stably-verify — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited stably-verify (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
stably verify checks whether your application works correctly by describing expected behavior in plain English. It launches an AI agent that navigates your app in a real browser, interacts with it, takes screenshots, and reports a structured PASS / FAIL / INCONCLUSIVE verdict. No test files are generated.
Always run `stably --version` first. If not found, install with npm install -g stably or use npx stably. Requires Node.js 20+ and a Stably account.
stably --version
echo "STABLY_API_KEY: ${STABLY_API_KEY:+set}"
echo "STABLY_PROJECT_ID: ${STABLY_PROJECT_ID:+set}"# Verify a feature works
stably verify "the login form accepts email and password and redirects to /dashboard"
# With a specific starting URL
stably verify "the pricing page shows 3 tiers" --url http://localhost:3000/pricing
# Set a budget cap (default: $5)
stably verify "checkout flow completes successfully" --max-budget 10
# Non-interactive mode (for CI or background agents)
stably verify "checkout flow completes" --no-interactive
# Use cloud browser instead of local
stably verify "login works" --browser cloud| Option | Description |
|---|---|
-u, --url <url> | Starting URL (auto-detected from localhost if omitted) |
--max-budget <dollars> | Budget cap in USD (default: 5) |
--no-interactive | Skip preflight prompts |
--browser <type> | Browser type: local or cloud (default: local). Also settable via STABLY_CLOUD_BROWSER=1 |
| Code | Verdict | Meaning |
|---|---|---|
0 | PASS | All requirements verified |
1 | FAIL | One or more requirements not met |
2 | INCONCLUSIVE | Cannot determine (app unreachable, auth wall, etc.) |
After making code changes, use stably verify to check the feature:
stably verify "description of expected behavior"stably verify command againstably verify does not create or modify any files. It only observes and reports. Fix the code yourself based on its findings.
# Gate on verification
stably verify "login works" && echo "Feature verified!"
# Handle all three outcomes
stably verify "checkout completes" ; code=$?
if [ $code -eq 0 ]; then echo "PASS";
elif [ $code -eq 1 ]; then echo "FAIL";
else echo "INCONCLUSIVE"; fistably verify is AI-powered and can take several minutes depending on complexity.
| Agent | Configuration |
|---|---|
| Claude Code | timeout: 600000 on Bash tool |
| Cursor | block_until_ms: 900000 |
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.