Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add heidihelena/citevahti --skill citevahti-claimsgit clone --depth 1 https://github.com/heidihelena/citevahtiWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/heidihelena/citevahti/citevahti-claims)<a href="https://agentmods.dev/skills/heidihelena/citevahti/citevahti-claims"><img src="https://agentmods.dev/badge/skills/heidihelena/citevahti/citevahti-claims/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/heidihelena/citevahti/citevahti-claims"><img src="https://agentmods.dev/badge/skills/heidihelena/citevahti/citevahti-claims.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00100 | $0.01426 |
| Opus 5 | $0.00050 | $0.00713 |
| Sonnet 5 | $0.00020 | $0.00285 |
| Haiku 4.5 | $0.00010 | $0.00143 |
Grade A, and why
citevahti-claims scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 84 lines — stays where its author put it; the contents beside it link to each section on GitHub.
CiteVahti claims — audit public language before it ships
CiteVahti's brand core is a refusal: it never issues a verdict, and it holds itself to the evidence standards it promotes. One sentence of overclaiming — "AI-verified", "guarantees accuracy", both forbidden below — spends that credibility permanently. This skill audits every public artifact against the boundary the product actually keeps.
Canonical sources (the audit is against these, not memory):
docs/DISCLOSURE.md (what is never certified) · docs/KNOWN_LIMITATIONS.md (what is
honestly not done) · docs/METHODS.md §PRISMA-trAIce (framework-compliance ceiling) ·
docs/SAFETY_INVARIANTS.md (what "safe" concretely means).
Triggers
Use when: publishing or editing site copy, README, docs/STATUS.md positioning,
LinkedIn/social posts, release notes, talk slides, marketing drafts
(docs/marketing/), or answering "can we claim X?".
Do NOT use for: internal notes and ADRs (not public), or code review.
The must-not-claim list
Reject or rewrite any artifact that states or implies:
| Forbidden | Why | Say instead |
|---|---|---|
| "guarantees accuracy / correctness" | no accuracy promise can be made; recall < 100% is a documented product fact | "surfaces problems for human adjudication" |
| "AI-verified" / "verified by AI" | AI is a blinded advisory second rater; it never sets the final value | "human-decided, AI-assisted, blinded second opinion" |
| "catches all errors" / "no citation problem escapes" | detection is imperfect and DOI/PMID-keyed; untestable claims exist | "flags what it can check; marks the rest untestable" |
| certification language: "certifies", "approves", "CiteVahti-validated", badges/seals | DISCLOSURE.md: use does not certify truth, quality, or absence of problems | "structured decision support and an audit trail" |
| "PRISMA / PRISMA-trAIce / Cochrane compliant, endorsed, aligned" | METHODS.md explicitly disclaims compliance and endorsement | "mirrors dual-screening logic; PRISMA-trAIce / RAISE-style transparency reporting" |
| verdict language: "CiteVahti says this citation is wrong" | it records your judgment with provenance | "flagged for your review", "did not find support" |
| accuracy numbers with no source | until the eval ledger is scored, there are no numbers (KNOWN_LIMITATIONS.md) | cite the published eval page, or phrase as commitment ("we will publish…") |
| "your data never leaves your machine" (absolute) | literature lookups go to PubMed/OpenAlex/Semantic Scholar/Crossref | "manuscript and ratings stay local; only literature queries go out; no telemetry" |
| "catches hallucinated references" (absolute) | fabricated-reference detection keys on DOI/PMID; identifier-less items can't be checked | "refuses to write unverifiable citations; flags references that don't resolve" |
| hosted-service implications: "upload", "try it in your browser" for the panel | ADR-0007: the web app is a local loopback panel; nothing is hosted | "runs locally; ten-minute install" |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 84 lines · 100 tokens per session scan A 23c6215e0708
citevahti-claims is a skill published in the GitHub repository heidihelena/citevahti (1 stars, last pushed 7d ago), licensed Apache-2.0. It adds 100 tokens to every session and 1,426 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
ml-paper-writing
Write publication-ready ML/AI papers for NeurIPS, ICML, ICLR, ACL, AAAI, COLM. Use when drafting papers from research repos, structuring arguments, verifying citations, or preparing camera-ready submissions. Includes LaTeX templates, reviewer guidelines, and citation verification workflows.
foia-requests
FOIA and public records workflows. Use when drafting requests, tracking submissions, checking exemptions, or appealing denials.
content-access
Legal methods for paywalled and geo-blocked content. Use for paywalls, academic papers, or open access via Unpaywall.
web-archiving
Web archiving and retrieval via Wayback Machine and Archive.today. Use to preserve content, reach dead pages, or save evidence.
brazil-records-requests
Public records requests under Brazil's Access to Information Law (LAI). Use for Fala.BR filings, e-SIC, and CGU/CMRI appeals.
interview-prep
Interview preparation and recording-consent law. Use for research, question frameworks, one-party or all-party consent rules.