agent-decision-receipts

Revoir · 66
Indexé dans Registry

Mint a tamper-evident, post-quantum-signed receipt for a consequential agent action (deploy, delete, pay, grant-access, model decision) so it can be verified later from the certificate alone. Use when an autonomous agent takes a side-effecting action that may need to be proven la

Verified installs0
Stars24.8K
Version1.0.0
Qualité91/100 · Excellent
Confiance66/100 · Sandbox uniquement
Audit83/100 · Revue nécessaire

Profil de l’actif

Recherche et travail de connaissance

Deep research, source comparison, literature review, RAG, knowledge search, and reports.

Voir la catégorie

Scénario

Agents de recherche

I need my agent to research a topic, compare sources, and produce a concise report.

Adéquation Agent

Claude Code + CLI + Codex

Compatible avec Codex, Claude Code, Cursor, CLI ou des Agents personnalisés.

Installer

Prêt

npx skills add alirezarezvani/claude-skills --skill agent-decision-receipts

Maintenance

À jour

Mis à jour aujourd’hui

Risque

Revue nécessaire

Dependency or permission surface needs review

Qualité GitHub

25K

91/100 Qualité · 74/100 Confiance

Tags de couverture

RechercheAgents de rechercheagent-skill

Notes de revue

Dependency or permission surface needs review · Permission surface may require sandboxing

Carte d’adoption Agent

Confiance, audit et préparation à l’installation en un coup d’œil

Ces scores combinent les métadonnées publiques du dépôt, les signaux de revue OpenAgentSkill, la fraîcheur de maintenance et la préparation à l’installation. Ils servent à présélectionner et ne remplacent pas la revue humaine.

Qualité

Excellent
91

High-confidence pick with strong adoption and healthy maintenance signals.

Confiance

Sandbox uniquement
66

Candidate utile avec des signaux de confiance incomplets ou mixtes. Gardez-la dans un espace isolé jusqu’à ce que la boucle de résultats confirme son adéquation.

Audit

Revue nécessaire
83

Revue lisible par machine de la préparation à l’installation, des métadonnées de sécurité, de la maintenance et du risque d’adoption.

Trust Score OpenAgentSkill v5

Revue humaine avant installation

Exécutez uniquement dans un sandbox et comparez les alternatives proches avant usage réel.

CodexClaude CodeCursorOpenAgentSkill CLI

Stars

25K stars GitHub

Activité du dépôt

25K stars et 3.5K forks

Maintenance

Mis à jour aujourd’hui

Licence

MIT

Installer

npx skills add alirezarezvani/claude-skills --skill agent-decision-receipts

Sécurité d’installation

Chemin d’installation standard de package ou runtime

Surface de permissions

secrets or environment access, shell or command execution

Résultats Agent

Pas encore de données de résultats Agent

Documentation

Contexte README/SKILL.md solide

Résumé des risques

Revoir avant production

  • The skill relies on an external package (openagentontology) for cryptographic operations; while this is clearly documented, the package's security posture is not independently verified by this review.
  • Financial research output is not financial advice; require human review before any live investment decision.
  • Quality score needs review
  • Permission surface needs review: secrets or environment access, shell or command execution

Préparation à l’installation

Chemin d’installation disponible

  • Le chemin d’installation est disponible
  • La preuve du dépôt est disponible
  • La licence est déclarée
  • Pas encore de preuve de résultat Agent-Proven

Métadonnées lisibles par Agent

Données de décision lisibles par machine pour ce skill.

Utilisez ce bloc ou le JSON intégré pour décider si un Agent doit installer ce skill, choisir une alternative ou demander d’abord une revue humaine.

Ouvrir JSON

Tâches adaptées

  • Workflows d’Agents de recherche
  • Équipes Claude Code
  • Équipes qui valorisent les signaux d’adoption GitHub
  • Sources de recherche

Agents adaptés

CodexClaude CodeCursorOpenAgentSkill CLICLI

Décision d’installation

Commande
npx skills add alirezarezvani/claude-skills --skill agent-decision-receipts
Politique
Revoir
Revue humaine
Oui

Confiance et risque

Confiance
66/100
Audit
83/100
Niveau de risque
Revue nécessaire

Boucle de résultat

Endpoint
/api/agent/outcome
ID d’événement
resolve
Résultats
5

Commande d’installation

npx skills add alirezarezvani/claude-skills --skill agent-decision-receipts

Ne pas utiliser quand

  • Équipes qui nécessitent un SLA soutenu par le fournisseur
  • production agents without a repository review
  • The skill relies on an external package (openagentontology) for cryptographic operations; while this is clearly documented, the package's security posture is not independently verified by this review.
  • No OpenAgentSkill engagement data yet
  • Indices de permissions à haut risque : Shell or command execution, Secrets or environment access

Sécurité Agent v2

39/100 · Éviter l’installation automatique

ExpérimentalRevoir

Sparse or mixed signals. Useful for discovery, but not for autonomous installation.

Test manually in an isolated workspace and compare against safer alternatives.

Résoudre via API

Élevé

Exécution shell ou de commande

Les métadonnées de la skill font référence à des workflows de terminal, CLI, shell, sous-processus ou exécution de commande.

Moyen

Accès réseau

La skill récupère probablement des pages distantes, API, dépôts ou services externes.

Moyen

Accès au système de fichiers

La skill peut lire ou écrire des fichiers de projet, documents, artefacts générés ou l’état local de l’espace de travail.

Élevé

Secrets or environment access

Skill metadata references credentials, tokens, environment variables, or secret-bearing workflows.

  • Indices de permissions à haut risque : Shell or command execution, Secrets or environment access
  • Dependency or permission surface needs review

Cibles d’installation

Installer ce skill dans votre workflow Agent

Utilisez le point de terminaison public pour récupérer la commande, la checklist, les prompts et les liens canoniques.

skill install

OpenAgentSkill CLI

Resolve policy, run the source installer safely, and report a verified install receipt.

$ npx --yes https://github.com/Leon-Drq/openagentskill/releases/download/cli-v0.2.1/openagentskill-0.2.1.tgz install alirezarezvani-agent-decision-receipts

Plan de résolution Agent

Laissez un Agent vérifier la pertinence avant l’installation.

L’API Resolve renvoie la skill sélectionnée, des alternatives, la politique de sécurité, les notes d’audit, la cible d’installation et un prompt prêt à l’emploi.

Ouvrir le plan texte

L’Agent doit vérifier

  • Task fit and alternatives from Resolve API.
  • Audit score, trust score, and safety policy warnings.
  • Install target compatibility for Codex, Claude Code, Cursor, or CLI.

Copier le prompt

Task: Use agent-decision-receipts in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20agent-decision-receipts%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/alirezarezvani-agent-decision-receipts/install
Install command: npx skills add alirezarezvani/claude-skills --skill agent-decision-receipts
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.

Relais Agent

Donnez à l’Agent le chemin d’installation, pas un autre annuaire.

Utilisez le point de terminaison public pour récupérer la commande, la checklist, les prompts et les liens canoniques.

Ouvrir l’API d’installation

Prompt Agent

Use agent-decision-receipts for this task. Review https://www.openagentskill.com/api/skills/alirezarezvani-agent-decision-receipts/install, then install with: npx skills add alirezarezvani/claude-skills --skill agent-decision-receipts

Métadonnées Registry

Profil lisible par Agent pour la sélection automatique de skills.

L’API Registry fournit les signaux de décision, confiance, audit, cas d’usage et installation sans analyser l’interface.

Ouvrir Manifest

Adéquation Agent

100/100

Agents de recherche

Plateformes

Claude Code

Rapport d’audit

Revue nécessaire · 83/100

Revue lisible par machine de la préparation à l’installation, des métadonnées de sécurité, de la maintenance et du risque d’adoption.

Voir le rapport d’auditVoir le rapport d’évaluation

Panneau de décision Agent

Choix principal pour Agents de recherche

Use this as a leading candidate, then validate the README and install path in your own agent stack.

100
Préparation
Adopter
Étape

Rôle dans la pile

Choix principal

Pertinence principale

Agents de recherche

Libellé de confiance

Prêt pour la production

Chemin d’installation

Commande prête

À utiliser lorsque

  • Workflows d’Agents de recherche
  • Équipes Claude Code
  • Équipes qui valorisent les signaux d’adoption GitHub

Preuves

  • 24,795 stars GitHub
  • recent repository activity
  • install command or GitHub repo available
  • profil qualité 91/100

revoir d’abord

  • The skill relies on an external package (openagentontology) for cryptographic operations; while this is clearly documented, the package's security posture is not independently verified by this review.
  • No OpenAgentSkill engagement data yet

Chemin d’implémentation

  1. 1Installez-le dans un Agent en sandbox et exécutez une tâche de Agents de recherche de bout en bout.
  2. 2Compare output quality, latency, and failure behavior against at least one alternative.
  3. 3Promote it into production only after reviewing repository permissions, license, and maintenance signals.

Profil de confiance

Sandbox uniquement

Candidate utile avec des signaux de confiance incomplets ou mixtes. Gardez-la dans un espace isolé jusqu’à ce que la boucle de résultats confirme son adéquation.

66
Trust Score OpenAgentSkill

Adoption GitHub

Validé

25K stars GitHub

Activité stars/forks

Validé

25K stars et 3.5K forks; l’activité des issues n’est pas disponible dans les métadonnées actuelles

Maintenance récente

Validé

Mis à jour aujourd’hui

Clarté de licence

Validé

MIT

Signaux positifs

  • Revue IA approuvée
  • Le chemin d’installation est disponible
  • La preuve du dépôt est disponible
  • Dépôt maintenu récemment
  • Large GitHub adoption signal
  • La commande d’installation ne présente aucun motif de haut risque évident
  • La boucle de résultats est prête mais nécessite la première exécution réelle de l’Agent

Réviser avant installation

  • The skill relies on an external package (openagentontology) for cryptographic operations; while this is clearly documented, the package's security posture is not independently verified by this review.
  • Financial research output is not financial advice; require human review before any live investment decision.
  • Quality score needs review
  • Permission surface needs review: secrets or environment access, shell or command execution
  • Dependency/runtime risk: command execution surface, credential or environment access
  • Permission surface: secrets or environment access, shell or command execution
  • Pas encore de rapports de résultats Agent réels
  • Une revue humaine est requise avant une installation sans surveillance

Action recommandée

Exécutez uniquement dans un sandbox et comparez les alternatives proches avant usage réel.

Profil qualité

Excellent candidat pour les workflows Agent

High-confidence pick with strong adoption and healthy maintenance signals.

91
Stars GitHub
25K
Actualité
Aujourd’hui
Prêt à installer
Oui
Licence
MIT
Réviser avant installation: The skill relies on an external package (openagentontology) for cryptographic operations; while this is clearly documented, the package's security posture is not independently verified by this review.

Adéquation au workflow

Utilisez cette skill dans ces scénarios

Adéquation au workflow

Ajouter à un workflow complet

Liste d’alternatives

Comparer avant installation

Similar skills that may fit this task.

Tout comparer

Vue d’ensemble

--- name: "agent-decision-receipts" description: "Mint a tamper-evident, post-quantum-signed receipt for a consequential agent action (deploy, delete, pay, grant-access, model decision) so it can be verified later from the certificate alone. Use when an autonomous agent takes a side-effecting action that may need to be proven later, or when satisfying EU AI Act Article 12 record-keeping. Three decisions: whether an action needs a receipt, minting it, verifying it. Signing is delegated to the open-source OpenAgentOntology package. Not after-the-fact log analysis; not a hosted notary; not a legal opinion." ---

# Agent Decision Receipts

## Overview

A log says an action happened. A **receipt is tamper-evident**: it records who, what, and under which policy, and it is signed, so any later edit breaks the signature. This skill mints one for a consequential agent action and verifies it later from the certificate alone: no database, no network, no trusting the issuer.

The crypto is not in this skill. It is the open-source **OpenAgentOntology** receipt primitive (Apache-2.0), which signs every receipt with Ed25519 **and** the post-quantum legs ML-DSA-65 (FIPS 204) + SLH-DSA (FIPS 205) when the post-quantum backend is installed. This skill is the decision layer: when to mint, what to put in, how to verify. One install, no per-skill crypto.

**Three decisions, nothing else:**

1. **Does this action need a receipt?** — side-effecting + consequential + later-provable = yes. 2. **Mint the receipt** — build the action manifest, sign it with the OAO primitive. 3. **Verify it** — recompute the hash, check each signature leg, from the cert alone.

This skill is **NOT log analysis.** Logs describe what happened and can be silently edited. A receipt is minted before/at execution and breaks if edited. Use logs for debugging; use receipts for evidence.

This skill is **NOT a hosted notary.** It mints a LOCAL, self-signed receipt anyone can verify offline. Cross-organization verification (one org proving to another) is a separate hosted service, out of scope here.

This skill is **NOT a legal opinion.** It produces evidence shaped to support FRE 902(13)/(14)-style certification and EU AI Act Article 12 record-keeping. Whether a given receipt is admitted is a question for counsel.

## Quick Start

```bash # Install the open-source receipt primitive (Apache-2.0). Add [pq] for the post-quantum legs. pip install "openagentontology[pq]"

# 1. Build + validate an action manifest (stdlib only, no crypto, no network) python scripts/build_action_manifest.py --agent my-deploy-agent --operation deploy \ --target prod/api --policy "EU AI Act Art 12" --out action.json

# 2. Mint the receipt over it (Ed25519 + post-quantum legs) python -c "import json,openagentontology.receipt as r; \ print(json.dumps(r.mint_receipt(json.load(open('action.json')), decision='ACTION_GOVERNED')))" > receipt.json

# 3. Verify from the cert alone (no DB, no network) python -c "import json,openagentontology.receipt as r; \ print(r.verify_receipt(json.load(open('receipt.json'))))" # -> {'ok': True, 'sig_ok': True, ... 'reason': 'verified from the cert alone via: ed25519, ml_dsa, slh_dsa'} ```

> **Dependency note.** This skill delegates the signing to `openagentontology` (Apache-2.0, opt-in `pip install`). The script shipped here is stdlib-only and adds no repo dependency; the package is installed by the operator (BYO-library pattern). If it is not installed, the build step still works — only minting/verifying require it.

## Core Workflow

The three decisions below are the skill: decide whether to receipt, mint, then verify.

## Decision 1: Does this action need a receipt?

Mint a receipt when the action is **all three** of:

| Test | Mint if... | |------|-----------| | Side-effecting | it writes, sends, deploys, deletes, pays, grants access, or changes external state | | Consequential | a wrong call costs money, breaks compliance, or harms a person | | Later-provable | someone (auditor, insurer, regulator, court, counterparty) may ask "what did the agent do and why?" |

Read-only, reversible, trivial actions do **not** need a receipt. Receipt everything and the signal drowns; receipt nothing and the one call that mattered cannot be proven.

High-signal triggers (mint by default): `deploy`, `delete`, `pay`/`wire`/`refund`, `grant_access`, `export`/`egress`, `approve`/`deny` a claim, any model decision that affects a person under a high-risk AI system.

## Decision 2: Mint the receipt

The action manifest is any ASCII-safe dict describing what the agent did. Four keys are **required** — `build_action_manifest.py` rejects the manifest (exit 2) if any is missing. Two more are added automatically:

| Key | Required? | What it carries | |-----|-----------|-----------------| | `agent_id` | **required** | the acting agent | | `operation` | **required** | the verb (deploy / delete / pay / decide / ...) | | `target` | **required** | what it acted on | | `policy` | **required** | the rule that governs it (e.g. "EU AI Act Art 12", "internal change-control") | | `inputs_hash` | auto-added | a hash of `--inputs`, so the full payload need not be stored in the clear (defaults to the hash of empty when `--inputs` is omitted) | | `decision_label` | auto-added | the receipt decision label (defaults to `ACTION_GOVERNED`) |

`mint_receipt(manifest, decision=...)` hashes the full manifest into the receipt evidence, signs the canonical body, and returns a receipt that carries: `evidence_hash`, `signature_b64` (Ed25519), and — when `[pq]` is installed — `ml_dsa_signature_b64` + `slh_dsa_signature_b64`. Each leg signs the same bytes; any one verifying proves authenticity.

> See [references/receipt-fields.md](references/receipt-fields.md) for the full receipt schema and the post-quantum rationale.

## Decision 3: Verify it

`verify_receipt(receipt)` recomputes `sha256(canonical(evidence))`, compares it to `evidence_hash`, then checks every signature leg it has a backend for. It returns `{ok, hash_ok, sig_ok, legs, reason}`. A single edited byte anywhere in the action breaks `hash_ok`; a forged signature breaks the leg. Verification needs only the receipt — no call back to the issuer.

This is the property that makes it evidence: a reviewer who distrusts the issuer can still confirm the receipt is intact and authentic, entirely offline.

## Anti-Patterns

- **Receipt the log, not the decision.** Minting a receipt over a log line written after the fact proves nothing. Mint at the point of action, over the action. - **Storing the signing key next to the receipts.** If the key is compromised, signatures mean nothing. Treat the key like any signing secret; never commit it. - **Ed25519-only when the post-quantum legs are available.** A receipt is long-lived evidence. Sign it once with the post-quantum legs (ML-DSA-65 + SLH-DSA) so it stays verifiable if a future quantum computer could break Ed25519. Install `[pq]`. - **Putting raw secrets or PII in the manifest.** The manifest is hashed into evidence and is recoverable from the receipt. Carry hashes (`inputs_hash`), not the cleartext. - **Calling it "admissible."** It is evidence shaped to *support* FRE 902(13)/(14)-style certification. Admissibility is a court's decision, not the tool's claim. - **Faking a signature when crypto is missing.** The primitive emits an explicit `unsigned` flag instead. Never present an unsigned receipt as signed.

## Cross-References

- `ra-qm-team/skills/eu-ai-act-specialist/` — decide the AI system's risk tier and Article 12 obligations; this skill mints the per-action record those obligations require. - `ra-qm-team/skills/iso42001-specialist/` — the AI management-system controls; receipts are the per-decision evidence those controls call for. - OpenAgentOntology (Apache-2.0): the open receipt primitive this skill drives — `pip install "openagentontology[pq]"`.

Détails techniques

Version
1.0.0
Licence
MIT
Dernière mise à jour
22 août 2026
Publié
22 août 2026

Instantané de décision

Choix principal

100
Prêt
Adopter
Étape

24,795 stars GitHub

Audit

Revue d’installation

Revue d’installation et d’adoption

83
Revue nécessaire
Sécurité
69/100
Maintenance
100/100
Installer
92/100
Ouvrir l’audit completVoir le rapport d’évaluation

Preuves validées par Agent

Preuves validées par Agent

Rapports après resolve, revue, installation et une exécution limitée.

0
Validé
Needs first agent runAuto-installation: revoir d’abordDernier: Inconnu
Taux de réussite
Échec récent
Résultats
0
Qualité de sortie
Échecs
0
Non pertinent
0
Installations
0
Bloqué par le risque
0
Configuration requise
0
Production
0

Aucune donnée de résultat Agent pour l’instant. La première exécution peut signaler succès, besoin de configuration, blocage de risque, échec ou non-pertinence via /api/agent/outcome.

Installer

Ajouter au workflow Agent

Gratuit et open source. Examinez le rapport avant l’installation dans des Agents de production.

Boucle de croissance

Kit de partage

X

Brouillon guidé par scénario pour agent-decision-receipts, prêt pour une publication manuelle sur X.

Note du curateur
agent-decision-receipts: Mint a tamper-evident, post-quantum-signed receipt for a consequential agent action (deploy,...

24.8K stars

https://www.openagentskill.com/skills/alirezarezvani-agent-decision-receipts?ref=x
Ouvrir le brouillon X
Réponse facultative avec commande d’installation
Listing + install path for agent-decision-receipts:
https://www.openagentskill.com/skills/alirezarezvani-agent-decision-receipts?ref=x

Install: npx skills add alirezarezvani/claude-skills --skill agent-decision-receipts

Source de la fiche

Indexé par Registry

Revendiable

Cette fiche a été indexée à partir de sources publiques et n’est pas marquée officielle tant qu’une revendication de mainteneur n’est pas approuvée.

Indexé par
Index communautaire OpenAgentSkill

L’attribution renvoie au dépôt public ou au profil du créateur. Les créateurs peuvent revendiquer la fiche pour mettre à jour les signaux de propriété.

Revendiquer ce skill

Revendication du propriétaire

Revendiquer cette fiche de skill

Cette fiche Indexé par Registry est attribuée à alirezarezvani, mais n’est pas encore marquée officielle. Revendiquez-la pour ajouter un signal de propriétaire vérifié et rendre les futures mises à jour de lancement, d’installation et d’audit plus fiables.

Kit de backlinks créateur

Ajoutez les badges de preuve à votre README

Affichez la fiche canonique, les signaux actuels de confiance et d’audit, ainsi que de vraies preuves Agent-Proven là où les développeurs évaluent le dépôt.

[![Listed on OpenAgentSkill](https://www.openagentskill.com/api/badge/alirezarezvani-agent-decision-receipts?metric=listed&label=Listed)](https://www.openagentskill.com/skills/alirezarezvani-agent-decision-receipts)
[![OpenAgentSkill Trust](https://www.openagentskill.com/api/badge/alirezarezvani-agent-decision-receipts?metric=trust&label=Trust)](https://www.openagentskill.com/skills/alirezarezvani-agent-decision-receipts)
[![OpenAgentSkill Audit](https://www.openagentskill.com/api/badge/alirezarezvani-agent-decision-receipts?metric=audit&label=Audit)](https://www.openagentskill.com/skills/alirezarezvani-agent-decision-receipts/audit)
[![Agent Proven](https://www.openagentskill.com/api/badge/alirezarezvani-agent-decision-receipts?metric=proven&label=Agent%20Proven)](https://www.openagentskill.com/skills/alirezarezvani-agent-decision-receipts)

Auteur

A

alirezarezvani

@alirezarezvani

Adéquation plateforme

Signaux de santé

Stars GitHub
24.8K
Score de qualité
54/100
Dernier push GitHub
22 août 2026
Indications de framework
Inconnu
Vues OpenAgentSkill
0
Copies d’installation
0
Clics sortants
0

Signal de communauté

Indiquez si ce skill semble utile à votre workflow Agent. Les retours agrégés améliorent le classement au fil du temps.

Confiance et sécurité

Sandbox uniquement

66
  • Adoption GitHub25K stars GitHubValidé
  • Activité stars/forks25K stars et 3.5K forks; l’activité des issues n’est pas disponible dans les métadonnées actuellesValidé
  • Maintenance récenteMis à jour aujourd’huiValidé
  • Clarté de licenceMITValidé
  • Complétude README/SKILL.mdLes métadonnées incluent suffisamment de contexte d’usage et de workflowValidé
  • Risque dépendances/runtimecommand execution surface, credential or environment accessCorriger