ax-check rule
AXC-F011: Claims extracted but not verified
Offline mode found URLs, packages or tool names that need the network to verify.
ax-check is a checker being prepared for release. This page documents the rule ahead of that release; see all 50 rules.
| Severity | info |
| Kind | Heuristic. A pattern match: a prompt to look, not a verdict. |
| Mode | ax-check drift |
| Applies to | Instruction files and manifests |
| Pattern tags | drift |
| Fix in one line | Re-run with --online (and --mcp or --cli where relevant) to verify these claims. |
ax-check found URLs, packages or tool names in the file, but it did not check them, because network checks are opt-in. This finding is a reminder, not a problem. It tells you what was left unchecked and how to check it.
What it checks
In the default offline mode, ax-check reads each file and lists the claims it contains: URLs, npm and PyPI packages, pinned versions and MCP tool names. It checks only local files on disk (see AXC-F010). For everything else it makes no network call. Instead it emits this one finding per file, with counts of what it saw and did not verify.
Why it matters
A clean offline run could be mistaken for a clean bill of health. This finding stops that. It says plainly which parts of the file have not been tested against the real world: links that may be dead, packages that may not exist, tools that may have been renamed.
The network is opt-in on purpose. A checker that quietly sends requests to many hosts, or to registries, from your machine or your CI is surprising, and you may not want it. ax-check makes network calls only when you ask for them, and each option asks for one kind.
How to fix
Run the check again with the options that match what was left unchecked:
--onlinechecks URLs (AXC-F001, AXC-F002) and looks up packages and versions in the npm registry and PyPI (AXC-F003, AXC-F004, AXC-F005).--mcp <url>is its own opt-in, and needs no--online. It fetches the live tool list for AXC-F006 and AXC-F007.--cli "<command>"is also its own opt-in. It runs the program with--helpand captures the help for AXC-F008 and AXC-F009.
Example
Before
$ ax-check drift AGENTS.md
AGENTS.md
info AXC-F011 Found 6 url, 2 npm, 1 pypi, 3 mcp-tool claim(s) that need --online to verify.
The wording of the output may differ slightly. The counts, by kind of claim, are what matter.
After
ax-check drift --online --mcp https://mcp.example.com/mcp AGENTS.md
With the options on, the claims are checked and the file receives specific findings for any that fail, or none. To see what would be checked before any request is made, add --dry-run: it lists each claim and what would be done with it, then stops.
How ax-check detects it
The check is deterministic. After extracting claims, ax-check counts them by kind: url, npm, pypi, mcp-tool, cli-command and cli-flag. Local paths are not counted, because AXC-F010 checks them on disk. When --mcp is given, MCP tool names are treated as checked, and when --cli is given, commands and flags are. If anything is left and --online was not given, one finding is reported for the file. When --online is given, this rule does not fire, and neither does it when there is nothing to verify.
When you use --online, it checks up to 200 distinct URLs (change it with --max-urls), one request at a time per host with a 500 millisecond gap, and a 10 second timeout per request. These limits keep a run polite to the sites it visits.
Known limit: the counts describe what ax-check could extract. It reads code spans, fenced code, links and manifest fields. Claims written only in free prose are not counted.
To silence it, use --disable AXC-F011, for example in an offline pipeline that is not allowed to reach the network.
Sources
- None needed. This rule describes how ax-check itself behaves: it makes network calls only when asked.
Related evidence
Records in the AX evidence register that share a pattern tag with this rule. A shared tag means the record is about the same pattern, not that it tests this rule. Read the evidence class before the number.
- EV-0039: Launch post and documentation disagree on agent output format (Independent measurement). Cloudflare's cf launch post says JSON output is 'condensed for agents', but the cf documentation says JSON output is indented whether or not output is a terminal, and a public issue reports byte-identical output with an agent detected.
- EV-0040: Agent skills recommended a package that does not exist (Vendor measurement). Merged pull requests in Vercel's agent plugin repository corrected skill instructions that recommended an npm package that is not published, and plugin guidance that advertised deployment cards the production MCP server does not expose.
