Adr VerifyCAUTION
🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native Claude Code / Codex / Hermes and many more Integrated
Overview
🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native Claude Code / Codex / Hermes and many more Integrated
ef7d4f0535e5OBSERVED · 2026-09-25What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: adr-verify description: Read back adr-patterns + adr-edges namespaces, surface dangling refs / supersede cycles / status mismatches; exit 1 on cycles argument-hint: "" allowed-tools: Bash mcp__plugin_ruflo-core_ruflo__memory_list mcp__plugin_ruflo-core_ruflo__memory_retrieve --- # ADR Verify Companion to `adr-index`. After import, reads the persisted graph and surfaces integrity issues: - **Dangling refs** — edge points at an ADR ID that doesn't exist in `adr-patterns`. Common cause: the referenced ADR is in a sibling repo or got deleted. - **Supersede cycles** — `ADR-A supersedes ADR-B` and `ADR-B supersedes ADR-A` (or longer cycles). Always data corruption. - **Status mismatches** — an ADR is the source of a `supersedes` edge but its own status isn't `Superseded`. Usually a missed status update during a successor ADR's promotion. **What this skill cannot catch:** an `adr-patterns` row for an ADR that was deleted from disk and has zero edges referencing it or from it — invisible to every check above (issue #2666). If the reported ADR count looks higher than what's actually on disk, run `adr-reindex`, not `adr-verify` again. ## When to use - Right after `adr-index` to confirm the graph is healthy - In CI as a fail-closed gate (`VERIFY_STRICT=1` exits 1 on any issue) - Before publishing an ADR-related release ## Steps ```bash node plugins/ruflo-adr/scripts/verify.mjs ``` Optional env: - `VERIFY_FORMAT=json` — JSON instead of markdown - `VERIFY_STRICT=1` — exit 1 on ANY issue (default: only on cycles) ## Exit codes | Code | Meaning | |---|---| | `0` | Graph healthy (or dangling refs / status mismatches present in non-strict mode) | | `1` | Supersede cycle detected, OR strict mode + any issue present | ## Cross-references - `adr-index` — populates the data this skill verifies - `scripts/import.mjs` — has its own dry-run validation; this skill is the read-back companion - `adr-reindex` — reconciles a deleted ADR that `adr-verify` cannot detect
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (4)
crates
plugin/agents
plugin/commands
plugin/skills
Gates applied: no_behavioural_pass.
ef7d4f0535e5full audit observations/trust-audit/skill/ruvnet__adr-verify.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-25 | ef7d4f0535e5 | CAUTION | B | 89 | first audit |
Questions
What does the Adr Verify skill do?
🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native Claude Code / Codex / Hermes and many more Integrated
Is Adr Verify safe to install?
With care. The audit graded it B (89/100) and found 4 things worth knowing before you trust this skill, listed below with the exact line each was found on.
What can Adr Verify access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
How current is this page?
The grade is for one exact copy of the source (ef7d4f0535e5), read on 2026-09-25. The repository is watched, and a new audit runs when it changes — this is the first audit.