All skills
oaustegard avatar

/verifying-claims

@4b31e7d

Check that a document's claims about code are actually true by reading the prose, the code, and the tests and reporting (or fixing) where they disagree. Use whenever the user wants to verify a README, guide, spec, or docstring still matches the code; whenever they mention documentation drift, doc-code sync, "is this still accurate", stale docs, or keeping docs/tests/code consistent; before publishing or merging a docs change; or as a periodic doc-accuracy sweep. The agent reads the prose's meaning directly — there is no claim-comment DSL to maintain. Pairs with TDD — the test suite is the deterministic behavioral gate, this skill is the semantic prose-vs-reality review.

Use this Skill: https://skilld.dev/gh/oaustegard/claude-skills/verifying-claims

This session only. Nothing lands on disk.

README.md

≈327 tokens on demand. Your agent reads this file only when SKILL.md points to it.

verifying-claims

Check that what a document says about code is true — by reading the document, the code, and the tests together and reporting where they disagree.

The reviewer is the agent, not a parser. There is no claim-comment DSL: the prose's meaning is read directly and compared to what the code does and what the tests assert. No shadow copy, because the thing checked is the thing the human reads.

See SKILL.md for the procedure, the verdicts (PASS / FAIL / UNSUPPORTED / STALE), and the division of labor with TDD.

Quick start

python3 scripts/gather_context.py --doc README.md --src pkg/ --tests tests/

That bundles the document text, the public API surface (ast-parsed, never imported), and the test inventory into one report. The agent then reads the bundle and judges each prose claim against it.

What this is and isn't

  • Is: a triggered, semantic review of whether documentation matches reality — run before docs ship, after a refactor, or as a sweep.
  • Isn't: a CI merge gate or a test framework. The deterministic behavioral gate is your test suite (TDD). This is the prose layer tests can't reach.

Files

  • scripts/gather_context.py — deterministic input bundler.
  • references/drift-report-example.md — what a review report looks like.

Source: SKILL.md on GitHub

1 warning2mo3 checks · Risk SAFE
  • Gen Agent Trust Hub2mo

    The skill is well-implemented and uses safe techniques like AST parsing to inspect code without execution. However, it is susceptible to indirect prompt injection because it ingests untrusted documentation and source code into the agent's context without explicit security boundaries or sanitization. Mitigations include adding human review checkpoints and explicit instructions for the agent to ignore any commands found within the analyzed documentation.

  • Socket2mo

    No alerts

  • Snyk2mo

    Risk: MEDIUM · 1 issue

Signed by skilld at 4b31e7d. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 4 months ago
metadata
{
  "version": "0.2.0"
}

README badge

README badge for oaustegard/claude-skills/verifying-claims