{"id":"7d470ad3-9d7c-43f5-9164-11a928764fef","entityType":"agent","slug":"verseagent-provenance-skill","name":"provenance","canonicalUrl":"https://www.xpersona.co/agent/verseagent-provenance-skill","canonicalPath":"/agent/verseagent-provenance-skill","generatedAt":"2026-10-09T11:51:00.098Z","source":"GITHUB_OPENCLEW","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-04-15T05:21:22.124Z","emptyReason":null},"description":"Track where information came from. Mark sources, verify trust, quarantine untrusted content. Essential for agents operating in multi-agent environments. --- name: provenance description: Track where information came from. Mark sources, verify trust, quarantine untrusted content. Essential for agents operating in multi-agent environments. metadata: { \"openclaw\": { \"emoji\": \"🔍\", \"requires\": { \"bins\": [\"sqlite3\", \"jq\"] } } } --- Provenance A skill for agents who need to know where information comes from. The Problem In multi-agent environments like Moltbook, content en","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1 GitHub stars reported by the source. Last updated 4/15/2026.","installCommand":"git clone https://github.com/verseagent/provenance-skill.git","sourceUrl":"https://github.com/verseagent/provenance-skill","homepage":null,"primaryLinks":[{"label":"View Source","url":"https://github.com/verseagent/provenance-skill","kind":"source"}],"safetyScore":94,"overallRank":30.9,"popularityScore":8,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Track where information came from. Mark sources, verify trust, quarantine untrusted content. Essential for agents operating in multi-agent environments. --- nam"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-04-15T05:21:22.124Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[{"label":"be","status":"self-declared"},{"label":"mark","status":"self-declared"}],"verifiedCount":0,"selfDeclaredCount":3,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"},{"key":"be","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"},{"key":"mark","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile capability:be|supported|profile capability:mark|supported|profile"}},"adoption":{"evidence":{"source":"GITHUB OPENCLEW","verified":false,"confidence":"medium","updatedAt":"2026-04-15T05:21:22.124Z","emptyReason":null},"stars":1,"forks":0,"downloads":null,"packageName":null,"latestVersion":null,"tractionLabel":"1 GitHub stars"},"release":{"evidence":{"source":"agent-index","verified":false,"confidence":"medium","updatedAt":"2026-04-14T22:24:26.845Z","emptyReason":null},"lastUpdatedAt":"2026-04-15T05:21:22.124Z","lastCrawledAt":"2026-04-14T22:24:26.845Z","lastIndexedAt":null,"nextCrawlAt":"2026-04-15T22:24:26.845Z","lastVerifiedAt":null,"highlights":[]},"execution":{"evidence":{"source":"GITHUB OPENCLEW","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"git clone https://github.com/verseagent/provenance-skill.git","setupComplexity":"low","setupSteps":["Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/verseagent-provenance-skill/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/verseagent-provenance-skill/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/verseagent-provenance-skill/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/verseagent-provenance-skill/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/verseagent-provenance-skill/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/verseagent-provenance-skill/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"GITHUB_OPENCLEW","generatedAt":"2026-10-09T11:51:00.098Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/verseagent-provenance-skill/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/verseagent-provenance-skill/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/verseagent-provenance-skill/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/verseagent-provenance-skill/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"GITHUB OPENCLEW","verified":false,"confidence":"high","updatedAt":"2026-04-15T05:21:22.124Z","emptyReason":null},"readme":"---\nname: provenance\ndescription: Track where information came from. Mark sources, verify trust, quarantine untrusted content. Essential for agents operating in multi-agent environments.\nmetadata: { \"openclaw\": { \"emoji\": \"🔍\", \"requires\": { \"bins\": [\"sqlite3\", \"jq\"] } } }\n---\n\n# Provenance\n\nA skill for agents who need to know where information comes from.\n\n## The Problem\n\nIn multi-agent environments like Moltbook, content enters your context from everywhere:\n- Posts from unknown agents\n- Data from external APIs\n- Content that's been passed through multiple systems\n\nOnce content is in context, you can't tell where it came from. This creates vulnerabilities:\n- Prompt injection attacks hidden in seemingly innocent content\n- Time-shifted payloads that assemble across multiple interactions\n- Social engineering through fabricated authority\n\n## What This Skill Does\n\nProvenance tracks the origin and trust level of content:\n\n- **Source marking**: Tag content with where it came from\n- **Trust policies**: Define rules for which sources to trust\n- **Quarantine**: Isolate content that fails trust checks\n- **Audit trail**: See the full custody chain of any piece of content\n\n## Commands\n\n### /mark-source <id> <source> [trust-level]\nMark content with its provenance. Trust levels: trusted, untrusted, unknown (default: unknown).\n\n```\n/mark-source msg-123 \"moltbook:@randomagent\" untrusted\n/mark-source doc-456 \"internal:collaborator\" trusted\n/mark-source api-789 \"external:weather-api\" unknown\n```\n\n### /check-provenance <id>\nSee the full provenance record for content.\n\n```\n/check-provenance msg-123\n```\n\nReturns: source, trust level, timestamp, any custody chain.\n\n### /trust-policy <add|remove|list> [pattern] [trust-level]\nManage trust policies. Patterns use glob matching.\n\n```\n/trust-policy add \"internal:*\" trusted\n/trust-policy add \"moltbook:*\" untrusted\n/trust-policy add \"api:weather*\" trusted\n/trust-policy list\n/trust-policy remove \"moltbook:*\"\n```\n\n### /quarantine <id> [reason]\nMove content to quarantine. Quarantined content is tracked separately.\n\n```\n/quarantine msg-123 \"Suspected prompt injection\"\n```\n\n### /quarantine-list\nSee all quarantined content with reasons.\n\n```\n/quarantine-list\n```\n\n### /verify-trust <id>\nCheck if content passes current trust policies.\n\n```\n/verify-trust msg-123\n```\n\nReturns: pass/fail and which policy matched.\n\n## Architecture\n\nProvenance uses SQLite for persistence, creating a database at `~/.provenance/trust.db`. Tables:\n\n- `content`: id, source, trust_level, marked_at, custody_chain\n- `policies`: pattern, trust_level, created_at\n- `quarantine`: content_id, reason, quarantined_at\n\n## Philosophy\n\n1. **Track everything**: Better to have provenance you don't need than need it and not have it\n2. **Default untrusted**: Unknown sources should be treated as untrusted until verified\n3. **Policies over judgment**: Explicit rules prevent in-the-moment trust decisions\n4. **Quarantine, don't delete**: Quarantined content can be reviewed, deleted content is gone\n\n## When To Use This Skill\n\n- When ingesting content from external sources (APIs, other agents, web)\n- Before acting on information that could be fabricated\n- When operating in multi-agent environments like Moltbook\n- When you need audit trails for compliance or debugging\n\n## Security Note\n\nThis skill helps you track provenance, but it can't verify that marked sources are authentic. If an attacker controls the marking process, they can mark malicious content as trusted. Use this as one layer of defense, not your only protection.\n","readmeExcerpt":"--- name: provenance description: Track where information came from. Mark sources, verify trust, quarantine untrusted content. Essential for agents operating in multi-agent environments. metadata: { \"openclaw\": { \"emoji\": \"🔍\", \"requires\": { \"bins\": [\"sqlite3\", \"jq\"] } } } --- Provenance A skill for agents who need to know where information comes from. The Problem In multi-agent environments like Moltbook, content en","codeSnippets":[],"executableExamples":[{"language":"text","snippet":"/mark-source msg-123 \"moltbook:@randomagent\" untrusted\n/mark-source doc-456 \"internal:collaborator\" trusted\n/mark-source api-789 \"external:weather-api\" unknown"},{"language":"text","snippet":"/check-provenance msg-123"},{"language":"text","snippet":"/trust-policy add \"internal:*\" trusted\n/trust-policy add \"moltbook:*\" untrusted\n/trust-policy add \"api:weather*\" trusted\n/trust-policy list\n/trust-policy remove \"moltbook:*\""},{"language":"text","snippet":"/quarantine msg-123 \"Suspected prompt injection\""},{"language":"text","snippet":"/quarantine-list"},{"language":"text","snippet":"/verify-trust msg-123"}],"parameters":{},"dependencies":[],"permissions":[],"extractedFiles":[],"languages":["typescript"],"docsSourceLabel":"GITHUB OPENCLEW","editorialOverview":"Track where information came from. Mark sources, verify trust, quarantine untrusted content. Essential for agents operating in multi-agent environments. --- name: provenance description: Track where information came from. Mark sources, verify trust, quarantine untrusted content. Essential for agents operating in multi-agent environments. metadata: { \"openclaw\": { \"emoji\": \"🔍\", \"requires\": { \"bins\": [\"sqlite3\", \"jq\"] } } } --- Provenance A skill for agents who need to know where information comes from. The Problem In multi-agent environments like Moltbook, content en","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":362,"uniquenessScore":66,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-04-15T05:21:22.124Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-04-15T05:21:22.124Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-09T11:51:00.098Z","emptyReason":null},"items":[{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-10T18:48:31.762Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/github_openclew","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}