A Claude skill that builds a verified contact list from free public sources — and the benchmark that keeps it honest.
Give it a description of a kind of person ("pediatric anesthesiologists within 50 miles of Myrtle Beach", "RevOps leads at Series B fintechs") and it sources them from organization websites and public registries, resolves what it can, and writes a CSV with a source and a confidence label on every field.
It also enriches a half-finished spreadsheet, grades an existing list for deliverability, and researches a shortlist for qualities a directory does not carry — such as past pediatric experience.
It never invents a contact. A guessed email that bounces costs more than a blank cell. With no known-good address for a domain it emits nothing, and says so. Anything unresolved stays empty.
That behaviour lives in deterministic code, not in prose, so it does not depend on a model choosing to be careful on a given run.
Four steps, so every one is reviewable. Do not pipe it straight into your skills directory.
# 1. land it somewhere inert
mkdir -p /tmp/skill-review && cd /tmp/skill-review
curl -fsSL -O https://github.com/Scotty108/leads-now-skill/releases/download/v1.0.0/leads-now-skill.zip
# 2. verify the bytes match what was published
curl -fsSL -O https://github.com/Scotty108/leads-now-skill/releases/download/v1.0.0/leads-now-skill.zip.sha256
shasum -a 256 -c leads-now-skill.zip.sha256
# 3. look before you extract
unzip -l leads-now-skill.zip
unzip -q leads-now-skill.zip -d ./review && find ./review -type f -exec cat {} +
# 4. only then install
cp -r ./review/leads-now ~/.claude/skills/Restart Claude Code. Confirm with "what skills do you have?" — look for
leads-now.
Claude apps / Cowork: upload the zip in Customize → Skills (do not
unzip it first). Cowork loads skills enabled for your claude.ai account, not
your local ~/.claude/skills/.
- No network calls from any shipped code.
leadkit.pyimports onlyargparse, csv, glob, gzip, json, math, os, re, sys, unicodedata, urllib.parse. It reads local files, transforms them, writes local files. - No credentials, no API keys, no accounts. Nothing to configure.
- No runtime instruction fetching. Every behaviour is in the files you installed, so what you review is what runs.
- All fetching goes through the host agent's own tools, under its normal permissions — never from inside a script.
- Business contact data only. No consumer or personal contact data, no scraping behind a login whose terms forbid it, no CAPTCHA or bot-detection evasion, and it does not send outreach.
Python 3.8+ and code execution. Web search and page fetching enable automatic sourcing; without them it still enriches a list you provide. Browser tools are optional and used only for sources that block plain fetching.
skills/leads-now/ THE SKILL — this is what ships
skill-bakeoff/ archived competitor, kept for the benchmark record
bench/ invariant tests + the comparison protocol
scripts/build-skill-zip.sh packages skills/leads-now/ for distribution
skill-bakeoff/finding-leads was generated by a separate skill-builder against
the same brief, and the two were measured head to head for four rounds so each
could absorb what the other did better. That bake-off is complete — see
skill-bakeoff/ARCHIVED.md for the result and what was ported across. Only
skills/leads-now/ ships; bench/LOOP.md documents the protocol that got it
there.
python3 bench/test_invariants.pyNine checks per skill — upload-legal frontmatter, no Claude-Code-only syntax, stdlib-only scripts, no network in scripts, the refusal behaviour, off-domain sample rejection, ambiguous-surname handling, and two measured facts the docs must not contradict.
Both of these are load-bearing and both were verified directly, not assumed:
- The NPI registry silently repeats past
skip=1000.skip=1000andskip=1200return identical records with no error and no truncation flag, so a naive pager produces duplicates and a count that looks complete. Shard the query;leadkit ingestexits 4 when it detects the ceiling. - Query the parent taxonomy, not the subspecialty. Within 50 miles of
Myrtle Beach:
Pediatric Anesthesiologyreturns 0 providers, parentAnesthesiologyreturns 72. The narrow query returns an empty list that looks like a correct answer.
A 50-mile radius around Myrtle Beach also spans two states — of the anesthesiology providers returned, 886 were in North Carolina. A single-state query drops every one.
MIT