Install
$ agentstack add skill-bryann2k-stipulate-skills-stip-check ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
stip-check
Read the approved contract and relevant extension check references. This stage evaluates the result; it does not redesign the feature or silently change requirements.
- Exercise or inspect the actual behavior required by each criterion. A build proves compilation, not UX, authorization or deployment. Distinguish failures from unavailable checks.
- Run
snapshotafter the last relevant source change. Create a results JSON outside the repository, or pass it through stdin:{"subject_digest":"","criteria":[{"id":"AC-1","status":"passed","evidence":""}]}. - Run
check --results. Cover each criterion exactly once. Valid statuses are passed, failed, unverified, not-applicable; only all passed advances to checked. A not-applicable requirement needs a contract correction and reapproval rather than silent acceptance. - Report gaps. Corrections go through stip-apply when authorized, then a new check. When all criteria pass, proceed to stip-docs.
The command checks report consistency and working-tree identity. It cannot authenticate evidence or perform semantic verification itself. Never fabricate a report merely to advance state. Do not include credentials or private payloads in evidence.md.
Runtime
Use the Python runtime bundled with this skill, independent of the current directory:
python3 /scripts/workflow.py --root
Python 3.10+ and Git are required for implementation and archive. Run --help or --help for exact arguments. The runtime is offline and never installs tools. System/developer instructions, current user intent and environment permissions remain authoritative.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: BRYANN2K
- Source: BRYANN2K/stipulate-skills
- License: Apache-2.0
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.