Install
$ agentstack add skill-kreek-consult-official-source-check ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
Official Source Check
Iron Law
MODEL MEMORY IS A HINT, NOT EVIDENCE, FOR VERSION-SENSITIVE BEHAVIOR.
When to Use
- Implementation depends on current external framework, library, runtime,
browser, SDK, cloud, or platform behavior.
- The repo does not already prove the exact API, configuration, migration,
browser behavior, or provider contract.
- The user asks for current, official, documented, verified, or best-practice
implementation.
When NOT to Use
- Project-local logic with tests and no external API dependency.
- Stable language syntax covered by the compiler, linter, or type checker.
- Typos, formatting, prose-only edits, or mechanical metadata changes.
- Emergency mitigation where the user accepts unverified risk.
Workflow
- Find the local version from manifests, lockfiles, imports, generated
clients, schemas, config, or CI images.
- Check the narrow source of truth: official docs, release notes, migration
guide, standards spec, or provider SDK reference.
- Compare that source with local conventions.
- Use the smallest source-compatible implementation.
- In the final claim, name the source checked or mark the claim unverified.
Verification
- [ ] Local version or platform was identified, or its absence was reported.
- [ ] The source of truth was checked for the exact pattern.
- [ ] Deprecated or version-incompatible APIs were avoided.
- [ ] Conflicts between source guidance and local convention were surfaced.
- [ ] Unverified external-behavior claims were marked unverified.
- [ ] Runtime behavior was proven when source guidance alone did not prove it.
Tripwires
| Trigger | Do this instead | False alarm | | --- | --- | --- | | "I know this API" | Check the local version and source of truth. | Project-local helper with tests. | | "The docs are too broad" | Check the narrow API, migration, or release-note page. | Offline task where user accepts unverified output. | | "Existing code does it this way" | Check whether the pattern is still supported before copying it. | Repo policy pins an older supported pattern. | | "I'll cite a blog post" | Use official docs, standards, release notes, or provider references first. | The project owns the library being edited. |
Handoffs
- Use
workflowto choose the full skill set. - Use
proofwhen source guidance must be backed by runtime behavior. - Use
documentationwhen the checked source needs to be captured for
maintainers.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: kreek
- Source: kreek/consult
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.