Operate / AI system builders
Operate with AI skills
Apply installed Receiz skills as exact operating procedures without allowing generated language to decide proof truth.
Implementation rail · @receiz/ai-skills 124.0.2
Exact execution and operator checks
- 01
Operator check
Load the exact installed skill
Load installed skill receiz-proof-skill only when its trigger matches. Record its package version, source digest, allowed tools, maximum autonomous authority, and private-data boundary.
Substantive records: /reference/ai-skills · /trust/hierarchy
Expected: The skill is selected from the installed package and remains behavioral instruction, not executable authority.
- 02
Exact mechanic
Qualify the installed skill package
pnpm test:ai-skills-distribution- Mechanic
- pnpm test:ai-skills-distribution
- Authentication and account boundary
- Authorized local repository checkout; the command proves only the checked repository boundary.
- Exact source
package.json· SHA-256 132f99232dfaf26f7186b73752938d1377042808f42d60d374fe7b2e57c7646b
Expected: Installed skill inventory, source bytes, triggers, and distribution contracts pass.
- 03
Operator check
Execute only an allowed mechanic
Require the agent to call an installed SDK or MCP verifier for exact bytes. Reject model prose, invented commands, excess permissions, secret disclosure, or autonomous mutation beyond the skill's declared boundary.
Substantive records: /reference/mcp · /reference/sdk
Expected: The deterministic mechanic returns the result; the model reports it without becoming authority.
- 04
Operator check
Retain an evidence record
Record selected skill, source digest, allowed tool call, exact artifact identity, verifier status, and explicit non-claims.
Substantive records: /reference/operations-receipts
Expected: The AI operating record is auditable and subordinate to proof.
Complete operating anatomy
Every boundary required to ship.
- Solved outcome
- An AI workflow follows typed steps, exposes tool evidence, preserves non-claims, and requires independent artifact verification.
- Prerequisites
- Install @receiz/ai-skills@124.0.2; hold the exact skill name, trigger, source digest, allowed tools, maximum autonomous authority, private-data boundary, user authorization, and deterministic mechanic selected for execution.
- Exact primitive
- guided proof operation
- Governing law
- Operate with AI skills is governed by invariant-first: A weaker observation cannot rewrite an already verified stronger fact. canonical-artifact-verifier: The verifier classifies the supplied artifact. Embedded subpayloads and remote responses remain subordinate. authority-boundaries: Assigned control custody remains separated by recorded boundary.
- Source-of-truth order
- Receiz law → sealed artifact truth → deterministic proof object state → verified durable local or register truth → authenticated snapshot → server distribution, synchronization, indexing, and publication → database, session, observability, and interface projections.
- Expected artifact, receipt, or state
- A bounded workflow result containing cited tool evidence and the artifact or receipt that must be verified independently.
- Inspection
- Inspect the selected skill, version, source digest, tool calls, artifact references, and explicit non-claims. Inspection exposes structure and receipt fields; inspection never establishes verification.
- Independent verification
- Independent verification for ai-skills: verify the artifact with deterministic code; never accept model prose as verification. This establishes only the guided proof operation boundary named by the bound sources; The implementation rail remains beneath proof authority: @receiz/ai-skills 124.0.2.
- Offline behavior
- Static skill instructions and local tools can operate without a model network when installed; any external model or provider boundary stays explicit.
- Identity and account boundary
- Public Record Moment, Seal File, Verify, Export, and public proof reading are account-free. Identity is optional and adds continuity, custody, recovery, and governed private controls after proof admission.
- Security boundary
- Limit tool permissions, keep secrets outside prompts and outputs, validate structured inputs, and require human authorization for material external mutations.
- Conformance command
pnpm --filter @receiz/ai-skills test- Deployment checks
- Pin the skill package, validate skill bytes and triggers, restrict tools and permissions, keep private material out of prompts and logs, require deterministic SDK or MCP execution, preserve tool evidence, reject model authority, and run distribution conformance.
- Production checklist
- Match exact trigger; inspect digest; enforce allowed tools; test excess-permission denial; test invented command rejection; execute deterministic verifier; compare model report; scan secrets; retain non-claims; run AI skill distribution tests.
- Rollback and containment
- Containment for ai-skills: The skill is not loaded. Install and bind the exact coordinated package record. The request is denied before execution. Reduce scope or obtain explicit bounded authorization through the documented mechanic. The claim is rejected. Execute the installed SDK or MCP verifier and report its exact result. Preserve every stronger held artifact and admitted state while the named boundary is corrected.
Fail closed
Mutation and failure matrix
Skill source digest, trigger, or installed name differs.
- Effect
- The skill is not loaded.
- Retry
- Do not substitute a similarly named instruction.
- Recovery
- Install and bind the exact coordinated package record.
Agent requests a tool or mutation beyond allowed authority.
- Effect
- The request is denied before execution.
- Retry
- Never let model confidence expand authority.
- Recovery
- Reduce scope or obtain explicit bounded authorization through the documented mechanic.
Model output claims verification without deterministic tool evidence.
- Effect
- The claim is rejected.
- Retry
- Do not treat prose as proof.
- Recovery
- Execute the installed SDK or MCP verifier and report its exact result.
Exact authority
Claim-to-source bindings
A weaker observation cannot rewrite an already verified stronger fact.
docs/invariant-first-kernel.mdnormative-doctrine · SHA-256 0617593ee5e1a39d51ebd6ccd3d50453b2c717723edc4a1a5f3ed496872c347cThe verifier classifies the supplied artifact. Embedded subpayloads and remote responses remain subordinate.
packages/receiz-sdk/src/artifactVerification.tsimplementation-verifier · SHA-256 c10cdba92568fea273e1d9e7a3321083d52945378ab0cc83aee9720d44f0bba3Assigned control custody remains separated by recorded boundary.
docs/governance/control-boundaries.v1.mdnormative-governance · SHA-256 da31636848c373e8d54e8d101885e15a9a29f7f8a734cf5fe675b7e7d5ec166e
One complete system