agent-decision-receipts
Mint a tamper-evident, post-quantum-signed receipt for a consequential agent action (deploy, delete, pay, grant-access, model decision) so it can be verified later from the certificate alone. Use when an autonomous agent takes a side-effecting action that may need to be proven la
Profil de l’actif
Recherche et travail de connaissance
Deep research, source comparison, literature review, RAG, knowledge search, and reports.
Scénario
Agents de recherche
I need my agent to research a topic, compare sources, and produce a concise report.
Adéquation Agent
Claude Code + CLI + Codex
Compatible avec Codex, Claude Code, Cursor, CLI ou des Agents personnalisés.
Installer
Prêt
npx skills add alirezarezvani/claude-skills --skill agent-decision-receipts
Maintenance
À jour
Mis à jour aujourd’hui
Risque
Revue nécessaire
Dependency or permission surface needs review
Qualité GitHub
25K
91/100 Qualité · 74/100 Confiance
Tags de couverture
Notes de revue
Dependency or permission surface needs review · Permission surface may require sandboxing
Carte d’adoption Agent
Confiance, audit et préparation à l’installation en un coup d’œil
Ces scores combinent les métadonnées publiques du dépôt, les signaux de revue OpenAgentSkill, la fraîcheur de maintenance et la préparation à l’installation. Ils servent à présélectionner et ne remplacent pas la revue humaine.
Qualité
ExcellentHigh-confidence pick with strong adoption and healthy maintenance signals.
Confiance
Sandbox uniquementCandidate utile avec des signaux de confiance incomplets ou mixtes. Gardez-la dans un espace isolé jusqu’à ce que la boucle de résultats confirme son adéquation.
Audit
Revue nécessaireRevue lisible par machine de la préparation à l’installation, des métadonnées de sécurité, de la maintenance et du risque d’adoption.
Trust Score OpenAgentSkill v5
Revue humaine avant installation
Exécutez uniquement dans un sandbox et comparez les alternatives proches avant usage réel.
Stars
25K stars GitHub
Activité du dépôt
25K stars et 3.5K forks
Maintenance
Mis à jour aujourd’hui
Licence
MIT
Installer
npx skills add alirezarezvani/claude-skills --skill agent-decision-receipts
Sécurité d’installation
Chemin d’installation standard de package ou runtime
Surface de permissions
secrets or environment access, shell or command execution
Résultats Agent
Pas encore de données de résultats Agent
Documentation
Contexte README/SKILL.md solide
Résumé des risques
Revoir avant production
- The skill relies on an external package (openagentontology) for cryptographic operations; while this is clearly documented, the package's security posture is not independently verified by this review.
- Financial research output is not financial advice; require human review before any live investment decision.
- Quality score needs review
- Permission surface needs review: secrets or environment access, shell or command execution
Préparation à l’installation
Chemin d’installation disponible
- Le chemin d’installation est disponible
- La preuve du dépôt est disponible
- La licence est déclarée
- Pas encore de preuve de résultat Agent-Proven
Métadonnées lisibles par Agent
Données de décision lisibles par machine pour ce skill.
Utilisez ce bloc ou le JSON intégré pour décider si un Agent doit installer ce skill, choisir une alternative ou demander d’abord une revue humaine.
Tâches adaptées
- Workflows d’Agents de recherche
- Équipes Claude Code
- Équipes qui valorisent les signaux d’adoption GitHub
- Sources de recherche
Agents adaptés
Décision d’installation
- Commande
- npx skills add alirezarezvani/claude-skills --skill agent-decision-receipts
- Politique
- Revoir
- Revue humaine
- Oui
Confiance et risque
- Confiance
- 66/100
- Audit
- 83/100
- Niveau de risque
- Revue nécessaire
Boucle de résultat
- Endpoint
- /api/agent/outcome
- ID d’événement
- resolve
- Résultats
- 5
Commande d’installation
npx skills add alirezarezvani/claude-skills --skill agent-decision-receiptsNe pas utiliser quand
- Équipes qui nécessitent un SLA soutenu par le fournisseur
- production agents without a repository review
- The skill relies on an external package (openagentontology) for cryptographic operations; while this is clearly documented, the package's security posture is not independently verified by this review.
- No OpenAgentSkill engagement data yet
- Indices de permissions à haut risque : Shell or command execution, Secrets or environment access
Skill alternatif
Last30days Skill
53.5K Stars
npx skills add mvanhorn/last30days-skill -g
Skill alternatif
Academic Research Skills
38.4K Stars
npx skills add Imbad0202/academic-research-skills
Skill alternatif
GPT Researcher
28.0K Stars
npx skills add assafelovic/gpt-researcher
Skill alternatif
DeepResearch
19.8K Stars
npx skills add Alibaba-NLP/DeepResearch
Sécurité Agent v2
39/100 · Éviter l’installation automatique
Sparse or mixed signals. Useful for discovery, but not for autonomous installation.
Test manually in an isolated workspace and compare against safer alternatives.
Élevé
Exécution shell ou de commande
Les métadonnées de la skill font référence à des workflows de terminal, CLI, shell, sous-processus ou exécution de commande.
Moyen
Accès réseau
La skill récupère probablement des pages distantes, API, dépôts ou services externes.
Moyen
Accès au système de fichiers
La skill peut lire ou écrire des fichiers de projet, documents, artefacts générés ou l’état local de l’espace de travail.
Élevé
Secrets or environment access
Skill metadata references credentials, tokens, environment variables, or secret-bearing workflows.
- Indices de permissions à haut risque : Shell or command execution, Secrets or environment access
- Dependency or permission surface needs review
Cibles d’installation
Installer ce skill dans votre workflow Agent
Utilisez le point de terminaison public pour récupérer la commande, la checklist, les prompts et les liens canoniques.
OpenAgentSkill CLI
Resolve policy, run the source installer safely, and report a verified install receipt.
$ npx --yes https://github.com/Leon-Drq/openagentskill/releases/download/cli-v0.2.1/openagentskill-0.2.1.tgz install alirezarezvani-agent-decision-receiptsPlan de résolution Agent
Laissez un Agent vérifier la pertinence avant l’installation.
L’API Resolve renvoie la skill sélectionnée, des alternatives, la politique de sécurité, les notes d’audit, la cible d’installation et un prompt prêt à l’emploi.
Ouvrir JSON
/api/agent/resolve?task=Use%20agent-decision-receipts%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Texte Resolve
/api/agent/resolve?task=Use%20agent-decision-receipts%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
Relais d’installation
/api/skills/alirezarezvani-agent-decision-receipts/install
L’Agent doit vérifier
- Task fit and alternatives from Resolve API.
- Audit score, trust score, and safety policy warnings.
- Install target compatibility for Codex, Claude Code, Cursor, or CLI.
Copier le prompt
Task: Use agent-decision-receipts in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20agent-decision-receipts%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/alirezarezvani-agent-decision-receipts/install
Install command: npx skills add alirezarezvani/claude-skills --skill agent-decision-receipts
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Relais Agent
Donnez à l’Agent le chemin d’installation, pas un autre annuaire.
Utilisez le point de terminaison public pour récupérer la commande, la checklist, les prompts et les liens canoniques.
Relais d’installation
/api/skills/alirezarezvani-agent-decision-receipts/install
Format texte LLM
/api/skills/alirezarezvani-agent-decision-receipts/install?format=text
Trouver des alternatives
/api/skills/search?q=agent-decision-receipts&limit=3
Prompt Agent
Use agent-decision-receipts for this task. Review https://www.openagentskill.com/api/skills/alirezarezvani-agent-decision-receipts/install, then install with: npx skills add alirezarezvani/claude-skills --skill agent-decision-receiptsMétadonnées Registry
Profil lisible par Agent pour la sélection automatique de skills.
L’API Registry fournit les signaux de décision, confiance, audit, cas d’usage et installation sans analyser l’interface.
Manifest
/api/registry/manifest/alirezarezvani-agent-decision-receipts
Texte LLM
/api/registry/manifest/alirezarezvani-agent-decision-receipts?format=text
Alias d’installation
/api/registry/install/alirezarezvani-agent-decision-receipts
Recommander
/api/registry/recommend?task=Use%20agent-decision-receipts%20in%20an%20agent%20workflow&limit=3
Adéquation Agent
Agents de recherche
Tags de cas d’usage
Plateformes
Claude Code
Rapport d’audit
Revue nécessaire · 83/100
Revue lisible par machine de la préparation à l’installation, des métadonnées de sécurité, de la maintenance et du risque d’adoption.
Panneau de décision Agent
Choix principal pour Agents de recherche
Use this as a leading candidate, then validate the README and install path in your own agent stack.
Rôle dans la pile
Choix principal
Pertinence principale
Agents de recherche
Libellé de confiance
Prêt pour la production
Chemin d’installation
Commande prête
À utiliser lorsque
- Workflows d’Agents de recherche
- Équipes Claude Code
- Équipes qui valorisent les signaux d’adoption GitHub
Preuves
- 24,795 stars GitHub
- recent repository activity
- install command or GitHub repo available
- profil qualité 91/100
revoir d’abord
- The skill relies on an external package (openagentontology) for cryptographic operations; while this is clearly documented, the package's security posture is not independently verified by this review.
- No OpenAgentSkill engagement data yet
Chemin d’implémentation
- 1Installez-le dans un Agent en sandbox et exécutez une tâche de Agents de recherche de bout en bout.
- 2Compare output quality, latency, and failure behavior against at least one alternative.
- 3Promote it into production only after reviewing repository permissions, license, and maintenance signals.
Profil de confiance
Sandbox uniquement
Candidate utile avec des signaux de confiance incomplets ou mixtes. Gardez-la dans un espace isolé jusqu’à ce que la boucle de résultats confirme son adéquation.
Adoption GitHub
Validé25K stars GitHub
Activité stars/forks
Validé25K stars et 3.5K forks; l’activité des issues n’est pas disponible dans les métadonnées actuelles
Maintenance récente
ValidéMis à jour aujourd’hui
Clarté de licence
ValidéMIT
Signaux positifs
- Revue IA approuvée
- Le chemin d’installation est disponible
- La preuve du dépôt est disponible
- Dépôt maintenu récemment
- Large GitHub adoption signal
- La commande d’installation ne présente aucun motif de haut risque évident
- La boucle de résultats est prête mais nécessite la première exécution réelle de l’Agent
Réviser avant installation
- The skill relies on an external package (openagentontology) for cryptographic operations; while this is clearly documented, the package's security posture is not independently verified by this review.
- Financial research output is not financial advice; require human review before any live investment decision.
- Quality score needs review
- Permission surface needs review: secrets or environment access, shell or command execution
- Dependency/runtime risk: command execution surface, credential or environment access
- Permission surface: secrets or environment access, shell or command execution
- Pas encore de rapports de résultats Agent réels
- Une revue humaine est requise avant une installation sans surveillance
Action recommandée
Exécutez uniquement dans un sandbox et comparez les alternatives proches avant usage réel.
Profil qualité
Excellent candidat pour les workflows Agent
High-confidence pick with strong adoption and healthy maintenance signals.
Adéquation au workflow
Utilisez cette skill dans ces scénarios
Investigate faster
Research agents
I need my agent to research a topic, compare sources, and produce a concise report.
Reduce risk
Security and compliance
I need my agent to scan a project for security risks and summarize what needs attention.
Manage repositories
GitHub automation
I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.
Adéquation au workflow
Ajouter à un workflow complet
Find, compare, and synthesize
Research report agent
A workflow for agents that gather sources, compare claims, summarize long material, and draft useful research briefs.
Inspect, patch, and verify code
Coding review agent
A workflow for software agents that inspect repositories, review pull requests, generate tests, and turn findings into shippable patches.
Operate and verify web apps
Browser QA agent
A workflow for agents that navigate products, fill forms, take screenshots, and verify real user flows across web applications.
Liste d’alternatives
Comparer avant installation
Similar skills that may fit this task.
Last30days Skill
Research the last 30 days across Reddit, X, YouTube, Hacker News, Polymarket, GitHub, and the web, then synthesize a grounded brief for an AI agent.
Academic Research Skills
Academic Research Skills for Claude Code: research → write → review → revise → finalize
GPT Researcher
Run autonomous deep research over web and local sources
DeepResearch
Tongyi Deep Research, the Leading Open-source Deep Research Agent
Vue d’ensemble
--- name: "agent-decision-receipts" description: "Mint a tamper-evident, post-quantum-signed receipt for a consequential agent action (deploy, delete, pay, grant-access, model decision) so it can be verified later from the certificate alone. Use when an autonomous agent takes a side-effecting action that may need to be proven later, or when satisfying EU AI Act Article 12 record-keeping. Three decisions: whether an action needs a receipt, minting it, verifying it. Signing is delegated to the open-source OpenAgentOntology package. Not after-the-fact log analysis; not a hosted notary; not a legal opinion." ---
# Agent Decision Receipts
## Overview
A log says an action happened. A **receipt is tamper-evident**: it records who, what, and under which policy, and it is signed, so any later edit breaks the signature. This skill mints one for a consequential agent action and verifies it later from the certificate alone: no database, no network, no trusting the issuer.
The crypto is not in this skill. It is the open-source **OpenAgentOntology** receipt primitive (Apache-2.0), which signs every receipt with Ed25519 **and** the post-quantum legs ML-DSA-65 (FIPS 204) + SLH-DSA (FIPS 205) when the post-quantum backend is installed. This skill is the decision layer: when to mint, what to put in, how to verify. One install, no per-skill crypto.
**Three decisions, nothing else:**
1. **Does this action need a receipt?** — side-effecting + consequential + later-provable = yes. 2. **Mint the receipt** — build the action manifest, sign it with the OAO primitive. 3. **Verify it** — recompute the hash, check each signature leg, from the cert alone.
This skill is **NOT log analysis.** Logs describe what happened and can be silently edited. A receipt is minted before/at execution and breaks if edited. Use logs for debugging; use receipts for evidence.
This skill is **NOT a hosted notary.** It mints a LOCAL, self-signed receipt anyone can verify offline. Cross-organization verification (one org proving to another) is a separate hosted service, out of scope here.
This skill is **NOT a legal opinion.** It produces evidence shaped to support FRE 902(13)/(14)-style certification and EU AI Act Article 12 record-keeping. Whether a given receipt is admitted is a question for counsel.
## Quick Start
```bash # Install the open-source receipt primitive (Apache-2.0). Add [pq] for the post-quantum legs. pip install "openagentontology[pq]"
# 1. Build + validate an action manifest (stdlib only, no crypto, no network) python scripts/build_action_manifest.py --agent my-deploy-agent --operation deploy \ --target prod/api --policy "EU AI Act Art 12" --out action.json
# 2. Mint the receipt over it (Ed25519 + post-quantum legs) python -c "import json,openagentontology.receipt as r; \ print(json.dumps(r.mint_receipt(json.load(open('action.json')), decision='ACTION_GOVERNED')))" > receipt.json
# 3. Verify from the cert alone (no DB, no network) python -c "import json,openagentontology.receipt as r; \ print(r.verify_receipt(json.load(open('receipt.json'))))" # -> {'ok': True, 'sig_ok': True, ... 'reason': 'verified from the cert alone via: ed25519, ml_dsa, slh_dsa'} ```
> **Dependency note.** This skill delegates the signing to `openagentontology` (Apache-2.0, opt-in `pip install`). The script shipped here is stdlib-only and adds no repo dependency; the package is installed by the operator (BYO-library pattern). If it is not installed, the build step still works — only minting/verifying require it.
## Core Workflow
The three decisions below are the skill: decide whether to receipt, mint, then verify.
## Decision 1: Does this action need a receipt?
Mint a receipt when the action is **all three** of:
| Test | Mint if... | |------|-----------| | Side-effecting | it writes, sends, deploys, deletes, pays, grants access, or changes external state | | Consequential | a wrong call costs money, breaks compliance, or harms a person | | Later-provable | someone (auditor, insurer, regulator, court, counterparty) may ask "what did the agent do and why?" |
Read-only, reversible, trivial actions do **not** need a receipt. Receipt everything and the signal drowns; receipt nothing and the one call that mattered cannot be proven.
High-signal triggers (mint by default): `deploy`, `delete`, `pay`/`wire`/`refund`, `grant_access`, `export`/`egress`, `approve`/`deny` a claim, any model decision that affects a person under a high-risk AI system.
## Decision 2: Mint the receipt
The action manifest is any ASCII-safe dict describing what the agent did. Four keys are **required** — `build_action_manifest.py` rejects the manifest (exit 2) if any is missing. Two more are added automatically:
| Key | Required? | What it carries | |-----|-----------|-----------------| | `agent_id` | **required** | the acting agent | | `operation` | **required** | the verb (deploy / delete / pay / decide / ...) | | `target` | **required** | what it acted on | | `policy` | **required** | the rule that governs it (e.g. "EU AI Act Art 12", "internal change-control") | | `inputs_hash` | auto-added | a hash of `--inputs`, so the full payload need not be stored in the clear (defaults to the hash of empty when `--inputs` is omitted) | | `decision_label` | auto-added | the receipt decision label (defaults to `ACTION_GOVERNED`) |
`mint_receipt(manifest, decision=...)` hashes the full manifest into the receipt evidence, signs the canonical body, and returns a receipt that carries: `evidence_hash`, `signature_b64` (Ed25519), and — when `[pq]` is installed — `ml_dsa_signature_b64` + `slh_dsa_signature_b64`. Each leg signs the same bytes; any one verifying proves authenticity.
> See [references/receipt-fields.md](references/receipt-fields.md) for the full receipt schema and the post-quantum rationale.
## Decision 3: Verify it
`verify_receipt(receipt)` recomputes `sha256(canonical(evidence))`, compares it to `evidence_hash`, then checks every signature leg it has a backend for. It returns `{ok, hash_ok, sig_ok, legs, reason}`. A single edited byte anywhere in the action breaks `hash_ok`; a forged signature breaks the leg. Verification needs only the receipt — no call back to the issuer.
This is the property that makes it evidence: a reviewer who distrusts the issuer can still confirm the receipt is intact and authentic, entirely offline.
## Anti-Patterns
- **Receipt the log, not the decision.** Minting a receipt over a log line written after the fact proves nothing. Mint at the point of action, over the action. - **Storing the signing key next to the receipts.** If the key is compromised, signatures mean nothing. Treat the key like any signing secret; never commit it. - **Ed25519-only when the post-quantum legs are available.** A receipt is long-lived evidence. Sign it once with the post-quantum legs (ML-DSA-65 + SLH-DSA) so it stays verifiable if a future quantum computer could break Ed25519. Install `[pq]`. - **Putting raw secrets or PII in the manifest.** The manifest is hashed into evidence and is recoverable from the receipt. Carry hashes (`inputs_hash`), not the cleartext. - **Calling it "admissible."** It is evidence shaped to *support* FRE 902(13)/(14)-style certification. Admissibility is a court's decision, not the tool's claim. - **Faking a signature when crypto is missing.** The primitive emits an explicit `unsigned` flag instead. Never present an unsigned receipt as signed.
## Cross-References
- `ra-qm-team/skills/eu-ai-act-specialist/` — decide the AI system's risk tier and Article 12 obligations; this skill mints the per-action record those obligations require. - `ra-qm-team/skills/iso42001-specialist/` — the AI management-system controls; receipts are the per-decision evidence those controls call for. - OpenAgentOntology (Apache-2.0): the open receipt primitive this skill drives — `pip install "openagentontology[pq]"`.
Détails techniques
- Version
- 1.0.0
- Licence
- MIT
- Dernière mise à jour
- 22 août 2026
- Publié
- 22 août 2026
Instantané de décision
Choix principal
24,795 stars GitHub
Audit
Revue d’installation
Revue d’installation et d’adoption
- Sécurité
- 69/100
- Maintenance
- 100/100
- Installer
- 92/100
Preuves validées par Agent
Preuves validées par Agent
Rapports après resolve, revue, installation et une exécution limitée.
- Taux de réussite
- —
- Échec récent
- —
- Résultats
- 0
- Qualité de sortie
- —
- Échecs
- 0
- Non pertinent
- 0
- Installations
- 0
- Bloqué par le risque
- 0
- Configuration requise
- 0
- Production
- 0
Aucune donnée de résultat Agent pour l’instant. La première exécution peut signaler succès, besoin de configuration, blocage de risque, échec ou non-pertinence via /api/agent/outcome.
Installer
Ajouter au workflow Agent
Gratuit et open source. Examinez le rapport avant l’installation dans des Agents de production.
Boucle de croissance
Kit de partage
Brouillon guidé par scénario pour agent-decision-receipts, prêt pour une publication manuelle sur X.
agent-decision-receipts: Mint a tamper-evident, post-quantum-signed receipt for a consequential agent action (deploy,... 24.8K stars https://www.openagentskill.com/skills/alirezarezvani-agent-decision-receipts?ref=x
Réponse facultative avec commande d’installation
Listing + install path for agent-decision-receipts: https://www.openagentskill.com/skills/alirezarezvani-agent-decision-receipts?ref=x Install: npx skills add alirezarezvani/claude-skills --skill agent-decision-receipts
Source de la fiche
Indexé par Registry
Cette fiche a été indexée à partir de sources publiques et n’est pas marquée officielle tant qu’une revendication de mainteneur n’est pas approuvée.
- Créateur
- alirezarezvani
- Indexé par
- Index communautaire OpenAgentSkill
L’attribution renvoie au dépôt public ou au profil du créateur. Les créateurs peuvent revendiquer la fiche pour mettre à jour les signaux de propriété.
Revendiquer ce skillRevendication du propriétaire
Revendiquer cette fiche de skill
Cette fiche Indexé par Registry est attribuée à alirezarezvani, mais n’est pas encore marquée officielle. Revendiquez-la pour ajouter un signal de propriétaire vérifié et rendre les futures mises à jour de lancement, d’installation et d’audit plus fiables.
Kit de backlinks créateur
Ajoutez les badges de preuve à votre README
Affichez la fiche canonique, les signaux actuels de confiance et d’audit, ainsi que de vraies preuves Agent-Proven là où les développeurs évaluent le dépôt.
[](https://www.openagentskill.com/skills/alirezarezvani-agent-decision-receipts)
[](https://www.openagentskill.com/skills/alirezarezvani-agent-decision-receipts)
[](https://www.openagentskill.com/skills/alirezarezvani-agent-decision-receipts/audit)
[](https://www.openagentskill.com/skills/alirezarezvani-agent-decision-receipts)Auteur
alirezarezvani
@alirezarezvani
Tags
Adéquation plateforme
Signaux de santé
- Stars GitHub
- 24.8K
- Score de qualité
- 54/100
- Dernier push GitHub
- 22 août 2026
- Indications de framework
- Inconnu
- Vues OpenAgentSkill
- 0
- Copies d’installation
- 0
- Clics sortants
- 0
Signal de communauté
Indiquez si ce skill semble utile à votre workflow Agent. Les retours agrégés améliorent le classement au fil du temps.
Confiance et sécurité
Sandbox uniquement
- Adoption GitHub25K stars GitHubValidé
- Activité stars/forks25K stars et 3.5K forks; l’activité des issues n’est pas disponible dans les métadonnées actuellesValidé
- Maintenance récenteMis à jour aujourd’huiValidé
- Clarté de licenceMITValidé
- Complétude README/SKILL.mdLes métadonnées incluent suffisamment de contexte d’usage et de workflowValidé
- Risque dépendances/runtimecommand execution surface, credential or environment accessCorriger
Skills associés
Last30days Skill
Research the last 30 days across Reddit, X, YouTube, Hacker News, Polymarket, GitHub, and the web, then synthesize a grounded brief for an AI agent.
53.5K StarsAcademic Research Skills
Academic Research Skills for Claude Code: research → write → review → revise → finalize
38.4K StarsGPT Researcher
Run autonomous deep research over web and local sources
28.0K StarsDeepResearch
Tongyi Deep Research, the Leading Open-source Deep Research Agent
19.8K Stars