VerifySAFE
Runnable ClaudeCode source code
Overview
Runnable ClaudeCode source code
1667a2c1c2d7OBSERVED · 2026-10-07Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- description: Verify a code change by running the app, the relevant command, or a focused server flow and reporting concrete evidence. --- # Verify Use this skill when a task is not finished until the change is exercised. ## Goal Produce a short verification result grounded in execution, not inference. Prefer the narrowest check that proves the changed behavior works. ## Workflow 1. Identify the changed surface area. 2. Pick the smallest realistic verification path. 3. Run the relevant command or request flow. 4. Capture the observable result: exit status, key output, HTTP status, or changed behavior. 5. Report what passed, what was not verified, and any remaining risk. ## Rules - Do not claim success without running something. - Prefer focused checks over broad smoke tests. - If the repo has no formal test target, use the nearest runnable workflow. - If a check is blocked by environment limits, state that explicitly. - Include exact commands when they are useful to repeat the verification. ## Verification Patterns ### CLI changes - Run the exact command path affected by the edit. - Check help text, flags, output formatting, exit codes, and side effects. - For interactive flows, prefer the most scriptable subcommand first. See `examples/cli.md`. ### Server changes - Start only the needed service. - Exercise the changed route, handler, or background path. - Validate status code, response shape, logs, and failure handling. See `examples/server.md`. ## Reporting Format - `Verified:` what you ran and what passed. - `Not verified:` anything you could not run. - `Risk:` the main remaining uncertainty, if any.
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (3)
curl -i http://127.0.0.1:PORT/health
Gates applied: no_behavioural_pass, no_license.
1667a2c1c2d7full audit observations/trust-audit/skill/oboard__verify.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 1667a2c1c2d7 | SAFE | B | 89 | first audit |
Questions
What does the Verify skill do?
Runnable ClaudeCode source code
Is Verify safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Verify access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Verify work with?
Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (1667a2c1c2d7), read on 2026-10-07. The repository is watched, and a new audit runs when it changes — this is the first audit.