Trust Signals
Provenance is **mandatory** in v0.2. Every stage run records:
v0.4.0concept
Trust signals (v0.2)
Provenance is mandatory in v0.2. Every stage run records:
{
"stage_id": "refactor",
"started_at": "2026-09-15T12:34:56.789Z",
"completed_at": "2026-09-15T12:35:01.234Z",
"duration_ms": 4445,
"model_used": "claude-3.5-sonnet",
"uses": [
{
"id": "code_rewriter",
"version": "0.2.1",
"version_pin": "strict",
"content_hash": "keccak256:9a4f...",
"fetched_at": "2026-09-15T12:34:57.000Z"
}
],
"mcp_servers_validated": [],
"input_sha256": "f4c1...",
"output_sha256": "a92d...",
"output_format": "code",
"output_format_validated": true,
"cost_micro_usdc": 12650,
"tokens": { "input": 1234, "output": 567 }
}
Pipeline-level provenance (top-level payload) aggregates:
{
"pipeline_name": "bobs-code-refactor",
"pipeline_version": "1.2.0",
"spec_hash": "keccak256:7e3b...",
"inputs_hash": "keccak256:c1f0...",
"outputs_hash": "keccak256:8ab2...",
"ts": "2026-09-15T12:35:01.234Z",
"stages": [ ... StageExecutionRecord[] ... ]
}
This entire payload is signed with the operator’s secp256k1 key (EIP-191) — buyers can verify reproducibility and that no SKILL was substituted. v0.3 will add TEE attestation alongside operator signature.