Skip to content

krokoko/software-verification

v0.5.0Apache-2.0

Design verification strategies that unlock higher levels of autonomous software development.

Software Verification Plugin

Design verification strategies that unlock higher levels of autonomous software development.

What it does

This plugin analyzes a codebase's current verification posture and designs a tailored strategy to close gaps. It produces:

  • Verification maturity tier (0-5)
  • Bug-surface classification (A–E) with ceremony-risk and routing guidance
  • Component breakdown with archetype classification and per-component maturity
  • Missing oracles and recommended oracle types
  • Exactness analysis (where exact correctness is possible vs. statistical/empirical)
  • Human review requirements (which components need human oversight)
  • Autonomy candidates (which components are ready for agent iteration)
  • Implementation roadmap with prioritized verification improvements

Skills

/assess-verification

Performs a full assessment of existing verification infrastructure. Inventories tests, linters, type checkers, contracts, schemas, formal specs, CI, test impact analysis, and operational validation. Classifies components by bug-surface (A–E), scores maturity, and assesses requirement traceability (does intent trace to tests and code?). Outputs verification-report.md.

/design-strategy

Takes an existing verification report (or performs lightweight discovery) and designs per-component verification strategies. Recommends tools, oracle patterns, evidence pipeline design, verification cost tiers (check / verify-quick / verify-full), a pipeline-enforced requirement traceability check, and an implementation roadmap. Outputs verification-strategy.md.

/detect-ai-smells

Assesses whether the codebase has automated gates to catch AI-generated code smells across 11 categories (plausible fabrication, shallow error handling, vacuous tests, vacuous formal specs, implicit drift, and more). Outputs ai-smells-gates-report.md.

Verification methods covered

CategoryMethods
TestingUnit, integration, property-based, BDD/executable specs, fuzzing, regression replay
TraceabilityRequirement → criterion → test → code mapping (RTM), intent-drift detection
Static analysisLinters, type checkers, SAST, abstract interpretation
ContractsPre/postconditions, invariants, schemas, Design by Contract
Formal methodsSpecifications, model checking, SMT, deductive verification, theorem proving
OperationalRuntime verification, shadow testing, canary deployment, chaos engineering
HumanCode review, approval gates, escalation

Relationship to AI Readiness plugin

The AI Readiness plugin answers "where are we?" while this plugin answers "what verification do we need?" They work well together but can be used independently.

Installation

Install via the Cairn plugin marketplace in your AI agent (Claude Code, Codex, or Cursor).