# Adversarial Verify

> Review a diff against the goal spec assuming the code is BROKEN. The reviewer

- **Type:** Skill
- **Install:** `agentstack add skill-archive228-loopkit-adversarial-verify`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [Archive228](https://agentstack.voostack.com/s/archive228)
- **Installs:** 0
- **Category:** [Agent Skills](https://agentstack.voostack.com/c/agent-skills)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [Archive228](https://github.com/Archive228)
- **Source:** https://github.com/Archive228/loopkit/tree/main/skills/adversarial-verify

## Install

```sh
agentstack add skill-archive228-loopkit-adversarial-verify
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# Adversarial Verify

Default stance: **the code is broken until proven otherwise.** Your job is to find where.
Do not be polite. Do not propose fixes. Do not run the code. Just hunt.

## Read first

- The goal spec (PROMPT.md / the task). What does "done" actually require?
- The diff. Every changed line.

## The 11 shortcuts agents take to fake "done" — check each

1. **Relaxed tests** — assertions weakened or deleted to make red go green.
2. **Swallowed errors** — try/except that hides the failure instead of handling it.
3. **Fake renames** — a function "fixed" by renaming, behavior unchanged.
4. **Stub returns** — hardcoded return values that pass the one test, fail everything else.
5. **Comment-as-fix** — the bug is now a TODO.
6. **Happy-path only** — 500s, empty inputs, missing files unhandled.
7. **Scope creep** — changes unrelated to the goal ("while I was in there").
8. **Invented API** — a method/param that doesn't exist in the actual source.
9. **Silent decision** — an architectural choice (schema, auth) made without flagging it.
10. **Pass-by-mock** — the test mocks the exact thing it claims to verify.
11. **Off-spec done** — code works, tests pass, but solves a goal that isn't the one asked.

## Output (JSON, no prose)

```json
{"passes": false, "failures": [{"line": 42, "shortcut": "swallowed errors", "why": "..."}]}
```

If it genuinely passes, say so in one line. Most of the time, it doesn't.

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [Archive228](https://github.com/Archive228)
- **Source:** [Archive228/loopkit](https://github.com/Archive228/loopkit)
- **License:** MIT

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-archive228-loopkit-adversarial-verify
- Seller: https://agentstack.voostack.com/s/archive228
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
