Agent skill

Verify Form Validation

by reticlehq in reticlehq/reticle

Check that a form actually rejects bad input: the error message renders, the submit button stays disabled, and no request goes out.

Apache-2.0Auto-check passedTesting & QA

Install Verify Form Validation

skills CLI
$ npx skills add reticlehq/reticle --skill verify-form-validation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install reticlehq/reticle verify-form-validation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/reticlehq/reticle.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/verify-form-validation .claude/skills/verify-form-validation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
verify-form-validation
GitHub stars
1.2k
Token cost
~1.6k tokens
SKILL.md length
703 words
Files
1
Skills in repo
18
Repo updated
First seen
Licence
Apache-2.0

At a glance

Check that a form actually rejects bad input: the error message renders, the submit button stays disabled, and no request goes out.

  • Works in 4 steps: The error is the app's own, not the… → The submit control's disabled state is… → Zero matching requests fired, counted,… → …
  • Validation logic was written but never driven
  • SKILL.md covers Read this before you start:…, Trigger the rejection, Prove nothing fired and Clear the error, plus 2 more sections
  • Calls curl and npx; reaches docs.reticle.sh

What it does

Verify Form Validation is an agent skill from reticlehq/reticle. Check that a form actually rejects bad input: the error message renders, the submit button stays disabled, and no request goes out. Use when validation logic was written but never driven, when a "required" or pattern check looks right on screen but was never proven, or when a bug report says the form submitted invalid data anyway.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Testing & QA, covering Forms and validation and QA and bug reports. The repository describes itself as: AI agents can generate code, but still struggle to understand what they build. Reticle brings Jev-style machine-native runtime perception to web & desktop applications. The licence is Apache-2.0.

When your agent uses it

  • Validation logic was written but never driven
  • Pattern check looks right on screen but was never proven
  • A bug report says the form submitted invalid data anyway

Example prompts

  • “required”
  • “/verify-form-validation”

Requirements

  • Node.js

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. The error is the app's own, not the browser's native bubble.
  2. The submit control's disabled state is real, not opacity/cursor styling that only looks inert. This is the same distinction…
  3. Zero matching requests fired, counted, not inferred from "no error was thrown."
  4. The rejection is conditional: a valid value clears the error and re-enables submit.

What it can do on your machine

Read from SKILL.md and the folder at commit 15bddcf. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • docs.reticle.sh

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Verify Form Validation loads about 1.6k tokens when it runs. Until then it costs about 89 tokens; SKILL.md has 703 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~89
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from reticlehq/reticle at commit 15bddcf, republished under its Apache-2.0 licence (© reticlehq). 703 words, ~1,557 tokens.

Download SKILL.mdSave it as .claude/skills/verify-form-validation/SKILL.md (or your agent's skills folder).
name
verify-form-validation
description
Check that a form actually rejects bad input: the error message renders, the submit button stays disabled, and no request goes out. Use when validation logic was written but never driven, when a "required" or pattern check looks right on screen but was never proven, or when a bug report says the form submitted invalid data anyway.
license
Apache-2.0
metadata.version
3.6.0
metadata.homepage
https://www.reticle.sh
metadata.repository
https://github.com/reticlehq/reticle

A rejected form still looks fine on screen

Validation code is written once, glanced at in the browser with one obviously-bad value, and never driven again. The bug that ships is never the value you tried. It's the one you didn't: a submit button that isn't disabled until the field blurs, a button that's disabled only by CSS and still clickable, or a handler that fires the request before the check finishes.

Reticle can drive the real form and check all three failure points at once. Not installed? RETICLE_INSTALL_SOURCE=npx_skill npx @reticlehq/server@latest init, then the install-and-verify skill.

Read this before you start: the browser's own validation can mask the app's

required, pattern, type="email" and friends stop the browser at the constraint-validation bubble before your app's JS ever runs. If you assert on that native tooltip, you've verified the browser, not the code you're supposed to be testing. Confirm the error you're checking is the app's own element (a testid, a role, a rendered string), not a :invalid pseudo-state, before you trust the verdict. If the form relies on native validation alone with no app-level check behind it, that's the finding: say so, don't paper over it with a predicate that happens to pass.

Trigger the rejection

Name the consequence before you act, same as any Reticle drive:

reticle_look({ action: "page", sessionId, mode: "interactive" })   // get refs for the field and submit control

reticle_act_and_wait({ sessionId, ref, action: "fill", args: { value: "<invalid>" }, until: { kind: "allOf", predicates: [
  { kind: "element", query: { testid: "field-error" } },
  { kind: "element", query: { role: "button", name: "Submit" }, state: "disabled" },
]}})

If the check runs on blur rather than on keystroke, move focus to a different control as its own step before asserting: reticle_act({ sessionId, ref: otherRef, action: "focus" }) on the submit button or the next field, since focusing anything else is what fires the blur you need. If it's debounced instead, don't sleep for it. Use reticle_run({ tool: "reticle_clock", args: { sessionId, advanceMs } }) to advance past the debounce window exactly as in test-error-states. A fixed sleep passes on your machine and flakes in CI.

Prove nothing fired

The button looking disabled is not the same claim as the request never leaving. Don't just trust the disabled state you already asserted. Try the submit anyway, so a fake-disabled control (CSS-only, still clickable) gets caught instead of waved through:

reticle_act({ sessionId, ref: submitRef, action: "click" })

Then assert the negative. Checking count: 0 the instant after the click proves nothing on its own: the request may simply not have been sent yet. Give the app a real window to have tried before you trust the absence, settling first and then checking the count, in one call:

reticle_assert({ sessionId, since, timeout_ms: 3000, predicate: { kind: "allOf", predicates: [
  { kind: "settled" },
  { kind: "net", method: "POST", urlContains: "/api/...", count: 0 },
]}})

The timeout_ms is what makes this a wait instead of a snapshot: reticle_assert defaults to timeout_ms: 0, one evaluation at the instant you call it, so without it settled is just checked once right after the click and proves nothing about whether the app was actually idle. With timeout_ms: 3000, the call keeps polling for up to three seconds until the page genuinely goes quiet. Only once it has settled does a count: 0 reading mean anything. Use since from the click's own result, not from the earlier fill, so you're scoped to requests after the submit attempt specifically.

Show full SKILL.md (212 more words)Show less

Clear the error

Correct the value and confirm the rejection was conditional, not permanent:

reticle_act_and_wait({ sessionId, ref, action: "fill", args: { value: "<valid>" }, until: { kind: "allOf", predicates: [
  { kind: "element", query: { testid: "field-error" }, absent: true },
  { kind: "element", query: { role: "button", name: "Submit" }, state: "enabled" },
]}})

A form that never re-enables once it has rejected something once is a second bug wearing the first one's clothes.

What to assert

Only verified: "yes" is a pass. "no" is a real finding, "unknown" means Reticle couldn't tell and needs a better capture, and "no-fault" means nothing was disproven but nothing was declared either. None of the three are evidence the form rejects bad input.

  1. The error is the app's own, not the browser's native bubble.
  2. The submit control's disabled state is real, not opacity/cursor styling that only looks inert. This is the same distinction design-system-compliance draws between disabled-looking and disabled.
  3. Zero matching requests fired, counted, not inferred from "no error was thrown."
  4. The rejection is conditional: a valid value clears the error and re-enables submit.

Honesty

A verdict here is about this field and this invalid value, not the whole form. A required-field check tells you nothing about a pattern check on a different field. If you only drove one input, say which one, and say the rest of the form is unverified rather than letting a single pass read as "the form validates."


Capability reference: curl https://docs.reticle.sh/capabilities.md. Everything else: curl https://docs.reticle.sh/llms.txt.

© reticlehq, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/verify-form-validation of reticlehq/reticle.

Open the folder on GitHubat commit 15bddcf

Compare with similar skills

Verify Form Validation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Verify Form Validation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Verify Form Validation this skillreticlehq/reticle1.2k—~1.6kAutomated safety check: PassApache-2.0
Reproduce Chat Statesdifferent-ai/openwork24k—~673Automated safety check: PassCustom licence
Visual QA For Web And Terminal UIscode-yeongyu/oh-my-openagent70k—~9.5kAutomated safety check: PassCustom licence
Test And Breakrohunj/claude-build-workflow231—~1.6kAutomated safety check: PassNone
Scoutqa Testgithub/awesome-copilot40k1 repos~3.5kAutomated safety check: PassMIT
Journey Deploybutterbase-ai/butterbase-skills534—~666Automated safety check: PassMIT

Similar skills

  • Reproduce Chat States

    different-ai/openwork

    Fires known chat states in the running OpenWork desktop app, such as provider errors, retries and tool steps, so you can check how each renders.

    24k GitHub stars~673 tokensUpdated today
    Testing & QAAuto-check passed
  • Visual QA For Web And Terminal UIs

    code-yeongyu/oh-my-openagent

    Checks a built UI against a human-interface checklist and any reference image, pairing day and night screenshots at two screen widths.

    70k GitHub stars~9.5k tokensUpdated today
    Testing & QAAuto-check passed
  • Test And Break

    rohunj/claude-build-workflow

    Autonomous testing skill that opens a deployed app, goes through user flows, tries to break things, and writes detailed bug reports.

    231 GitHub stars~1.6k tokensUpdated 8 mo ago
    Testing & QAAuto-check passed
  • Scoutqa Test

    github/awesome-copilot

    Official

    This skill should be used when the user asks to "test this website", "run exploratory testing", "check for accessibility issues", "verify the login flow works", "find bugs on this page", or requests…

    40k GitHub starsUsed in 1 repo~3.5k tokens
    Testing & QAAuto-check passed
  • Journey Deploy

    butterbase-ai/butterbase-skills

    Use as the deploy-verification stage of the Butterbase journey, after journey-frontend (or after any build stage if there is no frontend).

    534 GitHub stars~666 tokensUpdated 3 days ago
    Testing & QAAuto-check passed
  • Kb Testing Strategy

    Community-Access/accessibility-agents

    Reference data, not a reviewer. An agent skill from Community-Access/accessibility-agents.

    422 GitHub stars~1.4k tokensUpdated 15 days ago
    Testing & QAAuto-check passed

More from reticlehq/reticle

All 18 skills in this repo
  • Verify Login Logout

    reticlehq/reticle

    Prove sign-in lands the user where they should be, sign-out really ends the session so a protected page sends them back to sign in, and an expired session asks to sign in again instead of breaking.

    1.2k GitHub starsUsed in 1 repo~1.4k tokens
    Auto-check passed
  • Verify Optimistic Update

    reticlehq/reticle

    Prove a UI that updates before the server answers puts things back and says so when the request fails, and keeps the change when it succeeds.

    1.2k GitHub starsUsed in 1 repo~1.3k tokens
    Auto-check passed
  • Verify Pagination

    reticlehq/reticle

    Prove the next page of a list, or the next batch of an infinite scroll, loads NEW rows from the server, repeats none, and that the end of the list is handled.

    1.2k GitHub starsUsed in 1 repo~1.5k tokens
    Auto-check passed
  • Agentic TDD

    reticlehq/reticle

    Applies red-green TDD to behavior unit tests cannot reach, by stating the expected outcome against the running app with Reticle before writing the feature.

    1.2k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Whole-App Health Sweep

    reticlehq/reticle

    Sweeps a running web app by clicking every reachable control, then reports dead buttons, console errors, failed requests and mismatches between API data and the screen.

    1.2k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Broken UI Debugger

    reticlehq/reticle

    Finds why a running web app misbehaves when the console is empty and the code looks fine, by reading the click, request, store and console together.

    1.2k GitHub stars~1.3k tokensUpdated today
    Auto-check passed

Questions about Verify Form Validation

What does Verify Form Validation do?

Check that a form actually rejects bad input: the error message renders, the submit button stays disabled, and no request goes out. Verify Form Validation is an agent skill from reticlehq/reticle. Check that a form actually rejects bad input: the error message renders, the submit button stays disabled, and no request goes out.

When should I use Verify Form Validation?

Verify Form Validation fits situations like: validation logic was written but never driven; pattern check looks right on screen but was never proven; A bug report says the form submitted invalid data anyway.

How do I install Verify Form Validation in Claude Code?

Run `npx skills add reticlehq/reticle --skill verify-form-validation -a claude-code`. Or copy the skill folder (skills/verify-form-validation in reticlehq/reticle) into .claude/skills/verify-form-validation in your project. Claude Code loads it when a task matches its description.

How do I install Verify Form Validation in Codex?

Run `npx skills add reticlehq/reticle --skill verify-form-validation -a codex`. Or copy the skill folder (skills/verify-form-validation in reticlehq/reticle) into .agents/skills/verify-form-validation in your project. Codex loads it when a task matches its description.

Can I use Verify Form Validation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add reticlehq/reticle --skill verify-form-validation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/verify-form-validation, .gemini/skills/verify-form-validation, .github/skills/verify-form-validation and .opencode/skills/verify-form-validation in your project.

What does Verify Form Validation need to run?

Going by SKILL.md and its folder, Verify Form Validation needs the command-line tools its instructions call (curl and npx). Our summary lists: Node.js.

Does Verify Form Validation access the network?

SKILL.md names 1 domain. In commands or code: docs.reticle.sh; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Verify Form Validation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Verify Form Validation use?

Verify Form Validation is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Verify Form Validation use?

About 1.6k tokens (SKILL.md is roughly 6.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Verify Form Validation?

Skills that share tags, products or a category with Verify Form Validation: Reproduce Chat States (different-ai/openwork, 24k stars), Visual QA For Web And Terminal UIs (code-yeongyu/oh-my-openagent, 70k stars), Test And Break (rohunj/claude-build-workflow, 231 stars) and Scoutqa Test (github/awesome-copilot, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Verify Form Validation?

reticlehq (a GitHub organization) maintains it in reticlehq/reticle, which has 1,190 GitHub stars. The repository holds 18 skills in this directory. The repository was last updated on October 8, 2026.

Source: reticlehq/reticle on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.