Skip to content
Back to skills

Behavior Validation

ASecurity

Validates a running application, CLI, API, service, or generated artifact as a user or operator against a prewritten observable behavior contract while remaining source-blind. Use for acceptance checks, runtime proof, anti-fake probes, release smoke tests, or an independent companion to code review. Not for source-quality findings, root-cause diagnosis, or visual design judgment outside the contract.

  • 95 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 22, 2026
ai-agentsdebugginggitapi

Works with

  • terminal
  • cli
  • api

Security analysis

A100/100

Pro scans all 3 files and shows the line behind each finding

Scanned September 22, 2026

npx -y skills add thiientv/godmode --skill behavior-validation --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Behavior Validation?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Behavior Validation
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/thiientv-behavior-validation/badge)](https://www.skillsdirectory.com/skills/thiientv-behavior-validation)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: behavior-validation
description: >-
  Validates a running application, CLI, API, service, or generated artifact as
  a user or operator against a prewritten observable behavior contract while
  remaining source-blind. Use for acceptance checks, runtime proof, anti-fake
  probes, release smoke tests, or an independent companion to code review. Not
  for source-quality findings, root-cause diagnosis, or visual design judgment
  outside the contract.
---

# Behavior Validation

Judge what the product does, not how its source appears to do it.

## Establish isolation

Write or read the behavior contract before exercising the target. Use
[behavior-contract.md](references/behavior-contract.md). The contract must name
user tasks, expected outcomes, setup, allowed interfaces, negative cases, and
required evidence.

Do not inspect source, diffs, internal tests, Git history, or implementation
notes during validation. Interact only through public browser, CLI, API,
artifact, accessibility, or operator surfaces. If source is required, mark the
clause blocked and hand it to `root-cause-debugging`.

## Exercise the contract

1. Run each task through the same entry point a real user or operator uses.
2. Vary input and state to detect hard-coded success, stale data, or display-only
   behavior.
3. Test invalid, empty, interrupted, retry, persistence, and permission paths
   where the contract makes them relevant.
4. Capture redacted screenshots, terminal excerpts, response summaries, or
   artifact facts.
5. Mark every clause pass, fail, blocked, or out of scope. Lack of evidence is
   not a pass.

When a finding is fixed, rerun the failed clause and nearby regression probes;
do not rerun unrelated expensive scenarios without reason.

## Completion condition

Every relevant contract clause has a status and reproducible evidence, anti-fake
probes were attempted, secrets and private data were excluded, and the report
does not infer implementation defects from observable symptoms.

Files in this skill

  • SKILL.md2 KB
  • agents/openai.yaml227 B
  • references/behavior-contract.md512 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…