{"id":17190,"plugin_id":"plugins_6a746bbb64d48191942c65a16a1eb19f","kind":"skill","collection_source":null,"comparison_source":null,"observed_at":"2026-09-30T23:14:01.218Z","digest":"d5649108658e8d9ed7b7b7c9c39913fbadc5f825acfbeac81d0d726d1c31d808","against":null,"payload":{"description":"Design, create, inspect, sign, verify, or integrate Agent Attestation Records (AARs) when agent work needs portable Ed25519-signed claims, independent verdicts, ground-truth status, and evidence commitments.","included_files":[{"relative_path":"agents/openai.yaml","size_in_bytes":236}],"name":"aar-attestation","skill_md_contents":"---\nname: aar-attestation\ndescription: Design, create, inspect, sign, verify, or integrate Agent Attestation Records (AARs) when agent work needs portable Ed25519-signed claims, independent verdicts, ground-truth status, and evidence commitments.\n---\n\n# Agent Attestation Records\n\nRead `../../references/philosophy.md` for the signed-versus-true boundary and `../../references/threat-model.md` for verifier and secret risks.\n\nAttest a target-runtime claim or outcome that the user has asked to make\nportable. Do not issue an AAR for the coding assistant's patch, the plugin's\ndistribution, or SDK installation merely because this skill is available.\n\n## Workflow\n\n1. Fix the task claim and identify the subject, principal, verifier, verification method, independence class, and real-world source.\n2. Run the check before deciding verdict or `ground_truth`; retain the raw result outside the model narrative.\n3. Commit only necessary evidence: source, query/check, observation time, response hash, and a minimal non-sensitive excerpt.\n4. Use the published tooling instead of inventing fields from memory: `npx -y @frontier-infra/audit` bundles the canonical AAR signer/verifier (`agentcontrolplane/tools/aar.mjs`); the spec lives in `frontier-infra/agentcontrolplane`.\n5. Sign only through an operator-selected local key path and the discovered local tool. Never request, echo, copy, log, or bundle a private key. If key material was pasted into a prompt, transcript, issue, log, or other non-secret channel, treat it as exposed: refuse to use it, tell the operator to revoke or rotate it through their key-management process, and continue only with a newly provisioned key referenced by a local path or secret handle.\n6. Verify the final bytes independently with the published verifier:\n\n   ```sh\n   npx -y @frontier-infra/audit verify --evidence evidence.json --aar aar.json --did-json did.json\n   ```\n\n   Signing during an audit run is `npx -y @frontier-infra/audit run <repo> --out <dir> --sign-key <private-jwk.json> --did-json <did.json>` — key material by local file path only.\n\n7. Report the exact tool/schema source, signature validity when verified, AAR tier, evidence source, independence limitations, and any unverifiable claim. Keep the receipt and raw verification artifact linked but separately governed.\n\n## Safety rules\n\n- Do not write `verified` or `ground_truth: confirmed` until the actual check succeeded.\n- Do not let the worker self-attest as the independent verifier.\n- Keep evidence minimal and avoid credentials, personal data, and proprietary raw system output.\n"},"changes":[],"summary":"First saved snapshot. No earlier version is available for comparison.","summary_kind":"deterministic","summary_metadata":{}}