WitnessOps skills · first-party contracts
All Skills Library
Every entry is a committed SKILL.md with one exact byte sequence. Read it, copy it, download it, or send that exact version to the local Aegis checker.
First-party reference contracts, not customer evidence · Apache-2.0 · no marketplace, ratings, accounts, remote fetching, or cloud skill storage.
Governed agent verifier
Check a SKILL.md before an agent loads it.
Local, deterministic policy scan for agent skills. A pass is not a safety proof.
sha256:ccc325d40dc89823adff2d10f81fb02aa583a4edb5fd19bb1501b8512510bdb0Inspect exact bytes →Receipt-first verifier
Verify a WitnessOps receipt without inventing evidence.
Receipt-scoped checks only. Incomplete when evidence or trust inputs were not independently checked.
sha256:8555b23643e3d0e2e766df3e1914dd4493c2c46e43cdf36fd1c88b952c08e80dInspect exact bytes →Claim boundary copy
Write what a result does — and does not — establish.
Keeps public copy inside WitnessOps doctrine: no pentest, certification, or security-proof claims.
sha256:6062a6c2e241a3e4a83c7e91a9551377231763bc2390d5187d10a197989da7d0Inspect exact bytes →Governed recon
Passive-only exposure assessment. No exploitation.
Public-facing recon with a hard passive-only contract. Stops when the next step would touch the target.
sha256:15b91bee17d127c93226538e6b60cf857acf1c4b636192a24d4e43a260f4dbffInspect exact bytes →Evidence capture and chain
Keep findings tied to paths, hashes, and notes.
Normalize artifacts, notes, and manifests so a handover stays reviewable.
sha256:40b8bda4ce0e50781aa5dc4511d8c2e1956670d5b1bd07788501caae52cb6875Inspect exact bytes →Proof-run handover
Package what ran, what did not, and what the buyer can check.
Turns a bounded run into a reviewable package: scope, evidence references, and limits.
sha256:d837a8c6ceadf0405586a9be4328b79ae8eb8d741f7d2fb35df52d6939cd3e37Inspect exact bytes →Key custody hygiene
Talk about keys without moving them.
Rotation records, verifier keys, and custody metadata — never secret material.
sha256:b845467b7893636166969b353cb372b24ecdf344125b7d138bb4843b286f153eInspect exact bytes →Decision fabric validator
Schema-first checks on workflow classes and decision runs.
Validate decision runs against the declared workflow class. Negative fixtures stay negative.
sha256:f37deb9daa63ff44ce2159ed7ba24569749d229776a423627de76e7693577a4aInspect exact bytes →MCP tool hygiene
Bound MCP tools the way you bound skills.
Allowlists, no chain-loading of remote tools, and no silent expansion of scope.
sha256:1253bcb9c5ab0b19924a8b6bed828ab2d376325ffa1e66005133ed694059363aInspect exact bytes →Offboarding evidence
Access-removed proof as a specimen, not a story.
Deterministic evaluation of offboarding evidence: raw inputs, hashes, and a human-readable report.
sha256:539f28cbab67420aaf9a328d743e1345428c26da85cbc81262cb35fc21f21f4dInspect exact bytes →Sample case authoring
Labelled samples with inspectable limits.
Public sample cases stay synthetic, bounded, and honest about what they are not.
sha256:24b8897ab1dd242ada7d344abff1bc42c2db7ec99524f9d8306e1e427b761e2cInspect exact bytes →Boundary
A readable contract is not a safety certification.
These files make declared instructions inspectable. A local policy result is bounded to the selected policy and supplied bytes; it does not establish that a resulting workflow, external tool, model, or environment is safe.