Get started
StandardsSkillRightsProvenanceEvidenceBitcoinSkills

You wrote the skill. Can you prove it?

Anyone can claim they wrote a skill. Far fewer can prove they had this exact file, signed, before a certain date. Here is how to produce that evidence in about a minute, and how anyone can check it against Bitcoin without trusting us.

Adam Cowles12 September 20267 min read
A skill file resolving through a chain of hashes into a single block, lit like a sealed stamp

Claiming is cheap. Proving is the whole game.

Picture the argument you do not want to have. A skill you wrote, the compressed version of how you actually do your job, turns up inside someone else's pack with their name on it. Or the reverse: someone accuses you of lifting theirs. The files are nearly identical, because good methodology converges. So the question is not whose skill is better. It is a narrower, colder one:

Who can show they had this exact file, first?

Most people cannot answer that. A file's modification date is trivially forged. A commit can be back-dated. A screenshot proves nothing. If it ever came to it, you would be reaching for circumstantial scraps. This is a worked example of how to have the real thing instead, produced in about a minute, and checkable by anyone without taking your word for it or ours.

Be precise about what "prove it" means

Provenance is a strong tool and a narrow one. It is worth stating exactly what it does and does not establish, because a claim that overreaches is worse than none.

What you can prove: that this exact file (by its cryptographic hash) existed no later than a specific moment, that it was signed by a particular key, and where it sits in order relative to other registrations. Dated existence, integrity, a signer, and sequence.

What you cannot prove this way, and nobody can with a timestamp: that you are the legal owner, the original author, or that the idea is yours rather than convergent. A signature binds the bytes to a key, not the key to a person. Those are separate questions, settled by separate evidence.

That boundary is the point, not a caveat bolted on. In almost every real dispute about copied work, the thing you are missing is not a philosophical claim to authorship. It is dated, tamper-evident evidence that you held this artefact before the other party did. That is precisely what the steps below give you.

The minute of work

Start with the skill you already have. Declare its terms in one line of its existing frontmatter, then sign it with the SSH key you already own.

# one line in SKILL.md frontmatter
license: LicenseRef-SkillRights-NoTrain-1.0

# sign the folder with your existing ed25519 SSH key
skillrights sign ./cluster-doctor

Signing produces a manifest: the hash of every file, and a signature over it made with your key. That already gives you a local, tamper-evident record. Change one character of the skill afterwards and verification fails.

Then register it. This sends only evidence, the hash, your signature, the licence, the claimed author, to a public append-only log. The skill's content never leaves your machine.

skillrights register ./cluster-doctor --public
# Registered: sr:skill:01M2...
# Receipt:    ./cluster-doctor/.skillrights.receipt.json

You get back a permanent identifier and a receipt file. The receipt is the artefact that matters, so it is worth understanding what is inside it.

The receipt is the point

The log is a Merkle tree: every registration is a leaf, and the leaves hash together, in pairs, up to a single root. The receipt contains a short inclusion proof, the handful of hashes that let anyone recompute the root from your leaf alone. That is pure arithmetic. It needs no server and no trust.

On its own, that proves your file sits in the log. The step that makes the receipt outlive us is anchoring. Periodically the current root is submitted to the public OpenTimestamps calendars, which batch it into a Bitcoin transaction. Once that transaction is mined, the root is written permanently into a Bitcoin block. A fresh registration reads as pending for a few hours until that confirmation lands; after it does, you fold the Bitcoin proof into your own receipt:

skillrights receipt --upgrade ./cluster-doctor
# Anchored: this receipt now verifies against Bitcoin block 966403.
# It no longer needs the registry to prove it.

Now the receipt is self-contained. It carries the chain from your file all the way to a Bitcoin block, and it needs nothing from Quox to check.

The chain, and why it survives us

Four links connect your file to the blockchain, and only the last one touches Bitcoin:

  • Your file hashes to a leaf. You recompute it from the folder on your disk.
  • The leaf hashes up to a Merkle root, via the inclusion proof in the receipt. Arithmetic, no signature.
  • The root is committed into a named Bitcoin block by the OpenTimestamps proof embedded in the receipt.
  • The block is real, confirmed by Bitcoin. Not by us.

Our signing key appears nowhere in that chain. That is deliberate. If Quox vanished tomorrow, the receipt in your hands plus the public Bitcoin blockchain would still establish that your file existed by the time that block was mined. We are convenient, not load-bearing.

You can watch it hold with the registry switched off entirely:

skillrights receipt --offline ./cluster-doctor
# Bitcoin: anchored in block 966403 (verified offline, no registry needed).

That confirms every link except the last one: that the Bitcoin block itself is genuine. For that, you go to Bitcoin directly, which is the next step.

Checking it without trusting anyone

A proof only helps in a dispute if the other side, or an arbiter, can verify it without believing either of you. This one can, using tools that have nothing to do with SkillRights.

Extract the raw OpenTimestamps proof from the receipt, then read it with the independent OpenTimestamps client and confirm the block on any explorer:

skillrights receipt --extract-ots ./cluster-doctor

# with the independent OpenTimestamps client (pip install opentimestamps-client)
ots info sr_skill_01M2....ots
#   verify BitcoinBlockHeaderAttestation(966403)
#   # Bitcoin block merkle root 97dc58699ea1d8ec03ef9620eb0a49f580fe4227ea52d10b822d8baf36381531

Then open block 966403 on mempool.space and read its merkle root. It is that same value. Three independent sources, the log, the OpenTimestamps proof, and the Bitcoin blockchain, and one answer. None of them is us.

That exact example is live and real: it is the first entry in the public log. If you want the full walkthrough with the commands and the sources laid out step by step, it lives at skillrights.org/verify.

What this is not

Worth repeating the honest limits, because the value is in the precision.

A receipt does not stop anyone copying your skill. It is evidence, not a fence. It does not settle the open legal questions about training and fair use, which no timestamp can. It does not prove you are the original author or the rightful owner; it proves you held this exact file, signed, by a certain date. And it will not, by itself, win a case. What it does is give you the one thing that circumstantial arguments about copied work almost always lack: dated, tamper-evident, independently checkable evidence of exactly when you held it. In a world where claiming is free, being the party who can produce that is not a small advantage.

Norms tend to arrive before enforcement. robots.txt governed crawlers on convention for decades before any law cited it. Dated, portable evidence of what you held and when is the kind of thing that matters more, not less, as the rules around AI and training harden.

This is the second half of an argument. The first part makes the case that executing a skill should not silently license training on it. This part is the receipt: how you turn that stance into evidence you can actually hold up.

We hit all of this while building QuoxSkills, which makes skills portable between agents like Claude and Codex. If expertise is going to travel, the proof of who held it, and when, has to travel with it. The signing, registration and verification above are free and open at skillrights.org, with no account and nothing of ours required to check a receipt, permanently.

Quox builds evidence-first infrastructure for AI agents. SkillRights is free and open at skillrights.org; verify any receipt yourself at skillrights.org/verify.