Install
$ agentstack add skill-a-ariff-ariff-claude-plugins-citation-enforcer ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Citation Enforcer
Every code claim needs a citation. file:line or it didn't happen.
The rule
When you mention any of these, include the file path and line number:
- A function name -> "validateToken() at src/auth.ts:42"
- A variable -> "the MAX_RETRIES constant at src/config.ts:15"
- A class -> "the UserService class at src/services/user.ts:1"
- An import -> "imported from @auth/core at src/auth.ts:3"
- A config value -> "timeout set to 30000 at config/default.json:12"
- An error message -> "the error 'Invalid token' thrown at src/auth.ts:67"
Citation format
Standard: file:line Example: src/auth.ts:42
With range: file:line-line Example: src/auth.ts:42-58
With context: description at file:line Example: "the validateToken function at src/auth.ts:42"
Self-check
Before sending a response, scan it for uncited claims:
- Find every mention of a function, file, class, or variable
- Does each one have a file:line citation?
- If not, either:
a. Use Read/Grep to find the actual location and add it b. Remove the claim if you can't find it c. Clearly state "I haven't verified where this is located"
Examples
Bad: "The authentication middleware checks for valid tokens." Good: "The authentication middleware at src/middleware/auth.ts:15-30 checks for valid tokens by calling validateToken()."
Bad: "There's a bug in the error handling." Good: "The catch block at src/api/users.ts:87 swallows the error without logging it."
Bad: "The config file has the wrong timeout." Good: "The timeout at config/production.json:23 is set to 5000ms, which may be too low for this API call."
When citations aren't needed
- General programming concepts ("REST APIs use HTTP methods")
- Suggestions that aren't about existing code ("you could add a retry mechanism")
- Questions to the user ("what error are you seeing?")
- Tool output that already includes file references
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: a-ariff
- Source: a-ariff/ariff-claude-plugins
- License: MIT
- Homepage: https://github.com/a-ariff/ariff-claude-plugins#quick-start
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.