agent-decision-receipts

Revisar · 66
Indexado en Registry

Mint a tamper-evident, post-quantum-signed receipt for a consequential agent action (deploy, delete, pay, grant-access, model decision) so it can be verified later from the certificate alone. Use when an autonomous agent takes a side-effecting action that may need to be proven la

Verified installs0
Estrellas24.8K
Versión1.0.0
Calidad91/100 · Excelente
Confianza66/100 · Solo sandbox
Auditoría83/100 · Requiere revisión

Perfil del activo

Investigación y trabajo de conocimiento

Deep research, source comparison, literature review, RAG, knowledge search, and reports.

Ver categoría

Escenario

Agents de investigación

I need my agent to research a topic, compare sources, and produce a concise report.

Afinidad con Agent

Claude Code + CLI + Codex

Funciona con Codex, Claude Code, Cursor, CLI o Agents personalizados.

Instalar

Listo

npx skills add alirezarezvani/claude-skills --skill agent-decision-receipts

Mantenimiento

Actual

1 días desde el último push

Riesgo

Requiere revisión

Dependency or permission surface needs review

Calidad de GitHub

25K

91/100 Calidad · 74/100 Confianza

Etiquetas de cobertura

InvestigaciónAgents de investigaciónagent-skill

Notas de revisión

Dependency or permission surface needs review · Permission surface may require sandboxing

Tarjeta de adopción del Agent

Confianza, auditoría y preparación de instalación de un vistazo

Estas puntuaciones combinan metadatos públicos del repositorio, señales de revisión de OpenAgentSkill, actualidad de mantenimiento y preparación de instalación. Sirven para preseleccionar; no sustituyen la revisión humana.

Calidad

Excelente
91

High-confidence pick with strong adoption and healthy maintenance signals.

Confianza

Solo sandbox
66

Candidata útil con señales de confianza incompletas o mixtas. Manténgala en un espacio aislado hasta que el ciclo de resultados demuestre el ajuste.

Auditoría

Requiere revisión
83

Revisión legible por máquina de la preparación de instalación, los metadatos de seguridad, el mantenimiento y el riesgo de adopción.

Trust Score de OpenAgentSkill v5

Revisión humana antes de instalar

Ejecute solo en un sandbox y compare alternativas cercanas antes de usarla en trabajo real.

CodexClaude CodeCursorOpenAgentSkill CLI

Estrellas

25K estrellas de GitHub

Actividad del repositorio

25K estrellas y 3.5K forks

Mantenimiento

1 días desde el último push

Licencia

MIT

Instalar

npx skills add alirezarezvani/claude-skills --skill agent-decision-receipts

Seguridad de instalación

Ruta estándar de paquete o instalación en tiempo de ejecución

Superficie de permisos

secrets or environment access, shell or command execution

Resultados del Agent

Aún no hay datos de resultados del Agent

Documentación

Contexto sólido de README/SKILL.md

Resumen de riesgo

Revisar antes de producción

  • The skill relies on an external package (openagentontology) for cryptographic operations; while this is clearly documented, the package's security posture is not independently verified by this review.
  • Financial research output is not financial advice; require human review before any live investment decision.
  • Quality score needs review
  • Permission surface needs review: secrets or environment access, shell or command execution

Preparación de instalación

Ruta de instalación disponible

  • La ruta de instalación está disponible
  • La evidencia del repositorio está disponible
  • La licencia está declarada
  • Aún no hay evidencia de resultados Agent-Proven

Metadatos legibles por Agent

Datos de decisión legibles por máquina para este skill.

Usa este bloque o el JSON integrado para decidir si un Agent debe instalar este skill, elegir una alternativa o pedir revisión humana primero.

Abrir JSON

Tareas adecuadas

  • Flujos de Agents de investigación
  • Equipos de Claude Code
  • Equipos que valoran señales de adopción de GitHub
  • Fuentes de búsqueda

Agents adecuados

CodexClaude CodeCursorOpenAgentSkill CLICLI

Decisión de instalación

Comando
npx skills add alirezarezvani/claude-skills --skill agent-decision-receipts
Política
Revisar
Revisión humana

Confianza y riesgo

Confianza
66/100
Auditoría
83/100
Nivel de riesgo
Requiere revisión

Ciclo de resultados

Endpoint
/api/agent/outcome
ID del evento
resolve
Resultados
5

Comando de instalación

npx skills add alirezarezvani/claude-skills --skill agent-decision-receipts

No usar cuando

  • Equipos que necesitan un SLA con soporte del proveedor
  • production agents without a repository review
  • The skill relies on an external package (openagentontology) for cryptographic operations; while this is clearly documented, the package's security posture is not independently verified by this review.
  • Indicios de permisos de alto riesgo: Shell or command execution, Secrets or environment access
  • Dependency or permission surface needs review

Seguridad de Agent v2

39/100 · Evitar instalación automática

ExperimentalRevisar

Sparse or mixed signals. Useful for discovery, but not for autonomous installation.

Test manually in an isolated workspace and compare against safer alternatives.

Resolver con API

Alto

Ejecución de shell o comandos

Los metadatos del skill hacen referencia a terminal, CLI, shell, subprocesos o flujos de ejecución de comandos.

Medio

Acceso a red

El skill probablemente consulta páginas remotas, API, repositorios o servicios externos.

Medio

Acceso al sistema de archivos

El skill puede leer o escribir archivos de proyecto, documentos, artefactos generados o estado local.

Alto

Secrets or environment access

Skill metadata references credentials, tokens, environment variables, or secret-bearing workflows.

  • Indicios de permisos de alto riesgo: Shell or command execution, Secrets or environment access
  • Dependency or permission surface needs review

Destinos de instalación

Instala este skill en tu flujo de Agent

Usa el endpoint público para obtener el comando, la lista de seguridad, prompts y enlaces canónicos.

skill install

OpenAgentSkill CLI

Resolve policy, run the source installer safely, and report a verified install receipt.

$ npx --yes https://github.com/Leon-Drq/openagentskill/releases/download/cli-v0.2.1/openagentskill-0.2.1.tgz install alirezarezvani-agent-decision-receipts

Plan de resolución de Agent

Deja que un Agent valide el ajuste antes de instalar.

La API Resolve devuelve la skill elegida, alternativas, política de seguridad, notas de auditoría, destino de instalación y un prompt listo para usar.

Abrir plan de texto

Agent debe revisar

  • Task fit and alternatives from Resolve API.
  • Audit score, trust score, and safety policy warnings.
  • Install target compatibility for Codex, Claude Code, Cursor, or CLI.

Copiar prompt

Task: Use agent-decision-receipts in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20agent-decision-receipts%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/alirezarezvani-agent-decision-receipts/install
Install command: npx skills add alirezarezvani/claude-skills --skill agent-decision-receipts
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.

Traspaso de Agent

Da al Agent la ruta de instalación, no otro directorio.

Usa el endpoint público para obtener el comando, la lista de seguridad, prompts y enlaces canónicos.

Abrir API de instalación

Prompt de Agent

Use agent-decision-receipts for this task. Review https://www.openagentskill.com/api/skills/alirezarezvani-agent-decision-receipts/install, then install with: npx skills add alirezarezvani/claude-skills --skill agent-decision-receipts

Metadatos del Registry

Perfil legible por Agent para seleccionar skills automáticamente.

La API Registry expone señales de decisión, confianza, auditoría, casos de uso e instalación sin raspar la interfaz.

Abrir Manifest

Afinidad con Agent

100/100

Agents de investigación

Plataformas

Claude Code

Informe de auditoría

Requiere revisión · 83/100

Revisión legible por máquina de la preparación de instalación, los metadatos de seguridad, el mantenimiento y el riesgo de adopción.

Ver informe de auditoríaVer informe de evaluación

Panel de decisión de Agent

Elección principal para Agents de investigación

Use this as a leading candidate, then validate the README and install path in your own agent stack.

100
Preparación
Adoptar
Etapa

Rol en la pila

Elección principal

Ajuste principal

Agents de investigación

Etiqueta de confianza

Listo para producción

Ruta de instalación

Comando listo

Úsalo cuando

  • Flujos de Agents de investigación
  • Equipos de Claude Code
  • Equipos que valoran señales de adopción de GitHub

Evidencia

  • 24,795 estrellas de GitHub
  • recent repository activity
  • install command or GitHub repo available
  • perfil de calidad 91/100
  • 3 eventos de interacción de OpenAgentSkill

revisar primero

  • The skill relies on an external package (openagentontology) for cryptographic operations; while this is clearly documented, the package's security posture is not independently verified by this review.

Ruta de implementación

  1. 1Instálalo en un Agent de sandbox y ejecuta una tarea de Agents de investigación de principio a fin.
  2. 2Compare output quality, latency, and failure behavior against at least one alternative.
  3. 3Promote it into production only after reviewing repository permissions, license, and maintenance signals.

Perfil de confianza

Solo sandbox

Candidata útil con señales de confianza incompletas o mixtas. Manténgala en un espacio aislado hasta que el ciclo de resultados demuestre el ajuste.

66
Trust Score de OpenAgentSkill

Adopción en GitHub

Aprobado

25K estrellas de GitHub

Actividad de stars/forks

Aprobado

25K estrellas y 3.5K forks; la actividad de issues no está disponible en los metadatos actuales

Mantenimiento reciente

Aprobado

1 días desde el último push

Claridad de licencia

Aprobado

MIT

Señales positivas

  • Revisión de IA aprobada
  • La ruta de instalación está disponible
  • La evidencia del repositorio está disponible
  • Repositorio mantenido recientemente
  • Large GitHub adoption signal
  • El comando de instalación no muestra un patrón de alto riesgo evidente
  • El ciclo de resultados está listo, pero necesita la primera ejecución real de Agent

Revisar antes de instalar

  • The skill relies on an external package (openagentontology) for cryptographic operations; while this is clearly documented, the package's security posture is not independently verified by this review.
  • Financial research output is not financial advice; require human review before any live investment decision.
  • Quality score needs review
  • Permission surface needs review: secrets or environment access, shell or command execution
  • Dependency/runtime risk: command execution surface, credential or environment access
  • Permission surface: secrets or environment access, shell or command execution
  • Aún no hay informes reales de resultados del Agent
  • Se requiere revisión humana antes de una instalación desatendida

Acción recomendada

Ejecute solo en un sandbox y compare alternativas cercanas antes de usarla en trabajo real.

Perfil de calidad

Excelente candidato para flujos de Agent

High-confidence pick with strong adoption and healthy maintenance signals.

91
Estrellas de GitHub
25K
Actualidad
hace 1 días
Listo para instalar
Licencia
MIT
Revisar antes de instalar: The skill relies on an external package (openagentontology) for cryptographic operations; while this is clearly documented, the package's security posture is not independently verified by this review.

Ajuste de flujo

Usa esta skill en estos escenarios

Ajuste de flujo

Añadir a un flujo completo

Lista de alternativas

Compara antes de instalar

Similar skills that may fit this task.

Comparar todo

Resumen

--- name: "agent-decision-receipts" description: "Mint a tamper-evident, post-quantum-signed receipt for a consequential agent action (deploy, delete, pay, grant-access, model decision) so it can be verified later from the certificate alone. Use when an autonomous agent takes a side-effecting action that may need to be proven later, or when satisfying EU AI Act Article 12 record-keeping. Three decisions: whether an action needs a receipt, minting it, verifying it. Signing is delegated to the open-source OpenAgentOntology package. Not after-the-fact log analysis; not a hosted notary; not a legal opinion." ---

# Agent Decision Receipts

## Overview

A log says an action happened. A **receipt is tamper-evident**: it records who, what, and under which policy, and it is signed, so any later edit breaks the signature. This skill mints one for a consequential agent action and verifies it later from the certificate alone: no database, no network, no trusting the issuer.

The crypto is not in this skill. It is the open-source **OpenAgentOntology** receipt primitive (Apache-2.0), which signs every receipt with Ed25519 **and** the post-quantum legs ML-DSA-65 (FIPS 204) + SLH-DSA (FIPS 205) when the post-quantum backend is installed. This skill is the decision layer: when to mint, what to put in, how to verify. One install, no per-skill crypto.

**Three decisions, nothing else:**

1. **Does this action need a receipt?** — side-effecting + consequential + later-provable = yes. 2. **Mint the receipt** — build the action manifest, sign it with the OAO primitive. 3. **Verify it** — recompute the hash, check each signature leg, from the cert alone.

This skill is **NOT log analysis.** Logs describe what happened and can be silently edited. A receipt is minted before/at execution and breaks if edited. Use logs for debugging; use receipts for evidence.

This skill is **NOT a hosted notary.** It mints a LOCAL, self-signed receipt anyone can verify offline. Cross-organization verification (one org proving to another) is a separate hosted service, out of scope here.

This skill is **NOT a legal opinion.** It produces evidence shaped to support FRE 902(13)/(14)-style certification and EU AI Act Article 12 record-keeping. Whether a given receipt is admitted is a question for counsel.

## Quick Start

```bash # Install the open-source receipt primitive (Apache-2.0). Add [pq] for the post-quantum legs. pip install "openagentontology[pq]"

# 1. Build + validate an action manifest (stdlib only, no crypto, no network) python scripts/build_action_manifest.py --agent my-deploy-agent --operation deploy \ --target prod/api --policy "EU AI Act Art 12" --out action.json

# 2. Mint the receipt over it (Ed25519 + post-quantum legs) python -c "import json,openagentontology.receipt as r; \ print(json.dumps(r.mint_receipt(json.load(open('action.json')), decision='ACTION_GOVERNED')))" > receipt.json

# 3. Verify from the cert alone (no DB, no network) python -c "import json,openagentontology.receipt as r; \ print(r.verify_receipt(json.load(open('receipt.json'))))" # -> {'ok': True, 'sig_ok': True, ... 'reason': 'verified from the cert alone via: ed25519, ml_dsa, slh_dsa'} ```

> **Dependency note.** This skill delegates the signing to `openagentontology` (Apache-2.0, opt-in `pip install`). The script shipped here is stdlib-only and adds no repo dependency; the package is installed by the operator (BYO-library pattern). If it is not installed, the build step still works — only minting/verifying require it.

## Core Workflow

The three decisions below are the skill: decide whether to receipt, mint, then verify.

## Decision 1: Does this action need a receipt?

Mint a receipt when the action is **all three** of:

| Test | Mint if... | |------|-----------| | Side-effecting | it writes, sends, deploys, deletes, pays, grants access, or changes external state | | Consequential | a wrong call costs money, breaks compliance, or harms a person | | Later-provable | someone (auditor, insurer, regulator, court, counterparty) may ask "what did the agent do and why?" |

Read-only, reversible, trivial actions do **not** need a receipt. Receipt everything and the signal drowns; receipt nothing and the one call that mattered cannot be proven.

High-signal triggers (mint by default): `deploy`, `delete`, `pay`/`wire`/`refund`, `grant_access`, `export`/`egress`, `approve`/`deny` a claim, any model decision that affects a person under a high-risk AI system.

## Decision 2: Mint the receipt

The action manifest is any ASCII-safe dict describing what the agent did. Four keys are **required** — `build_action_manifest.py` rejects the manifest (exit 2) if any is missing. Two more are added automatically:

| Key | Required? | What it carries | |-----|-----------|-----------------| | `agent_id` | **required** | the acting agent | | `operation` | **required** | the verb (deploy / delete / pay / decide / ...) | | `target` | **required** | what it acted on | | `policy` | **required** | the rule that governs it (e.g. "EU AI Act Art 12", "internal change-control") | | `inputs_hash` | auto-added | a hash of `--inputs`, so the full payload need not be stored in the clear (defaults to the hash of empty when `--inputs` is omitted) | | `decision_label` | auto-added | the receipt decision label (defaults to `ACTION_GOVERNED`) |

`mint_receipt(manifest, decision=...)` hashes the full manifest into the receipt evidence, signs the canonical body, and returns a receipt that carries: `evidence_hash`, `signature_b64` (Ed25519), and — when `[pq]` is installed — `ml_dsa_signature_b64` + `slh_dsa_signature_b64`. Each leg signs the same bytes; any one verifying proves authenticity.

> See [references/receipt-fields.md](references/receipt-fields.md) for the full receipt schema and the post-quantum rationale.

## Decision 3: Verify it

`verify_receipt(receipt)` recomputes `sha256(canonical(evidence))`, compares it to `evidence_hash`, then checks every signature leg it has a backend for. It returns `{ok, hash_ok, sig_ok, legs, reason}`. A single edited byte anywhere in the action breaks `hash_ok`; a forged signature breaks the leg. Verification needs only the receipt — no call back to the issuer.

This is the property that makes it evidence: a reviewer who distrusts the issuer can still confirm the receipt is intact and authentic, entirely offline.

## Anti-Patterns

- **Receipt the log, not the decision.** Minting a receipt over a log line written after the fact proves nothing. Mint at the point of action, over the action. - **Storing the signing key next to the receipts.** If the key is compromised, signatures mean nothing. Treat the key like any signing secret; never commit it. - **Ed25519-only when the post-quantum legs are available.** A receipt is long-lived evidence. Sign it once with the post-quantum legs (ML-DSA-65 + SLH-DSA) so it stays verifiable if a future quantum computer could break Ed25519. Install `[pq]`. - **Putting raw secrets or PII in the manifest.** The manifest is hashed into evidence and is recoverable from the receipt. Carry hashes (`inputs_hash`), not the cleartext. - **Calling it "admissible."** It is evidence shaped to *support* FRE 902(13)/(14)-style certification. Admissibility is a court's decision, not the tool's claim. - **Faking a signature when crypto is missing.** The primitive emits an explicit `unsigned` flag instead. Never present an unsigned receipt as signed.

## Cross-References

- `ra-qm-team/skills/eu-ai-act-specialist/` — decide the AI system's risk tier and Article 12 obligations; this skill mints the per-action record those obligations require. - `ra-qm-team/skills/iso42001-specialist/` — the AI management-system controls; receipts are the per-decision evidence those controls call for. - OpenAgentOntology (Apache-2.0): the open receipt primitive this skill drives — `pip install "openagentontology[pq]"`.

Detalles técnicos

Versión
1.0.0
Licencia
MIT
Última actualización
22 ago 2026
Publicado
22 ago 2026

Resumen de decisión

Elección principal

100
Listo
Adoptar
Etapa

24,795 estrellas de GitHub

Auditoría

Revisión de instalación

Revisión de instalación y adopción

83
Requiere revisión
Seguridad
69/100
Mantenimiento
100/100
Instalar
92/100
Abrir auditoría completaVer informe de evaluación

Evidencia probada por Agent

Evidencia probada por Agent

Informes de resultados tras resolver, revisar, instalar y una ejecución limitada.

0
Probado
Needs first agent runAuto-instalación: revisar primeroÚltimo: Desconocido
Tasa de éxito
Fallo reciente
Resultados
0
Calidad de salida
Fallidos
0
No relevante
0
Instalaciones
0
Bloqueado por riesgo
0
Configuración necesaria
0
Producción
0

Aún no hay datos de resultados de Agent. La primera ejecución puede informar éxito, configuración necesaria, bloqueos de riesgo, fallo o irrelevancia mediante /api/agent/outcome.

Instalar

Añadir al flujo de Agent

Gratis y de código abierto. Revisa el informe antes de instalar en Agents de producción.

Bucle de crecimiento

Kit para compartir

X

Borrador basado en un caso para agent-decision-receipts, listo para publicar manualmente en X.

Nota del curador
agent-decision-receipts: Mint a tamper-evident, post-quantum-signed receipt for a consequential agent action (deploy,...

24.8K stars

https://www.openagentskill.com/skills/alirezarezvani-agent-decision-receipts?ref=x
Abrir borrador de X
Respuesta opcional con comando de instalación
Listing + install path for agent-decision-receipts:
https://www.openagentskill.com/skills/alirezarezvani-agent-decision-receipts?ref=x

Install: npx skills add alirezarezvani/claude-skills --skill agent-decision-receipts

Fuente de la ficha

Indexado por Registry

Reclamable

Esta ficha se indexó desde fuentes públicas y no está marcada como oficial hasta que se apruebe una reclamación de mantenedor.

Indexado por
Índice comunitario de OpenAgentSkill

La atribución enlaza al repositorio público o al perfil del creador. Los creadores pueden reclamar la ficha para actualizar las señales de propiedad.

Reclamar este skill

Reclamación del propietario

Reclamar esta ficha de skill

Esta ficha Indexado por Registry se atribuye a alirezarezvani, pero aún no está marcada como oficial. Reclámala para añadir una señal de propietario verificado y hacer más fiables futuras actualizaciones de lanzamiento, instalación y auditoría.

Kit de enlaces para creadores

Añade las insignias de evidencia a tu README

Muestra la ficha canónica, las señales actuales de confianza y auditoría, y evidencia real de Agent-Proven donde los desarrolladores evalúan el repositorio.

[![Listed on OpenAgentSkill](https://www.openagentskill.com/api/badge/alirezarezvani-agent-decision-receipts?metric=listed&label=Listed)](https://www.openagentskill.com/skills/alirezarezvani-agent-decision-receipts)
[![OpenAgentSkill Trust](https://www.openagentskill.com/api/badge/alirezarezvani-agent-decision-receipts?metric=trust&label=Trust)](https://www.openagentskill.com/skills/alirezarezvani-agent-decision-receipts)
[![OpenAgentSkill Audit](https://www.openagentskill.com/api/badge/alirezarezvani-agent-decision-receipts?metric=audit&label=Audit)](https://www.openagentskill.com/skills/alirezarezvani-agent-decision-receipts/audit)
[![Agent Proven](https://www.openagentskill.com/api/badge/alirezarezvani-agent-decision-receipts?metric=proven&label=Agent%20Proven)](https://www.openagentskill.com/skills/alirezarezvani-agent-decision-receipts)

Autor

A

alirezarezvani

@alirezarezvani

Etiquetas

Afinidad con plataforma

Señales de salud

Estrellas de GitHub
24.8K
Puntuación de calidad
54/100
Último push de GitHub
22 ago 2026
Pistas del framework
Desconocido
Vistas de OpenAgentSkill
3
Copias de instalación
0
Clics externos
0

Señal de comunidad

Comparte si este skill resulta útil para tu flujo de Agent. Los comentarios agregados mejoran la clasificación con el tiempo.

Confianza y seguridad

Solo sandbox

66
  • Adopción en GitHub25K estrellas de GitHubAprobado
  • Actividad de stars/forks25K estrellas y 3.5K forks; la actividad de issues no está disponible en los metadatos actualesAprobado
  • Mantenimiento reciente1 días desde el último pushAprobado
  • Claridad de licenciaMITAprobado
  • Completitud de README/SKILL.mdLos metadatos incluyen suficiente contexto de uso y flujo de trabajoAprobado
  • Riesgo de dependencias/runtimecommand execution surface, credential or environment accessCorregir