skill:plaud-theme/yidian-draft-pr@0.3.6

publishedlatestTIER 2shell
01

验证链

verification axis
unverified
签名身份
本站点没有读取 Sigstore bundle
unverified
Rekor 条目
没有查询透明日志
unverified
树摘要
unverified
快照时效
hub-2 · 没有 timestamp

四格全部是「未验证」,这不是加载中,也不会变:本站点是构建期渲染的静态页, 它没有 timestamp、没有 Sigstore bundle、没有内置 TUF 根, 因此 02-registry.md §6 的验证链一步都没跑。 虚线圈的意思是「我们没验」,不是「验了没过」—— 后者是圈叉,两个图形在本站点刻意不同形。 要真的验,用 CLI(它没有 --no-verify,也没有 --insecure)。

02

信任台账

provenance of this page

这一页的每个值是谁说的

source of record
签名身份
本站点未读取真验签时这里是 release.yml 的完整 identity 字符串;它与 timestamp.yml 是两个身份,精确比对、不可互换、不做前缀匹配。
OIDC issuer
本站点未读取真验签时这里是 https://token.actions.githubusercontent.com 的完整字符串。
Rekor 条目
本站点未读取透明日志是公开的:任何人都能独立取回同一条条目,不需要经过本站 —— 而本站确实没去取。
树摘要
geoly-tree-v1:sha256:09c7f0cbbf808d2dbf3b629622a0fcd3c45d610696f493aa21b2091728b6f2a1覆盖载荷全部文件的 路径 + mode + 字节。本页只是把快照里的这个值转述一遍。
$skills-hub verify skill:plaud-theme/yidian-draft-pr@0.3.6 --print-tree-digest
资产摘要
sha256:c71e035cdbdb10db5a1aaa29deb3d67ada923d86fb4a0e06b402fa1b1e7f0111skill_plaud-theme_yidian-draft-pr_0.3.6.tar.gz · 17,101 B(16.7 KiB)
$shasum -a 256 skill_plaud-theme_yidian-draft-pr_0.3.6.tar.gz
快照来源
hub-2.json(previous hub-1) · created_at 2026-09-03T02:40:47Z文件字节 sha256:65b9e90555c5934f052ec86db7e5c5ecee7dd0021989112ed99dfed79dc0e3a7 · 30,031 B(29.3 KiB)。 文件名里的编号是 2,快照内部声明的是 2(一致,但没有 timestamp 能说最新是第几张,一致只表示文件自洽)。快照里不含生成它自己的 commit SHA(那会自引用)。
Attestation
本站点未读取hub-<N>.intoto.jsonl(DSSE)是取证输入,安装链路本来就不读它;本站点也没读。它的 workflowRef 必须钉到 40 位 commit,与上面「签名身份」用的 @refs/heads/main 不是一回事,不要「统一」它们。
审批
PR #14 · 批准人 (空)
714736afbe0c63589104d5bba2a1ca8fa171b2ff
head_sha 指向投稿 PR 的 head,早于本快照存在,因此允许出现,不构成自引用。 这一栏只是快照里记下的 login 串:它证明不了「该人是维护者」「该 approve 针对的是这个 head_sha」 「approve 当前仍有效」—— 那三件事只有 GitHub 答得了。
03

出处

provenance

出处

original
author_github_id
U_kgDODu4RvA
原生投稿,没有上游仓库。
submitted_by_pr
#14
04

安装

$skills-hub install skill:plaud-theme/yidian-draft-pr@0.3.6

措辞一律是「截至 hub-2」—— 本站点没有 timestamp,说不了「现在」。

05

描述与 record 全字段

工作树载荷与快照 record 的 tree_digest 相同(本地比对,未验签)

工作树载荷重新打包出的 tree_digest 与快照 record 相等(geoly-tree-v1:sha256:09c7f0cbbf808d2dbf3b629622a0fcd3c45d610696f493aa21b2091728b6f2a1)

这只说明两串字节相同。它不是一次验签: 本页没有读 Sigstore bundle,也没有读 timestamp, 所以它证明不了这张快照是真的、也证明不了它是当前的。 上面那四格「未验证」并没有因为这一行而改变。

Enforce the yidian pull request workflow for GitHub repos. Use when a user asks to create, inspect, or prepare a PR for a yidian repo, especially requests involving cherry-picking selected commits onto a fresh PR branch (any base branch — develop, us/yidian-dev, global/yidian-dev, jp/yidian-main, us/yidian-main, main, or any other). This skill requires cherry-pick based PR branches, requires all created PRs to be Draft PRs, and requires the yidian Shopify PR body sections for summary, verification evidence, screenshots, risk, rollback, and regression matrix. It does not restrict which branch a PR targets. It does restrict which FILES reach the PR: only Shopify theme code goes in — editor/agent droppings and caches are dropped outright, and any other non-theme path (CI, repo scripts, docs, lockfiles) is confirmed with the user path by path before it stays. (来自载荷 manifest,不在快照 record 里)

快照 record 逐字段

signed fields
id
skill:plaud-theme/yidian-draft-pr@0.3.6
kind
skill
namespace
plaud-theme
name
yidian-draft-pr
version
0.3.6
path
artifacts/skills/plaud-theme/yidian-draft-pr/0.3.6
license
MIT
status
published
tree_digest
geoly-tree-v1:sha256:09c7f0cbbf808d2dbf3b629622a0fcd3c45d610696f493aa21b2091728b6f2a1
asset.file
skill_plaud-theme_yidian-draft-pr_0.3.6.tar.gz
asset.sha256
sha256:c71e035cdbdb10db5a1aaa29deb3d67ada923d86fb4a0e06b402fa1b1e7f0111
asset.size
17,101 B(16.7 KiB)
clients
claude · cursor · codex · agents载荷 manifest 声明
capabilities
TIER 2shell
capabilities 按 §7 那张表算出:Tier 2; 快照 review.capability_tier 记的是 Tier 2。 两者一致。§7 的表:none → Tier 0;network / external-tool → Tier 1;shell / credentials / writes-repo → Tier 2。 表里没有的能力名一律按最高档处理。
replaces
空数组
conflicts
空数组
owner
org · geoly-ai不可变 node id O_kgDOD7uDqA