integrity-forensics skill
Run the Anti-Autoresearch integrity-forensics sweep (span-anchored evidence ledger → GPT auditors propose findings → a rules-only reporter that lists every proposal with what the auditor said about it) against a paper via a SHA-pinned thin launcher — then convert the verdict into a typed policy gate (BLOCK/WARN/NO_NEW_BLOCKER) and an append-only obligations ledger. Use when user says \"integrity forensics\", \"forensic audit this paper\", \"投稿前自查诚信\", \"审这篇论文的诚信\", or says \"anti-autoresearch\" when the upstream repo's own skills are not installed. Also invoked by /paper-writing (submission self-forensics, default ON), /peer-review (forensic appendix), /resubmit-pipeline.
Is the integrity-forensics skill safe?
Clean: nothing in its files matched our rules. We read 1 file in the folder on 2026-09-28.
No findings.
Install the integrity-forensics skill
A skill is a folder. Copy it into your agent's skills folder and the agent loads it when the task matches its description.
git clone --depth 1 https://github.com/wanshuiyin/Auto-claude-code-research-in-sleep.git /tmp/Auto-claude-code-research-in-sleep mkdir -p ~/.claude/skills cp -r /tmp/Auto-claude-code-research-in-sleep/skills/integrity-forensics ~/.claude/skills/integrity-forensics
In the Claude apps, zip the folder and upload it from the Skills settings. The folder on GitHub
The instructions your agent would load
SKILL.md as published, without the frontmatter. Read it on GitHub
Integrity Forensics — thin launcher for Anti-Autoresearch
Audit target: $ARGUMENTS
What this is. ARIS generates papers; Anti-Autoresearch
is its outward-pointed dual — reviewer-side integrity forensics (46 patterns
across 8 families, deterministic GRIM/GRIMMER/statcheck core, span-anchored
claims, a rules-only reporter that summarizes rather than adjudicates). This skill is a
thin launcher: it pins an upstream commit, validates the pin with the
upstream eval gate, delegates execution unchanged, and post-processes the
verdict into ARIS's policy vocabulary. It vendors nothing and forks nothing.
🔁 Cadence fence (shared-references/external-cadence.md): this skill is
verdict-bearing decision support. Do not wrap it in /loop / /schedule —
and NEVER as "iterate edits until it stops flagging" (see The One Forbidden
Loop below).
Constants
The launcher NEVER tracks upstream HEAD; bumping this constant is a reviewed change (see Pin-bump checklist).
- ANTIARREPO = https://github.com/wanshuiyin/Anti-Autoresearch.git
- ANTIARCOMMIT = b47af6f983b38347b6d2110379e266400597cf66 — the SHA-pin.
on purpose: ARIS also runs on DeepSeek Harness, Codex CLI, Cursor, Trae, Antigravity and Copilot CLI, where ~/.claude/ would name an installation the user does not have. An older clone at ~/.claude/anti-autoresearch is unused; move it and its .arisevalok_* receipt only to keep an offline deterministic-only run working, otherwise delete it whenever convenient.
- CLONEDIR = ~/.aris/anti-autoresearch** — the pinned working copy. Host-neutral
parameters and never maps ARIS — effort: onto upstream settings. The pinned upstream runs exactly what it pins (gpt-6-astra + xhigh, its own design decision). Overriding upstream review policy from a launcher would create a second, unauditable configuration surface.
- NO REVIEWER KNOBS. This launcher exposes no reviewer model/effort
(shared-references/integration-contract.md §2): .aris/tools/ → tools/ → $ARISREPO/tools/ → $ARISREPO/tools/ via ~/.aris/repo. Failure policy A (required): if it cannot be resolved at assurance: submission, STOP — never improvise the gate.
- GATEHELPER = forensicsgate.py — resolved via the canonical chain
Step 0 — Bootstrap the pin (idempotent)
CLONE_DIR="$HOME/.aris/anti-autoresearch"
ANTI_AR_COMMIT="b47af6f983b38347b6d2110379e266400597cf66"
mkdir -p "$HOME/.aris"
if [ ! -d "$CLONE_DIR/.git" ]; then
git clone --no-checkout https://github.com/wanshuiyin/Anti-Autoresearch.git "$CLONE_DIR"
fi
# fetch ONLY if the pin isn't already present — a cached, validated pin works offline
git -C "$CLONE_DIR" cat-file -e "$ANTI_AR_COMMIT^{commit}" 2>/dev/null \
|| git -C "$CLONE_DIR" fetch -q origin
git -C "$CLONE_DIR" checkout -qf "$ANTI_AR_COMMIT" || {
echo "FATAL: cannot checkout pinned commit $ANTI_AR_COMMIT"; exit 1; }
# Force a PRISTINE tree at the pin — local tampering with the clone (edited
# adjudicator, injected module, even one hidden inside a NESTED git repo,
# which single-f clean skips) must not survive bootstrap and run under the
# official pin's name. Every step is checked; then the tree is verified.
git -C "$CLONE_DIR" reset --hard -q "$ANTI_AR_COMMIT" || {
echo "FATAL: reset to pin failed"; exit 1; }
git -C "$CLONE_DIR" clean -ffdxq || {
echo "FATAL: clean failed"; exit 1; }
[ -z "$(git -C "$CLONE_DIR" status --porcelain)" ] || {
echo "FATAL: clone is not pristine after reset+clean — refusing tStep 1 — Delegate: run the upstream sweep, unchanged
Open and follow $CLONEDIR/workflows/anti-autoresearch/SKILL.md** end to end on the target. Two wrapper rules — the ONLY things this launcher adds:
Run every upstream bash block with cd "$CLONEDIR" first — ALWAYS the cd, never just an exported ROOT (upstream blocks re-derive ROOT themselves and would overwrite it) — and refer to the paper by absolute path**, otherwise upstream resolves ROOT to the ARIS repo and finds the wrong Python spine.
- cwd. Upstream skills self-locate via git rev-parse --show-toplevel.
(session hygiene; upstream already specifies fresh-thread-per-dimension, serial execution, and its own model pins — do not alter them).
- Codex calls carry approval-policy: never + sandbox: read-only
Everything else — the evidence ledger, coverage.json state machine, the nine auditor dimensions, the refutation pass, the deterministic summary — is upstream's contract. Never rewrite, soften, or re-map its outputs (report.json + REPORT.md, verdict ∈ CLEANGIVENEVIDENCE / SOFTFLAGS / HARDFLAGS / REVIEW_UNAVAILABLE). The observability level (L0/L1/L2) is whatever upstream derives from the artifacts present — do not promise L2.
Step 2 — Typed gate + obligations (ARIS-side post-processing)
# Resolve $GATE_HELPER via the canonical chain (integration-contract §2), then
# ONE atomic call (update + gate in a single locked transaction — the gate only
# ever speaks for the report the ledger has folded, sha-bound):
python3 "$GATE_HELPER" evaluate --report "$PAPER_DIR/report.json" --paper-dir "$PAPER_DIR" \
--anti-ar-commit "$ANTI_AR_COMMIT" --executor-model "<this pipeline's executor>"
# exit 0 = WARN / NO_NEW_BLOCKER · exit 1 = BLOCKThe gate translates the verdict into policy WITHOUT re-labeling it:
plus: any OPEN critical obligation → BLOCK; any OPEN obligation → at least WARN; a closed-without-receipt or unknown-status ledger entry → BLOCK (a hand-edited "status": "RESOLVED" does not open the gate).
gate.json also records a paperfingerprint (sha over the paper's compile inputs AND deliverables — .tex/.bib/.sty/.cls/figures/PDF). The downstream preflight is ONE command: python3 "$GATEHELPER" fresh --paper-dir "$PAPERDIR" --anti-ar-commit "$ANTIARCOMMIT" — exit 0 ⟺ the gate was produced at the CURRENT pin ∧ a gate exists ∧ nothing in the paper changed after it ∧ the gate matches the current obligations ledger ∧ the decision — re-computed from the sha-verified archived report (lastreport.json) + the live ledger, never read from the gate's stored token — is pass-capable (WARN / NONEWBLOCKER). Anything else — missing gate, post-gate edit or recompile, unbound ledger or archive, recompute mismatch, BLOCK, unknown token — exits 1: re-run the sweep + evaluate. Every ledger mutation (update/resolve/waive) deletes the standing gate.json, so an interrupted run can never leave a stale pass; and evaluate refuses a report OLDER than any paper file (a stale report cannot be folded onto text it never audited). Run evaluate immediately after the sweep, before touching any paper file.
The gate artifact also records honest provenance: upstream's auditors are GPT-family, so for a Claude executor the findings carry cross-family proposal provenance; for a Codex executor they are same-family. Either way this gate only raises flags — it has no acceptance to grant, so the distinction is informational, not a loophole.
Step 3 — Fix what it found (obligations, not a polish loop)
Every OPEN obligation gets DISPOSITIONED — fixed, or explicitly waived. Upstream now reports every proposal an auditor made rather than deciding which ones do not count, so expect more obligations than a pre-2026-08 sweep opened, and expect some of them to be proposals you disagree with. waive is a first-class, expected outcome — "a model proposed this and I, the human, judge it wrong" is a normal disposition here, not a last resort. Weigh each one against the report's columns: Anchored, Observability, FP-risk, Surface, Ext-check.
For the ones that are real, use the right door:
Close each obligation explicitly — the receipt is typed and hashed:
python3 "$GATE_HELPER" resolve --paper-dir "$PAPER_DIR" --obligation-id <id> \
--fix-type corrected-from-results|claim-narrowed|claim-withdrawn|citation-replaced \
--evidence <path-to-the-ground-truth-that-backs-the-fix> \
--verified-by "human:<name>" | "checker:<tool>" | "cross-family-review:<thread-id>"
# or, with HUMAN sign-off only:
python3 "$GATE_HELPER" waive --paper-dir "$PAPER_DIR" --obligation-id <id> \
--approver "human:<name>" --reason "<why this stands as-is>"Rules the ledger enforces mechanically (tests/testforensicsgate.py):
UNRESOLVED_DISAPPEARANCE — rewording the span is not a fix;
- append-only — re-running the sweep can open obligations, never close them;
- a finding that disappears from a later report stays OPEN and gains
legitimate resolution — with the deletion diff as evidence);
- claim-withdrawn is an honest fix (deleting an unsupported claim is a
original finding snapshot immutable;
- a waiver is not a resolution: human-approved, permanently recorded,
critical needs a family checker, a fresh cross-family review, or a human (--verified-by requires TYPED provenance and is recorded; naming a human who did not approve is a false record with a permanent paper trail);
- the executor's fix_type label is a receipt, not a verdict — closure of a
evidence file must still exist and still hash to what was recorded at closure time — editing the evidence after closing re-opens the BLOCK;
- receipts are re-verified, not remembered: on every later gate the
finish Step 3 by re-running the sweep + evaluate, so the gate that downstream preflights read reflects the post-fix state.
- resolve/waive (like update) invalidate the standing gate.json —
The One Forbidden Loop
Never run "edit → re-sweep → repeat until CLEAN". That objective function teaches the editor to defeat the detector — deleting an anchored span kills a flag faster than fixing the number, and the result is a paper laundered against its own audit. The re-run after fixes exists to confirm the DISCREPANCY is gone (and to catch new ones); the obligations ledger — not the verdict — decides whether the gate opens.
Trust boundary (what is computed vs what is protocol)
append-only ledger lifecycle, sha bindings (report ↔ ledger ↔ archive), receipt re-hashing, the paper fingerprint, pin/version match, and the recomputed decision (fresh never trusts a stored token).
- Computed (the gate enforces these mechanically): verdict→policy mapping,
More skills from wanshuiyin/Auto-claude-code-research-in-sleep
- Aablation-plannerUse when main results pass result-to-claim (claim_supported=yes or partial) and ablation studies are needed for paper submission.
- Aablation-plannerUse when main results pass result-to-claim (`claim_supported = yes` or `partial`) and ablation studies are needed for paper submission. A secondary Codex agent designs ablations from a reviewer's perspective; the local executor reviews feasibility and implements.
- AalphaxivQuick single-paper lookup via AlphaXiv LLM-optimized summaries with tiered source fallback. Use when user says "explain this paper", "summarize paper", pastes an arXiv/AlphaXiv URL, or provides a bare arXiv ID for quick understanding - not for broad literature search.
- AalphaxivQuick single-paper lookup via AlphaXiv LLM-optimized summaries with tiered source fallback. Use when user says "explain this paper", "summarize paper", pastes an arXiv/AlphaXiv URL, or provides a bare arXiv ID for quick understanding - not for broad literature search.
- Aanalyze-resultsAnalyze ML experiment results, compute statistics, generate comparison tables and insights. Use when user says "analyze results", "compare", or needs to interpret experimental data.
- Aanalyze-resultsAnalyze ML experiment results, compute statistics, generate comparison tables and insights. Use when user says \"analyze results\", \"compare\", or needs to interpret experimental data.
- AarxivSearch, download, and summarize academic papers from arXiv. Use when user says "search arxiv", "download paper", "fetch arxiv", "arxiv search", "get paper pdf", or wants to find and save papers from arXiv to the local paper library.
- AarxivSearch, download, and summarize academic papers from arXiv. Use when user says \"search arxiv\", \"download paper\", \"fetch arxiv\", \"arxiv search\", \"get paper pdf\", or wants to find and save papers from arXiv to the local paper library.
- Aauto-paper-improvement-loopAutonomously improve a generated paper via GPT-6-Astra xhigh review → implement fixes → recompile, for 2 rounds. Use when user says \"改论文\", \"improve paper\", \"论文润色循环\", \"auto improve\", or wants to iteratively polish a generated paper.
- Aauto-paper-improvement-loopAutonomously improve a generated paper via Claude review through claude-review MCP → implement fixes → recompile, for 2 rounds. Use when user says \"改论文\", \"improve paper\", \"论文润色循环\", \"auto improve\", or wants to iteratively polish a generated paper.
- Aauto-paper-improvement-loopAutonomously improve a generated paper via Gemini review through gemini-review MCP → implement fixes → recompile, for 2 rounds. Use when user says \"改论文\", \"improve paper\", \"论文润色循环\", \"auto improve\", or wants to iteratively polish a generated paper.
- Aauto-paper-improvement-loopAutonomously improve a generated paper via GPT-6-Astra xhigh review → implement fixes → recompile, for 2 rounds. Use when user says \"改论文\", \"improve paper\", \"论文润色循环\", \"auto improve\", or wants to iteratively polish a generated paper.