2026-10-11 16:38 UTC

PromptSign creator sergey_v claims its Sigstore signing and verification tooling establishes publisher provenance and update integrity for AI instruction files, potentially enabling trusted-publisher policies for installed agent skills.

state: seedheat: lowuncertainty: highknownscott: lowagentic-security software-supply-chain agent-skillssergey_vPromptSign

What is this?

The supplied case describes PromptSign as a Show HN project by sergey_v for signing and verifying AI instruction files with Sigstore, with claimed benefits for publisher provenance and update integrity. None of the supplied web results directly documents PromptSign or its creator, so its implementation and support for trusted-publisher policies remain unverified. The snippets establish related work: nolabs-ai/agent-sign describes Sigstore attestations for SKILLS.md and CLAUDE.md with publisher-identity checks, while OpenSSF describes Sigstore’s signature and transparency-log infrastructure. These support the technical context, not PromptSign’s specific claims or any guarantee that signed instructions behave safely.

Why it matters to Scott

PromptSign’s claimed publisher-identity and instruction-integrity checks repeat the signed-skills position already held in Scott’s Agent Provenance Stack and Cryptographic Trust pages; they address artefact authenticity, not the full chain of action authorisation or behavioural safety. The supplied material establishes neither a consequential adopter nor verified implementation or trusted-publisher enforcement, so this is currently another example of his position rather than a reason to change what he builds or argues; no supplied radar page tracks PromptSign itself.
ip:framework.agent-provenance-stackip:concept.cryptographic-trustradar:concept.software-supply-chainradar:concept.agent-skillsradar:concept.agent-provenanceradar:skillpreflight-agent-skill-scoringradar:anthropic-skill-scanner-backdoor-bypass
queries asked of Scott's wikis
  • agent skill installation and update trust policies
  • instruction file provenance and publisher identity
  • coding agent harness verification hooks
  • software supply chain signing and attestations
  • authenticity versus behavioral safety in agent security

Measured heat

now 0 pts/hpeak 0 pts/hcomments 0/hpeers p14momentum: steady2 platformsage 742h
points/hour across evidence · reading as of 2026-10-12 02:59:37.977291+11:00 · deterministic, not a model opinion

How the heat travelled

09-10 18:53 (minted)⭐ origin echo-reconstructedThe creator presents PromptSign as Sigstore signing and verification for AI instruction files, motivated by checking authorship, installed-f
PromptSign on blog (echo) · attributed from hn.story.49647883 · published time unknown
—
09-10 18:03first on hacker news · published · lag ?Show HN: PromptSign – Sigstore signing and verification for AI instruction files
sergey_v
—
09-10 18:03amplified on hacker news 👑hn.story.49647883
sergey_v
peak 1 · 0 comments · 106% of case engagement
09-10 18:21our radar first saw it · lag ?discovery anchor: hn.story.49647883—
pace: p11 vs 519 stories at the 720h mark (now 742h old) — behind addom-local-coding-harness (0.5x)

Evidence (2) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnShow HN: PromptSign – Sigstore signing and verification for AI instruction filessergey_v10
🟧 echo.blog ⭐The creator presents PromptSign as Sigstore signing and verification for AI instruction files, motivated by checking authorship, installed-fPromptSign——

Interpretation history

Decision trace