Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add krokoko/cairn --skill assess-verificationgit clone --depth 1 https://github.com/krokoko/cairnWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/krokoko/cairn/assess-verification)<a href="https://agentmods.dev/skills/krokoko/cairn/assess-verification"><img src="https://agentmods.dev/badge/skills/krokoko/cairn/assess-verification/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/krokoko/cairn/assess-verification"><img src="https://agentmods.dev/badge/skills/krokoko/cairn/assess-verification.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00053 | $0.04039 |
| Opus 5 | $0.00026 | $0.02020 |
| Sonnet 5 | $0.00011 | $0.00808 |
| Haiku 4.5 | $0.00005 | $0.00404 |
Grade A, and why
assess-verification scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 326 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Software Verification Assessment
Assess the current verification maturity of a codebase. Produce a verification-report.md with maturity tier, component breakdown, missing oracles, exactness analysis, human review requirements, autonomy candidates, feedback loop completeness, workflow gate assessment, and shift-left positioning.
Workflow
Step 1: Inventory existing verification
Search for all verification-related artifacts:
Testing:
- Test files:
*_test.*,*_spec.*,test_*.*,tests/,__tests__/ - Test config:
jest.config.*,pytest.ini,pyproject.toml [tool.pytest],vitest.config.* - Property tests: imports of
hypothesis,fast-check,proptest,QuickCheck - Fuzzing:
fuzz/,*_fuzz_test.go,cargo-fuzzconfig,AFLconfigs - Mutation testing:
mutmut,stryker.conf.*,cargo-mutantsconfig
Static analysis:
- Linters:
.eslintrc*,ruff.toml,.golangci.yml,clippy.toml - Type checkers:
tsconfig.json,mypy.ini,pyrightconfig.json - SAST tools:
.semgrep/,codeql-config.yml - Sanitizers: ASan/TSan/UBSan flags in build configs or CI
- Profiling:
pprof,perf,py-spyconfigurations or scripts
Security and supply chain:
- Dependency / SCA scanning: Dependabot (
.github/dependabot.yml), Renovate, Snyk,npm audit,pip-audit,osv-scanner,govulncheckin CI - Secret scanning:
gitleaks,detect-secrets,trufflehogconfigs or hooks - IaC scanning:
tfsec,checkov,kics,terrascanconfigs or CI steps
Contracts and schemas:
- Schemas:
*.schema.json,*.proto,openapi.*,*.graphql - Contracts: assertions,
icontract,contractslibrary imports,invariant - Consumer-driven contracts:
pact/,pacts/, Pact broker config, Spring Cloud Contract stubs - Formal specs:
*.tla,*.cfg(TLC),*.als,*.dfy
CI and operational:
- CI config:
.github/workflows/,.gitlab-ci.yml - Coverage:
codecov.yml, coverage report configs - Canary/shadow: feature flag configs, deployment configs, traffic splitting
What ships with it
12 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- references/agentops-telemetry-assessment.md 2.4 KB
- references/agentops-telemetry.md 4.4 KB
- references/bug-surface-routing.md 3.9 KB
- references/decision-framework.md 3.0 KB
- references/documentation-verification.md 3.7 KB
- references/feedback-loop-model.md 3.2 KB
- references/maturity-model.md 3.2 KB
- references/method-failure-modes.md 4.9 KB
- references/report-template.md 4.4 KB
- references/shift-left-model.md 5.3 KB
- references/traceability-model.md 3.6 KB
- references/verification-taxonomy.md 7.5 KB
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 326 lines · 53 tokens per session scan A d59f1d6254c5
assess-verification is a skill published in the GitHub repository krokoko/cairn (14 stars, last pushed 5d ago), licensed Apache-2.0. It adds 53 tokens to every session and 4,039 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
reproducibility-validate
Run a workflow multiple times and compare outputs to produce a similarity score and pass/fail verdict.
eval-agent
Run evaluation tests against an agent to assess quality and archetype resistance.
eval-workflow
Run evaluation tests against a multi-agent workflow to assess orchestration quality and failure archetype resistance.
auto-test-execution
Automatically execute tests when code-generating agents modify source files, enforcing the execute-before-return pattern.
devkit-test
Auto-fix discoverable issues.
execute-feedback
Execute tests on generated code and iterate until passing.