Agent skill

Audit Reference Originality

by nirholas in nirholas/three.ws

Audit a website or digital experience against its supplied source references for originality and plagiarism risk.

Apache-2.0Auto-check passed

Install Audit Reference Originality

skills CLI
$ npx skills add nirholas/three.ws --skill audit-reference-originality -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install nirholas/three.ws audit-reference-originality --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/nirholas/three.ws.git skills-src && mkdir -p .claude/skills && cp -r skills-src/third_party/designcode-agent-skills/agent-skills/codex/audit-reference-originality .claude/skills/audit-reference-originality && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
audit-reference-originality
GitHub stars
227
Used in
1 other repo
Token cost
~1.8k tokens
SKILL.md length
868 words
Files
4 (incl. scripts, references)
Skills in repo
92
Repo updated
First seen
Licence
Apache-2.0

At a glance

Audit a website or digital experience against its supplied source references for originality and plagiarism risk.

  • Works in 6 steps: Build the source registry → Inventory the current site and its history → Compare category by category → …
  • Codex must compare current
  • SKILL.md covers Preserve the audit boundary, 1. Build the source registry, 2. Inventory the current site… and 3. Compare category by category, plus 4 more sections
  • Runs Python scripts from its folder; calls git and python

What it does

Audit Reference Originality is an agent skill from nirholas/three.ws. Audit a website or digital experience against its supplied source references for originality and plagiarism risk. Use when Codex must compare current or historical site output with reference pages, capture packs, screenshots, copy, brands, numbers, images, assets, videos, layouts, motion, or code; raise evidence-backed red flags; distinguish common visual grammar from distinctive copying; and propose concrete fixes without making unsupported legal claims.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts and reference files (for example `agents/openai.yaml`, `references/audit-rubric.md` and `scripts/build_evidence_inventory.py`).

The repository describes itself as: Open-source platform for 3D AI agents. Turn text or a photo into a rigged, animated GLB avatar, give it an LLM brain, memory and a wallet, and embed it anywhere with one web… The licence is Apache-2.0.

When your agent uses it

  • Codex must compare current
  • Historical site output with reference pages
  • Raise evidence-backed red flags
  • Distinguish common visual grammar from distinctive copying

Example prompts

  • “/audit-reference-originality”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Build the source registry
  2. Inventory the current site and its history
  3. Compare category by category
  4. Triangulate every red flag
  5. Propose fixes
  6. Report the result

What it can do on your machine

Read from SKILL.md and the folder at commit ddf6e49. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • git
    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Audit Reference Originality loads about 1.8k tokens when it runs, and up to ~3.1k if it reads all its reference files. Until then it costs about 122 tokens; SKILL.md has 868 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~122
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from nirholas/three.ws at commit ddf6e49, republished under its Apache-2.0 licence (© nirholas). 868 words, ~1,762 tokens.

Download SKILL.mdSave it as .claude/skills/audit-reference-originality/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
audit-reference-originality
description
Audit a website or digital experience against its supplied source references for originality and plagiarism risk. Use when Codex must compare current or historical site output with reference pages, capture packs, screenshots, copy, brands, numbers, images, assets, videos, layouts, motion, or code; raise evidence-backed red flags; distinguish common visual grammar from distinctive copying; and propose concrete fixes without making unsupported legal claims.

Audit Reference Originality

Compare the shipped experience with the complete reference corpus. Treat the audit as an evidence exercise, not a vibe check.

Preserve the audit boundary

  • Audit only unless the user also asks for fixes.
  • Call findings originality risks, overlaps, or red flags; do not declare legal plagiarism from visual similarity alone.
  • Pair every red flag with exact current-site evidence and exact reference evidence.
  • Keep fact, inference, and unknown access separate.
  • Do not clear a site after checking only its homepage screenshot.

1. Build the source registry

Start with the materials explicitly supplied in the task or recorded by the project:

  • manifests, prompt packs, and originality matrices
  • representative stills, full-page captures, and section crops
  • MP4s and extracted motion frames
  • reference URLs and named creators
  • source brand assets, copy, numbers, screenshots, and downloads
  • project briefs, IMAGE_CREDITS.md, licenses, and attribution files

Prefer local evidence captured at the time of the brief. Use a live reference only to fill a real gap, because it may have changed. Record each reference's path or URL, role, date when known, and which categories it can prove.

Stop and report an access gap when a promised reference is missing. Do not silently reduce a full-page or motion audit to one cover image.

2. Inventory the current site and its history

Inspect:

  • rendered text, metadata, navigation, calls to action, legal copy, and hidden accessible labels
  • brand names, wordmarks, logos, icons, people, companies, URLs, and product/interface data
  • prices, metrics, dates, counts, percentages, package names, and repeated proof claims
  • every rendered image, background, texture, screenshot, font, logo, icon, audio file, and downloadable asset
  • every video, poster, frame sequence, shot order, transition, duration, and playback treatment
  • layout hierarchy, section order, distinctive compositions, typography behavior, motion grammar, shaders, cursor effects, and interaction sequences
  • current source, built output when available, asset provenance, and repository history

Do not trust filenames as proof of originality. Inspect the bytes, visible result, and history. Search renamed, deleted, and replaced files with git log, git show, git log -S, and git log --all --name-status.

Run the deterministic inventory helper when local files are available:

bash
python <skill-dir>/scripts/build_evidence_inventory.py \
  --site <site-root> \
  --reference <reference-file-or-directory> \
  --reference <another-reference> \
  --output <temporary-output.json>

The helper finds current and historical exact-file matches, suspicious basename reuse, normalized text overlap, and repeated number tokens. Treat its output as leads for human review, not an automatic verdict.

3. Compare category by category

Read references/audit-rubric.md before judging findings.

Audit at least these categories:

  1. Text — headlines, body copy, labels, CTAs, captions, legal text, alt text, metadata, and decorative wording.
  2. Brands — names, marks, wordmarks, proprietary icons, people, companies, partnerships, URLs, and distinctive verbal identity.
  3. Numbers — metrics, percentages, prices, dates, counts, plan structures, durations, and interface values.
  4. Images — exact files, crops, generated derivatives, screenshots, people, poses, objects, signature compositions, and color treatment.
  5. Assets — fonts, icons, logos, textures, mockups, downloads, code bundles, and third-party media with unclear provenance.
  6. Videos — exact files, frames, shots, timing, camera moves, edit rhythm, transitions, overlays, posters, and audio.
  7. Structure and motion — section order, unusual layout devices, pinned sequences, cursor interactions, shaders, and combinations of signature elements.
  8. History — copied material that was later renamed, recolored, cropped, hidden, deleted, or replaced.

Common patterns such as black backgrounds, large sans-serif type, ordinary pricing tables, standard fade-ins, or a conventional footer are not red flags by themselves. Escalate combinations of distinctive elements or direct evidence.

Show full SKILL.md (319 more words)Show less

4. Triangulate every red flag

For each candidate:

  1. Identify the current-site artifact and location.
  2. Identify the exact reference artifact and location.
  3. State the observable overlap without guessing intent.
  4. State what differs.
  5. Assign severity using the rubric.
  6. Propose the smallest fix that breaks the overlap while preserving the site's goal.

Use hashes for exact files, normalized excerpts for copy, side-by-side crops for imagery, and matched timestamps or frames for video. A source-brand string found only in a test that explicitly forbids it is not a shipped-copy violation; explain context.

5. Propose fixes

Prefer concrete replacements:

  • rewrite source-like copy from the new brand's audience, offer, and vocabulary
  • replace names, URLs, logos, people, metrics, dates, plan names, and legal text
  • regenerate or license new imagery with a materially different subject, composition, and motif arrangement
  • replace copied assets and document provenance
  • re-cut videos with new shots, timing, transitions, overlays, and audio
  • reorder or redesign distinctive section and motion sequences
  • remove stale source material from current output and, when required, repository history or published artifacts

Do not recommend cosmetic recoloring as a fix for copied identity, copy, media, or composition.

6. Report the result

Lead with one verdict:

  • Clear in checked scope
  • Clear with low-risk similarities
  • Changes recommended
  • Block release
  • Blocked by missing evidence

Then provide:

  1. checked source registry
  2. red-flag table ordered by severity
  3. category pass list
  4. history findings
  5. access gaps and unproven areas
  6. prioritized fix plan

Include a row even when a high-risk category could not be checked. Never turn missing evidence into a pass.

Completion checks

  • Every supplied reference form was inspected.
  • Rendered output and source were both checked.
  • Text, brands, numbers, images, assets, videos, structure/motion, and history were covered.
  • Every red flag cites two evidence locations.
  • Exact matches are distinguished from stylistic similarity.
  • Proposed fixes replace the copied element rather than disguising it.
  • The report states what remains unverified.

© nirholas, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in third_party/designcode-agent-skills/agent-skills/codex/audit-reference-originality of nirholas/three.ws.

  • SKILL.md
  • agents/openai.yaml
  • references/audit-rubric.md
  • scripts/build_evidence_inventory.py

Open the folder on GitHubat commit ddf6e49

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in nirholas/three.ws, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Audit Reference Originality next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Audit Reference Originality compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Audit Reference Originality this skillnirholas/three.ws2271 repos~1.8kAutomated safety check: PassApache-2.0
Digital Forensicssickn33/agentic-awesome-skills47k1 repos~495Automated safety check: PassMIT
Digital Forensicszhaoxuya520/reverse-skill40k2 repos~389Automated safety check: WarnMIT
Finding ExperimentsPostHog/posthog40k—~783Automated safety check: PassCustom licence
ExperimentsArize-ai/phoenix12k—~1.8kAutomated safety check: PassCustom licence
Scroll Experiencesickn33/agentic-awesome-skills47k2 repos~534Automated safety check: PassMIT

Similar skills

  • Digital Forensics

    sickn33/agentic-awesome-skills

    Authorized digital forensics: memory dumps, disk timelines, PCAP investigation, artifact triage, and incident-response evidence preservation.

    47k GitHub starsUsed in 1 repo~495 tokens
    SecurityAuto-check passed
  • Digital Forensics

    zhaoxuya520/reverse-skill

    A skill your agent uses for authorized digital forensics including memory dumps, disk timelines, PCAP investigation, artifact triage, and IR evidence preservation.

    40k GitHub starsUsed in 2 repos~389 tokens
    SecurityAuto-check: warnings
  • Finding Experiments

    PostHog/posthog

    Official

    Resolves a PostHog experiment reference from natural language to a concrete experiment ID by browsing experiment-list (not feature-flag tools), with disambiguation when multiple experiments match.

    40k GitHub stars~783 tokensUpdated today
    Frontend & DesignAuto-check passed
  • Experiments

    Arize-ai/phoenix

    Run, read, and compare dataset-backed experiments to find evidence that a prompt or pipeline is improving.

    12k GitHub stars~1.8k tokensUpdated today
    AI & LLM EngineeringAuto-check passed
  • Scroll Experience

    sickn33/agentic-awesome-skills

    Expert in building immersive scroll-driven experiences - parallax storytelling, scroll animations, interactive narratives, and cinematic web experiences.

    47k GitHub starsUsed in 2 repos~534 tokens
    Writing & ContentAuto-check passed
  • Sbom Supply Chain

    sickn33/agentic-awesome-skills

    Generate, sign, and verify SBOMs and provenance attestations to secure the software supply chain.

    47k GitHub starsUsed in 2 repos~3.4k tokens
    SecurityAuto-check passed

More from nirholas/three.ws

All 92 skills in this repo
  • Add Shader Cursor Trail

    nirholas/three.ws

    Add the Shaders WebGPU mouse effect used for the Tidal Commons hero: a white twinkling halftone cursor trail driven by ChromaFlow, masked through a DotGrid, finished with chromatic ripples and film…

    227 GitHub starsUsed in 1 repo~760 tokens
    Auto-check passed
  • Publish Project To GitHub

    nirholas/three.ws

    Package a finished local project into an intentional GitHub repository, create a strong README and visual preview, push it safely, configure a public GitHub Pages URL when the project is compatible…

    227 GitHub starsUsed in 1 repo~2.2k tokens
    Auto-check: notes
  • Turn a completed daily UI inspiration capture into exactly five original landing-page builds, one per separate Codex task, using Sites.

    227 GitHub starsUsed in 1 repo~1.9k tokens
    Auto-check passed
  • Write Like Meng On X

    nirholas/three.ws

    Write, rewrite, review, or continuously refine X/Twitter posts in Meng To's current voice using his deduplicated authored-post corpus, personal and product context, shared resources, and Content…

    227 GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Browser Video Recording

    nirholas/three.ws

    Create polished 60 fps 4:3 4K browser screen-recording style videos from Codex in-app browser captures, with browser-only crop, natural macOS cursor styling, deliberate click choreography…

    227 GitHub starsUsed in 1 repo~1.5k tokens
    Auto-check passed
  • Metamask Agent Wallet

    nirholas/three.ws

    A skill your agent uses when the user asks anything about blockchain wallets, transactions, signing, token transfers, supported chains, wallet balances, perpetual futures trading, prediction…

    227 GitHub stars~4.5k tokensUpdated today
    Auto-check passed

Questions about Audit Reference Originality

What does Audit Reference Originality do?

Audit a website or digital experience against its supplied source references for originality and plagiarism risk. ws. Audit a website or digital experience against its supplied source references for originality and plagiarism risk.

When should I use Audit Reference Originality?

Audit Reference Originality fits situations like: Codex must compare current; historical site output with reference pages; raise evidence-backed red flags; distinguish common visual grammar from distinctive copying.

How do I install Audit Reference Originality in Claude Code?

Run `npx skills add nirholas/three.ws --skill audit-reference-originality -a claude-code`. Or copy the skill folder (third_party/designcode-agent-skills/agent-skills/codex/audit-reference-originality in nirholas/three.ws) into .claude/skills/audit-reference-originality in your project. Claude Code loads it when a task matches its description.

How do I install Audit Reference Originality in Codex?

Run `npx skills add nirholas/three.ws --skill audit-reference-originality -a codex`. Or copy the skill folder (third_party/designcode-agent-skills/agent-skills/codex/audit-reference-originality in nirholas/three.ws) into .agents/skills/audit-reference-originality in your project. Codex loads it when a task matches its description.

Can I use Audit Reference Originality in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add nirholas/three.ws --skill audit-reference-originality -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-reference-originality, .gemini/skills/audit-reference-originality, .github/skills/audit-reference-originality and .opencode/skills/audit-reference-originality in your project.

What does Audit Reference Originality need to run?

Going by SKILL.md and its folder, Audit Reference Originality needs Python for the scripts in its folder and the command-line tools its instructions call (git and python). Our summary lists: Python 3.

Does Audit Reference Originality access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Audit Reference Originality safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Audit Reference Originality use?

Audit Reference Originality is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Audit Reference Originality use?

About 1.8k tokens (SKILL.md is roughly 7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.4k tokens, read only when the agent opens those files.

What are the alternatives to Audit Reference Originality?

Skills that share tags, products or a category with Audit Reference Originality: Digital Forensics (sickn33/agentic-awesome-skills, 47k stars), Digital Forensics (zhaoxuya520/reverse-skill, 40k stars), Finding Experiments (PostHog/posthog, 40k stars) and Experiments (Arize-ai/phoenix, 12k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Audit Reference Originality?

nirholas (a GitHub user) maintains it in nirholas/three.ws, which has 227 GitHub stars. The repository holds 92 skills in this directory. The repository was last updated on October 8, 2026.

Source: nirholas/three.ws on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.