PromptSign creator sergey_v claims its Sigstore signing and verification tooling establishes publisher provenance and update integrity for AI instruction files, potentially enabling trusted-publisher policies for installed agent skills.
state: seedheat: lowuncertainty: highknownscott: lowagentic-security software-supply-chain agent-skillssergey_vPromptSign
What is this?
The supplied case describes PromptSign as a Show HN project by sergey_v for signing and verifying AI instruction files with Sigstore, with claimed benefits for publisher provenance and update integrity. None of the supplied web results directly documents PromptSign or its creator, so its implementation and support for trusted-publisher policies remain unverified. The snippets establish related work: nolabs-ai/agent-sign describes Sigstore attestations for SKILLS.md and CLAUDE.md with publisher-identity checks, while OpenSSF describes Sigstore’s signature and transparency-log infrastructure. These support the technical context, not PromptSign’s specific claims or any guarantee that signed instructions behave safely.
Why it matters to Scott
PromptSign’s claimed publisher-identity and instruction-integrity checks repeat the signed-skills position already held in Scott’s Agent Provenance Stack and Cryptographic Trust pages; they address artefact authenticity, not the full chain of action authorisation or behavioural safety. The supplied material establishes neither a consequential adopter nor verified implementation or trusted-publisher enforcement, so this is currently another example of his position rather than a reason to change what he builds or argues; no supplied radar page tracks PromptSign itself.
ip:framework.agent-provenance-stackip:concept.cryptographic-trustradar:concept.software-supply-chainradar:concept.agent-skillsradar:concept.agent-provenanceradar:skillpreflight-agent-skill-scoringradar:anthropic-skill-scanner-backdoor-bypass
queries asked of Scott's wikis
- agent skill installation and update trust policies
- instruction file provenance and publisher identity
- coding agent harness verification hooks
- software supply chain signing and attestations
- authenticity versus behavioral safety in agent security
Measured heat
now 0 pts/hpeak 0 pts/hcomments 0/hpeers p14momentum: steady2 platformsage 742h
points/hour across evidence · reading as of 2026-10-12 02:59:37.977291+11:00 · deterministic, not a model opinion
How the heat travelled
pace: p11 vs 519 stories at the 720h mark (now 742h old) — behind addom-local-coding-harness (0.5x)
Evidence (2) — ⭐ canonical anchor
Interpretation history
2026-09-10T19:01:28Z
No new evidence changes the interpretation: PromptSign remains a creator-announced provenance tool, and the reconstructed echo is not independent corroboration. Its practical value for trusted-publisher enforcement remains unverified; signing alone does not establish instruction safety or action authorization.
2026-09-10T18:58:30Z
grounded: known/low — PromptSign’s claimed publisher-identity and instruction-integrity checks repeat the signed-skills position already held in Scott’s Agent Provenance Stack and Cr
2026-09-10T18:53:27Z
case created — This tooling launch is distinct from the open paper about assistants neglecting supply-chain trust signals and should not be attached merely by topic.
Decision trace
- 10-04 06:06review_dormantscheduled targets exhausted or 28 quiet days
- 10-04 06:06drop_targetsquiet through full ladder or over cap 8
- 09-11 05:01repriceNo new evidence changes the interpretation: PromptSign remains a creator-announced provenance tool, and the reconstructed echo is not independent corroboration. Its practical value for trusted-publish
- 09-11 05:01alert_silentThe announcement has already been assessed, and this look adds no implementation verification, harness integration, or consequential adoption. There is no new delta that makes notifying Scott today mo
- 09-11 05:01alert_routeThe announcement has already been assessed, and this look adds no implementation verification, harness integration, or consequential adoption. There is no new delta that makes notifying Scott today mo
- 09-11 04:59alert_silentThe creator’s announcement establishes a new provenance-tool offering, while its implementation and enforcement claims remain unvalidated. Signing skill-directory manifests is a relevant application o
- 09-11 04:59alert_routeThe creator’s announcement establishes a new provenance-tool offering, while its implementation and enforcement claims remain unvalidated. Signing skill-directory manifests is a relevant application o
- 09-11 04:58groundPromptSign’s claimed publisher-identity and instruction-integrity checks repeat the signed-skills position already held in Scott’s Agent Provenance Stack and Cryptographic Trust pages; they address ar
- 09-11 04:53createThis tooling launch is distinct from the open paper about assistants neglecting supply-chain trust signals and should not be attached merely by topic.