← Completion ReceiptCONTENT HISTORY

Update to Completion Receipt

Snapshot Sep 30, 2026 · 23:15 UTC · version 0.1.5

Collection source: not recorded for this historical snapshot.

WHAT CHANGED · RULE-BASED ANALYSIS

First saved snapshot

No earlier snapshot is available to establish a change.

Compare saved observations

Download comparison JSON
Full technical diff · 0 changed fields
Full snapshot data
{
  "name": "agent-shipproof",
  "description": "Use when an approved local command needs a verifiable receipt. Run only that command, record its exit status, selected file hashes, and observed Git state, or verify later path-level drift; never treat the receipt as proof of correctness, security, identity, authorization, or sandboxing.",
  "included_files": [],
  "skill_md_contents": "---\nname: agent-shipproof\ndescription: Use when an approved local command needs a verifiable receipt. Run only that command, record its exit status, selected file hashes, and observed Git state, or verify later path-level drift; never treat the receipt as proof of correctness, security, identity, authorization, or sandboxing.\n---\n\n# Completion Receipt\n\nUse this skill when the user wants a reviewable record of what a coding-agent run actually observed.\n\n## Boundary\n\nThe product emits a **Completion Receipt**. Never call the receipt an attestation, certification, signature, correctness proof, security proof, identity proof, or sandbox guarantee. The product name does not widen the artifact's evidence claim.\n\n## Workflow\n\n1. Confirm the exact root, command, claims, and include patterns. Never infer authorization for an external or destructive command.\n2. Keep secrets out of arguments, claims, command output, and selected artifacts.\n3. Run `shipproof run` only for the explicitly authorized command. It executes with the caller's permissions and is not a sandbox; set a conservative timeout and output ceiling.\n4. Report the observed command exit, selected artifact count, local Git fields, and receipt digest.\n5. For v0.1.5 receipts, review the `observed_evidence` envelope and its explicit omissions before describing coverage.\n6. Use `shipproof verify` later to identify added, removed, or changed paths without exposing contents.\n7. Treat any integrity mismatch, missing HMAC key, untrusted selection contract, or tool error as non-passing.\n8. Stop before sharing or uploading a receipt unless the user separately authorizes it after sensitivity review.\n\nOptional pilot HMAC authentication uses a shared secret supplied through an environment variable. It is not a public-key signature and does not prove who ran the command.\n"
}

SHA-256: 58634677942f1143e899a69e27eace58ee198ab9d3ce62ecd2e9a4d09981caa0