Official agent skill

Code Change Verification

by openai in openai/openai-guardrails-js

Select and run Guardrails verification for code, dependency, test, tooling, documentation, or repository-workflow changes.

OfficialMITAuto-check passedAI & LLM Engineering

Install Code Change Verification

skills CLI
$ npx skills add openai/openai-guardrails-js --skill code-change-verification -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install openai/openai-guardrails-js code-change-verification --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/openai/openai-guardrails-js.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/code-change-verification .claude/skills/code-change-verification && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-change-verification
GitHub stars
104
Token cost
~619 tokens
SKILL.md length
293 words
Files
2
Skills in repo
5
Repo updated
First seen
Licence
MIT

At a glance

Select and run Guardrails verification for code, dependency, test, tooling, documentation, or repository-workflow changes.

  • Tasks that involve LLM guardrails
  • SKILL.md covers Select the evidence and Full sequence
  • Calls npm and git

What it does

Code Change Verification is an agent skill from openai/openai-guardrails-js, published by the product's own GitHub organization. Select and run Guardrails verification for code, dependency, test, tooling, documentation, or repository-workflow changes.

Its SKILL.md is about 620 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in AI & LLM Engineering, covering LLM guardrails. It works with npm. The repository describes itself as: OpenAI Guardrails - TypeScript / JavaScript. The licence is MIT.

When your agent uses it

  • Tasks that involve LLM guardrails

Example prompts

  • “/code-change-verification”

What it can do on your machine

Read from SKILL.md and the folder at commit 8e88be0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Change Verification loads about 619 tokens when it runs. Until then it costs about 37 tokens; SKILL.md has 293 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~37
When it runs · the whole SKILL.md, loaded when a task matches
~619

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from openai/openai-guardrails-js at commit 8e88be0, republished under its MIT licence (© openai). 293 words, ~619 tokens.

Download SKILL.mdSave it as .claude/skills/code-change-verification/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
code-change-verification
description
Select and run Guardrails verification for code, dependency, test, tooling, documentation, or repository-workflow changes.

Code Change Verification

Follow repository verification and inspect the current package.json scripts before selecting checks. Run from the selected linked worktree's root; preserve its branch and user-owned changes.

Select the evidence

Changed areaVerification
Runtime, public types, dependencies, build/test configuration, packagingFull sequence below; focused tests during implementation
SDK integration or dependency compatibilityBuild first, then the relevant src/__tests__/integration/sdk-*.test.ts tests; full sequence before handoff
Site content, links, navigation, or VitePress toolingnpm ci, then npm run docs:check
Contributor instructions or skill metadata onlyValidate commands, relative links, frontmatter/UI metadata, and git diff --check

When areas overlap, combine their required checks. A test described as "integration" is not necessarily live: inspect its fixtures and calls before running it. The normal suite uses local fixtures and mocks; do not turn ordinary verification into a credentialed eval or an external API experiment.

Full sequence

Run each command separately and inspect its exit status before proceeding:

sh
npm ci
npm run build
npm run test:run
npm run lint
npm run docs:check

The build emits CommonJS and declarations consumed by compatibility tests. test:run avoids watch mode. Biome lint includes formatting and import checks; VitePress and the Node documentation tests run through docs:check. Invoke npm directly in the host shell, including PowerShell; no platform-specific wrapper or additional formatter is needed.

Keep verification within the available sandbox. Diagnose failures and fix only in-scope defects; report unrelated failures and missing coverage. Retry a transient failure when evidence supports that diagnosis. After a fix, repeat checks whose evidence it invalidated. Never report a skipped or failed gate as passing, and do not infer Windows coverage from Linux or macOS results.

Report the command, result, tested Node version, and any coverage limits. For remote checks, associate the result with the current PR head. The review gate in AGENTS.md also applies before pushing; passing tests do not replace it.

© openai, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .agents/skills/code-change-verification of openai/openai-guardrails-js.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit 8e88be0

Compare with similar skills

Code Change Verification next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Change Verification compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Change Verification this skillopenai/openai-guardrails-js104—~619Automated safety check: PassMIT
Reduce Bundle Sizekcsujeet/ilamy-calendar351—~2.9kAutomated safety check: PassMIT
ObliteratusRedWoodOG/Hermes-Desktop1776 repos~3.8kAutomated safety check: PassMIT
Aisafetyhotwuyoscar/AISafetyHot-Hub175—~1.2kAutomated safety check: PassCustom licence
Lemonade Router Builderamd/skills395—~4kAutomated safety check: PassMIT
Persona Designkangarooking/system-prompt-skills2051 repos~956Automated safety check: PassMIT

Similar skills

  • Reduce Bundle Size

    kcsujeet/ilamy-calendar

    Systematically reduce the shipped bundle size of a JS/TS library without sacrificing code readability or breaking consumer APIs.

    351 GitHub stars~2.9k tokensUpdated 3 days ago
    Frontend & DesignAuto-check passed
  • Obliteratus

    RedWoodOG/Hermes-Desktop

    Remove refusal behaviors from open-weight LLMs using OBLITERATUS — mechanistic interpretability techniques (diff-in-means, SVD, whitened SVD, LEACE, SAE decomposition, etc.) to excise guardrails…

    177 GitHub starsUsed in 6 repos~3.8k tokens
    AI & LLM EngineeringAuto-check passed
  • Aisafetyhot

    wuyoscar/AISafetyHot-Hub

    Read AI Safety HOT daily digests, search recent AI safety research and incidents, and follow current hot topics.

    175 GitHub stars~1.2k tokensUpdated today
    AI & LLM EngineeringAuto-check passed
  • Turns a natural-language description of routing intent into a valid Lemonade collection.router policy JSON.

    395 GitHub stars~4k tokensUpdated today
    AI & LLM EngineeringAuto-check passed
  • Persona Design

    kangarooking/system-prompt-skills

    当需要为 AI 产品定义核心身份、角色声明和能力边界时调用此 skill。典型场景包括:设计新 AI 产品的 system prompt 首段、为不同场景创建差异化角色(如教学助手 vs 编程代理)、重新定义 AI 与用户的关系框架。

    205 GitHub starsUsed in 1 repo~956 tokens
    AI & LLM EngineeringAuto-check passed
  • Execution Guardrails

    mrtooher/fable-mode

    Always-on operational guardrails, model-independent. An agent skill from mrtooher/fable-mode.

    870 GitHub stars~1k tokensUpdated 1 mo ago
    AI & LLM EngineeringAuto-check passed

More from openai/openai-guardrails-js

  • Implementation Final Review

    openai/openai-guardrails-js

    Official

    Prepare independent review of a complete Guardrails change before pushing or updating a PR, using the repository adversarial-review procedure.

    104 GitHub stars~825 tokensUpdated 9 days ago
    Auto-check passed
  • Implementation Kickoff

    openai/openai-guardrails-js

    Official

    Start or resume a requested Guardrails implementation or PR takeover in the selected linked worktree with bounded scope and verification.

    104 GitHub stars~1k tokensUpdated 9 days ago
    Auto-check passed
  • Implementation Strategy

    openai/openai-guardrails-js

    Official

    Choose bounded implementation scope and existing owning modules before Guardrails runtime, configuration, client, resource, streaming, Agents, or SDK compatibility changes and feedback fixes.

    104 GitHub stars~951 tokensUpdated 9 days ago
    Auto-check passed
  • PR Draft Summary

    openai/openai-guardrails-js

    Official

    Draft a Guardrails PR from its complete final diff and carry out authorized CI and review follow-up, including stacked PRs and takeovers.

    104 GitHub stars~1k tokensUpdated 9 days ago
    Auto-check passed

Works with

Questions about Code Change Verification

What does Code Change Verification do?

Select and run Guardrails verification for code, dependency, test, tooling, documentation, or repository-workflow changes. Code Change Verification is an agent skill from openai/openai-guardrails-js, published by the product's own GitHub organization. Select and run Guardrails verification for code, dependency, test, tooling, documentation, or repository-workflow changes.

When should I use Code Change Verification?

Code Change Verification fits situations like: tasks that involve LLM guardrails.

How do I install Code Change Verification in Claude Code?

Run `npx skills add openai/openai-guardrails-js --skill code-change-verification -a claude-code`. Or copy the skill folder (.agents/skills/code-change-verification in openai/openai-guardrails-js) into .claude/skills/code-change-verification in your project. Claude Code loads it when a task matches its description.

How do I install Code Change Verification in Codex?

Run `npx skills add openai/openai-guardrails-js --skill code-change-verification -a codex`. Or copy the skill folder (.agents/skills/code-change-verification in openai/openai-guardrails-js) into .agents/skills/code-change-verification in your project. Codex loads it when a task matches its description.

Can I use Code Change Verification in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add openai/openai-guardrails-js --skill code-change-verification -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-change-verification, .gemini/skills/code-change-verification, .github/skills/code-change-verification and .opencode/skills/code-change-verification in your project.

What does Code Change Verification need to run?

Going by SKILL.md and its folder, Code Change Verification needs the command-line tools its instructions call (npm and git).

Does Code Change Verification access the network?

SKILL.md contains no URLs. Its commands use npm and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Code Change Verification safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Code Change Verification use?

Code Change Verification is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Change Verification use?

About 619 tokens (SKILL.md is roughly 2.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Code Change Verification?

Skills that share tags, products or a category with Code Change Verification: Reduce Bundle Size (kcsujeet/ilamy-calendar, 351 stars), Obliteratus (RedWoodOG/Hermes-Desktop, 177 stars), Aisafetyhot (wuyoscar/AISafetyHot-Hub, 175 stars) and Lemonade Router Builder (amd/skills, 395 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Change Verification?

openai (a GitHub organization, an official publisher) maintains it in openai/openai-guardrails-js, which has 104 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on September 28, 2026.

Source: openai/openai-guardrails-js on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.