Agent instruction file integrity seal
Seal agent instruction files and verify them so developers and hosts only pass approved content to models.
What it is
An integrity seal for instruction files (Markdown and configured instruct formats — AGENTS.md, skills, policy docs you keep next to code): a BLAKE3 content digest in YAML front matter. You verify that seal before agents or CI use the file. Optional GPG signature attests who sealed it (same settings as git commit -S).
This answers: Is this still the instruction text I sealed?
It does not claim legal authorship, replace code review, or guarantee how a model will behave — only that the file contents match the seal. It proves that instructions have not been altered or changed since it was shipped.
Why use it
- Stop silent prompt edits — multi-agent workflows and shared repos rewrite instructions; check fails with path + digests.
- Gate model input — fail the pipeline or refuse the agent run when seals break.
- Same check everywhere — CLI, tiny binary, browser extension, and zero-dep SDKs share official vectors.
- Clear failures — every non-OK path is listed (no silent exit-only fails).
- End User Support - Verify that what the user is running still matches what you shipped and that the user hasn’t customized anything when troubleshooting anomalies in agent execution.
How it works
- Canonicalize document content (format details).
- Write
hashseal: "blake3:<hex>"into front matter (seal fields excluded from the hash). - Optionally add
hashseal_sigvia--sign. - Before use: recompute digest; compare; report status per file.
hashseal seal --instruct [--sign]
hashseal check [--require-signature]
What does it do to my instruction files?
It adds a single line to the YAML Front Matter of your instruction files:
For example:
hashseal: "blake3:52fdb937b7c8e46f94723ea84eab22a4aff20830d2a9c9f62452536591c1d6cc"
How to use it in your projects
1. Install the CLI
Package and binary are both named hashseal:
cargo build -p hashseal --release
# or cargo install --path rust/hashseal --locked
See Install.
2. Seal instructions
hashseal seal --instruct --root .
hashseal seal --instruct --sign --root . # GPG via git config
By default this seals agent instruction files only (for example AGENTS.md, CLAUDE.md, Copilot/Cursor rules, and common agent skill/command directories) — not every README.md or docs page. Override with document.include / document.exclude in .hashseal.json (see CLI config).
3. Check before agents / models
hashseal check --root .
# optional tiny binary (blake3-only deps):
hashseal-check --root .
4. Or check in-process (no CLI)
Use a verify SDK in your language so CI or a host can validate Markdown without spawning a process.
5. Optional surfaces
| Surface | Use when |
|---|---|
| Browser extension | Paste-check instructions in the browser |
| VS Code / IDE | Seal/check from the editor |
| Agent skills | Teach agents to respect sealed files |
| Signing | Require cryptographic attestation |
Docs in this section
| Page | Topic |
|---|---|
| Seal format | Front matter, canonical modes, chicken-and-egg |
| Verify SDKs | JS, Python, Java, Go, Ruby, .NET + vectors |
| CLI | seal --instruct, check, unseal |
| Signing | GPG / git key settings |
Related (build line)
Tree ledgers and CI plugins live under Build tools — same core algorithms, different object (directory vs document).
Copyright (c) 2026 MonkeyKing.dev