completion-verifier

completion-verifier is an agent for Claude Code from navapbc/digital-service-orchestra. It costs 35 tokens per session (8,516 once invoked), scanned B, original, Apache-2.0.

A verification agent that checks whether completed work meets its written success criteria and story completion requirements.

In plain words
What is it for?
Use it before closing epics or stories to confirm that each required outcome is demonstrably present in the implementation.
Why use it?
It separates checking whether the requested work was delivered from judging code quality or correctness.

Agent for Claude Code

Written for Claude Code: ${CLAUDE_PLUGIN_ROOT} variable. Also seen: model in frontmatter; mentions Claude Code.

Runs only inside its plugin — its command needs a path that Claude Code sets for a plugin’s own hooks and for nothing else. Install the plugin, not this.

Part of the dso plugin — 37 skills, 4 commands, 53 agents shipped together

Good fit Use it before closing epics or stories to confirm that each required outcome is demonstrably present in the implementation.

Compare 6 agents from other repositories ↓
Install

Getting it into your agent

This one installs as part of its plugin. Adding the marketplace and installing the plugin brings it with everything else the plugin ships.

Claude Code
/plugin marketplace add navapbc/digital-service-orchestra
Claude Code
/plugin install dso

Made for: Claude Code.

Or install dso, the plugin that ships this one along with the rest of its 37 skills, 4 commands, 53 agents.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for completion-verifier

README.md
[![agentmods](https://agentmods.dev/badge/agents/navapbc/digital-service-orchestra/completion-verifier/github.svg)](https://agentmods.dev/agents/navapbc/digital-service-orchestra/completion-verifier)
Your own site
<a href="https://agentmods.dev/agents/navapbc/digital-service-orchestra/completion-verifier"><img src="https://agentmods.dev/badge/agents/navapbc/digital-service-orchestra/completion-verifier/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for completion-verifier

Your own site · 80×15
<a href="https://agentmods.dev/agents/navapbc/digital-service-orchestra/completion-verifier"><img src="https://agentmods.dev/badge/agents/navapbc/digital-service-orchestra/completion-verifier.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 35 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 8,516 The whole file, excluding the scripts and references it only reads on demand.
Security scan B 2 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00035 $0.08516
Opus 5 $0.00017 $0.04258
Sonnet 5 $0.00007 $0.01703
Haiku 4.5 $0.00003 $0.00852

Measured 9d ago against content hash f2b2859b3e04, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-09, from the pricing page.

Security

Grade B, and why

completion-verifier scanned grade B with 2 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Reads agent configuration directoriesmediumAgent snooping

.claude/, .codex/, .gemini/ hold keys, settings and other credentials a mod has no legitimate need for.

grep -rl "<component-name>" ${CLAUDE_PLUGIN_ROOT}/skills/ ${CLAUDE_PLUGIN_ROOT}/scripts/ ${CLAUDE_PLUGIN_ROOT}/hooks/ .claude/scripts/ 2>/dev/null # shim-exempt: grep search path, not script invocation

Makes network callslowCapability

Not a fault in itself. Listed so you know the mod talks to something, and to what.

- **observable-behavior**: outcome only producible by running external commands, network calls, or end-to-end user flows (e.g., "installer completes within 10 minutes", "curl returns 200", "Claude Code launches"). Eviden
plugins/dso/agents/completion-verifier.md · 588 lines

How it starts

The opening of the file, as written. The whole thing — 588 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Completion Verifier

You are a dedicated completion verification agent. Your sole purpose is to answer the question: "Did we build what the spec says?" — not "Is the code correct?" You verify that each success criterion or done definition is demonstrably satisfied by the implementation. You do not evaluate code quality, correctness, or style.

Startup: Session HEAD Sync (worktree isolation fix)

When dispatched with isolation: "worktree", the Agent runtime creates your worktree branched from origin/main — NOT from the orchestrator's session HEAD. If the orchestrator injected SESSION_BRANCH and SESSION_HEAD into your prompt, sync to the session HEAD as your FIRST action before reading any source files. Bug a951-d6f2-0c21-443f tracks this.

if [[ -n "${SESSION_BRANCH:-}" && -n "${SESSION_HEAD:-}" ]]; then
    bash "${CLAUDE_PLUGIN_ROOT}/scripts/worktree-session-head-sync.sh"  # shim-exempt: internal orchestration script
    if [[ $? -ne 0 ]]; then
        echo "ERROR: worktree-session-head-sync.sh failed — aborting" >&2
        exit 1
    fi
elif [[ -n "${SESSION_BRANCH:-}" || -n "${SESSION_HEAD:-}" ]]; then
    echo "WARNING: SESSION_BRANCH/SESSION_HEAD partially set — skipping worktree sync" >&2
fi

When both are unset (orchestrator on main, no session in flight), do nothing — your default origin/main worktree is correct.

Guiding Principle

The question you answer is: did we build what the spec says?

This is distinct from code review. You do NOT ask: is the code correct? Is the code well-written? Does it follow best practices? Those questions are answered by the code review gate and test gate, which are explicitly out of scope for this agent.

Read the full file on GitHub · 588 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 9d ago First seen · 588 lines · 35 tokens per session scan B f2b2859b3e04

Subscribe to this mod's changes

completion-verifier is an agent published in the GitHub repository navapbc/digital-service-orchestra (6 stars, last pushed yesterday), licensed Apache-2.0. It adds 35 tokens to every session and 8,516 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it B with 2 findings (reads agent configuration directories, makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.