Money Quality
iamzifei/show-me-the-money
Code and product quality gates for shipping with confidence.
Feature verification (READ-ONLY, P0-P5). An agent skill from sd0xdev/sd0x-harness.
$ npx skills add sd0xdev/sd0x-harness --skill feature-verify -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install sd0xdev/sd0x-harness feature-verify --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/sd0xdev/sd0x-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/feature-verify .claude/skills/feature-verify && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "feature-verify" agent skill from https://github.com/sd0xdev/sd0x-harness/tree/main/skills/feature-verify into .claude/skills/feature-verify/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "feature-verify", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/sd0xdev/sd0x-harness/tree/main/skills/feature-verifyType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add sd0xdev/sd0x-harness --skill feature-verify -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install sd0xdev/sd0x-harness feature-verify --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sd0xdev/sd0x-harness.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/feature-verify .agents/skills/feature-verify && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "feature-verify" agent skill from https://github.com/sd0xdev/sd0x-harness/tree/main/skills/feature-verify into .agents/skills/feature-verify/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "feature-verify", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add sd0xdev/sd0x-harness --skill feature-verify -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install sd0xdev/sd0x-harness feature-verify --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sd0xdev/sd0x-harness.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/feature-verify .cursor/skills/feature-verify && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "feature-verify" agent skill from https://github.com/sd0xdev/sd0x-harness/tree/main/skills/feature-verify into .cursor/skills/feature-verify/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "feature-verify", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/sd0xdev/sd0x-harness.git --path skills/feature-verify--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add sd0xdev/sd0x-harness --skill feature-verify -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install sd0xdev/sd0x-harness feature-verify --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sd0xdev/sd0x-harness.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/feature-verify .gemini/skills/feature-verify && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "feature-verify" agent skill from https://github.com/sd0xdev/sd0x-harness/tree/main/skills/feature-verify into .gemini/skills/feature-verify/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "feature-verify", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install sd0xdev/sd0x-harness feature-verifyInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add sd0xdev/sd0x-harness --skill feature-verify -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/sd0xdev/sd0x-harness.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/feature-verify .github/skills/feature-verify && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "feature-verify" agent skill from https://github.com/sd0xdev/sd0x-harness/tree/main/skills/feature-verify into .github/skills/feature-verify/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "feature-verify", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add sd0xdev/sd0x-harness --skill feature-verify -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install sd0xdev/sd0x-harness feature-verify --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sd0xdev/sd0x-harness.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/feature-verify .opencode/skills/feature-verify && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "feature-verify" agent skill from https://github.com/sd0xdev/sd0x-harness/tree/main/skills/feature-verify into .opencode/skills/feature-verify/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "feature-verify", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
feature-verifyFeature verification (READ-ONLY, P0-P5). An agent skill from sd0xdev/sd0x-harness.
Feature Verify is an agent skill from sd0xdev/sd0x-harness. Feature verification (READ-ONLY, P0-P5). Use when: verifying feature behavior after deployment, validating API responses, diagnosing production issues, post-deploy smoke test. Not for: modifying data (use feature-dev), code review (use codex-review-fast), writing tests (use codex-test-gen), security audit (use codex-security).
Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `references/blackbox-testing.md`, `references/environments.md` and `references/output-template.md`).
It sits in Testing & QA, covering QA and bug reports, Security review and Deployment. The repository describes itself as: The harness layer for Claude Code — a reference implementation of harness engineering with hook-enforced dual review, state-machine gates that survive context compaction, and… The licence is MIT.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit a4d4bc1. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadGrepGlobBashWebFetchTaskSkillFrom allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
claudecurlgitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use curl and git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Feature Verify loads about 3.2k tokens when it runs, and up to ~9.4k if it reads all its reference files. Until then it costs about 86 tokens; SKILL.md has 1,141 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
allowed-tools: Read, Grep, Glob, Bash, WebFetch, Task, SkillAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from sd0xdev/sd0x-harness at commit a4d4bc1, republished under its MIT licence (© sd0xdev). 1,141 words, ~3,221 tokens.
.claude/skills/feature-verify/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.| Need | Use Instead |
|---|---|
| Modify data or state | /feature-dev |
| Code quality review | /codex-review-fast |
| Generate unit tests | /codex-test-gen |
| Security audit | /codex-security |
| Run local tests | /verify |
| Review test coverage | /codex-test-review |
⚠️ ALL OPERATIONS MUST BE READ-ONLY ⚠️
Claude independent analysis → Codex third-perspective confirmation → Integrated verdictTool safety note:
allowed-toolsincludesBashfor curl/log queries. Read-only enforcement is behavioral — all commands MUST be reviewed againstreferences/safety-rules.mdbefore execution. Codex independently verifies compliance at P5.
Auto-detect from references/environments.md configuration:
| Level | Available Resources | P3 API | P4 Observation | Confidence Cap |
|---|---|---|---|---|
| L4 | API + Log + Metrics | Full | Log + Metrics | High |
| L3 | API + Log | Full | Log only | High |
| L2-API | API only | Full | Response-only | Medium |
| L2-OBS | Log only (API unreachable) | Skip | Time-window scan | Medium |
| L1 | No runtime access | Skip P3/P4 | Code review only | Low |
Auto-detection logic (see references/environments.md § Degradation Detection):
| API Status | Log System | Metrics | Level |
|---|---|---|---|
| Reachable | Yes | Yes | L4 |
| Reachable | Yes | No | L3 |
| Reachable | No | — | L2-API |
| Unreachable | Yes | — | L2-OBS |
| Unreachable | No | — | L1 |
Fail-closed: If Endpoint Allowlist section is missing, skip P3 (cannot call unverified endpoints). At L1, skip P3 and P4. Provide code-review-based analysis only with Low confidence. At L2-OBS, skip P3 (API unreachable); execute P4 time-window scan and background service observation only.
sequenceDiagram
participant C as Claude
participant U as User
participant API as Target API
participant Log as Log System
participant Cx as Codex
C->>C: P0: Scope & Safety
C->>C: P1: Diff-Lite Scoping
C->>U: P2: Test Charter (approve?)
U->>C: Approved
C->>API: P3: API Execute (read-only)
C->>Log: P4: Observation Correlate
C->>Cx: P5: Codex independent review
Cx-->>C: Codex verdict
C->>U: P5: Integrated Verdict ReportRead safety-rules.md and environments.md.
| Check | Method | Fail Action |
|---|---|---|
| Environment select | --env flag or ask user; load from references/environments.md | Default to test |
| Read-only confirmed | Review references/safety-rules.md and load the endpoint allowlist. This row runs before any request is made — see below | — |
| API reachable | Deterministic health-check (3x, 2s timeout — see references/environments.md) | Unreachable + Log config → L2-OBS; Unreachable + no Log → L1 |
| Deployment aligned | Compare local HEAD with deployed version | Mismatch → warn, lower confidence |
| Degradation level | Check references/environments.md for log/metrics config | Set level (L1-L4) |
The health check is a request, so the allowlist gates it too. A reviewer found this skill calling the configured health endpoint before enforcing its own deny-all policy — which is the one request the policy could never have approved, because nothing had loaded the allowlist yet. Validate the health endpoint and its method against the allowlist first; if the allowlist is missing, or the health endpoint is not on it, make no request and degrade on that basis (unreachable-equivalent), recording why. "It is only a health check" is exactly the reasoning the deny-all policy exists to refuse.
Read blackbox-testing.md § P1.
Scope only — no code quality judgment.
git diff main...HEAD --name-only (or user-provided scope)Fallback: If no git diff available, ask user for feature description and build scope manually.
--level override: If user passes --level L2-API, skip log/metrics cases even if configured. --level L2-OBS forces observation-only mode. --level L2 defaults to L2-API for backward compatibility.
Read blackbox-testing.md § P2.
Generate test cases dynamically from P1 results:
| Type | Goal | When |
|---|---|---|
| L1 Regression | Affected API returns expected results | L2-API+ (N/A for L2-OBS) |
| L2 Active Trigger | New code path exercised, verify response | L2-API+ (N/A for L2-OBS) |
| L3 Passive Observe | Background service running, check logs | L3+ only |
| M1 Metrics | Metrics correctly emitted with right labels | L4 only |
User approval gate: Present charter table to user for confirmation before proceeding to P3. User may add/remove/modify cases.
Prerequisites: P2 approved, degradation level is L2-API or higher (L2-API/L3/L4). L2-OBS skips P3 entirely (API unreachable).
For each test case:
references/environments.md (generate unique request ID per call)references/safety-rules.md)references/environments.md (no real user data)# Example execution pattern
make_headers
REQ_ID=$(extract_request_id)
# Timing comes from curl, not from `date`: `date +%s%3N` is GNU-only and on macOS prints a literal
# `3N`, so the subtraction that used to live here produced garbage on the platform this repo runs on.
RESP=$(curl -s -w "\n%{http_code}\n%{time_total}" -X {{ METHOD }} "$HOST/{{ ENDPOINT }}" \
"${HEADERS[@]}" -d '{{ PAYLOAD }}')
LATENCY=$(echo "$RESP" | tail -1) # seconds, millisecond resolution
HTTP_CODE=$(echo "$RESP" | tail -2 | head -1)
BODY=$(echo "$RESP" | sed '$d' | sed '$d')Read blackbox-testing.md § P4.
Prerequisites: Degradation level L2-OBS or L3+.
L2-OBS mode: Skip subsection A (no P3 requests to correlate). Execute B (time-window scan) and C (background service observation). Observation window: deploy_time → now (fallback: user-specified or last 30min).
For each P3 request, query logs by request ID with fallback strategy:
Retry: 30s fast → 120s delayed → mark unreachable.
Scan test period for anomalies (error + warn levels).
Query logs for schedule/cron tags with 120s delay.
Query metrics system for affected metrics, verify labels and values.
Record what cannot be observed through black-box testing. List in report for /codex-test-review follow-up.
| Verdict | Condition |
|---|---|
| Pass | L1 passed + L2 has expected signal + L3 normal + M1 correct (N/A items don't block) |
| Warn | L1 passed but L2 signal missing, or L3/M1 has non-blocking anomaly |
| Blocked | L1 failed, or regression detected, or M1 shows incorrect labels |
| Inconclusive | API/log/metrics unreachable, insufficient evidence |
| Level | Condition |
|---|---|
| High | L3/L4 + Claude and Codex agree |
| Medium | L2-API (API-only) or L2-OBS (observation-only) or partial agreement |
| Low | L1 (no runtime) or Claude and Codex diverge |
/codex-brainstorm with P1 scope + P3 results + P4 observations (see references/blackbox-testing.md § P5)Codex must independently verify (see references/blackbox-testing.md § P5 prompt):
references/environments.md)Generate report using output-template.md.
Verdict is independent: Report may recommend follow-up skills (/codex-review-fast, /verify, /codex-test-review) but does NOT auto-invoke them.
| Rule | Description |
|---|---|
| Single request | One request at a time (no load testing) |
| Fixed parameters | Use test parameters from references/environments.md |
| Read-only only | Only allowlisted endpoints (references/safety-rules.md) |
| No PII | No real user credentials, keys, or sensitive data in payloads |
| Rate aware | Respect API rate limits |
references/output-template.md format| File | Content | Read At |
|---|---|---|
| environments.md | API endpoints, auth headers, log/metrics config, test params | P0, P3 |
| safety-rules.md | Read-only rules, endpoint allowlist, forbidden ops | P0, P3 |
| blackbox-testing.md | Diff-lite scoping, test charter design, log verification, blind spots | P1, P2, P4, P5 |
| output-template.md | Verdict report format | P5 |
Input: /feature-verify "User Auth API" --env test
Action: P0(reachable? → L3) → P1(diff → /api/auth/*) → P2(L1+L2 charter, user approves)
→ P3(curl read-only endpoints) → P4(log correlation) → P5(verdict: Pass, High)Input: /feature-verify "Payment query" --env prod --level L2
Action: P0(prod, forced L2) → P1(diff → /api/payment/query) → P2(L1+L2, no L3)
→ P3(curl) → P4(response-only) → P5(verdict: Pass, Medium)Input: /feature-verify "Background sync job" --env staging
Action: P0(staging, L3) → P1(diff → cron changes) → P2(L3 passive only)
→ P3(skip — no API endpoint) → P4(log observation for schedule tag) → P5(verdict)Input: /feature-verify "Cache optimization" (no env configured)
Action: P0(no config → L1) → P1(diff → cache service) → P2(code review only)
→ P3(skip) → P4(skip) → P5(verdict: Inconclusive, Low — recommend configuring references/environments.md)Input: /feature-verify "Order processing" --env prod
Action: P0(prod, API unreachable 3/3, Log config present → L2-OBS)
→ P1(diff → /api/order/*) → P2(L3 passive + time-window only, no L1/L2 active)
→ P3(skip — API unreachable) → P4(time-window scan: deploy→now, background observation)
→ P5(verdict: Pass/Warn/Inconclusive, Medium)© sd0xdev, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (references) in skills/feature-verify of sd0xdev/sd0x-harness.
Open the folder on GitHubat commit a4d4bc1
Feature Verify next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Feature Verify this skillsd0xdev/sd0x-harness | 192 | — | ~3.2k | Automated safety check: Notes | MIT | |
| Money Qualityiamzifei/show-me-the-money | 1k | — | ~5.7k | Automated safety check: Pass | Custom licence | |
| Vss E2E Smokeopen-edge-platform/edge-ai-libraries | 169 | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | |
| Review Codetobihagemann/turbo | 407 | — | ~3.2k | Automated safety check: Pass | MIT | |
| Write Fix Briefn1m21n/Infinite | 264 | — | ~2.9k | Automated safety check: Pass | Custom licence | |
| Spec Dogfoodleo-kuang-ai/spec-first | 107 | — | ~6.1k | Automated safety check: Notes | MIT |
iamzifei/show-me-the-money
Code and product quality gates for shipping with confidence.
open-edge-platform/edge-ai-libraries
Run this skill whenever the user asks to verify my VSS install works, smoke test VSS, check whether the deployment succeeded, or run an end-to-end test of summary/search for the…
tobihagemann/turbo
Review code for bugs, security vulnerabilities, API misuse, consistency issues, simplicity problems, or test coverage gaps and low-value tests by running internal reviews and a peer review in…
n1m21n/Infinite
Turn a bug report, review findings, broken-UI screenshot or new-node idea into a verified, file/line-precise implementation prompt after checking the real code.
leo-kuang-ai/spec-first
Hands-off, diff-scoped browser QA of the active branch or PR.
foryourhealth111-pixel/Vibe-Skills
Remove AI-generated code slop from a branch: unnecessary comments, redundant defensive checks, boilerplate, style drift, and type casts.
sd0xdev/sd0x-harness
Write an Architecture Decision Record (ADR) for a feature — Context / Decision / Status / Consequences / Alternatives, filed as docs/features/<feature/adr-<NNN-<title.md with a 3-digit zero-padded…
sd0xdev/sd0x-harness
Load GitHub PR review comments into AI session — analyze, triage, plan.
sd0xdev/sd0x-harness
Change-aware next step advisor. An agent skill from sd0xdev/sd0x-harness.
sd0xdev/sd0x-harness
Obsidian vault integration via official CLI. An agent skill from sd0xdev/sd0x-harness.
sd0xdev/sd0x-harness
Agent-driven workflow orchestration (v1 report-only). An agent skill from sd0xdev/sd0x-harness.
sd0xdev/sd0x-harness
Post friendly review comments to a GitHub PR — prepare locally, preview, then submit as atomic review.
Categories
Feature verification (READ-ONLY, P0-P5). An agent skill from sd0xdev/sd0x-harness. Feature Verify is an agent skill from sd0xdev/sd0x-harness. Feature verification (READ-ONLY, P0-P5).
Feature Verify fits situations like: : verifying feature behavior after deployment; validating API responses; diagnosing production issues; post-deploy smoke test.
Run `npx skills add sd0xdev/sd0x-harness --skill feature-verify -a claude-code`. Or copy the skill folder (skills/feature-verify in sd0xdev/sd0x-harness) into .claude/skills/feature-verify in your project. Claude Code loads it when a task matches its description.
Run `npx skills add sd0xdev/sd0x-harness --skill feature-verify -a codex`. Or copy the skill folder (skills/feature-verify in sd0xdev/sd0x-harness) into .agents/skills/feature-verify in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sd0xdev/sd0x-harness --skill feature-verify -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/feature-verify, .gemini/skills/feature-verify, .github/skills/feature-verify and .opencode/skills/feature-verify in your project.
Going by SKILL.md and its folder, Feature Verify needs the command-line tools its instructions call (claude, curl and git). Its frontmatter pre-approves these tools: Read, Grep, Glob, Bash, WebFetch, Task, Skill.
SKILL.md contains no URLs. Its commands use curl and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Feature Verify is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 6.2k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Feature Verify: Money Quality (iamzifei/show-me-the-money, 1k stars), Vss E2E Smoke (open-edge-platform/edge-ai-libraries, 169 stars), Review Code (tobihagemann/turbo, 407 stars) and Write Fix Brief (n1m21n/Infinite, 264 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
sd0xdev (a GitHub user) maintains it in sd0xdev/sd0x-harness, which has 192 GitHub stars. The repository holds 89 skills in this directory. The repository was last updated on October 8, 2026.
Source: sd0xdev/sd0x-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.