{"id":18918,"plugin_id":"plugins_6a8d4dc60bf081918a06094873890eb4","kind":"skill","collection_source":null,"comparison_source":null,"observed_at":"2026-09-30T23:15:02.472Z","digest":"0a4ee90010f606e10951b6d8d36c8bc34217d4ba65ec6cd823e6167b666a1cb4","against":null,"payload":{"description":"Use this when a user supplies an AgentProof v2 receipt, OpsTruth evidence receipt, complete OpsTruth v1 execution handoff, or sealed DoneState v2 verification handoff and needs integrity, signer trust or fresh outcome verification. Never execute, repeat or trust the underlying action merely because its receipt is cryptographically valid.","included_files":[{"relative_path":"agents/openai.yaml","size_in_bytes":452}],"name":"verify-action-receipt","skill_md_contents":"---\nname: verify-action-receipt\ndescription: Use this when a user supplies an AgentProof v2 receipt, OpsTruth evidence receipt, complete OpsTruth v1 execution handoff, or sealed DoneState v2 verification handoff and needs integrity, signer trust or fresh outcome verification. Never execute, repeat or trust the underlying action merely because its receipt is cryptographically valid.\n---\n\n# Verify Action Receipt\n\nRequire the receipt document or complete OpsTruth report. Accept trusted signer fingerprints only when the user supplies them or they come from an authoritative policy source.\n\n1. Call `opstruth_verify_receipt` for an AgentProof signed receipt v2.\n2. Call `opstruth_verify_evidence_receipt` for a complete OpsTruth report containing its evidence receipt.\n3. Distinguish structural validity, digest validity, cryptographic validity and signer trust.\n4. Call `opstruth_verify_execution_result` only when the complete ActionRequest, ActionAuthorization and ExecutionReceipt are present together with separate authoritative authorizer and executor fingerprint allowlists and a public repository target.\n5. Call `opstruth_get_verifier_identity` before a DoneState objective is created so its authoritative policy can pin the exact DoneState-compatible fingerprint.\n6. Call `opstruth_attest_donestate_handoff` only for a sealed `donestate.verification-handoff.v2`. Return its signed attestation for separate submission; never submit it to DoneState or describe `uncertain` as verified.\n7. Treat a valid signature from an untrusted signer as cryptographically valid but untrusted.\n8. Treat global authorization nonce reuse as unproven unless an authoritative replay source is available outside the stateless public plugin.\n9. Do not claim that the underlying action, inspection or deployment is correct merely because the receipt signature is valid.\n10. Never execute, compensate, repeat or replay the recorded action.\n"},"changes":[],"summary":"First saved snapshot. No earlier version is available for comparison.","summary_kind":"deterministic","summary_metadata":{}}