shipping-artifacts skillA
shipping-artifacts is agent-read markdown (skill) from sathiaai/adversarial-review: Every claim ships with the artifact that proves it — test output, a run dir, an attestation, a review verdict. Use when finishing a change or asserting that something works..
Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.
What the file says
# Shipping artifacts A claim without an artifact a skeptic would accept is an opinion. This project's whole premise is "is this change correct?" answered with *evidence*, not model self-assurance — so hold yourself to the same bar. ## The rule When you assert something is done, correct, safe, or passing, attach the artifact that lets someone else confirm it **without rerunning your reasoning**: | Claim | Artifact that ships with it | |---|---| | "Tests pass" | The suite's `N passed, M failed` line, and — for a change that could regress others — the byte-identical fail-set vs the base branch (prove the deltas are yours or nobody's). | | "No regressions" | A baseline run of the *unchanged* base plus your run; a diff of the two fail-sets. | | "The verdict is X" | The run dir under `.adversarial-review/` — the immutable audit record — and the `aggregate.py`-computed `verdict.json`, never a hand-authored verdict. | | "It's tamper-evident" | The `compute_attestation()` digest (and a detached signature when `--sign` is used). | | "It was reviewed" | The adversarial-review run's verdict, attached to the PR, at the stated tier. | …
Read the whole file at its exact version.
How to install
mdr add sathiaai/adversarial-review/shipping-artifacts@git:20260910.c480f23mdr add sathiaai/adversarial-review/shipping-artifacts@sha256:2579bad57ecdd3e3Pin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.
[](https://markdownregistry.com/a/art_5a7avhx2j5obvanp)
1 badge views in 30 days
Versions
| version | committed | commit | size | audit | |
|---|---|---|---|---|---|
| git:20260910.c480f23 latest | 2026-09-10 | c480f23 | 2,693 B | A | view · diff |
| git:20260910.3ea871a | 2026-09-10 | 3ea871a | 2,386 B | A | view |
Audit of the latest version
- pass: Frontmatter block present
- pass: Frontmatter declares a name
- pass: Frontmatter declares a description
- pass: Size between 200 bytes and 200 KB (2693 bytes)
- pass: No zero-width or bidi control characters
- pass: No instruction hidden inside an HTML comment
- pass: No link to an exfiltration or paste host
- pass: No credential-shaped string
- pass: No instruction to send local credentials anywhere
- pass: No text hidden with inline styles
- pass: No prompt-injection phrasing
- pass: No curl or wget piped into a shell
- pass: No recursive delete of root, home or parent
- pass: No instruction to read or print local credentials
- pass: No base64 blob over 200 characters
- pass: No link to a raw IP address
- pass: No script tag
Source
sathiaai/adversarial-review · 3 stars · license MIT · pushed 2026-09-23 · branch main
API
GET https://markdownregistry.com/api/v1/artifacts/art_5a7avhx2j5obvanp GET https://markdownregistry.com/api/v1/resolve?ref=sathiaai/adversarial-review/shipping-artifacts GET https://markdownregistry.com/api/v1/blob/2579bad57ecdd3e3500197e5366b163fab10245edb7e2eba2ae6ea95188e5db1
Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.