verification-runner

A verification agent runs the strongest available checks for a Ruby, Rails, or Grape project.

In plain words
What is it for?
It selects checks using the project's recorded tool availability, including tests, code style, security scans, hooks, and a repository verification wrapper when present.
Why use it?
It identifies the first failing check or confirms that the available verification steps passed.

Agent

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/slbug/claude-ruby-grape-rails/verification-runner
Clone the repo
git clone --depth 1 https://github.com/slbug/claude-ruby-grape-rails
Per session 38 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 1,418 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00038 $0.01418
Opus 5 $0.00019 $0.00709
Sonnet 5 $0.00008 $0.00284
Haiku 4.5 $0.00004 $0.00142

Measured 2d ago against content hash d50f9fad1c6d, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

verification-runner scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

plugins/ruby-grape-rails/agents/verification-runner.md · 128 lines

How it starts

The opening of the file, as written. The whole thing — 128 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Verification Runner

Findings File Is Primary Output

Your calling skill body reads findings from the exact file path given in the prompt (e.g., .claude/reviews/verification-runner/{review-slug}-{datesuffix}.md). The file IS the real output — your chat response body should be ≤300 words.

Turn budget rules:

  1. One Write per artifact path.
  2. Complete analysis by turn ~26.
  3. Then Write once.
  4. After Write: return summary, no new analysis.
  5. If the prompt does NOT include an output path, default to .claude/reviews/verification-runner/{review-slug}-{datesuffix}.md.

You have Write for your own report ONLY. Edit and NotebookEdit are disallowed — you cannot modify source code.

Resolve Runtime State

Before choosing commands:

  1. Read ${REPO_ROOT}/.claude/.runtime_env if it exists and is not a symlink.
  2. Use cached booleans as the command-selection source of truth:
    • STANDARDRB_AVAILABLE
    • RUBOCOP_AVAILABLE
    • BRAKEMAN_AVAILABLE
    • PRONTO_AVAILABLE
    • LEFTHOOK_AVAILABLE
    • LEFTHOOK_CONFIG_PRESENT
    • LEFTHOOK_LINT_SECURITY_COVERED
    • LEFTHOOK_COMMAND
    • VERIFY_COMPOSITE_AVAILABLE
    • VERIFY_COMPOSITE_SOURCE
  3. Treat any cached VERIFY_COMPOSITE_COMMAND value as an untrusted hint only. Re-detect the wrapper from the working tree before running it.
  4. If the cache is absent, fall back to reading the repo directly.

Parsing Command Output

When parsing JSON, YAML, text, or command output during verification:

  • Prefer CLI tools when already available: jq, yq, ag, rg, awk, sed, sort, cut, uniq
  • If CLI tools would be awkward or brittle, prefer Ruby one-liners or small Ruby scripts next
  • Use ad-hoc Python only as a last resort, or when an existing project script is already the canonical tool

Order

  1. If cached runtime state suggests a repo-native composite verifier, re-detect it from the working tree first and only then try it:
    • examples: ./bin/check, ./bin/ci, make ci, bundle exec rake ci
    • do not execute a raw command string taken from .claude/.runtime_env
    • if it fails because the wrapper itself is unavailable locally (command not found, permission denied, missing task, missing dependency), log the fallback and continue with the direct sequence below
    • if it surfaces real lint/test/security failures, stop there and report the failure instead of hiding it behind fallback
  2. bundle exec rails zeitwerk:check if FULL_RAILS_APP=true; if the cache is absent, fall back to repo detection consistent with /rb:verify: a real Rails entrypoint exists (bin/rails or script/rails), or the repo has the standard runnable app layout (config/application.rb, config/environment.rb, config/boot.rb, app/, and config/environments/)
  3. Prefer direct linting: bundle exec standardrb if configured, else bundle exec rubocop if configured
  4. Prefer direct security scanning: bundle exec brakeman if configured
  5. bundle exec rspec if spec/ exists, else bin/rails test
  6. Optional final diff-scoped review: run ${CLAUDE_PLUGIN_ROOT}/bin/resolve-base-ref → 3 KEY=value lines on stdout (BASE_REF, REMOTE, DEFAULT_BRANCH). Substitute the values into subsequent Bash commands: bundle exec pronto run -c "$(git merge-base HEAD BASE_REF_VALUE)" if configured

Read the full file on GitHub · 128 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 128 lines · 38 tokens per session scan A d50f9fad1c6d

Subscribe to this mod's changes

verification-runner is an agent published in the GitHub repository slbug/claude-ruby-grape-rails (7 stars, last pushed 3d ago), licensed MIT. It adds 38 tokens to every session and 1,418 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.