Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add AtlasOmnia/donna-starter --skill source-verificationgit clone --depth 1 https://github.com/AtlasOmnia/donna-starterWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/atlasomnia/donna-starter/source-verification)<a href="https://agentmods.dev/skills/atlasomnia/donna-starter/source-verification"><img src="https://agentmods.dev/badge/skills/atlasomnia/donna-starter/source-verification/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/atlasomnia/donna-starter/source-verification"><img src="https://agentmods.dev/badge/skills/atlasomnia/donna-starter/source-verification.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00036 | $0.05120 |
| Opus 5 | $0.00018 | $0.02560 |
| Sonnet 5 | $0.00007 | $0.01024 |
| Haiku 4.5 | $0.00004 | $0.00512 |
Grade A, and why
source-verification scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
- For legislature / statutes pages (for example, a state legislature site), if `web_extract` returns a giant truncated page or search results are noisy, fetch the exact section URL with `curl -L -A 'Mozilla/5.0'` and ext Copies of this mod
1 near-identical copy found in the catalogue:
- source-verification — 100% identical, 0 lines differ
How it starts
The opening of the file, as written. The whole thing — 241 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Source Verification
Use this when the user asks to verify an article, claim, controversy, company/news item, or web page. The deliverable is a grounded verdict, not a generic summary.
Operating pattern
- Extract the article text and metadata first:
- Title, date, author if available, publication/source, outbound links, and the exact claims being made.
- If
web_extracttimes out or returns empty, do not keep retrying the same path. Switch to browser automation or terminal HTTP requests with a normal User-Agent, then parse with BeautifulSoup/readability-style extraction.
- Break the article into checkable claims:
- Timeline/date claims.
- Quantitative claims: counts, stars, funding, releases, benchmark scores.
- Attribution/provenance claims: who said what, where, when.
- Technical claims: architecture, features, implementation details.
- Verify against primary or near-primary sources before relying on commentary:
- GitHub API for repo creation dates, releases, tags, issues, licenses, stars/forks, and comment history.
- Official docs, release notes, READMEs, technical reports, company posts.
- Raw files from GitHub for current README/license/config evidence.
- Search results only as discovery, not final proof.
- Compare source quality:
- Distinguish first-party accusation/defense, neutral reporting, reposts/aggregators, and low-provenance blogs.
- Flag articles with no byline, few/no outbound citations, sensational wording, or copied/reframed claims.
- Produce a concise verification table:
- Claim.
- Status: Supported / Partially supported / Unsupported / Misleading / Unverifiable.
- Evidence.
- Caveat.
- Finish with a bottom-line verdict:
- What is solidly verified.
- What is plausible but not proven.
- What the article overstates.
- What additional evidence would change the conclusion.
- When the user is testing whether a person is racist / antisemitic / extremist, rank evidence by strength instead of presenting a flat list:
- Strongest: direct first-person statements, slurs, endorsements of core conspiracy claims, explicit refusals or exclusions aimed at the group, or primary-source recordings/posts.
- Medium: repeated use of coded language or dog whistles that reputable sources trace to extremist subcultures.
- Weakest: guilt-by-association, platform-sharing, audience overlap, or commentary about what supporters believe.
- In the answer, lead with the strongest verified item first. If the best evidence is only medium-strength, say that plainly instead of overselling.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 241 lines · 36 tokens per session scan A 0ef7bd6f7dad
source-verification is a skill published in the GitHub repository AtlasOmnia/donna-starter (111 stars, last pushed 13d ago), licensed MIT. It adds 36 tokens to every session and 5,120 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
npm-downloads-to-leads
Takes a list of npm package names (yours or competitors'), fetches 12 weeks of daily download data from the npm API, computes a breakout velocity score per package to identify hockey-stick growth, fetches maintainer profiles from the npm registry and GitHub API, and outputs a ranked lead brief for each breakout…
gh-issue-to-demand-signal
Takes a competitor's public GitHub repo URL, fetches their open issues via the GitHub REST API, filters noise locally, clusters issues into 6 demand categories, computes a demand score per issue and per cluster, and outputs a ranked demand gap report with a GTM messaging brief. Use when asked to scan a competitor's…
domain-expired-opportunity-finder
Evaluates expired domain candidates against a target niche, scores them by topical relevance, historical activity level, and history cleanliness, then outputs a ranked shortlist with explainable reasoning and risk flags.
company-radar
Competitive intelligence orchestrator tracking companies across 8+ platforms (GitHub, Twitter, Reddit, HN, PH, YC Jobs) with heat scores and AI briefings.
linkedin-job-post-to-buyer-pain-map
Takes pasted LinkedIn job posts or hiring descriptions and converts them into a structured buyer pain map with inferred pains, capability gaps, buy-vs-build signal, account priority scores, and suggested outreach angles. Use when asked to analyze hiring posts, decode job descriptions for buyer intent, build a pain map…
producthunt-launch-kit
Use when the user asks to prepare a Product Hunt launch or generate Product Hunt listing assets. Generates tagline variants under 60 chars, a 500-char description, a maker comment, launch-day tweet thread, LinkedIn post, and a 4-email launch sequence.