frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Show HN: PromptSign – Sigstore signing and verification for AI instruction files

https://promptsign.ai/
1•sergey_v•38m ago
I built PromptSign after finding some useful-looking AI skills on the Internet and realizing I couldn't really know where they came from. In particular, I could not answer:

1) Who created the skill?

2) Is what I'm invoking right now really what I installed in the first place?

3) Is this update from the same source as the original?

4) What if I only wanted to install by reputation i.e. to whitelist certain skill publishers and ignore everyone else?

AI instructions are markdown files, freely modifiable after install. The only check I could find was once at install against a digest in the marketplace manifest that the publisher controls.

In short, there was no permanent AI skill "identity".

How it works: PromptSign signs AI instruction files with Sigstore keyless signing after the author authenticates via a GitHub, Google, or Microsoft account. Sigstore issues a short-lived certificate binding that identity to an ephemeral Ed25519 key (generated locally and never written to disk). PromptSign signs a manifest of hashes for every file in the skill's directory with that key.

The manifest is signed as a Dead Simple Signing Envelope (DSSE) and sent to Rekor for public timestamping, because Sigstore certificates expire in minutes. The bundle stored alongside the skill (.promptsign directory) holds that envelope, the signing certificate, and the Rekor receipt. That bundle verifies offline, naming the publisher at any time.

For question 4 a policy file can pin a skill name pattern to a required identity and issuer. Question 3 is trust on first use (on by default): the first signer seen for a name is remembered, and a later signature from anyone else is a hard failure even when the policy is otherwise only warning.

I added Claude Code and Codex hooks to call my verifier to report any skill integrity and identity at session start and tool use time. A skill with a failing signature is blocked before use by default, which is the point of a signing tool. For OpenClaw an install policy blocks a tampered skill before it reaches disk.

Hooks can fail on unsigned skills too, rather than just report them. It's an enforce rule in the policy file, but the default is warn.

There is a 2-minute silent demo video on the site with a real terminal session, not a mockup, at https://promptsign.ai/posts/what-signing-proves. However, there is another angle: the website itself can sign and verify skills when you don't want to install anything. Signing needs network access for Sigstore login, certificate request to Fulcio, and Rekor log POST.

Note that Fulcio and Rekor don't send CORS headers, so the browser flow relays through a narrow forwarder on promptsign.ai (implemented by "promptsign proxy" CLI command). It passes GET/POST/OPTIONS to allowlisted Sigstore hosts only. File contents still never leave the tab; what transits is the manifest: relative paths and hashes.

Verification is fully offline thanks to the pinned Sigstore root in the site's JavaScript.

And now I want to say four things:

1) Signed is not a safety verdict. A malicious skill that is signed still verifies (but we'll know who did it).

2) Unsigned is not malicious, because almost the entire ecosystem is unsigned today.

3) Content scanning is still needed to tell you what the skill does.

4) The Rekor log is public. The signer's email ends up in the certificate that is permanently stored by Rekor, so that email is permanently public. The skill's filenames are not public, because Rekor stores only the SHA-256 hash of the manifest, but not manifest itself.

PromptSign is work in progress with some existing rough edges. For example, CLI binaries are not Authenticode-signed or notarized (though GitHub build-provenance attestations are there), so you'll have to bypass Windows or macOS gatekeepers to run them. Spec and code are Apache 2.0. I'd love to hear your critiques on the approach!

Usenet-Rewind

https://www.usenet-rewind.com/
1•drw•3m ago•0 comments

PCBGolf challenge: Are you better than an autorouter?

https://github.com/commaai/PCBGolf
1•adeebshihadeh•4m ago•0 comments

Show HN: Two small Chrome extensions for Hebrew text and dates

https://chaimsapps.com/
1•chaimtweiss•6m ago•0 comments

Portuguese group D3 sues Meta, TikTok and YouTube over addictive design

https://www.reuters.com/business/portuguese-group-d3-sues-meta-tiktok-youtube-over-addictive-desi...
1•nusq•8m ago•0 comments

CERN Renounces RHEL in Favor of Debian

https://www.infoq.com/news/2026/09/cern-debian-infra/
2•hilux•8m ago•0 comments

AI researcher who warned of 'disaster' is now a target of the right

https://www.washingtonpost.com/technology/2026/09/10/ai-researcher-who-warned-disaster-is-now-tar...
1•reaperducer•8m ago•0 comments

Show HN: I built Founder.best and its products now show up in AI recommendations

https://www.founder.best
1•NimeshikaP•9m ago•0 comments

Michael Levin: Ingressing Minds

https://www.mdpi.com/2409-9287/11/5/161
2•md224•11m ago•0 comments

Robinhood CEO says companies can't control how their stock is tokenized

https://www.cnbc.com/2026/09/09/robinhood-ceo-says-companies-cant-control-how-their-stock-is-toke...
2•ijidak•12m ago•0 comments

European gas prices keep climbing as IEA calls for emergency reserves

https://www.euronews.com/business/2026/09/09/european-gas-prices-keep-climbing-as-iea-calls-for-e...
1•leonidasrup•12m ago•0 comments

Vanishing Culture: A Report on Our Fragile Cultural Record [pdf]

https://blog.archive.org/wp-content/uploads/2024/10/Vanishing-Culture-2024.pdf
2•CharlesW•14m ago•0 comments

Democratizing AGI

https://cowboy.inc/blog/software-that-keeps-you-human
4•chadd•15m ago•0 comments

OpenAI pausing new $200 plan subscriptions

https://twitter.com/thsottiaux/status/2098113585683808624
5•tosh•16m ago•2 comments

Allocator Designs

https://os.phil-opp.com/allocator-designs/
1•mahirsaid•17m ago•0 comments

Show HN: Replaces the X-axis and timeline visualization in videos

https://vf.deploy.re
1•DanielHall•17m ago•0 comments

What are your plans for when Software Engineering is no longer a viable career?

2•hackersnooze1•17m ago•4 comments

Not just another mission control dashboard

https://www.npmjs.com/package/@bluearch/mission-control
1•jproctor•18m ago•1 comments

Apple's new A20 Pro smartphone chip around 25% faster than its predecessor

https://www.tomshardware.com/pc-components/cpus/apples-new-a20-pro-smartphone-chip-around-25-perc...
2•fork-bomber•20m ago•0 comments

A rant about phishing: It's not the user's fault (and not DNS either)

https://maurycyz.com/misc/domains/
1•speckx•20m ago•0 comments

AMD releases new Ryzen 5 5500F and Ryzen 5 7500 to save budget PC building

https://www.tomshardware.com/pc-components/cpus/amd-releases-new-ryzen-5-5500f-and-ryzen-5-7500-t...
2•doener•22m ago•0 comments

A remote island, these GPS hackers are preparing for an invisible war

https://www.bbc.com/future/article/20260908-inside-the-fight-to-protect-the-worlds-satellite-signals
3•PotatoNinja•22m ago•0 comments

Show HN: Nightshift – Your code gets better while you sleep

https://github.com/openslop/nightshift
2•tcbrah•23m ago•1 comments

The Global Data Center Boom Is a Gift to Spies

https://www.lawfaremedia.org/article/the-global-data-center-boom-is-a-gift-to-spies
3•hn_acker•23m ago•0 comments

Chinese AI Giants Accused of Sending User Queries to U.S. Models

https://www.wsj.com/tech/ai/chinese-ai-giants-accused-of-sending-millions-of-user-queries-to-u-s-...
3•doener•24m ago•0 comments

The Worst Are Full of Passionate Intensity: An Anthropology of AI Safety

https://twitter.com/brianchau57/status/2098035812365463637
1•MrBuddyCasino•24m ago•0 comments

Show HN: Claude Code hooks that log every tool call, 124ms per call

https://github.com/fuckbigtech-ai/homestead-memory
2•frumza•26m ago•0 comments

Can Grindr stay up during RNC conventions?

https://www.irishstar.com/news/politics/grindr-rnc-midterm-elections-convention-37648501
6•hyperhello•26m ago•0 comments

The AI policy window is open. We need to act

https://openai.com/index/ai-policy-window/
1•tosh•26m ago•0 comments

European Railway Station Index 2026

https://consumerchoicecenter.org/european-railway-station-index-2026/
1•tosh•28m ago•0 comments

A somewhat optimistic view of AI in mathematics

https://proofsandprompts.com/2026/09/10/a-somewhat-optimistic-view-of-ai-in-mathematics/
1•bearseascape•28m ago•0 comments