Teams often declare work complete without proving every requirement, path, review, and gap. This skill creates a traceable chain from intent to evidence and a defensible delivery decision.
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Agent request
Review the Skillstore skill "tracing-requirements-to-verification" from https://skillstore.io/skills/solohic-tracing-requirements-to-verification.md and its manifest at https://skillstore.io/api/skills/solohic-tracing-requirements-to-verification/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.
Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Using "tracing-requirements-to-verification". A checkout change has three requirements, six acceptance items, one missing end-to-end path test, and a review finding about rollback evidence.
Expected outcome:
The requirements may remain implemented, but delivery is incomplete. Add the missing journey evidence, classify rollback evidence as a cross-cutting constraint, assign an owner, and rerun the completion gate.
Using "tracing-requirements-to-verification". A team has passing unit tests and a host status of shipped, but no target-specific evidence for two acceptance items.
Expected outcome:
Keep the affected acceptance items implemented rather than verified.
Do not infer completion from passing tests or host lifecycle status.
Record the missing evidence and the verification needed to close the gap.
Using "tracing-requirements-to-verification". A reviewer proposes an unrelated reporting improvement during a release review.
Expected outcome:
Classify it as an optional enhancement unless an owner accepts a scope amendment. Keep it out of the current closure decision.
All 220 static findings are false positives caused by documentation syntax and ordinary governance language. The reviewed files contain no executable shell usage, network reconnaissance, or prompt-injection instructions; no net-new semantic security finding was identified.
No confirmed security findings were detected by the latest completed static and semantic audit. This does not prove the skill has no side effects.
Audited by: codex
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
solohic. (2026). tracing-requirements-to-verification security audit report (audit version 1) [Author version unspecified]. Skillstore. https://skillstore.io/skills/solohic-tracing-requirements-to-verification/audits/1
BibTeX citation
@techreport{solohic-solohic-tracing-requirements-to-verification-2026,
author = {solohic},
title = {tracing-requirements-to-verification security audit report (audit version 1)},
institution = {Skillstore},
year = {2026},
number = {1},
url = {https://skillstore.io/skills/solohic-tracing-requirements-to-verification/audits/1},
note = {Author version unspecified}
}
CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "tracing-requirements-to-verification security audit report (audit version 1)"
version: "unspecified"
type: report
authors:
- name: "solohic"
date-released: "2026-09-19"
url: "https://skillstore.io/skills/solohic-tracing-requirements-to-verification/audits/1"
identifiers:
- type: other
value: "skillstore:solohic-tracing-requirements-to-verification:audit:1"
description: "Skillstore immutable audit report identifier"
Skillstore Score
Why this scoreEvidence Confidence: Medium
45
Architecture
85
Maintainability
87
Content
65
Community
83
Spec Compliance
What You Can Build
Plan a Multi-Step Feature
Turn feature requirements into acceptance items, verification methods, implementation mappings, and explicit delivery gaps.
Review a Release Packet
Audit evidence, journeys, review coverage, unresolved gaps, and completion gates before a release decision.
Coordinate Cross-Agent Work
Keep scope, ownership, evidence, review state, and continuation conditions consistent across parallel contributors.
Try These Prompts
Create a Basic Trace
Map these requirements to acceptance criteria, implementation tasks, verification methods, and known evidence gaps: [paste requirements].
Assess Journey Applicability
Review this delivery scope and decide whether an actor journey is required. Explain the path dependencies and required evidence: [paste scope].
Classify Review Findings
Classify each review finding as required-gap, evidence-gap, cross-cutting-constraint, scope-amendment, optional-enhancement, or quality-defect. Link each finding to affected trace objects: [paste findings].
Run the Completion Gate
Audit this closure packet against the completion gate. Check required children, requirement evidence, journey evidence, review governance, effective gates, gaps, and continuation. State the supported disposition and missing actions: [paste packet].
Best Practices
Assign stable IDs before implementation begins.
Keep item evidence separate from journey path evidence.
Record every material gap with an owner and close condition.
Avoid
Treating passing tests as proof of every requirement.
Using host status to infer trace completion.
Turning every review suggestion into immediate scope.
Frequently Asked Questions
What does this skill trace?
It traces intent through requirements, acceptance items, implementation work, evidence, reviews, gaps, and delivery decisions.
When is a journey trace needed?
Use one when an actor must follow ordered or causally connected steps to reach an accepted outcome.
Does it run tests for me?
No. It defines evidence needs and evaluates supplied status and artifacts.
Can a passing test verify several requirements?
Only when separate target-specific evidence claims show what the test proves for each requirement.
How are review findings handled?
Each finding is classified and linked to affected requirements, acceptance items, journeys, gaps, or scope decisions.
Can it replace release governance?
No. It complements host-native gates and preserves stronger security, review, and release controls.