Skip to content

Ship the one skill as an attested computation, retire the placement gate - #22

Merged
PaulMRamirez merged 1 commit into
mainfrom
claude/r6-templates
Sep 20, 2026
Merged

PaulMRamirez merged 1 commit into
mainfrom
claude/r6-templates

Conversation

@PaulMRamirez

Copy link
Copy Markdown
Contributor

A computation is a skill (ADR E, docs/decisions/adr-e-a-computation-is-a-skill.md in the marketplace repository). The template's one example becomes that shape, and the placement gate leaves the workflow.

Files changed

File What changed
skills/example-workflow/scripts/example_executor.py new. Binds the one declared parameter (window, 12 to 48 trailing months), reads the data root, writes a receipt with run_id, code_sha256, bound_parameters and results, and refuses a value outside the range with a reason code and exit status 3, writing no receipt. It also owns the closed form the data root is generated from (--write-series), so there is one source of truth for the data. Standard library only.
skills/example-workflow/scripts/example_attester.py new. Takes a receipt and returns a verdict with no language model in the path: fields, code (the receipt's digest is the executor beside it), parameter, data (the series regenerated from the executor's closed form hashes to the receipt's and the committed file's digest), recompute (every number in the results) and plausible. Exit 1 on any drift.
skills/example-workflow/scripts/example_helper.py deleted. The helper it replaces computed the same kind of summary with no receipt and no attester.
skills/example-workflow/SKILL.md rewritten as the run procedure: bind values only, pass the runtime name, run the attester before quoting a number, cite the concept by path. The "Must NOT" list gains "quote a number from a receipt that has not attested PASS" and "bind an undeclared parameter or point the executor at other data".
knowledge/computations/example-workflow.md new. The Attested Computation concept in OKF v0.2 section 10 shape: type, runtime: python, one parameters entry, computation, executor.resource, executor.receipt, attester.resource, status: draft, sources. computation and attester.resource are paths relative to the concept (../../skills/example-workflow/scripts/...) and resolve to the scripts.
knowledge/references/retrieval/example-series/example_series.csv moved from verification/fixtures/, byte for byte. The data an executor reads is data, so it lives in the bundle.
knowledge/references/retrieval/example-series/SOURCES.json new. The provenance stamp: synthetic, public domain, the generator that writes it, the row count and the digest.
knowledge/index.md rewritten: what the bundle holds, a computations section listing the concept, a references section describing the data root, and sphere_scope: cross-cutting in the frontmatter, which is what lets a scaffold concept carry an empty spheres list.
knowledge/log.md one entry for the concept and its data root.
verification/example_workflow.py rewritten. The golden runs the executor on the committed data root, the attester on the receipt it wrote, the refusal on a window out of range, and the attester once more on a receipt with one number changed, which must fail. It names both scripts, which is what the new validate finding looks for.
verification/fixtures/README.md, verification/fixtures/make_fixtures.py, verification/fixtures/example_series.csv deleted. The fixture moved to the data root and its generator moved into the executor; the README's rule is now stated in the top-level README, where a copy reads it before it has a fixture of its own.
.github/workflows/plugin-gate.yml the placement-check step and the comment that described it are gone.
.github/workflows/goldens.yml the comment no longer describes the glob as what the placement gate measures, and no longer says the goldens read only verification/fixtures/.
README.md rewritten wherever it named the planes, ADR C, the placement rule or placement-check. The merge rule is now the one sentence about where files go; a new section, "The computation this template ships", describes the concept, the executor, the attester and the golden; the layout block, the delete-the-examples step and the gate list follow the new shape.
CONNECTORS.md "A connector is the REACH plane only" becomes plain words.
.osp/package.yaml the header comment's "REACH" becomes "the services it reaches".

Gate results

Run from the repository root with build-kit and nasa-daac-knowledge checked out beside it:

$ uv run ../build-kit/scripts/osp.py validate . --standalone
plugin-template: ok
osp validate: PASSED (1 repositories, 0 errors)
$ uv run ../build-kit/scripts/osp.py render . --check
plugin-template: projections current
osp render --check: PASSED (0 drifted files)
$ uv run ../build-kit/scripts/osp.py plugin-check .
plugin-template: conforms to Agent Plugins 1.0.0
osp plugin-check: PASSED (Agent Plugins 1.0.0, 0 errors)
$ uv run ../build-kit/scripts/osp.py advertise . --check --into README.md
plugin-template 0.1.0: Claude Code: Supported (development environment), Claude Cowork: Not qualified, OpenAI Codex: Not qualified, Claude Science: Outside the required matrix
osp advertise --check: PASSED (0 errors)
$ uv run ../nasa-daac-knowledge/tools/check_okf_v02.py knowledge
W4  knowledge/computations/example-workflow.md: trust tier: unverified

concepts: 1  tiers: unverified 1
errors: 0  warnings: 1
conformant with OKF v0.2 (§11); warnings above are SHOULDs, not failures
$ uv run ../nasa-daac-knowledge/tools/check_script_deps.py .
check_script_deps: 3 scripts scanned, 0 cannot resolve their own dependencies
$ uv run ../nasa-daac-knowledge/tools/check_prose.py .
check_prose: clean (24 files scanned)
$ uv run verification/example_workflow.py
attested run sha256:17eeb37112d097ad
example computation: executor, attester, refusal and tamper all behave

The one warning is the concept's trust tier, which is what a template should show: the concept ships status: draft and unsigned, and a copy signs its own computation once a steward has reviewed it. signature_check.py knowledge --report reports stable signed 0, owed 0, pending 0, untraced 0, stable unsigned 0, not stable 1. osp.py lock . --report reports the release lock stale, which it also does on main before this branch; a release commit re-runs osp.py lock.

The build-kit branch claude/r6-tools was not pushed while this was being built, so the two new validate findings could not be run against the tree. The template is built to satisfy both by construction: nothing under knowledge/ is runnable (the bundle holds one concept, one CSV and one JSON stamp), and the concept's computation and attester.resource resolve inside the package to files the golden names.

For the reviewer

Three things were decided that the brief left open, and each is worth a look.

The synthetic series moved out of verification/fixtures/ and into the bundle's data root at knowledge/references/retrieval/example-series/, and the fixtures tree was deleted rather than kept alongside. The brief said the executor reads a synthetic fixture and the attester regenerates it; keeping the fixture under verification/ would have made a skill's script read from the goldens' tree, which is the direction the placement sentence forbids. One data root, read by the executor and by the golden, is the arrangement ADR E describes, and it lets the template show what a stamped data root looks like. The cost is that the template no longer carries a worked example of the fixture-provenance rule, so that rule is now stated in prose in the README's layout section instead.

The fixture generator moved into the executor as a series() function with a --write-series mode, replacing make_fixtures.py. The attester regenerates the data from that same function, so the executor's digest covers the generator and an edit to either invalidates every earlier receipt. A separate generator would have been a second source of truth that the attester could not hash.

The golden runs a fourth case the brief did not ask for: the attester on a receipt with one number changed, which must fail. It is four lines, and without it the PASS the golden asserts would not distinguish an attester that checks from one that returns PASS.

Two files outside the brief's list were touched, because leaving them would have contradicted the record this implements: CONNECTORS.md said "A connector is the REACH plane only", and .osp/package.yaml's header comment named REACH. Both are now plain words. prove in .osp/surfaces.yaml is left alone: it is a qualification capability identifier validated against build-kit's schema, not the plane word.

Merges after ADR E (marketplace docs/decisions/adr-e-a-computation-is-a-skill.md) merges, on the coordinator's review

🤖 Generated with Claude Code

https://claude.ai/code/session_01R5XWr4m3ZmmuRqMa1yHHpi


Generated by Claude Code

A computation is a skill (ADR E in the marketplace repository's
docs/decisions). The template's one example becomes that shape.

The skill's scripts/ now holds the two halves of an attested
computation: example_executor.py binds the one declared parameter
(window, 12 to 48 trailing months), reads the data root, writes a
receipt with a run identifier, its own digest, the bound parameters
and the results, and refuses a value outside the range with a reason
code and exit status 3; example_attester.py hashes the executor,
regenerates the series from the executor's own closed form, recomputes
every number in the receipt and exits nonzero on drift, with no
language model in the path. The example helper it replaces is gone.

knowledge/computations/example-workflow.md is the Attested Computation
concept beside them, in OKF v0.2 shape: runtime, one parameter,
computation and executor.resource and attester.resource as paths
relative to the concept that resolve to the scripts, the receipt
fields, status draft and its sources. The data the executor reads
moves out of verification/fixtures/ into the bundle's data root,
knowledge/references/retrieval/example-series/, with a SOURCES.json
provenance stamp: data is knowledge, and nothing under knowledge/ is
runnable.

The SKILL.md is the run procedure: bind values only, pass the runtime
name, attest before quoting a number, cite the concept by path. The
golden runs the executor on the data root, the attester on the receipt,
the refusal, and the attester once more on a tampered receipt, which
must fail.

The gate loses the placement step and its comment; osp.py validate
covers placement now. The README says where files go in one sentence,
describes the computation the template ships, and no longer names the
planes, ADR C or the placement rule; CONNECTORS.md and the package
metadata comment lose the plane words too.

Co-Authored-By: Claude <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01R5XWr4m3ZmmuRqMa1yHHpi
Signed-off-by: Claude <noreply@anthropic.com>
@PaulMRamirez
PaulMRamirez merged commit 606fd84 into main Sep 20, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants