Install
$ agentstack add skill-vincentchuwaichow-vanguard-frontier-agentic-definition-of-done ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Definition of Done
Doctrine
The order is load-bearing. The integrity manifest must hash the settled tree, so asset-integrity:write always runs last, on its own, from the repo root — never folded into a parallel generator batch, never run from a subdirectory.
Trigger
- Before declaring any change in this repo finished.
- Whenever the stop hook reports uncommitted or untracked changes.
Input
The list of paths you touched in this change.
Decision matrix
Pick the steps that apply based on what changed — most changes trigger more than one row.
- catalog / agents / skills / roles / providers changed →
npm run manifest:write:all,
then re-run asset-integrity LAST on its own (the parallel-generator ordering caveat in CLAUDE.md).
skills/**changed →npm run manifest:write.catalog/model-policy.jsonormodel-registry.jsonchanged → `npm run
model-policy:check (and model-policy:apply` if the projection changed).
tools/vfa-tui/**changed → `cd tools/vfa-tui && cargo fmt --check && cargo clippy
--all-targets -- -D warnings && cargo test. Return to the repo root afterwards — a persisted cd` has broken integrity runs before.
- any root file /
agents//plugins//package.jsonchanged → asset-integrity
refresh required.
The invariant sequence
Always, in this order:
- Applicable generators from the decision matrix above.
python3 tests/validate-asset-integrity.py --writefrom the REPO ROOT, last, on its own.npm run validate— zero failures.npm run lint:spellandnpx --yes markdownlint-cli2 "**/*.md" "#node_modules"— zero
failures.
git statusclean after committing with a scoped conventional-commit message.git push -u origin(retry with backoff on network errors only).
Footguns
grep -cE 'FAIL|ERROR'exits 1 on a count of 0 — do not chain it with&&before the
commit, or a clean gate run looks like a failure and blocks you.
- Run integrity from the repo root — a leftover
cdintotools/vfa-tuimakes the write
silently target a nonexistent path.
- Warnings from model-policy are exit-0 by design — read them, don't treat them as failures.
- Never edit
catalog/asset-integrity.jsonby hand.
Output
The checklist above with pass evidence per step, then the commit hash and push confirmation.
Delegation note
Gate runs may be delegated to a Haiku subagent per agentic-delegation's "Gate run" workflow template, but the orchestrator reads the results and owns the commit — a delegate's self-report that gates passed is not verification.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: VincentChuWaiChow
- Source: VincentChuWaiChow/vanguard-frontier-agentic
- License: Apache-2.0
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.