Perplexity Web Search
davila7/claude-code-templates
Runs web-grounded searches through Perplexity's Sonar models over OpenRouter for current events, recent literature and cited facts beyond the model's training cutoff.
Fact-check LLM-drafted technical content against primary sources — source hierarchy, programmatic existence probes for tool and plugin names, class-before-instance error triage, the…
$ npx skills add trilwu/secskills --skill verifying-skill-accuracy -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install trilwu/secskills verifying-skill-accuracy --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/verifying-skill-accuracy .claude/skills/verifying-skill-accuracy && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "verifying-skill-accuracy" agent skill from https://github.com/trilwu/secskills/tree/main/.claude/skills/verifying-skill-accuracy into .claude/skills/verifying-skill-accuracy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "verifying-skill-accuracy", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/trilwu/secskills/tree/main/.claude/skills/verifying-skill-accuracyType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add trilwu/secskills --skill verifying-skill-accuracy -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install trilwu/secskills verifying-skill-accuracy --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/verifying-skill-accuracy .agents/skills/verifying-skill-accuracy && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "verifying-skill-accuracy" agent skill from https://github.com/trilwu/secskills/tree/main/.claude/skills/verifying-skill-accuracy into .agents/skills/verifying-skill-accuracy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "verifying-skill-accuracy", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trilwu/secskills --skill verifying-skill-accuracy -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install trilwu/secskills verifying-skill-accuracy --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/verifying-skill-accuracy .cursor/skills/verifying-skill-accuracy && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "verifying-skill-accuracy" agent skill from https://github.com/trilwu/secskills/tree/main/.claude/skills/verifying-skill-accuracy into .cursor/skills/verifying-skill-accuracy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "verifying-skill-accuracy", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/trilwu/secskills.git --path .claude/skills/verifying-skill-accuracy--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add trilwu/secskills --skill verifying-skill-accuracy -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install trilwu/secskills verifying-skill-accuracy --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/verifying-skill-accuracy .gemini/skills/verifying-skill-accuracy && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "verifying-skill-accuracy" agent skill from https://github.com/trilwu/secskills/tree/main/.claude/skills/verifying-skill-accuracy into .gemini/skills/verifying-skill-accuracy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "verifying-skill-accuracy", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install trilwu/secskills verifying-skill-accuracyInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add trilwu/secskills --skill verifying-skill-accuracy -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/verifying-skill-accuracy .github/skills/verifying-skill-accuracy && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "verifying-skill-accuracy" agent skill from https://github.com/trilwu/secskills/tree/main/.claude/skills/verifying-skill-accuracy into .github/skills/verifying-skill-accuracy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "verifying-skill-accuracy", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trilwu/secskills --skill verifying-skill-accuracy -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install trilwu/secskills verifying-skill-accuracy --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/verifying-skill-accuracy .opencode/skills/verifying-skill-accuracy && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "verifying-skill-accuracy" agent skill from https://github.com/trilwu/secskills/tree/main/.claude/skills/verifying-skill-accuracy into .opencode/skills/verifying-skill-accuracy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "verifying-skill-accuracy", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
verifying-skill-accuracyFact-check LLM-drafted technical content against primary sources — source hierarchy, programmatic existence probes for tool and plugin names, class-before-instance error triage, the…
Verifying Skill Accuracy is an agent skill from trilwu/secskills. Fact-check LLM-drafted technical content against primary sources — source hierarchy, programmatic existence probes for tool and plugin names, class-before-instance error triage, the truncated-negative trap, adversarial re-checking, and the verified-stamp discipline. Use when auditing a SKILL.md for factual errors, before stamping a skill verified, when a command or artifact claim needs confirming against upstream documentation, or when reviewing any drafted content whose specifics were written from model memory.
Its SKILL.md is about 4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Research & Science, covering Fact-checking and source verification. The repository describes itself as: Transform Claude Code into your personal security engineer. The licence is MIT.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit ca53957. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
curlpython3From the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
defuddle.mdvolatility3.readthedocs.ioFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Verifying Skill Accuracy loads about 4k tokens when it runs. Until then it costs about 136 tokens; SKILL.md has 2,178 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from trilwu/secskills at commit ca53957, republished under its MIT licence (© trilwu). 2,178 words, ~3,981 tokens.
.claude/skills/verifying-skill-accuracy/SKILL.md (or your agent's skills folder).Skills in this repo are drafted with LLM assistance. The methodology in them is usually sound; the specifics are not trustworthy until checked. The measured rate from the first verification pass was 31 factual errors across 11 of 12 skills — about 2.6 per skill, with a single skill clean on both passes. Assume that rate applies to anything unstamped.
This skill is the procedure for driving that rate down, and for knowing when you are allowed to say a skill has been verified.
verified: frontmatter stampauthoring-security-skills, then
verify with this skill as the final gatepython3 scripts/validate.py --strict, which checks form onlyThe repo's CI is a closed loop. validate.py, sync_attack.py, and
run_evals.py check frontmatter shape, cross-reference integrity, ATT&CK-index
consistency, and routing against self-authored eval cases. Every one of
those can pass on a skill whose commands do not exist.
Green CI means the skill is well-formed. It says nothing about whether it is true. Never cite a passing test run as evidence of accuracy.
Once you identify an error class, check it everywhere before moving on — not just in the skill that surfaced it. Errors of a class cluster, and a per-skill pass leaves the collection internally inconsistent.
Two cases from this repo make the point. The legacy Sigma date format was
fixed in writing-sigma-rules, then turned up again in
engineering-detections — in a skill that had already been stamped, because
the per-skill inventory did not include a class fixed elsewhere. And
attacking-entra-id was still calling retired AzureAD PowerShell cmdlets
while investigating-m365-entra already used the modern Graph equivalents:
the collection contradicted itself, and only a cross-cutting grep showed it.
So: fix the instance, then immediately grep every skill for the pattern, and say in the commit which classes you swept. Classes worth sweeping in a security collection — tool renames and archived projects, CVE IDs, cloud metadata endpoints, removed API versions, default ports, spec version claims, and any behaviour gated on a platform version.
Do not start by checking facts one at a time. First ask: is there a single systematic claim whose failure invalidates everything below it?
In analyzing-memory-images, the skill invoked Volatility as volatility3.
The real entry point is vol. That one error made all 40 commands in the
file uncopyable — far more damage than the two nonexistent plugins found
afterwards, and fixable with one substitution.
Check in this order:
A class error is cheap to fix and expensive to miss. An instance error is the reverse.
Use the highest tier available, and record which tier you used.
| Tier | Source | Use for |
|---|---|---|
| 1 | Official docs for the specific version, upstream source, RFCs, the vendor's own reference | Command syntax, plugin names, API shapes, protocol details |
| 2 | Vendor KB, release notes, changelogs, official blog announcing a change | Defaults, retention windows, licence gates, deprecations |
| 3 | Maintainer-authored write-ups, conference material by the tool author | Intent, gotchas, why a thing behaves as it does |
| 4 | Community posts, tutorials, Stack Overflow | Leads to verify at tier 1 — never as the citation |
| — | Model memory | Nothing. Not one claim. |
Two rules on top of the table:
latest or stable doc branches, and note when the skill targets an older
pinned release.Each of these has produced a real error in this repo:
Pull documentation through defuddle.md, which strips a page to its main
content and returns Markdown with YAML frontmatter. Prefix any URL:
curl -sL "https://defuddle.md/learn.microsoft.com/en-us/purview/audit-log-retention-policies"The scheme is optional in the path — defuddle.md/example.com/x and
defuddle.md/https://example.com/x both work.
Two reasons, and the second matters more than the first:
grep, instead of a model's summary of the page. That is
what makes it safe to draw a negative conclusion — see below.Use it for documentation, specs, vendor KB, and articles. Do not use it for:
A blocked fetch is not a negative result. Some hosts refuse the extractor
and return an error blob instead of the page — freedesktop.org answers with
{"error":"Failed to fetch: 418 I'm a teapot"}. Treat that as "I did not read
the page", never as "the page does not say this". It is the truncated-negative
trap wearing a different hat, and the fix is the same: re-fetch directly before
concluding anything.
Where a project publishes one doc page per module, existence is a status code, not a judgment call. This is the highest-confidence, lowest-effort check available, and it batches.
# One plugin: 200 = exists, 404 = does not
curl -s -o /dev/null -w "%{http_code}\n" \
"https://volatility3.readthedocs.io/en/latest/volatility3.plugins.windows.idt.html"
# Every plugin the skill references, in one pass
plugins=$(grep -oE '\b(windows|linux|mac)\.[a-z_]+' SKILL.md | sort -u)
for p in $plugins; do
code=$(curl -s -o /dev/null -w "%{http_code}" \
"https://volatility3.readthedocs.io/en/latest/volatility3.plugins.$p.html")
[ "$code" = "200" ] || echo "MISSING $code $p"
doneThat pass settled 32 plugin references in seconds and found the two that do not exist. Adapt the URL pattern per project — most doc generators (Sphinx, mkdocs, pkg.go.dev, docs.rs, npm, PyPI) expose a per-symbol or per-package URL you can probe the same way.
When a project has no per-symbol docs, fall back to an exact-string search of
the upstream source — a raw file fetch and a grep for the literal
identifier. Both of these are deterministic. Prefer them over asking any model,
including yourself.
A summarizer saying "not found" is not evidence of absence.
Fetching a large index page and asking what it contains returned "pslist, pstree, psaux, sockstat: not listed" for the Volatility Linux plugin index. All four exist. The page had been truncated before the model saw those entries. Acting on that output would have introduced four errors into a correct section — verification making the file worse.
The asymmetry that matters:
So: never delete or rewrite content on a summarized negative. Promote every negative to a deterministic check before you touch the file.
The cheapest promotion is to stop summarizing. Fetch the page through
defuddle.md and grep the full Markdown yourself — the answer becomes a match
count rather than a model's recollection:
L="volatility3.readthedocs.io/en/latest/volatility3.plugins.linux.html"
for p in pslist pstree psaux sockstat; do
echo "$p: $(curl -sL "https://defuddle.md/$L" | grep -c "linux\.$p module")"
done
# pslist: 1 pstree: 1 psaux: 1 sockstat: 1 -- all four presentThat is the exact check that refutes the summarizer's "not listed" on all four. Where a per-symbol URL exists, the status probe below is stronger still. If you can get neither, leave the content alone and flag it unconfirmed — an unverified line is recoverable, a confidently deleted correct one is not.
Not all errors cost the same. Spend effort where failure is silent.
| Failure mode | Example | Cost |
|---|---|---|
| Loud — fails on first run | Wrong CLI flag, nonexistent plugin | Minutes. The tool tells you. |
| Silent — produces a confident wrong answer | Misread event ID, wrong retention window, wrong artifact meaning | An incident timeline that lawyers read. |
Verify silent-failure claims first and hardest. In practice that means the defensive and forensic content — event IDs, log schemas, artifact semantics, retention — outranks offensive tool syntax, even though the offensive content looks more dangerous.
A concrete case: the M365 skill claimed 90 days of Unified Audit Log for E3. The real default has been 180 days since October 2023. An analyst trusting the skill reads an empty 90-day window as "no activity" and closes an investigation that had six months of history available.
defuddle.md so you are reading full text cheaply rather than
a summary.verified: Stampverified: 2026-07-26 # ISO 8601; validate.py parses and counts thisThe stamp means: the whole checkable surface of this skill was driven to a primary source on that date. It does not mean the skill is good, current forever, or complete.
Rules:
validate.py treats a missing stamp as an
unverified draft, which is the documented default. A malformed date is an
error because it corrupts the count.Check the current position any time:
python3 scripts/validate.py --strict # prints "Fact-checked ...: N/72"authoring-security-skills — writing a new skill; verify with this skill
before stampingCONTRIBUTING.md — the merge bar and house stylescripts/validate.py — structural checks and the verified-count report© trilwu, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/verifying-skill-accuracy of trilwu/secskills.
Open the folder on GitHubat commit ca53957
Verifying Skill Accuracy next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Verifying Skill Accuracy this skilltrilwu/secskills | 157 | — | ~4k | Automated safety check: Pass | MIT | |
| Perplexity Web Searchdavila7/claude-code-templates | 32k | 11 repos | ~3.5k | Automated safety check: Notes | MIT | |
| Citation Verification GuideGalaxy-Dawn/claude-scholar | 5.7k | 2 repos | ~1.9k | Automated safety check: Pass | MIT | |
| Article Fact Checkerdigoal/blog | 8.6k | — | ~939 | Automated safety check: Pass | GPL-2.0 | |
| Deep Research Agent TeamImbad0202/academic-research-skills | 51k | — | ~13k | Automated safety check: Pass | Custom licence | |
| Docs Grounding Verifiermicrosoft/apm | 4k | — | ~1.9k | Automated safety check: Pass | MIT |
davila7/claude-code-templates
Runs web-grounded searches through Perplexity's Sonar models over OpenRouter for current events, recent literature and cited facts beyond the model's training cutoff.
Galaxy-Dawn/claude-scholar
Reference guidance for checking every citation in academic writing against canonical sources such as DOI, arXiv, CrossRef and Semantic Scholar, to catch fake or wrong references.
digoal/blog
三层审查模型,逐段逐句验证文章真伪、证据链与逻辑结构。Use when the user asks to fact-check, verify, audit, or evaluate the credibility of an article, essay, report, opinion piece, social-media post, or any written claim —…
Imbad0202/academic-research-skills
Runs a 13-agent pipeline for rigorous academic research, from forming the question through systematic search, synthesis, bias checks and an APA 7.0 report.
microsoft/apm
A skill your agent uses to verify CLAIM-LEVEL grounding of a documentation page (or set of pages) against the source code.
bradygaster/squad
Review and validate claims using counter-hypothesis testing.
trilwu/secskills
Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.
trilwu/secskills
Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.
trilwu/secskills
Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…
trilwu/secskills
Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.
trilwu/secskills
Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…
trilwu/secskills
Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…
Categories
Fact-check LLM-drafted technical content against primary sources — source hierarchy, programmatic existence probes for tool and plugin names, class-before-instance error triage, the…. Verifying Skill Accuracy is an agent skill from trilwu/secskills. Fact-check LLM-drafted technical content against primary sources — source hierarchy, programmatic existence probes for tool and plugin names, class-before-instance error triage, the truncated-negative trap, adversarial re-checking, and the verified-stamp discipline.
Verifying Skill Accuracy fits situations like: auditing a SKILL.md for factual errors; before stamping a skill verified; artifact claim needs confirming against upstream documentation; reviewing any drafted content whose specifics were written from model memory.
Run `npx skills add trilwu/secskills --skill verifying-skill-accuracy -a claude-code`. Or copy the skill folder (.claude/skills/verifying-skill-accuracy in trilwu/secskills) into .claude/skills/verifying-skill-accuracy in your project. Claude Code loads it when a task matches its description.
Run `npx skills add trilwu/secskills --skill verifying-skill-accuracy -a codex`. Or copy the skill folder (.claude/skills/verifying-skill-accuracy in trilwu/secskills) into .agents/skills/verifying-skill-accuracy in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trilwu/secskills --skill verifying-skill-accuracy -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/verifying-skill-accuracy, .gemini/skills/verifying-skill-accuracy, .github/skills/verifying-skill-accuracy and .opencode/skills/verifying-skill-accuracy in your project.
Going by SKILL.md and its folder, Verifying Skill Accuracy needs the command-line tools its instructions call (curl and python3). Our summary lists: Python 3.
SKILL.md names 2 domains. In commands or code: defuddle.md and volatility3.readthedocs.io; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Verifying Skill Accuracy is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Verifying Skill Accuracy: Perplexity Web Search (davila7/claude-code-templates, 32k stars), Citation Verification Guide (Galaxy-Dawn/claude-scholar, 5.7k stars), Article Fact Checker (digoal/blog, 8.6k stars) and Deep Research Agent Team (Imbad0202/academic-research-skills, 51k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
trilwu (a GitHub user) maintains it in trilwu/secskills, which has 157 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on September 4, 2026.
Source: trilwu/secskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.