Agent skill

Verify Fix

by vlinx-io in vlinx-io/VelaTerm

Use only when the user explicitly requests verification that a security fix remediates a reported vulnerability.

MITAuto-check passed

Install Verify Fix

skills CLI
$ npx skills add vlinx-io/VelaTerm --skill verify-fix -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vlinx-io/VelaTerm verify-fix --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vlinx-io/VelaTerm.git skills-src && mkdir -p .claude/skills && cp -r skills-src/src-tauri/resources/codex-security/skills/verify-fix .claude/skills/verify-fix && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
verify-fix
GitHub stars
275
Token cost
~757 tokens
SKILL.md length
338 words
Files
2
Skills in repo
26
Repo updated
First seen
Licence
MIT

At a glance

Use only when the user explicitly requests verification that a security fix remediates a reported vulnerability.

  • Works in 5 steps: Establish the original vulnerability,… → Confirm the current checkout contains… → Trace the original exploit path through… → …
  • Explicitly requests verification that a security fix remediates a reported vulnerability
  • SKILL.md covers When to Use, Objective, Assessment Method and Verification Workflow, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Verify Fix is an agent skill from vlinx-io/VelaTerm. Use only when the user explicitly requests verification that a security fix remediates a reported vulnerability. Do not invoke automatically while implementing fixes, reviewing ordinary code changes, or running tests. Do not use for non-security fixes, candidate finding validation, or full repository scans.

Its SKILL.md is about 760 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

The repository describes itself as: VelaTerm = Codex + iTerm2, The Best ADE for AI Coding. The licence is MIT.

When your agent uses it

  • Explicitly requests verification that a security fix remediates a reported vulnerability
  • Non-security fixes
  • Candidate finding validation
  • Full repository scans

Example prompts

  • “/verify-fix”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Establish the original vulnerability, its preconditions, affected security boundary, and legitimate behavior that must continue to work.
  2. Confirm the current checkout contains the affected component. Follow moved or refactored code rather than treating a missing file, removed…
  3. Trace the original exploit path through the current implementation and check the nearest relevant control, equivalent paths, and plausible…
  4. Run the original reproducer, focused regression checks, or legitimate-behavior checks only when they can run without modifying the…
  5. Return one result per supplied finding, in the requested order. Treat closed tickets, unrelated passing tests, and the absence of a new…

What it can do on your machine

Read from SKILL.md and the folder at commit 98b5f2f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are json).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Verify Fix loads about 757 tokens when it runs. Until then it costs about 80 tokens; SKILL.md has 338 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~80
When it runs · the whole SKILL.md, loaded when a task matches
~757

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vlinx-io/VelaTerm at commit 98b5f2f, republished under its MIT licence (© vlinx-io). 338 words, ~757 tokens.

Download SKILL.mdSave it as .claude/skills/verify-fix/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
verify-fix
description
Use only when the user explicitly requests verification that a security fix remediates a reported vulnerability. Do not invoke automatically while implementing fixes, reviewing ordinary code changes, or running tests. Do not use for non-security fixes, candidate finding validation, or full repository scans.

Verify Fix

When to Use

Invoke this skill only for an explicit request to verify a security fix, including a direct $verify-fix invocation. A request to implement a fix or run its tests does not by itself request this skill. For other tasks, follow the user's requested workflow and response format without applying this skill's JSON result contract.

Objective

Determine whether each supplied security finding has been fixed in the current checkout. Operate in standalone verification-only mode; do not create, modify, or delete repository files, apply patches, commit changes, write artifacts, or modify issue trackers.

Assessment Method

Use ../../references/static-finding-assessment.md to identify the original attacker-controlled source, security control, sensitive sink, reachable path, trust boundary, counterevidence, and proof gaps. If the caller already supplied that reference in the prompt, use the supplied contents without reading it again.

Verification Workflow

  1. Establish the original vulnerability, its preconditions, affected security boundary, and legitimate behavior that must continue to work.
  2. Confirm the current checkout contains the affected component. Follow moved or refactored code rather than treating a missing file, removed line, or changed function name as proof of remediation.
  3. Trace the original exploit path through the current implementation and check the nearest relevant control, equivalent paths, and plausible bypasses.
  4. Run the original reproducer, focused regression checks, or legitimate-behavior checks only when they can run without modifying the repository. Preserve exact static evidence when runtime checks are unavailable.
  5. Return one result per supplied finding, in the requested order. Treat closed tickets, unrelated passing tests, and the absence of a new scan finding as insufficient proof.

Result Contract

Return exactly one JSON object:

json
{
  "results": [
    {
      "id": "finding-or-issue-id",
      "status": "fixed|still_vulnerable|inconclusive",
      "evidence": "specific current source, exploit, test, or proof-gap evidence"
    }
  ]
}
  • Use fixed only when evidence proves the original security boundary is closed and legitimate behavior remains intact.
  • Use still_vulnerable only when evidence proves the original vulnerable path remains reachable.
  • Use inconclusive for a repository mismatch, missing original context, unavailable relevant checks, an unproven legitimate control, or another material proof gap.

Never infer a stronger verdict by weakening the read-only boundary, substituting a different vulnerability, or hiding missing evidence.

© vlinx-io, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in src-tauri/resources/codex-security/skills/verify-fix of vlinx-io/VelaTerm.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit 98b5f2f

Compare with similar skills

Verify Fix next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Verify Fix compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Verify Fix this skillvlinx-io/VelaTerm275—~757Automated safety check: PassMIT
No Explicit Anythedaviddias/Front-End-Checklist74k—~565Automated safety check: PassMIT
Explicit Identityparcadei/Continuous-Claude-v33.9k1 repos~323Automated safety check: PassMIT
Explicit Checkerbitwize-music-studio/claude-ai-music-skills540—~1.3kAutomated safety check: PassCC0-1.0
Explicit Instruction Sequence BuilderGarethManning/education-agent-skills837—~5.2kAutomated safety check: PassCustom licence
Masm Explicit Stack Interface0xMiden/protocol133—~716Automated safety check: PassMIT

Similar skills

  • No Explicit Any

    thedaviddias/Front-End-Checklist

    A skill your agent uses when reviewing TypeScript files for type safety regressions, during code review of functions that handle external data, or when the codebase has ESLint warnings for…

    74k GitHub stars~565 tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Explicit Identity

    parcadei/Continuous-Claude-v3

    Explicit Identity Across Boundaries

    3.9k GitHub starsUsed in 1 repo~323 tokens
    Auto-check passed
  • Explicit Checker

    bitwize-music-studio/claude-ai-music-skills

    Scans lyrics for explicit content and verifies that explicit flags match actual content.

    540 GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed
  • Explicit Instruction Sequence Builder

    GarethManning/education-agent-skills

    Build a complete explicit instruction sequence from teacher modelling through guided practice to independent work.

    837 GitHub stars~5.2k tokensUpdated 1 mo ago
    EducationAuto-check passed
  • A skill your agent uses when defining the interface for a new MASM procedure — keep its inputs explicit on the stack and its outputs limited to values it produces.

    133 GitHub stars~716 tokensUpdated today
    DevelopmentAuto-check passed
  • .NET Aspire Explicit Configuration

    Aaronontheweb/dotnet-skills

    Wires .NET Aspire AppHost resources into explicit environment-variable configuration, keeping application code free of Aspire client packages and service discovery.

    1.2k GitHub starsUsed in 1 repo~1.3k tokens
    Backend & APIsAuto-check passed

More from vlinx-io/VelaTerm

All 26 skills in this repo
  • Assess Patch Risk

    vlinx-io/VelaTerm

    Assess an immutable patch artifact's program impact, regression risk, and auto-merge eligibility.

    275 GitHub stars~2.1k tokensUpdated 2 days ago
    Auto-check passed
  • Vspawn

    vlinx-io/VelaTerm

    Explicitly spawn a standalone child session under the current vlx-term session, passing the task in as its first message (mirrors spawntask).

    275 GitHub stars~2.5k tokensUpdated 2 days ago
    Auto-check passed
  • Deep Security Scan

    vlinx-io/VelaTerm

    A skill your agent uses when the user asks for a deep, exhaustive, multi-pass, or variance-reducing repository-wide or scoped-path Codex Security scan.

    275 GitHub stars~3.3k tokensUpdated 2 days ago
    Auto-check passed
  • Define Security Policy

    vlinx-io/VelaTerm

    Define, review, or update SECURITY.md guidance for a repository or component.

    275 GitHub stars~1.5k tokensUpdated 2 days ago
    Auto-check passed
  • Track Findings

    vlinx-io/VelaTerm

    Track validated Codex Security findings in Linear, Jira, GitHub issues, or draft GitHub security advisories.

    275 GitHub stars~5.1k tokensUpdated 2 days ago
    Auto-check passed
  • Vopen

    vlinx-io/VelaTerm

    Open a file or URL in the vlx-term center pane (mirrors the vopen command).

    275 GitHub stars~697 tokensUpdated 2 days ago
    Auto-check passed

Questions about Verify Fix

What does Verify Fix do?

Use only when the user explicitly requests verification that a security fix remediates a reported vulnerability. Verify Fix is an agent skill from vlinx-io/VelaTerm. Use only when the user explicitly requests verification that a security fix remediates a reported vulnerability.

When should I use Verify Fix?

Verify Fix fits situations like: explicitly requests verification that a security fix remediates a reported vulnerability; non-security fixes; candidate finding validation; full repository scans.

How do I install Verify Fix in Claude Code?

Run `npx skills add vlinx-io/VelaTerm --skill verify-fix -a claude-code`. Or copy the skill folder (src-tauri/resources/codex-security/skills/verify-fix in vlinx-io/VelaTerm) into .claude/skills/verify-fix in your project. Claude Code loads it when a task matches its description.

How do I install Verify Fix in Codex?

Run `npx skills add vlinx-io/VelaTerm --skill verify-fix -a codex`. Or copy the skill folder (src-tauri/resources/codex-security/skills/verify-fix in vlinx-io/VelaTerm) into .agents/skills/verify-fix in your project. Codex loads it when a task matches its description.

Can I use Verify Fix in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vlinx-io/VelaTerm --skill verify-fix -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/verify-fix, .gemini/skills/verify-fix, .github/skills/verify-fix and .opencode/skills/verify-fix in your project.

What does Verify Fix need to run?

SKILL.md names no scripts, command-line tools or credentials: Verify Fix is instructions for the agent only.

Does Verify Fix access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Verify Fix safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Verify Fix use?

Verify Fix is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Verify Fix use?

About 757 tokens (SKILL.md is roughly 3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Verify Fix?

Skills that share tags, products or a category with Verify Fix: No Explicit Any (thedaviddias/Front-End-Checklist, 74k stars), Explicit Identity (parcadei/Continuous-Claude-v3, 3.9k stars), Explicit Checker (bitwize-music-studio/claude-ai-music-skills, 540 stars) and Explicit Instruction Sequence Builder (GarethManning/education-agent-skills, 837 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Verify Fix?

vlinx-io (a GitHub user) maintains it in vlinx-io/VelaTerm, which has 275 GitHub stars. The repository holds 26 skills in this directory. The repository was last updated on October 7, 2026.

Source: vlinx-io/VelaTerm on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.