Install
$ agentstack add skill-buildmoonshot-skillpacks-verify-before-done ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Verify Before Done
Do not say a change is "done," "fixed," or "working" until you have evidence that it is.
What counts as evidence
In rough order of strength:
- Run it. Execute the test, build, script, or command that exercises the change and read the actual output.
- Add a check. If nothing tests this path, write a small test or assertion that would fail before your fix and pass after — then run it.
- Trace it. If you genuinely can't run anything, walk the changed logic step by step with a concrete example input and show the result. Say explicitly that this is a trace, not an execution.
How to report
- If it passed: say so, and briefly say what you ran ("ran
npm test— 14 passing"). - If it failed: say that plainly and show the output. A failure you report is a problem solved; a failure you hide is a problem shipped.
- If you couldn't verify: say "I couldn't verify this because ___" instead of implying it works. Never let an unverified change wear the word "done."
The rule
> "Should work" is not "works." If you didn't check, don't claim it.
Why this matters
The most expensive bug is the one the agent confidently called "fixed." Verification converts confident guesses into either a real result or an honest "not yet" — both of which save the user from discovering the failure in production.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: buildmoonshot
- Source: buildmoonshot/skillpacks
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.