Install
$ agentstack add skill-a-ariff-ariff-claude-plugins-cross-checker ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Cross-Checker: Multi-Angle Verification
Never trust a single source. Verify from at least two independent angles before accepting a claim as fact.
The cross-checking method
For any claim, check it against multiple sources:
Source 1: The code itself
Read the actual file. What does the code do? This is the strongest evidence.
Source 2: Tests
What do the tests expect? Tests reveal intended behavior. If a test expects validateToken to return false for expired tokens, that's the designed behavior.
Source 3: Git history
What was the original intent? Git blame and commit messages reveal why code was written. "commit abc123: fix token expiration check to reject tokens older than 24h"
Source 4: Documentation
README, comments, JSDoc, API docs. Do they match the code? If docs say one thing and code does another, the code is truth but the discrepancy matters.
Source 5: Configuration
Config files, environment variables, feature flags. Runtime behavior may differ from what the code looks like.
Source 6: Dependencies
Package versions, API compatibility, deprecated features. A function might exist in the code but be broken due to a dependency update.
Minimum verification standard
| Situation | Minimum angles needed | |-----------|----------------------| | Stating a fact to the user | 1 (read the code) | | Recommending a code change | 2 (code + tests or git history) | | Security-related claims | 3 (code + tests + docs/config) | | Production deployment advice | 3 (code + config + git history) | | "This is safe to delete" | 3 (code + grep for references + tests) |
Cross-check workflow
- Make the initial claim based on what you know
- Identify which type of claim it is (fact, recommendation, security)
- Check the required number of angles
- If sources agree: proceed with confidence
- If sources disagree: flag the discrepancy, investigate further
- If sources are insufficient: say so, suggest how to get more evidence
Red flags that demand cross-checking
- "This function is never called" (grep the entire codebase first)
- "This file isn't used anymore" (check imports, configs, build scripts)
- "This dependency can be removed" (check all import statements)
- "This environment variable isn't needed" (check all config files and deploy scripts)
- "This test is redundant" (check what specific edge case it covers)
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: a-ariff
- Source: a-ariff/ariff-claude-plugins
- License: MIT
- Homepage: https://github.com/a-ariff/ariff-claude-plugins#quick-start
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.