SkillVaultskills Browse all 1,000+ skills

Code Quality · Version 1.1.0 · Reviewed 2026-08-02

Finding Provenance Validator

Make a defensible decision about finding citation validation and rule provenance checking with evidence, explicit trade-offs, and a verification plan.

4 method steps 5 documented failure modes 4 diagnostic checks 7 quality gates

Verifies that review findings cite real rules, current code, and traceable evidence rather than fabricated or stale references. It grounds the decision in structured findings, cited code revisions, guideline identifiers, source documents, and current repository state and explicitly prevents a correct-sounding finding surviving because its cited rule, line, or evidence does not exist in the reviewed revision.

₹199 one-time

Get this skill archive

Install in your AI coding tool

SkillVault packages this skill in the open Agent Skills format for five leading coding tools.

What this skill helps you do

  • Finding citation validation
  • Rule provenance checking
  • Stale evidence rejection

How Finding Provenance Validator works

You provide

The code, its invariants, and how failures currently surface

It inspects

Error paths and lifetime handling for finding citation validation

It decides

A rule provenance checking change that makes invalid states unrepresentable

You verify

A deliberately invalid input fails clearly at the boundary

What it checks first

Finding Provenance Validator verifies that review findings cite real rules, current code, and traceable evidence rather than fabricated or stale references. It grounds the decision in structured findings, cited code revisions, guideline identifiers, source documents, and current repository state and explicitly prevents a correct-sounding finding surviving because its cited rule, line, or evidence does not exist in the reviewed revision. Use it when the work involves Finding citation validation, Rule provenance checking, Stale evidence rejection.

  1. Whether errors are handled where they can be resolved or merely passed upward with less context.
  2. Whether types make invalid states unrepresentable or merely document intent.
  3. Ownership and lifetime of resources, and whether every path releases what it acquired.
  4. Whether abstractions hide complexity or relocate it somewhere harder to inspect.

Failure modes it recognizes

  • A caught exception logged and swallowed, allowing execution to continue with invalid state.
  • Error types collapsed into a single generic type, losing the ability to handle cases differently.
  • Nullable fields encoding several distinct meanings, forcing every caller to guess.
  • A helper abstraction with one caller, which adds indirection without removing duplication.
  • Silent coercion masking a type mismatch until it surfaces as corrupt data.

Answers it will reject

  • Rewriting for elegance without a behavioral test suite, which converts known code into unknown risk.
  • Adding a lint rule to enforce a pattern nobody has justified.
  • Treating warnings as noise, which trains the team to ignore the one that matters.

Decision rules it applies

  • Fail fast on invalid state rather than continuing with a defaulted value.
  • Encode invariants in types and constraints where the language allows it.
  • Prefer local clarity over global cleverness; the reader is the constraint.

Evidence it asks for

  • Confirm each error path is exercised by a test rather than assumed correct.
  • Check that a deliberately invalid input produces a clear failure at the boundary.
  • Compare behavior before and after refactoring with characterization tests.

The method inside

  1. Establish what is actually true about finding citation validation from the supplied evidence, and mark what is missing.
  2. Identify the mechanism behind rule provenance checking rather than restating the symptom.
  3. Choose the smallest defensible change for stale evidence rejection, weighing impact, confidence, effort, and reversibility.
  4. Record consequences, rollback, and open questions

Deliverables

  • Finding citation validation assessment
  • Rule provenance checking decision and action plan
  • Stale evidence rejection verification checklist

Evidence requirements

  • Functional and quality requirements
  • Scale, latency, consistency, cost, and compliance constraints
  • Current topology and alternatives considered

Quality gates

  • Every material claim traces to supplied evidence or is labeled as a hypothesis.
  • The response follows the declared deliverable contract.
  • No execution, access, measurement, or verification is invented.
  • Secrets and personal data are redacted rather than repeated.
  • The user receives a concrete independent verification step.
  • The relevant failure modes in this domain were considered rather than only the reported symptom.
  • No listed anti-pattern was recommended as a solution.

Example task

Input

Apply the finding provenance validator to our current finding citation validation work. We need a concrete decision, bounded changes, and evidence that the result is correct.

Expected output

Start with structured findings, cited code revisions, guideline identifiers, source documents, and current repository state. The highest-risk failure is a correct-sounding finding surviving because its cited rule, line, or evidence does not exist in the reviewed revision. Reject documentary findings whose code and rule provenance cannot both be resolved, while labeling pure reasoning separately. Verify the result by resolving every retained citation against immutable revisions and deliberately testing broken tags and moved lines.

Boundaries and compatibility

Ideal for

  • Finding citation validation: produce a decision or artifact grounded in supplied evidence.
  • Rule provenance checking: produce a decision or artifact grounded in supplied evidence.
  • Stale evidence rejection: produce a decision or artifact grounded in supplied evidence.

Out of scope

  • Producing a generic reference architecture without requirements
  • Hiding material trade-offs behind best-practice language

Agent compatibility

  • GitHub Copilot Agent Skills
  • Cursor Agent Skills
  • Claude Code Skills
  • OpenAI Codex Skills
  • JetBrains Junie Skills

Tool policy: Advisory by default. No tools are assumed. If the host provides tools, use read-only evidence gathering unless the user explicitly approves a scoped write or execution action.