decodie-verify
Verify that learning entries still match the source code they reference. Resolves content-based anchors, stamps confirmed entries with the current commit SHA, and marks mismatches as stale. Use to maintain entry accuracy after code changes.
How do I install this agent skill?
npx skills add https://github.com/owenbush/decodie-skill --skill decodie-verifyIs this agent skill safe to install?
- Gen Agent Trust Hubpass
The 'decodie-verify' skill is used to keep documentation anchors in sync with source code. It performs local file reads and updates its own configuration file, using a standard git command to track the repository state. No malicious patterns such as exfiltration, obfuscation, or remote code execution were found.
- Socketpass
No alerts
- Snykpass
Risk: LOW · No issues
What does this agent skill do?
Decodie — Verify Mode
Confirm that every learning entry in .decodie/index.json still matches the source code it references, mark mismatches as stale, and stamp confirmed entries with the current commit SHA.
This mode modifies .decodie/index.json only. It never modifies session files, source code, or anything outside .decodie/.
Activation
Parse the optional path argument:
- If no path provided, verify all entries.
- If a path is provided, verify only entries whose
sources(orreferences[].file) overlap that path. For a directory, an entry is in scope if any source file starts with that directory. - If the path does not exist, report the error and stop.
Setup
- Confirm
.decodie/exists. If not: "No.decodie/directory found — nothing to verify." Stop. - Read
.decodie/index.json. If empty: "No entries to verify." Stop. - Determine current commit SHA:
If not a git repo, warn and continue (anchor checks still run, butgit rev-parse HEADverified_shacannot be set).
Verification Process
For each entry in scope:
-
Resolve source files. Prefer
sources; fall back to uniquereferences[].filevalues. If falling back, backfill thesourcesfield. -
Check each reference
{ file, anchor, anchor_hash }:- File missing → reference fails.
- File exists → search for literal
anchorstring. If found, recompute SHA-256 hash and confirm first 8 hex chars matchanchor_hash.
-
Decide outcome:
- All references resolve →
stale: false,verified_sha= HEAD SHA. - Any reference fails →
stale: true, leaveverified_shaunchanged.
- All references resolve →
-
Write back to
index.json. Preserve all other fields and sort order.
Reporting
Decodie verify
Verified: N entries (verified_sha -> <short-sha>)
Stale: M entries
Skipped: K entries (out of scope)
Backfilled sources on: B entries
If stale entries exist, list them:
Stale entries:
- entry-1711540000-a1b2 -- references/0: src/lib/foo.ts (anchor not found)
- entry-1711540123-c3d4 -- references/1: src/lib/bar.ts (file missing)
Important Notes
- Append-only for entry content. Only
sources,verified_sha, andstalemay be updated. - Idempotent. Running twice with no changes is a no-op.
- Path is a filter. Out-of-scope entries are skipped, not cleared.
- No git history rewriting. Only reads HEAD via
git rev-parse.
How can the creator link this skill?
Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.
<a href="https://skillzs.dev/skills/owenbush/decodie-skill/decodie-verify">View decodie-verify on skillZs</a>