Install Action State Receipts
Action State Receipts works beside your AI agent. Before the agent pays, books, signs, cancels or shares your details, it checks the step against your rules, and every step is sealed on your machine as a receipt you can check. Nothing of the receipts' content leaves your machine.
Your agent does the install, by following the Action State install skill. This page is for you: what the install puts on your machine, the exact versions, every checksum your agent reports back, and the sites it reaches. The last section says how to give your agent the skill.
What gets installed
- capsulectl v0.1.0-rc14 (commit
49651e2f156e370208dec605ded653c5f0a9a4bf), a command-line program. - The deal skill: the instructions your agent follows before it pays, books, signs, cancels or shares your details.
- The Action State plugin 0.0.9, which adds the
capsulectl actionstatecommands, and its skill, actionstate-rules. The install sets the plugin as the rules checker every receipt check runs, with the rules packasg/everyday/0.3.4. - A scheduled task, Action State checkpoint cadence, that publishes one checkpoint of hashes to the public witness every 5 minutes.
- A standing rule in your agent's memory: before it pays, orders, books, confirms, signs, cancels or shares your details, it follows the deal skill and asks you first.
Action State rules run on Linux x86_64 only. On any other device the install stops at its first step, and nothing is installed.
What's new: A merchant you have paid before is recognised across your deals (payments recorded before rc13 count only within their own deal). Recurring charges and a change to a payee's account are not yet checked on purchases.
Limits in this version: Selling is not yet checked. After a refund, your 7-day spending limit may show as not checked for up to 31 days.
Your rules are what you permit; your agent shows them to you as a table when the install ends. Your receipts are what happened: for each purchase or other commitment, what you asked, what was proposed, what you approved, what was done, and any difference.
The checksums
Your agent checks every file against these SHA-256 values before it installs anything, and stops if one differs. Any checksum your agent reports to you must match this list, character for character.
- Install skill rc14-p0.0.9-s0.0.8,
/install/rc14-p0.0.9-s0.0.8/actionstate-install/SKILL.md:
5cb84886fcf56e0dff9ba8330cb931f0d80beecf4c9b222c35daf203d62cbaf8 - Install script rc14-p0.0.9-s0.0.8,
/install/rc14-p0.0.9-s0.0.8/install.sh:
3e733700669e6bcb51082210327544d6d0b179a48b7a7e843117041ae90a79c7 - capsulectl v0.1.0-rc14, Linux x86_64,
capsulectl-v0.1.0-rc14-linux-amd64:
c8d1ea26cb042319ac6ad562c3dfac7ecc23687bd5c8b60a938904c61f1be627 - capsulectl build attestation,
capsulectl-v0.1.0-rc14.sigstore.json:
ac4828cedc40fdbb5a4dc3ac3aaaf99a24fd92b0872de1afa9537dece5368c31 - capsule-cli source archive (holds the deal skill),
v0.1.0-rc14.tar.gz:
febc716659b2601579a4f7e7d8cf4d4795cdfce1a3222554dc3eac8d287e3800 - The deal skill,
skills/deal/SKILL.md:
f27aacc5c255293fada8f15ad5c62dbc59d9ed427f8c319e9282c93fca88226c - Action State plugin 0.0.9,
capsulectl-actionstate-linux-amd64-v0.0.9:
71cd6b7963f3b5c70b9b0f13a3499097dcaeccdc8f7ec3f4d42d43c822e63a79 - actionstate-rules skill archive,
actionstate-rules-skill-v0.0.8.tar.gz:
945943794420260052b1ae77bc5701ff4ae55e9c58939c15f495a752c59d6a7d - The actionstate-rules skill,
actionstate-rules/SKILL.md:
cf1f55a297969ddd665dea68aca8a0e6a289a246dd2b7f3fd5fac1b3401b9595
The rules pack asg/everyday/0.3.4 has the definition digest
cd98aaec5acf8cea86f91fc21dd7df6b36a67c7b55340489b66e6ce88b85117b; the rules checker is pinned to it. The public
witness's key is 39bb654c9dc0afe1c0edef0deffaa69099b8518836c9ba26e0491535840f96b5.
What you are trusting: GitHub to deliver the capsulectl files from
github.com/action-state-group/capsule-cli, GitHub's build attestation for
that repository (checked when the agent has a recent gh), and the SHA-256
values on this page. The install skill, the install script, the plugin and
the actionstate-rules skill have no build attestation yet: they are checked
by their SHA-256 only, and those values are published on this site, the same
place the files come from. A matching checksum shows a download arrived
intact; it does not show that this site was not tampered with.
When the install ends
Your agent shows you your rules table, exactly as the plugin printed it, and the path of your report, a page that checks itself when you open it, with no internet connection. Then a short Install details note: what was installed, whether the build attestation was verified or only the checksum, and where the full record is, with every checksum and exit code. If you ask for the checksums, they come from that record, and they match the list above.
The sites it reaches
You may be asked whether to allow some of these sites. For the trust-root sites and the witness, choose "Always allow this site", not "Allow once": the check and the checkpoints run on every install and on a schedule, mostly when nobody is there to answer.
- github.com: the capsulectl release, the source archive of the deal skill, and the build attestation's bundle.
- release-assets.githubusercontent.com: GitHub's own host, which serves the capsulectl release files.
- codeload.github.com: GitHub's own host, which serves the source archive.
- actionstate.ai: this page, the install skill, the install script, and the Action State plugin and its rules skill.
- witness.agentactioncapsule.org: the public witness. Only hashes go there, never the content of your receipts. The grant covers agentactioncapsule.org and its subdomains, including verify.agentactioncapsule.org, the independent verifier.
- tuf-repo-cdn.sigstore.dev and tuf-repo.github.com: Sigstore's and
GitHub's trust roots, reached only when the agent has a recent
gh, to check the build's signature. Nothing is downloaded or installed from them.
Your agent asks you one question before it starts: what name to record as the operator of your rules record. That name is the only one the record holds. Without a name, the install still runs, but your rules table is skipped.
Give your agent the install skill
The install skill holds every step, the commands and the checks. There are two ways to give it to your agent; either way, ask your agent to "install Action State Receipts with this skill".
- Paste it. Open the install skill, copy all of it, and paste it into the chat with your agent.
- Let your agent download it. An agent that can run shell commands
downloads the skill and its checksum with the lines below, and installs
nothing unless the SHA-256 is this page's,
5cb84886fcf56e0dff9ba8330cb931f0d80beecf4c9b222c35daf203d62cbaf8.
curl -fsSLO https://actionstate.ai/install/rc14-p0.0.9-s0.0.8/actionstate-install/SKILL.md && curl -fsSLO https://actionstate.ai/install/rc14-p0.0.9-s0.0.8/actionstate-install/SKILL.md.sha256
[ "$(awk '{print $1}' SKILL.md.sha256)" = 5cb84886fcf56e0dff9ba8330cb931f0d80beecf4c9b222c35daf203d62cbaf8 ] && sha256sum -c SKILL.md.sha256
The skill's numbered steps are the ones the install script runs, and the ones a message from the install refers to as "the steps on actionstate.ai/install".
What a receipt is, and is not
A receipt shows which steps the agent sealed, and that they were not changed afterwards: it is tamper-evident against the agent and against Action State. It is the agent's own record of what it did, not a statement from the merchant; calling the check is advisory, and a step never sealed is not in it. Anyone can check a receipt file independently at verify.agentactioncapsule.org: open it and drop the file in.