Open Protocol · Working Draft v0.8.0
Model for Origin Attestation and Trust
Keyless signing · Logged by default · Tamper-evident by design
WHAT IT COVERS
AI agent content (skills, rules, hooks, etc.) runs inside your AI tools with direct access to your files, credentials, and context. A tampered or substituted file is a supply-chain attack with no obvious entry point. MOAT makes the chain of custody auditable before you install.
The installed files match the hash in the signed manifest. Any modification, even a single byte, fails verification.
The signing identity is tied to a GitHub Actions OIDC token. You can see exactly which repo and workflow signed it.
Every signature is recorded in Sigstore Rekor, a public append-only ledger. You can verify the entry independently.
Anything a developer tool loads from a registry: SKILL.md files, CLAUDE.md rules, MCP configs, sub-agents, hooks.
Add one GitHub Actions workflow. On push, MOAT generates a signed manifest for your content and anchors a log entry in Sigstore Rekor, before anything reaches a registry.
No key material leaves your pipeline. The signing identity is your OIDC token from GitHub Actions (nothing to rotate, nothing to store).
The signed manifest is pushed to a registry branch, which is just a regular GitHub repository. No publishing infrastructure to run. The registry picks it up from there.
The registry verifies the publisher's manifest and adds its own attestation: what was indexed, when, and under which registry. That attestation is logged to Rekor independently of the publisher's entry.
Anyone can verify the full chain without asking either party.
Run moat-verify before installing. It checks the installed files
against the manifest hash and confirms both the publisher signature and the
registry attestation are present in Rekor.
The dashed line in the diagram is key: moat-verify checks Rekor
directly, independent of the registry. The install only proceeds on a clean
chain of custody.
REFERENCE IMPLEMENTATION
Syllago is the reference implementation for MOAT: signed manifests, Rekor log entries, and consumer verification working end-to-end against a real registry.
Syllago adopted MOAT from day one: signed manifests, Rekor log entries, and a consumer-facing verification step baked into the install flow.
syllago.dev →The Syllago Meta Registry is the first registry that acts simultaneously as a publisher (signing and attesting its own index) and as a registry operator serving that index to consumers.
github.com/OpenScribbler/syllago-meta-registry →Working draft · v0.8.0
The core spec, install-time verification script, Publisher Action, and Registry Action are complete and versioned. Broader ecosystem tooling is in progress; the spec and reference implementations are stable.