agent-decision-receipts
Mint a tamper-evident, post-quantum-signed receipt for a consequential agent action (deploy, delete, pay, grant-access, model decision) so it can be verified later from the certificate alone. Use when an autonomous agent takes a side-effecting action that may need to be proven la
供給アセットの概要
リサーチとナレッジ作業
Deep research, source comparison, literature review, RAG, knowledge search, and reports.
シナリオ
リサーチ Agent
I need my agent to research a topic, compare sources, and produce a concise report.
Agent 適合
Claude Code + CLI + Codex
Codex、Claude Code、Cursor、CLI、またはカスタム Agent に対応します。
インストール
準備完了
npx skills add alirezarezvani/claude-skills --skill agent-decision-receipts
メンテナンス
新しい
本日プッシュ
リスク
要レビュー
Dependency or permission surface needs review
GitHub 品質
25K
91/100 品質 · 74/100 信頼
対象タグ
レビュー注記
Dependency or permission surface needs review · Permission surface may require sandboxing
Agent 導入スコアカード
信頼、監査、インストール準備状況を一目で確認
公開リポジトリのメタデータ、OpenAgentSkill のレビューシグナル、保守の鮮度、インストール準備状況を組み合わせたスコアです。候補選定の目安であり、人によるレビューの代替ではありません。
品質
優秀採用度と保守性のシグナルが強い高信頼候補です。
信頼
サンドボックス限定信頼シグナルが不足または混在する有用な候補です。結果ループがタスク適合を示すまで、隔離されたワークスペースで使用してください。
監査
要レビューインストール準備、安全メタデータ、保守、採用リスクの機械可読なレビュー。
OpenAgentSkill Trust Score v5
インストール前に人のレビュー
実作業で使う前に、サンドボックスでのみ実行し、近い代替と比較してください。
スター
GitHub スター 25K
リポジトリ活動
スター 25K、フォーク 3.5K
メンテナンス
本日プッシュ
ライセンス
MIT
インストール
npx skills add alirezarezvani/claude-skills --skill agent-decision-receipts
インストール安全性
標準パッケージまたはランタイムのインストールパス
権限範囲
secrets or environment access, shell or command execution
Agent の成果
Agent の成果データはまだありません
ドキュメント
README/SKILL.md の文脈が十分です
リスク概要
本番前にレビュー
- The skill relies on an external package (openagentontology) for cryptographic operations; while this is clearly documented, the package's security posture is not independently verified by this review.
- Financial research output is not financial advice; require human review before any live investment decision.
- Quality score needs review
- Permission surface needs review: secrets or environment access, shell or command execution
インストール準備状況
インストールパスを利用可能
- インストールパスを利用できます
- リポジトリの根拠を利用できます
- ライセンスが明示されています
- Agent-Proven の成果エビデンスはまだありません
Agent 可読メタデータ
このスキルの機械可読な判断データ。
このブロックまたは埋め込み JSON を使い、Agent がこのスキルをインストールすべきか、代替を選ぶべきか、先に人のレビューを求めるべきかを判断できます。
適したタスク
- リサーチ Agent ワークフロー
- Claude Code チーム
- GitHub 採用シグナルを重視するチーム
- 検索ソース
適した Agent
インストール判断
- コマンド
- npx skills add alirezarezvani/claude-skills --skill agent-decision-receipts
- ポリシー
- レビュー
- 人によるレビュー
- はい
信頼とリスク
- 信頼
- 66/100
- 監査
- 83/100
- リスクレベル
- 要レビュー
成果ループ
- エンドポイント
- /api/agent/outcome
- イベント ID
- resolve
- 成果
- 5
インストールコマンド
npx skills add alirezarezvani/claude-skills --skill agent-decision-receipts使わない場合
- ベンダー提供の SLA が必要なチーム
- production agents without a repository review
- The skill relies on an external package (openagentontology) for cryptographic operations; while this is clearly documented, the package's security posture is not independently verified by this review.
- OpenAgentSkill の利用フィードバックはまだありません
- 高リスク権限のヒント: Shell or command execution, Secrets or environment access
Agent セーフティ v2
39/100 · 自動インストールを避ける
Sparse or mixed signals. Useful for discovery, but not for autonomous installation.
Test manually in an isolated workspace and compare against safer alternatives.
高
Shell またはコマンド実行
Skill メタデータに端末、CLI、Shell、サブプロセス、またはコマンド実行のワークフローが含まれます。
中
ネットワークアクセス
Skill はリモートページ、API、リポジトリ、外部サービスにアクセスする可能性があります。
中
ファイルシステムアクセス
Skill はプロジェクトファイル、ドキュメント、生成物、ローカルワークスペース状態を読み書きする可能性があります。
高
Secrets or environment access
Skill metadata references credentials, tokens, environment variables, or secret-bearing workflows.
- 高リスク権限のヒント: Shell or command execution, Secrets or environment access
- Dependency or permission surface needs review
インストール先
Agent ワークフローにこのスキルをインストール
公開インストールエンドポイントからコマンド、安全チェックリスト、対象プロンプト、正規リンクを取得します。
OpenAgentSkill CLI
Resolve policy, run the source installer safely, and report a verified install receipt.
$ npx --yes https://github.com/Leon-Drq/openagentskill/releases/download/cli-v0.2.1/openagentskill-0.2.1.tgz install alirezarezvani-agent-decision-receiptsAgent 解決プラン
インストール前に Agent に適合性を検証させます。
Resolve API は第一候補、代替、安全ポリシー、監査メモ、インストール先、Agent がそのまま使えるプロンプトを返します。
JSON を開く
/api/agent/resolve?task=Use%20agent-decision-receipts%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve テキスト
/api/agent/resolve?task=Use%20agent-decision-receipts%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
インストール引き継ぎ
/api/skills/alirezarezvani-agent-decision-receipts/install
Agent が確認すべきこと
- Resolve API でタスク適合と代替を確認。
- 監査・信頼スコアと安全ポリシーの警告を確認。
- Codex、Claude Code、Cursor、CLI のインストール先互換性を確認。
プロンプトをコピー
Task: Use agent-decision-receipts in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20agent-decision-receipts%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/alirezarezvani-agent-decision-receipts/install
Install command: npx skills add alirezarezvani/claude-skills --skill agent-decision-receipts
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent 引き継ぎ
別のディレクトリではなく、インストール経路を Agent に渡します。
公開インストールエンドポイントからコマンド、安全チェックリスト、対象プロンプト、正規リンクを取得します。
インストール引き継ぎ
/api/skills/alirezarezvani-agent-decision-receipts/install
LLM テキスト形式
/api/skills/alirezarezvani-agent-decision-receipts/install?format=text
代替を探す
/api/skills/search?q=agent-decision-receipts&limit=3
Agent プロンプト
Use agent-decision-receipts for this task. Review https://www.openagentskill.com/api/skills/alirezarezvani-agent-decision-receipts/install, then install with: npx skills add alirezarezvani/claude-skills --skill agent-decision-receiptsRegistry メタデータ
自動スキル選択用の Agent 可読プロファイル。
Registry API 経由で判断、信頼、監査、ユースケース、インストールのシグナルを提供し、UI をスクレイピングせずに Agent が順位付けできます。
Manifest
/api/registry/manifest/alirezarezvani-agent-decision-receipts
LLM テキスト
/api/registry/manifest/alirezarezvani-agent-decision-receipts?format=text
インストール別名
/api/registry/install/alirezarezvani-agent-decision-receipts
推奨
/api/registry/recommend?task=Use%20agent-decision-receipts%20in%20an%20agent%20workflow&limit=3
Agent 適合
リサーチ Agent
プラットフォーム
Claude Code
Agent 判断パネル
リサーチ Agent 向けの第一候補
有力候補として扱い、自分の Agent スタックで README とインストール経路を検証してください。
スタック内の役割
第一候補
主な適合
リサーチ Agent
信頼ラベル
本番対応
インストールパス
コマンド準備済み
使う場面
- リサーチ Agent ワークフロー
- Claude Code チーム
- GitHub 採用シグナルを重視するチーム
根拠
- GitHub スター 24,795
- 最近のリポジトリ活動
- インストールコマンドまたは GitHub リポジトリが利用可能
- 品質プロファイル 91/100
先にレビュー
- The skill relies on an external package (openagentontology) for cryptographic operations; while this is clearly documented, the package's security posture is not independently verified by this review.
- OpenAgentSkill の利用フィードバックはまだありません
実装パス
- 1サンドボックスの Agent にインストールし、リサーチ Agent タスクを一度最初から最後まで実行します。
- 2Compare output quality, latency, and failure behavior against at least one alternative.
- 3Promote it into production only after reviewing repository permissions, license, and maintenance signals.
信頼プロファイル
サンドボックス限定
信頼シグナルが不足または混在する有用な候補です。結果ループがタスク適合を示すまで、隔離されたワークスペースで使用してください。
GitHub 採用度
合格GitHub スター 25K
スター/フォーク活動
合格スター 25K、フォーク 3.5K; 現在のメタデータでは Issue 活動を利用できません
最近のメンテナンス
合格本日プッシュ
ライセンスの明確さ
合格MIT
良いシグナル
- AI レビュー承認済み
- インストールパスを利用できます
- リポジトリの根拠を利用できます
- 最近保守されたリポジトリ
- Large GitHub adoption signal
- インストールコマンドに明確な高リスクパターンはありません
- 成果ループは準備済みですが、最初の実行が必要です
インストール前にレビュー
- The skill relies on an external package (openagentontology) for cryptographic operations; while this is clearly documented, the package's security posture is not independently verified by this review.
- Financial research output is not financial advice; require human review before any live investment decision.
- Quality score needs review
- Permission surface needs review: secrets or environment access, shell or command execution
- Dependency/runtime risk: command execution surface, credential or environment access
- Permission surface: secrets or environment access, shell or command execution
- 実際の Agent 成果レポートはまだありません
- 無人インストールの前に人によるレビューが必要です
推奨アクション
実作業で使う前に、サンドボックスでのみ実行し、近い代替と比較してください。
品質プロファイル
優秀 Agent ワークフロー向けの候補
採用度と保守性のシグナルが強い高信頼候補です。
ワークフロー適合
このスキルを使うシナリオ
Investigate faster
Research agents
I need my agent to research a topic, compare sources, and produce a concise report.
Reduce risk
Security and compliance
I need my agent to scan a project for security risks and summarize what needs attention.
Manage repositories
GitHub automation
I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.
ワークフロー適合
完全なワークフローに追加
Find, compare, and synthesize
Research report agent
A workflow for agents that gather sources, compare claims, summarize long material, and draft useful research briefs.
Inspect, patch, and verify code
Coding review agent
A workflow for software agents that inspect repositories, review pull requests, generate tests, and turn findings into shippable patches.
Operate and verify web apps
Browser QA agent
A workflow for agents that navigate products, fill forms, take screenshots, and verify real user flows across web applications.
代替候補
インストール前に比較
このタスクに適する可能性のある類似スキル。
Last30days Skill
Research the last 30 days across Reddit, X, YouTube, Hacker News, Polymarket, GitHub, and the web, then synthesize a grounded brief for an AI agent.
Academic Research Skills
Academic Research Skills for Claude Code: research → write → review → revise → finalize
GPT Researcher
Run autonomous deep research over web and local sources
DeepResearch
Tongyi Deep Research, the Leading Open-source Deep Research Agent
概要
--- name: "agent-decision-receipts" description: "Mint a tamper-evident, post-quantum-signed receipt for a consequential agent action (deploy, delete, pay, grant-access, model decision) so it can be verified later from the certificate alone. Use when an autonomous agent takes a side-effecting action that may need to be proven later, or when satisfying EU AI Act Article 12 record-keeping. Three decisions: whether an action needs a receipt, minting it, verifying it. Signing is delegated to the open-source OpenAgentOntology package. Not after-the-fact log analysis; not a hosted notary; not a legal opinion." ---
# Agent Decision Receipts
## Overview
A log says an action happened. A **receipt is tamper-evident**: it records who, what, and under which policy, and it is signed, so any later edit breaks the signature. This skill mints one for a consequential agent action and verifies it later from the certificate alone: no database, no network, no trusting the issuer.
The crypto is not in this skill. It is the open-source **OpenAgentOntology** receipt primitive (Apache-2.0), which signs every receipt with Ed25519 **and** the post-quantum legs ML-DSA-65 (FIPS 204) + SLH-DSA (FIPS 205) when the post-quantum backend is installed. This skill is the decision layer: when to mint, what to put in, how to verify. One install, no per-skill crypto.
**Three decisions, nothing else:**
1. **Does this action need a receipt?** — side-effecting + consequential + later-provable = yes. 2. **Mint the receipt** — build the action manifest, sign it with the OAO primitive. 3. **Verify it** — recompute the hash, check each signature leg, from the cert alone.
This skill is **NOT log analysis.** Logs describe what happened and can be silently edited. A receipt is minted before/at execution and breaks if edited. Use logs for debugging; use receipts for evidence.
This skill is **NOT a hosted notary.** It mints a LOCAL, self-signed receipt anyone can verify offline. Cross-organization verification (one org proving to another) is a separate hosted service, out of scope here.
This skill is **NOT a legal opinion.** It produces evidence shaped to support FRE 902(13)/(14)-style certification and EU AI Act Article 12 record-keeping. Whether a given receipt is admitted is a question for counsel.
## Quick Start
```bash # Install the open-source receipt primitive (Apache-2.0). Add [pq] for the post-quantum legs. pip install "openagentontology[pq]"
# 1. Build + validate an action manifest (stdlib only, no crypto, no network) python scripts/build_action_manifest.py --agent my-deploy-agent --operation deploy \ --target prod/api --policy "EU AI Act Art 12" --out action.json
# 2. Mint the receipt over it (Ed25519 + post-quantum legs) python -c "import json,openagentontology.receipt as r; \ print(json.dumps(r.mint_receipt(json.load(open('action.json')), decision='ACTION_GOVERNED')))" > receipt.json
# 3. Verify from the cert alone (no DB, no network) python -c "import json,openagentontology.receipt as r; \ print(r.verify_receipt(json.load(open('receipt.json'))))" # -> {'ok': True, 'sig_ok': True, ... 'reason': 'verified from the cert alone via: ed25519, ml_dsa, slh_dsa'} ```
> **Dependency note.** This skill delegates the signing to `openagentontology` (Apache-2.0, opt-in `pip install`). The script shipped here is stdlib-only and adds no repo dependency; the package is installed by the operator (BYO-library pattern). If it is not installed, the build step still works — only minting/verifying require it.
## Core Workflow
The three decisions below are the skill: decide whether to receipt, mint, then verify.
## Decision 1: Does this action need a receipt?
Mint a receipt when the action is **all three** of:
| Test | Mint if... | |------|-----------| | Side-effecting | it writes, sends, deploys, deletes, pays, grants access, or changes external state | | Consequential | a wrong call costs money, breaks compliance, or harms a person | | Later-provable | someone (auditor, insurer, regulator, court, counterparty) may ask "what did the agent do and why?" |
Read-only, reversible, trivial actions do **not** need a receipt. Receipt everything and the signal drowns; receipt nothing and the one call that mattered cannot be proven.
High-signal triggers (mint by default): `deploy`, `delete`, `pay`/`wire`/`refund`, `grant_access`, `export`/`egress`, `approve`/`deny` a claim, any model decision that affects a person under a high-risk AI system.
## Decision 2: Mint the receipt
The action manifest is any ASCII-safe dict describing what the agent did. Four keys are **required** — `build_action_manifest.py` rejects the manifest (exit 2) if any is missing. Two more are added automatically:
| Key | Required? | What it carries | |-----|-----------|-----------------| | `agent_id` | **required** | the acting agent | | `operation` | **required** | the verb (deploy / delete / pay / decide / ...) | | `target` | **required** | what it acted on | | `policy` | **required** | the rule that governs it (e.g. "EU AI Act Art 12", "internal change-control") | | `inputs_hash` | auto-added | a hash of `--inputs`, so the full payload need not be stored in the clear (defaults to the hash of empty when `--inputs` is omitted) | | `decision_label` | auto-added | the receipt decision label (defaults to `ACTION_GOVERNED`) |
`mint_receipt(manifest, decision=...)` hashes the full manifest into the receipt evidence, signs the canonical body, and returns a receipt that carries: `evidence_hash`, `signature_b64` (Ed25519), and — when `[pq]` is installed — `ml_dsa_signature_b64` + `slh_dsa_signature_b64`. Each leg signs the same bytes; any one verifying proves authenticity.
> See [references/receipt-fields.md](references/receipt-fields.md) for the full receipt schema and the post-quantum rationale.
## Decision 3: Verify it
`verify_receipt(receipt)` recomputes `sha256(canonical(evidence))`, compares it to `evidence_hash`, then checks every signature leg it has a backend for. It returns `{ok, hash_ok, sig_ok, legs, reason}`. A single edited byte anywhere in the action breaks `hash_ok`; a forged signature breaks the leg. Verification needs only the receipt — no call back to the issuer.
This is the property that makes it evidence: a reviewer who distrusts the issuer can still confirm the receipt is intact and authentic, entirely offline.
## Anti-Patterns
- **Receipt the log, not the decision.** Minting a receipt over a log line written after the fact proves nothing. Mint at the point of action, over the action. - **Storing the signing key next to the receipts.** If the key is compromised, signatures mean nothing. Treat the key like any signing secret; never commit it. - **Ed25519-only when the post-quantum legs are available.** A receipt is long-lived evidence. Sign it once with the post-quantum legs (ML-DSA-65 + SLH-DSA) so it stays verifiable if a future quantum computer could break Ed25519. Install `[pq]`. - **Putting raw secrets or PII in the manifest.** The manifest is hashed into evidence and is recoverable from the receipt. Carry hashes (`inputs_hash`), not the cleartext. - **Calling it "admissible."** It is evidence shaped to *support* FRE 902(13)/(14)-style certification. Admissibility is a court's decision, not the tool's claim. - **Faking a signature when crypto is missing.** The primitive emits an explicit `unsigned` flag instead. Never present an unsigned receipt as signed.
## Cross-References
- `ra-qm-team/skills/eu-ai-act-specialist/` — decide the AI system's risk tier and Article 12 obligations; this skill mints the per-action record those obligations require. - `ra-qm-team/skills/iso42001-specialist/` — the AI management-system controls; receipts are the per-decision evidence those controls call for. - OpenAgentOntology (Apache-2.0): the open receipt primitive this skill drives — `pip install "openagentontology[pq]"`.
技術詳細
- バージョン
- 1.0.0
- ライセンス
- MIT
- 最終更新
- 2026年8月22日
- 公開日
- 2026年8月22日
判断の要約
第一候補
GitHub スター 24,795
Agent 実証エビデンス
Agent 実証エビデンス
Resolve、レビュー、インストール、限定実行後の成果レポート。
- 成功率
- —
- 直近の失敗
- —
- 成果
- 0
- 出力品質
- —
- 失敗
- 0
- 非該当
- 0
- インストール数
- 0
- リスクによりブロック
- 0
- 設定が必要
- 0
- 本番
- 0
Agent の実行結果はまだありません。最初の実行では /api/agent/outcome を通じて成功、設定要件、リスクによるブロック、失敗、非該当を報告できます。
成長ループ
共有キット
agent-decision-receipts 用のシナリオベース草案です。X へ手動投稿できます。
agent-decision-receipts: Mint a tamper-evident, post-quantum-signed receipt for a consequential agent action (deploy,... 24.8K stars https://www.openagentskill.com/skills/alirezarezvani-agent-decision-receipts?ref=x
任意:インストールコマンド付きの返信
Listing + install path for agent-decision-receipts: https://www.openagentskill.com/skills/alirezarezvani-agent-decision-receipts?ref=x Install: npx skills add alirezarezvani/claude-skills --skill agent-decision-receipts
掲載元
Registry により登録
この掲載は公開ソースから登録されており、メンテナー申請が承認されるまで公式として表示されません。
- インデックス作成者
- OpenAgentSkill コミュニティインデックス
帰属は公開リポジトリまたは作成者プロフィールにリンクされています。作成者は掲載を申請して所有権シグナルを更新できます。
このスキルを申請所有者の申請
このスキル掲載を申請
この Registry により登録 掲載は alirezarezvani に帰属していますが、まだ公式として表示されていません。申請すると、確認済み所有者シグナルが追加され、今後の公開、インストール、監査更新の信頼性が高まります。
クリエイター被リンクキット
README にエビデンスバッジを追加
開発者がリポジトリを評価する場所で、正規掲載、現在の信頼・監査シグナル、実際の Agent-Proven エビデンスを表示します。
[](https://www.openagentskill.com/skills/alirezarezvani-agent-decision-receipts)
[](https://www.openagentskill.com/skills/alirezarezvani-agent-decision-receipts)
[](https://www.openagentskill.com/skills/alirezarezvani-agent-decision-receipts/audit)
[](https://www.openagentskill.com/skills/alirezarezvani-agent-decision-receipts)作者
alirezarezvani
@alirezarezvani
プラットフォーム適合
健全性シグナル
- GitHub スター
- 24.8K
- 品質スコア
- 54/100
- 最終 GitHub プッシュ
- 2026年8月22日
- フレームワークのヒント
- 不明
- OpenAgentSkill 閲覧数
- 0
- インストールコピー数
- 0
- 外部クリック
- 0
コミュニティシグナル
このスキルが Agent ワークフローに役立つかを共有してください。集約されたフィードバックがランキングを改善します。
信頼と安全性
サンドボックス限定
- GitHub 採用度GitHub スター 25K合格
- スター/フォーク活動スター 25K、フォーク 3.5K; 現在のメタデータでは Issue 活動を利用できません合格
- 最近のメンテナンス本日プッシュ合格
- ライセンスの明確さMIT合格
- README/SKILL.md の完全性メタデータには十分な利用・ワークフロー文脈があります合格
- 依存関係/ランタイムのリスクcommand execution surface, credential or environment access修正
関連スキル
Last30days Skill
Research the last 30 days across Reddit, X, YouTube, Hacker News, Polymarket, GitHub, and the web, then synthesize a grounded brief for an AI agent.
53.5K スターAcademic Research Skills
Academic Research Skills for Claude Code: research → write → review → revise → finalize
38.4K スターGPT Researcher
Run autonomous deep research over web and local sources
28.0K スターDeepResearch
Tongyi Deep Research, the Leading Open-source Deep Research Agent
19.8K スター