost units, multiplicities, axes, parents, witnesses, or reconstruction data;
  • independently supplied claims accepted without establishing the needed property;
  • incompatible producer/consumer values, including empty or singular cases;
  • implicit changes of ring, field, parent, or axes; and
  • advertised semantics that disagree with the typed result or kernel.

Check serialized producer-consumer composition when relevant. Defining-invariant proof belongs in tests or an admitted caller-claim operation, not replay during ordinary result construction. Use current official backend documentation and the pinned implementation for consequential backend claims.

For a representation, performance, admission-limit, or backend-selection investigation, read scale and backends. Audit what the contract unnecessarily excludes as well as what it unsafely accepts. Preserve the motivating request and exact invariant; a fast but weaker result is not a scale improvement.

Show full SKILL.md (321 more words)Show less

Check a justified transformation

For a changed mathematical owner, choose a relevant invariant or equivariance and derive its expected effect before writing the test. Relabelling may preserve a scalar invariant while transporting indexed witnesses; row permutations must preserve the intended set or multiset semantics. Translation preserves planar squared circumradii, while scaling by nonzero c multiplies them by c². Translation preserves repeated differences; an invertible linear coordinate map transports their values and preserves their multiplicities. These are examples, not a requirement that every operation support every transformation. State when the transformation changes the problem or leaves the admitted domain.

Use the actual source and an independent defining-identity check, alongside the relation between transformed outputs. Include a negative control for an invalid invariance assumption or lost source indices/multiplicities. For a transformation or encoding operation, check that source identities, hypotheses and the intended relation survive the map: correct solver execution on the encoded problem does not establish that the mathematical model was valid.

Keep these tests with the affected owner. Do not introduce a catalog-wide matrix, generic assurance fields, or repeated expensive verification during result construction. A concrete example is tests/math/combinatorics/additive/test_difference_profile_equivariance.py: affine coordinate changes and source permutations are checked against exact source subtraction, with stale-index and noninjective-map controls.

Establish the finding and finish

After proving a defect, inspect the owner, shared helper, and its callers for the same mechanism, keeping adjacent candidates confirmed, disproved, or untested. Choose a repair at the invariant's owning boundary. Preserve a regression that fails on the base for the intended reason when feasible, using an independent oracle, defining identity, or adversarial composition rather than source-text assertions. Select validation through the contributor guide's owning lanes.

Report the public claim, reproduction and observed result, violated invariant, affected scope, smallest repair, and meaningful proof gaps. If implementation was authorized, complete the focused repair and affected checks before handing back; existing authorization persists, but local investigation does not grant permission for external writes.

© morluto, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in .agents/skills/audit-public-operation-contracts of morluto/jacobian.

  • SKILL.md
  • agents/openai.yaml
  • references/scale-and-backends.md

Open the folder on GitHubat commit 9dc2aaf

Compare with similar skills

Audit Public Operation Contracts next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Audit Public Operation Contracts compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Audit Public Operation Contracts this skillmorluto/jacobian220—~2kAutomated safety check: PassMIT
Research RefinezjYao36/Auto-Research-Refine1286 repos~6.9kAutomated safety check: NotesNone
Read GitHubAgentTeam-TaichuAI/ScienceClaw6712 repos~638Automated safety check: PassNone
Proof Run Orchestratorwanshuiyin/Auto-claude-code-research-in-sleep17k1 repos~4.7kAutomated safety check: PassMIT
FirstdataMLT-OSS/FirstData184—~3.1kAutomated safety check: PassMIT
Fin Generate Ideacsmar432/finai-research109—~2.5kAutomated safety check: PassMIT

Similar skills

  • Research Refine

    zjYao36/Auto-Research-Refine

    Turns a vague research direction into a focused, problem-anchored method plan through up to five review rounds with a second model.

    128 GitHub starsUsed in 6 repos~6.9k tokens
    Research & ScienceAuto-check: notes
  • Read GitHub

    AgentTeam-TaichuAI/ScienceClaw

    Read and search GitHub repository documentation via gitmcp.io MCP service.

    671 GitHub starsUsed in 2 repos~638 tokens
    Research & ScienceAuto-check passed
  • Proof Run Orchestrator

    wanshuiyin/Auto-claude-code-research-in-sleep

    Runs a mathematical proof project as a stateful pipeline of run directories: a local attempt first, then a manual GPT Pro handoff package, with an optional DeepSeek audit.

    17k GitHub starsUsed in 1 repo~4.7k tokens
    Research & ScienceAuto-check passed
  • Firstdata

    MLT-OSS/FirstData

    Find official portals, APIs, and download paths for authoritative primary data sources (governments, international organizations, research institutions, etc.).

    184 GitHub stars~3.1k tokensUpdated 8 days ago
    Research & ScienceAuto-check passed
  • Fin Generate Idea

    csmar432/finai-research

    针对经济金融研究方向的创意生成与评估。生成8-12个可发表的研究idea,过滤后在数据可行的情况下进行小规模实证验证,输出排序后的研究想法报告。

    109 GitHub stars~2.5k tokensUpdated 5 days ago
    Research & ScienceAuto-check passed
  • Math Proof Solo

    anthropics/claude-plugins-official

    Official

    Solves one hard mathematics problem in a single session without subagents, keeping settled steps in a notes file and ending with a self-contained proof.md.

    38k GitHub stars~1.5k tokensUpdated today
    Research & ScienceAuto-check passed

More from morluto/jacobian

All 11 skills in this repo
  • Evaluate Jacobian reliability using recently resolved conjectures as held-out probes.

    220 GitHub stars~816 tokensUpdated 5 days ago
    Auto-check passed
  • Harbor Benchmarks

    morluto/jacobian

    Author, package, validate, or run mathematical evaluations as Jacobian Harbor datasets.

    220 GitHub stars~690 tokensUpdated 5 days ago
    Auto-check passed
  • Extract reusable Jacobian capabilities from a mathematical solution corpus, rather than one agent trajectory.

    220 GitHub stars~1.9k tokensUpdated 5 days ago
    Auto-check passed
  • Investigate MCP tool availability, discovery, and selection, including controlled adoption evaluations.

    220 GitHub stars~1k tokensUpdated 5 days ago
    Auto-check passed
  • Review mathematical agent trajectories for evidence-backed Jacobian improvements; do not resume solving.

    220 GitHub stars~848 tokensUpdated 5 days ago
    Auto-check passed
  • Verifier Evaluations

    morluto/jacobian

    Design, audit, or repair mathematical benchmark verifiers, submission contracts, and scoring.

    220 GitHub stars~661 tokensUpdated 5 days ago
    Auto-check passed

Questions about Audit Public Operation Contracts

What does Audit Public Operation Contracts do?

Design or audit a Jacobian operation’s mathematical contract, boundedness, exact results, and composition. Audit Public Operation Contracts is an agent skill from morluto/jacobian. Design or audit a Jacobian operation’s mathematical contract, boundedness, exact results, and composition.

When should I use Audit Public Operation Contracts?

Audit Public Operation Contracts fits situations like: tasks that involve Math and symbolic computation.

How do I install Audit Public Operation Contracts in Claude Code?

Run `npx skills add morluto/jacobian --skill audit-public-operation-contracts -a claude-code`. Or copy the skill folder (.agents/skills/audit-public-operation-contracts in morluto/jacobian) into .claude/skills/audit-public-operation-contracts in your project. Claude Code loads it when a task matches its description.

How do I install Audit Public Operation Contracts in Codex?

Run `npx skills add morluto/jacobian --skill audit-public-operation-contracts -a codex`. Or copy the skill folder (.agents/skills/audit-public-operation-contracts in morluto/jacobian) into .agents/skills/audit-public-operation-contracts in your project. Codex loads it when a task matches its description.

Can I use Audit Public Operation Contracts in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add morluto/jacobian --skill audit-public-operation-contracts -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-public-operation-contracts, .gemini/skills/audit-public-operation-contracts, .github/skills/audit-public-operation-contracts and .opencode/skills/audit-public-operation-contracts in your project.

What does Audit Public Operation Contracts need to run?

SKILL.md names no scripts, command-line tools or credentials: Audit Public Operation Contracts is instructions for the agent only.

Does Audit Public Operation Contracts access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Audit Public Operation Contracts safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Audit Public Operation Contracts use?

Audit Public Operation Contracts is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Audit Public Operation Contracts use?

About 2k tokens (SKILL.md is roughly 7.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.7k tokens, read only when the agent opens those files.

What are the alternatives to Audit Public Operation Contracts?

Skills that share tags, products or a category with Audit Public Operation Contracts: Research Refine (zjYao36/Auto-Research-Refine, 128 stars), Read GitHub (AgentTeam-TaichuAI/ScienceClaw, 671 stars), Proof Run Orchestrator (wanshuiyin/Auto-claude-code-research-in-sleep, 17k stars) and Firstdata (MLT-OSS/FirstData, 184 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Audit Public Operation Contracts?

morluto (a GitHub user) maintains it in morluto/jacobian, which has 220 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on October 5, 2026.

Source: morluto/jacobian on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.