verify-artifact skill
Prove that the file you are about to send, publish, or hand off IS the thing you mean — before it leaves your hands. Rebuild from source, check integrity, diff the derived artifact against its source, and require the recipient to echo what they received. Use before sending a paper/PDF for review, shipping a release or replication package, handing files to a coauthor or collaborator, uploading anything to an external reviewer or model, or publishing. Prevents an entire review/QA cycle from being spent on defects that exist only in the artifact, not in the work.
Is the verify-artifact skill safe?
Clean: nothing in its files matched our rules. We read 1 file in the folder on 2026-09-28.
No findings.
Install the verify-artifact skill
A skill is a folder. Copy it into your agent's skills folder and the agent loads it when the task matches its description.
git clone --depth 1 https://github.com/pedrohcgs/claude-code-my-workflow.git /tmp/claude-code-my-workflow mkdir -p ~/.claude/skills cp -r /tmp/claude-code-my-workflow/.claude/skills/verify-artifact ~/.claude/skills/verify-artifact
In the Claude apps, zip the folder and upload it from the Skills settings. The folder on GitHub
The instructions your agent would load
SKILL.md as published, without the frontmatter. Read it on GitHub
Verify the artifact before it leaves
A review is only as good as the thing reviewed. If the artifact is corrupt, truncated, stale, or silently renumbered, a competent reviewer will return confident findings about defects that do not exist in your work — and you will spend a cycle chasing them. This is cheap to prevent and expensive to miss.
Rule: never send a derived artifact you have not diffed against its source.
1. Rebuild from source, in one shell invocation
Never send yesterday's build. Rebuild, then copy to the send location in the same command, so nothing can change underneath you.
Cloud-synced folders (Dropbox/iCloud/OneDrive) dehydrate files: a PDF can become 0 bytes or a partial copy between building and reading it. Symptoms: Syntax Error: Couldn't find trailer dictionary, a 70 KB file that should be 700 KB. Build-tool "up to date" messages are not evidence the file is intact — the tool checks timestamps, not content. Always stage to a local (non-synced) directory and verify there.
2. Integrity checks (mechanical, fast, non-negotiable)
- Size and structure: byte size in the expected range; page/record/row count as expected.
- It parses: open it with a real reader (pdfinfo, pdftotext, a JSON/CSV parser, unzip -t). A file that exists is not a file that works.
- Sample the content: first and last page/record actually contain what you expect — truncation shows up at the end.
- Unresolved markers: for documents, count ??, [cite], TODO, XXX, \ref{ leftovers, "Chapter ??"; for code/data, NaNs, empty cells, placeholder values.
3. Diff the derived artifact against its source
This is the step people skip and the one that pays. If you produced the artifact by transforming, excerpting, compressing, or subsetting, then enumerate what could have been lost and check it:
- Labels/anchors/IDs: set of identifiers in source vs artifact. Anything defined in source and referenced but missing in the artifact is a break.
- Numbering: removing a numbered object silently renumbers everything after it, so a citation that was "Lemma 10" becomes "Lemma 6" — every downstream reference now points somewhere plausible and wrong. Check numbering stability, not just presence.
- Counts: sections, tables, figures, rows, functions, endpoints — before vs after.
- Nested content: excerpting a block can remove statements nested inside it, not just the prose you meant to cut.
If you cut anything, leave a visible in-artifact note saying so, so a reviewer does not read an omission as a gap.
4. Make the recipient prove what they got
Ask the reviewer (human or model) to state, at the top of their response, the exact filenames, page/record counts, and version they are reviewing. This catches stale caches, wrong attachments, and silent fallbacks to an older upload — failures that are otherwise invisible until the findings make no sense.
Use unique filenames per round (report_r6.pdf, not report.pdf). Repeated identical names invite the recipient's system to serve a cached earlier copy.
5. If findings look strange, suspect the artifact first
Before acting on a review, ask: could this finding be an artifact of what I sent? Signals: complaints about missing/undefined references, "sections appear truncated", "the proof ends mid-argument", numbering that does not match your copy, or objections to text you know is present. Re-verify the artifact before you re-verify the work. Applying "fixes" for artifact-induced findings actively damages correct material.
Minimum checklist
- Rebuild from source; stage to a local dir in the same shell command.
- Verify it parses; check size, counts, first/last content.
- Count unresolved markers — expect zero.
- Diff identifiers/numbering/counts against source; note any deliberate omissions in the artifact itself.
- Unique filename for this round.
- Require the recipient to echo filename + counts.
Cross-references
- verification-ladder.md — rung 2 (existence → substantiveness → wiring → coherence)
- external-oracle-process.md §7 — cloud-synced files upload corrupt
More skills from pedrohcgs/claude-code-my-workflow
- Aadjudicate-reviewTurn an incoming set of findings — from an AI reviewer, a referee report, a code review, a linter, or a second model — into verified fixes, without letting a confident misread damage correct work. Every finding is a CANDIDATE until checked against the actual source. Use whenever you receive review comments, audit findings, or a critique you did not write yourself, especially when the reviewer is a model or when the volume is too large to check by feel.
- Aaudit-reproducibilityEnforce the replication-protocol.md rule by cross-checking numeric claims in a manuscript against the actual R / Stata / Python outputs. Report PASS/FAIL per claim against tolerance thresholds. Use before submission and before releasing a replication package.
- Ablast-radiusBefore and after changing anything shared — a function's return value, a signature, a schema, a label set, a config default, a constant, a file format — find every consumer and actually run them. Catches the change that looks purely additive but silently breaks a contract in a file you never opened. Use when editing shared code, adding a field/column/return element, renaming, changing units or defaults, or touching a pipeline that produces reported numbers.
- Acapture-environmentSnapshot the computational environment for a replication package — detects the analysis stack (R / Stata / Python) and emits the right lockfiles (renv.lock + sessionInfo.txt, requirements.txt / environment.yml / uv.lock, Stata version + ado package list), records seeds and RNG kind, optionally writes a pinning Dockerfile, and produces a paste-ready "Computational requirements" block. Use when user says "capture the environment", "snapshot my dependencies", "pin the versions", "make a renv.lock / requirements.txt", "make this byte-reproducible", or before releasing a replication package to openICPSR / the AEA Data Editor.
- AchallengeStress-test a finding against the choices you did not make. Enumerates the discrete forks a competent analyst could have taken (measure definition, sample filter, control set, clustering level, weighting, functional form), runs the specification grid, and reports the distribution rather than a point estimate — then attacks the identifying assumption with named, computable sensitivity statistics. Use when the user says "is this robust", "challenge this result", "specification curve", "multiverse", "how sensitive is this", "what if I'd used a different measure", "stress-test my estimate", or before a result becomes a headline claim. NOT a reviewer of prose or code — it challenges the CLAIM.
- AcheckpointSave a structured state snapshot before stopping or handing off. Captures the active plan, recent decisions, file pointers (with line numbers), open questions, and the next 1–3 actions into a checkpoint file under `quality_reports/checkpoints/`. Optionally proposes `[LEARN]` entries to add to MEMORY.md. Use when user says "checkpoint", "save state", "snapshot before I stop", "where am I", "wrap up the session for handoff", or before a long break / model switch / collaborator handoff. Companion to (NOT replacement for) the narrative session-log workflow.
- Acoauthor-briefGenerate a co-author / collaborator handoff brief for a multi-author, multi-machine project — summarizing what changed since the last brief (git delta), the current state of each artifact (manuscript, analysis, slides), open questions, how to reproduce locally, and any restricted-data access steps. Use when user says "coauthor brief", "handoff brief", "bring my coauthor up to speed", "what changed since last week", "onboard a collaborator", "write a handoff for [name]", or before sending a co-author the repo. NOT a commit or a checkpoint — it is the cross-machine, cross-person summary `meta-governance.md` only partially covers.
- AcommitCommit the current work — runs the quality, consistency and passport gates, branches off main if needed, stages specific files, and writes a commit whose subject states what is now true. Pushes and opens a pull request only with --pr or when the user asks; never merges — a merge happens only when the user explicitly says to merge. Use ONLY on explicit commit intent — user says "commit", "let's commit this", "open a PR", or prefixes with `/commit`. Do NOT auto-invoke on vague end-of-task phrases ("we're done", "wrap up") — those require explicit confirmation first. Never force-pushes or skips hooks.
- Acompile-latexCompile a Beamer LaTeX slide deck with XeLaTeX (3 passes + bibtex). Use when user says "compile", "build the slides", "rebuild the PDF", "run latex", "render the tex", or asks why a `.tex` file isn't producing a PDF. Operates on `Slides/*.tex`.
- Acompress-sessionDistill the current conversation into a structured note (decisions made, open questions, file pointers with line numbers, next 1–3 actions) and save to `quality_reports/session_logs/` before auto-compression. Differs from `/checkpoint` (explicit stop-point snapshot) and from auto-compaction (which truncates rather than distills). Use when context is approaching auto-compact threshold, when a long pipeline has accumulated many decisions, or when the user says "compress", "distil this session", "before we hit auto-compact", "structured handoff before context resets".
- Acontext-statusShow current context status and session health. Use to check how much context has been used, whether auto-compact is approaching, and what state will be preserved.
- Acreate-lectureCreate a new Beamer lecture `.tex` from source papers and materials, with notation consistency checks and the project's preamble wired in. Use when user says "create a lecture on X", "new lecture from these papers", "start a deck on topic Y", "scaffold a new Beamer file", "build me a lecture from these PDFs". Scaffolds the full deck — NOT for compiling existing `.tex` (use `/compile-latex`).