Design Reference Verdict — Security agent for Claude Code
Ranks one app surface against Mobbin reference screens and returns a single verdict line with file:line-anchored gaps.
How to install Design Reference Verdict
Installs to ~/.claude/agents/raaaf-claude-skills-design-reference-verdict.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/raaaf/claude-skills/HEAD/agents/design-reference-verdict.md -o ~/.claude/agents/raaaf-claude-skills-design-reference-verdict.md Restart Claude Code, or start a new session, for it to be picked up.
What Design Reference Verdict does
name: design-reference-verdict description: Ranks one app surface against Mobbin reference screens and returns a single verdict line with file:line-anchored gaps. Used by /design-audit Phase 2.5, never dispatched directly by the user. tools:
- Read
- Grep
- Glob model: sonnet effort: medium maxTurns: 10
Design Reference Verdict
You are dispatched by the `design-audit` skill, once per core surface. Read `design-audit/agents/reference-verdict.md` in the skill directory named in y
Alternatives in Security
- Retool Endpoint Audit — Checks a migration slice against the main app's API surface — whether a local implementation duplicates an exi 7.2k ★
- Dr Audit — Sub-agent prompt: audit Decision Records in an implementation-plan.md for canonical form and reference resolut 432 ★
- Dashclaw Security Reviewer — Read-only security reviewer specialized for the DashClaw stack (Next.js 16 App Router, Neon/Postgres via repos 297 ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
Design Surface Mapper
Maps which surfaces of the surface taxonomy an app has and which its domain expects but lacks, before the /des
UI UX Architect
Use this agent when you need a comprehensive UI/UX audit, design review, or visual refinement of the app's scr
Ehs Local App
Local application security specialist for the Ethical Hacker Squad. Reviews command-line tools, desktop applic
Codex Adversarial
Thin shim around codex exec review — runs codex directly, writes audit entry, returns terse verdict+count. Use
API Security Analyst
Invoked by api-review-orchestrator or directly to audit a REST/OpenAPI spec and related implementation files f
Security Triage
Independently evaluate a single security finding to decide whether it is a real, exploitable vulnerability or
Related Skills
LinkedIn Post Analyser
Claude Code / Cowork skill that scores a drafted LinkedIn post across 7 platform dimensions before you publish
Design Scan
Quarterly design-scan ritual (D7, v0.40.0) — refresh the curated visual reference library. Review recent Awwwa
Reddit Research Agent
Read-only Reddit research MCP server. Finds the subreddits where a topic is actually discussed, ranks threads