# Citation Enforcer

> Forces every code-related claim to include file:line citations. No citation means the claim must be verified or removed. Use when building documentation, writing code reviews, or any output that others will rely on.

- **Type:** Skill
- **Install:** `agentstack add skill-a-ariff-ariff-claude-plugins-citation-enforcer`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [a-ariff](https://agentstack.voostack.com/s/a-ariff)
- **Installs:** 0
- **Category:** [AI & ML](https://agentstack.voostack.com/c/ai-and-ml)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [a-ariff](https://github.com/a-ariff)
- **Source:** https://github.com/a-ariff/ariff-claude-plugins/tree/main/plugins/citation-enforcer/skills/citation-enforcer
- **Website:** https://github.com/a-ariff/ariff-claude-plugins#quick-start

## Install

```sh
agentstack add skill-a-ariff-ariff-claude-plugins-citation-enforcer
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# Citation Enforcer

Every code claim needs a citation. file:line or it didn't happen.

## The rule

When you mention any of these, include the file path and line number:

- A function name -> "validateToken() at src/auth.ts:42"
- A variable -> "the MAX_RETRIES constant at src/config.ts:15"
- A class -> "the UserService class at src/services/user.ts:1"
- An import -> "imported from @auth/core at src/auth.ts:3"
- A config value -> "timeout set to 30000 at config/default.json:12"
- An error message -> "the error 'Invalid token' thrown at src/auth.ts:67"

## Citation format

Standard: `file:line`
Example: `src/auth.ts:42`

With range: `file:line-line`
Example: `src/auth.ts:42-58`

With context: `description at file:line`
Example: "the validateToken function at src/auth.ts:42"

## Self-check

Before sending a response, scan it for uncited claims:

1. Find every mention of a function, file, class, or variable
2. Does each one have a file:line citation?
3. If not, either:
   a. Use Read/Grep to find the actual location and add it
   b. Remove the claim if you can't find it
   c. Clearly state "I haven't verified where this is located"

## Examples

Bad: "The authentication middleware checks for valid tokens."
Good: "The authentication middleware at src/middleware/auth.ts:15-30 checks for valid tokens by calling validateToken()."

Bad: "There's a bug in the error handling."
Good: "The catch block at src/api/users.ts:87 swallows the error without logging it."

Bad: "The config file has the wrong timeout."
Good: "The timeout at config/production.json:23 is set to 5000ms, which may be too low for this API call."

## When citations aren't needed

- General programming concepts ("REST APIs use HTTP methods")
- Suggestions that aren't about existing code ("you could add a retry mechanism")
- Questions to the user ("what error are you seeing?")
- Tool output that already includes file references

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [a-ariff](https://github.com/a-ariff)
- **Source:** [a-ariff/ariff-claude-plugins](https://github.com/a-ariff/ariff-claude-plugins)
- **License:** MIT
- **Homepage:** https://github.com/a-ariff/ariff-claude-plugins#quick-start

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-a-ariff-ariff-claude-plugins-citation-enforcer
- Seller: https://agentstack.voostack.com/s/a-ariff
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
