create-prove

create-prove is a skill for Claude Code, Codex from aeonfun/aeon. It costs 21 tokens per session (1,096 once invoked), scanned A, original, MIT.

A verification tool for a specific pull request that changes one runnable Aeon skill. It runs that skill through the repository's real GitHub Actions workflow and attaches evidence tied to the exact commit.

In plain words
What is it for?
Use it to validate an Aeon skill change, confirm a successful correlated Actions run, and attach a proof record to the pull request.
Why use it?
A code review or a green-looking change does not prove that the workflow works. This tool requires a matching open pull request and commit before posting proof.

Skill for Claude CodeCodex

Written for no agent in particular: nothing here depends on one.

Good fit Use it to validate an Aeon skill change, confirm a successful correlated Actions run, and attach a proof record to the pull request.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/aeonfun/aeon/create-prove
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add aeonfun/aeon --skill create-prove
Clone the repo
git clone --depth 1 https://github.com/aeonfun/aeon

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for create-prove

README.md
[![agentmods](https://agentmods.dev/badge/skills/aeonfun/aeon/create-prove/github.svg)](https://agentmods.dev/skills/aeonfun/aeon/create-prove)
Your own site
<a href="https://agentmods.dev/skills/aeonfun/aeon/create-prove"><img src="https://agentmods.dev/badge/skills/aeonfun/aeon/create-prove/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for create-prove

Your own site · 80×15
<a href="https://agentmods.dev/skills/aeonfun/aeon/create-prove"><img src="https://agentmods.dev/badge/skills/aeonfun/aeon/create-prove.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 21 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,096 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00021 $0.01096
Opus 5.5 $0.00008 $0.00438
Sonnet 5.5 $0.00004 $0.00219
Haiku 4.5 $0.00002 $0.00110

Measured 15d ago against content hash c9d80641f15d, method: parsed. Prices are Anthropic first-party input rates as of 2026-10-04, from the pricing page.

Security

Grade A, and why

create-prove scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 15d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/create-prove/SKILL.md · 70 lines

How it starts

The opening of the file, as written. The whole thing — 70 lines — stays where its author put it; the contents beside it link to each section on GitHub.

${var} - Required immutable target in the form owner/repo#pr@40-character-lowercase-sha.

Today is ${today}. Prove the behavior of one Aeon-shaped change by running the changed skill through the target repository's real aeon.yml workflow. A green diff review is not proof. A successful, correlated Actions run is proof.

Scope

This first implementation supports Aeon-shaped pull requests that change exactly one runnable skills/<slug>/SKILL.md. It does not launch conventional applications and it does not guess which skill represents a workflow-only or configuration-only change. Unsupported target shapes must fail closed without posting a proof receipt.

Never prove create-prove by recursively dispatching itself. Exit PROVE_UNSUPPORTED instead.

Steps

  1. Parse ${var} into target=owner/repo#pr and expected_sha. Reject any value outside the exact grammar above with PROVE_INVALID_TARGET.
  2. Read the PR through gh api. Require all of the following:
    • the PR is open;
    • its current head.sha equals expected_sha;
    • its head branch belongs to the same repository, because gh workflow run --ref cannot execute an untrusted fork branch in the base repository;
    • exactly one changed path matches skills/<slug>/SKILL.md;
    • the slug is not create-prove. Any mismatch exits PROVE_UNSUPPORTED or PROVE_STALE without a receipt.
  3. Inspect the changed skill's frontmatter and instructions. Choose the smallest real, non-destructive variable that exercises the changed behavior. If no safe real invocation exists, exit PROVE_UNSAFE rather than inventing evidence. Do not use synthetic credentials or a dry-run mode.
  4. Dispatch the target branch's workflow by filename, with a unique correlation ID whose dispatch_id must start with the literal prefix prove- — .github/workflows/aeon.yml's commit-skip guard only recognizes that exact prefix to know this run is being proved, not a normal dispatch, and must not commit or push to the branch it's proving. Getting this prefix wrong silently defeats the immutable-head guarantee this whole skill exists to provide:
    dispatch_id="prove-${pr_number}-$(date -u +%Y%m%dT%H%M%SZ)-${RANDOM}"
    gh workflow run aeon.yml --repo "$repo" --ref "$head_branch" \
      -f skill="$skill" -f var="$proof_var" -f dispatch_id="$dispatch_id"
    
    Discover the run only by the exact correlated run title, using the same rule as chain-runner.yml. Never select merely the newest run for that skill.
  5. Wait up to 30 minutes. Require status=completed and conclusion=success. Fetch the run log and the captured skill output. Confirm the output is non-empty and does not contain _No output captured._. A successful Actions wrapper with no captured behavior is PROVE_MISSING_EVIDENCE.
  6. Re-read the PR and require its head SHA still equals expected_sha.
  7. Post one PR comment containing a concise description of the exercised path, the run URL, a short output excerpt, and exactly one final machine receipt:
    <!-- aeon-proof:{"schema":1,"target":"owner/repo#N","sha":"<sha>","kind":"aeon-skill","skill":"<slug>","evidence_run_id":123,"evidence_url":"https://github.com/owner/repo/actions/runs/123","verdict":"proven"} -->
    
    Construct the JSON with jq -cn, then render it on one line. Do not post the receipt until every gate above passes.
  8. End with the target, skill, run ID, run URL, and PROVE_VERDICT=proven in the captured output.

Read the full file on GitHub · 70 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 15d ago First seen · 70 lines · 21 tokens per session scan A c9d80641f15d

Subscribe to this mod's changes

create-prove is a skill published in the GitHub repository aeonfun/aeon (762 stars, last pushed today), licensed MIT. It adds 21 tokens to every session and 1,096 once invoked, about $0.0001 per session on Opus 5.5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-19.

Related

Other skills, from other repositories

git-worktree

Create isolated git worktrees for feature development without switching branches.

FlorianBruniaux/claude-code-plugins · 15 tokens

git-worktree-status

Check status of background verification tasks running in a git worktree.

FlorianBruniaux/claude-code-plugins · 17 tokens

workflow-patterns

Use this skill when implementing tasks according to Conductor's TDD workflow, handling phase checkpoints, managing git commits for tasks, or understanding the verification protocol.

FluxonLab/Skillry · 35 tokens

agent-framework-py-release

Use when cutting a Python release for the microsoft/agent-framework monorepo. Triggers on "bump py versions", "cut a python release", "prepare release PR for python", "release py packages", "bump python to X.Y.Z", or similar requests to bump Python package versions and prepare a release PR. Handles all four lifecycle…

microsoft/agent-framework · 103 tokens

model-merging

Merge multiple fine-tuned models using mergekit to combine capabilities without retraining. Use when creating specialized models by blending domain-specific expertise (math + coding + chat), improving performance beyond single models, or experimenting rapidly with model variants. Covers SLERP, TIES-Merging, DARE, Task…

davila7/claude-code-templates · 73 tokens

foundry-hosted-agent-validation

Step-by-step process for validating a Python Foundry hosted agent sample (under python/samples/04-hosting/foundry-hosted-agents/) end to end — running it locally (native runtime and azd ai agent run) and after deploying it to an Azure AI Foundry project with azd. Use this when asked to validate a hosted agent sample.

microsoft/agent-framework · 82 tokens