Dep Validate
blokadaorg/blokada
A skill your agent uses to validate risky dependency bumps end to end as a local or cloud-launched agent.
Evidence-led audit/fix rounds for any codebase in any language.
$ npx skills add WrongStack/WrongStack --skill evidence-audit -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install WrongStack/WrongStack evidence-audit --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/WrongStack/WrongStack.git skills-src && mkdir -p .claude/skills && cp -r skills-src/packages/core/skills/evidence-audit .claude/skills/evidence-audit && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "evidence-audit" agent skill from https://github.com/WrongStack/WrongStack/tree/main/packages/core/skills/evidence-audit into .claude/skills/evidence-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "evidence-audit", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/WrongStack/WrongStack/tree/main/packages/core/skills/evidence-auditType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add WrongStack/WrongStack --skill evidence-audit -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install WrongStack/WrongStack evidence-audit --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/WrongStack/WrongStack.git skills-src && mkdir -p .agents/skills && cp -r skills-src/packages/core/skills/evidence-audit .agents/skills/evidence-audit && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "evidence-audit" agent skill from https://github.com/WrongStack/WrongStack/tree/main/packages/core/skills/evidence-audit into .agents/skills/evidence-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "evidence-audit", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add WrongStack/WrongStack --skill evidence-audit -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install WrongStack/WrongStack evidence-audit --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/WrongStack/WrongStack.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/packages/core/skills/evidence-audit .cursor/skills/evidence-audit && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "evidence-audit" agent skill from https://github.com/WrongStack/WrongStack/tree/main/packages/core/skills/evidence-audit into .cursor/skills/evidence-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "evidence-audit", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/WrongStack/WrongStack.git --path packages/core/skills/evidence-audit--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add WrongStack/WrongStack --skill evidence-audit -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install WrongStack/WrongStack evidence-audit --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/WrongStack/WrongStack.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/packages/core/skills/evidence-audit .gemini/skills/evidence-audit && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "evidence-audit" agent skill from https://github.com/WrongStack/WrongStack/tree/main/packages/core/skills/evidence-audit into .gemini/skills/evidence-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "evidence-audit", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install WrongStack/WrongStack evidence-auditInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add WrongStack/WrongStack --skill evidence-audit -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/WrongStack/WrongStack.git skills-src && mkdir -p .github/skills && cp -r skills-src/packages/core/skills/evidence-audit .github/skills/evidence-audit && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "evidence-audit" agent skill from https://github.com/WrongStack/WrongStack/tree/main/packages/core/skills/evidence-audit into .github/skills/evidence-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "evidence-audit", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add WrongStack/WrongStack --skill evidence-audit -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install WrongStack/WrongStack evidence-audit --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/WrongStack/WrongStack.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/packages/core/skills/evidence-audit .opencode/skills/evidence-audit && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "evidence-audit" agent skill from https://github.com/WrongStack/WrongStack/tree/main/packages/core/skills/evidence-audit into .opencode/skills/evidence-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "evidence-audit", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
evidence-auditEvidence-led audit/fix rounds for any codebase in any language.
Evidence Audit is an agent skill from WrongStack/WrongStack. Evidence-led audit/fix rounds for any codebase in any language. Finds only defects that a runnable proof reproduces on current code, applies the narrowest in-scope patch, verifies with a second proof, promotes high-risk proofs to permanent regression tests, and reports exact validation results. Use whenever the user asks to audit, bug-hunt, "find real bugs in", "prove and fix", "continue the audit round on", or "what is actually broken in" a package, module, directory, or service, even without the word "audit"…
Its SKILL.md is about 3.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).
It sits in Development, covering Refactoring. The repository describes itself as: An AI coding agent that reads your code, edits files, runs commands, and reasons through bugs — across a terminal REPL, a full-screen TUI, and a browser UI, while you keep your… The licence is MIT.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 57f6018. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Evidence Audit loads about 3.5k tokens when it runs. Until then it costs about 174 tokens; SKILL.md has 1,769 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from WrongStack/WrongStack at commit 57f6018, republished under its MIT licence (© WrongStack). 1,769 words, ~3,496 tokens.
.claude/skills/evidence-audit/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Invoke as $evidence-audit <scope>. The text after the skill name is the scope. Every round produces the same thing: a ledger of findings where each finding has a proof that fails on current code, a patch that touches only the scope, and a verifier that passes after the patch. Nothing without a proof becomes a patch. Nothing without a verifier is called fixed. This holds in every language and every repo: an unproven "improvement" is a regression risk with no upside.
AGENTS.md, CONTRIBUTING.md, or equivalent at the root and in the scope). Run git status --short and record the output: these are pre-existing changes you must preserve and never touch.git log --stat -20. Do not read implementations in depth yet.Awaiting scope., and stop. Do not choose for them.Scope confirmed: <paths>. Everything you patch must be inside it. Files outside may be read for callers, types, and configs only..temp_files/ledger_<scope-slug>.md already exists, this is a continued round: read it, keep its IDs, start new findings from the next free ID. Never renumber.Keep the ledger at .temp_files/ledger_<scope-slug>.md. All proofs live in .temp_files/ at the repo root (create it if needed) and are written in the project's own language using its own runner or a plain executable in that language. For each candidate defect:
.temp_files/prove_F<ID>_<slug>.<ext>. It must run against current, unmodified code and contain:EXPECTED: and ACTUAL: side by side and ending with PROBLEM CONFIRMED + non-zero exit;bug / perf / resource-leak / race / ownership / input-handling. Record location (file:line, symbol), impact, and severity with a one-line reason.Candidate discovery is bounded: aim for 1–3 confirmed findings per round. More than that usually means the round should split into two scopes.
.temp_files/verify_F<ID>_<slug>.<ext>: the same reproduction plus at least two nearby edge cases (empty, boundary, repeated call, out-of-order completion, failure injected at the dependency). It ends with FIX VERIFIED + zero exit.prove_F<ID>_* and confirm it now prints PROBLEM NOT REPRODUCED. Paste both outputs into the ledger.race / ownership / lifecycle findings, the verifier must use gated completion order: explicit barriers, channels, futures, latches, or deferreds that force the stale task to complete after the stop/restart. Sleep-based timing is not accepted as verification in any language. Run under the project's race detector or sanitizer if one is configured.For findings rated High or Critical, or any race / ownership finding, promote the strongest proof into the project's permanent test suite next to the code it covers, following the project's test naming, placement, and assertion conventions. .temp_files artifacts are evidence for this round; the regression test is what protects the branch next month. Record the test path in the ledger. Medium/Low findings may stay as .temp_files verifiers unless the user asks otherwise.
git diff --check.Run broader suites serially when tests share writers (temp dirs, daemons, ports, databases); parallel runs produce false failures in such repos. Paste the command and the result line for each step. If a step was not run, say NOT RUN and why. Never imply it passed.
If the sandbox blocks a command (network, write outside the workspace, process spawn), request approval for that exact command rather than working around it. A workaround changes what was validated.
prove_*, verify_*, and ledger files in place.git commit, push, reset, stash, checkout --, or .temp_files cleanup unless the user explicitly authorizes it in this session.git status --short again and confirm the pre-existing changes from Setup step 1 are unchanged.Awaiting instructions for the next turn. If the user asked for continued rounds, propose the next scope as one line with a reason, not a roadmap.Recurring defect shapes that survive regardless of language. Check for them explicitly where the scope has async, concurrency, resources, or external input.
| Symptom | Cause | Fix shape | Verifier shape |
|---|---|---|---|
| Stale async work publishes into a stopped/restarted/replaced owner | State accepted after an await/callback without re-checking identity, generation, or liveness | Capture identity+generation before the suspension point, compare after, drop on mismatch | Gated completion order: start → stop/replace → release the stale task → assert nothing published |
| Cleanup removes another instance's file, lock, socket, or record | Ownership assumed after a failed exclusive create or an uncertain existence probe | Clean or reclaim only on proven ownership (token/PID/generation) or proven absence; fail closed on unknown errors | Two instances contend; assert the loser never deletes the winner's resource; injected unknown error aborts cleanup |
| Handler, callback, or listener runs on a disposed/closed owner | Registration outlives the owner; close didn't unregister or cancel in-flight work | Close unregisters and flips a closed flag every entry point checks | Close, then fire the event; assert no-op and no panic/throw |
| Resource count grows across repeated operations (handles, goroutines/threads, listeners, connections, memory) | Release missing on an error or early-return path | Move release into finally/defer/RAII/context manager; make release idempotent | N iterations with injected failure; assert count unchanged before vs after |
| Partial write, torn record, or replay divergence | Writer committed an incomplete or out-of-order record on error; reader trusts arrival order | Write complete records atomically; sequence by generation, not arrival | Replay into fresh state after one injected failure; deep-equal against live state |
| Off-by-one or boundary mishandling | Inclusive/exclusive mismatch at 0, 1, length, max | Fix the comparison; assert the boundary in a comment only if non-obvious | Proof at exactly the boundary, control one step inside |
| Error swallowed or converted to a default | Catch-all returns nil/zero/empty instead of propagating | Propagate, or handle the one specific case and propagate the rest | Inject the error at the seam; assert it reaches the caller |
| Unvalidated input reaches a sensitive operation | Trust boundary assumed, not enforced | Validate at the boundary; reject, don't sanitize-and-continue | Malformed/hostile input; assert rejection and no side effect |
ALWAYS end the round with this exact layout, taken from the ledger:
## Round <N> — <scope>
### Summary
<findings confirmed / dropped / promoted; residual risk in one sentence>
### Toolchain
<language/version, test runner cmd, build cmd, lint cmd, race/sanitizer if any — with the file each was read from>
### Findings
#### F<ID> — <type> — <severity> — <title>
- Location:
- Root cause:
- Proof (before): .temp_files/prove_F<ID>_<slug>.<ext> → <key lines>
- Patch: <files:lines changed>
- Proof (after): .temp_files/verify_F<ID>_<slug>.<ext> → <key lines>; original proof → PROBLEM NOT REPRODUCED
- Regression test: <path> | not promoted (<reason>)
### Not reproduced (dropped)
<one line each, or "none">
### Validation
- Focused tests: <cmd> → <result>
- Scope tests: <cmd> → <result>
- Build/typecheck: <cmd> → <result>
- Format/lint (scoped): <cmd> → <result>
- git diff --check: <result>
- NOT RUN: <full suite / live / security / other> — <reason>
### Boundaries
<environment contamination observed, security lines stopped, shared-branch notes>
### Working tree
<git status --short; confirmation that pre-existing changes are untouched>
### Next scope (if rounds continue)
<one line + reason>prove_ that printed PROBLEM CONFIRMED on unmodified code, with an unaffected control (and a stated baseline for perf).verify_ that printed FIX VERIFIED three times in a row, and its prove_ now prints PROBLEM NOT REPRODUCED.git status changes untouched.NOT RUN.© WrongStack, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in packages/core/skills/evidence-audit of WrongStack/WrongStack.
Open the folder on GitHubat commit 57f6018
Evidence Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Evidence Audit this skillWrongStack/WrongStack | 370 | — | ~3.5k | Automated safety check: Pass | MIT | |
| Dep Validateblokadaorg/blokada | 3.3k | — | ~5.7k | Automated safety check: Notes | MPL-2.0 | |
| Effect TSmattiacerutti/supernova | 187 | — | ~2.8k | Automated safety check: Pass | MIT | |
| Skill Writingmillionco/expect | 3.6k | — | ~1.8k | Automated safety check: Pass | Custom licence | |
| Go Rigmudrii/openclaw-dashboard | 458 | — | ~2.8k | Automated safety check: Pass | MIT | |
| AI Development Guideshinpr/claude-code-workflows | 691 | — | ~3.9k | Automated safety check: Pass | MIT |
blokadaorg/blokada
A skill your agent uses to validate risky dependency bumps end to end as a local or cloud-launched agent.
mattiacerutti/supernova
Write idiomatic Effect v4 TypeScript following official best practices from effect-solutions and the Effect source.
millionco/expect
Write and improve agent skills (SKILL.md files). An agent skill from millionco/expect.
mudrii/openclaw-dashboard
A skill your agent uses when building, reviewing, or refactoring Go code that must follow strict design discipline — ATDD/TDD workflow, explicit dependency injection, package-boundary discipline…
shinpr/claude-code-workflows
Applies language-agnostic and backend technical decision criteria, anti-pattern detection, debugging, and quality gates.
mudrii/openclaw-dashboard
A skill your agent uses when building, reviewing, or refactoring Go code in this repository.
WrongStack/WrongStack
Design or substantially improve user-facing interfaces with a product-specific visual direction, content hierarchy, and rendered critique.
WrongStack/WrongStack
A skill your agent uses to audit an interface that already exists and say precisely why it looks generated, templated, or unfinished — a scored rubric across composition, typography, color, states…
WrongStack/WrongStack
A skill your agent uses when external coding agents (Claude Code, Aider, custom scripts) need to participate in the project's shared WrongStack mailbox, or when a user asks to "expose the mailbox"…
WrongStack/WrongStack
A skill your agent uses whenever work can be split across multiple AI agents running in parallel, or when orchestrating leader/worker patterns in WrongStack.
WrongStack/WrongStack
Use this skill before asserting that a CSS, HTML or accessibility capability is available, unavailable, or the right tool — it carries dated, refreshable platform facts and refuses to let stale…
WrongStack/WrongStack
A skill your agent uses when the user wants to communicate with WrongStack's shared project mailbox from outside WrongStack — read messages sent by WrongStack agents, send replies, broadcast to all…
Categories
Evidence-led audit/fix rounds for any codebase in any language. Evidence Audit is an agent skill from WrongStack/WrongStack. Evidence-led audit/fix rounds for any codebase in any language.
Evidence Audit fits situations like: the user asks to audit; find real bugs in; continue the audit round on; what is actually broken in a package.
Run `npx skills add WrongStack/WrongStack --skill evidence-audit -a claude-code`. Or copy the skill folder (packages/core/skills/evidence-audit in WrongStack/WrongStack) into .claude/skills/evidence-audit in your project. Claude Code loads it when a task matches its description.
Run `npx skills add WrongStack/WrongStack --skill evidence-audit -a codex`. Or copy the skill folder (packages/core/skills/evidence-audit in WrongStack/WrongStack) into .agents/skills/evidence-audit in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add WrongStack/WrongStack --skill evidence-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/evidence-audit, .gemini/skills/evidence-audit, .github/skills/evidence-audit and .opencode/skills/evidence-audit in your project.
Going by SKILL.md and its folder, Evidence Audit needs the command-line tools its instructions call (git).
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Evidence Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.5k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Evidence Audit: Dep Validate (blokadaorg/blokada, 3.3k stars), Effect TS (mattiacerutti/supernova, 187 stars), Skill Writing (millionco/expect, 3.6k stars) and Go Rig (mudrii/openclaw-dashboard, 458 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
WrongStack (a GitHub organization) maintains it in WrongStack/WrongStack, which has 370 GitHub stars. The repository holds 38 skills in this directory. The repository was last updated on October 7, 2026.
Source: WrongStack/WrongStack on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.