SkillAgentSearch skills...

integrity-forensics

Run the Anti-Autoresearch integrity-forensics sweep (span-anchored evidence ledger → GPT auditors propose findings → a rules-only reporter that lists every proposal with what the auditor said about it) against a paper via a SHA-pinned thin launcher — then convert the verdict into a typed policy gate…

Install / Use

npx skills add wanshuiyin/Auto-claude-code-research-in-sleep --skill integrity-forensics

Installs into whichever agent you are using.

About this skill
📄

SKILL.md

Installable skill definition

Quality Score

96/100

Supported Platforms

Universal

Tags

Our assessment of integrity-forensics

integrity-forensics scores 96/100 on our quality scale, 70th of 794 AI & Machine Learning skills we index (top 9%).

Its SKILL.md is 17 KB long, well organised into 26 sections with 3 code examples: a thorough specification that gives an agent plenty to work with.

With 16,644 GitHub stars, it is one of the more widely adopted skills in the catalogue.

Substance
30/30
Structure
18/20
Description
15/15
Adoption
18/20
Freshness
15/15

Maintenance, license and trust

  • The repository was last updated 9 days ago, so integrity-forensics is actively maintained.
  • It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
  • Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

integrity-forensics compared with similar skills

All 4 of these similar skills score higher than integrity-forensics; compare them before choosing.

SkillScoreStarsUpdatedFormat
integrity-forensics (this skill)by wanshuiyin9616.6k9d agoSKILL.md
claude-memby thedotmack10094.8ktodayCLAUDE.md
Understand-Anythingby Egonex-AI10084.4k16d agoCLAUDE.md
headroomby headroomlabs-ai10074.0k1d agoCLAUDE.md
CowAgentby zhayujie10047.1ktodayCLAUDE.md

Frequently asked questions

How do I install integrity-forensics?
Run npx skills add wanshuiyin/Auto-claude-code-research-in-sleep --skill integrity-forensics. The install tabs above show the steps for each supported agent.
Which AI agents does integrity-forensics work with?
It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
Is integrity-forensics safe to use?
It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is integrity-forensics still maintained?
The repository was last updated 9 days ago, so integrity-forensics is actively maintained.

name: integrity-forensics description: "Run the Anti-Autoresearch integrity-forensics sweep (span-anchored evidence ledger → GPT auditors propose findings → a rules-only reporter that lists every proposal with what the auditor said about it) against a paper via a SHA-pinned thin launcher — then convert the verdict into a typed policy gate (BLOCK/WARN/NO_NEW_BLOCKER) and an append-only obligations ledger. Use when user says "integrity forensics", "forensic audit this paper", "投稿前自查诚信", "审这篇论文的诚信", or says "anti-autoresearch" when the upstream repo's own skills are not installed. Also invoked by /paper-writing (submission self-forensics, default ON), /peer-review (forensic appendix), /resubmit-pipeline." argument-hint: "[paper-dir | pdf | arxiv-id]" allowed-tools: Bash(*), Read, Write, Grep, Glob, mcp__codex__codex

Integrity Forensics — thin launcher for Anti-Autoresearch

Audit target: $ARGUMENTS

What this is. ARIS generates papers; Anti-Autoresearch is its outward-pointed dual — reviewer-side integrity forensics (46 patterns across 8 families, deterministic GRIM/GRIMMER/statcheck core, span-anchored claims, a rules-only reporter that summarizes rather than adjudicates). This skill is a thin launcher: it pins an upstream commit, validates the pin with the upstream eval gate, delegates execution unchanged, and post-processes the verdict into ARIS's policy vocabulary. It vendors nothing and forks nothing.

🔁 Cadence fence (shared-references/external-cadence.md): this skill is verdict-bearing decision support. Do not wrap it in /loop / /schedule — and NEVER as "iterate edits until it stops flagging" (see The One Forbidden Loop below).

Constants

  • ANTI_AR_REPO = https://github.com/wanshuiyin/Anti-Autoresearch.git
  • ANTI_AR_COMMIT = b47af6f983b38347b6d2110379e266400597cf66 — the SHA-pin. The launcher NEVER tracks upstream HEAD; bumping this constant is a reviewed change (see Pin-bump checklist).
  • CLONE_DIR = ~/.aris/anti-autoresearch — the pinned working copy. Host-neutral on purpose: ARIS also runs on DeepSeek Harness, Codex CLI, Cursor, Trae, Antigravity and Copilot CLI, where ~/.claude/ would name an installation the user does not have. An older clone at ~/.claude/anti-autoresearch is unused; move it and its .aris_eval_ok_* receipt only to keep an offline deterministic-only run working, otherwise delete it whenever convenient.
  • NO REVIEWER KNOBS. This launcher exposes no reviewer model/effort parameters and never maps ARIS — effort: onto upstream settings. The pinned upstream runs exactly what it pins (gpt-6-astra + xhigh, its own design decision). Overriding upstream review policy from a launcher would create a second, unauditable configuration surface.
  • GATE_HELPER = forensics_gate.py — resolved via the canonical chain (shared-references/integration-contract.md §2): .aris/tools/ → tools/ → $ARIS_REPO/tools/ → $ARIS_REPO/tools/ via ~/.aris/repo. Failure policy A (required): if it cannot be resolved at assurance: submission, STOP — never improvise the gate.

Step 0 — Bootstrap the pin (idempotent)

CLONE_DIR="$HOME/.aris/anti-autoresearch"
ANTI_AR_COMMIT="b47af6f983b38347b6d2110379e266400597cf66"

mkdir -p "$HOME/.aris"
if [ ! -d "$CLONE_DIR/.git" ]; then
    git clone --no-checkout https://github.com/wanshuiyin/Anti-Autoresearch.git "$CLONE_DIR"
fi
# fetch ONLY if the pin isn't already present — a cached, validated pin works offline
git -C "$CLONE_DIR" cat-file -e "$ANTI_AR_COMMIT^{commit}" 2>/dev/null \
    || git -C "$CLONE_DIR" fetch -q origin
git -C "$CLONE_DIR" checkout -qf "$ANTI_AR_COMMIT" || {
    echo "FATAL: cannot checkout pinned commit $ANTI_AR_COMMIT"; exit 1; }
# Force a PRISTINE tree at the pin — local tampering with the clone (edited
# adjudicator, injected module, even one hidden inside a NESTED git repo,
# which single-f clean skips) must not survive bootstrap and run under the
# official pin's name. Every step is checked; then the tree is verified.
git -C "$CLONE_DIR" reset --hard -q "$ANTI_AR_COMMIT" || {
    echo "FATAL: reset to pin failed"; exit 1; }
git -C "$CLONE_DIR" clean -ffdxq || {
    echo "FATAL: clean failed"; exit 1; }
[ -z "$(git -C "$CLONE_DIR" status --porcelain)" ] || {
    echo "FATAL: clone is not pristine after reset+clean — refusing to run"; exit 1; }

# One-time-per-pin validation: the upstream eval gate (8 injected-defect
# classes, 100% recall + zero clean false positives) must PASS before this
# pin is allowed to produce a verdict. NEVER skip; NEVER proceed on failure.
# The marker lives OUTSIDE the clone: a marker inside a tamperable tree proves
# nothing (and `git clean` above would erase it, forcing re-eval every run).
MARKER="${CLONE_DIR}.aris_eval_ok_${ANTI_AR_COMMIT}"
if [ ! -f "$MARKER" ]; then
    ( cd "$CLONE_DIR" && python3 eval/run_eval.py ) || {
        echo "FATAL: upstream eval gate FAILED at pin $ANTI_AR_COMMIT — refusing to"
        echo "       use an unvalidated forensics pin for verdicts."; exit 1; }
    touch "$MARKER"
fi
echo "anti-autoresearch pinned at $ANTI_AR_COMMIT (eval gate: validated)"

Step 1 — Delegate: run the upstream sweep, unchanged

Open and follow $CLONE_DIR/workflows/anti-autoresearch/SKILL.md end to end on the target. Two wrapper rules — the ONLY things this launcher adds:

  1. cwd. Upstream skills self-locate via git rev-parse --show-toplevel. Run every upstream bash block with cd "$CLONE_DIR" first — ALWAYS the cd, never just an exported ROOT (upstream blocks re-derive ROOT themselves and would overwrite it) — and refer to the paper by absolute path, otherwise upstream resolves ROOT to the ARIS repo and finds the wrong Python spine.
  2. Codex calls carry approval-policy: never + sandbox: read-only (session hygiene; upstream already specifies fresh-thread-per-dimension, serial execution, and its own model pins — do not alter them).

Everything else — the evidence ledger, coverage.json state machine, the nine auditor dimensions, the refutation pass, the deterministic summary — is upstream's contract. Never rewrite, soften, or re-map its outputs (report.json + REPORT.md, verdict ∈ CLEAN_GIVEN_EVIDENCE / SOFT_FLAGS / HARD_FLAGS / REVIEW_UNAVAILABLE). The observability level (L0/L1/L2) is whatever upstream derives from the artifacts present — do not promise L2.

Step 2 — Typed gate + obligations (ARIS-side post-processing)

# Resolve $GATE_HELPER via the canonical chain (integration-contract §2), then
# ONE atomic call (update + gate in a single locked transaction — the gate only
# ever speaks for the report the ledger has folded, sha-bound):
python3 "$GATE_HELPER" evaluate --report "$PAPER_DIR/report.json" --paper-dir "$PAPER_DIR" \
    --anti-ar-commit "$ANTI_AR_COMMIT" --executor-model "<this pipeline's executor>"
# exit 0 = WARN / NO_NEW_BLOCKER · exit 1 = BLOCK

The gate translates the verdict into policy WITHOUT re-labeling it:

| upstream verdict | policy | |---|---| | HARD_FLAGS | BLOCK — an auditor proposed something critical and it is on the table for you to read; never "the machine found fraud" | | REVIEW_UNAVAILABLE | BLOCK — an incomplete sweep cannot wave a paper through | | SOFT_FLAGS | WARN — human disposition. Read the never-ran list too: the upstream verdict folds incompleteness in only when it would otherwise be clean, so a WARN can sit on top of a sweep where verdict-bearing dimensions never ran. evaluate and fresh both print those dimensions | | CLEAN_GIVEN_EVIDENCE | NO_NEW_BLOCKER — never called PASS or accepted: it means "no flag found in the evidence at hand", not an acquittal | | anything else | BLOCK (fail closed) |

plus: any OPEN critical obligation → BLOCK; any OPEN obligation → at least WARN; a closed-without-receipt or unknown-status ledger entry → BLOCK (a hand-edited "status": "RESOLVED" does not open the gate).

gate.json also records a paper_fingerprint (sha over the paper's compile inputs AND deliverables — .tex/.bib/.sty/.cls/figures/PDF). The downstream preflight is ONE command: python3 "$GATE_HELPER" fresh --paper-dir "$PAPER_DIR" --anti-ar-commit "$ANTI_AR_COMMIT" — exit 0 ⟺ the gate was produced at the CURRENT pin ∧ a gate exists ∧ nothing in the paper changed after it ∧ the gate matches the current obligations ledger ∧ the decision — re-computed from the sha-verified archived report (last_report.json) + the live ledger, never read from the gate's stored token — is pass-capable (WARN / NO_NEW_BLOCKER). Anything else — missing gate, post-gate edit or recompile, unbound ledger or archive, recompute mismatch, BLOCK, unknown token — exits 1: re-run the sweep + evaluate. Every ledger mutation (update/resolve/waive) deletes the standing gate.json, so an interrupted run can never leave a stale pass; and evaluate refuses a report OLDER than any paper file (a stale report cannot be folded onto text it never audited). Run evaluate immediately after the sweep, before touching any paper file.

The gate artifact also records honest provenance: upstream's auditors are GPT-family, so for a Claude executor the findings carry cross-family proposal provenance; for a Codex executor they are same-family. Either way this gate only raises flags — it has no acceptance to grant, so the distinction is informational, not a loophole.

Step 3 — Fix what it found (obligations, not a polish loop)

Every OPEN obligation gets DISPOSITIONED — fixed, or explicitly waived. Upstream now reports every proposal an auditor made rather than deciding which ones do not count, so expect more obligations than a pre-2026-08 sweep opened, and expect some of them to be proposals you disagree with. waive is a first-class, expected outcome — "a model proposed this and I, the human, judge it wrong" is a normal disposition here, not a last resort. Weigh each one against the report's columns: Anchored, Observability, FP-risk, Surface, Ext-check.

For the ones that are real, use the right door:

| Finding family | Repair route | |---|---| | A — numeric self-consistency | recompute from the RESULT FILES (/paper-claim-audit evidence chain); fix the number, not the sentence | | D — experiment integrity | back to /experiment-audit / rerun | | E — citations | /citation-audit KEEP/FIX/REPLACE machinery | | G — proof & derivation | /proof-checker's fix loop | | B / C / H — scope, baselines, eval design | science-level: feed the finding to /auto-review-loop as reviewer INPUT, or to the human | | AIS / advisory (zero-weight) | optional context for /auto-paper-improvement-loop; never gates |

Close each obligation explicitly — the receipt is typed and hashed:

python3 "$GATE_HELPER" resolve --paper-dir "$PAPER_DIR" --obligation-id <id> \
    --fix-type corrected-from-results|claim-narrowed|claim-withdrawn|citation-replaced \
    --evidence <path-to-the-ground-truth-that-backs-the-fix> \
    --verified-by "human:<name>" | "checker:<tool>" | "cross-family-review:<thread-id>"
# or, with HUMAN sign-off only:
python3 "$GATE_HELPER" waive --paper-dir "$PAPER_DIR" --obligation-id <id> \
    --approver "human:<name>" --reason "<why this stands as-is>"

Rules the ledger enforces mechanically (tests/test_forensics_gate.py):

  • append-only — re-running the sweep can open obligations, never close them;
  • a finding that disappears from a later report stays OPEN and gains UNRESOLVED_DISAPPEARANCE — rewording the span is not a fix;
  • claim-withdrawn is an honest fix (deleting an unsupported claim is a legitimate resolution — with the deletion diff as evidence);
  • a waiver is not a resolution: human-approved, permanently recorded, original finding snapshot immutable;
  • the executor's `fi

Truncated for display — read the full file on GitHub.

Related Skills

View on GitHub
GitHub Stars16.6k
CategoryAI
Updated9d ago
Forks1.4k

Languages

Python

Trust signals

100/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

No cautions