# Signed Agent Action Receipts

- id: signed-agent-action-receipts
- type: prompt
- category: agent-security
- detail: https://agents.proofandstate.com/products/signed-agent-action-receipts

## Summary
Build an evidence-bound execution system where one bounded consequential action requires transaction-specific approval, executes exactly once, is independently verified, and produces an offline-verifiable signed receipt.

## Problem
Consequential agent actions can blur proposal, approval, execution, verification, and proof into one trust boundary, making replay and false-success risks difficult to audit.

## Core outcomes
- Transaction-specific approval
- Separated proposer, authority, executor, signer, and verifier
- Exactly-once bounded mutation
- Independent state verification
- Signed receipt and offline verification
- Deterministic interrupted-execution reconciliation

## Requirements
- Node.js 22.5+ with ESM and strict TypeScript
- Git and local filesystem
- Durable SQL storage
- Separate Ed25519 approval and receipt-signing keys
- SHA-256 support
- Disposable Git repository for demonstration
- Child-process API

## Boundaries
- Protect one bounded action first rather than claiming generic tool security
- Approval and receipt-signing key material must remain separate
- Executor claims are not sufficient verification
- Development process separation is not an OS sandbox

## Tags
- agent-security
- receipts
- approval
- cryptographic-proof
- idempotency

## Canonical source
- repository: AyobamiH/agent-shop-products (main)
- payload path: products/signed-agent-action-receipts/PROMPT.md

## Not published
Price, ratings, reviews, sales figures and full PROMPT.md / SKILL.md payload bodies are not published.
