Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add cckyros/goal-acceptance --skill confirm-criteriongit clone --depth 1 https://github.com/cckyros/goal-acceptanceWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/cckyros/goal-acceptance/confirm-criterion)<a href="https://agentmods.dev/skills/cckyros/goal-acceptance/confirm-criterion"><img src="https://agentmods.dev/badge/skills/cckyros/goal-acceptance/confirm-criterion/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/cckyros/goal-acceptance/confirm-criterion"><img src="https://agentmods.dev/badge/skills/cckyros/goal-acceptance/confirm-criterion.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00032 | $0.00441 |
| Opus 5 | $0.00016 | $0.00220 |
| Sonnet 5 | $0.00006 | $0.00088 |
| Haiku 4.5 | $0.00003 | $0.00044 |
Grade A, and why
confirm-criterion scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
"evidence": "reviewer re-ran: curl -s localhost:3000/health → 200 {\"status\":\"ok\"}", What it actually says
Confirm Criterion Skill
This tool converts a self-claimed pass into a formal pass, unblocking
can_complete_goal. It MUST be called by an independent reviewer agent
— not the agent that performed the work.
Who Should Call This
- ✅ A subagent spawned specifically to review the work
- ✅ A different agent session that re-verifies independently
- ❌ The same agent that called
validate_criterionwithpassed
What to Do
- Read the criterion description and its original evidence
- Independently re-verify — do NOT trust the original evidence:
- If
method=command: re-run the command yourself - If
method=file: read the file yourself and check the content - If
method=url: make the HTTP request yourself
- If
- If the re-verification passes, call
confirm_criterionwith YOUR fresh evidence (not a copy of the original) - If the re-verification fails, call
validate_criterionwithstatus=failedand your evidence showing the failure
Evidence Type
Must be high-confidence: command, file, or url. text evidence is
rejected — a reviewer saying "looks fine" without re-running is worthless.
Example
{
"criterion_id": "api-200",
"evidence": "reviewer re-ran: curl -s localhost:3000/health → 200 {\"status\":\"ok\"}",
"evidence_type": "command"
}
Rejection Scenarios
| Scenario | Result |
|---|---|
Criterion is not passed |
Error: not a self-claimed pass |
| Criterion is already confirmed | Error: not a self-claimed pass |
evidence_type=text |
Error: high-confidence evidence required |
| Empty evidence | Error: evidence is required |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 53 lines · 32 tokens per session scan A d451cd52ed70
confirm-criterion is a skill published in the GitHub repository cckyros/goal-acceptance (3 stars, last pushed 13d ago), licensed MIT. It adds 32 tokens to every session and 441 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
daytona-windows-cert
Run the verified Windows repro for iPolloWork enterprise TLS behavior: install a fake corporate CA into the Windows machine store, serve healthy and broken HTTPS control planes, install a Windows build, and prove the desktop app and spawned runtimes use the operating system trust path.
daytona-recording-artifacts
Use this skill to collect proof that a Daytona UI flow works. Use fraimz before declaring the flow passed. If the user asks to do e2e tests for a feature, frame proof is required unless they explicitly ask for non-UI or mock-only validation.
fraimz
create a fraimz, make fraimz, prove it works, frame proof, PR proof, validate experience, e2e evidence, fraimz.html. The full fraimz loop — frame the claim, drive the real app via CDP, validate/repair, output fraimz.html. Use whenever a task ends with "please create a fraimz" or any change needs end-to-end proof.
daytona-electron-den
Electron and Den, desktop plus cloud, two-sandbox e2e, cloud auth, marketplace, org policy, worker proxy, provider sync, desktop handoff. Validate Electron against a Daytona Den server with unified proof.
run-evals
Launch a real iPolloWork app and run coded eval flows against it. This skill owns launch + run; the prove/repair/verdict loop and evidence standard live in the fraimz skill — load that too for anything that ends in a verdict.
delivery-proof
Delivery proof and the doublecheck report. Use when the work is done and the delivery must be proven — consolidate the spec, test timeline, review verdicts, and verification checks into a doublecheckreport, and only then claim completion.