← Plugin catalog
Developer Tools

AgentProof

Miguel Herrero Burgos v0.1.0

Publisher description

From the marketplace listing

Starts a new instrumented Codex CLI session and leaves a local, hash-only receipt of command events and checked repository states. Later, AgentProof validates the receipt and compares its recorded final file commitments with the current repository. The child runs non-interactively with Codex approvals disabled and retains the selected read-only or workspace-write sandbox. It does not capture the current Codex conversation or establish completeness, truth, authorship, work quality, compliance, payment authorization or settlement, and it uses no HREVN service or credential.

Language: English · Automatically detected from descriptions.

Files & skills

File archives

Plugin package16 files · 28.3 KBBrowse files →
Skill instructions
agentproof4.88 KB

View saved version →

---
name: agentproof
description: Capture a new instrumented Codex CLI session into a canonical hash-only AgentProof receipt, or verify a receipt and its recorded repository commitments locally. Use when the user asks to create agent-execution evidence, verify an AgentProof receipt, or compare it with the current Git repository. Do not use to claim capture of the current Codex session, completeness, truth, authorship, work quality, compliance, payment authorization, settlement, signing, or anchoring.
---

# AgentProof

AgentProof starts a separate Codex CLI child process and records only hashes and typed
metadata from what its collector observes. It cannot capture the current Codex
conversation.

## Required boundary

- State before capture: `This starts a new instrumented Codex session; it does not capture the current session.`
- Treat a valid receipt as integrity and ordering evidence for observed events only.
- Never describe it as proof of completeness, truth, quality, safety, compliance,
  identity, payment authorization, or settlement.
- Never request, print, inspect, store, or place a credential in the request.
- Never add Sign, Anchor, payment, settlement, gateway, or model-API steps.
- Do not call an Anthropic or OpenAI model API. Capture invokes the installed Codex CLI
  using that CLI's existing authentication.
- Capture starts the child with Codex approval policy `never` because the child is
  non-interactive and cannot answer approval prompts. State this before execution.
  This does not widen its sandbox: it must retain the request's `read-only` or
  `workspace-write` sandbox.
- Capture needs the child CLI's network connection and nested sandbox. If the host
  sandbox blocks either, ask the user to approve the fixed launcher outside that
  outer sandbox. Never widen permissions silently. The child must still use the
  request's `read-only` or `workspace-write` sandbox.

## Resolve the runtime

Set `<skill-dir>` conceptually to the absolute directory containing this `SKILL.md`.
Use the script at `<skill-dir>/scripts/agentproof.py`. Do not copy it into the user's
workspace or modify it.

Read [request-contract.md](references/request-contract.md) and
[supported-repository-profile.md](references/supported-repository-profile.md) before
the first execution.

## Capture

1. Confirm the current working directory is the intended trusted Git repository.
2. Explain the new-session boundary using the exact sentence above.
3. Explain that the new child is non-interactive, uses Codex approval policy `never`,
   and retains the selected sandbox.
4. Create `.agentproof/request.json` with a structured write tool, never shell
   interpolation:

```json
{
  "action": "capture",
  "model": "<installed Codex model identifier>",
  "prompt": "<task for the new child session>",
  "sandbox": "workspace-write"
}
```

5. Run only:

```text
python3 -B <skill-dir>/scripts/agentproof.py --request .agentproof/request.json
```

6. If Codex requires approval to run that fixed command outside its outer sandbox,
   request it and explain that the nested child retains the requested sandbox.
7. Report the output path, event count, chain head and explicit gaps. Do not reproduce
   prompt or command content from the session.

The runtime removes the request after validating it and refuses to overwrite an
existing receipt. Never delete an existing receipt merely to make capture succeed;
ask the user how to preserve it.

## Verify

Create this exact request with a structured write tool:

```json
{"action":"verify"}
```

Use Verify for receipts produced by this strict plugin line. Do not promise that
historical Build Week prototype receipts are accepted.

Run the same fixed command. Report `MATCH` or `MISMATCH`, the receipt-chain status and
the explicit limits as separate fields. Never compress `MATCH` into `verified`,
`correct`, `authentic`, or an equivalent approval. A match does not establish who
produced the state or whether it is correct.

## Failure handling

- Preserve fail-closed errors; do not bypass path, symlink, schema, overwrite or
  repository checks.
- If Git is unavailable, or if `codex` is unavailable or unauthenticated, stop and
  report that capture was not performed.
- The runtime suppresses raw child stderr. On child failure it reports only a SHA-256
  commitment, byte count and line count; do not reconstruct or request the raw text.
- For `git_repository_required`, `run_from_git_repository_root`,
  `non_utf8_repository_path`, `repository_symlink_unsupported`,
  `snapshot_file_too_large`, `snapshot_total_too_large`,
  `repository_file_too_large` or `receipt_publish_failed`, stop and report the
  matching condition from the supported repository profile. Do not retry by
  weakening or bypassing that boundary.
- For `unexpected_runtime_error`, report only its exception type and traceback
  SHA-256 commitment. Never request, reconstruct or reproduce the raw traceback.
- Do not summarize a failed run as a valid receipt.

Referenced files: 8

Package details

Publisher declarations from the archived package. These are separate from our research and the live service's terms.

Package license
Apache-2.0
Package author
Miguel Herrero
Keywords
agent-evidence, codex, hash-chain, session-receipt

Declared capabilities

  • Local capture
  • Receipt verification

Package observed Oct 2, 2026.

Technical details
First seen
Sep 30, 2026 · 22:02 UTC
Last seen
Oct 2, 2026 · 12:00 UTC
Collection status
Collected

plugins_6a6c4af6f8108191a79fa88526a7b5a6

Download plugin data (JSON)