build-evidence-map skill
Build an auditable evidence map for a contested technical choice, research synthesis, proposal review, or consequential decision. Use when Copilot must preserve supporting, contradicting, qualifying, and missing evidence with exact source regions instead of collapsing disagreement into prose.
Is the build-evidence-map skill safe?
Clean: nothing in its files matched our rules. We read 5 files in the folder on 2026-09-28.
No findings.
Install the build-evidence-map skill
A skill is a folder. Copy it into your agent's skills folder and the agent loads it when the task matches its description.
git clone --depth 1 https://github.com/github/awesome-copilot.git /tmp/awesome-copilot mkdir -p ~/.claude/skills cp -r /tmp/awesome-copilot/skills/build-evidence-map ~/.claude/skills/build-evidence-map
In the Claude apps, zip the folder and upload it from the Skills settings. The folder on GitHub
The instructions your agent would load
SKILL.md as published, without the frontmatter. Read it on GitHub
Build Evidence Map
Turn one contested question into a portable decision artifact that shows what supports the current position, what pushes against it, and what remains unknown. Do not use a graph to decorate an answer that has not been sourced.
For a simple factual claim or a general fact-checking request, use a verification workflow such as doublecheck instead. Use this skill when the relationships between evidence, intermediate claims, trade-offs, and missing facts matter.
Workflow
position. Narrow the question until a reader can identify what action or belief the map is testing.
- Frame one decision. Write one falsifiable question and one provisional
sources. Record the URL or absolute local path, publisher, publication date, retrieval date, section/page/line/timestamp locator, and a short checkable excerpt. Read references/evidence-ladder.md when source quality is disputed.
- Collect bounded source regions. Prefer direct observations and primary
- Atomize the reasoning. Create only four node types:
- position: the single current verdict;
- claim: an intermediate proposition;
- evidence: a faithful statement of one source region;
- unknown: a specific missing fact that could change the verdict.
missing. Add a plain-language note explaining why the source node bears on the target. Topical similarity is not support. Different scope, date, or population is not automatically a contradiction.
- Type every edge. Use supports, contradicts, qualifies, or
provisional verdict survives it. Represent scope differences with qualifies edges.
- Preserve counterevidence. Do not delete contrary evidence because the
Add an unknown, narrow the position, or qualify a claim.
- Express uncertainty structurally. Do not invent confidence percentages.
references/map-schema.md. Keep IDs short, stable, and semantic.
- Write UTF-8 JSON with a .doubt.json suffix. Follow
scripts/validate.mjs relative to this SKILL.md, then run it with Node.js 18 or newer:
- Validate fail-closed. Resolve
node <skill-directory>/scripts/validate.mjs decision.doubt.jsonThe bundled validator uses only Node.js built-ins and does not require npm or network access. Fix every finding before reporting success. Only say the map is valid when the command exits 0 and prints VALID followed by a 64-character receipt. A file hash, node count, JSON parse, or manual schema review is not a Doubt receipt. If deterministic validation cannot run, report that block instead of inventing success.
Render the validated map only when the user has already installed doubt-ai@0.8.0; do not install or execute a remote package implicitly:
doubt map decision.doubt.json --out decision.htmlfollowing command retrieves each recorded HTTP(S) source and fails closed if an excerpt cannot be matched:
- Verify source snapshots only with explicit network permission. The
doubt verify decision.doubt.json \
--out decision.verified.doubt.jsonNever run this command implicitly. Local file verification does not use the network. Do not write a verification object by hand or hide a mismatch.
counterevidence, unknowns, edge notes, and exact source regions remain readable. Treat JSON as the canonical editable artifact; HTML is a shareable view.
- Inspect the deliverable. Confirm that the question, verdict,
Quality gates
A finished map must satisfy all of these:
excerpt;
- exactly one position has incoming reasoning;
- every evidence node names one source and participates in an edge;
- every source is used and has dates, a bounded locator, and a substantive
- every non-position node has a directed path to the position;
- the reasoning graph has no duplicate edges or directed cycles;
- contrary or qualifying evidence is present when the source set contains it;
- each decision-changing gap is an explicit unknown node;
- every edge note explains support, contradiction, qualification, or absence;
- the verdict is no broader than the evidence.
Deliver the result
Report:
- the current position in one sentence;
- the strongest counterevidence or qualification;
- the most important unresolved unknown;
- paths to the canonical JSON and any rendered HTML;
- whether deterministic validation and explicit source verification ran.
Never describe a structurally valid map as proven true. Validation establishes traceability and graph integrity; source quality and inference quality still require human review.
More skills from github/awesome-copilot
- Aacquire-codebase-knowledgeUse this skill when the user explicitly asks to map, document, or onboard into an existing codebase. Trigger for prompts like "map this codebase", "document this architecture", "onboard me to this repo", or "create codebase docs". Do not trigger for routine feature implementation, bug fixes, or narrow code edits unless the user asks for repository-level discovery.
- Aacreadiness-assessRun the AgentRC readiness assessment on the current repository and produce a static HTML dashboard at reports/index.html. Wraps `npx github:microsoft/agentrc readiness` and hands off rendering to the @ai-readiness-reporter custom agent. Supports policies (--policy) for org-specific scoring. Use when asked to assess, audit, or score the AI readiness of a repo.
- Aacreadiness-generate-instructionsGenerate tailored AI agent instruction files via AgentRC instructions command. Produces .github/copilot-instructions.md (default, recommended for Copilot in VS Code) plus optional per-area .instructions.md files with applyTo globs for monorepos. Use after running /acreadiness-assess to close gaps in the AI Tooling pillar.
- Aacreadiness-policyHelp the user pick, write, or apply an AgentRC policy. Policies customise readiness scoring by disabling irrelevant checks, overriding impact/level, setting pass-rate thresholds, or chaining org baselines with team overrides. Use when the user asks about strict mode, AI-only scoring, custom weights, CI gating, or wants org-wide standardisation.
- Aad-campaign-analyzerUse this skill when the user shares ad campaign performance data and asks what to cut, scale, or test. Trigger for prompts like "analyze my ad campaigns", "where am I wasting ad spend", "reallocate my ad budget", "which ads are actually working", or "ROAS analysis". Do not trigger for campaign planning or creative generation without performance data.
- Aadd-educational-commentsAdd educational comments to the file specified, or prompt asking for file to comment if one is not provided.
- Aadobe-illustrator-scriptingWrite, debug, and optimize Adobe Illustrator automation scripts using ExtendScript (JavaScript/JSX). Use when creating or modifying scripts that manipulate documents, layers, paths, text frames, colors, symbols, artboards, or any Illustrator DOM objects. Covers the complete JavaScript object model, coordinate system, measurement units, export workflows, and scripting best practices.
- Aagent-architectureDesign AI agent architectures through requirements discovery, or audit and diagnose architectural flaws in existing agents. Architecture only; excludes implementation and general code review.
- Aagent-governancePatterns and techniques for adding governance, safety, and trust controls to AI agent systems. Use this skill when: - Building AI agents that call external tools (APIs, databases, file systems) - Implementing policy-based access controls for agent tool usage - Adding semantic intent classification to detect dangerous prompts - Creating trust scoring systems for multi-agent workflows - Building audit trails for agent actions and decisions - Enforcing rate limits, content filters, or tool restrictions on agents - Working with any agent framework (PydanticAI, CrewAI, OpenAI Agents, LangChain, AutoGen)
- Aagent-owasp-complianceCheck any AI agent codebase against the OWASP Agentic Security Initiative (ASI) Top 10 risks. Use this skill when: - Evaluating an agent system's security posture before production deployment - Running a compliance check against OWASP ASI 2026 standards - Mapping existing security controls to the 10 agentic risks - Generating a compliance report for security review or audit - Comparing agent framework security features against the standard - Any request like "is my agent OWASP compliant?", "check ASI compliance", or "agentic security audit"
- Aagent-skill-stackFind, evaluate, and assemble the smallest compatible set of AI Agent Skills for an end-to-end natural-language goal. Use when a user wants Skills for a multi-step workflow, asks which Skills fit a project, needs an installed-Skill audit or conflict check, has low Skill recall, wants indirect helpers such as humanizers or compliance checks, or wants a project-specific Skill Stack with controlled installation. Search local Skills, registries, GitHub, and OpenCLI; compare adoption, verified fit, safety, and overlap. Do not use for locating one known or common Skill; use the generic find-skills workflow.
- Aagent-supply-chainVerify supply chain integrity for AI agent plugins, tools, and dependencies. Use this skill when: - Generating SHA-256 integrity manifests for agent plugins or tool packages - Verifying that installed plugins match their published manifests - Detecting tampered, modified, or untracked files in agent tool directories - Auditing dependency pinning and version policies for agent components - Building provenance chains for agent plugin promotion (dev → staging → production) - Any request like "verify plugin integrity", "generate manifest", "check supply chain", or "sign this plugin"