Update Qm
yc-software/qm
Update a QM source fork by merging upstream, or upgrade a package deployment dependency, and open a PR.
Verifies a POST-EXECUTION mainnet (or other network) smart-contract deployment PR for this repo: confirms every deployed contract is listed in the PR description, that the on-chain verified source…
$ npx skills add OriginProtocol/origin-dollar --skill verify-deployment-pr -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install OriginProtocol/origin-dollar verify-deployment-pr --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/OriginProtocol/origin-dollar.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/verify-deployment-pr .claude/skills/verify-deployment-pr && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "verify-deployment-pr" agent skill from https://github.com/OriginProtocol/origin-dollar/tree/master/.claude/skills/verify-deployment-pr into .claude/skills/verify-deployment-pr/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "verify-deployment-pr", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/OriginProtocol/origin-dollar/tree/master/.claude/skills/verify-deployment-prType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add OriginProtocol/origin-dollar --skill verify-deployment-pr -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install OriginProtocol/origin-dollar verify-deployment-pr --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/OriginProtocol/origin-dollar.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/verify-deployment-pr .agents/skills/verify-deployment-pr && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "verify-deployment-pr" agent skill from https://github.com/OriginProtocol/origin-dollar/tree/master/.claude/skills/verify-deployment-pr into .agents/skills/verify-deployment-pr/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "verify-deployment-pr", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add OriginProtocol/origin-dollar --skill verify-deployment-pr -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install OriginProtocol/origin-dollar verify-deployment-pr --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/OriginProtocol/origin-dollar.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/verify-deployment-pr .cursor/skills/verify-deployment-pr && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "verify-deployment-pr" agent skill from https://github.com/OriginProtocol/origin-dollar/tree/master/.claude/skills/verify-deployment-pr into .cursor/skills/verify-deployment-pr/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "verify-deployment-pr", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/OriginProtocol/origin-dollar.git --path .claude/skills/verify-deployment-pr--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add OriginProtocol/origin-dollar --skill verify-deployment-pr -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install OriginProtocol/origin-dollar verify-deployment-pr --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/OriginProtocol/origin-dollar.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/verify-deployment-pr .gemini/skills/verify-deployment-pr && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "verify-deployment-pr" agent skill from https://github.com/OriginProtocol/origin-dollar/tree/master/.claude/skills/verify-deployment-pr into .gemini/skills/verify-deployment-pr/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "verify-deployment-pr", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install OriginProtocol/origin-dollar verify-deployment-prInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add OriginProtocol/origin-dollar --skill verify-deployment-pr -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/OriginProtocol/origin-dollar.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/verify-deployment-pr .github/skills/verify-deployment-pr && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "verify-deployment-pr" agent skill from https://github.com/OriginProtocol/origin-dollar/tree/master/.claude/skills/verify-deployment-pr into .github/skills/verify-deployment-pr/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "verify-deployment-pr", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add OriginProtocol/origin-dollar --skill verify-deployment-pr -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install OriginProtocol/origin-dollar verify-deployment-pr --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/OriginProtocol/origin-dollar.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/verify-deployment-pr .opencode/skills/verify-deployment-pr && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "verify-deployment-pr" agent skill from https://github.com/OriginProtocol/origin-dollar/tree/master/.claude/skills/verify-deployment-pr into .opencode/skills/verify-deployment-pr/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "verify-deployment-pr", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
verify-deployment-prVerifies a POST-EXECUTION mainnet (or other network) smart-contract deployment PR for this repo: confirms every deployed contract is listed in the PR description, that the on-chain verified source…
Verify Deployment PR is an agent skill from OriginProtocol/origin-dollar. Verifies a POST-EXECUTION mainnet (or other network) smart-contract deployment PR for this repo: confirms every deployed contract is listed in the PR description, that the on-chain verified source (and its dependencies) matches the codebase via sol2uml diff, that constructor args and the initialize tx match the Foundry script, and that the on-chain governance proposal matches the script's actions. Use when asked to review, verify, audit, or sign off on an executed deployment PR. Invoke explicitly with…
Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Backend & APIs, covering Smart contracts, Deployment and Pull requests. It works with Git. The repository describes itself as: OUSD and OETH are stablecoins that passively accrue yield while you are holding it. The licence is MIT.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 1be34f7. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
BashReadGrepGlobTaskFrom allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitghnpmpnpmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, gh, npm and pnpm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
ETHERSCAN_API_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Verify Deployment PR loads about 2.6k tokens when it runs. Until then it costs about 140 tokens; SKILL.md has 1,100 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
2. Require `contracts/.env` with `PROVIDER_URL` and `ETHERSCAN_API_KEY`:-oE '^(PROVIDER_URL|ETHERSCAN_API_KEY)=' .env`. Source it for shell use:`set -a; . ./.env; set +a` (so `$ETHERSCAN_API_KEY` is available to `sol2uml`).diff`, run from `contracts/` and source `.env` first so `$ETHERSCAN_API_KEY`allowed-tools: Bash, Read, Grep, Glob, TaskAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from OriginProtocol/origin-dollar at commit 1be34f7, republished under its MIT licence (© OriginProtocol). 1,100 words, ~2,573 tokens.
.claude/skills/verify-deployment-pr/SKILL.md (or your agent's skills folder).READ-ONLY audit of an already-executed deployment PR. Never broadcast a transaction,
never edit files, never re-run the live deployment. All on-chain data comes from the
block explorer (via sol2uml/Etherscan) or a read-only RPC.
contracts/: cd contracts.contracts/.env with PROVIDER_URL and ETHERSCAN_API_KEY:
grep -oE '^(PROVIDER_URL|ETHERSCAN_API_KEY)=' .env. Source it for shell use:
set -a; . ./.env; set +a (so $ETHERSCAN_API_KEY is available to sol2uml).ETHERSCAN_API_KEY → checks 2/3/4 can't run → STOP and report the blocker.gh authenticated (gh auth status). If absent, ask the user to paste the
PR body + deployed-address list rather than failing.sol2uml on PATH (command -v sol2uml). If absent: npm i -g sol2uml.gh pr view "$PR" --json headRefName,state,mergeCommitgit rev-parse --abbrev-ref HEAD and git status --porcelainheadRefName, OR — if the PR is already
merged — that the checkout contains its merge commit
(git merge-base --is-ancestor <mergeCommit> HEAD).gh pr checkout <PR>
(or git checkout <headRefName> / git stash) and re-run. Do not verify against the
wrong code.PR=$1. gh pr view "$PR" --json title,body,files,baseRefName,headRefName,state,url.git diff --name-only origin/master...HEAD -- 'contracts/scripts/deploy/**/*.s.sol'
(or read the PR files). Ignore 000_Example.s.sol. The folder under
scripts/deploy/<network>/ gives the network (mainnet, base, sonic, hyperevm,
…) — use it for sol2uml --network <net> and map it to the chain deployment file
(build/deployments-1.json, -8453.json, -146.json, -999.json, etc.)._execute(), enumerate every contract creation (new <Contract>(args))
and every _recordDeployment("<KEY>", address(...), type(<Contract>).name) call.
Resolve <KEY> → address from the matching entry in the chain deployment JSON's
contracts array (.name, .implementation). The JSON field is named
implementation even for proxies and non-implementation contracts. If a newly
recorded key is absent from the committed JSON, mark checks 1/3/4 ❌.AbstractDeployScript("<ID>").
Resolve its proposalId, tsDeployment, and tsGovernance from the matching entry
in the chain deployment JSON's executions array. Build expected governance actions
from _buildGovernanceProposal() calls to
govProposal.action(target, "signature(types)", abi.encode(args)).
If proposalId is 0/absent while governance is expected, mark check 5 ⚠️
("no proposalId recorded — resolve from on-chain Governor events or ask the deployer").[{key, contractType, address, constructorArgs, proposalId, network, deployScript}].Checks 2/3/4 are per-address and independent — fan them out with parallel Task
sub-agents (one per deployed contract) when there are several; otherwise run inline.
Each check yields: status (✅ pass / ⚠️ needs-human / ❌ fail), one-line evidence, a
details block, and a confidence (High/Med/Low). Absence of evidence is ⚠️/❌, never ✅.
1 — All deployed contracts listed in the PR description
2 — Verified on-chain code (and dependencies) matches the codebase
contracts/:
sol2uml diff <address> .,node_modules --network <net> --apiKey "$ETHERSCAN_API_KEY"
This downloads the explorer-verified source for the address and diffs it (and its
dependencies) against the local checkout.*Proxy addresses run the same diff against the proxy
source; expect the standard proxy to match.3 — Constructor arguments are correct
new <Contract>(args)) corresponding to each
_recordDeployment in _execute() and resolve constants/addresses used by it.[].4 — The initialize / interaction tx matches the deploy script
_execute() performs a post-deploy call — typically a proxy
initialize(...)/_initialize(...) — locate the corresponding on-chain
tx (explorer tx list for the proxy address, or the proxy's deployment receipt) and
confirm the arguments match the Foundry script.5 — Governance proposal matches the deploy script
pnpm ops proposal --id,
it parses the id as a float and overflows on real (77-digit) proposalIds. Use the
GovernorSix (addresses.mainnet.GovernorSix) ABI with the id as a BigNumber:
g.state(id) and g.getActions(id) -> (targets, values, signatures, calldatas)
(calldatas are selector-stripped — the signature is a separate string)._buildGovernanceProposal(): resolve every target through
constants or resolver.resolve("<KEY>") and the chain deployment JSON, keep the
signature passed to govProposal.action, and evaluate the corresponding abi.encode
arguments to compare against each on-chain calldata.state: Executed for a fully-executed deploy; Pending/Active/
Queued is normal when reviewing before execution — flag it but it is not a failure.6 — Smoke tests after fork execution — SKIPPED (per project decision). Mark N/A.
Verdict = VERIFIED only if checks 2,3,4,5 are ✅ (check 1 may be ⚠️ if the sole gap is documentation; check 4 may be ⚠️ if there is genuinely no init/interaction call). Any ❌ in 2–5, or an unresolved ⚠️, → BLOCKERS FOUND. Emit the report:
# Deployment PR Verification — #<PR> (<title>)
Verified against: <branch>@<short-sha>
Foundry script(s): <list> | Network: <net> | Proposal: <proposalId>
Verdict: <VERIFIED | BLOCKERS FOUND>
- [<✅|⚠️|❌>] 1. All deployed contracts listed in PR description — <evidence> (conf)
- [<✅|⚠️|❌>] 2. Verified code (+deps) matches codebase (sol2uml diff) — <evidence> (conf)
- [<✅|⚠️|❌>] 3. Constructor args correct — <evidence> (conf)
- [<✅|⚠️|❌>] 4. Initialize/interaction tx matches deploy script — <evidence> (conf)
- [<✅|⚠️|❌>] 5. Governance proposal matches deploy script — <evidence> (conf)
- [⏭️] 6. Smoke tests — skipped (N/A)
## Details
### 2. sol2uml diff <per-address: address, clean/diff, differing files>
### 3. Constructor args <per-address: Foundry-script args vs on-chain args>
### 4. Initialize tx <tx hash, decoded args vs Foundry-script args>
### 5. Proposal diff <on-chain getActions vs script actions, or "identical">
## Human still owes (manual)
- Off-chain Safe/multisig follow-ups noted in the Foundry script.
- That the PR's stated intent matches the on-chain effect (judgment).
- Anything marked ⚠️ above.sol2uml diff, run from contracts/ and source .env first so $ETHERSCAN_API_KEY
is set; use --network matching the deploy folder (base→base, sonic→sonic, etc.).*Proxy against
the proxy contract, not the impl.sol2uml diff (no file differences) is the pass signal for check 2; treat any
reported file difference as ❌ pending human review, not a warning.proposalId is 0/absent, do not fabricate one — mark check 5 ⚠️ and ask the deployer.deployments/<network>/*.json remains a Talos compatibility registry, not the source
of truth for Foundry deployment execution. Use build/deployments-<chainId>.json for
Foundry-recorded names, addresses, and execution metadata.© OriginProtocol, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/verify-deployment-pr of OriginProtocol/origin-dollar.
Open the folder on GitHubat commit 1be34f7
Verify Deployment PR next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Verify Deployment PR this skillOriginProtocol/origin-dollar | 153 | — | ~2.6k | Automated safety check: Notes | MIT | |
| Update Qmyc-software/qm | 15k | — | ~1.8k | Automated safety check: Pass | MIT | |
| Vercel Deploy Previewjeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~1.6k | Automated safety check: Pass | MIT | |
| Nestjs Git Commit PR Messageaiskillstore/marketplace | 430 | — | ~2.4k | Automated safety check: Pass | MIT | |
| Foundry Deploy Fixturesaviggiano/security | 144 | — | ~634 | Automated safety check: Pass | MIT | |
| Finding TriageHacktronAI/skills | 115 | — | ~2.9k | Automated safety check: Notes | MIT |
yc-software/qm
Update a QM source fork by merging upstream, or upgrade a package deployment dependency, and open a PR.
jeremylongshore/tons-of-skills-marketplace
Create and manage Vercel preview deployments for branches and pull requests.
aiskillstore/marketplace
Prepares and publishes intentional Git changes for NestJS projects.
aviggiano/security
Create or refactor Foundry deployment fixtures for Solidity tests.
HacktronAI/skills
Interactively validate and triage Hacktron findings against the actual source code and (optionally) a live deployment, separate true positives from false positives, adjust severity, then either…
lidofinance/diffyscan
Creates or extends a Diffyscan verification config for a deployed contract or deployment.
OriginProtocol/origin-dollar
Generate Foundry fork tests for contracts that need real on-chain integration coverage.
OriginProtocol/origin-dollar
Reorganize Foundry test files (.t.sol) for readability and consistency without changing semantics.
OriginProtocol/origin-dollar
Generate Foundry smoke tests that validate deployment health using DeployManager/Resolver against real on-chain state with pending governance applied.
OriginProtocol/origin-dollar
Handle git commits with auto-staging, targeted pre-commit formatting, and Conventional Commit messages.
OriginProtocol/origin-dollar
Develop, modify, review, and maintain standalone Talos actions in contracts/tasks/actions, including chain guardrails, contract bindings, transaction safety, schedules, action catalogues, and Talos…
OriginProtocol/origin-dollar
Generate Foundry unit tests for a contract using this repository's conventions, structure, and naming.
Works with
Categories
Verifies a POST-EXECUTION mainnet (or other network) smart-contract deployment PR for this repo: confirms every deployed contract is listed in the PR description, that the on-chain verified source…. Verify Deployment PR is an agent skill from OriginProtocol/origin-dollar. Verifies a POST-EXECUTION mainnet (or other network) smart-contract deployment PR for this repo: confirms every deployed contract is listed in the PR description, that the on-chain verified source (and its dependencies) matches the codebase via sol2uml diff, that constructor args and the initialize tx match the Foundry script, and that the on-chain governance proposal matches the script's actions.
Verify Deployment PR fits situations like: asked to review; sign off on an executed deployment PR.
Run `npx skills add OriginProtocol/origin-dollar --skill verify-deployment-pr -a claude-code`. Or copy the skill folder (.claude/skills/verify-deployment-pr in OriginProtocol/origin-dollar) into .claude/skills/verify-deployment-pr in your project. Claude Code loads it when a task matches its description.
Run `npx skills add OriginProtocol/origin-dollar --skill verify-deployment-pr -a codex`. Or copy the skill folder (.claude/skills/verify-deployment-pr in OriginProtocol/origin-dollar) into .agents/skills/verify-deployment-pr in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add OriginProtocol/origin-dollar --skill verify-deployment-pr -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/verify-deployment-pr, .gemini/skills/verify-deployment-pr, .github/skills/verify-deployment-pr and .opencode/skills/verify-deployment-pr in your project.
Going by SKILL.md and its folder, Verify Deployment PR needs the command-line tools its instructions call (git, gh, npm and pnpm) and credentials named ETHERSCAN_API_KEY. Our summary lists: Node.js; A credential in ETHERSCAN_API_KEY. Its frontmatter pre-approves these tools: Bash, Read, Grep, Glob, Task.
SKILL.md contains no URLs. Its commands use git, gh and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file; pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Verify Deployment PR is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Verify Deployment PR: Update Qm (yc-software/qm, 15k stars), Vercel Deploy Preview (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Nestjs Git Commit PR Message (aiskillstore/marketplace, 430 stars) and Foundry Deploy Fixtures (aviggiano/security, 144 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
OriginProtocol (a GitHub organization) maintains it in OriginProtocol/origin-dollar, which has 153 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on October 7, 2026.
Source: OriginProtocol/origin-dollar on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.