maintain-verification-skill
cursor/plugins
Audit and refresh a project's verification skill to keep its feature map aligned with current source and behavior.
What is maintain-verification-skill?
This skill maintains the accuracy of a verification skill's feature map by reading source code in parallel, exercising features live, and shipping proven corrections. Use it periodically to catch documentation drift, harness gaps, and product regressions without editing product code.
- Index and validate the feature map for missing, duplicate, or dead entries
- Launch concurrent read-only source analysis per feature to identify likely drift
- Exercise every mapped feature live in a single coordinated session
- Reconcile source findings and live results into a single outcome
- Triage issues as documentation drift, harness gaps, or product regressions
- Ship at most one PR of proven corrections, or report clean/blocked status
How to install maintain-verification-skill
npx skills add https://github.com/cursor/plugins --skill maintain-verification-skill- An existing verification skill with a feature map (typically in .cursor/skills/verify-*/)
- Access to the project's source code and a running instance of the app for live testing
How to use maintain-verification-skill
- 1.Identify the target verification skill in the project (usually .cursor/skills/verify-*/)
- 2.Run the skill with /maintain-verification-skill or "audit the verify skill"
- 3.Review the source analysis and live test results for each feature
- 4.Triage any drift as documentation, harness, or product issues
- 5.Approve and merge the resulting PR if changes are needed, or confirm clean/blocked status
Use cases
- Refresh a verification skill after major product changes to catch documentation rot
- Validate that all user-facing features are covered by the feature map and harness
- Identify which features have become unreachable due to missing prerequisites or changed behavior
- Confirm harness recipes still work against current source and live app state
- Audit a verification skill before shipping it to ensure map accuracy
- Developers maintaining a project's verification skill
- Teams using /create-verification-skill who need periodic audits
- QA or documentation leads ensuring feature coverage stays current
maintain-verification-skill FAQ
Doc drift: the feature map or description doesn't match current source or behavior (fix the map). Harness gap: the feature works but the test recipe can't drive it (fix the harness). Product regression: the app's behavior is actually broken (report it separately, don't paper over it in docs).
No. Only edit the verification skill's own directory (SKILL.md, features/, harness scripts). If you find a product bug, report it separately; don't fix it in the skill.
It's only marked verified-unreachable if you document the concrete prerequisite (auth, entitlement, OS, external state) and the route attempted. If the map omits that prerequisite, that's drift to fix.
Health-check the instance before each drive. If a doctor failure is caused by skill drift, fix it and retry once. If a feature can't be reached, verify the prerequisite is documented. Any harness fix must be re-driven live before shipping.
Only when there are proven corrections to the skill's own files. For clean runs (no drift found) or blocked runs (coverage incomplete), report the outcome without a PR.
Full instructions (SKILL.md)
Source of truth, from cursor/plugins.
name: maintain-verification-skill description: "Periodic pass that keeps a project's verification skill and feature map honest: parallel source readers per feature, one live session driving every feature, at most one PR of proven corrections. Use for /maintain-verification-skill or "audit the verify skill"." disable-model-invocation: true
Maintain a verification skill
A feature map rots the moment the app changes. This skill is the upkeep loop for a skill generated by /create-verification-skill (or any project-local verification skill with a feature map). The unit of rigor is the feature, not every sentence: cover every feature file from source and exercise every feature live, without terminalising every bullet.
Outcomes
Pick one, and say which:
- clean — every feature got source and live coverage; nothing worth shipping. No branch, no PR.
- changed — one PR ships proven doc, harness, or map corrections.
- blocked — coverage could not finish or a proven fix could not ship safely. Say exactly what blocked it.
Edit scope
Only edit the verification skill's own directory (its SKILL.md, features/, and any harness scripts it owns). Never edit product code during a run: a behavior the map describes that the app no longer does is either doc drift (fix the map) or a product regression (report it, don't paper over it in docs).
Pass
-
Locate the target. Find the verification skill to maintain: the project-local skill whose body has launch/drive sections and a feature map (usually
.cursor/skills/verify-*/). Several candidates → ask which one; none → stop and point at/create-verification-skillinstead of inventing a target. -
Index hygiene. Read the feature map README and glob its sibling files. Fix missing, extra, duplicate, or dead entries. Lightweight; no generated inventory.
-
Source wave. One read-only subagent per feature file, launched concurrently. Each explains "how does this user-facing feature work?" from source, flags likely doc drift with citations, and returns one concise live-verification recipe. Children never drive the app and never edit files. Return shape: feature summary / source entry points / likely drift or none / one recipe.
-
Reconcile. Every feature file has a returned summary. Merge overlapping recipes into as few app states as practical. Spot-check cited drift; don't re-prove clean claims. Sweep recent churn for user-facing surfaces missing from the map — require a concrete source path before calling one missing.
-
Live pass. Required even when source looks clean. The coordinator owns all driving; follow the verification skill's own launch model — one long-lived instance driven serially for servers and UIs, or a fresh isolated session per drive for short-lived CLIs (the skill's Launch section decides, not this one). Exercise every feature at least once, and hold three invariants the whole pass, whatever the failure: (1) never drive an instance you haven't health-checked since it last did something surprising — doctor before first drive, doctor on each fresh session where sessions are the unit, doctor again after any failed drive, and where doctor can't see the failure (a wedged UI state on a healthy process), reset to a known state or relaunch rather than hoping; (2) evidence captured so far survives every cleanup, checked at its named location, not assumed; (3) nothing a drive started outlives that drive's usefulness — failed-iteration residue is cleaned whether the session is stuck, exited, or shared (for a shared instance, clean the residue, not the instance). A doctor failure caused by skill drift is drift: fix it under edit scope and retry once — restart whatever the fix invalidated, nothing more — before calling the pass
blocked. A feature that can't be reached isverified-unreachableonly with the concrete prerequisite (auth, entitlement, OS, external state) and the route attempted; if the map omits that prerequisite, that's drift. Any harness fix from triage gets re-driven live before it ships. Final teardown happens after the last drive of the run — including those re-proofs — so nothing outlives the run (evidence stays, per the skill). -
Triage. Wrong or missing user-POV description → doc drift, fix it. Working behavior the harness can't drive → harness gap, fix it; a harness fix follows the same helpers rule as generation (scripts executable, invocation documented in the skill body). App behavior that's actually broken → product gap; record it for the user, keep it out of this PR.
-
Ship or stop. For changed: one PR of proven corrections, re-read every changed file first. For clean or blocked: no PR, report the outcome and the coverage honestly.
Keep concise run notes (features covered, unreachable prerequisites, confirmed drift, outcome) in a scratch location; don't commit them.
Related skills
More from cursor/plugins and the wider catalog.

make-pr-easy-to-review
Clean up PR history, improve descriptions, and guide reviewers without changing code behavior.

new-branch-and-pr
Create a focused branch, implement changes, and open a pull request with test notes.

no-comments
Remove unnecessary comments and encode constraints by spawning Comment Sicko analysis.

Poteto Mode
Poteto's deliberate agent style: concise responses, simple code, verified work, and rigorous decision-making.

pr-review-canvas
Generate interactive HTML walkthroughs of GitHub PRs with diffs, annotations, and moved-code detection.

principle-boundary-discipline
Concentrate validation at system boundaries; trust internal types and keep business logic pure.