Verify-Agent-Action
Verify-Agent-Action is an data AI skill with a core value of Review a proposed AI-agent action or human-approval packet before execution. It
helps developers solve real-world problems in the data domain, boosting
efficiency, automating repetitive tasks, and optimizing workflows.
Review a proposed AI-agent action or human-approval packet before execution. Use when an agent wants to run a consequential tool, command, deployment, message, purchase, credential operation, or data
Quick Facts
mkdir -p ./skills/verify-agent-action && curl -sfL https://raw.githubusercontent.com/github/awesome-copilot/main/skills/verify-agent-action/SKILL.md -o ./skills/verify-agent-action/SKILL.md Run in terminal / PowerShell. Requires curl (Unix) or PowerShell 5+ (Windows).
Skill Content
# Verify Agent Action
Treat a plausible approval screen as a claim, not proof. Verify the complete
decision path before a human or an external enforcement point decides whether
to act.
Preserve the safety boundary
- Never execute, approve, sign, send, purchase, deploy, or mutate anything.
- Never convert this review into execution authority.
- Never infer missing evidence, identities, timestamps, or parameters.
- Treat a valid schema, checksum, or signature as insufficient by itself.
- Treat signatures as evidence of attribution and integrity, not factual truth.
- Keep supporting and refuting evidence separate; do not average conflict away.
- Fail closed on a material mismatch. Use `INCONCLUSIVE` when required evidence
is unavailable.
Set this field in every final result:
{"execution_authorized": false}Collect the review packet
Request only the artifacts needed for the review:
1. The original user or system request.
2. The exact proposed action:
- operation or tool name
- target resource
- complete parameters
- filesystem and network scope
- maximum execution count
- not-before and expiry times
3. The assessment that claims the action is justified.
4. The source evidence and policy used by that assessment.
5. The approval record, including approver identity, role, action digest, nonce,
audience, issue time, expiry, and use count.
6. The latest monitoring events and expected heartbeat interval.
7. The current trusted time and any prior nonce-use record.
List missing fields before analysis. Do not silently substitute defaults.
Build the exact action identity
Create one normalized action object without dropping fields:
{
"operation": "git.push",
"target": "owner/repository",
"parameters": {
"branch": "fix/example",
"commit": "40-character-sha",
"remote": "origin"
},
"filesystem_scope": [],
"network_scope": ["github.com:443"],
"execution_count": 1,
"not_before": "RFC3339 timestamp",
"expires_at": "RFC3339 timestamp"
}Use a project-specified canonicalization and digest algorithm when provided.
Otherwise, report that cryptographic identity cannot be independently verified;
still compare every field structurally.
Never normalize away a security-relevant distinction such as:
- branch, commit, repository, environment, recipient, amount, currency, or host
- recursive, force, overwrite, privileged, destructive, or dry-run flags
- filesystem roots, CIDRs, ports, domains, execution counts, or expiry
Run the six controls
Evaluate every control as `PASS`, `FAIL`, `INCONCLUSIVE`, or `NOT_APPLICABLE`.
1. Recompute the assessment
- Re-run the declared deterministic evaluator from the declared source inputs
when its implementation is available.
- Compare the complete canonical result, not selected fields.
- Mark `FAIL` if the received result differs from recomputation.
- Mark `INCONCLUSIVE` when only schema validation, an internal checksum, or an
unverifiable evaluator claim is available.
2. Match the exact approved action
- Compare the proposed action with the action bound into the approval.
- Compare the complete normalized object and its digest.
- Mark `FAIL` if any material field changed after approval.
- Treat a broad target or scope as a mismatch when the evidence justifies only
a narrower action.
3. Reject replay and identity ambiguity
- Verify the nonce is unique and unused.
- Verify subject, audience, issuer, approver role, issue time, not-before time,
expiry, and maximum use count.
- Mark `FAIL` for a reused nonce, wrong audience, expired approval, future-dated
approval, excessive use count, revoked identity, or role mismatch.
- Mark `INCONCLUSIVE` if no trustworthy replay store or time source exists.
4. Test reviewer independence
Build a dependence table for every reviewer or evaluator:
| Dimension | Compare |
|---|---|
| Model | family, version, fine-tune |
| Provider | account and control pla
🎯 Best For
- Engineering teams doing code reviews
- Open source maintainers
- GitHub Copilot users
- Claude users
- Data professionals
💡 Use Cases
- Reviewing pull requests for security vulnerabilities
- Checking code style consistency
- Data pipeline auditing
- Query optimization
📖 How to Use This Skill
- 1
Install the Skill
Copy the install command from the Terminal tab and run it. The SKILL.md file downloads to your local skills directory.
- 2
Load into Your AI Assistant
Open GitHub Copilot or Claude and reference the skill. Paste the SKILL.md content or use the system prompt tab.
- 3
Apply Verify-Agent-Action to Your Work
Provide context for your task — paste source material, describe your audience, or share existing work to guide the AI.
- 4
Review and Refine
Edit the AI output for accuracy, tone, and completeness. Add human insight where the AI lacks context.
❓ Frequently Asked Questions
Does this skill check for OWASP Top 10?
Security-focused review skills often include OWASP checks. Check the skill content for specific vulnerability categories covered.
How do I install Verify-Agent-Action?
Copy the install command from the Terminal tab and run it. The skill downloads to ./skills/verify-agent-action/SKILL.md, ready to use.
Can I customize this skill for my team?
Absolutely. Edit the SKILL.md file to add team-specific instructions, examples, or workflows.
⚠️ Common Mistakes to Avoid
Blindly accepting AI suggestions
Always verify AI-generated review comments. Some suggestions may not apply to your specific codebase conventions.
Ignoring data quality
AI analysis inherits all data quality issues — profile your data first.