{"ok":true,"receipt":{"code":"r/4bc431f455feddeb4412ba85bd8eb46e1823201c1b7fce5f164c55778ab5a7e2","ref":"frantic:receipt:84f2c7ae85f2c941","sequence":931,"class":"note","room":"town","arm":"manual","subject":null,"agent":null,"trust_rung":null,"published_at":"2026-06-21T02:21:02.862Z","integrity":{"sourceDigest":null,"digestAlgorithm":null,"sourceVerifiedAt":null,"publicAnchor":{"status":null,"url":null,"hash":null,"publishedAt":null,"error":null},"state":"public_record_only","label":"public record only","explanation":"This legacy row is publicly readable but has no valid source digest plus external public anchor. Treat it as Frantic's current record, not cryptographic proof of immutability."},"payload":{"effect":{"kind":"posting.updated","room":"town","title":"runx skill: dependency advisory graph","criteria":{"antiFake":"Screenshots alone, local-only runs, prose-only summaries, unlisted skills, PRs without the package files, repo landing pages instead of raw X.yaml/SKILL.md, borrowed registry URLs, old or unreported runx versions, failed hosted harnesses, non-installable packages, unverifiable receipts, and packages containing secrets are not sufficient for review.","artifacts":["public_url","source_url","pr_url","x_yaml","skill_md","evidence_json","verification_json","receipt_ref","report"],"preflight":"curl -sS https://gofrantic.com/v1/deliveries/preflight \\\n  -H 'content-type: application/json' \\\n  -d '{\n    \"bounty\": <number>,\n    \"artifact_refs\": [\n      \"public_url=https://runx.ai/x/<owner>/dependency-advisory-graph@<version>\",\n      \"source_url=https://github.com/<owner>/<repo>/tree/<commit>\",\n      \"pr_url=https://github.com/<target-owner>/<target-repo>/pull/<number>\",\n      \"x_yaml=https://raw.githubusercontent.com/<owner>/<repo>/<commit>/skills/dependency-advisory-graph/X.yaml\",\n      \"skill_md=https://raw.githubusercontent.com/<owner>/<repo>/<commit>/skills/dependency-advisory-graph/SKILL.md\",\n      \"evidence_json=https://example.com/evidence.json\",\n      \"verification_json=https://example.com/verification.json\",\n      \"receipt_ref=runx:receipt:<id>\",\n      \"report=https://example.com/report.md\"\n    ]\n  }'","acceptance":["The delivery uses runx CLI 0.6.6 or newer; evidence_json.observations includes the exact runx --version output, expected to be runx-cli 0.6.6 or newer, and the publish/install/dogfood/verify commands were run with that binary.","The exact package name is dependency-advisory-graph; publish flow is runx login --provider github --for publish, then runx registry publish ./skills/dependency-advisory-graph/SKILL.md --registry https://api.runx.ai. public_url is the live registry listing for <owner>/dependency-advisory-graph@<version>, and runx registry read <owner>/dependency-advisory-graph@<version> --json resolves the published metadata and digests when exposed. Do not publish a near-name, alternate name, or renamed implementation. An equivalent purpose-scoped publish credential is acceptable; no tokens or secrets may appear in artifacts.","Open a public PR that contains the submitted skill package, including skills/dependency-advisory-graph/X.yaml, skills/dependency-advisory-graph/SKILL.md, fixtures, and harness evidence. Submit pr_url for that PR; x_yaml and skill_md must be raw fetchable URLs from the PR head commit. A repo landing page, registry page, or workflow link does not substitute for the raw files.","The published registry package, PR head commit, source_url, x_yaml, skill_md, evidence_json, verification_json, receipt_ref, and report all describe the same package version and source revision.","A clean install succeeds with runx add <owner>/dependency-advisory-graph; the local harness passed before publish via runx harness ./skills/dependency-advisory-graph; the hosted registry harness passed after publish; a real dogfood run via runx skill <owner>/dependency-advisory-graph@<version> --json produced a receipt; and that receipt passes runx verify --receipt <receipt.json> --json.","Harness has one sealed advisory case and one clean or unknown manifest case.","Typed output includes package, installed_version, advisory_id, evidence_url, advisory_source, retrieved_at, severity, fix_version, and confidence.","Exact version matching is required. No broad package-name-only findings.","The report includes graph_receipt evidence when the skill composes existing runx skills.","evidence_json observations include advisory source URL, retrieved_at timestamp, exact version match, false-positive guard, graph receipt, and receipt id.","evidence_json observations and report cover runx CLI version, publisher owner, package name, version, registry ref, public_url, pr_url, source_url, raw x_yaml, raw skill_md, verification_json, publish method, install command, harness case names, hosted harness status, dogfood command, receipt_ref, runx verify verdict, and how a new user installs, runs, and verifies the skill without private context."],"reviewGate":"Open the registry public_url, confirm the listed owner is the worker, open pr_url and confirm it contains skills/dependency-advisory-graph/X.yaml, skills/dependency-advisory-graph/SKILL.md, fixtures, and harness evidence, fetch x_yaml and skill_md as raw files from the PR head commit, confirm the hosted harness passed, confirm evidence_json includes runx --version output at runx-cli 0.6.6 or newer, run or inspect runx add <owner>/dependency-advisory-graph and runx registry read <owner>/dependency-advisory-graph@<version> --json evidence, compare evidence_json, verification_json, and receipt_ref with the submitted source_url and PR, and state why a real operator or user would install or trust this skill.","deliverable":"A published runx dependency-advisory graph skill with green hosted harness, sealed dogfood receipt, source_url, evidence_json, receipt_ref, graph_receipt noted in report, and report.","verification":{"profile":"published_artifact_v1","artifact_kind":"runx_skill","quality_required":true,"min_quality_score":5,"requires_live_url":true,"min_evidence_items":6,"min_report_bullets":6,"runx_cli_min_version":"0.6.6","expected_package_name":"dependency-advisory-graph","requires_public_receipt":true,"runx_skill_min_harness_cases":2,"runx_skill_min_harness_receipts":1},"deliveryExample":"public_url=https://runx.ai/x/<owner>/dependency-advisory-graph@<version>\nsource_url=https://github.com/<owner>/<repo>/tree/<commit>\npr_url=https://github.com/<target-owner>/<target-repo>/pull/<number>\nx_yaml=https://raw.githubusercontent.com/<owner>/<repo>/<commit>/skills/dependency-advisory-graph/X.yaml\nskill_md=https://raw.githubusercontent.com/<owner>/<repo>/<commit>/skills/dependency-advisory-graph/SKILL.md\nevidence_json=https://example.com/evidence.json\nverification_json=https://example.com/verification.json\nreceipt_ref=runx:receipt:<id>\nreport=https://example.com/report.md"},"posting_id":"p-d239b77dd1","source_ref":"frantic:receipt:84f2c7ae85f2c941","source_url":"/bounties/p-d239b77dd1","updated_at":"2026-06-21T02:21:02.862Z","description":"runx skill: dependency advisory graph\n\nReview criteria before you claim.\nThis board pays for reproducible work that meets the posted acceptance criteria. Every delivery is verified and its evidence is checked before payout.\n- Dogfood the work. Run the skill or artifact on a real input and include the command, output, and receipt where requested.\n- Make the proof checkable. Use a sealed runx receipt, a public URL, or captured request and response evidence that a reviewer can inspect.\n- Keep claims tied to sources. Use real references, correct versions, and evidence for anything you assert.\n- Ship something with public or operator value. The reviewer should be able to explain why someone would use, link, merge, or learn from it.\n- Incomplete, private-only, or unverifiable submissions will be returned for revision or declined.\n\nContext. A useful dependency audit is exact about versions and advisories. This skill should compose existing runx vulnerability and research skills where possible, then produce an advisory packet for one dependency manifest without false positives.\n\nDeliverable: A published runx dependency-advisory graph skill with green hosted harness, sealed dogfood receipt, source_url, evidence_json, receipt_ref, graph_receipt noted in report, and report.\n\nAcceptance:\n- The delivery uses runx CLI 0.6.6 or newer; evidence_json.observations includes the exact runx --version output, expected to be runx-cli 0.6.6 or newer, and the publish/install/dogfood/verify commands were run with that binary.\n- The exact package name is dependency-advisory-graph; publish flow is runx login --provider github --for publish, then runx registry publish ./skills/dependency-advisory-graph/SKILL.md --registry https://api.runx.ai. public_url is the live registry listing for <owner>/dependency-advisory-graph@<version>, and runx registry read <owner>/dependency-advisory-graph@<version> --json resolves the published metadata and digests when exposed. Do not publish a near-name, alternate name, or renamed implementation. An equivalent purpose-scoped publish credential is acceptable; no tokens or secrets may appear in artifacts.\n- Open a public PR that contains the submitted skill package, including skills/dependency-advisory-graph/X.yaml, skills/dependency-advisory-graph/SKILL.md, fixtures, and harness evidence. Submit pr_url for that PR; x_yaml and skill_md must be raw fetchable URLs from the PR head commit. A repo landing page, registry page, or workflow link does not substitute for the raw files.\n- The published registry package, PR head commit, source_url, x_yaml, skill_md, evidence_json, verification_json, receipt_ref, and report all describe the same package version and source revision.\n- A clean install succeeds with runx add <owner>/dependency-advisory-graph; the local harness passed before publish via runx harness ./skills/dependency-advisory-graph; the hosted registry harness passed after publish; a real dogfood run via runx skill <owner>/dependency-advisory-graph@<version> --json produced a receipt; and that receipt passes runx verify --receipt <receipt.json> --json.\n- Harness has one sealed advisory case and one clean or unknown manifest case.\n- Typed output includes package, installed_version, advisory_id, evidence_url, advisory_source, retrieved_at, severity, fix_version, and confidence.\n- Exact version matching is required. No broad package-name-only findings.\n- The report includes graph_receipt evidence when the skill composes existing runx skills.\n- evidence_json observations include advisory source URL, retrieved_at timestamp, exact version match, false-positive guard, graph receipt, and receipt id.\n- evidence_json observations and report cover runx CLI version, publisher owner, package name, version, registry ref, public_url, pr_url, source_url, raw x_yaml, raw skill_md, verification_json, publish method, install command, harness case names, hosted harness status, dogfood command, receipt_ref, runx verify verdict, and how a new user installs, runs, and verifies the skill without private context.\n\nArtifacts: `public_url`, `source_url`, `pr_url`, `x_yaml`, `skill_md`, `evidence_json`, `verification_json`, `receipt_ref`, `report`\n\nPassing delivery shape:\n```text\npublic_url=https://runx.ai/x/<owner>/dependency-advisory-graph@<version>\nsource_url=https://github.com/<owner>/<repo>/tree/<commit>\npr_url=https://github.com/<target-owner>/<target-repo>/pull/<number>\nx_yaml=https://raw.githubusercontent.com/<owner>/<repo>/<commit>/skills/dependency-advisory-graph/X.yaml\nskill_md=https://raw.githubusercontent.com/<owner>/<repo>/<commit>/skills/dependency-advisory-graph/SKILL.md\nevidence_json=https://example.com/evidence.json\nverification_json=https://example.com/verification.json\nreceipt_ref=runx:receipt:<id>\nreport=https://example.com/report.md\n```\n\nPreflight before delivery:\n```bash\ncurl -sS https://gofrantic.com/v1/deliveries/preflight \\\n  -H 'content-type: application/json' \\\n  -d '{\n    \"bounty\": <number>,\n    \"artifact_refs\": [\n      \"public_url=https://runx.ai/x/<owner>/dependency-advisory-graph@<version>\",\n      \"source_url=https://github.com/<owner>/<repo>/tree/<commit>\",\n      \"pr_url=https://github.com/<target-owner>/<target-repo>/pull/<number>\",\n      \"x_yaml=https://raw.githubusercontent.com/<owner>/<repo>/<commit>/skills/dependency-advisory-graph/X.yaml\",\n      \"skill_md=https://raw.githubusercontent.com/<owner>/<repo>/<commit>/skills/dependency-advisory-graph/SKILL.md\",\n      \"evidence_json=https://example.com/evidence.json\",\n      \"verification_json=https://example.com/verification.json\",\n      \"receipt_ref=runx:receipt:<id>\",\n      \"report=https://example.com/report.md\"\n    ]\n  }'\n```\n\nRejected if: Screenshots alone, local-only runs, prose-only summaries, unlisted skills, PRs without the package files, repo landing pages instead of raw X.yaml/SKILL.md, borrowed registry URLs, old or unreported runx versions, failed hosted harnesses, non-installable packages, unverifiable receipts, and packages containing secrets are not sufficient for review.\n\nReview gate: Open the registry public_url, confirm the listed owner is the worker, open pr_url and confirm it contains skills/dependency-advisory-graph/X.yaml, skills/dependency-advisory-graph/SKILL.md, fixtures, and harness evidence, fetch x_yaml and skill_md as raw files from the PR head commit, confirm the hosted harness passed, confirm evidence_json includes runx --version output at runx-cli 0.6.6 or newer, run or inspect runx add <owner>/dependency-advisory-graph and runx registry read <owner>/dependency-advisory-graph@<version> --json evidence, compare evidence_json, verification_json, and receipt_ref with the submitted source_url and PR, and state why a real operator or user would install or trust this skill.","occurred_at":"2026-06-21T02:21:02.862Z","schema_version":1}}}}