AgentStack
SKILL verified MIT Self-run

Official Source Check

skill-kreek-consult-official-source-check · by kreek

Use when external behavior must be checked against official sources.

No reviews yet
0 installs
0 views
view→install

Install

$ agentstack add skill-kreek-consult-official-source-check

✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

Are you the author of Official Source Check? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Official Source Check

Iron Law

MODEL MEMORY IS A HINT, NOT EVIDENCE, FOR VERSION-SENSITIVE BEHAVIOR.

When to Use

  • Implementation depends on current external framework, library, runtime,

browser, SDK, cloud, or platform behavior.

  • The repo does not already prove the exact API, configuration, migration,

browser behavior, or provider contract.

  • The user asks for current, official, documented, verified, or best-practice

implementation.

When NOT to Use

  • Project-local logic with tests and no external API dependency.
  • Stable language syntax covered by the compiler, linter, or type checker.
  • Typos, formatting, prose-only edits, or mechanical metadata changes.
  • Emergency mitigation where the user accepts unverified risk.

Workflow

  1. Find the local version from manifests, lockfiles, imports, generated

clients, schemas, config, or CI images.

  1. Check the narrow source of truth: official docs, release notes, migration

guide, standards spec, or provider SDK reference.

  1. Compare that source with local conventions.
  2. Use the smallest source-compatible implementation.
  3. In the final claim, name the source checked or mark the claim unverified.

Verification

  • [ ] Local version or platform was identified, or its absence was reported.
  • [ ] The source of truth was checked for the exact pattern.
  • [ ] Deprecated or version-incompatible APIs were avoided.
  • [ ] Conflicts between source guidance and local convention were surfaced.
  • [ ] Unverified external-behavior claims were marked unverified.
  • [ ] Runtime behavior was proven when source guidance alone did not prove it.

Tripwires

| Trigger | Do this instead | False alarm | | --- | --- | --- | | "I know this API" | Check the local version and source of truth. | Project-local helper with tests. | | "The docs are too broad" | Check the narrow API, migration, or release-note page. | Offline task where user accepts unverified output. | | "Existing code does it this way" | Check whether the pattern is still supported before copying it. | Repo policy pins an older supported pattern. | | "I'll cite a blog post" | Use official docs, standards, release notes, or provider references first. | The project owns the library being edited. |

Handoffs

  • Use workflow to choose the full skill set.
  • Use proof when source guidance must be backed by runtime behavior.
  • Use documentation when the checked source needs to be captured for

maintainers.

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet — be the first.

Versions

  • v0.1.0 Imported from the upstream source.