Finish the Loop
Treat completion as a claim that needs evidence from the intended target.
- Read
WORKFLOW.jsonand create.skdd/runs/<run-id>/state.jsonbefore changing the system. - Pin each acceptance line to an explicit target tuple: environment, resource, and revision. Do not let the executor silently choose or revise the target.
- Record the executor identity and credential scope.
- Reproduce, change, and drive the real artifact. Keep the run state resumable after interruption.
- Collect evidence with a provider that has a different identity and credential scope from the executor. A test run by the same process is useful feedback, but it is not independent proof.
- Emit
receipt.jsonusing the proof-receipt schema. Bind the skill bytes and each acceptance contract with SHA-256 digests. - Run
skdd proof verify receipt.json --skill SKILL.md. - Report
verifiedonly when the verifier passes. Otherwise report the reason codes and leave the looprefused,blocked, oropen.
Never translate “the build passed” into “the user-visible outcome works.” Evidence must match the acceptance target exactly.