Skills executor-verification
๐Ÿ“ฆ

executor-verification

Content revision r1 Medium Risk โš™๏ธ External commands๐Ÿ“ Filesystem access

Verify Completion Claims With Recorded Evidence

Completion claims can hide failed, skipped, or untested requirements. This skill guides requirement-level verification with observed output, commit-bound evidence, and explicit human acceptance.

Supports: Claude Codex Code(CC)
๐Ÿ“Š 69 Adequate

Install with my Agent

Copy this request to your Agent. It includes the canonical Skill page and manifest.

Agent request
Review the Skillstore skill "executor-verification" from https://skillstore.io/skills/atri10-executor-verification.md and its manifest at https://skillstore.io/api/skills/atri10-executor-verification/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.

Your Agent should still show its plan and request any confirmation required by the security policy.

Agent-readable resources

Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.

Test it

Using "executor-verification". Verify an integration criterion that requires HTTP 409 with no partial write.

Expected outcome:

  • Illustrative outcome: FAILED.
  • Observed: the integration test received HTTP 500 instead of HTTP 409.
  • Required: HTTP 409 with no partial write.
  • Next step: return the mismatch to execution and reverify after the fix.

Using "executor-verification". Summarize a verification round where one manual criterion was never checked.

Expected outcome:

  • Illustrative summary: 11 PROVEN, 0 FAILED, 1 NOT-RUN, 0 UNAVAILABLE.
  • Exception: the manual criterion has no recorded observation.
  • Completion remains unproven. Present the exception for human acceptance or further verification.

Using "executor-verification". Run a criterion when the evidence runner lacks a required credential.

Expected outcome:

  • Illustrative runner outcome: NOT-RUN.
  • Evidence: none; no run and no evidence file.
  • Reason: the criterion requires a credential that was not provided.
  • Do not inspect the environment for secrets or assume the criterion passes.

Security Audit

Medium Risk
v1 โ€ข 10/5/2026 Open versioned report

All 155 static findings are false positives involving Markdown formatting, intended local verification, companion paths, or protective secret-handling guidance. Two semantic workflow risks concern unisolated regression reverts and retained evidence after secret-scan failures. No evidence found of malicious prompt injection or exfiltration; companion helper implementations are outside the two reviewed files.

2
Files scanned
819
Lines analyzed
0
Review items
0
False positives ignored

Confirmed security concerns (2)

Medium
Regression Verification Reverts Fixes Without Isolation
The regression workflow says "Revert the fix" and "Restore the fix" without an isolated worktree or recovery checkpoint. Following it in a shared worktree can discard edits or disrupt concurrent work.
The ordered steps explicitly require reverting and restoring code, but provide no isolation or preservation procedure. No destructive command is specified, so damage depends on implementation.
Medium
Secret Recovery Does Not Address Retained Evidence Copies
After a secret finding, the runner says "redact and rewrite" through the evidence helper. The storage policy creates new attempt files instead of overwriting, so sensitive originals may remain in tracked evidence.
Recovery requests another write while the documented helper preserves earlier attempts. No cleanup or quarantine of detected sensitive originals is specified; the helper implementation is outside this audit.
Audited by: codex
Share & cite this report

Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.

Open versioned report
Security Assessment

Copy report link

https://skillstore.io/skills/atri10-executor-verification/audits/1?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/atri10-executor-verification/security.svg)](https://skillstore.io/skills/atri10-executor-verification?utm_source=security_passport_badge)

HTML badge

<a href="https://skillstore.io/skills/atri10-executor-verification?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/atri10-executor-verification/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Embed card

<iframe src="https://skillstore.io/embed/skills/atri10-executor-verification.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Academic citations (APA ยท BibTeX ยท CFF)

APA citation

atri10. (2026). executor-verification security audit report (audit version 1) [Author version unspecified]. Skillstore. https://skillstore.io/skills/atri10-executor-verification/audits/1

BibTeX citation

@techreport{atri10-atri10-executor-verification-2026, author = {atri10}, title = {executor-verification security audit report (audit version 1)}, institution = {Skillstore}, year = {2026}, number = {1}, url = {https://skillstore.io/skills/atri10-executor-verification/audits/1}, note = {Author version unspecified} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "executor-verification security audit report (audit version 1)" version: "unspecified" type: report authors: - name: "atri10" date-released: "2026-10-05" url: "https://skillstore.io/skills/atri10-executor-verification/audits/1" identifiers: - type: other value: "skillstore:atri10-executor-verification:audit:1" description: "Skillstore immutable audit report identifier"

Skillstore Score

Why this score Evidence Confidence: Medium
55
Architecture
85
Maintainability
87
Content
65
Community
87
Spec Compliance

What You Can Build

Verify a Feature Before Handoff

Walk existing acceptance criteria, gather suitable evidence, and present unresolved requirements before a feature handoff.

Review Requirement Coverage

Compare observed test and smoke outcomes with requirements, without treating a passing unit suite as full feature proof.

Coordinate Agent Verification

Dispatch one evidence runner per criterion, inspect the returned artifact, and route failures back to the owning implementation plan.

Try These Prompts

Check One Requirement
Verify criterion [reference] in [verification document] at the current state. Report its requirement, named method, observed output, and status without changing code.
Build an Outcomes Round
Walk every criterion in [verification document]. Record state, commands, outcomes, and evidence citations. Summarize all four statuses and stop for human acceptance.
Dispatch an Evidence Runner
Prepare one runner for [criterion] using the provided template. Fill every placeholder, select a model explicitly, and verify prerequisites before dispatch.
Reverify After a Shared-Code Fix
Review fix [commit] against the existing ledger. Identify affected criteria and append a new round. Use isolated regression checks and scan retained evidence before committing.

Best Practices

  • Record the exact tested state and match each requirement to the evidence type its strategy names.
  • Use an isolated worktree for regression reverts and preserve all existing user changes.
  • Redact before capture, scan every retained evidence attempt, and resolve sensitive originals before tracking or committing.

Avoid

  • Treating passing unit tests, clean review reports, or expected output as proof of every requirement.
  • Changing code during verification to obtain a passing result without a separate fix and new evidence round.
  • Hiding FAILED, NOT-RUN, or UNAVAILABLE outcomes when presenting the completion summary.

Frequently Asked Questions

What does this skill verify?
It guides checks against existing verification criteria and records observed outcomes. It does not invent acceptance criteria or guarantee software correctness.
Can I use it with Claude, Codex, or Claude Code?
The report lists all three tools. The workflow still requires command execution, repository access, and the referenced Executor dependencies.
Are the helper scripts included?
No. The reviewed skill contains instructions and an evidence runner template. Companion Executor helpers are referenced separately and were not audited here.
What happens when a check cannot run?
Record NOT-RUN or UNAVAILABLE with the exact blocker. Missing evidence is not a pass, and residual gaps require explicit human acceptance.
Does verification fix failing code?
No. Failures return to execution. After fixes land, append a new round and reverify every criterion the change could affect.
What precautions apply to stored evidence?
Redact sensitive output before writing and scan retained files. A redacted replacement does not guarantee earlier sensitive attempts were removed.

Developer Details

Author

atri10

License

MIT

Skillstore revision

r1

Version notice

The author did not declare a version.

Ref

6d0b11444384184b7ae743742a7e233a9a705cd9

Maintenance freshness

10/6/2026

Usage

0 downloads ยท 0 views

File structure

๐Ÿ“„ evidence-runner-prompt.md

๐Ÿ“„ SKILL.md

More from atri10

View all
View all