Operate / AI system builders

Operate with AI skills

Apply installed Receiz skills as exact operating procedures without allowing generated language to decide proof truth.

guided proof operation@receiz/ai-skills 124.0.2Complete production checklist

Implementation rail · @receiz/ai-skills 124.0.2

Exact execution and operator checks

  1. 01

    Operator check

    Load the exact installed skill

    Load installed skill receiz-proof-skill only when its trigger matches. Record its package version, source digest, allowed tools, maximum autonomous authority, and private-data boundary.

    Substantive records: /reference/ai-skills · /trust/hierarchy

    Expected: The skill is selected from the installed package and remains behavioral instruction, not executable authority.

  2. 02

    Exact mechanic

    Qualify the installed skill package

    pnpm test:ai-skills-distribution
    Mechanic
    pnpm test:ai-skills-distribution
    Authentication and account boundary
    Authorized local repository checkout; the command proves only the checked repository boundary.
    Exact source
    package.json · SHA-256 132f99232dfaf26f7186b73752938d1377042808f42d60d374fe7b2e57c7646b

    Expected: Installed skill inventory, source bytes, triggers, and distribution contracts pass.

  3. 03

    Operator check

    Execute only an allowed mechanic

    Require the agent to call an installed SDK or MCP verifier for exact bytes. Reject model prose, invented commands, excess permissions, secret disclosure, or autonomous mutation beyond the skill's declared boundary.

    Substantive records: /reference/mcp · /reference/sdk

    Expected: The deterministic mechanic returns the result; the model reports it without becoming authority.

  4. 04

    Operator check

    Retain an evidence record

    Record selected skill, source digest, allowed tool call, exact artifact identity, verifier status, and explicit non-claims.

    Substantive records: /reference/operations-receipts

    Expected: The AI operating record is auditable and subordinate to proof.

Complete operating anatomy

Every boundary required to ship.

Solved outcome
An AI workflow follows typed steps, exposes tool evidence, preserves non-claims, and requires independent artifact verification.
Prerequisites
Install @receiz/ai-skills@124.0.2; hold the exact skill name, trigger, source digest, allowed tools, maximum autonomous authority, private-data boundary, user authorization, and deterministic mechanic selected for execution.
Exact primitive
guided proof operation
Governing law
Operate with AI skills is governed by invariant-first: A weaker observation cannot rewrite an already verified stronger fact. canonical-artifact-verifier: The verifier classifies the supplied artifact. Embedded subpayloads and remote responses remain subordinate. authority-boundaries: Assigned control custody remains separated by recorded boundary.
Source-of-truth order
Receiz law → sealed artifact truth → deterministic proof object state → verified durable local or register truth → authenticated snapshot → server distribution, synchronization, indexing, and publication → database, session, observability, and interface projections.
Expected artifact, receipt, or state
A bounded workflow result containing cited tool evidence and the artifact or receipt that must be verified independently.
Inspection
Inspect the selected skill, version, source digest, tool calls, artifact references, and explicit non-claims. Inspection exposes structure and receipt fields; inspection never establishes verification.
Independent verification
Independent verification for ai-skills: verify the artifact with deterministic code; never accept model prose as verification. This establishes only the guided proof operation boundary named by the bound sources; The implementation rail remains beneath proof authority: @receiz/ai-skills 124.0.2.
Offline behavior
Static skill instructions and local tools can operate without a model network when installed; any external model or provider boundary stays explicit.
Identity and account boundary
Public Record Moment, Seal File, Verify, Export, and public proof reading are account-free. Identity is optional and adds continuity, custody, recovery, and governed private controls after proof admission.
Security boundary
Limit tool permissions, keep secrets outside prompts and outputs, validate structured inputs, and require human authorization for material external mutations.
Conformance command
pnpm --filter @receiz/ai-skills test
Deployment checks
Pin the skill package, validate skill bytes and triggers, restrict tools and permissions, keep private material out of prompts and logs, require deterministic SDK or MCP execution, preserve tool evidence, reject model authority, and run distribution conformance.
Production checklist
Match exact trigger; inspect digest; enforce allowed tools; test excess-permission denial; test invented command rejection; execute deterministic verifier; compare model report; scan secrets; retain non-claims; run AI skill distribution tests.
Rollback and containment
Containment for ai-skills: The skill is not loaded. Install and bind the exact coordinated package record. The request is denied before execution. Reduce scope or obtain explicit bounded authorization through the documented mechanic. The claim is rejected. Execute the installed SDK or MCP verifier and report its exact result. Preserve every stronger held artifact and admitted state while the named boundary is corrected.

Fail closed

Mutation and failure matrix

F1

Skill source digest, trigger, or installed name differs.

Effect
The skill is not loaded.
Retry
Do not substitute a similarly named instruction.
Recovery
Install and bind the exact coordinated package record.
F2

Agent requests a tool or mutation beyond allowed authority.

Effect
The request is denied before execution.
Retry
Never let model confidence expand authority.
Recovery
Reduce scope or obtain explicit bounded authorization through the documented mechanic.
F3

Model output claims verification without deterministic tool evidence.

Effect
The claim is rejected.
Retry
Do not treat prose as proof.
Recovery
Execute the installed SDK or MCP verifier and report its exact result.

Exact authority

Claim-to-source bindings

  1. A weaker observation cannot rewrite an already verified stronger fact.

    docs/invariant-first-kernel.mdnormative-doctrine · SHA-256 0617593ee5e1a39d51ebd6ccd3d50453b2c717723edc4a1a5f3ed496872c347c
  2. The verifier classifies the supplied artifact. Embedded subpayloads and remote responses remain subordinate.

    packages/receiz-sdk/src/artifactVerification.tsimplementation-verifier · SHA-256 c10cdba92568fea273e1d9e7a3321083d52945378ab0cc83aee9720d44f0bba3
  3. Assigned control custody remains separated by recorded boundary.

    docs/governance/control-boundaries.v1.mdnormative-governance · SHA-256 da31636848c373e8d54e8d101885e15a9a29f7f8a734cf5fe675b7e7d5ec166e