Found is not loaded.
Validate each observed SKILL.md. Map its Claude Code, Codex, Cursor, OpenClaw, and Hermes paths. Mark every unproven runtime claim as unknown.
SkillWitness 0.1.0 READ-ONLY · 5 runtimes · 1 skill · 3 instances Skill Claude Codex portable-demo PVE??? PVE??? P present V portable-valid E eligible-by-path D runtime-discovered ? A enabled ? I invoked ?
Six claims. Never collapsed.
A file can be present and valid without ever reaching the runtime. SkillWitness keeps each claim attached to the evidence that can actually support it.
Present
Readable regular SKILL.md.
Portable valid
Metadata and document profile passed.
Eligible path
Documented runtime root.
Discovered
Needs a runtime-owned catalog receipt.
Enabled
Needs runtime-owned enable evidence.
Invoked
Needs an exact invocation receipt.
One matrix. Five runtimes.
Canonical roots, compatibility roots, legacy locations, plugin caches, sources, aliases, exact content, drift, and documented precedence stay visibly different.
Scroll horizontally to inspect every runtime →
| Skill | Claude Code | Codex | Cursor | OpenClaw | Hermes |
|---|---|---|---|---|---|
| portable-demo | PVE??? | PVE??? | ---??? | ---??? | ---??? |
| cache-only | PV-??? | ---??? | ---??? | ---??? | ---??? |
| drifted-skill | PVE??? | PVE??? | ---??? | ---??? | PVE??? |
Evidence without exposure.
The report is useful for support and CI because it records structure, identity, and state—without copying the content that may be private.
What it reads
- Registered or explicit skill roots
- At most 512 KiB per SKILL.md
- Structure, lengths, and content digest
- Symlink and realpath identity
What it refuses
- No conversations or session databases
- No config values, tokens, cookies, or env
- No skill execution or agent launch
- No body or description text in reports
Try the safe demo.
The demo is fixed synthetic data. It never scans your home directory and requires no account, key, or runtime configuration.
npx --yes github:daijx66-crypto/skillwitness --demoGet started