Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Verification Loop

ASecurity

Evidence-before-assertions workflow. Use before claiming work is done, before release, and after any behavior change in scripts/skills/MCP.

54 stars
0 votes
0 copies
0 views
Added 9/22/2026
toolsgoshell

Works with

climcp

Security Analysis

A100/100

Scanned 9/22/2026

$npx -y skills add rexleimo/aios --skill verification-loop --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Verification Loop?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Verification Loop
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/rexleimo-verification-loop/badge)](https://www.skillsdirectory.com/skills/rexleimo-verification-loop)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: verification-loop
description: Evidence-before-assertions workflow. Use before claiming work is done, before release, and after any behavior change in scripts/skills/MCP.

installCatalogName: verification-loop
clients: [codex, claude, gemini, opencode, hermes, workbuddy, pi, zcode, qoder]
scopes: [global, project]
defaultInstall:
  global: true
  project: false
tags: [general, verification]
repoTargets: [codex, claude, gemini, opencode, hermes, workbuddy, pi, zcode, qoder]
---

# Verification Loop

## Trigger
Use this skill when:
- You changed runtime behavior (scripts, wrappers, MCP server, install flows)
- You are about to say "done", "fixed", "works", or "passes"
- You are about to bump version / release

## Rules
- Prefer commands with deterministic exit codes over "it looks fine".
- If you cannot run verification, say exactly what you could not run and why.

## Baseline Checks (AIOS)
1. Run the verifier:
   - `aios doctor`
   - Or: `aios doctor`
   - Compatibility wrappers: `scripts/verify-aios.sh` / `scripts/verify-aios.ps1`

2. MCP server changes (minimum):
   - `cd mcp-server && npm run typecheck`
   - `cd mcp-server && npm run build`
   - Manual smoke: `chrome.launch_cdp` -> `browser.connect_cdp` -> `page.goto` -> `page.extract_text`/`page.screenshot` -> `browser.close`

3. Install/wrapper changes:
   - Re-run install/update on a clean-ish shell session.
   - Confirm new commands are visible and resolve to `ROOTPATH` scripts.

## Evidence Capture
- Record the exact commands run and whether they succeeded.
- For failures: include the first actionable error line and the remediation you applied.

## Structured Verdict Schema

Inspired by the-pair v2.0.2 `quality_gate.rs`: every completion claim MUST be
backed by a structured verdict with exactly four sections. A verdict missing any
section is an **automatic REJECT** — there is no partial credit.

The four required sections, in order:

1. **FILES_REVIEWED** — list of files reviewed with line ranges and change status.
2. **CHECKS** — typecheck, test suite, lint — each with a concrete PASS/FAIL status.
3. **CODE** — the specific code snippet or issue reference, as a quoted block.
4. **VALIDATION** — summary verdict: `APPROVED` or `REJECTED`, with `score`,
   `complete`, and `missing[]`. When rejected, `missing` feeds the next round
   directly, plus specific `next_actions`.

### Mandatory format

```
VERDICT:
FILES_REVIEWED:
  - path/to/file.ts: lines 45-67 (changed)
CHECKS:
  - typecheck: PASS
  - test suite: PASS (8/8)
  - lint: PASS
CODE:
  > // specific snippet or issue reference
VALIDATION:
  APPROVED — score: 1.0, complete: true, missing: []
  OR
  REJECTED — score: <0-1>, complete: false,
    missing:
      - [specific gap feeding the next round]
    next_actions:
      - [specific, actionable step per gap]
```

Rules:
- All four section headers (`FILES_REVIEWED:`, `CHECKS:`, `CODE:`, `VALIDATION:`)
  MUST be present, each on its own line, followed by a non-empty body.
- A section header with no body counts as missing → REJECT.
- `CHECKS` MUST enumerate concrete commands with PASS/FAIL, not "looks fine".
- `CODE` MUST quote the exact snippet under review or the exact issue — never a
  paraphrase.
- `VALIDATION` MUST start with `APPROVED` or `REJECTED` and MUST carry `score`,
  `complete`, and `missing`. If `REJECTED`, `missing` MUST list each gap and
  `next_actions` MUST give one actionable step per gap.

### Retry budget and feedback loop

- Each verdict round declares `retry_budget: <N> remaining: <M>` alongside the
  verdict (default budget 3, agreed with the task owner when lower).
- A REJECTED verdict returns `valid: false + feedback (the missing[] list) +
  remaining budget`; the next round addresses exactly that feedback, nothing else.
- Budget exhausted → stop reworking, report REJECTED with the remaining
  `missing[]` as the handoff. Never silently restart the budget.
- You self-report budget use; the harness only records what you declared.

### Requery on parse failure

When your verdict fails to parse (missing header, empty section), do not
assert "done" and do not restart the whole task. Issue one structured requery
to yourself, up to the retry budget:

```
REQUERY (attempt <k>/<N>):
  parse_error: <which header missing or empty>
  fix: <re-emit full verdict with all four sections non-empty>
```

Then re-emit the complete verdict block. A parse failure is a format fix,
never a content waiver — all four sections stay mandatory.

### Verdict validator

Completeness is machine-checkable with no LLM calls. The validator lives at
`scripts/lib/skills/verdict-schema.mjs` and exposes two functions:

- `parseVerdictText(text)` → extracts the four sections from a verdict block and
  records which headers were present.
- `validateVerdictCompleteness(parsed)` → returns
  `{ approved, missing_sections, empty_sections, next_actions }`. `approved` is
  `true` only when all four sections are present and non-empty.

Use the validator as a gate before asserting "done": if it returns
`approved: false`, the verdict is rejected and the listed `next_actions` must be
satisfied first.

Attribution

rexleimorexleimo
View sourceSee grades on GitHubMore from rexleimo →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

ucoz-landing-skill

Create and edit uCoz homepage landing pages via MCP: custom templates, hero sections, lead forms, navigation menus, SEO, and responsive layout. Includes a visual design system (style selection, layout/grid, section recipes, typography/spacing, color tokens, component states, icons, modern CSS/JS, motion, imagery, social proof, copy/voice, accessibility). Uses ucoz-mcp tools for templates, site file uploads, and site modules.

107 votes

Paperclip

Interact with the Paperclip control plane API for task coordination and governance. Use when checking assignments, updating issue status, posting comments, delegating work, managing routines, or calling Paperclip API endpoints.

953191 votes

Pptx

Presentation toolkit (.pptx). Create/edit slides, layouts, content, speaker notes, comments, for programmatic presentation creation and modification.

471861 votes

Daw Music

Digital Audio Workstation usage, music composition, interactive music systems, and game audio implementation for immersive soundscapes.

761 votes

Instantly Rdsthomas Mission Control

Instantly.ai cold email outreach API - manage campaigns, leads, accounts, and analytics. Use for cold email automation, lead management, campaign creation/monitoring, and email account warmup.

761 votes
View all in tools →