Agent skill

Verifying Skill Accuracy

by trilwu in trilwu/secskills

Fact-check LLM-drafted technical content against primary sources — source hierarchy, programmatic existence probes for tool and plugin names, class-before-instance error triage, the…

MITAuto-check passedResearch & Science

Install Verifying Skill Accuracy

skills CLI
$ npx skills add trilwu/secskills --skill verifying-skill-accuracy -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trilwu/secskills verifying-skill-accuracy --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/verifying-skill-accuracy .claude/skills/verifying-skill-accuracy && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
verifying-skill-accuracy
GitHub stars
157
Token cost
~4k tokens
SKILL.md length
2,178 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

Fact-check LLM-drafted technical content against primary sources — source hierarchy, programmatic existence probes for tool and plugin names, class-before-instance error triage, the…

  • Works in 4 steps: Tool identity — the binary/entry-point… → Naming scheme — how the tool names its… → Path and file conventions — where… → …
  • Auditing a SKILL.md for factual errors
  • SKILL.md covers When to Use, When NOT to Use, The Core Distinction: Form vs… and Sweep by Class Across the…, plus 11 more sections
  • Calls curl and python3; reaches defuddle.md and volatility3.readthedocs.io

What it does

Verifying Skill Accuracy is an agent skill from trilwu/secskills. Fact-check LLM-drafted technical content against primary sources — source hierarchy, programmatic existence probes for tool and plugin names, class-before-instance error triage, the truncated-negative trap, adversarial re-checking, and the verified-stamp discipline. Use when auditing a SKILL.md for factual errors, before stamping a skill verified, when a command or artifact claim needs confirming against upstream documentation, or when reviewing any drafted content whose specifics were written from model memory.

Its SKILL.md is about 4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Research & Science, covering Fact-checking and source verification. The repository describes itself as: Transform Claude Code into your personal security engineer. The licence is MIT.

When your agent uses it

  • Auditing a SKILL.md for factual errors
  • Before stamping a skill verified
  • Artifact claim needs confirming against upstream documentation
  • Reviewing any drafted content whose specifics were written from model memory

Example prompts

  • “/verifying-skill-accuracy”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Tool identity — the binary/entry-point name, and the major version the
  2. Naming scheme — how the tool names its plugins, modules, or subcommands.
  3. Path and file conventions — where artifacts actually live on the version
  4. Individual claims — only now, one by one.

What it can do on your machine

Read from SKILL.md and the folder at commit ca53957. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • defuddle.md
    • volatility3.readthedocs.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Verifying Skill Accuracy loads about 4k tokens when it runs. Until then it costs about 136 tokens; SKILL.md has 2,178 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~136
When it runs · the whole SKILL.md, loaded when a task matches
~4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from trilwu/secskills at commit ca53957, republished under its MIT licence (© trilwu). 2,178 words, ~3,981 tokens.

Download SKILL.mdSave it as .claude/skills/verifying-skill-accuracy/SKILL.md (or your agent's skills folder).
name
verifying-skill-accuracy
description
Fact-check LLM-drafted technical content against primary sources — source hierarchy, programmatic existence probes for tool and plugin names, class-before-instance error triage, the truncated-negative trap, adversarial re-checking, and the verified-stamp discipline. Use when auditing a SKILL.md for factual errors, before stamping a skill verified, when a command or artifact claim needs confirming against upstream documentation, or when reviewing any drafted content whose specifics were written from model memory.

Verifying Skill Accuracy

Skills in this repo are drafted with LLM assistance. The methodology in them is usually sound; the specifics are not trustworthy until checked. The measured rate from the first verification pass was 31 factual errors across 11 of 12 skills — about 2.6 per skill, with a single skill clean on both passes. Assume that rate applies to anything unstamped.

This skill is the procedure for driving that rate down, and for knowing when you are allowed to say a skill has been verified.

When to Use

  • Auditing an existing SKILL.md against primary sources
  • Before adding or renewing a verified: frontmatter stamp
  • After drafting new skill content, on the specifics you just wrote
  • When a reader reports that a command, ID, or field name does not work
  • Reviewing any technical content where the author was a model

When NOT to Use

  • Writing a new skill from scratch — use authoring-security-skills, then verify with this skill as the final gate
  • Structural or style problems (frontmatter, sections, line count) — that is python3 scripts/validate.py --strict, which checks form only
  • Deciding whether a technique is a good idea — that is judgment, not fact

The Core Distinction: Form vs Truth

The repo's CI is a closed loop. validate.py, sync_attack.py, and run_evals.py check frontmatter shape, cross-reference integrity, ATT&CK-index consistency, and routing against self-authored eval cases. Every one of those can pass on a skill whose commands do not exist.

Green CI means the skill is well-formed. It says nothing about whether it is true. Never cite a passing test run as evidence of accuracy.

Sweep by Class Across the Whole Collection

Once you identify an error class, check it everywhere before moving on — not just in the skill that surfaced it. Errors of a class cluster, and a per-skill pass leaves the collection internally inconsistent.

Two cases from this repo make the point. The legacy Sigma date format was fixed in writing-sigma-rules, then turned up again in engineering-detections — in a skill that had already been stamped, because the per-skill inventory did not include a class fixed elsewhere. And attacking-entra-id was still calling retired AzureAD PowerShell cmdlets while investigating-m365-entra already used the modern Graph equivalents: the collection contradicted itself, and only a cross-cutting grep showed it.

So: fix the instance, then immediately grep every skill for the pattern, and say in the commit which classes you swept. Classes worth sweeping in a security collection — tool renames and archived projects, CVE IDs, cloud metadata endpoints, removed API versions, default ports, spec version claims, and any behaviour gated on a platform version.

Triage: Class Errors Before Instance Errors

Do not start by checking facts one at a time. First ask: is there a single systematic claim whose failure invalidates everything below it?

In analyzing-memory-images, the skill invoked Volatility as volatility3. The real entry point is vol. That one error made all 40 commands in the file uncopyable — far more damage than the two nonexistent plugins found afterwards, and fixable with one substitution.

Check in this order:

  1. Tool identity — the binary/entry-point name, and the major version the syntax belongs to. Volatility 2 and 3 share almost no command surface.
  2. Naming scheme — how the tool names its plugins, modules, or subcommands. Getting the scheme right validates or invalidates dozens of lines at once.
  3. Path and file conventions — where artifacts actually live on the version in question.
  4. Individual claims — only now, one by one.

A class error is cheap to fix and expensive to miss. An instance error is the reverse.

Source Hierarchy

Use the highest tier available, and record which tier you used.

TierSourceUse for
1Official docs for the specific version, upstream source, RFCs, the vendor's own referenceCommand syntax, plugin names, API shapes, protocol details
2Vendor KB, release notes, changelogs, official blog announcing a changeDefaults, retention windows, licence gates, deprecations
3Maintainer-authored write-ups, conference material by the tool authorIntent, gotchas, why a thing behaves as it does
4Community posts, tutorials, Stack OverflowLeads to verify at tier 1 — never as the citation
—Model memoryNothing. Not one claim.

Two rules on top of the table:

  • Match the version. Docs for 2.x do not establish 3.x behaviour. Prefer latest or stable doc branches, and note when the skill targets an older pinned release.
  • Ask when it last changed, not just whether it is true. Vendor defaults move: Microsoft's Audit (Standard) retention went 90 → 180 days in October 2023, and material written before that is now wrong without being obviously wrong.

Never Assert These From Memory

Each of these has produced a real error in this repo:

  • CLI entry points and subcommand names
  • Plugin, module, and package names
  • Version numbers, and any "the default is X" claim
  • Event IDs and their exact semantics (4778 is session reconnect, not connect)
  • Log field and column names
  • Retention windows and licence gates
  • CVE IDs, CVSS vectors, and affected-version ranges
  • API paths, parameter names, required scopes
  • Legal precedent and case outcomes — a draft in this repo cited Mango Markets and Platypus as convictions proving exploitation is prosecuted as theft. Both went the other way: the Platypus pair were acquitted in Paris, and Eisenberg's Mango convictions were vacated in May 2025. Memory produced a confident claim that was backwards.

Reading Sources: Fetch Markdown, Not HTML

Pull documentation through defuddle.md, which strips a page to its main content and returns Markdown with YAML frontmatter. Prefix any URL:

bash
curl -sL "https://defuddle.md/learn.microsoft.com/en-us/purview/audit-log-retention-policies"

The scheme is optional in the path — defuddle.md/example.com/x and defuddle.md/https://example.com/x both work.

Two reasons, and the second matters more than the first:

  1. It cuts tokens. Measured against the pages used in this repo's passes: 78% smaller on a prose doc page (Microsoft Learn), 33% on a link-heavy API index. Prose collapses hard; link tables less so.
  2. It returns the full text, deterministically. You get the whole page as Markdown you can grep, instead of a model's summary of the page. That is what makes it safe to draw a negative conclusion — see below.

Use it for documentation, specs, vendor KB, and articles. Do not use it for:

  • JSON or API responses — readability extraction mangles structured data. Fetch those raw.
  • HTTP status probes — you need the status of the real host, not of a proxy that may return 200 for its own error page.
  • Anything internal, client-owned, or target-owned. The URL leaves your machine and goes to a third party. Never route an engagement URL, an internal hostname, or a client's estate through an external extraction service. Public vendor documentation only.
  • Authenticated or JS-rendered pages — it fetches as an anonymous client.

A blocked fetch is not a negative result. Some hosts refuse the extractor and return an error blob instead of the page — freedesktop.org answers with {"error":"Failed to fetch: 418 I'm a teapot"}. Treat that as "I did not read the page", never as "the page does not say this". It is the truncated-negative trap wearing a different hat, and the fix is the same: re-fetch directly before concluding anything.

Programmatic Existence Probes

Where a project publishes one doc page per module, existence is a status code, not a judgment call. This is the highest-confidence, lowest-effort check available, and it batches.

bash
# One plugin: 200 = exists, 404 = does not
curl -s -o /dev/null -w "%{http_code}\n" \
  "https://volatility3.readthedocs.io/en/latest/volatility3.plugins.windows.idt.html"

# Every plugin the skill references, in one pass
plugins=$(grep -oE '\b(windows|linux|mac)\.[a-z_]+' SKILL.md | sort -u)
for p in $plugins; do
  code=$(curl -s -o /dev/null -w "%{http_code}" \
    "https://volatility3.readthedocs.io/en/latest/volatility3.plugins.$p.html")
  [ "$code" = "200" ] || echo "MISSING $code  $p"
done

That pass settled 32 plugin references in seconds and found the two that do not exist. Adapt the URL pattern per project — most doc generators (Sphinx, mkdocs, pkg.go.dev, docs.rs, npm, PyPI) expose a per-symbol or per-package URL you can probe the same way.

When a project has no per-symbol docs, fall back to an exact-string search of the upstream source — a raw file fetch and a grep for the literal identifier. Both of these are deterministic. Prefer them over asking any model, including yourself.

Show full SKILL.md (901 more words)Show less

The Truncated-Negative Trap

A summarizer saying "not found" is not evidence of absence.

Fetching a large index page and asking what it contains returned "pslist, pstree, psaux, sockstat: not listed" for the Volatility Linux plugin index. All four exist. The page had been truncated before the model saw those entries. Acting on that output would have introduced four errors into a correct section — verification making the file worse.

The asymmetry that matters:

  • A positive is cheap. If the tool shows you the identifier, it exists.
  • A negative is expensive. Absence from a summarized fetch may mean absent, truncated, renamed, moved, or paginated away.

So: never delete or rewrite content on a summarized negative. Promote every negative to a deterministic check before you touch the file.

The cheapest promotion is to stop summarizing. Fetch the page through defuddle.md and grep the full Markdown yourself — the answer becomes a match count rather than a model's recollection:

bash
L="volatility3.readthedocs.io/en/latest/volatility3.plugins.linux.html"
for p in pslist pstree psaux sockstat; do
  echo "$p: $(curl -sL "https://defuddle.md/$L" | grep -c "linux\.$p module")"
done
# pslist: 1   pstree: 1   psaux: 1   sockstat: 1  -- all four present

That is the exact check that refutes the summarizer's "not listed" on all four. Where a per-symbol URL exists, the status probe below is stronger still. If you can get neither, leave the content alone and flag it unconfirmed — an unverified line is recoverable, a confidently deleted correct one is not.

Consequence Weighting

Not all errors cost the same. Spend effort where failure is silent.

Failure modeExampleCost
Loud — fails on first runWrong CLI flag, nonexistent pluginMinutes. The tool tells you.
Silent — produces a confident wrong answerMisread event ID, wrong retention window, wrong artifact meaningAn incident timeline that lawyers read.

Verify silent-failure claims first and hardest. In practice that means the defensive and forensic content — event IDs, log schemas, artifact semantics, retention — outranks offensive tool syntax, even though the offensive content looks more dangerous.

A concrete case: the M365 skill claimed 90 days of Unified Audit Log for E3. The real default has been 180 days since October 2023. An analyst trusting the skill reads an empty 90-day window as "no activity" and closes an investigation that had six months of history available.

Procedure

  1. Inventory the checkable claims. Grep the skill for the classes above — commands, identifiers, IDs, field names, numbers with units. Anything that could be wrong in a way a reader would not notice.
  2. Resolve class-level claims first (tool name, version, naming scheme). Re-scope everything below to what survives.
  3. Batch-probe every identifier with a deterministic check.
  4. Verify remaining claims at tier 1 or 2, recording the source. Pull the pages through defuddle.md so you are reading full text cheaply rather than a summary.
  5. Correct, and say what changed and why in the commit body — the next reader needs to know a claim was checked, not just that a line moved.
  6. Adversarial second pass. Re-read your corrections trying to refute them. The original pass over this repo found errors that survived the first read and fell on the second; assume yours will too.
  7. Stamp only if complete — see below.

The verified: Stamp

yaml
verified: 2026-07-26    # ISO 8601; validate.py parses and counts this

The stamp means: the whole checkable surface of this skill was driven to a primary source on that date. It does not mean the skill is good, current forever, or complete.

Rules:

  • No stamp for a partial pass. Three defense skills in this repo were materially corrected and deliberately left unstamped, because each pass covered the dominant claim class but not the whole file. A partial pass labelled complete is worse than no label, because it converts an honest unknown into a false assurance.
  • Re-stamp on a re-check, not on an edit. Adding a section does not renew the date.
  • Absence is not a defect. validate.py treats a missing stamp as an unverified draft, which is the documented default. A malformed date is an error because it corrupts the count.

Check the current position any time:

bash
python3 scripts/validate.py --strict   # prints "Fact-checked ...: N/72"

Rationalizations to Reject

  • "CI passes, so it's fine." CI checks form. Every error found in this repo was in a file with green CI.
  • "I'm confident about this one." Confidence is uncorrelated with accuracy on identifiers and version-specific defaults. The Mango Markets claim was written with complete confidence and was backwards.
  • "The tool will error if it's wrong, so the reader will notice." True for syntax, false for interpretation — and interpretation errors are the ones that reach a deliverable.
  • "The docs didn't mention it, so I removed it." A summarized fetch omits content constantly. Promote the negative to a status code or an exact-string grep before deleting anything.
  • "I'll route everything through defuddle, it saves tokens." It is for public prose. Structured JSON comes back mangled, status probes need the real host, and engagement or client URLs must never be handed to a third-party service to satisfy a token budget.
  • "It was right when it was written." Retention windows, licence gates, and default paths change under you. Verification is dated for exactly this reason; "correct in 2024" is not a defence in 2026.
  • "I fixed the errors I found, so I can stamp it." You can stamp it when you have looked at everything checkable, not when you have run out of errors you happened to notice.
  • "Close enough — the reader will adapt." The reader is often a model executing the command, or an analyst under incident pressure. Neither adapts.

References

  • authoring-security-skills — writing a new skill; verify with this skill before stamping
  • CONTRIBUTING.md — the merge bar and house style
  • scripts/validate.py — structural checks and the verified-count report

© trilwu, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/verifying-skill-accuracy of trilwu/secskills.

Open the folder on GitHubat commit ca53957

Compare with similar skills

Verifying Skill Accuracy next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Verifying Skill Accuracy compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Verifying Skill Accuracy this skilltrilwu/secskills157—~4kAutomated safety check: PassMIT
Perplexity Web Searchdavila7/claude-code-templates32k11 repos~3.5kAutomated safety check: NotesMIT
Citation Verification GuideGalaxy-Dawn/claude-scholar5.7k2 repos~1.9kAutomated safety check: PassMIT
Article Fact Checkerdigoal/blog8.6k—~939Automated safety check: PassGPL-2.0
Deep Research Agent TeamImbad0202/academic-research-skills51k—~13kAutomated safety check: PassCustom licence
Docs Grounding Verifiermicrosoft/apm4k—~1.9kAutomated safety check: PassMIT

Similar skills

  • Perplexity Web Search

    davila7/claude-code-templates

    Runs web-grounded searches through Perplexity's Sonar models over OpenRouter for current events, recent literature and cited facts beyond the model's training cutoff.

    32k GitHub starsUsed in 11 repos~3.5k tokens
    Research & ScienceAuto-check: notes
  • Citation Verification Guide

    Galaxy-Dawn/claude-scholar

    Reference guidance for checking every citation in academic writing against canonical sources such as DOI, arXiv, CrossRef and Semantic Scholar, to catch fake or wrong references.

    5.7k GitHub starsUsed in 2 repos~1.9k tokens
    Research & ScienceAuto-check passed
  • 三层审查模型,逐段逐句验证文章真伪、证据链与逻辑结构。Use when the user asks to fact-check, verify, audit, or evaluate the credibility of an article, essay, report, opinion piece, social-media post, or any written claim —…

    8.6k GitHub stars~939 tokensUpdated today
    Research & ScienceAuto-check passed
  • Deep Research Agent Team

    Imbad0202/academic-research-skills

    Runs a 13-agent pipeline for rigorous academic research, from forming the question through systematic search, synthesis, bias checks and an APA 7.0 report.

    51k GitHub stars~13k tokensUpdated today
    Research & ScienceAuto-check passed
  • Official

    A skill your agent uses to verify CLAIM-LEVEL grounding of a documentation page (or set of pages) against the source code.

    4k GitHub stars~1.9k tokensUpdated yesterday
    Research & ScienceAuto-check passed
  • Fact Checking

    bradygaster/squad

    Review and validate claims using counter-hypothesis testing.

    3.3k GitHub stars~503 tokensUpdated today
    Research & ScienceAuto-check passed

More from trilwu/secskills

All 50 skills in this repo
  • Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.

    157 GitHub stars~3.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.

    157 GitHub stars~3.1k tokensUpdated 1 mo ago
    Auto-check: notes
  • Securing AI Systems

    trilwu/secskills

    Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…

    157 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing Binaries

    trilwu/secskills

    Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.

    157 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing Go Binaries

    trilwu/secskills

    Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…

    157 GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing iOS Binaries

    trilwu/secskills

    Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…

    157 GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Verifying Skill Accuracy

What does Verifying Skill Accuracy do?

Fact-check LLM-drafted technical content against primary sources — source hierarchy, programmatic existence probes for tool and plugin names, class-before-instance error triage, the…. Verifying Skill Accuracy is an agent skill from trilwu/secskills. Fact-check LLM-drafted technical content against primary sources — source hierarchy, programmatic existence probes for tool and plugin names, class-before-instance error triage, the truncated-negative trap, adversarial re-checking, and the verified-stamp discipline.

When should I use Verifying Skill Accuracy?

Verifying Skill Accuracy fits situations like: auditing a SKILL.md for factual errors; before stamping a skill verified; artifact claim needs confirming against upstream documentation; reviewing any drafted content whose specifics were written from model memory.

How do I install Verifying Skill Accuracy in Claude Code?

Run `npx skills add trilwu/secskills --skill verifying-skill-accuracy -a claude-code`. Or copy the skill folder (.claude/skills/verifying-skill-accuracy in trilwu/secskills) into .claude/skills/verifying-skill-accuracy in your project. Claude Code loads it when a task matches its description.

How do I install Verifying Skill Accuracy in Codex?

Run `npx skills add trilwu/secskills --skill verifying-skill-accuracy -a codex`. Or copy the skill folder (.claude/skills/verifying-skill-accuracy in trilwu/secskills) into .agents/skills/verifying-skill-accuracy in your project. Codex loads it when a task matches its description.

Can I use Verifying Skill Accuracy in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trilwu/secskills --skill verifying-skill-accuracy -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/verifying-skill-accuracy, .gemini/skills/verifying-skill-accuracy, .github/skills/verifying-skill-accuracy and .opencode/skills/verifying-skill-accuracy in your project.

What does Verifying Skill Accuracy need to run?

Going by SKILL.md and its folder, Verifying Skill Accuracy needs the command-line tools its instructions call (curl and python3). Our summary lists: Python 3.

Does Verifying Skill Accuracy access the network?

SKILL.md names 2 domains. In commands or code: defuddle.md and volatility3.readthedocs.io; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Verifying Skill Accuracy safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Verifying Skill Accuracy use?

Verifying Skill Accuracy is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Verifying Skill Accuracy use?

About 4k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Verifying Skill Accuracy?

Skills that share tags, products or a category with Verifying Skill Accuracy: Perplexity Web Search (davila7/claude-code-templates, 32k stars), Citation Verification Guide (Galaxy-Dawn/claude-scholar, 5.7k stars), Article Fact Checker (digoal/blog, 8.6k stars) and Deep Research Agent Team (Imbad0202/academic-research-skills, 51k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Verifying Skill Accuracy?

trilwu (a GitHub user) maintains it in trilwu/secskills, which has 157 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on September 4, 2026.

Source: trilwu/secskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.