Agent skill

Verify Source

by Totoro-jam in Totoro-jam/battle-tested-patterns

Verify all production proof source links in pattern documents.

MITAuto-check passedDevelopment

Install Verify Source

skills CLI
$ npx skills add Totoro-jam/battle-tested-patterns --skill verify-source -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Totoro-jam/battle-tested-patterns verify-source --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Totoro-jam/battle-tested-patterns.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/verify-source .claude/skills/verify-source && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
verify-source
GitHub stars
344
Token cost
~930 tokens
SKILL.md length
419 words
Files
1
Skills in repo
5
Repo updated
First seen
Licence
MIT

At a glance

Verify all production proof source links in pattern documents.

  • Works in 5 steps: Run automated link check → Convert branch links to SHA permalinks → Verify line-range content → …
  • Development work in your project
  • SKILL.md covers Steps and Rules
  • Calls pnpm, tsx and gh; needs GITHUB_TOKEN

What it does

Verify Source is an agent skill from Totoro-jam/battle-tested-patterns. Verify all production proof source links in pattern documents. Run automated checks for HTTP status, format, SHA permanence, and line-range content accuracy.

Its SKILL.md is about 930 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development. It works with GitHub. The repository describes itself as: Battle-tested programming patterns from production codebases — React, Linux, Go, Chromium, and more. Precise source links, multi-language examples, runnable exercises. The licence is MIT.

When your agent uses it

  • Development work in your project

Example prompts

  • “/verify-source”

Requirements

  • A credential in GITHUB_TOKEN

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Run automated link check
  2. Convert branch links to SHA permalinks
  3. Verify line-range content
  4. Manual verification (for warnings)
  5. Report

What it can do on your machine

Read from SKILL.md and the folder at commit 660e0e9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pnpm
    • tsx
    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pnpm and gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GITHUB_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Verify Source loads about 930 tokens when it runs. Until then it costs about 43 tokens; SKILL.md has 419 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~43
When it runs · the whole SKILL.md, loaded when a task matches
~930

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Totoro-jam/battle-tested-patterns at commit 660e0e9, republished under its MIT licence (© Totoro-jam). 419 words, ~930 tokens.

Download SKILL.mdSave it as .claude/skills/verify-source/SKILL.md (or your agent's skills folder).
name
verify-source
description
Verify all production proof source links in pattern documents. Run automated checks for HTTP status, format, SHA permanence, and line-range content accuracy.

You are verifying production proof links in this repository. This is the most critical quality check — every pattern's credibility depends on accurate, live source links.

Steps

bash
pnpm verify-links

This scans all docs/**/*.md and root README.md/README.zh-CN.md files, extracts GitHub URLs, and checks:

  • HTTP status (with automatic retry on 5xx)
  • Whether Production Proof links include line numbers (#L18-L22)
  • Whether links use SHA permalinks vs branch names
  • Whether any #L1 file-level links exist in Production Proof

Output categories:

  • ✅ [proof] — valid Production Proof link with line numbers
  • ✅ [other] — valid non-Production-Proof link
  • ⚠️ [proof] — Production Proof link missing line numbers
  • ℹ️ — branch-based link (not SHA permalink)
  • ❌ — broken link (HTTP error)

For CI mode (exit 1 on broken links): pnpm verify-links -- --ci

If the report shows branch-based links, convert them:

bash
tsx scripts/convert-to-sha-links.ts --dry-run    # preview changes
tsx scripts/convert-to-sha-links.ts               # execute conversion

Authentication: prefers gh auth token (system keyring), falls back to GITHUB_TOKEN env var.

3. Verify line-range content

For links that pass HTTP checks, verify that the referenced code lines actually match the pattern:

bash
pnpm verify-lines                    # Check all Production Proof links
pnpm verify-lines --pattern <name>   # Check a single pattern
pnpm verify-lines --verbose          # Show all results including passes
pnpm verify-lines --section all      # Also check "More Production Uses" section
pnpm verify-lines --no-cache         # Re-fetch everything (ignore cache)

This script performs two layers of verification:

  • L1: Range validity — checks that line numbers are within file bounds
  • L2: Keyword presence — checks that pattern-related keywords appear in the referenced code

Output:

  • ✅ — line range valid and keywords found
  • ⚠️ — line range valid but no keywords found (review manually)
  • ❌ FAIL — line range exceeds file length (must fix)
  • ❌ ERROR — fetch failed (network issue, retry)

Results are cached in tmp/line-range-cache.json (SHA links are immutable, so cache is permanent).

Show full SKILL.md (178 more words)Show less
4. Manual verification (for warnings)

For any ⚠️ warnings from verify-lines, manually confirm:

  • Open the GitHub link in a browser
  • Verify the code at the specified lines actually demonstrates the pattern
  • The usage description in the table is accurate

For ❌ FAIL results (line range out of bounds), the link must be fixed:

  1. Open the raw file at the SHA commit
  2. Find the correct line range for the relevant code
  3. Update the link in both EN and ZH pattern docs
  4. Also check README.md / README.zh-CN.md for the same link
5. Report

Output a summary:

  • ✅ Valid links (count)
  • ⚠️ Format issues or keyword warnings (list each)
  • ❌ Broken links (list each with file location)

For broken links, suggest the fix per .sop/06-broken-link-fix.md.

Rules

  • Never fabricate a replacement URL — if you can't find the new location, leave a <!-- TODO --> marker
  • Always verify with automated tools first (pnpm verify-links, pnpm verify-lines), then manually for warnings
  • When fixing line-range errors in pattern docs, also update README.md and README.zh-CN.md if they contain the same link
  • Check the actual code content, not just HTTP status

© Totoro-jam, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/verify-source of Totoro-jam/battle-tested-patterns.

Open the folder on GitHubat commit 660e0e9

Compare with similar skills

Verify Source next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Verify Source compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Verify Source this skillTotoro-jam/battle-tested-patterns344—~930Automated safety check: PassMIT
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Greplooponyx-dot-app/onyx32k4 repos~3.3kAutomated safety check: PassMIT
Check PRonyx-dot-app/onyx32k2 repos~2.3kAutomated safety check: PassMIT
Setup Matt Pocock Skillsbestofjs/bestofjs3.1k20 repos~1.7kAutomated safety check: PassMIT
Summarise Ecosystem Resultsastral-sh/ruff50k1 repos~2.2kAutomated safety check: PassMIT

Similar skills

  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Greploop

    onyx-dot-app/onyx

    Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.

    32k GitHub starsUsed in 4 repos~3.3k tokens
    DevelopmentAuto-check passed
  • Check PR

    onyx-dot-app/onyx

    Checks a GitHub, GitLab, or Perforce (p4) pull request (or merge request, or shelved changelist) for unresolved review comments, failing status checks, and incomplete PR descriptions.

    32k GitHub starsUsed in 2 repos~2.3k tokens
    DevelopmentAuto-check passed
  • Setup Matt Pocock Skills

    bestofjs/bestofjs

    Configure this repo for the engineering skills — set up its issue tracker, triage label vocabulary, and domain doc layout.

    3.1k GitHub starsUsed in 20 repos~1.7k tokens
    DevelopmentAuto-check passed
  • Official

    A skill your agent uses when a user says "summarise ecosystem results", "summarize this ty ecosystem report", "what changed in this ecosystem run?", or asks to summarise or summarize ty ecosystem…

    50k GitHub starsUsed in 1 repo~2.2k tokens
    DevelopmentAuto-check passed
  • Merges external GitHub pull requests while keeping the original author credited, and fixes conflicts after the merge instead of rewriting the contribution.

    16k GitHub starsUsed in 1 repo~847 tokens
    DevelopmentAuto-check passed

More from Totoro-jam/battle-tested-patterns

  • Adopt a Design Pattern

    Totoro-jam/battle-tested-patterns

    Matches a coding problem to one of 46 documented systems patterns, checks that it really fits, then adapts it into your codebase with a test for its invariant.

    344 GitHub stars~4.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Pattern Conformance Audit

    Totoro-jam/battle-tested-patterns

    Audits a codebase's existing patterns, such as rate limiters, circuit breakers and caches, against canonical invariants and flags mislabeled or divergent ones.

    344 GitHub stars~1.6k tokensUpdated 1 mo ago
    Auto-check passed
  • New Pattern Authoring Workflow

    Totoro-jam/battle-tested-patterns

    Step-by-step workflow for adding a new pattern to the battle-tested-patterns repo: validate the topic, verify sources, write the doc, code and exercises.

    344 GitHub stars~1.5k tokensUpdated 1 mo ago
    Auto-check passed
  • Failure Diagnosis Loop

    Totoro-jam/battle-tested-patterns

    Walks the agent through a fixed loop for failing tests and build errors: reproduce, isolate, hypothesize, instrument, fix, verify, then add a regression test.

    344 GitHub stars~319 tokensUpdated 1 mo ago
    Auto-check passed

Works with

Categories

Questions about Verify Source

What does Verify Source do?

Verify all production proof source links in pattern documents. Verify Source is an agent skill from Totoro-jam/battle-tested-patterns. Verify all production proof source links in pattern documents.

When should I use Verify Source?

Verify Source fits situations like: development work in your project.

How do I install Verify Source in Claude Code?

Run `npx skills add Totoro-jam/battle-tested-patterns --skill verify-source -a claude-code`. Or copy the skill folder (.claude/skills/verify-source in Totoro-jam/battle-tested-patterns) into .claude/skills/verify-source in your project. Claude Code loads it when a task matches its description.

How do I install Verify Source in Codex?

Run `npx skills add Totoro-jam/battle-tested-patterns --skill verify-source -a codex`. Or copy the skill folder (.claude/skills/verify-source in Totoro-jam/battle-tested-patterns) into .agents/skills/verify-source in your project. Codex loads it when a task matches its description.

Can I use Verify Source in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Totoro-jam/battle-tested-patterns --skill verify-source -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/verify-source, .gemini/skills/verify-source, .github/skills/verify-source and .opencode/skills/verify-source in your project.

What does Verify Source need to run?

Going by SKILL.md and its folder, Verify Source needs the command-line tools its instructions call (pnpm, tsx and gh) and credentials named GITHUB_TOKEN. Our summary lists: A credential in GITHUB_TOKEN.

Does Verify Source access the network?

SKILL.md contains no URLs. Its commands use gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Verify Source safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Verify Source use?

Verify Source is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Verify Source use?

About 930 tokens (SKILL.md is roughly 3.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Verify Source?

Skills that share tags, products or a category with Verify Source: PR Babysitter (openinterpreter/openinterpreter, 69k stars), Greploop (onyx-dot-app/onyx, 32k stars), Check PR (onyx-dot-app/onyx, 32k stars) and Setup Matt Pocock Skills (bestofjs/bestofjs, 3.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Verify Source?

Totoro-jam (a GitHub user) maintains it in Totoro-jam/battle-tested-patterns, which has 344 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on September 4, 2026.

Source: Totoro-jam/battle-tested-patterns on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.