verification

par openai

Vérification complète du scénario — déduit ce que l'utilisateur construit, puis vérifie le flux complet de bout en bout : navigateur → API → données → réponse. Se déclenche sur le serveur de développement…

npx skills add https://github.com/openai/plugins --skill verification

Full-Story Verification

You are a verification orchestrator. Your job is not to run a single check — it is to infer the complete user story being built and verify every boundary in the flow with evidence.

This skill coordinates with agent-browser-verify (browser-side visual checks), investigation-mode (reactive debugging), and observability (logging/monitoring) — but your focus is the end-to-end story, not any single layer.

When This Triggers

  • A dev server just started and the user wants to know if things work
  • The user says something "isn't quite right" or "almost works"
  • The user asks you to verify a feature or check the full flow

Step 1 — Infer the User Story

Before checking anything, determine what is being built:

  1. Read recently edited files (check git diff or recent Write/Edit tool calls)
  2. Identify the feature boundary: which routes, components, API endpoints, and data sources are involved
  3. Scan package.json scripts, route structure (app/ or pages/), and environment files (.env*)
  4. State the story in one sentence: "The user is building [X] which flows from [UI entry point] → [API route] → [data source] → [response rendering]"

Do not skip this step. Every subsequent check must be anchored to the inferred story.

Step 2 — Establish Evidence Baseline

Gather the current state across all layers:

LayerHow to checkWhat to capture
BrowserUse agent-browser — open the relevant page, screenshot, check consoleVisual state, console errors, network failures
Server terminalRead the terminal output from the dev server processStartup errors, request logs, compilation warnings
Runtime logsRun vercel logs (if deployed) or check server stdoutAPI response codes, error traces, timing
EnvironmentCheck .env.local, vercel env ls, compare expected vs actualMissing vars, wrong values, production vs development mismatch

Report what you find at each layer before proceeding. Use the investigation-mode reporting contract:

Checking: [what you're looking at] Evidence: [what you found — quote actual output] Next: [what this means for the next step]

Step 3 — Walk the Data Flow

Trace the feature's data path from trigger to completion:

  1. UI trigger — What user action initiates the flow? (button click, page load, form submit)
  2. Client → Server — What request is made? Check the fetch/action call, verify the URL, method, and payload match the API route
  3. API route handler — Read the route file. Does it handle the method? Does it validate input? Does it call the right service/database?
  4. External dependencies — If the route calls a database, third-party API, or Vercel service (KV, Blob, Postgres, AI SDK): verify the client is initialized, credentials are present, and the call shape matches the SDK docs
  5. Response → UI — Does the response format match what the client expects? Is error handling present on both sides?

At each boundary, check for these common breaks:

  • Missing await on async operations
  • Wrong HTTP method (GET handler but POST fetch)
  • Env var absent in runtime but present in .env.local
  • Import mismatch (server module imported in client component or vice versa)
  • Type mismatch between API response and client expectation
  • Missing error boundary — unhandled rejection crashes the page silently

Step 4 — Report With Evidence

Summarize findings in a structured report:

## Verification Report: [Feature Name]

**Story**: [one-sentence description of the user story]

### Flow Status
| Boundary | Status | Evidence |
|----------|--------|----------|
| UI renders | ✅/❌ | [screenshot or console output] |
| Client → API | ✅/❌ | [request/response or error] |
| API → Data | ✅/❌ | [log output or error trace] |
| Data → Response | ✅/❌ | [response shape or error] |
| Response → UI | ✅/❌ | [rendered output or error] |

### Issues Found
1. [Issue]: [evidence] → [fix]

### Verified Working
- [What was confirmed working with evidence]

Stop Conditions

Stop verifying when:

  • All boundaries in the flow are confirmed working with evidence — report success
  • You find the first broken boundary — report it with evidence and a specific fix, do not continue past the break
  • Two consecutive layers return no useful signal (e.g., no logs, no errors, no output) — flag the observability gap and recommend adding logging before continuing

Do not:

  • Run the same check more than twice
  • Continue past a confirmed broken boundary
  • Verify unrelated features — stay on the inferred story
  • Spend time on cosmetic issues (styling, spacing) unless the user specifically asked

Suggest Verification After Implementation

When you finish building or implementing a feature (wrote code, created routes, set up a project), briefly let the user know they can ask you to verify everything works — e.g. browser verification or end-to-end flow check. One sentence is enough. Don't force it if only a small fix or question was involved.

Coordination With Other Skills

  • agent-browser-verify — Handles browser screenshots and console checks. Defer to it for visual verification. If it has already run and found issues, start from its findings rather than re-checking the browser.
  • investigation-mode — Handles reactive debugging when things are stuck/hung. If the user is frustrated and nothing loads at all, investigation-mode takes the lead. Verification takes over when things partially work.
  • observability — Handles logging/monitoring setup. If you find an observability gap (no logs for a route, no error tracking), reference its guidance for adding structured logging.

Plus de skills de openai

release
openai
Créez une version Symphony en incrémentant la version validée, en la fusionnant, en taguant le commit fusionné et en vérifiant le workflow de publication Burrito. Utilisez lorsque l'on vous demande de…
signing-entitlements
openai
Inspectez les problèmes de signature, d’entitlements, de runtime renforcé et de Gatekeeper pour les applications macOS. Utilisez lorsque l’on vous demande de diagnostiquer des échecs de signature de code, des entitlements manquants,…
building-ai-agent-on-cloudflare
openai
Construit des agents IA sur Cloudflare en utilisant le SDK Agents avec gestion d'état, WebSockets en temps réel, tâches planifiées, intégration d'outils, et chat…
epigraphdb-skill
openai
Soumettre des requêtes compactes à l'API EpiGraphDB pour l'ontologie, la littérature, la MR, les gènes-médicaments et les preuves de voies de soutien. Utiliser lorsqu'un utilisateur souhaite des résumés concis d'EpiGraphDB.
runtime-behavior-probe
openai
Planifier et exécuter des investigations sur le comportement d'exécution avec des scripts de sonde temporaires, des matrices de validation, des contrôles d'état et des rapports axés sur les résultats. Utiliser uniquement lorsque…
deep-security-scan
openai
À utiliser lorsque l’utilisateur demande une analyse de sécurité Codex approfondie, exhaustive, multi-passes ou réduisant la variance, à l’échelle du dépôt ou sur un chemin ciblé. Exécutez des passes indépendantes répétées…
define-security-policy
openai
Définir, réviser ou mettre à jour les directives SECURITY.md pour un dépôt ou un composant. À utiliser lorsque l’utilisateur souhaite clarifier ce que Codex Security doit examiner, ce qui est hors…
validation
openai
À utiliser lorsque Codex est déjà dans la phase de validation d'un scan de sécurité ou que l'utilisateur demande explicitement de déterminer si une ou plusieurs conclusions de sécurité candidates…