Agent skill

Check Wip1006 Config

by worldcoin in worldcoin/world-chain

Inspect the active WIP-1006 factory configuration from an L1 AnchorStateRegistry at one finalized snapshot, including safety state, Nitro PCR approvals, and optional implementation comparison.

MITAuto-check passedDevelopment

Install Check Wip1006 Config

skills CLI
$ npx skills add worldcoin/world-chain --skill check-wip1006-config -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install worldcoin/world-chain check-wip1006-config --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/worldcoin/world-chain.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/check-wip1006-config .claude/skills/check-wip1006-config && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
check-wip1006-config
GitHub stars
116
Token cost
~1.4k tokens
SKILL.md length
573 words
Files
2 (incl. scripts)
Skills in repo
7
Repo updated
First seen
Licence
MIT

At a glance

Inspect the active WIP-1006 factory configuration from an L1 AnchorStateRegistry at one finalized snapshot, including safety state, Nitro PCR approvals, and optional implementation comparison.

  • Development work in your project
  • Runs Python scripts from its folder; calls python3 and gh; reaches api.github.com; needs GH_TOKEN and GITHUB_TOKEN

What it does

Check Wip1006 Config is an agent skill from worldcoin/world-chain. Inspect the active WIP-1006 factory configuration from an L1 AnchorStateRegistry at one finalized snapshot, including safety state, Nitro PCR approvals, and optional implementation comparison.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including scripts (for example `scripts/check_config.py`).

It sits in Development. It works with Ethereum. The licence is MIT.

When your agent uses it

  • Development work in your project

Example prompts

  • “/check-wip1006-config”

Requirements

  • Python 3
  • A credential in GITHUB_TOKEN

What it can do on your machine

Read from SKILL.md and the folder at commit 0733816. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3
    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • api.github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GH_TOKEN
    • GITHUB_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Check Wip1006 Config loads about 1.4k tokens when it runs. Until then it costs about 53 tokens; SKILL.md has 573 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~53
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from worldcoin/world-chain at commit 0733816, republished under its MIT licence (© worldcoin). 573 words, ~1,380 tokens.

Download SKILL.mdSave it as .claude/skills/check-wip1006-config/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
check-wip1006-config
description
Inspect the active WIP-1006 factory configuration from an L1 AnchorStateRegistry at one finalized snapshot, including safety state, Nitro PCR approvals, and optional implementation comparison.

Run python3 scripts/check_config.py <anchor_state_registry> <mainnet|sepolia> [l1_rpc] [--implementation <address>], resolving the script relative to this skill directory. Execute directly; do not read/recreate the script unless troubleshooting. Requires Python standard library, Foundry cast (local Keccak only), and the adjacent investigate-game RPC helper. GitHub CLI authentication (gh auth login) or GH_TOKEN/GITHUB_TOKEN with repository push access lets the release lookup include draft releases. No transactions are sent.

RPC defaults: ETHEREUM_PROVIDER for mainnet, ETHEREUM_SEPOLIA_PROVIDER for sepolia. An explicit URL overrides the environment. Never expose URLs/credentials. Wrong chain IDs fail. Reads use an EIP-1898 canonical block hash, preferably finalized; unsupported finalized tags fall back explicitly to latest. Historical state, JSON-RPC batches and event queries are required. No unpinned state fallback is permitted.

Return the script's compact text report directly, preserving complete addresses/hashes, UNKNOWN fields, checks, provenance, and snapshot metadata. Exit 1 means incomplete or inconsistent configuration; partial output is useful but is not a clean bill of health. Do not infer missing values from existing games or deployment files. If factory discovery fails, report the failed registry getter rather than guessing a deployment.

The script discovers registry → factory → gameImpls(1006), SystemConfig/SuperchainConfig, bond vault/token, SP1 backend, council authority, Nitro key registry → attestation verifier → certificate/P384 dependencies. It checks registration, immutable relationships, constructor constraints, proof domain, ETH init bond (must be zero with this ERC-20 architecture), pauses and PCR approvals. Game type 1006 and domain encoding version 1 are protocol identifiers from repository source, not deployment configuration.

--implementation adds an OLD (currently registered) vs NEW (supplied candidate) comparison of all collected implementation/dependency parameters at the same snapshot, including unchanged values. Changes are not classified as safe/unsafe. The candidate is not assumed activated.

Active means the implementation registered at the snapshot, used by games created after its activation. setImplementation() does not update existing games. Existing game parameters are never evidence of current factory configuration.

PCR0/1/2 are Keccak digests of raw PCRs, not raw SHA-384 PCR bytes. The implementation pins only PCR0 (teeImageId); there is no unique expected PCR1/2. Approval events supply candidate triples, and isPCRSetApproved verifies current state. Scanning is bounded (64 requests and 180 seconds per verifier); unavailable/incomplete history means UNKNOWN, never “not approved.” A missing approved triple blocks new registrations, but PCR revocation does not revoke already registered signers.

Show full SKILL.md (203 more words)Show less

The report identifies the proofs/... release matching the active implementation's aggregation vkey, range vkey commitment, and teeImageId. The script reads release notes from the world-chain releases via GitHub's API and hashes each release's raw PCR0 before comparing it with the onchain image ID. All three values must match one release. Draft releases require GitHub authentication with push access; without confirmed draft visibility, a search with no published match reports UNKNOWN because drafts could match. A complete search with no match reports that the onchain proofs release doesn't match any release in the world-chain releases section. Missing onchain values, unavailable GitHub data, malformed release notes, or an incomplete search also report UNKNOWN. This is release metadata identification, not proof artifact verification.

Limitations: this inspects the repository's contract interfaces, not arbitrary future implementations. Getter compatibility/code presence cannot authenticate deployed bytecode, prove key/artifact correctness, test a proof, or certify end-to-end availability. Custom verifier adapters may yield UNKNOWN dependencies. The supplied registry is the trust root, not independently authenticated as a canonical deployment. No automatic network switch. No signer inventory, private keys, certificate cache enumeration, or existing-game inspection. RPC completeness is trusted for historical logs.

Examples:

text
$check-wip1006-config 0x... sepolia
$check-wip1006-config 0x... mainnet https://... --implementation 0x...

Example report shape (illustrative, not live data; actual addresses/hashes are untruncated):

text
WIP-1006 Active Configuration
Network: sepolia | Chain ID: 11155111
Snapshot: <number> | <hash> | <UTC timestamp> | finalized
...
WIP-1006
implementation: <address>
proposerBond: <integer> [raw ERC-20 units]
...
TEE Attestation
PCR0=<digest> PCR1=<digest> PCR2=<digest> approved=True
...
Onchain proofs release: proofs/v1.0.0-rc.4
Release source: https://api.github.com/repos/worldcoin/world-chain/releases
...
Checks
[OK] Factory init bond is zero (ETH); proposer bond uses the ERC-20 vault
[UNKNOWN] Proof artifacts/key correctness cannot be established from getters
...
Discovered via
implementation: factory.gameImpls(1006)
...

© worldcoin, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (scripts) in .agents/skills/check-wip1006-config of worldcoin/world-chain.

  • SKILL.md
  • scripts/check_config.py

Open the folder on GitHubat commit 0733816

Compare with similar skills

Check Wip1006 Config next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Check Wip1006 Config compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Check Wip1006 Config this skillworldcoin/world-chain116—~1.4kAutomated safety check: PassMIT
Wagmi Feature Developmentwevm/wagmi6.8k—~3.8kAutomated safety check: PassMIT
Release Roundethereumjs/ethereumjs-monorepo2.8k—~2kAutomated safety check: PassNone
Update Est Fixturesethereumjs/ethereumjs-monorepo2.8k—~3.3kAutomated safety check: PassNone
Starknet JSstarknet-io/starknet.js1.3k—~1.2kAutomated safety check: PassMIT
Lean Reviewgeanlabs/gean177—~1.5kAutomated safety check: PassMIT

Similar skills

  • Walks through adding a Wagmi feature across its layers: a Viem-based core action, TanStack Query options, and React and Vue bindings.

    6.8k GitHub stars~3.8k tokensUpdated 9 days ago
    DevelopmentAuto-check passed
  • Release Round

    ethereumjs/ethereumjs-monorepo

    Runs a coordinated EthereumJS npm release round in six human-gated phases — intent and readiness, CHANGELOG, version bump, publish (human executes), post-publish verification, and announcements.

    2.8k GitHub stars~2k tokensUpdated 22 days ago
    DevelopmentAuto-check passed
  • Update Est Fixtures

    ethereumjs/ethereumjs-monorepo

    Updates EthereumJS execution-spec test fixtures from an ethereum/execution-specs release, then (after a human merge) points the monorepo submodule, updates VM npm scripts, reports a first test run…

    2.8k GitHub stars~3.3k tokensUpdated 22 days ago
    DevelopmentAuto-check passed
  • Starknet JS

    starknet-io/starknet.js

    A skill your agent uses when writing or debugging JavaScript/TypeScript that interacts with Starknet through the starknet.js SDK — building Call objects or calldata, encoding/decoding Cairo types…

    1.3k GitHub stars~1.2k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Lean Review

    geanlabs/gean

    Review a branch or PR's diff against main and report opportunities to subtract — simplify, delete, and reduce the number of concepts a reader has to hold in their head.

    177 GitHub stars~1.5k tokensUpdated today
    DevelopmentAuto-check passed
  • Mark Task Executed

    ethereum-optimism/superchain-ops

    Mark one or more superchain-ops tasks as EXECUTED by updating each task README's Status line to link the on-chain execution transaction, then open a PR.

    99 GitHub stars~679 tokensUpdated yesterday
    DevelopmentAuto-check passed

More from worldcoin/world-chain

  • Debug Node Tracing

    worldcoin/world-chain

    Debug World Chain nodes with temporary admintracingDirectives log filters and targeted log collection.

    116 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Investigate Game

    worldcoin/world-chain

    Verify an Ethereum address is a WIP1006 dispute game and report its status, claim, bonds, proof configuration, and proposal context in a compact debugging table.

    116 GitHub stars~533 tokensUpdated today
    Auto-check passed
  • Pending Games

    worldcoin/world-chain

    List unresolved WIP1006 dispute game addresses by scanning backward through at most the newest 2000 entries in a supplied factory.

    116 GitHub stars~550 tokensUpdated today
    Auto-check passed
  • Recovery Parent

    worldcoin/world-chain

    Find the nearest defender-winning, ASR claim-valid game backward in a WIP-1006 lineage for the proposer and defender recovery-parent flag.

    116 GitHub stars~570 tokensUpdated today
    Auto-check passed
  • Scan Invalid Games

    worldcoin/world-chain

    Scan WIP1006 games inside their challenge deadline for root claims that disagree with a supplied L2 consensus RPC at finalized L2 blocks, including challenge status and game creator.

    116 GitHub stars~532 tokensUpdated today
    Auto-check passed
  • Invalid Parent

    worldcoin/world-chain

    Trace a WIP1006 INVALIDPARENT cascade to its first ancestor with a different status or invalidation reason.

    116 GitHub stars~295 tokensUpdated 2 days ago
    Auto-check passed

Works with

Categories

Questions about Check Wip1006 Config

What does Check Wip1006 Config do?

Inspect the active WIP-1006 factory configuration from an L1 AnchorStateRegistry at one finalized snapshot, including safety state, Nitro PCR approvals, and optional implementation comparison. Check Wip1006 Config is an agent skill from worldcoin/world-chain. Inspect the active WIP-1006 factory configuration from an L1 AnchorStateRegistry at one finalized snapshot, including safety state, Nitro PCR approvals, and optional implementation comparison.

When should I use Check Wip1006 Config?

Check Wip1006 Config fits situations like: development work in your project.

How do I install Check Wip1006 Config in Claude Code?

Run `npx skills add worldcoin/world-chain --skill check-wip1006-config -a claude-code`. Or copy the skill folder (.agents/skills/check-wip1006-config in worldcoin/world-chain) into .claude/skills/check-wip1006-config in your project. Claude Code loads it when a task matches its description.

How do I install Check Wip1006 Config in Codex?

Run `npx skills add worldcoin/world-chain --skill check-wip1006-config -a codex`. Or copy the skill folder (.agents/skills/check-wip1006-config in worldcoin/world-chain) into .agents/skills/check-wip1006-config in your project. Codex loads it when a task matches its description.

Can I use Check Wip1006 Config in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add worldcoin/world-chain --skill check-wip1006-config -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/check-wip1006-config, .gemini/skills/check-wip1006-config, .github/skills/check-wip1006-config and .opencode/skills/check-wip1006-config in your project.

What does Check Wip1006 Config need to run?

Going by SKILL.md and its folder, Check Wip1006 Config needs Python for the scripts in its folder, the command-line tools its instructions call (python3 and gh) and credentials named GH_TOKEN and GITHUB_TOKEN. Our summary lists: Python 3; A credential in GITHUB_TOKEN.

Does Check Wip1006 Config access the network?

SKILL.md names 1 domain. In commands or code: api.github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Check Wip1006 Config safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Check Wip1006 Config use?

Check Wip1006 Config is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Check Wip1006 Config use?

About 1.4k tokens (SKILL.md is roughly 5.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Check Wip1006 Config?

Skills that share tags, products or a category with Check Wip1006 Config: Wagmi Feature Development (wevm/wagmi, 6.8k stars), Release Round (ethereumjs/ethereumjs-monorepo, 2.8k stars), Update Est Fixtures (ethereumjs/ethereumjs-monorepo, 2.8k stars) and Starknet JS (starknet-io/starknet.js, 1.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Check Wip1006 Config?

worldcoin (a GitHub organization) maintains it in worldcoin/world-chain, which has 116 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on October 11, 2026.

Source: worldcoin/world-chain on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.