Agent skill

Strict Enforcement

by povvo in povvo/claudikins-kernel

A skill your agent uses when running claudikins-kernel:verify, checking implementation quality, deciding pass/fail verdicts, or enforcing cross-command gates — requires actual evidence of code…

MITAuto-check: notesTesting & QA

Install Strict Enforcement

skills CLI
$ npx skills add povvo/claudikins-kernel --skill strict-enforcement -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install povvo/claudikins-kernel strict-enforcement --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/povvo/claudikins-kernel.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/strict-enforcement .claude/skills/strict-enforcement && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
strict-enforcement
GitHub stars
128
Token cost
~2.7k tokens
SKILL.md length
779 words
Files
11 (incl. references)
Skills in repo
4
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when running claudikins-kernel:verify, checking implementation quality, deciding pass/fail verdicts, or enforcing cross-command gates — requires actual evidence of code…

  • Works in 5 steps: Automated Quality Checks → Output Verification (catastrophiser) → Code Simplification (Optional) → …
  • Running claudikins-kernel:verify
  • SKILL.md covers When to use this skill, Core Philosophy, Verification Phases and Rationalizations to Resist, plus 8 more sections
  • Calls npm, cargo and jq

What it does

Strict Enforcement is an agent skill from povvo/claudikins-kernel. Use when running claudikins-kernel:verify, checking implementation quality, deciding pass/fail verdicts, or enforcing cross-command gates — requires actual evidence of code working, not just passing tests

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 11 other files, including reference files (for example `references/advanced-verification.md`, `references/agent-integration.md` and `references/cynic-rollback.md`).

It sits in Testing & QA. It works with npm. The repository describes itself as: SRE thinking applied to Claude Code, based on Boris Cherny's Q&A. It enforces a strict 4-stage pipeline with gates between each step. You literally cannot skip verification. You… The licence is MIT.

When your agent uses it

  • Running claudikins-kernel:verify
  • Checking implementation quality
  • Deciding pass/fail verdicts
  • Enforcing cross-command gates — requires actual evidence of code working

Example prompts

  • “/strict-enforcement”

Requirements

  • Pre-approved tools (allowed-tools): Read, Grep, Glob, Bash, WebFetch, Skill, mcp__plugin_claudikins-tool-executor_tool-executor__search_tools, mcp__plugin_claudikins-tool-executor_tool-executor__get_tool_schema, mcp__plugin_claudikins-tool-executor_tool-executor__execute_code

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Automated Quality Checks
  2. Output Verification (catastrophiser)
  3. Code Simplification (Optional)
  4. Klaus Escalation
  5. Human Checkpoint

What it can do on your machine

Read from SKILL.md and the folder at commit 8b626a4. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep
    • Glob
    • Bash
    • WebFetch
    • Skill
    • mcp__plugin_claudikins-tool-executor_tool-executor__search_tools
    • mcp__plugin_claudikins-tool-executor_tool-executor__get_tool_schema
    • mcp__plugin_claudikins-tool-executor_tool-executor__execute_code

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • cargo
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Strict Enforcement loads about 2.7k tokens when it runs, and up to ~23k if it reads all its reference files. Until then it costs about 56 tokens; SKILL.md has 779 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~56
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~23k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Grep, Glob, Bash, WebFetch, Skill, mcp__plugin_claudikins-tool-executor_tool-executor__search_

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from povvo/claudikins-kernel at commit 8b626a4, republished under its MIT licence (© povvo). 779 words, ~2,725 tokens.

Download SKILL.mdSave it as .claude/skills/strict-enforcement/SKILL.md (or your agent's skills folder). This skill also uses 10 other files; get the full folder from GitHub.
name
strict-enforcement
description
Use when running claudikins-kernel:verify, checking implementation quality, deciding pass/fail verdicts, or enforcing cross-command gates — requires actual evidence of code working, not just passing tests
allowed-tools
Read, Grep, Glob, Bash, WebFetch, Skill, mcp__plugin_claudikins-tool-executor_tool-executor__search_tools, mcp__plugin_claudikins-tool-executor_tool-executor__get_tool_schema, mcp__plugin_claudikins-tool-executor_tool-executor__execute_code

Strict Enforcement Verification Methodology

When to use this skill

Use this skill when you need to:

  • Run the claudikins-kernel:verify command
  • Validate implementation before shipping
  • Decide pass/fail verdicts
  • Check code integrity after changes
  • Enforce cross-command gates

Core Philosophy

"Evidence before assertions. Always." - Verification philosophy

Never claim code works without seeing it work. Tests passing is not enough. Claude must SEE the output.

The Three Laws
  1. See it working - Screenshots, curl responses, CLI output. Actual evidence.
  2. Human checkpoint - No auto-shipping. Human reviews evidence and decides.
  3. Exit code 2 gates - Verification failures block claudikins-kernel:ship. No exceptions.

Verification Phases

Phase 1: Automated Quality Checks

Run the automated checks first. Fast feedback.

CheckCommand PatternWhat It Catches
Testsnpm test / pytest / cargo testLogic errors, regressions
Lintnpm run lint / ruff / clippyStyle issues, common bugs
Typestsc / mypy / cargo checkType mismatches, interface drift
Buildnpm run build / cargo buildCompilation errors, bundling issues

Flaky Test Detection (C-12):

Test fails?
├── Re-run failed tests
├── Pass 2nd time?
│   └── Yes → STOP: [Accept flakiness] [Fix tests] [Abort]
└── Fail 2nd time?
    ├── Run isolated
    └── Still fail? → STOP: [Fix] [Skip] [Abort]
Phase 2: Output Verification (catastrophiser)

This is the feedback loop that makes Claude's code actually work.

Project TypeVerification MethodEvidence
Web appStart server, screenshot, test flowsScreenshots, console logs
APICurl endpoints, check responsesStatus codes, response bodies
CLIRun commands, capture outputstdout, stderr, exit codes
LibraryRun examples, check resultsOutput values, test coverage
ServiceCheck logs, verify health endpointLog patterns, health responses

Fallback Hierarchy (A-3):

If primary method unavailable, fall back:

  1. Start server + screenshot (preferred for web)
  2. Curl endpoints (preferred for API)
  3. Run CLI commands (preferred for CLI)
  4. Run tests only (fallback)
  5. Code review only (last resort)

Timeout: 30 seconds per verification method (CMD-30).

Phase 3: Code Simplification (Optional)

After verification passes, optionally run cynic for polish.

Prerequisites:

  • Phase 2 (catastrophiser) must PASS
  • Human approves: "Run cynic for polish pass?"

cynic Rules:

  • Preserve exact behaviour (tests MUST still pass)
  • Remove unnecessary abstraction
  • Improve naming clarity
  • Delete dead code
  • Flatten nested conditionals

If tests fail after simplification:

  • Log failure reasons
  • Show human
  • Proceed anyway (A-5) with caveat

See cynic-rollback.md for recovery patterns.

Phase 4: Klaus Escalation

If stuck during verification:

Is mcp__claudikins-klaus available? (E-16)
├── No →
│   Offer: [Manual review] [Ask Claude differently] (E-17)
│   Fallback: [Accept with uncertainty] [Max retries, abort] (E-18)
└── Yes →
    Spawn klaus via SubagentStop hook
Phase 5: Human Checkpoint

The final gate. Present comprehensive evidence.

Verification Report
-------------------
Tests:  ✓ 47/47 passed
Lint:   ✓ 0 issues
Types:  ✓ 0 errors
Build:  ✓ success

Evidence:
- Screenshot: .claude/evidence/login-flow.png
- API test: POST /api/auth → 200 OK
- CLI test: mycli --help → exit 0

[Ready to Ship] [Needs Work] [Accept with Caveats]

Human decides. If approved, set unlock_ship = true.

Rationalizations to Resist

Agents under pressure find excuses. These are all violations:

ExcuseReality
"Tests pass, that's good enough"Tests aren't enough. SEE it working. Screenshots, curl, output.
"I'll verify after shipping"Verify BEFORE ship. That's the whole point.
"The type checker caught everything"Types don't catch runtime issues. Get evidence.
"Screenshot failed but it probably works""Probably" isn't evidence. Fix the screenshot or use fallback.
"Human checkpoint is just a formality"Human checkpoint is the gate. No auto-shipping.
"Code review is enough for this change"Code review is last resort fallback. Try harder.
"Tests are flaky, I'll ignore the failure"Flaky tests hide real failures. Fix or explicitly accept with caveat.
"Exit code 2 is too strict"Exit code 2 exists to block bad ships. Pass properly.

All of these mean: Get evidence. Human decides. No shortcuts.

Show full SKILL.md (276 more words)Show less

Red Flags — STOP and Reassess

If you're thinking any of these, you're about to violate the methodology:

  • "It should work because..."
  • "The tests pass so..."
  • "I'm confident that..."
  • "It worked before..."
  • "The types check so..."
  • "I'll just skip verification this once"
  • "Human will approve anyway"
  • "Evidence isn't necessary for this change"

All of these mean: STOP. Get evidence. Present to human. Let them decide.

Exit Code 2 Pattern (CRITICAL)

The verify-gate.sh hook enforces the gate:

bash
# Both conditions MUST be true
ALL_PASSED=$(jq -r '.all_checks_passed' "$STATE")
HUMAN_APPROVED=$(jq -r '.human_checkpoint.decision' "$STATE")

if [ "$ALL_PASSED" != "true" ]; then
  exit 2  # Blocks claudikins-kernel:ship
fi

if [ "$HUMAN_APPROVED" != "ready_to_ship" ]; then
  exit 2  # Blocks claudikins-kernel:ship
fi

File Manifest (C-6):

At verification completion, generate SHA256 hashes of all source files:

bash
find . \( -name '*.ts' -o -name '*.py' -o -name '*.rs' \) \
  | xargs sha256sum > .claude/verify-manifest.txt

This lets claudikins-kernel:ship detect if code was modified after verification.

Cross-Command Gate (C-14)

claudikins-kernel:verify requires claudikins-kernel:execute to have completed:

bash
if [ ! -f "$EXECUTE_STATE" ]; then
  echo "ERROR: claudikins-kernel:execute has not been run"
  exit 2
fi

This enforces the claudikins-kernel:outline → claudikins-kernel:execute → claudikins-kernel:verify → claudikins-kernel:ship flow.

Agent Integration

AgentRoleWhen
catastrophiserSee code workingPhase 2: Output verification
cynicPolish passPhase 3: Simplification (optional)

Both agents run with context: fork and background: true.

See agent-integration.md for coordination patterns.

State Tracking

verify-state.json
json
{
  "session_id": "verify-2026-01-16-1100",
  "execute_session_id": "execute-2026-01-16-1030",
  "branch": "execute/task-1-auth-middleware",
  "phases": {
    "test_suite": { "status": "PASS", "count": 47 },
    "lint": { "status": "PASS", "issues": 0 },
    "type_check": { "status": "PASS", "errors": 0 },
    "output_verification": { "status": "PASS", "agent": "catastrophiser" },
    "code_simplification": { "status": "PASS", "agent": "cynic" }
  },
  "all_checks_passed": true,
  "human_checkpoint": {
    "decision": "ready_to_ship",
    "caveats": []
  },
  "unlock_ship": true,
  "verified_manifest": "sha256:...",
  "verified_commit_sha": "abc123..."
}

Anti-Patterns

Don't do these:

  • Trusting test results without seeing code run
  • Skipping output verification because "tests pass"
  • Auto-approving verification without human checkpoint
  • Modifying code after verification passes
  • Ignoring flaky test warnings
  • Proceeding when lint/type checks fail

Edge Case Handling

SituationReference
Tests hang or timeouttest-timeout-handling.md
Auto-fix breaks codelint-fix-validation.md
Primary verification failsverification-method-fallback.md
Type-check results uncleartype-check-confidence.md
cynic breaks testscynic-rollback.md
Large project stateverify-state-compression.md

References

Full documentation in this skill's references/ folder:

© povvo, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 10 other files (references) in skills/strict-enforcement of povvo/claudikins-kernel.

  • SKILL.md
  • references/advanced-verification.md
  • references/agent-integration.md
  • references/cynic-rollback.md
  • references/lint-fix-validation.md
  • references/red-flags.md
  • references/test-timeout-handling.md
  • references/type-check-confidence.md
  • references/verification-checklist.md
  • references/verification-method-fallback.md
  • references/verify-state-compression.md

Open the folder on GitHubat commit 8b626a4

Compare with similar skills

Strict Enforcement next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Strict Enforcement compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Strict Enforcement this skillpovvo/claudikins-kernel128—~2.7kAutomated safety check: NotesMIT
Quality Scandiegosouzapw/OmniRoute75k—~748Automated safety check: PassMIT
Testingwellwelwel/poku1.2k—~1kAutomated safety check: PassMIT
Actions CI Tuningmizchi/skills360—~2.6kAutomated safety check: PassNone
CI Triageandymai/brepjs115—~3.8kAutomated safety check: PassApache-2.0
OpenHarness End-to-End EvalsHKUDS/OpenHarness16k1 repos~2.1kAutomated safety check: NotesMIT

Similar skills

  • Quality Scan

    diegosouzapw/OmniRoute

    Runs a scoped, read-only quality scan on a repository candidate and reports exact evidence, failures and frozen debt, without treating a static scan as release acceptance.

    75k GitHub stars~748 tokensUpdated today
    Testing & QAAuto-check passed
  • Testing

    wellwelwel/poku

    Testing deep-dive for poku covering test structure, commands, patterns, fixtures, utils, Docker compatibility, and coverage.

    1.2k GitHub stars~1k tokensUpdated 3 mo ago
    Testing & QAAuto-check passed
  • Actions CI Tuning

    mizchi/skills

    A skill your agent uses when auditing or improving GitHub Actions workflows for a project.

    360 GitHub stars~2.6k tokensUpdated 8 days ago
    Testing & QAAuto-check passed
  • CI Triage

    andymai/brepjs

    This skill should be used when a brepjs GitHub Actions job is red or behaving oddly on github.com (a remote CI run, not a local pre-commit/pre-push hook) — "CI failed", "ci-pass is failing", "npm ci…

    115 GitHub stars~3.8k tokensUpdated today
    Testing & QAAuto-check passed
  • Validates OpenHarness features by running real multi-turn agent loops with live LLM calls against an unfamiliar codebase, checking actual tool execution.

    16k GitHub starsUsed in 1 repo~2.1k tokens
    Testing & QAAuto-check: notes
  • Qwen Code E2E Testing

    QwenLM/qwen-code

    Guides end-to-end testing of the Qwen Code CLI in headless mode with real model calls, MCP test servers and inspection of raw API traffic.

    28k GitHub stars~2.1k tokensUpdated today
    Testing & QAAuto-check passed

More from povvo/claudikins-kernel

  • Brain Jam Plan

    povvo/claudikins-kernel

    A skill your agent uses when running claudikins-kernel:outline, brainstorming implementation approaches, gathering requirements iteratively, structuring complex technical plans, or facing analysis…

    128 GitHub stars~2k tokensUpdated 5 mo ago
    Auto-check passed
  • Git Workflow

    povvo/claudikins-kernel

    A skill your agent uses when running claudikins-kernel:execute, decomposing plans into tasks, setting up two-stage review, deciding batch sizes, or handling stuck agents — enforces isolation…

    128 GitHub stars~3.4k tokensUpdated 5 mo ago
    Auto-check: notes
  • Shipping Methodology

    povvo/claudikins-kernel

    A skill your agent uses when running claudikins-kernel:ship, preparing PRs, writing changelogs, deciding merge strategy, or handling CI failures — enforces GRFP-style iterative approval, code…

    128 GitHub stars~3.2k tokensUpdated 5 mo ago
    Auto-check: notes

Works with

Questions about Strict Enforcement

What does Strict Enforcement do?

A skill your agent uses when running claudikins-kernel:verify, checking implementation quality, deciding pass/fail verdicts, or enforcing cross-command gates — requires actual evidence of code…. Strict Enforcement is an agent skill from povvo/claudikins-kernel.

When should I use Strict Enforcement?

Strict Enforcement fits situations like: running claudikins-kernel:verify; checking implementation quality; deciding pass/fail verdicts; enforcing cross-command gates — requires actual evidence of code working.

How do I install Strict Enforcement in Claude Code?

Run `npx skills add povvo/claudikins-kernel --skill strict-enforcement -a claude-code`. Or copy the skill folder (skills/strict-enforcement in povvo/claudikins-kernel) into .claude/skills/strict-enforcement in your project. Claude Code loads it when a task matches its description.

How do I install Strict Enforcement in Codex?

Run `npx skills add povvo/claudikins-kernel --skill strict-enforcement -a codex`. Or copy the skill folder (skills/strict-enforcement in povvo/claudikins-kernel) into .agents/skills/strict-enforcement in your project. Codex loads it when a task matches its description.

Can I use Strict Enforcement in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add povvo/claudikins-kernel --skill strict-enforcement -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/strict-enforcement, .gemini/skills/strict-enforcement, .github/skills/strict-enforcement and .opencode/skills/strict-enforcement in your project.

What does Strict Enforcement need to run?

Going by SKILL.md and its folder, Strict Enforcement needs the command-line tools its instructions call (npm, cargo and jq). Its frontmatter pre-approves these tools: Read, Grep, Glob, Bash, WebFetch, Skill, mcp__plugin_claudikins-tool-executor_tool-executor__search_tools, mcp__plugin_claudikins-tool-executor_tool-executor__get_tool_schema, mcp__plugin_claudikins-tool-executor_tool-executor__execute_code.

Does Strict Enforcement access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Strict Enforcement safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Strict Enforcement use?

Strict Enforcement is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Strict Enforcement use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 20k tokens, read only when the agent opens those files.

What are the alternatives to Strict Enforcement?

Skills that share tags, products or a category with Strict Enforcement: Quality Scan (diegosouzapw/OmniRoute, 75k stars), Testing (wellwelwel/poku, 1.2k stars), Actions CI Tuning (mizchi/skills, 360 stars) and CI Triage (andymai/brepjs, 115 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Strict Enforcement?

povvo (a GitHub user) maintains it in povvo/claudikins-kernel, which has 128 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on April 22, 2026.

Source: povvo/claudikins-kernel on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.