Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add wazimmerman/zimster --skill verification-before-completiongit clone --depth 1 https://github.com/wazimmerman/zimsterWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/wazimmerman/zimster/verification-before-completion)<a href="https://agentmods.dev/skills/wazimmerman/zimster/verification-before-completion"><img src="https://agentmods.dev/badge/skills/wazimmerman/zimster/verification-before-completion.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00021 | $0.01611 |
| Opus 5 | $0.00010 | $0.00805 |
| Sonnet 5 | $0.00004 | $0.00322 |
| Haiku 4.5 | $0.00002 | $0.00161 |
Grade A, and why
verification-before-completion scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 178 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Verification Before Completion
Adapted from Superpowers' evidence-before-claims discipline under the MIT License.
Iron law
NO COMPLETION CLAIMS WITHOUT FRESH VERIFICATION EVIDENCE
Before saying done, fixed, passing, ready, or safe:
- identify the exact requirement;
- identify the canonical command/observation;
- run it on the final relevant tree/environment;
- read complete output, exit status, counts, warnings, skips;
- map evidence to the requirement;
- claim only the supported state.
Delegated implementation evidence is incomplete until the persistent owner
has inspected it, run the named acceptance proof, and recorded acceptance.
Requested model settings are not proof of the effective model; report
effective routing as unverified when the harness cannot expose it.
Discover canonical commands first
Resolve <zimster-runtime> to the installed using-zimster skill root when it
contains scripts/project-commands.mjs, otherwise to the full plugin root when
that script exists there. Never resolve it from the target repository; use the
manual fallback when neither path exists.
Prefer repository-declared commands in this order:
- repository instructions (
AGENTS.md,CLAUDE.md, contribution docs); - package scripts (
package.json, language manifests); - Makefile, task runner, or project scripts;
- CI workflow commands.
Use <zimster-runtime>/scripts/project-commands.mjs as an inventory aid when
available. Prefer npm test over an
invented node --test command when the repository defines it. Invent direct
commands or flags only when canonical commands cannot establish the required
proof; state why and how the direct command differs.
Classify command evidence accurately
Do not call every successful process a “full suite.” Distinguish:
- command failed before discovering tests: setup/flag/loader failure; zero behavioral evidence;
- command succeeded with zero tests: valid command, no tests discovered;
- baseline suite ran with zero tests: starting-state fact, not a post-change passing suite;
- focused test run: named subset with exact counts;
- affected/subsystem suite: declared scope and counts;
- full project gate: canonical project command and exact counts;
- external/hardware/manual observation: named environment and result.
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 178 lines · 21 tokens per session scan A 02795ce86ed1
verification-before-completion is a skill published in the GitHub repository wazimmerman/zimster (2 stars, last pushed 6d ago), licensed MIT. It adds 21 tokens to every session and 1,611 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
build-test
Run the project's build / typecheck / lint / test commands and emit the build.passing + tests.passing signals devloop convergence reads.
rudder
Use locally captured coding-session intent to resolve a device-local behavioral spec, generate focused tests from that spec, implement the smallest production changes through red-green TDD, and verify coverage with the repository's native tooling. Use when the user asks to run Rudder, create or regenerate tests for…
TDD 开发纪律助手
A development skill based on TDD, or test-driven development: write or update a test first, make it pass with the smallest code change, then improve the code and check for regressions.
ship
Enforces Law 1 (Research Before Executing), Law 3 (One Thing at a Time), and Law 4 (Verify Before Reporting) of the 7 Laws of AI Agent Discipline. Fix one defect through TDD and one PR, isolate unrelated dirty checkouts in an owner-locked clean worktree, and return only eligible clean checkouts to the detected default…
debugging
Investigate failures whose root cause is still unknown — narrow the search space, instrument, and test falsifiable hypotheses. Use for intermittent or environment-dependent behavior, unexplained stack traces, regressions with no known trigger, or any symptom without a confirmed cause. Ends once the root cause is…
security-audit
Security review and hardening workflow — root-cause analysis of vulnerabilities, authentication and authorization checks, least privilege, input handling, secret hygiene, and security regression tests. Use when reviewing code for security, fixing a vulnerability, hardening a feature, or handling auth, permissions…