# Loop Verify

> Runs this project's verification contract and decides honestly whether something is verified, a gap, or a lie. Use before calling anything done, and whenever a report says "should work".

- **Type:** Skill
- **Install:** `agentstack add skill-cbdreamer11-cb-loop-kit-claude-plugin-loop-verify`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [cbdreamer11](https://agentstack.voostack.com/s/cbdreamer11)
- **Installs:** 0
- **Category:** [Agent Skills](https://agentstack.voostack.com/c/agent-skills)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [cbdreamer11](https://github.com/cbdreamer11)
- **Source:** https://github.com/cbdreamer11/CB-loop-kit-claude-plugin/tree/main/skills/loop-verify

## Install

```sh
agentstack add skill-cbdreamer11-cb-loop-kit-claude-plugin-loop-verify
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# Verify for real

Read `.loop/VERIFY.md` and run the slots that apply to what changed. Then write down
what you observed, in the words of what you saw — not in the words of what you hoped.

## The three things that are not verification

1. **A green build.** It proves the code compiles. Nothing else.
2. **"I read the code and it looks right."** The bug you are looking for is exactly
   the one that looks right.
3. **"It should work."** Then it is not verified. Say that instead.

Add two more that fool people constantly:

4. **An exit code of 0** — a command can succeed while doing nothing.
5. **An HTTP 200** — many servers answer 200 for a page that does not exist. Verify
   by finding a **string that only exists in the new behaviour**, not by status code.

## What counts

Each slot must produce an artifact or a direct observation:

- **BUILD** — the project's build/test command, green. Necessary, never sufficient.
- **OBSERVE** — the thing itself, doing its thing: a page rendered in a real browser
  with a clean console and a real interaction (click, type, navigate); a CLI run with
  its real output; an endpoint returning the new field. A screenshot or captured
  output is the artifact.
- **DATA** — query the store and confirm the effect: the row exists, the value
  changed, the wrong value is refused.
- **MONEY** — if money moves, use the provider's test mode and confirm the resulting
  state changed for real. Never test with live money.

## Testing against a real system

If the project has a test database or a seeded environment, use it: set up, run,
tear down. **That is the default.** Working against a live system is an exception
that must be declared in `.loop/VERIFY.md`, and when it is unavoidable: wrap in a
transaction and roll back, or restore the fixtures afterwards and confirm nothing
was left behind.

Two traps worth naming: your own tooling may run with more privileges than a real
user, which hides permission bugs — check with the actual role. And a check that
passes for you may fail for a signed-out visitor — check both.

## The verdict

For each slot: **VERIFIED** (with the one line of what you observed), **GAP**
(with the reason it cannot be checked here — a missing access, no browser, no test
environment), or **FAILED** (go back to building). A slot may not be silently
skipped. If a required slot is a GAP, the item is not done — it is delivered with a
declared gap, and it says so in `.loop/STATE.md`.

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [cbdreamer11](https://github.com/cbdreamer11)
- **Source:** [cbdreamer11/CB-loop-kit-claude-plugin](https://github.com/cbdreamer11/CB-loop-kit-claude-plugin)
- **License:** MIT

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-cbdreamer11-cb-loop-kit-claude-plugin-loop-verify
- Seller: https://agentstack.voostack.com/s/cbdreamer11
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
