Agent skill

Vero Source Dafny

by sunblaze-ucb in sunblaze-ucb/vero

Load BEFORE translating Dafny source to Lean 4. An agent skill from sunblaze-ucb/vero.

Apache-2.0Auto-check: notesWriting & Content

Install Vero Source Dafny

skills CLI
$ npx skills add sunblaze-ucb/vero --skill vero-source-dafny -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sunblaze-ucb/vero vero-source-dafny --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sunblaze-ucb/vero.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/vero-source-dafny .claude/skills/vero-source-dafny && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
vero-source-dafny
GitHub stars
107
Token cost
~2k tokens
SKILL.md length
680 words
Files
1
Skills in repo
16
Repo updated
First seen
Licence
Apache-2.0

At a glance

Load BEFORE translating Dafny source to Lean 4. An agent skill from sunblaze-ucb/vero.

  • Works in 4 steps: Ledger struct in Impl foundation file… → Valid is vocabulary — Spec helper def… → Deposit → API reference implementation… → …
  • Tasks that involve Translation
  • SKILL.md covers When to use, Output-shape recap…, Classification rules and Type mapping, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Vero Source Dafny is an agent skill from sunblaze-ucb/vero. Load BEFORE translating Dafny source to Lean 4. Provides Dafny-specific classification rules, type mappings, and patterns for mapping Dafny constructs (method / function / predicate / lemma / datatype / class) into the ratified bundle paradigm (Impl/ + Spec/ + Bundle + Harness). Pair with vero-discover, vero-plan, vero-translate, and vero-dafny-pitfalls.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Writing & Content, covering Translation. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Translation

Example prompts

  • “/vero-source-dafny”

Requirements

  • Pre-approved tools (allowed-tools): Read, Write, Edit, Bash, Grep, Glob

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Ledger struct in Impl foundation file (no markers).
  2. Valid is vocabulary — Spec helper def valid : Ledger → Prop if
  3. Deposit → API reference implementation with code markers.
  4. requires Valid() + ensures Valid() → one

What it can do on your machine

Read from SKILL.md and the folder at commit 0a7325d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Bash
    • Grep
    • Glob

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are dafny, json and lean).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Vero Source Dafny loads about 2k tokens when it runs. Until then it costs about 94 tokens; SKILL.md has 680 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~94
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Write, Edit, Bash, Grep, Glob

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sunblaze-ucb/vero at commit 0a7325d, republished under its Apache-2.0 licence (© sunblaze-ucb). 680 words, ~2,047 tokens.

Download SKILL.mdSave it as .claude/skills/vero-source-dafny/SKILL.md (or your agent's skills folder).
name
vero-source-dafny
description
Load BEFORE translating Dafny source to Lean 4. Provides Dafny-specific classification rules, type mappings, and patterns for mapping Dafny constructs (method / function / predicate / lemma / datatype / class) into the ratified bundle paradigm (Impl/ + Spec/ + Bundle + Harness). Pair with vero-discover, vero-plan, vero-translate, and vero-dafny-pitfalls.
allowed-tools
Read, Write, Edit, Bash, Grep, Glob

VCG Source: Dafny → Lean 4

Dafny-specific classification and translation patterns for the ratified curation paradigm. The shape of the emitted Lean is pinned by reference/BankLedger/ + .claude/skills/vero-translate/SKILL.md — this skill teaches the language mapping.

When to use

  • Classifying items in a Dafny (.dfy) source (with vero-discover).
  • Writing the translation plan for a Dafny source (with vero-plan).
  • Emitting Lean from Dafny (with vero-translate).

Output-shape recap (non-negotiable)

For each source-side module you translate:

  • <Project>/Impl/<Module>.lean holds:

    • Types (fully defined, no markers).
    • namespace Bank … abbrev <Fn>Sig := … per API signature (no markers).
    • def Bank.<fn> : Bank.<Fn>Sig := <translated reference impl> wrapped in code / code_aux markers.
    • !curation @review v1 annotations on each reference implementation.
  • <Project>/Spec/<Module>.lean holds only def spec_<…> (impl : RepoImpl) : Prop := …. Frozen; no markers. Spec bodies access APIs via impl.<repo_impl_field>.<fn>.

  • <Project>/Bundle.lean + <Project>/Harness.lean are shared across modules; translate emits them once per benchmark.

  • Test.lean carries #guard conformance tests against Bank.* directly (no Bank.Ref namespace — retired 2026-04-20).

See .claude/skills/vero-translate/SKILL.md for exact file templates.

Classification rules

For each top-level Dafny item, decide what Lean artifact it becomes.

Dafny itemLean artifactNotes
datatypeinductive in Impl (foundation file)No markers; fully defined.
type (alias)abbrev in Impl (foundation file)No markers.
type (opaque)opaque in ImplNo markers; axiomatize via axiom.
class / traitstructure in Impl + API abbrev <Fn>Sig per methodMethods → API reference implementations (code markers); class invariants often → spec_*.
methoddef Bank.<fn> : Bank.<Sig> := <translated reference impl> in Impl + one spec_* per ensuresensures clauses translate to specs, not inline theorems.
function (non-ghost)Same as method — API with sig + translated body + ensures → spec_*.
function (ghost, vocabulary)Full-body def in Impl or Spec helper — no markersVocabulary used by other specs (toSeq, isValid). Body given; not a benchmark task.
predicateProp-returning vocabulary def in Impl or Spec, no markers
lemma (states a property worth tracking)spec_* entry in plan.jsonLemmas become specs in the new paradigm.
lemma (proof helper only)Drop from plan — becomes proof_aux downstream—
method marked {:axiom}axiom <name> : <type> in ImplDocuments external guarantees.
Test (method Main or assert)#guard in Test.leanComputable values only.

Classify by role, not keyword. A function marked ghost in Dafny that gets used by other specs is vocabulary → Spec helper, no markers. A method that implements push is an API → code slot, markers.

Show full SKILL.md (310 more words)Show less

Type mapping

DafnyLean 4
intInt
natNat
boolBool
stringString
charChar
realFloat (prefer Rat if exact arithmetic matters)
seq<T>List T
seq<char>String (usually)
set<T>List T with uniqueness spec, or Finset T if Mathlib is in scope
multiset<T>List T (preserves multiplicity)
map<K,V>List (K × V) with uniqueness spec
array<T>Array T
T? (nullable)Option T
tuple (T, U)T × U
function T -> UT → U
datatype Foo = A | B(x: Int)inductive Foo where | A | B (x : Int)

Arrows in Lean are → (U+2192), not ->.

API translation pattern

Dafny:

dafny
method CreateAccount(id: int, ledger: Ledger) returns (r: Ledger)
    requires /* … */
    ensures /* post */
{ /* impl */ }

plan.json entry:

json
{
  "upstream_name": "CreateAccount",
  "lean_name": "createAccount",
  "sig_abbrev": "CreateAccountSig",
  "lean_type": "AccountId → Ledger → Ledger",
  "opaque": false,
  "nl_description": "Add a new account with the given id to the ledger."
}

Emitted Impl:

lean
namespace Bank
abbrev CreateAccountSig := AccountId → Ledger → Ledger
end Bank

-- !benchmark @start code_aux def=createAccount
-- !benchmark @end code_aux def=createAccount

-- !curation @review v1 [ ] createAccount — Impl/Account, code, reference impl
def Bank.createAccount : Bank.CreateAccountSig :=
-- !benchmark @start code def=createAccount
  -- translated Dafny body, not `sorry`
  ...
-- !benchmark @end code def=createAccount
Partial functions

When Dafny declares requires:

  • Total (condition always discharged by types): drop the requires; Lean type captures it.
  • Partial with caller-supplied witness: (h : <precond>) → <return>.
  • Partial expecting failure reporting: Option <return> or Except Err <return>.

Match the project's other partial APIs for consistency.

Spec translation pattern

ensures on an API

Each ensures clause becomes one spec_* entry:

dafny
method Deposit(id: int, amt: nat, l: Ledger) returns (r: Option<Ledger>)
    ensures r.Some? ==> Sum(r.value) == Sum(l) + amt

plan.json:

json
{
  "name": "spec_deposit_preserves_sum",
  "nl_description": "After a successful deposit, the total equals the previous total plus the amount.",
  "lean_form": "∀ (id : AccountId) (amt : Balance) (l : Ledger) (l' : Ledger), impl.bankLedger.deposit id amt l = some l' → impl.bankLedger.totalAssets l' = impl.bankLedger.totalAssets l + amt",
  "apis_referenced": ["deposit", "totalAssets"],
  "curator_intended_truth": "prove"
}

Emitted Spec:

lean
/-- After a successful deposit, the total equals the previous total plus the amount. -/
def spec_deposit_preserves_sum (impl : RepoImpl) : Prop :=
  ∀ (id : AccountId) (amt : Balance) (l : Ledger) (l' : Ledger),
    impl.bankLedger.deposit id amt l = some l' →
    impl.bankLedger.totalAssets l' = impl.bankLedger.totalAssets l + amt
Standalone lemma

A lemma whose statement encodes a property the benchmark should track:

dafny
lemma DepositCommutes(a b: Value, l: Ledger)
    ensures Deposit(a, Deposit(b, l).value) == Deposit(b, Deposit(a, l).value)

→ plan.json spec_deposit_commutes (same schema as above).

A pure proof helper (no new property): drop from the plan.

Class invariant pattern

dafny
class Ledger {
  var accounts: seq<Account>;
  predicate Valid() { NoDuplicateIds(accounts) }
  method Deposit(id, amt) requires Valid() ensures Valid() { … }
}
  1. Ledger struct in Impl foundation file (no markers).
  2. Valid is vocabulary — Spec helper def valid : Ledger → Prop if purely spec; foundation-file helper if also used in Impl code.
  3. Deposit → API reference implementation with code markers.
  4. requires Valid() + ensures Valid() → one spec_deposit_preserves_valid.

Common pitfalls (see vero-dafny-pitfalls)

  • Dafny's seq[i] is total with side-condition i < |seq|; Lean List.get? returns Option. Choose one consistently.
  • multiset semantics don't map cleanly — pick List with explicit multiplicity spec or document divergence.
  • assume clauses are red flags; surface as !curation @review in the emitted Impl.

Load vero-dafny-pitfalls before translating any non-trivial item.

Pair with

  • vero-plan — consumes Dafny classifications.
  • vero-translate — emits Lean per the templates.
  • vero-dafny-pitfalls — Dafny→Lean corner cases.
  • vero-lean-pitfalls — universal Lean traps.

© sunblaze-ucb, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/vero-source-dafny of sunblaze-ucb/vero.

Open the folder on GitHubat commit 0a7325d

Compare with similar skills

Vero Source Dafny next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Vero Source Dafny compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Vero Source Dafny this skillsunblaze-ucb/vero107—~2kAutomated safety check: NotesApache-2.0
Translation Diff ExportDevolutions/UniGetUI26k—~1.1kAutomated safety check: PassMIT
Sync Translationssymfony/symfony31k—~1.9kAutomated safety check: PassMIT
Translation Diff ImportDevolutions/UniGetUI26k—~750Automated safety check: PassMIT
Translation Diff TranslateDevolutions/UniGetUI26k—~934Automated safety check: PassMIT
Generate Translationspayloadcms/payload45k—~1.1kAutomated safety check: PassMIT

Similar skills

  • Translation Diff Export

    Devolutions/UniGetUI

    Compares UniGetUI JSON locale files against English, identifies untranslated or source-changed keys, and generates patch, reference, and handoff files for a target language.

    26k GitHub stars~1.1k tokensUpdated today
    Writing & ContentAuto-check passed
  • Sync Translations

    symfony/symfony

    Synchronize translation catalogs across maintained Symfony branches: find messages that newer branches added to the English catalogs but that are still missing from the oldest maintained branch…

    31k GitHub stars~1.9k tokensUpdated today
    Writing & ContentAuto-check passed
  • Translation Diff Import

    Devolutions/UniGetUI

    Merges translated key-value pairs from a UniGetUI JSON localization patch back into the full language file and validates the merged result.

    26k GitHub stars~750 tokensUpdated today
    Writing & ContentAuto-check passed
  • Translation Diff Translate

    Devolutions/UniGetUI

    Translates a sparse UniGetUI JSON language patch, writes completed entries into the working copy, preserves placeholders and terminology, and prepares the patch for merge-back.

    26k GitHub stars~934 tokensUpdated today
    Writing & ContentAuto-check passed
  • Generate Translations

    payloadcms/payload

    A skill your agent uses when new translation keys are added to packages to generate new translations strings

    45k GitHub stars~1.1k tokensUpdated today
    Writing & ContentAuto-check passed
  • Drives long-form fiction, scripts, storyboards, interactive films and long-document translation through InkOS, with every change made by a typed action.

    10k GitHub starsUsed in 1 repo~1.1k tokens
    Writing & ContentAuto-check passed

More from sunblaze-ucb/vero

All 16 skills in this repo
  • Vero Discover

    sunblaze-ucb/vero

    A skill your agent uses when scanning a verified source repo (Dafny, Verus, or Coq) to classify every item and produce per-file discovery markdown for human curation.

    107 GitHub stars~3.9k tokensUpdated 1 mo ago
    Auto-check: notes
  • Vero Translate

    sunblaze-ucb/vero

    A skill your agent uses when translating selected verified items from Dafny/Verus/Coq into a compilable Lean 4 benchmark.

    107 GitHub stars~4.9k tokensUpdated 1 mo ago
    Auto-check: notes
  • Vero Coq Pitfalls

    sunblaze-ucb/vero

    Load BEFORE translating any Coq item to Lean 4 to avoid known Coq→Lean pitfalls.

    107 GitHub stars~1.5k tokensUpdated 1 mo ago
    Auto-check: notes
  • Vero Dafny Pitfalls

    sunblaze-ucb/vero

    Load BEFORE translating any Dafny item to Lean 4 to avoid known Dafny→Lean pitfalls.

    107 GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check: notes
  • Vero Lean Pitfalls

    sunblaze-ucb/vero

    Load BEFORE writing any Lean 4 translation to avoid common Lean pitfalls (universes, coercions, type-class resolution, notation).

    107 GitHub stars~1.4k tokensUpdated 1 mo ago
    Auto-check: notes
  • Vero Plan

    sunblaze-ucb/vero

    Use after vero-select to write a detailed translation plan as .vero/plan.json — the authoritative contract the TRANSLATE stage executes.

    107 GitHub stars~3.6k tokensUpdated 1 mo ago
    Auto-check: notes

Questions about Vero Source Dafny

What does Vero Source Dafny do?

Load BEFORE translating Dafny source to Lean 4. An agent skill from sunblaze-ucb/vero. Vero Source Dafny is an agent skill from sunblaze-ucb/vero. Load BEFORE translating Dafny source to Lean 4.

When should I use Vero Source Dafny?

Vero Source Dafny fits situations like: tasks that involve Translation.

How do I install Vero Source Dafny in Claude Code?

Run `npx skills add sunblaze-ucb/vero --skill vero-source-dafny -a claude-code`. Or copy the skill folder (.claude/skills/vero-source-dafny in sunblaze-ucb/vero) into .claude/skills/vero-source-dafny in your project. Claude Code loads it when a task matches its description.

How do I install Vero Source Dafny in Codex?

Run `npx skills add sunblaze-ucb/vero --skill vero-source-dafny -a codex`. Or copy the skill folder (.claude/skills/vero-source-dafny in sunblaze-ucb/vero) into .agents/skills/vero-source-dafny in your project. Codex loads it when a task matches its description.

Can I use Vero Source Dafny in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sunblaze-ucb/vero --skill vero-source-dafny -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vero-source-dafny, .gemini/skills/vero-source-dafny, .github/skills/vero-source-dafny and .opencode/skills/vero-source-dafny in your project.

What does Vero Source Dafny need to run?

SKILL.md names no scripts, command-line tools or credentials: Vero Source Dafny is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Write, Edit, Bash, Grep, Glob.

Does Vero Source Dafny access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Vero Source Dafny safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Vero Source Dafny use?

Vero Source Dafny is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Vero Source Dafny use?

About 2k tokens (SKILL.md is roughly 8.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Vero Source Dafny?

Skills that share tags, products or a category with Vero Source Dafny: Translation Diff Export (Devolutions/UniGetUI, 26k stars), Sync Translations (symfony/symfony, 31k stars), Translation Diff Import (Devolutions/UniGetUI, 26k stars) and Translation Diff Translate (Devolutions/UniGetUI, 26k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Vero Source Dafny?

sunblaze-ucb (a GitHub organization) maintains it in sunblaze-ucb/vero, which has 107 GitHub stars. The repository holds 16 skills in this directory. The repository was last updated on August 17, 2026.

Source: sunblaze-ucb/vero on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.