Verification
A task is never complete because the agent says so. Detected and configured checks, browser and smoke steps, remediation, and plugin checks.
After the agent finishes, the worker runs the verification steps in the project. Every required step must
pass. If one fails, its output goes back to the agent to fix — up to maxRemediationAttempts (default 3) — and then
the task needs a person (RECOVERY_REQUIRED).
Detected steps
Without configured steps, checks are detected from project files (autoDetect, on by default):
| Project | Detected steps |
|---|---|
package.json | typecheck, lint, build, test scripts, with the package manager in use |
| Composer | composer test, or vendor/bin/phpunit |
| Python | pytest when there are tests |
| Go, Rust | build and test |
Configured steps
Each step is { kind, name, command, required, timeoutMs }; commands are argument lists, never shell strings.
Kinds: git_status, install, typecheck, lint, build, test, custom, smoke and browser.
{
"verification": {
"steps": [
{ "kind": "install", "command": ["pnpm", "install", "--frozen-lockfile"] },
{ "kind": "typecheck", "command": ["pnpm", "typecheck"] },
{ "kind": "test", "command": ["pnpm", "test"], "timeoutMs": 900000 },
{ "kind": "custom", "name": "Licences", "command": ["pnpm", "licenses", "list"], "required": false }
]
}
}Smoke and browser
smoke:GET urlmust answer below 400.browser: Chromium (Playwright from the project) opensurl; console errors, uncaught page errors, failed requests and HTTP errors fail the step, and a screenshot is stored. Both can start the app themselves, andbrowsercan visit every page — see Browser QA.
Plugin checks
Plugins with a task.verify hook add checks of their own. A failed plugin check is a
required step: the agent is sent back to fix it.
Multi-repository projects
The policy's steps run in the primary repository, and detected checks run in every other repository the task changed.
Turning it off
verification.enabled: false in a policy. The report then says verification was disabled by policy.