skills/prove/SKILL.md
Prove a claim by re-deriving it (run + gate) instead of asserting "done" — the one-line re-derivation verb — plus the compile action that emits a self-contained, vault-backed build gate into any repo. Use when: "prove it", "prove tests pass", "prove the build is clean", "re-derive done", "run the produces-gate", "gate this claim", "--with-attestations", "compile", "emit a build gate", "stamp a gate into a repo", "compile a repo-native build gate", "--trigger hook,ci", or any former /wicked-garden:{prove|compile} invocation.
npx skillsauth add mikeparcewski/wicked-garden wicked-garden-proveInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Run this skill inline — never fork it. prove is designed to run in the parent context so the gate stays a reflex verb, not a dispatch ritual.
The one-line re-derivation verb. Before you tell the user something is "done" / "tests pass" / "the build is clean", prove it — don't assert it. This runs the command, freezes its real exit code as wicked-vault evidence, and gates by re-running the verifier. Exit 0 only on a re-derived PASS; fail-closed (exit 3) when the loom/vault backend is unresolvable — never a vacuous pass.
It collapses the gate ritual (vault init → declare-contract → record --run → gate) into one call, so the gate is something you reach for by reflex.
Instructions:
--by command executes in --project-dir, default .):
sh "${CLAUDE_PLUGIN_ROOT}/scripts/_python.sh" \
"${CLAUDE_PLUGIN_ROOT}/scripts/qe/prove.py" \
<claim> --by "<command>" [--verifier exit_code_eq:0] [--project-dir <dir>]
e.g. prove.py tests-pass --by "pytest -q" · prove.py build-clean --by "npm run build"--verifier re-runs against the
command's output: regex_match:<re> / not_contains:<re> scan stdout;
jq_pred:<expr> evaluates a predicate over the command's JSON stdout;
commit_exists:<sha> checks a git commit. This works on final and interim
artifacts — prove an intermediate produce the moment it exists, not only at the end:
prove.py adr-has-decision --by "cat decision.md" --verifier "regex_match:## Decision" --kind doc
prove.py config-no-secrets --by "cat app.yaml" --verifier "not_contains:(?i)password" --kind doc
prove.py enough-options --by "cat options.json" --verifier "jq_pred:.options | length >= 2" --kind doc
satisfied is the truth; re_derived: true means it
was recomputed from frozen evidence (not your claim); gate: "unavailable"
means the backend is down and the gate failed closed.satisfied: true. On REJECT, the claim is
false — fix it, don't narrate around it.Hard gates (incident/migrate/review): --with-attestations. Add it and the
gate stays REJECT (UNATTESTED) until an INDEPENDENT evaluator — not the agent
that did the work — runs wicked-vault attest <artifact-id> --opinion pass. The
doer's own evidence cannot satisfy a hard gate; that's the point. Find the
artifact with wicked-vault list --scope <scope> --phase <phase>. A reject
attestation flips the gate to REJECT even if the evidence re-derives.
Trigger phrases: "compile", "emit a build gate", "stamp a gate into a repo".
Emit a self-contained, vault-backed build gate into a target repo. Detects
the repo's test/lint/build commands and writes <repo>/.wicked/ (contract +
gate.py + README). The gate re-derives each claim through wicked-vault and
runs with no wicked-garden runtime present. Optionally installs the
triggers that fire it (pre-push hook / GitHub Actions). The vault is resolved
at runtime via npx — it is the one thing the compiler never compiles.
The emitted gate is deliberately vault-direct (shells
wicked-vault, notwicked-loom). The garden's own gate uses loom; the emitted gate can't assume loom is installed in a foreign repo, so it depends only on the vault.
Parse the arguments: first non-flag token is the repo path (default .); pass
--trigger <value> through verbatim when present. Then:
sh "${CLAUDE_PLUGIN_ROOT}/scripts/_python.sh" "${CLAUDE_PLUGIN_ROOT}/scripts/compiler/compile.py" "<repo-path>" <flags>
Parse the JSON manifest and report, concisely:
tests-pass / lint-clean / build-clean) and their commands;needs_review: true — warn which bindings were inferred at low confidence and tell the user to confirm/fix <repo>/.wicked/contract.json;python3 <repo>/.wicked/gate.py (exit 0 = PASS); note wicked-vault must be resolvable (npx wicked-vault or a global install).Never hand-edit the emitted bindings block — re-run this action after the repo changes shape.
development
Pattern-conformance agent-half: evaluates a produced artifact or diff against a set of architectural/design pattern rules from the conformance-rule store (wicked_governance schema). Returns structured findings with rule ID, severity, and rationale — the deterministic half (mechanical rule recall) is done by the guard pipeline; this is the semantic evaluation step. Triggered by: the guard_pipeline `outgov_pattern` check (session-close), or explicitly by an engineering review when WICKED_OUTGOV_RULES_DIR is populated. NOT a replacement for the full `engineering` review skill — focuses only on conformance to stored Pattern rules; architecture and code-quality checks live in the `engineering` skill. Semantic evaluation reuses `wicked-garden-qe-semantic-reviewer` as the designated agent-half evaluator (per garden#983 spec). This skill is the orchestrating wrapper that loads applicable Pattern rules and delegates the per-rule semantic judgment to qe-semantic-reviewer.
tools
The FOUNDATIONAL domain-model capability: extract a codebase's domain — testable business rules (with confidence + provenance), entities, requirements — as a schema-conformant model on the estate graph. The workers annotate the store; wicked-core reads it and builds the requirements graph, coverage-gating fail-closed. Steers three fork workers. A shared substrate, not a modernization tool. The `modernize` archetype DERIVES from it; build / migrate / review / specify / explore consume the SAME domain model — none OWN it. Understanding a codebase's domain is upstream of almost everything else garden does. Use when: "extract the business rules / domain model from this codebase", "build a requirements graph from the code", "what does this system actually require", "reverse-engineer the domain before we build/port/migrate". Works on ANY codebase (modern or legacy) — the value is the domain model, not the porting. NOT the code transform itself (that is the archetype consuming this model). This skill produces the DOMAIN MODEL, not new code.
development
Domain-graph fork worker for the modernize archetype. Groups the estate's Louvain communities into business domains, attaches each requirement to its cluster (advisory cluster_id provenance), and invokes wicked-core's domain-graph build (which reads the annotated estate store, recomputes coverage fail-closed, and builds the requirements graph) — then validates core's output against the vendored schema. Use when: dispatched by wicked-garden-domain after rule extraction to turn a flat rule set into cluster-keyed domains; "group these into domains", "build the requirements graph", "translate clusters into a domain model". NOT for mining the rules themselves (that is domain-extractor) or threat-modeling (that is domain-coverage).
tools
Rule-extraction fork worker for the FOUNDATIONAL domain-model capability. Mines testable business rules from a codebase — each with a numeric confidence and a provenance{source, ref, source_kinds} — and annotates them into the estate store so wicked-core can build the domain-model requirements graph (coverage-gated). This is a substrate, not a modernization tool: the `modernize` archetype DERIVES from it, and build / migrate / review / specify / explore can consume the same domain model — none OWN it. Use when: dispatched by wicked-garden-domain to mine the business_rules of a codebase (or a module); "extract the domain rules", "what does this system require", building the requirements half of a domain model. NOT for grouping into domains (that is domain-modeler) or judging coverage (that is domain-coverage — a seat-distinct evaluator).