Agent skill

Validate Headers

by TotalCross in TotalCross/totalcross

Validate or fix LGPL-2.1-only headers, apply approved copyright provenance, and prepare provenance audits for renamed, split, copied, or extracted first-party code.

LGPL-2.1Auto-check passedDevelopment

Install Validate Headers

skills CLI
$ npx skills add TotalCross/totalcross --skill validate-headers -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install TotalCross/totalcross validate-headers --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/TotalCross/totalcross.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/validate-headers .claude/skills/validate-headers && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
validate-headers
GitHub stars
227
Token cost
~1.1k tokens
SKILL.md length
451 words
Files
1
Skills in repo
2
Repo updated
First seen
Licence
LGPL-2.1

At a glance

Validate or fix LGPL-2.1-only headers, apply approved copyright provenance, and prepare provenance audits for renamed, split, copied, or extracted first-party code.

  • Works in 6 steps: Identify the intended scope → Validate the smallest useful file set → Fix ordinary or provenance-backed headers → …
  • Tasks that involve Embedded systems
  • SKILL.md covers 1. Identify the intended scope, 2. Validate the smallest…, 3. Fix ordinary or… and 4. Audit substantial code…, plus 2 more sections
  • Calls python3 and git

What it does

Validate Headers is an agent skill from TotalCross/totalcross. Validate or fix LGPL-2.1-only headers, apply approved copyright provenance, and prepare provenance audits for renamed, split, copied, or extracted first-party code.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Embedded systems. It works with Java and Linux. The repository describes itself as: TotalCross is a Software Development Kit that helps cross platform application development. Currently supported platforms are: Windows, Wince, Android, iOS, Linux and Linux ARM…

When your agent uses it

  • Tasks that involve Embedded systems

Example prompts

  • “/validate-headers”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Identify the intended scope
  2. Validate the smallest useful file set
  3. Fix ordinary or provenance-backed headers
  4. Audit substantial code movement
  5. Approve or reject an audit
  6. Report results efficiently

What it can do on your machine

Read from SKILL.md and the folder at commit 34cc7ee. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Validate Headers loads about 1.1k tokens when it runs. Until then it costs about 45 tokens; SKILL.md has 451 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~45
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from TotalCross/totalcross at commit 34cc7ee, republished under its LGPL-2.1 licence (© TotalCross). 451 words, ~1,074 tokens.

Download SKILL.mdSave it as .claude/skills/validate-headers/SKILL.md (or your agent's skills folder).
name
validate-headers
description
Validate or fix LGPL-2.1-only headers, apply approved copyright provenance, and prepare provenance audits for renamed, split, copied, or extracted first-party code.

Use the repository tools from the repository root. The validator is the source of truth; do not derive a header from the current pathname when an approved active provenance audit applies.

1. Identify the intended scope

Avoid dumping a noisy worktree. Prefer:

sh
git diff --name-only --diff-filter=ACMR --cached -- <task paths>

When nothing is staged:

sh
git diff --name-only --diff-filter=ACMR -- <task paths>

Do not add repository headers to upstream, vendored, generated, or exempt files merely to make validation pass. Respect the exclusions implemented by scripts/validate-copyright-headers.sh and documented in AGENTS.md. Generated evidence under legal/copyright-provenance/audits/ is intentionally excluded from ordinary header validation.

2. Validate the smallest useful file set

For explicit files:

sh
python3 scripts/validate-copyright-headers.sh --files <changed files>

For staged changes, omit --files; when nothing is staged, the validator uses the working-tree diff:

sh
python3 scripts/validate-copyright-headers.sh

The validator also accepts:

sh
python3 scripts/validate-copyright-headers.sh --commit <commit>
python3 scripts/validate-copyright-headers.sh <base> <head>

Approved manifests listed in legal/copyright-provenance/active-audits.json take precedence over Git pathname creation dates. For covered files, the validator checks the code fingerprint and historical source before validating the inherited header. Treat a stale-audit error as a request for a new audit; never bypass it with a current-year-only header.

3. Fix ordinary or provenance-backed headers

Use the validator instead of manually reconstructing ranges:

sh
python3 scripts/validate-copyright-headers.sh \
  --fix --files <changed files>

New first-party files normally use the current-year Amalgam header. Existing files preserve the applicable SuperWaba, TotalCross, and Amalgam ranges. Provenance-backed files inherit the chain from the approved audit.

After fixing, rerun the focused validation and:

sh
git diff --check -- <task paths>

4. Audit substantial code movement

Create an audit when a refactor renames, splits, merges, copies, or extracts substantial code and the destination pathname no longer represents the source history:

sh
python3 legal/copyright-provenance/audit-code-provenance.py \
  <initial-commit> <final-commit> [source-path]

Omit source-path for automatic source discovery. Review summary.md and the per-source reports. Confirm that final targets are real descendants, unrelated generic code is absent, and intermediate deleted paths appear only as lineage evidence.

Do not edit generated evidence or reports to alter the conclusion. Correct the audit tool and run a new audit when the result is wrong.

Show full SKILL.md (150 more words)Show less

5. Approve or reject an audit

Audit review is a maintainer operation:

sh
python3 legal/copyright-provenance/review-audit.py <audit-id>

The command asks whether to approve, reject, or cancel. Approval can optionally append the manifest to active-audits.json without removing existing entries. When activated, it verifies the audit tool hash and covered code fingerprints, fixes the covered headers, runs validation, stages only the audit-related changes, and creates one signed atomic commit.

Because the review command can stage and commit, do not run it unless the user explicitly requested the review and authorized the resulting commit. Do not manually mark a manifest approved or edit active-audits.json as a substitute for this workflow.

6. Report results efficiently

Report:

  • files checked or fixed;
  • whether active provenance was applied;
  • validation pass or failure;
  • stale audits or manual-review findings;
  • the commit created by review-audit.py, when explicitly authorized.

Do not paste full generated reports or broad validator output. Show only the relevant errors and paths.

© TotalCross, LGPL-2.1. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/validate-headers of TotalCross/totalcross.

Open the folder on GitHubat commit 34cc7ee

Compare with similar skills

Validate Headers next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Validate Headers compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Validate Headers this skillTotalCross/totalcross227—~1.1kAutomated safety check: PassLGPL-2.1
Simulink Configure Real Time Targetmatlab/simulink-agentic-toolkit1.2k—~4.8kAutomated safety check: NotesCustom licence
Flash IdfLeoKemp223/embed-ai-tool984—~581Automated safety check: NotesNone
Docker Jfr Benchmark Loopeclipse-rdf4j/rdf4j420—~945Automated safety check: PassBSD-3-Clause
Rsid SDKrealsenseai/RealSenseID122—~4.1kAutomated safety check: PassApache-2.0
Intelliconnect Service Styleruanrongman/IntelliConnect147—~2.4kAutomated safety check: PassApache-2.0

Similar skills

  • Simulink Configure Real Time Target

    matlab/simulink-agentic-toolkit

    Manage Simulink Real-Time target computers from MATLAB — list available targets, check whether a target is connected, read its lifecycle status, add/remove/rename targets, set IP addresses and…

    1.2k GitHub stars~4.8k tokensUpdated today
    DevelopmentAuto-check: notes
  • Flash Idf

    LeoKemp223/embed-ai-tool

    当需要通过 ESP-IDF 工具链烧录固件到 ESP32 系列芯片,或启动调试会话时使用. An agent skill from LeoKemp223/embed-ai-tool.

    984 GitHub stars~581 tokensUpdated 1 mo ago
    DevelopmentAuto-check: notes
  • Docker Jfr Benchmark Loop

    eclipse-rdf4j/rdf4j

    Run a repeatable RDF4J performance loop against one JMH benchmark in Docker with Linux Java 26 and JFR CPU-time profiling.

    420 GitHub stars~945 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Rsid SDK

    realsenseai/RealSenseID

    RealSenseID face authentication SDK reference. An agent skill from realsenseai/RealSenseID.

    122 GitHub stars~4.1k tokensUpdated today
    Backend & APIsAuto-check passed
  • Intelliconnect Service Style

    ruanrongman/IntelliConnect

    Create or update IntelliConnect Spring Boot service/serviceimpl code in this repository style.

    147 GitHub stars~2.4k tokensUpdated today
    Backend & APIsAuto-check passed
  • Swing UI Test Headless Guard

    lakernote/easy-postman

    A skill your agent uses when adding or updating EasyPostman Swing/TestNG UI tests that may run in headless CI or no-display Linux environments.

    721 GitHub stars~275 tokensUpdated today
    Testing & QAAuto-check passed

More from TotalCross/totalcross

  • Logical Commits

    TotalCross/totalcross

    Create focused Git commits that follow this repository's validated commit-message format, with required scopes, focused validation, and preservation of unrelated local changes; invoke only when the…

    227 GitHub stars~1.3k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Validate Headers

What does Validate Headers do?

Validate or fix LGPL-2.1-only headers, apply approved copyright provenance, and prepare provenance audits for renamed, split, copied, or extracted first-party code. Validate Headers is an agent skill from TotalCross/totalcross.1-only headers, apply approved copyright provenance, and prepare provenance audits for renamed, split, copied, or extracted first-party code.

When should I use Validate Headers?

Validate Headers fits situations like: tasks that involve Embedded systems.

How do I install Validate Headers in Claude Code?

Run `npx skills add TotalCross/totalcross --skill validate-headers -a claude-code`. Or copy the skill folder (.agents/skills/validate-headers in TotalCross/totalcross) into .claude/skills/validate-headers in your project. Claude Code loads it when a task matches its description.

How do I install Validate Headers in Codex?

Run `npx skills add TotalCross/totalcross --skill validate-headers -a codex`. Or copy the skill folder (.agents/skills/validate-headers in TotalCross/totalcross) into .agents/skills/validate-headers in your project. Codex loads it when a task matches its description.

Can I use Validate Headers in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add TotalCross/totalcross --skill validate-headers -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/validate-headers, .gemini/skills/validate-headers, .github/skills/validate-headers and .opencode/skills/validate-headers in your project.

What does Validate Headers need to run?

Going by SKILL.md and its folder, Validate Headers needs the command-line tools its instructions call (python3 and git). Our summary lists: Python 3.

Does Validate Headers access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Validate Headers safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Validate Headers use?

Validate Headers is published under the LGPL-2.1 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Validate Headers use?

About 1.1k tokens (SKILL.md is roughly 4.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Validate Headers?

Skills that share tags, products or a category with Validate Headers: Simulink Configure Real Time Target (matlab/simulink-agentic-toolkit, 1.2k stars), Flash Idf (LeoKemp223/embed-ai-tool, 984 stars), Docker Jfr Benchmark Loop (eclipse-rdf4j/rdf4j, 420 stars) and Rsid SDK (realsenseai/RealSenseID, 122 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Validate Headers?

TotalCross (a GitHub organization) maintains it in TotalCross/totalcross, which has 227 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on October 8, 2026.

Source: TotalCross/totalcross on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.