Skip to content
Back to skills

Os Signing Setup

ASecurity

Guide a human through creating the SSH signing key that authorizes the human approval gates (plan approval, code acceptance, closure): passphrase-protected key or FIDO hardware key, the allowed_signers files, the isolation status, and the interactive signing self-test, on macOS or Windows. Trigger with "set up my approval key", "create the ssh signing key", "set up signing identity", "HUMAN_PROOF_REQUIRED", "test my signing key". Never used to record decisions or advance tasks.

  • 7 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 20, 2026
ai-agentspythonrustbash

Works with

  • terminal

Security analysis

A100/100

Pro scans all 17 files and shows the line behind each finding

Scanned October 3, 2026

npx -y skills add richfrem/agent-plugins-skills --skill os-signing-setup --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Os Signing Setup?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Os Signing Setup
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/richfrem-os-signing-setup/badge)](https://www.skillsdirectory.com/skills/richfrem-os-signing-setup)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: os-signing-setup
plugin: agent-agentic-os
description: >
  Guide a human through creating the SSH signing key that authorizes the human approval gates (plan approval, code acceptance, closure):
  passphrase-protected key or FIDO hardware key, the allowed_signers files, the isolation
  status, and the interactive signing self-test, on macOS or Windows. Trigger with "set up my
  approval key", "create the ssh signing key", "set up signing identity", "HUMAN_PROOF_REQUIRED",
  "test my signing key". Never used to record decisions or advance tasks.
allowed-tools: Bash, Read
---

# OS Signing Setup (`os-signing-setup`)

Guides human operators through creating and verifying passphrase-protected or FIDO hardware SSH signing keys required for cryptographic approval gates (`APPROVED`, `VERIFY_EXIT`, `DONE`).

## Contents

- [Critical Constraints](#critical-constraints)
- [Quick start](#quick-start)
- [Workflow](#workflow)
- [Verification](#verification)
- [References](#references)

## Critical Constraints

1. **Never Run Setup Autonomously**: Key creation and self-tests require interactive human terminal prompts; agents must never run them directly.
2. **Never Touch Private Keys**: Never create, read, copy, or move private keys, and never edit `allowed_signers*`.
3. **No Automated Approvals**: Never pipe passphrases or fabricate signatures; signatures are proof of actual human presence.

## Quick start

Check signing status and key readiness:

```bash
python3 scripts/setup_ciba_identity.py --check
```

## Workflow

1. **Check Status**: Run status check to verify whether trust anchors or keys are missing.
2. **Guide Key Creation**: Provide instructions for the human to run `python3 scripts/setup_ciba_identity.py` in their own terminal.
3. **Run Self-Test**: Direct the human to execute `python3 scripts/test_signing_mechanics.py`.
4. **Inspect Results**: Advise the human based on script output and verify readiness.

## Verification

Confirm trust anchors exist and key is verified (exit code 0):

```bash
python3 scripts/setup_ciba_identity.py --check
```

## References

- [acceptance-criteria.md](references/acceptance-criteria.md) — Acceptance criteria for cryptographic approval workflows.
- [fallback-tree.md](references/fallback-tree.md) — Remediation pathways when signing checks fail.
- [isolation-setup.md](references/isolation-setup.md) — OS account isolation steps and residual risk notes.
- [os-signing-setup-guide.md](references/os-signing-setup-guide.md) — Plain-language setup guide and identity definitions.
- [SIGNING_WORKFLOW_OVERVIEW.md](references/SIGNING_WORKFLOW_OVERVIEW.md) — Cryptographic boundary architecture.

Files in this skill

  • README.md2.9 KB
  • SKILL.md4.7 KB
  • acceptance-criteria.md56 B
  • evals/evals.json751 B
  • references/SIGNING_WORKFLOW_OVERVIEW.md48 B
  • references/acceptance-criteria.md59 B
  • references/fallback-tree.md53 B
  • references/isolation-setup.md38 B
  • scripts/control_plane/__init__.py45 B
  • scripts/control_plane/identity_layout.py52 B
  • scripts/control_plane/identity_setup.py51 B
  • scripts/control_plane/isolation_check.py52 B
  • scripts/control_plane/signing_selftest.py53 B
  • scripts/control_plane/snapshot.py45 B
  • scripts/control_plane/ssh_signing.py48 B
  • scripts/setup_ciba_identity.py39 B
  • scripts/test_signing_mechanics.py42 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…