Qualify a check before it is allowed to clear anything — prove it can detect the failure it is meant to catch.

MITAuto-check: notesResearch & Science

Install Vaccinate

skills CLI
$ npx skills add pedrohcgs/claude-code-my-workflow --skill vaccinate -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install pedrohcgs/claude-code-my-workflow vaccinate --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/pedrohcgs/claude-code-my-workflow.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/vaccinate .claude/skills/vaccinate && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
vaccinate
GitHub stars
1.7k
Token cost
~2.1k tokens
SKILL.md length
1,100 words
Files
7 (incl. references)
Skills in repo
59
Repo updated
First seen
Licence
MIT

At a glance

Qualify a check before it is allowed to clear anything — prove it can detect the failure it is meant to catch.

  • Works in 6 steps: Name the failure → Build the seeded set + a clean control → Run the checker blind → …
  • The user says does this check work
  • SKILL.md covers When to run it, Protocol, Worked example and Anti-patterns, plus 7 more sections
  • Calls bash

What it does

Vaccinate is an agent skill from pedrohcgs/claude-code-my-workflow. Qualify a check before it is allowed to clear anything — prove it can detect the failure it is meant to catch. Seeds known defects into a copy of a real artifact plus a clean control, runs the checker, and reports recall and false-positive rate into a qualification ledger. Use when the user says "does this check work", "qualify the gate", "test my reviewer", "seed defects", "vaccinate", "qualify the checks", "can I trust this review", "does it pass for the right reason", or before relying on any automated check…

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including reference files (for example `evals/README.md`, `evals/cases/README.md` and `evals/cases/detects-stale-gate.md`).

It sits in Research & Science. The repository describes itself as: A ready-to-fork Claude Code template for academics using LaTeX/Beamer + R. Multi-agent review, quality gates, adversarial QA, and replication protocols. The licence is MIT.

When your agent uses it

  • The user says does this check work
  • Qualify the gate
  • Test my reviewer
  • Qualify the checks

Example prompts

  • “does this check work”
  • “qualify the gate”
  • “test my reviewer”
  • “/vaccinate”

Requirements

  • Pre-approved tools (allowed-tools): Read, Write, Bash, Glob, Grep, Agent

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Name the failure
  2. Build the seeded set + a clean control
  3. Run the checker blind
  4. Score
  5. Write the ledger row
  6. Act on the result

What it can do on your machine

Read from SKILL.md and the folder at commit ae72617. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Bash
    • Glob
    • Grep
    • Agent

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Vaccinate loads about 2.1k tokens when it runs, and up to ~3.2k if it reads all its reference files. Until then it costs about 161 tokens; SKILL.md has 1,100 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~161
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Write, Bash, Glob, Grep, Agent

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from pedrohcgs/claude-code-my-workflow at commit ae72617, republished under its MIT licence (© pedrohcgs). 1,100 words, ~2,123 tokens.

Download SKILL.mdSave it as .claude/skills/vaccinate/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
vaccinate
description
Qualify a check before it is allowed to clear anything — prove it can detect the failure it is meant to catch. Seeds known defects into a copy of a real artifact plus a clean control, runs the checker, and reports recall and false-positive rate into a qualification ledger. Use when the user says "does this check work", "qualify the gate", "test my reviewer", "seed defects", "vaccinate", "qualify the checks", "can I trust this review", "does it pass for the right reason", or before relying on any automated check or referee simulation for a decision that matters. NOT a code fixer and NOT a reviewer itself — it grades the grader.
allowed-tools
Read, Write, Bash, Glob, Grep, Agent
argument-hint
[checker or skill to qualify] [artifact to seed]
disable-model-invocation
true
metadata.protocol
check-qualification

Vaccinate — grade the grader

Twenty bugs were once planted in a working codebase and the review agents were asked to check it again. They reported everything was fine. Recall: 0/20.

A vaccine is a small, controlled dose of error that strengthens the whole system. This skill administers one.

The rule it enforces: an unqualified check is not weak evidence — it is none.

When to run it

  • Before a referee simulation, reproducibility gate, or review agent is used to make a decision that matters (a submission, a release, a deposit).
  • After changing a checker — a modified gate is unqualified until re-measured.
  • On a schedule for gates that guard load-bearing claims. Detection decays as artifacts drift.

Protocol

1. Name the failure

State the defect class the check is supposed to catch. "Catches problems" is not a class. "Detects a coefficient in the text that no longer matches its table" is.

2. Build the seeded set + a clean control

Work on a copy, never the live artifact. Produce:

  • N seeded variants, one defect each, drawn from references/defect-library.md.
  • At least one clean control — an unmodified copy.

The control is not optional. Without it you measure recall and call it accuracy.

Verify each seed actually violates something. A seed that the artifact already permits creates no defect, and the checker correctly reporting "pass" will look like a broken gate. This is the most common way a qualification run produces a false alarm about itself.

3. Run the checker blind

Run the check or agent against each variant in a fresh context, one variant per run. It must not know which variant it has, how many defects exist, or that a qualification is underway. For an AI reviewer, spawn a fresh-context Agent call (not a conversation fork, which would carry the seeded answer key).

4. Score
MetricDefinition
Recallseeded defects correctly identified / seeded defects planted
False-positive ratefindings on the clean control that are factually false / total findings on the control
Localizationdid it name the right location, or just report unease?
Baseline deltarecall of a simpler alternative (a grep, a diff, a one-line assertion)

A finding on the clean control counts as a false positive only when it is factually wrong — not merely unwelcome. A reviewer prompted to find gaps will report some in sound work; that is expected behaviour, not a failure.

The baseline is load-bearing. A five-agent panel that scores no better than grep -n has not earned its cost.

5. Write the ledger row

Append to quality_reports/qualification/LEDGER.md:

| date | target | artifact | defect classes | N | recall | FPR | baseline | verdict |

Verdicts: PASS (detects its named class at an agreed threshold) · FAIL (misses it) · BLOCKED (could not be run — say why; do not record as PASS).

6. Act on the result
  • FAIL → the check does not license its claim. Fix the check or stop citing it. Do not weaken the seed until it passes.
  • PASS → record the threshold. A PASS at one difficulty is not a PASS at another.
  • Either way, a checker with no ledger row is unqualified, and its green light means nothing.

Worked example

/vaccinate check-model-versions.sh
  1. Failure class: "a superseded model presented as current".
  2. Seed: append The newest model is Opus 4.8 and it is the default. to README.md. Control: unmodified README.md.
  3. Run: bash scripts/check-model-versions.sh; echo $?
  4. Score: seeded → exit 1 (detected). Control → exit 0 (no false alarm). Recall 1/1, FPR 0/0. Baseline: grep -c "Opus 4.8" README.md also detects — so the gate's value is its allow-marker logic, not raw detection.
  5. Ledger: PASS.
  6. Restore the artifact and re-run to confirm you are back to green.

Anti-patterns

  • Seeding into an artifact that already permits the seed — measures nothing, looks like a broken gate.
  • Telling the reviewer it is a test — it will look harder than it does in production.
  • Counting any finding as a hit — a finding at the wrong location is not detection.
  • One seed, one run — a single trial does not distinguish detection from luck. Use ≥2 replicates per class where cost allows.
  • Weakening the seed until it passes — that is fitting the test to the checker.
  • Skipping the clean control — the most common omission, and it hides the cost.
Show full SKILL.md (417 more words)Show less

Reference files

FileRead when
references/defect-library.mdchoosing what to seed — defect classes by artifact type
evals/README.mdthe complementary question: does the skill produce better output than not having it?

Doctrine: what qualification means

Do not assume more machinery is better

A second model, more agents, or a longer debate is not presumed to verify better. Before an elaborate procedure earns extra weight, show it outperforms a simpler check on the same prespecified seeded failures and valid cases, reporting both detection and false alarms. Complexity that has not beaten a baseline is cost, not assurance.

Treat AI verdicts as predictions, not facts

When a model grades, triages, or reviews at scale:

  • keep a sampled set for qualified human review, and record how it was sampled (retain coverage of hard subgroups — do not sample only the easy middle);
  • keep fitting/prompt-tuning cases separate from evaluation cases;
  • report where AI and expert judgments diverge;
  • remember a well-calibrated average score certifies no individual verdict;
  • agreement between models is not independent evidence — they share failure modes and converge on the same wrong answer at a meaningful rate.

Any material change to the model, prompt, rubric, or target population requires fresh human labels and recalibration.

Requalify after material change

A check qualified against an old interface, schema, or scale may silently stop testing anything. Re-run the seeded-defect proof after material changes to the object under test or to the check itself.

Distinguish qualified checks from scientific judgments

  • Qualified checks have a defensible reference answer: unique keys, units convert, a table regenerates, an estimator recovers an analytic special case, a seeded fault triggers a failure. These can be automated and rerun forever.
  • Scientific judgments — whether a field measures the intended construct, whether an identifying assumption is plausible, whether a result deserves causal language — cannot be automated, and no volume of qualified checks substitutes for one.

Confirm the check actually ran

A missing, substituted, or degraded check is missing evidence, not a pass. Verify the run happened (log, exit status, artifact timestamp — not an assumption); that it ran on the current object, not a cached one; that nothing was skipped, filtered, or swallowed into a default; and that the tolerance was fixed before the comparison. A tolerance loosened after a failed comparison converts evidence into decoration. If it must be loosened, record it as an approved divergence with a reason.

Cross-references

© pedrohcgs, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (references) in .claude/skills/vaccinate of pedrohcgs/claude-code-my-workflow.

  • SKILL.md
  • evals/README.md
  • evals/cases/README.md
  • evals/cases/detects-stale-gate.md
  • evals/cases/nottrigger-simple-question.md
  • evals/cases/requires-clean-control.md
  • references/defect-library.md

Open the folder on GitHubat commit ae72617

Compare with similar skills

Vaccinate next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Vaccinate compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Vaccinate this skillpedrohcgs/claude-code-my-workflow1.7k—~2.1kAutomated safety check: NotesMIT
Hypothesis Generationspacering-net/codeg3.9k14 repos~3.6kAutomated safety check: NotesMIT
GitHub Deep Researchbytedance/deer-flow84k4 repos~1.3kAutomated safety check: PassMIT
Nature Paper CardYuan1z0825/nature-skills47k2 repos~2.1kAutomated safety check: PassApache-2.0
Content Research Writerweapp-tailwindcss/weapp-tailwindcss1.9k25 repos~3.5kAutomated safety check: PassMIT
Last30daysmvanhorn/last30days-skill64k—~7.9kAutomated safety check: NotesMIT

Similar skills

  • Hypothesis Generation

    spacering-net/codeg

    Structured hypothesis formulation from observations. An agent skill from spacering-net/codeg.

    3.9k GitHub starsUsed in 14 repos~3.6k tokens
    Research & ScienceAuto-check: notes
  • GitHub Deep Research

    bytedance/deer-flow

    Researches a GitHub repository over four rounds using the GitHub API and web search, then writes a structured markdown report with timeline, metrics and Mermaid diagrams.

    84k GitHub starsUsed in 4 repos~1.3k tokens
    Research & ScienceAuto-check passed
  • Nature Paper Card

    Yuan1z0825/nature-skills

    Builds a structured deep-reading card for one scientific paper, covering methods, how experiments support claims, limitations and research ideas, with a script to prepare the source.

    47k GitHub starsUsed in 2 repos~2.1k tokens
    Research & ScienceAuto-check passed
  • Content Research Writer

    weapp-tailwindcss/weapp-tailwindcss

    Assists in writing high-quality content by conducting research, adding citations, improving hooks, iterating on outlines, and providing real-time feedback on each section.

    1.9k GitHub starsUsed in 25 repos~3.5k tokens
    Research & ScienceAuto-check passed
  • Last30days

    mvanhorn/last30days-skill

    Research what people actually say about any topic in the last 30 days.

    64k GitHub stars~7.9k tokensUpdated yesterday
    Research & ScienceAuto-check: notes
  • Peer Review

    spacering-net/codeg

    Structured manuscript/grant review with checklist-based evaluation.

    3.9k GitHub starsUsed in 17 repos~5.9k tokens
    Research & ScienceAuto-check: notes

More from pedrohcgs/claude-code-my-workflow

All 59 skills in this repo
  • Devils Advocate

    pedrohcgs/claude-code-my-workflow

    Adversarial 5-7 question challenge to a deck's pedagogical choices — ordering, prerequisites, cognitive load, motivation.

    1.7k GitHub starsUsed in 2 repos~641 tokens
    Auto-check passed
  • Compile Latex

    pedrohcgs/claude-code-my-workflow

    Compile a Beamer LaTeX slide deck with XeLaTeX (3 passes + bibtex).

    1.7k GitHub starsUsed in 1 repo~492 tokens
    Auto-check: notes
  • Context Status

    pedrohcgs/claude-code-my-workflow

    Show current context status and session health. An agent skill from pedrohcgs/claude-code-my-workflow.

    1.7k GitHub starsUsed in 1 repo~613 tokens
    Auto-check: notes
  • Capture Environment

    pedrohcgs/claude-code-my-workflow

    Snapshot the computational environment for a replication package — detects the analysis stack (R / Stata / Python) and emits the right lockfiles (renv.lock + sessionInfo.txt, requirements.txt /…

    1.7k GitHub stars~2.8k tokensUpdated 13 days ago
    Auto-check: notes
  • Checkpoint

    pedrohcgs/claude-code-my-workflow

    Save a structured state snapshot before stopping or handing off.

    1.7k GitHub stars~2.8k tokensUpdated 13 days ago
    Auto-check: notes
  • Coauthor Brief

    pedrohcgs/claude-code-my-workflow

    Generate a co-author / collaborator handoff brief for a multi-author, multi-machine project — summarizing what changed since the last brief (git delta), the current state of each artifact…

    1.7k GitHub stars~2.9k tokensUpdated 13 days ago
    Auto-check: notes

Questions about Vaccinate

What does Vaccinate do?

Qualify a check before it is allowed to clear anything — prove it can detect the failure it is meant to catch. Vaccinate is an agent skill from pedrohcgs/claude-code-my-workflow. Qualify a check before it is allowed to clear anything — prove it can detect the failure it is meant to catch.

When should I use Vaccinate?

Vaccinate fits situations like: the user says does this check work; qualify the gate; test my reviewer; qualify the checks.

How do I install Vaccinate in Claude Code?

Run `npx skills add pedrohcgs/claude-code-my-workflow --skill vaccinate -a claude-code`. Or copy the skill folder (.claude/skills/vaccinate in pedrohcgs/claude-code-my-workflow) into .claude/skills/vaccinate in your project. Claude Code loads it when a task matches its description.

How do I install Vaccinate in Codex?

Run `npx skills add pedrohcgs/claude-code-my-workflow --skill vaccinate -a codex`. Or copy the skill folder (.claude/skills/vaccinate in pedrohcgs/claude-code-my-workflow) into .agents/skills/vaccinate in your project. Codex loads it when a task matches its description.

Can I use Vaccinate in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add pedrohcgs/claude-code-my-workflow --skill vaccinate -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vaccinate, .gemini/skills/vaccinate, .github/skills/vaccinate and .opencode/skills/vaccinate in your project.

What does Vaccinate need to run?

Going by SKILL.md and its folder, Vaccinate needs the command-line tools its instructions call (bash). Its frontmatter pre-approves these tools: Read, Write, Bash, Glob, Grep, Agent.

Does Vaccinate access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Vaccinate safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Vaccinate use?

Vaccinate is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Vaccinate use?

About 2.1k tokens (SKILL.md is roughly 8.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.1k tokens, read only when the agent opens those files.

What are the alternatives to Vaccinate?

Skills that share tags, products or a category with Vaccinate: Hypothesis Generation (spacering-net/codeg, 3.9k stars), GitHub Deep Research (bytedance/deer-flow, 84k stars), Nature Paper Card (Yuan1z0825/nature-skills, 47k stars) and Content Research Writer (weapp-tailwindcss/weapp-tailwindcss, 1.9k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Vaccinate?

pedrohcgs (a GitHub user) maintains it in pedrohcgs/claude-code-my-workflow, which has 1,655 GitHub stars. The repository holds 59 skills in this directory. The repository was last updated on September 27, 2026.

Source: pedrohcgs/claude-code-my-workflow on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.