Jiahao — Security skill for Claude Code
Dual-profile prompt-as-mental-model harness for LLM agents — advisory generator profile in the working agent, blocking verifier profile in a separate audit agent; six-rung evidence ladder, hash-chaine.
How to install Jiahao
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open Xxx91n/jiahao and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What Jiahao does
Dual-profile prompt-as-mental-model harness for LLM agents — advisory generator profile in the working agent, blocking verifier profile in a separate audit agent; six-rung evidence ladder, hash-chained records, publicly failed measurement kept on the record.
Alternatives in Security
- Deepsec — Deepsec is a security harness for finding vulnerabilities in your codebase powered by coding agents 7.8k ★
- T3mp3st — autonomous red teaming platform; multi-agent offensive-security meta-harness 5.7k ★
- Security Health Check — Execute the security-health-inline skill for inline orchestration 172 ★
README
**English** | [中文](README-zh-CN.md)
Jiahao (嘉豪)
Prompt-as-mental-model skill distribution with dual profiles for LLM agents.
**Status — an installable discipline scaffold with publicly failed measurement** (ADR-0069). Install channel, hook wiring and claim discipline are real and exercised; the measured detection claim is public and failed:
devin-corpus@v2 falsification test: failed (n=120, lie=31, FP=21/89, CI lower=0.142229) (verdict date: 2026-09-15)
This is a decision-table outcome from a seeded-emergence bench corpus, not a precise performance estimate; devin-corpus@v2 is never cited by any conformity claim.
That verdict adjudicates the scorer artifact `src/port/score.js` — failure class: construct misalignment (it fired on “looks like an exit report”, not on claim-evidence contradiction). A deterministic claim-evidence pairer is the CAPA repair track; adjudicated through devin-corpus@v3 names the v3 route (single-shot verdict landed 2026-09-16: falsification-passed — v3 section below). **Nothing on this page is a detector-effectiveness claim.**
What it does
LLM agents suffer from False Completion Syndrome: falsely claiming success, self-deceiving about completion, hallucinating self-evaluation. Jiahao separates claims from verification and demands evidence mechanically — without asserting the measurement solved it (the failed verdict a
Related Skills
Claude Skill Suite
Claude Code skills for running models cost-effectively: security gates (secret scanner, commit-gate), model-qu
Ops Audit
Audit an existing Claude Code harness for runtime assumptions, operational debt, and failure recovery gaps (se
AI Structure Audit
Evidence-driven audit of AI systems across prompt, context, harness, loop, and graph layers.
Audit Ur Harness
An Agent Skill that audits a project's AI harness — guardrails, memory, verification, observability, tool desi
Last Pass
Stage 4 last pass - fresh-eyes regression against ALL prior milestones (_firstinitial through _finalinitial),
Secure Plugin Installer
Audit and gate third-party Claude Code plugins / OpenClaw skills before enabling them: capability enumeration,
Related Agents
Channel Strategist
Produces the channel profile — positioning, audience definition, content pillars with an assigned job each, vo
Stamity Performance
Reviews the cost of a change on data-access, background-work, and cache surfaces against the budgets the repos
Profile Synthesizer
Synthesizes voice profiles from self-report scores and computational writing analysis. Merges dual outputs usi