grounded-vault skill
Use when maintaining a durable Markdown knowledge store that agents compile from sources, when every number or quote in a wiki page must trace back to an immutable source, or when compiled pages need cheap drift detection against the code they describe. Teaches the raw/wiki/archive layout, per-claim provenance links, and git fingerprints for zero-token staleness checks.
Is the grounded-vault skill safe?
Clean: nothing in its files matched our rules. We read 2 files in the folder on 2026-09-28.
No findings.
Install the grounded-vault skill
A skill is a folder. Copy it into your agent's skills folder and the agent loads it when the task matches its description.
git clone --depth 1 https://github.com/wshobson/agents.git /tmp/agents mkdir -p ~/.claude/skills cp -r /tmp/agents/plugins/documentation-standards/skills/grounded-vault ~/.claude/skills/grounded-vault
In the Claude apps, zip the folder and upload it from the Skills settings. The folder on GitHub
The instructions your agent would load
SKILL.md as published, without the frontmatter. Read it on GitHub
Grounded Vault
A grounded vault is a three-layer Markdown store in which every compiled claim can be traced back to an immutable source and every page can be checked for staleness with one git diff. It needs a git repository and nothing else. The convention comes from the llm-wiki-loop project, which is a reference implementation rather than a dependency; this skill teaches the pattern so it works with plain files and whatever agent is in the session.
When to Use
- An agent compiles notes, papers, transcripts, logs, or code into wiki pages that later sessions rely on.
- A page cites numbers, dates, or quotes, and a reader must be able to verify each one against its source.
- Pages describe code, and rereading the codebase every session to check whether they still hold is too expensive.
- Knowledge must be corrected without losing history: superseded pages are archived, never deleted.
Session state, task queues, and conversation continuity are a different problem; use the context-management or conductor plugins for those. This skill is about provenance and drift on a durable knowledge store.
The three layers
Two files sit at the vault root. index.md is the map of every current page. log.md is an append-only record of what changed and why. Both change in the same commit as the page they describe.
Page header contract
Every wiki/ page opens with a header block:
# Authentication architecture
> Raw: [raw/notes/auth-v1.md](../raw/notes/auth-v1.md), [raw/adr/0007-jwt.md](../raw/adr/0007-jwt.md)
> Fingerprint: git:5b237fa
> Monitored: src/auth/jwt.ts, src/auth/session.ts, package.json
> Status: Current- Raw: lists every source the page was compiled from. Inline claims link to their specific source as well: Tokens expire after 15 minutes (raw/adr/0007-jwt.md).
- Fingerprint: is the short commit hash the page was compiled against.
- Monitored: lists the code paths the page describes. A change to any of them after the fingerprint means the page may be stale.
- Status: is Current, Outdated (monitored code moved on), or Disputed (a newer source contradicts the page).
Grounding rule
A compiled page states only what a source supports, and every number, date, or quotation appears verbatim in the linked source. A synthesis says it is one and links its inputs. A gap in the sources is written into the page as a gap rather than filled by guessing.
Check it mechanically: for each linked claim, search the linked raw file for the exact figure or quoted phrase. A miss is a grounding error and blocks the commit. The script in references/details.md does this for a whole vault.
Drift detection
Compare the fingerprint with the current tree instead of rereading monitored code:
git diff --stat 5b237fa..HEAD -- src/auth/jwt.ts src/auth/session.ts package.jsonEmpty output means the page still describes the code it was compiled against. Any output means recompile: reread only the changed files, update the page, and stamp the new fingerprint. The check runs in milliseconds and spends no model tokens.
Workflow
- Ingest. Put new material in raw/ under a dated or sourced filename. Never rewrite an existing raw file; add a new one beside it.
- Compile. Write or update the wiki/ page with the header block, a source link on every claim, and the fingerprint of the commit the code was read at.
- Check. Run the grounding check and the drift check before committing. Fix misses at the source; do not weaken a claim to make the check pass.
- Garbage collect. When drift or a contradicting source appears and the page is not recompiled now, change its status, move it to archive/, and record the reason:
> Status: Outdated
> Reason: src/auth/session.ts changed after git:5b237fa; see log.md 2026-09-01- Update the map. Every add, move, or archive updates index.md and appends one line to log.md in the same commit.
Commit gate
Run both checks from a pre-commit hook or a CI step so a page cannot land with an unverifiable number or a stale fingerprint:
python3 scripts/check_vault.py --strict # exits 1 on any grounding miss or drifted pageGoing deeper
references/details.md covers: the vault check script, batching the drift check across pages, templates for index.md and log.md, renamed or deleted monitored files, sources that are binary or live at external URLs, and the reference implementation.
More skills from wshobson/agents
- Aairflow-dag-patternsBuild production Apache Airflow DAGs with best practices for operators, sensors, testing, and deployment. Use when creating data pipelines, orchestrating workflows, or scheduling batch jobs.
- Aangular-migrationMigrate from AngularJS to Angular using hybrid mode, incremental component rewriting, and dependency injection updates. Use when upgrading AngularJS applications, planning framework migrations, or modernizing legacy Angular code.
- Aanti-reversing-techniquesUnderstand anti-reversing, obfuscation, and protection techniques encountered during software analysis. Use this skill when analyzing malware evasion techniques, when implementing anti-debugging protections for CTF challenges, when reverse engineering packed binaries, or when building security research tools that need to detect virtualized environments.
- Aapi-design-principlesMaster REST and GraphQL API design principles to build intuitive, scalable, and maintainable APIs that delight developers. Use when designing new APIs, reviewing API specifications, or establishing API design standards.
- Aarchitecture-decision-recordsWrite and maintain Architecture Decision Records (ADRs) following best practices for technical decision documentation. Use when documenting significant technical decisions, reviewing past architectural choices, or establishing decision processes.
- Aarchitecture-patternsImplement proven backend architecture patterns including Clean Architecture, Hexagonal Architecture, and Domain-Driven Design. Use this skill when designing clean architecture for a new microservice, when refactoring a monolith to use bounded contexts, when implementing hexagonal or onion architecture patterns, or when debugging dependency cycles between application layers.
- Aasync-python-patternsMaster Python asyncio, concurrent programming, and async/await patterns for high-performance applications. Use when building async APIs, concurrent systems, or I/O-bound applications requiring non-blocking operations.
- Aauth-implementation-patternsMaster authentication and authorization patterns including JWT, OAuth2, session management, and RBAC to build secure, scalable access control systems. Use when implementing auth systems, securing APIs, or debugging security issues.
- Aavoid-ai-writingAudit and rewrite prose so it stops reading as machine-generated. Use this skill when asked to remove AI-isms, clean up AI writing, edit a draft for AI tells, audit a README, changelog, release note, PR description, or blog post for machine-sounding prose, or make text sound less like AI. Supports a detect-only mode, a rewrite mode, and an edit-in-place mode, with optional voice and context profiles.
- Abacktesting-frameworksBuild robust backtesting systems for trading strategies with proper handling of look-ahead bias, survivorship bias, and transaction costs. Use when developing trading algorithms, validating strategies, or building backtesting infrastructure.
- Abazel-build-optimizationOptimize Bazel builds for large-scale monorepos. Use when configuring Bazel, implementing remote execution, or optimizing build performance for enterprise codebases.
- Abefore-you-buildPre-build product and feature risk review for founders, product managers, and AI-assisted builders. Use this skill when the user is about to build a landing page, MVP, SaaS product, internal tool, agent workflow, or major feature and needs to check demand, positioning, monetization, retention, trust, distribution, and adoption risk before implementation starts.