Skip to content
Back to skills

Integration Qualification

ASecurity

Qualify an external integration against immutable release evidence and prepare a draft-only human promotion decision without deployment, spend, publication, or outreach.

  • 40 stars
  • 0 votes
  • 0 copies
  • 3 views
  • Added September 3, 2026
ai-agentsrustgosecurity

Security analysis

A100/100

Pro scans all 6 files and shows the line behind each finding

Scanned September 3, 2026

npx -y skills add rhein1/agoragentic-integrations --skill integration-qualification --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Integration Qualification?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Integration Qualification
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/rhein1-integration-qualification/badge)](https://www.skillsdirectory.com/skills/rhein1-integration-qualification)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: integration-qualification
description: Qualify an external integration against immutable release evidence and prepare a draft-only human promotion decision without deployment, spend, publication, or outreach.
---

# Integration qualification

Use this workflow when an external framework, host, protocol, or package may deserve an Agoragentic adapter or compatibility record.

1. Identify the canonical upstream project from official metadata.
2. Pin the exact stable tag, source commit, released asset name, size, URL, and independently recomputed SHA-256 digest.
3. Record release drift without changing the pin or executing a newer binary.
4. Classify levels with the prerequisite graph in `src/index.mjs`: policy and runtime both branch from source; exact requires runtime; hosted requires exact; production requires hosted. Never infer a capability from an adjacent branch.
5. Build only the minimum truthful adapter needed for the requested level.
6. Run conformance and adversarial cases at the exact evidence boundary. Verify bytes before extraction or execution.
7. Generate and verify a schema-closed, public-safe evidence packet. Require real RFC 3339 timestamps, credential-free HTTPS URLs, positive safe-integer byte counts, nonblank evidence references, own required object fields, and dense index-only arrays. Reject proxies, accessors, cycles, credentials, local identities, private paths, and provider data before hashing. The JSON Schema is structural; always require the runtime verifier because schema-only acceptance is not evidence. The generic verifier does not dereference or authenticate caller-supplied evidence references, so the integration-specific consumer must cross-bind exact expected references and digests. Inherited values or a new hash never cure malformed evidence.
8. Mark every unresolved failed or unknown observation that blocks promotion in `promotion_blockers`. Preserve supported evidence levels, but withhold candidate levels until blockers are resolved; do not relabel a security or quality blocker as an action-boundary violation.
9. Prepare a draft PR and keep promotion human-owned.
10. Record the result as verified, blocked, regressed, or `update_available` with exact evidence references.

Never treat code, fixtures, docs, generated examples, model output, CI, or a successful hash check as exact-runtime, hosted, or production evidence by itself.

Stop before credentials, paid calls, deployment, publication, outreach, public compatibility claims, wallet or settlement changes, trust changes, or ranking changes unless the owner grants separate exact authority.

Files in this skill

  • README.md5.5 KB
  • SKILL.md2.6 KB
  • package.json364 B
  • schema/evidence-packet.v1.schema.json11.3 KB
  • src/index.mjs36.2 KB
  • test/qualification.test.mjs34.1 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…