Inspect Trust

skillerr/inspect-trust

Submitted by @dev_jordan · Jordan Reyes

Jul 15, 2026 · minted Jul 18, 2026

sha256:e11bd46a3d4a
FreeNot anchoredmintedinspectablecapabilitiesdigest-pinnednative

70/ 100 · Solid

WIP · 2.0-signals

Skill Score is actively being developed and will get sharper over time.

  • Sealed package20/20

    Minted .skill blob in the registry

  • Digest published15/15

    sha256 pin published on skillerr.com

  • Permissions declared15/15

    Capabilities / permissions declared

  • Source attested10/10

    Namespace, submitter, or source URL (not a vendor endorsement)

  • Transparency log0/15

    Not anchored

  • Release profile0/15

    Release profile gates not met

  • Registry signal5/5

    4201 install(s) on registry

  • Not revoked5/5

    No revocation on log

Not a malware scan. Not “safe to run.” Transparent registry signals only. Inclusion is not endorsement.

npx @skillerr/add skillerr/inspect-trust

Registry pin: sha256:e11bd46a3d4a (shown on TrustView; install by name resolves to this sealed blob)

Sealed install targets

Writes inspect-trust.skill (sealed ZIP) plus optional skillerr.json. Not a bare SKILL.md.

Download inspect-trust.skill

Sealed ZIP with digest + skillerr.json. Not a bare SKILL.md.

Free skills install with npx @skillerr/add. Sign in for account history.

Install and download deliver a digest-pinned open .skill package (docs.skillerr.com). Pasting a SKILL.md from the internet has none of this proof.

  • inspect-trust.skill ZIP

    Open-protocol .skill ZIP (skill.json + workflow), not a public raw SKILL.md URL

  • Registry digest pin

    sha256:e11bd46a3d4a…

  • Inspect before run

    TrustView on skillerr.com; SKILL.md is a lossy adapter inside the package

  • Permissions surface

    Capabilities not declared

  • Transparency log

    Inclusion proof in the skillerr.com registry log

This skill has not marked capabilities as declared. Treat the map as incomplete.

  • noneNo elevated capslow

    No fs / net / shell declared beyond default agent context

Declarations for humans and agents. Not a runtime sandbox guarantee.

Confirm the digest on this page matches the live registry. This checks identity pins only: not a security scan.

expect sha256:e11bd46a3d4a45c2
npx @skillerr/add info skillerr/inspect-trust
curl -sS https://skillerr.com/api/v1/skills/skillerr/inspect-trust | grep -o '"digest":"[^"]*"'

Inspect a .skill TrustView (digest, capabilities, mint status) before you run anything.

Open any sealed .skill package and render its TrustView: package digest, declared capabilities, sensitivity, mint attestation, and workflow summary. Built for humans and agents who refuse to execute uninspected packages. Pair with dry-run for a full inspect-before-run loop.

TrustView preview on skillerr.com. Install and download serve the sealed package: there is no public raw SKILL.md URL.

---
name: inspect-trust
title: Inspect Trust
description: Inspect a .skill TrustView (digest, capabilities, mint status) before you run anything.
---

# Inspect Trust

Inspect a .skill TrustView (digest, capabilities, mint status) before you run anything.

## Description

Open any sealed .skill package and render its TrustView: package digest, declared capabilities, sensitivity, mint attestation, and workflow summary. Built for humans and agents who refuse to execute uninspected packages. Pair with dry-run for a full inspect-before-run loop.

## Capabilities

- none
Public Ledger
Not anchored
published_at
2026-01-14T10:30:00.000Z
version
0.1.0
updated_at
2026-06-22T09:15:00.000Z
license
MIT
minted_at
2026-07-18T11:35:05.000Z
permanence
in registry log
digest
sha256:e11bd46a3d4a45c2cd62b8b5c9381ac4a220f2258dc4de6a95c2f7d975ce4077

Public permanence uses Sigstore Rekor. The ledger link is shown when a real logIndex was recorded at mint. Green Anchored requires an offline inclusion proof verify. Catalog claims alone never paint Anchored. Inclusion is not endorsement.