Open Protocol · Working Draft v0.8.0

Your AI agent content
deserves a MOAT.

Model for Origin Attestation and Trust

Keyless signing  ·  Logged by default  ·  Tamper-evident by design

WHAT IT COVERS

What MOAT makes verifiable.

AI agent content (skills, rules, hooks, etc.) runs inside your AI tools with direct access to your files, credentials, and context. A tampered or substituted file is a supply-chain attack with no obvious entry point. MOAT makes the chain of custody auditable before you install.

INTEGRITY

Content hasn't changed

The installed files match the hash in the signed manifest. Any modification, even a single byte, fails verification.

PROVENANCE

It came from who you think

The signing identity is tied to a GitHub Actions OIDC token. You can see exactly which repo and workflow signed it.

TRANSPARENCY

Signatures are logged

Every signature is recorded in Sigstore Rekor, a public append-only ledger. You can verify the entry independently.

COVERAGE

Skills, rules, agents, hooks

Anything a developer tool loads from a registry: SKILL.md files, CLAUDE.md rules, MCP configs, sub-agents, hooks.

01 · SIGNED

Publisher signs.

Add one GitHub Actions workflow. On push, MOAT generates a signed manifest for your content and anchors a log entry in Sigstore Rekor, before anything reaches a registry.

No key material leaves your pipeline. The signing identity is your OIDC token from GitHub Actions (nothing to rotate, nothing to store).

02 · PUBLISHED

Publisher publishes.

The signed manifest is pushed to a registry branch, which is just a regular GitHub repository. No publishing infrastructure to run. The registry picks it up from there.

03 · ATTESTED

Registry attests.

The registry verifies the publisher's manifest and adds its own attestation: what was indexed, when, and under which registry. That attestation is logged to Rekor independently of the publisher's entry.

Anyone can verify the full chain without asking either party.

04 · VERIFIED

Consumer verifies.

Run moat-verify before installing. It checks the installed files against the manifest hash and confirms both the publisher signature and the registry attestation are present in Rekor.

The dashed line in the diagram is key: moat-verify checks Rekor directly, independent of the registry. The install only proceeds on a clean chain of custody.

REFERENCE IMPLEMENTATION

MOAT in the wild.

Syllago is the reference implementation for MOAT: signed manifests, Rekor log entries, and consumer verification working end-to-end against a real registry.

IMPLEMENTATION

Reference implementation

Syllago adopted MOAT from day one: signed manifests, Rekor log entries, and a consumer-facing verification step baked into the install flow.

syllago.dev →
META REGISTRY

First publisher + registry in one

The Syllago Meta Registry is the first registry that acts simultaneously as a publisher (signing and attesting its own index) and as a registry operator serving that index to consumers.

github.com/OpenScribbler/syllago-meta-registry →

Working draft · v0.8.0

Ready to adopt MOAT.

The core spec, install-time verification script, Publisher Action, and Registry Action are complete and versioned. Broader ecosystem tooling is in progress; the spec and reference implementations are stable.