Atlas / Skills / leoyeai / Reikys Hallucination Guard

Reikys Hallucination GuardSAFE

skills/leoyeai/reikys-hallucination-guard

🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai

Verdict
SAFE
Grade
B
Trust score
89 /100
Version
1.0.0
Hosts
1 documented
License
MIT
Stars
2,160
01

Overview

🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai

Read from source at commit 4f3b4a2a472eOBSERVED Ā· 2026-10-08
02

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
openclawmentioned
03

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: hallucination-guard
version: 1.0.0
author: reikys
description: Execution-based verification guardrail with 14 check items for AI agent output
tags: [verification, quality, safety, guard, hallucination]
trigger: "hallucination check"
---

# šŸ›”ļø hallucination-guard

> **Solving the biggest trust problem with AI agents.**
> Not with "double-check that" prompts, but with 14 execution-based verification items.

---

## šŸŽÆ Problem Definition

AI agents carry the following trust issues:

| Problem Type | Example |
|-------------|---------|
| **Path hallucination** | References non-existent files/directories as if they exist |
| **Command hallucination** | Describes uninstalled binaries as if they run normally |
| **Library hallucination** | Writes code that `import`s packages that don't exist on npm/pip |
| **Numerical hallucination** | States unsourced statistics/percentages as fact |
| **Completeness hallucination** | Reports "done" while leaving TODO/PLACEHOLDER behind |
| **Consistency hallucination** | Uses different names for the same concept within a document |

### Limitations of Existing Solutions

- **truth-check, verification-before-completion**: Just tells the agent "check again" — still hallucination-based
- **hallucination-guard**: 14 concrete items Ɨ executable commands Ɨ structured PASS/FAIL report

---

## ⚔ Quick Start

### 1. Trigger Method
Call anytime during agent conversation with the following phrases:

```
hallucination check
hallucination check on <target file/path>
hallucination check --scope=fact,completeness
```

### 2. Auto-Execution Method
Add to the system prompt so the agent automatically runs this skill before completing a task:

```
Before completing any task, you must run all 14 checks from the hallucination-guard SKILL.md,
output the PASS/FAIL report, and fix any FAIL items.
```

### 3. Quick Check (3-Minute Version)
When the full 14 items feel like too much, run only the essential 5:

```bash
# Run only H-1, H-2, H-9, H-10, H-12
hallucination check --quick
```

---

## šŸ“‹ 14 Check Items in Detail

### šŸ”µ Fact Verification (H-1 ~ H-5)

---

#### H-1: File Path Existence Verification

**Purpose:** Verify that files/directories referenced by the agent actually exist

**Verification Commands:**
```bash
# macOS / Linux
stat <path>
ls -la <path>

# Existence check only (exit code based)
[ -e "<path>" ] && echo "PASS: $path exists" || echo "FAIL: $path not found"

# Batch check for multiple paths
for p in path1 path2 path3; do
  [ -e "$p" ] && echo "āœ… $p" || echo "āŒ $p"
done
```

**Windows (PowerShell):**
```powershell
Test-Path "C:\path\to\check"
```

**Pass Criteria:** All referenced paths confirmed to exist via `stat`/`Test-Path` → PASS

---

#### H-2: Command/Binary Existence Verification

**Purpose:** Verify that CLI commands used in code or documentation are actually installed

**Verification Commands:**
```bash
# macOS / Linux
which <command>
command -v <command>

# Example: batch check for multiple binaries
for cmd in git node python3 docker jq; do
  command -v "$cmd" &>/dev/null \
    && echo "āœ… $cmd: $(which $cmd)" \
    || echo "āŒ $cmd: not installed"
done
```

**Windows (PowerShell):**
```powershell
Get-Command <command> -ErrorAction SilentlyContinue
```

**Pass Criteria:** All CLI commands appearing in documents/code confirmed via `command -v` → PASS

---

#### H-3: URL Validity Check (Optional)

**Purpose:** Verify that links/API endpoints embedded in documentation are actually accessible

**Verification Commands:**
```bash
# Check HTTP status code (5-second timeout)
curl -sI --max-time 5 <url> | head -1

# Batch check script
urls=(
  "https://example.com/api"
  "https://docs.example.com"
)
for url in "${urls[@]}"; do
  status=$(curl -sI --max-time 5 "$url" | head -1 | awk '{print $2}')
  if [[ "$status" =~ ^[23] ]]; then
    echo "āœ… $url → HTTP $status"
  else
    echo "āŒ $url → HTTP $status (or unreachable)"
  fi
done
```

**Note:** False positive/negative possible depending on network environment. Manual verification recommended for internal network URLs.

**Pass Criteria:** External reference URLs respond with 2xx/3xx → PASS (optional execution)

---

#### H-4: Code Syntax Validity Check

**Purpose:** Verify that code generated by the agent is actually parseable

**Verification Commands:**

**Python:**
```bash
python3 -c "
import ast, sys
with open('target.py') as f:
    src = f.read()
try:
    ast.parse(src)
    print('āœ… Python syntax valid')
except SyntaxError as e:
    print(f'āŒ SyntaxError: {e}')
    sys.exit(1)
"
```

**JavaScript/TypeScript:**
```bash
# Node.js
node --check target.js

# TypeScript
npx tsc --noEmit target.ts
```

**JSON:**
```bash
jq . target.json > /dev/null && echo "āœ… JSON valid" || echo "āŒ JSON parse failed"
```

**YAML:**
```bash
python3 -c "import yaml; yaml.safe_load(open('target.yaml'))" \
  && echo "āœ… YAML valid" || echo "āŒ YAML parse failed"
```

**Shell:**
```bash
bash -n target.sh && echo "āœ… Shell syntax valid" || echo "āŒ Shell syntax error"
```

**Pass Criteria:** All generated code files pass their respective language parsers → PASS

---

#### H-5: Numerical Data Cross-Verification

**Purpose:** Verify that statistics/numbers mentioned by the agent are substantiated

**Verification Method:**
```
Checklist:
ā–” Is the source (URL, paper, official docs) specified for the number?
ā–” Can the source be cross-verified with 2+ references?
ā–” Is the data current? (check date)
ā–” Is uncertainty appropriately expressed? ("approximately X%", "roughly Nx")
```

**Auto-detection Pattern (grep):**
```bash
# Detect unsourced number patterns
grep -En "[0-9]+%" <file> | grep -v "http\|source\|ref\|reference"
grep -En "[0-9]+(x|times)" <file> | grep -v "http\|source"
```

**Pass Criteria:** All numbers have cited sources or are labeled "needs verification:" → PASS

---

### 🟔 Consistency (H-6 ~ H-8)

---

#### H-6: No Self-Contradiction

**Purpose:** Verify there are no conflicting claims within the same document

**Verification 
04

Trust audit

SAFEgrade B Ā· trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (1)

MEDIUMObfuscation / stealth Ā· obf.base64_blob Ā· CWE-506, CWE-94
skills/compdf-conversion-cli/scripts/license.xml:9
<key>k5Ey9KFlkqpj+SDkUw+5ED9lTA3En/qUi0zdrydUCH3kMWTE3Eh65NXnFCaxlY2omY2JHnlEoK7Li7oOEvM7eG5VPdcO/sFlMfoCRdnLYdepJ+uLzYwOWR8W4yQVve/clxVFTVRL4DFleKInGdpAxIbHZT2yi4ADAMENls1N1XSLojRuqXePXDeAT/4Mv4TTx0s

Gates applied: no_behavioural_pass.

Audited 2026-10-08 Ā· audit v0.4.1 Ā· source sha 4f3b4a2a472efull audit observations/trust-audit/skill/leoyeai__reikys-hallucination-guard.json Ā· Report an issue / request a re-scan
05

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-084f3b4a2a472eSAFEB89first audit
06

Questions

What does the Reikys Hallucination Guard skill do?

🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai

Is Reikys Hallucination Guard safe to install?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.

What can Reikys Hallucination Guard access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

Which assistants does Reikys Hallucination Guard work with?

Its documentation mentions openclaw. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (4f3b4a2a472e), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement