skills/project/abyss/os-abyss-artifact-trust-loop/SKILL.md
--- name: os-abyss-artifact-trust-loop scope: project status: scaffold summary: OS Abyss artifact-trust loop for routing ABI, provenance, signatures, SBOM, C2PA, drift, and consumer gates through abyss-machine read models and owner-local producers. invocation_mode: explicit-preferred technique_dependencies: - AOA-T-0001 - AOA-T-0002 - AOA-T-0028 --- # os-abyss-artifact-trust-loop ## Intent Use this skill to route OS Abyss ABI, provenance, signature, SBOM, SLSA/in-toto, Sigstore/Cosign,
npx skillsauth add 8Dionysus/aoa-skills os-abyss-artifact-trust-loopInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Use this skill to route OS Abyss ABI, provenance, signature, SBOM, SLSA/in-toto, Sigstore/Cosign, C2PA, TUF, SCITT, durable evidence, drift, and trust-gate work through the existing abyss-machine trust plane without creating a second trust authority.
The skill gives agents one natural loop: detect the artifact class, inspect requirements, inspect owner producer routes, inspect affected or stale evidence, refresh evidence only through the owner route, then require a consumer trust-gate verdict before consumption or landing.
Use this skill when:
Do not use this skill when:
.aoa session search, evidence routing, memory rehydration, or graph indexingagent, installer, runtime, release_consumer, or another owner-defined intentabyss-machine artifacts outputaoa-evals scenarios when behavior or trust claims changeAGENTS.md, local manifests, release docs, or validator surfaces. Use center or doctrine docs only as orientation, not as a replacement for the owner route.abyss-machine artifacts requirements, classify, producer-profile, affected, or registry surfaces over guessing. If the class remains unclear, stop with manual-review posture instead of forcing a class.abyss_machine MCP when it is runtime-visible:
abyss_machine_surface(name="artifact-trust-requirements", artifact_class=CLASS)abyss_machine_surface(name="artifact-trust-producer-profiles", artifact_class=CLASS)abyss_machine_surface(name="artifact-trust-affected", artifact_class=CLASS)abyss_machine_surface(name="artifact-trust-affected", artifact_class=CLASS, source_repo=OWNER, source_ref=SOURCE_REF) when source-ref or dirty-state evidence is knownabyss_machine_surface(name="artifact-trust-coverage")abyss_machine_surface(name="artifact-trust-coverage", source_repo=OWNER, source_ref=SOURCE_REF) when coverage must be checked against a specific source-ref contextabyss_machine_surface(name="artifact-trust-registry-latest", artifact_class=CLASS, consumer_intent=INTENT)abyss_machine_surface(name="artifact-trust-gate", artifact_class=CLASS, consumer_intent=INTENT)abyss_machine_surface(name="artifact-trust-scenarios")abyss_machine_surface(name="artifact-trust-validate")abyss-machine artifacts requirements --artifact-class CLASS --jsonabyss-machine artifacts producer-profiles --artifact-class CLASS --require-command-resolution --jsonabyss-machine artifacts affected --artifact-class CLASS --jsonabyss-machine artifacts trust-coverage --jsonabyss-machine artifacts trust-coverage --source-root PUBLIC_SEED_ROOT --source-repo OWNER --source-ref SOURCE_REF --json when separating installed public-seed evidence from a dirty source checkoutabyss-machine artifacts registry-latest --artifact-class CLASS --consumer-intent INTENT --jsonabyss-machine artifacts trust-gate --artifact-class CLASS --consumer-intent INTENT --jsonabyss-machine artifacts scenarios --jsonabyss-machine artifacts validate --jsonsource_context.public_seed_root until stronger evidence explains it.verify, sign, materialize-subjects, evidence-promote, OCI signing checks, update metadata checks, C2PA sidecars, or release bundle commands.trust-gate allow or an explicitly preserved warn posture before consumption. Treat warn as a live warning with a reason, not as green. Treat deny as blocking. Treat missing class or missing registry evidence as manual-review or deny according to owner rules.aoa-evals proof or negative scenarios when behavior, consumer admission, artifact policy, public claim, generated machine surface, or release posture changes.abyss-machine as authority for host enforcement, durable registry, trust gates, trust roots, update lane, and artifact policy read models.abyss-machine MCP read-only, typed, allowlisted, and bounded. It may inspect artifact-trust read models; it must not become a signer, builder, promoter, registry writer, privileged runner, or repair tool.aoa-sdk as typed reader/assertion surface, not the producer of host truth.aoa-evals as proof and negative-scenario authority when trust claims or consumer decisions need durable proof..aoa as session evidence routing, memory rehydration, and graph/index context. It is not trust policy authority and cannot override current owner files or live gates.abyss-machine MCP can expose the needed read-only surfaces.pkexec, service restart, or arbitrary command execution..aoa summaries replace owner-local producer commands and validators.warn as success, or treating a narrow smoke test as full OS Abyss artifact-trust coverage.trust-gate returned allow, warn, deny, or manual-review and the final recommendation preserved that verdict.public_source_seed, bootstrap_install_bundle, runtime_or_container_artifact, ai_model_or_runtime_bundle, aoa_sdk_python_distribution, aoa_session_memory_portable_bundle, and public_media_export.Manifest-backed techniques:
8Dionysus/aoa-techniques at cd276f040d55d490bd015b8698c7a5d594b9f875 using path techniques/execution/agent-workflows-core/plan-diff-apply-verify-report/TECHNIQUE.md and sections: Intent, When to use, Inputs, Outputs, Core procedure, Contracts, Risks, Validation8Dionysus/aoa-techniques at cd276f040d55d490bd015b8698c7a5d594b9f875 using path techniques/instruction/docs-boundary/source-of-truth-layout/TECHNIQUE.md and sections: Intent, When to use, Inputs, Outputs, Core procedure, Contracts, Risks, Validation8Dionysus/aoa-techniques at cd276f040d55d490bd015b8698c7a5d594b9f875 using path techniques/execution/agent-workflows-core/confirmation-gated-mutating-action/TECHNIQUE.md and sections: Intent, When to use, Inputs, Outputs, Core procedure, Contracts, Risks, Validationabyss-machine artifacts affected rather than hard-coding sibling topology in this skill.development
Sanitize private technical material into a public-safe owner-bounded derivative, or resolve authority among authored, generated, runtime, and installed sources. Use for governed incidents, logs, configs, diagnostics, or conflicting source roles. Do not use for ordinary editing, memo/session work, direct publication, or durable-memory authority.
tools
Diagnose a reviewed recurring session/workflow failure, or carry one bounded owner repair through checkpoint, rollback, and real health verification. Use for reviewed contamination, drift, repeated route/tool failure, or an established diagnosis ready for repair. Do not use on live evidence, for vague self-improvement, or to call a proposed or merely executed change verified.
tools
Use only when a literal ref to a closed/reviewed session packet is supplied, to extract, classify, propose promotion or branching, or identify an automation opportunity. Missing, live, or unreviewed evidence must fail closed without inventing a ref. Natural closeout preservation belongs to aoa-memo-writeback. Do not use for generic summaries, progression, direct owner writes, scheduling, mutation, or telemetry authority.
testing
Turn one stable technical truth into bounded evidence through contract, coverage-audit, or property mode. Use to define a named consumer seam, audit what existing checks really constrain, or express a broad invariant after manual cases establish meaning. Compose with aoa-eval when an evaluation surface must first be found or applied. Do not use for undefined behavior, generic test plans, or green checks as whole-system proof.