Atlas / Skills / ruvnet / Witness

WitnessCAUTION

skills/ruvnet/witness

🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native Claude Code / Codex / Hermes and many more Integrated

Verdict
CAUTION
Grade
B
Trust score
89 /100
Version
—
Hosts
—
License
MIT
Stars
73,288
01

Overview

🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native Claude Code / Codex / Hermes and many more Integrated

Read from source at commit ef7d4f0535e5OBSERVED · 2026-09-26
02

Install

Commands as the repository documents them. They are shown, not run.

npm i @noble/ed25519
03

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: witness
description: Sign, verify, and track fix-marker regressions over time using a deterministic Ed25519 witness manifest. Works in any project — clone the toolkit, run init, register fixes, regen on each release.
argument-hint: "init|regen|verify|history [...]"
allowed-tools: Bash(node *), Read, Write, Edit
---

# Witness — cryptographic fix-regression tracking

The witness toolkit lets you ship every release with a *signed* manifest
that lists every documented fix in your codebase along with a sha256 +
marker substring. Anyone with the same git commit can re-derive the
public key and verify the signature without a committed private key.

A temporal history (JSONL) tracks how the fix population evolves across
releases — so when a regression appears, you can pinpoint *the commit
that introduced it*, not just "it's broken now."

This skill works two ways:
1. **Inside ruflo** — used by ruflo's own CI to gate publishes (see
   `.github/workflows/v3-ci.yml` job `witness-verify`).
2. **In your own project** — copy `plugins/ruflo-core/scripts/witness/`
   into your repo, run `init.mjs`, register your fixes in
   `witness-fixes.json`, and call `regen.mjs` from your release pipeline.

## Quick start (any project)

```bash
# One-time bootstrap — creates verification.md.json,
# verification-history.jsonl, and witness-fixes.json template
node plugins/ruflo-core/scripts/witness/init.mjs --root .

# Edit witness-fixes.json: add { id, desc, file, marker } per fix.
# A "marker" is a distinctive substring that MUST appear in `file`
# while the fix is present. If someone reverts the fix, the marker
# disappears and `verify` reports it as `regressed`.

# Regenerate the manifest (signing requires @noble/ed25519)
npm i @noble/ed25519
node plugins/ruflo-core/scripts/witness/regen.mjs \
  --manifest verification.md.json \
  --history verification-history.jsonl \
  --fixes witness-fixes.json

# Verify markers are present in the live tree
node plugins/ruflo-core/scripts/witness/verify.mjs \
  --manifest verification.md.json

# Or authenticate the manifest and check source markers in a clean clone.
# Generated dist/ entries are explicitly reported as skipped.
node plugins/ruflo-core/scripts/witness/verify.mjs \
  --manifest verification.md.json --source-only
```

## Temporal queries (ADR-103)

```bash
# Latest snapshot vs. previous
node plugins/ruflo-core/scripts/witness/history.mjs \
  --history verification-history.jsonl summary

# For each currently-regressed fix, find the commit that introduced it
node plugins/ruflo-core/scripts/witness/history.mjs \
  --history verification-history.jsonl regressions

# Status timeline for a specific fix
node plugins/ruflo-core/scripts/witness/history.mjs \
  --history verification-history.jsonl timeline --id F1

# Machine-readable for CI
node plugins/ruflo-core/scripts/witness/history.mjs \
  --history verification-history.jsonl summary --json
```

`summary` exits non-zero if any fix newly regressed since the last
snapshot — drop it in CI as a soft pre-merge gate.

## Anti-patterns

- **Hand-editing `verification.md.json`** — always regenerate via `regen.mjs`,
  otherwise the signature breaks.
- **Markers that are too generic** (`'function'`, `'import'`) — pick something
  unique enough that `grep` doesn't false-positive against unrelated code.
- **Skipping the history append** — without `--history`, you lose the
  ability to bisect when a regression was introduced.
- **Committing one without the other** — `verification.md.json` and
  `verification-history.jsonl` belong in the same commit; the JSONL is
  what lets future you verify the signed manifest is the latest in the line.

## Files

- `scripts/witness/lib.mjs` — shared regenerate / history logic.
- `scripts/witness/regen.mjs` — CLI: sign + append history.
- `scripts/witness/history.mjs` — CLI: query the temporal log.
- `scripts/witness/init.mjs` — CLI: bootstrap into a fresh project.
- `scripts/witness/verify.mjs` — CLI: validate signature + markers.

## In ruflo's CI

`v3-ci.yml` job `witness-verify` runs after the behavioral smoke tests
and before `publish`. Failure modes:

| Failure | Cause |
|---|---|
| `signatureValid: no` | manifest hand-edited; re-run regen |
| `regressed: > 0` | a documented fix lost its marker since issuance |
| `missing: > 0` | a cited dist file no longer exists; rebuild or remove the entry |
| `scope: source-only` | signature + source markers checked; generated entries intentionally skipped |
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeNA
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (4)

MEDIUMInventory / provenance · inv.symlink · CWE-1104
crates
crates
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
plugin/agents
plugin/agents
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
plugin/commands
plugin/commands
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
plugin/skills
plugin/skills
Why it matters. link not followed

Gates applied: no_behavioural_pass.

Audited 2026-09-26 · audit v0.4.1 · source sha ef7d4f0535e5full audit observations/trust-audit/skill/ruvnet__witness.json · Report an issue / request a re-scan
05

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-09-26ef7d4f0535e5CAUTIONB89first audit
06

Questions

What does the Witness skill do?

🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native Claude Code / Codex / Hermes and many more Integrated

Is Witness safe to install?

With care. The audit graded it B (89/100) and found 4 things worth knowing before you trust this skill, listed below with the exact line each was found on.

What can Witness access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

How current is this page?

The grade is for one exact copy of the source (ef7d4f0535e5), read on 2026-09-26. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement