patpat-verify

patpat-verify is a skill for Cursor from goiltpatpat/patpat. It costs 41 tokens per session (800 once invoked), scanned A, original, MIT.

A verification method for checking whether a code or repository claim is true using the actual file, interface, or user-visible result that proves it.

In plain words
What is it for?
Use it after code changes or during acceptance checks to test behavior, inspect static structure, review visible output and side effects, and check the final version-control diff.
Why use it?
It prevents relying on tests or build results that do not show how the changed feature really behaves. It also records what was checked, what happened, and what remains uncertain.

Skill for Cursor

Written for Cursor: shipped in a Cursor plugin.

Part of the patpat plugin — 22 skills, 1 agent, 3 hooks shipped together

Good fit Use it after code changes or during acceptance checks to test behavior, inspect static structure, review visible output and side effects, and check the final version-control diff.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/goiltpatpat/patpat/patpat-verify
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add goiltpatpat/patpat --skill patpat-verify
Clone the repo
git clone --depth 1 https://github.com/goiltpatpat/patpat

Made for: Cursor.

Or install patpat, the plugin that ships this one along with the rest of its 22 skills, 1 agent, 3 hooks.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for patpat-verify

README.md
[![agentmods](https://agentmods.dev/badge/skills/goiltpatpat/patpat/patpat-verify/github.svg)](https://agentmods.dev/skills/goiltpatpat/patpat/patpat-verify)
Your own site
<a href="https://agentmods.dev/skills/goiltpatpat/patpat/patpat-verify"><img src="https://agentmods.dev/badge/skills/goiltpatpat/patpat/patpat-verify/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for patpat-verify

Your own site · 80×15
<a href="https://agentmods.dev/skills/goiltpatpat/patpat/patpat-verify"><img src="https://agentmods.dev/badge/skills/goiltpatpat/patpat/patpat-verify.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 41 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 800 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00041 $0.00800
Opus 5 $0.00020 $0.00400
Sonnet 5 $0.00008 $0.00160
Haiku 4.5 $0.00004 $0.00080

Measured today against content hash 2565a897ce3f, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-10, from the pricing page.

Security

Grade A, and why

patpat-verify scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/patpat-verify/SKILL.md · 48 lines

How it starts

The opening of the file, as written. The whole thing — 48 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Patpat Verify

For a bounded local proof, use this skill and its relevant references. Read the operating protocol in full for uncertainty, security, auth, billing, secrets, architecture, cross-cutting work, or delivery intent. Do not load the router or reread unchanged instructions already loaded in this session.

Read proof over proxy and preserve safety.

Build the proof

  1. Reconcile the requested outcomes with the proof contract using proof over proxy; name missing requirements before running checks.
  2. Identify the authoritative artifact or user surface.
  3. Capture a baseline or reproduce the prior state when relevant.
  4. Run the smallest targeted automated check.
  5. For behavioral claims, exercise the changed logic through the authoritative interface under representative conditions when safe and practical. For static claims, use the strongest deterministic check on the authoritative artifact.
  6. Observe visible output and material side effects directly.
  7. Inspect the final diff and version-control state for unrelated changes.
  8. Record the command or action, observed result, cleanup, and limitation for each material claim; do not mark the whole request verified with uncovered outcomes.

For every test or evaluator used as evidence, apply the behavioral check from proof over proxy: a mock-call assertion, copied constant, self-referential expected value, or fixture-only agreement cannot prove user-observed behavior. Replace it with a concrete input and literal expected output or side effect, or classify the claim as static instead.

Claim-adaptive verification and proxy rejection

Match verification depth to the claim and risk:

  • Behavioral claims: Vary material inputs, relevant error branches, or state transitions when safe and practical. Call the subject through the authoritative interface and assert the literal observed result or material effect. A mock interaction, call count, truthiness check, copied constant, or clean compilation does not prove the behavior by itself.
  • Static claims: Use deterministic structure, schema, type, or content checks when that is the authoritative surface. Do not manufacture runtime theater for a non-runtime claim.
  • Proxy evidence: Fixtures and mocks may isolate a contract, but they do not replace the real system when the claim concerns that system. Reject narrative summaries, hardcoded fixture answers, and clean compilation as sole behavioral proof.
  • Fresh binding: Bind evidence to the exact candidate revision or a reproducible working-tree snapshot, plus material inputs, environment, and oracle. Require the committed head for commit-, push-, PR-, or delivery-bound claims. Reject stale, cached, or transferred logs.

Read the full file on GitHub · 48 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. today Changed · +2 lines 2565a897ce3f
  2. 3d ago Changed 14b8652dc452
  3. 10d ago First seen · 46 lines · 41 tokens per session scan A 689b1a725944

Subscribe to this mod's changes

patpat-verify is a skill published in the GitHub repository goiltpatpat/patpat (1 stars, last pushed yesterday), licensed MIT. It adds 41 tokens to every session and 800 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.