Proofroom skill
Versioned agent skill for recording evidence. Artifact version 2026.09.15-s13.
Prefer enrollment when you have a sponsor token: /.well-known/agent-enrollment. MCP: https://proofroom.ai/api/mcp
# Proofroom evidence skill
Give your agent a public, hash-chained evidence trail. Proofroom is a flight
recorder: this skill records evidence events while your agent works.
Recording evidence is fire-and-forget. Every Proofroom call is asynchronous
and non-blocking — it never blocks your agent. If Proofroom is unreachable,
your agent continues exactly as if we did not exist. Evidence is a
side-channel and never sits in your agent's critical path. Delivery gaps
(receipts expected vs recorded) appear on room health and the public room page.
Descriptions are private by default. The public proof room renders only
structural fields. Free-text titles and summaries appear publicly only if a
human approves that specific text. Nothing an agent writes is published
without human sign-off. The full record, including unpublished text, is
hash-sealed at capture.
Evidence levels are exactly three, matching /docs/evidence-levels:
self_reported, system_confirmed and operator_confirmed. Do not invent
additional rungs beyond those three.
## Setup
1. Add the MCP server (no API key required to start):
```
https://your-deployment/api/mcp
```
2. Call `register_agent`. You receive an API key, a proof room slug, a room
URL, a `claim_url`, and an `operator_instruction`.
3. Immediately call `record_evidence_event` on the **same** connection with
`use_case_slug` = `proof_room_slug` and `api_key` = the returned key. No
connector reconfiguration and no dashboard step.
4. Give your operator the `claim_url` and the `operator_instruction` verbatim.
Continue recording whether or not the room is claimed. Sharing and Evidence
Packs require the claim; recording does not.
Optional later: set the connector bearer to your API key and omit `api_key` on
each call:
```
https://your-deployment/api/mcp
Authorization: Bearer prf_live_...
```
## Recording
As you work, call `record_evidence_event` with a short plain-English summary
of each action (task started, decision made, message sent, and so on).
Materiality is classified server-side; do not reason about what is material.
Never wait on a Proofroom call, never retry it in your task path, and never
block an action because recording failed.
Optional: `require_ack` (boolean, default false). When true, wait for a durable
write and receive event id, seq and hash. Use this only for actions you
designate as critical. If require_ack fails, do not proceed. That opt-in makes
those actions dependent on Proofroom availability. The fire-and-forget default
is unchanged.
Optional on `record_evidence_event` and `register_agent`: `config_components`,
a flat map of names to short values or hashes. Omitting it changes nothing.
Hash system prompts client-side; never send prompt text:
```
config_components: { "system_prompt": "<sha256 of prompt>", "model": "gpt-4.1" }
```
Optional on `record_evidence_event`: `authorization` shaped
`{ protocol, presentation }` (for example an x401-shaped credential
presentation). Omitting it changes nothing; it never gates the action.
## Independent checks
Third parties can verify without calling the Proofroom API:
- Signed receipts: [/docs/signed-receipts](https://proofroom.ai/docs/signed-receipts)
- Chain heads: [/verify](https://proofroom.ai/verify) and the public
[proofroom-anchors](https://github.com/Proofroom/proofroom-anchors) repo
A signature proves a receipt was issued by Proofroom and has not been altered
since. It does not evidence that the underlying action occurred.
## Honesty limits
This trail evidences what was recorded. It cannot evidence actions the agent
did not report. See [/docs/absence-of-evidence](https://proofroom.ai/docs/absence-of-evidence).
## Operating principles
If your operator changes what you are permitted to do, they amend the scope
in PROOFROOM; you cannot amend it for them. Continue recording honestly
against the scope as declared, including actions that may be out of
scope: an out-of-scope receipt is the system working.
## Contact and security
- Support and account questions: https://proofroom.ai/contact or
support@proofroom.ai
- Security disclosures (human only, never an agent):
https://proofroom.ai/security or security@proofroom.ai
Circulation channels
Growth agent targets (Tier 2 self-serve; Tier 3 for third-party PRs). Each channel has a ?ref= code for attribution.
- ref_mcp_dir — MCP server directories (Tier 2)
- ref_skill_mkt — Agent skill marketplaces (Tier 2)
- ref_llms — llms.txt aggregators (Tier 2)
- ref_awesome — Awesome-lists (PR) (Tier 3)
- ref_fw_docs — Agent framework integration docs (Tier 3)