Format
What a dossier looks like
---dossier
{
"name": "hello",
"title": "Hello World Dossier",
"version": "1.1.0",
"risk_level": "low",
"requires_approval": false,
"checksum": { "algorithm": "sha256", "hash": "2caae4c1…" },
"signature": { "algorithm": "ed25519", "key_id": "imboard-ai", "signature": "tleSPJ4T…" }
}
---
# Hello World Dossier
The skill an AI agent follows, written in plain markdown.
The header above is what makes them verifiable.
Trimmed from the published getting-started/hello dossier.
How trust works
- Trust is a local decision. A valid signature from a key you have not added is reported as untrusted, never auto-trusted.
- Trusted keys live in
~/.dossier/trusted-keys.txt, managed with ai-dossier keys add, list, export and revoke. Revoking is local to that machine. - To let others verify your skills, sign with your own Ed25519 key (
keys generate), send them the public key (keys export), and they run keys add. Extra registries, including self-hosted ones over HTTPS, are added with config --add-registry. - Verification proves integrity and origin. It does not prevent prompt injection or make a dossier safe to run. Read the security model.