Agent skill

witness

Sign, verify, and track fix-marker regressions over time using a deterministic Ed25519 witness manifest. Works in any project — clone the toolkit, run init, register fixes, regen on each release.

rUv71,307★ · +1,002/wk · 3 repos on radarProfile →
claude-codecodexcan modify filesMIT
Install
npx skills add ruvnet/ruflo --skill witness --agent claude-code

Same command for any agent — swap --agent for codex, cursor, copilot.

Facts
Files in the skill folder: 1
SKILL.md size: 4 KB
Bundled scripts: none
Allowed tools: Bash(node*)ReadWriteEdit
Path: plugins/ruflo-core/skills/witness/SKILL.md
Open the folder on GitHub →
Where it comes from
Source: ruvnet/ruflo
Stars: 67,015 · +629 this week
Language: TypeScript
Read our review of the source →

Weekly change comes from our own snapshots, not the repository page — it measures attention, not adoption.

From the SKILL.md

# Witness — cryptographic fix-regression tracking The witness toolkit lets you ship every release with a *signed* manifest that lists every documented fix in your codebase along with a sha256 + marker substring. Anyone with the same git commit can re-derive the public key and verify the signature without a committed private key. A temporal history (JSONL) tracks how the fix population evolves across releases — so when a regression appears, you can pinpoint *the commit that introduced it*, not just "it's broken now." This skill works two ways: 1. **Inside ruflo** — used by ruflo's own CI to gate publishes (see `.github/workflows/v3-ci.yml` job `witness-verify`). 2. **In your own project** — copy `plugins/ruflo-core/scripts/witness/` into your repo, run `init.mjs`, register your fixes in `witness-fixes.json`, and call `regen.mjs` from your release pipeline. ## Quick start (any project) ```bash # One-time bootstrap — creates verification.md.json, # verification-history.jsonl, and witness-fixes.json template node plugins/ruflo-core/scripts/witness/init.mjs --root . # Edit witness-fixes.json: add { id, desc, file, marker } per fix. # A "marker" is a distinctive substring that MUST appea

What's inside
Steps it walks through
  1. Quick start (any project)
  2. Temporal queries (ADR-103)
  3. Anti-patterns
  4. Files
  5. In ruflo's CI
Commands it runs
One-time bootstrap — creates verification.md.json,
node plugins/ruflo-core/scripts/witness/init.mjs --root .
Edit witness-fixes.json: add { id, desc, file, marker } per fix.
A "marker" is a distinctive substring that MUST appear in `file`
while the fix is present. If someone reverts the fix, the marker
disappears and `verify` reports it as `regressed`.
Regenerate the manifest (signing requires @noble/ed25519)
npm i @noble/ed25519
node plugins/ruflo-core/scripts/witness/regen.mjs \
Verify markers are present in the live tree
More from ruflo
All skills →
About this skill
What does the witness skill do?

Sign, verify, and track fix-marker regressions over time using a deterministic Ed25519 witness manifest. Works in any project — clone the toolkit, run init, register fixes, regen on each release.

How do I install it?

Run `npx skills add ruvnet/ruflo --skill witness --agent claude-code` — it drops the skill into your project so the agent can pick it up. Swap the --agent value for codex, cursor or copilot if you use one of those.

Where does this skill come from?

From ruvnet/ruflo, a repository with 67,015 stars. We read it straight from the repository tree rather than a submitted listing, so what you see here is what is actually published.

Is a popular skill a good skill?

Not necessarily. Stars measure attention, not adoption — a repository can trend for a week and be abandoned. That is why we show the weekly change from our own snapshots next to the total, instead of a single flattering number.

Keep going