Agent skill

Vc Risk Evidence Pack

by withkynam in withkynam/vibecode-pro-max-kit

Define and generate the manual-first evidence pack for high-risk work.

MITAuto-check passedBusiness, Finance & HR

Install Vc Risk Evidence Pack

skills CLI
$ npx skills add withkynam/vibecode-pro-max-kit --skill vc-risk-evidence-pack -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install withkynam/vibecode-pro-max-kit vc-risk-evidence-pack --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/withkynam/vibecode-pro-max-kit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/vc-risk-evidence-pack .claude/skills/vc-risk-evidence-pack && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
vc-risk-evidence-pack
GitHub stars
1.1k
Token cost
~2k tokens
SKILL.md length
836 words
Files
13 (incl. scripts)
Skills in repo
32
Repo updated
First seen
Licence
MIT

At a glance

Define and generate the manual-first evidence pack for high-risk work.

  • Works in 5 steps: risk-gate.json → context-snippets.json → verification.json → …
  • Business, Finance & HR work in your project
  • SKILL.md covers When To Invoke, 6 High-Risk Class Definitions, 5-Artifact Schema and Auto-Stop Rule, plus 2 more sections
  • Runs JavaScript scripts from its folder

What it does

Vc Risk Evidence Pack is an agent skill from withkynam/vibecode-pro-max-kit. Define and generate the manual-first evidence pack for high-risk work. Covers 6 high-risk class definitions and the 5-artifact schema required before finalizing, pushing, or handing off.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 19 other files, including scripts (for example `README.md`, `scripts/fixtures/validate-evidence-pack/fail/harness/context-snippets.json` and `scripts/fixtures/validate-evidence-pack/fail/harness/review-decision.json`).

It sits in Business, Finance & HR. The repository describes itself as: Your AI forgets. This remembers. Spec-driven coding harness for vibecoders, product owners, CEOs and real builders — self-improving context memory, 15 agents, 33 skills working…. The licence is MIT.

When your agent uses it

  • Business, Finance & HR work in your project

Example prompts

  • “/vc-risk-evidence-pack”

Requirements

  • Node.js

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. risk-gate.json
  2. context-snippets.json
  3. verification.json
  4. review-decision.json
  5. adversarial-validation.json

What it can do on your machine

Read from SKILL.md and the folder at commit 3bcb2f9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 11 files in scripts/ (JavaScript), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Vc Risk Evidence Pack loads about 2k tokens when it runs. Until then it costs about 52 tokens; SKILL.md has 836 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~52
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from withkynam/vibecode-pro-max-kit at commit 3bcb2f9, republished under its MIT licence (© withkynam). 836 words, ~2,020 tokens.

Download SKILL.mdSave it as .claude/skills/vc-risk-evidence-pack/SKILL.md (or your agent's skills folder). This skill also uses 12 other files; get the full folder from GitHub.
name
vc-risk-evidence-pack
description
Define and generate the manual-first evidence pack for high-risk work. Covers 6 high-risk class definitions and the 5-artifact schema required before finalizing, pushing, or handing off.
argument-hint
[risk class and work description]
trigger_keywords
risk evidence, high-risk pack, evidence pack, risk gate, adversarial validation
layer
contract
metadata.author
vibecode-pro-max-kit
metadata.version
1.0.0

vc-risk-evidence-pack

Output style: Follow process/development-protocols/communication-standards.md — answer-first, plain language, no unexplained jargon, TL;DR on long responses.

Generate and validate the manual-first evidence pack required before finalizing, pushing, or handing off high-risk implementation work.

When To Invoke

  • VALIDATE Layer 1 security surface check — when the plan touches a high-risk class, flag the need for an evidence pack before routing to execute-agent.
  • EXECUTE before marking high-risk work complete — execute-agent must produce or verify the evidence pack exists before reporting DONE on any high-risk class.
  • code-reviewer as pre-PR quality gate — code-reviewer checks for the evidence pack presence before approving changes that touch a high-risk surface.

6 High-Risk Class Definitions

From process/development-protocols/orchestration.md ("High-Risk Execution Handoff") and process/development-protocols/implementation-standards.md ("Risky Work Evidence Contract") — both sources agree:

  1. auth or identity — authentication flows, session tokens, user identity resolution, Clerk JWT handling, or any surface that determines who the caller is.
  2. billing or credits — billing events, credit balance mutations, Stripe charge flows, OpenRouter credit accounting, credit transaction records, or subscription state changes.
  3. schema/data migration or destructive data mutation — Prisma migrations, raw SQL mutations, destructive writes that delete or overwrite persistent data, or schema changes to existing models.
  4. public API or external contract changes — tRPC procedure signature changes visible to the frontend, Hono route contract changes consumed by external callers, webhook shape changes, or any API surface that third parties or the client app depend on.
  5. deploy/runtime/container/proxy/gateway behavior — Dockerfile changes, supervisord config, start.sh, container service ports, Bun server entry, Hono route registration, Caddy proxy config, worker-node provisioning, or any change that affects how a running service starts or routes traffic.
  6. permission, secret, or trust-boundary logic — instance token gating, verifyInstanceOwnership, BYOK secret fetch paths, MITM proxy key injection, Bright Data credential handling, or any logic that controls what a caller is allowed to access.

5-Artifact Schema

Per task-folder artefact colocation, all artifacts go inside the selected plan's task folder (e.g. process/features/{feature}/active/{slug}_{date}/harness/ or process/general-plans/active/{slug}_{date}/harness/), so the whole pack moves with the plan as a unit. Legacy path reports/harness/ is deprecated for new writes; never write the pack to a sibling reports/ dir or any ad-hoc location. The validator script lives at .claude/skills/vc-risk-evidence-pack/scripts/validate-risk-artifacts.mjs.

1. risk-gate.json

Records the risk class, work description, and approver identity before work begins or is finalized.

json
{
  "riskClass": "<one of the 6 classes above>",
  "workDescription": "<short description of the change>",
  "approver": "<person or agent that reviewed the risk classification>",
  "mustStopBeforeFinalize": true
}
2. context-snippets.json

Relevant code snippets with exact file and line citations for every surface the change touches in the high-risk class.

json
{
  "snippets": [
    {
      "file": "packages/api/src/router/billing.ts",
      "lines": "120-145",
      "description": "verifyInstanceOwnership call before secret read",
      "content": "<excerpt>"
    }
  ]
}
3. verification.json

Documents every verification step taken and its result. Steps must cover both the happy path and at least one failure or boundary case.

json
{
  "steps": [
    {
      "step": "<what was verified>",
      "command": "<command run, if applicable>",
      "result": "PASS | FAIL | SKIP",
      "notes": "<observations>"
    }
  ]
}
4. review-decision.json

The explicit reviewer decision record. Must contain APPROVE or REJECT with a written rationale — no implicit approvals.

json
{
  "reviewer": "<name or agent>",
  "decision": "APPROVE | REJECT",
  "rationale": "<written reason>",
  "timestamp": "<ISO 8601 date>"
}
5. adversarial-validation.json

Required when the path is high-risk or attack-sensitive (e.g. auth bypass, privilege escalation, secret exfiltration). Documents adversarial scenarios considered and whether each was ruled out.

json
{
  "scenarios": [
    {
      "scenario": "<attack or misuse description>",
      "ruled_out": true,
      "rationale": "<why this path is not exploitable>"
    }
  ]
}
Show full SKILL.md (372 more words)Show less

Auto-Stop Rule

If risk is high, do not treat the work as ready to finalize until the evidence pack exists and the reviewer decision is recorded.

If the evidence pack is missing, say so explicitly — do not proceed silently, do not imply the work is proven, and do not report DONE.

Verbatim from implementation-standards.md:

Auto-stop rule:

  • if risk is high, do not treat the work as ready to finalize until the evidence pack exists and the reviewer decision is recorded
  • if the evidence pack is missing, say so explicitly instead of implying the work is proven

This contract is manual-first and opt-in by risk class. It is not a default blocking hook.

Verbatim from orchestration.md:

If the risk gate says mustStopBeforeFinalize: true, do not imply the work is fully proven until the pack exists and the reviewer decision is present. Keep this manual-first. Do not invent a blocking hook or alternate workflow owner.

Validation Checklist

Steps to confirm each artifact is complete before handoff:

  • risk-gate.json populated with correct risk class, work description, approver, and mustStopBeforeFinalize flag
  • context-snippets.json includes all affected file:line citations for every surface touching the high-risk class
  • verification.json documents each test step and result, covering happy path and at least one boundary/failure case
  • review-decision.json has explicit APPROVE or REJECT with written rationale and timestamp — no implicit approvals
  • adversarial-validation.json present if the path is attack-sensitive (auth bypass, privilege escalation, secret exfiltration, trust-boundary violation)

High-Risk Work Evidence Contract

Verbatim from process/development-protocols/implementation-standards.md ("Risky Work Evidence Contract"):

For high-risk work, use a manual-first evidence pack before calling the change ready for finalize, push, or human handoff.

High-risk classes include:

  • auth or identity flows
  • billing, payments, or credit accounting
  • schema/data migrations or destructive writes
  • public API or external contract changes
  • deploy/runtime/container/proxy/gateway behavior
  • permission, secret, or trust-boundary logic

Preferred artifact set inside the selected plan's task folder ({slug}_{date}/harness/):

  • risk-gate.json
  • context-snippets.json
  • verification.json
  • review-decision.json
  • adversarial-validation.json for high-risk or adversarial paths

Auto-stop rule:

  • if risk is high, do not treat the work as ready to finalize until the evidence pack exists and the reviewer decision is recorded
  • if the evidence pack is missing, say so explicitly instead of implying the work is proven

This contract is manual-first and opt-in by risk class. It is not a default blocking hook.

© withkynam, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 12 other files (scripts) in .claude/skills/vc-risk-evidence-pack of withkynam/vibecode-pro-max-kit.

  • SKILL.md
  • README.md
  • scripts/fixtures/validate-evidence-pack/fail/harness/context-snippets.json
  • scripts/fixtures/validate-evidence-pack/fail/harness/review-decision.json
  • scripts/fixtures/validate-evidence-pack/fail/harness/risk-gate.json
  • scripts/fixtures/validate-evidence-pack/fail/harness/verification.json
  • scripts/fixtures/validate-evidence-pack/pass/harness/adversarial-validation.json
  • scripts/fixtures/validate-evidence-pack/pass/harness/context-snippets.json
  • scripts/fixtures/validate-evidence-pack/pass/harness/review-decision.json
  • scripts/fixtures/validate-evidence-pack/pass/harness/risk-gate.json
  • scripts/fixtures/validate-evidence-pack/pass/harness/verification.json
  • scripts/validate-evidence-pack.mjs
  • scripts/validate-risk-artifacts.mjs

Open the folder on GitHubat commit 3bcb2f9

Compare with similar skills

Vc Risk Evidence Pack next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Vc Risk Evidence Pack compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Vc Risk Evidence Pack this skillwithkynam/vibecode-pro-max-kit1.1k—~2kAutomated safety check: PassMIT
Okx Cex Earnokx/agent-skills1872 repos~3.3kAutomated safety check: PassMIT
Alpaca CLIalpacahq/cli178—~2.6kAutomated safety check: PassApache-2.0
Superior Trade AuthSuperior-Trade/superior-skills215—~950Automated safety check: PassMIT
Birdeye APIagiprolabs/claude-trading-skills410—~1.8kAutomated safety check: PassMIT
YfinanceSilvioBaratto/optimizer176—~4kAutomated safety check: NotesCustom licence

Similar skills

  • Okx Cex Earn

    okx/agent-skills

    Manages OKX Simple Earn (flexible savings/lending), Flash Earn, On-chain Earn (staking/DeFi), Dual Investment (DCD/双币赢), and AutoEarn (自动赚币) via the okx CLI.

    187 GitHub starsUsed in 2 repos~3.3k tokens
    Business, Finance & HRAuto-check passed
  • Alpaca CLI

    alpacahq/cli

    Install, configure, and use the Alpaca CLI - a command-line tool for the Alpaca Trading API.

    178 GitHub stars~2.6k tokensUpdated yesterday
    Business, Finance & HRAuto-check passed
  • Superior Trade Auth

    Superior-Trade/superior-skills

    A skill your agent uses when an agent needs to register a Superior Trade account, verify an email OTP, configure x-api-key authentication, or recover from missing or invalid credentials before using…

    215 GitHub stars~950 tokensUpdated 1 mo ago
    Business, Finance & HRAuto-check passed
  • Birdeye API

    agiprolabs/claude-trading-skills

    Solana token market data via Birdeye — prices, OHLCV, trades, token metadata, security checks, and trader activity

    410 GitHub stars~1.8k tokensUpdated 1 mo ago
    Business, Finance & HRAuto-check passed
  • Yfinance

    SilvioBaratto/optimizer

    Load proactively whenever the user works with yfinance or Yahoo Finance data — pulling price history, fetching financials or analyst data, screening stocks / funds / ETFs, streaming real-time…

    176 GitHub stars~4k tokensUpdated 3 days ago
    Business, Finance & HRAuto-check: notes
  • Coingecko API

    agiprolabs/claude-trading-skills

    Broad crypto market data from CoinGecko covering 13,000+ tokens.

    410 GitHub stars~1.6k tokensUpdated 1 mo ago
    Business, Finance & HRAuto-check passed

More from withkynam/vibecode-pro-max-kit

All 32 skills in this repo
  • Library Documentation Seeker

    withkynam/vibecode-pro-max-kit

    Looks up library and framework documentation through Context7 first, with bundled Node scripts as a fallback that fetch and analyze llms.txt files.

    1.1k GitHub starsUsed in 1 repo~1k tokens
    Auto-check: notes
  • Vc Sequential Thinking

    withkynam/vibecode-pro-max-kit

    Apply step-by-step analysis for complex problems with revision capability.

    1.1k GitHub starsUsed in 1 repo~854 tokens
    Auto-check passed
  • Agent Browser Automation

    withkynam/vibecode-pro-max-kit

    Drives a browser through the agent-browser CLI, using compact snapshots with element refs to keep context small in long sessions, plus video recording and cloud browsers.

    1.1k GitHub stars~2.6k tokensUpdated 3 mo ago
    Auto-check passed
  • Context Routing Audit

    withkynam/vibecode-pro-max-kit

    Audits a project's context routing, skill discoverability and skill wiring by running a chain of validator scripts and fixing whatever they report.

    1.1k GitHub stars~1.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Active Plan Audit

    withkynam/vibecode-pro-max-kit

    Reviews a codebase's active plan files for staleness and completion, then archives only the ones confirmed done or obsolete against the real code.

    1.1k GitHub stars~757 tokensUpdated 3 mo ago
    Auto-check passed
  • Systematic Debugging and Investigation

    withkynam/vibecode-pro-max-kit

    Forces root-cause investigation before any fix, combining a four-phase debugging method with log, CI and performance investigation techniques and a rule against unverified completion claims.

    1.1k GitHub stars~1.5k tokensUpdated 3 mo ago
    Auto-check passed

Questions about Vc Risk Evidence Pack

What does Vc Risk Evidence Pack do?

Define and generate the manual-first evidence pack for high-risk work. Vc Risk Evidence Pack is an agent skill from withkynam/vibecode-pro-max-kit. Define and generate the manual-first evidence pack for high-risk work.

When should I use Vc Risk Evidence Pack?

Vc Risk Evidence Pack fits situations like: business, Finance & HR work in your project.

How do I install Vc Risk Evidence Pack in Claude Code?

Run `npx skills add withkynam/vibecode-pro-max-kit --skill vc-risk-evidence-pack -a claude-code`. Or copy the skill folder (.claude/skills/vc-risk-evidence-pack in withkynam/vibecode-pro-max-kit) into .claude/skills/vc-risk-evidence-pack in your project. Claude Code loads it when a task matches its description.

How do I install Vc Risk Evidence Pack in Codex?

Run `npx skills add withkynam/vibecode-pro-max-kit --skill vc-risk-evidence-pack -a codex`. Or copy the skill folder (.claude/skills/vc-risk-evidence-pack in withkynam/vibecode-pro-max-kit) into .agents/skills/vc-risk-evidence-pack in your project. Codex loads it when a task matches its description.

Can I use Vc Risk Evidence Pack in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add withkynam/vibecode-pro-max-kit --skill vc-risk-evidence-pack -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vc-risk-evidence-pack, .gemini/skills/vc-risk-evidence-pack, .github/skills/vc-risk-evidence-pack and .opencode/skills/vc-risk-evidence-pack in your project.

What does Vc Risk Evidence Pack need to run?

Going by SKILL.md and its folder, Vc Risk Evidence Pack needs JavaScript for the scripts in its folder. Our summary lists: Node.js.

Does Vc Risk Evidence Pack access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Vc Risk Evidence Pack safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Vc Risk Evidence Pack use?

Vc Risk Evidence Pack is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Vc Risk Evidence Pack use?

About 2k tokens (SKILL.md is roughly 8.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Vc Risk Evidence Pack?

Skills that share tags, products or a category with Vc Risk Evidence Pack: Okx Cex Earn (okx/agent-skills, 187 stars), Alpaca CLI (alpacahq/cli, 178 stars), Superior Trade Auth (Superior-Trade/superior-skills, 215 stars) and Birdeye API (agiprolabs/claude-trading-skills, 410 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Vc Risk Evidence Pack?

withkynam (a GitHub user) maintains it in withkynam/vibecode-pro-max-kit, which has 1,147 GitHub stars. The repository holds 32 skills in this directory. The repository was last updated on June 21, 2026.

Source: withkynam/vibecode-pro-max-kit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.