← AgentProofCONTENT HISTORYWHAT CHANGED · RULE-BASED ANALYSIS
Update to AgentProof
Snapshot Sep 30, 2026 · 23:13 UTC · version 0.1.0
Collection source: not recorded for this historical snapshot.
First saved snapshot
No earlier snapshot is available to establish a change.
Compare saved observations
Download comparison JSONFull technical diff · 0 changed fields
Full snapshot data
{
"description": "Capture a new instrumented Codex CLI session into a canonical hash-only AgentProof receipt, or verify a receipt and its recorded repository commitments locally. Use when the user asks to create agent-execution evidence, verify an AgentProof receipt, or compare it with the current Git repository. Do not use to claim capture of the current Codex session, completeness, truth, authorship, work quality, compliance, payment authorization, settlement, signing, or anchoring.",
"included_files": [
{
"relative_path": "agents/openai.yaml",
"size_in_bytes": 242
},
{
"relative_path": "references/request-contract.md",
"size_in_bytes": 3409
},
{
"relative_path": "references/supported-repository-profile.md",
"size_in_bytes": 3728
},
{
"relative_path": "scripts/agentproof.py",
"size_in_bytes": 9147
},
{
"relative_path": "scripts/agentproof_runtime/__init__.py",
"size_in_bytes": 454
},
{
"relative_path": "scripts/agentproof_runtime/capture.py",
"size_in_bytes": 14599
},
{
"relative_path": "scripts/agentproof_runtime/receipt.py",
"size_in_bytes": 16051
},
{
"relative_path": "scripts/agentproof_runtime/repository.py",
"size_in_bytes": 2784
}
],
"name": "agentproof",
"skill_md_contents": "---\nname: agentproof\ndescription: Capture a new instrumented Codex CLI session into a canonical hash-only AgentProof receipt, or verify a receipt and its recorded repository commitments locally. Use when the user asks to create agent-execution evidence, verify an AgentProof receipt, or compare it with the current Git repository. Do not use to claim capture of the current Codex session, completeness, truth, authorship, work quality, compliance, payment authorization, settlement, signing, or anchoring.\n---\n\n# AgentProof\n\nAgentProof starts a separate Codex CLI child process and records only hashes and typed\nmetadata from what its collector observes. It cannot capture the current Codex\nconversation.\n\n## Required boundary\n\n- State before capture: `This starts a new instrumented Codex session; it does not capture the current session.`\n- Treat a valid receipt as integrity and ordering evidence for observed events only.\n- Never describe it as proof of completeness, truth, quality, safety, compliance,\n identity, payment authorization, or settlement.\n- Never request, print, inspect, store, or place a credential in the request.\n- Never add Sign, Anchor, payment, settlement, gateway, or model-API steps.\n- Do not call an Anthropic or OpenAI model API. Capture invokes the installed Codex CLI\n using that CLI's existing authentication.\n- Capture starts the child with Codex approval policy `never` because the child is\n non-interactive and cannot answer approval prompts. State this before execution.\n This does not widen its sandbox: it must retain the request's `read-only` or\n `workspace-write` sandbox.\n- Capture needs the child CLI's network connection and nested sandbox. If the host\n sandbox blocks either, ask the user to approve the fixed launcher outside that\n outer sandbox. Never widen permissions silently. The child must still use the\n request's `read-only` or `workspace-write` sandbox.\n\n## Resolve the runtime\n\nSet `<skill-dir>` conceptually to the absolute directory containing this `SKILL.md`.\nUse the script at `<skill-dir>/scripts/agentproof.py`. Do not copy it into the user's\nworkspace or modify it.\n\nRead [request-contract.md](references/request-contract.md) and\n[supported-repository-profile.md](references/supported-repository-profile.md) before\nthe first execution.\n\n## Capture\n\n1. Confirm the current working directory is the intended trusted Git repository.\n2. Explain the new-session boundary using the exact sentence above.\n3. Explain that the new child is non-interactive, uses Codex approval policy `never`,\n and retains the selected sandbox.\n4. Create `.agentproof/request.json` with a structured write tool, never shell\n interpolation:\n\n```json\n{\n \"action\": \"capture\",\n \"model\": \"<installed Codex model identifier>\",\n \"prompt\": \"<task for the new child session>\",\n \"sandbox\": \"workspace-write\"\n}\n```\n\n5. Run only:\n\n```text\npython3 -B <skill-dir>/scripts/agentproof.py --request .agentproof/request.json\n```\n\n6. If Codex requires approval to run that fixed command outside its outer sandbox,\n request it and explain that the nested child retains the requested sandbox.\n7. Report the output path, event count, chain head and explicit gaps. Do not reproduce\n prompt or command content from the session.\n\nThe runtime removes the request after validating it and refuses to overwrite an\nexisting receipt. Never delete an existing receipt merely to make capture succeed;\nask the user how to preserve it.\n\n## Verify\n\nCreate this exact request with a structured write tool:\n\n```json\n{\"action\":\"verify\"}\n```\n\nUse Verify for receipts produced by this strict plugin line. Do not promise that\nhistorical Build Week prototype receipts are accepted.\n\nRun the same fixed command. Report `MATCH` or `MISMATCH`, the receipt-chain status and\nthe explicit limits as separate fields. Never compress `MATCH` into `verified`,\n`correct`, `authentic`, or an equivalent approval. A match does not establish who\nproduced the state or whether it is correct.\n\n## Failure handling\n\n- Preserve fail-closed errors; do not bypass path, symlink, schema, overwrite or\n repository checks.\n- If Git is unavailable, or if `codex` is unavailable or unauthenticated, stop and\n report that capture was not performed.\n- The runtime suppresses raw child stderr. On child failure it reports only a SHA-256\n commitment, byte count and line count; do not reconstruct or request the raw text.\n- For `git_repository_required`, `run_from_git_repository_root`,\n `non_utf8_repository_path`, `repository_symlink_unsupported`,\n `snapshot_file_too_large`, `snapshot_total_too_large`,\n `repository_file_too_large` or `receipt_publish_failed`, stop and report the\n matching condition from the supported repository profile. Do not retry by\n weakening or bypassing that boundary.\n- For `unexpected_runtime_error`, report only its exception type and traceback\n SHA-256 commitment. Never request, reconstruct or reproduce the raw traceback.\n- Do not summarize a failed run as a valid receipt.\n"
}SHA-256 of public snapshot: db3ad8208531507185a48604601f395cf9c3b420d391ec3075b72f69b2b44780