ai.imboard/dossier
AI 与智能体by imboard-ai
面向 dossier automation standard 的 MCP server,使 LLMs 能发现、验证并执行 dossiers 自动化流程。
什么是 ai.imboard/dossier?
面向 dossier automation standard 的 MCP server,使 LLMs 能发现、验证并执行 dossiers 自动化流程。
README
Dossier — Portable, Signed Skills for Any AI Agent
Skills are easy to write. Dossiers make them trustworthy, versioned, and portable across every LLM tool.
Quick Concept A dossier is a skill — a reusable instruction set an AI executes — with trust, versioning, and cross-tool portability built in. Think npm or Docker Hub, but for AI skills: signed, versioned, shareable.
┌──────────────────────────────────────────────────────────────────────┐
│ │
│ Write instructions Verify integrity AI executes │
│ in Markdown (.ds.md) with checksums & the workflow │
│ signatures intelligently │
│ │
│ ┌──────────┐ sign ┌──────────┐ run ┌──────────┐ │
│ │ Author │ ─────────> │ Verify │ ────────> │ AI Agent │ │
│ └──────────┘ └──────────┘ └──────────┘ │
│ │ │ │ │
│ .ds.md file checksum + validated │
│ with JSON signature results with │
│ frontmatter verification evidence │
│ │
└──────────────────────────────────────────────────────────────────────┘
New here? → 5-min Quick Start | Using Claude Code? → MCP in 60 Seconds | Want to try now? → Get started in 30 seconds
At a Glance
flowchart LR
A["📝 Create\n.ds.md file"] --> B["🔏 Sign\nchecksum +\nsignature"]
B --> C["✅ Verify\nintegrity &\nauthenticity"]
C --> D["🤖 Execute\nAI runs the\nworkflow"]
D --> E["📋 Validate\nsuccess criteria\n& evidence"]
style A fill:#e3f2fd,stroke:#1565c0,color:#0d47a1
style B fill:#fce4ec,stroke:#c62828,color:#b71c1c
style C fill:#fff3e0,stroke:#ef6c00,color:#e65100
style D fill:#e8f5e9,stroke:#2e7d32,color:#1b5e20
style E fill:#f3e5f5,stroke:#6a1b9a,color:#4a148c
What: Skills (.ds.md files) any AI agent can run — signed, versioned, portable across tools
Why: A plain skill lives in one tool and anyone can tamper with it; a dossier is that same skill made verifiable, version-pinned, and shareable
Safety: Built-in checksums, cryptographic signatures, and CLI verification tools
Works with: Claude, ChatGPT, Cursor, any LLM — no vendor lock-in
Status: Protocol v1.0 (stable spec) | CLI v0.8.5 | 15+ example skills | Active development
File conventions: Dossiers use
.ds.md(immutable instructions) and.dsw.md(mutable working files). Frontmatter uses---dossier(JSON) instead of---(YAML) to avoid parser conflicts. Learn more
Get Started
1. Run a dossier — zero install
Pick any LLM you already have and paste this:
Analyze my project using the dossier at:
https://raw.githubusercontent.com/imboard-ai/ai-dossier/main/examples/guides/context-engineering-best-practices.ds.md
That's it. The LLM reads the dossier and follows its instructions — no tools needed.
Want to verify it first?
npx @ai-dossier/cli verify https://raw.githubusercontent.com/imboard-ai/ai-dossier/main/examples/guides/context-engineering-best-practices.ds.md
2. Add the MCP server to Claude Code
One command gives Claude Code native dossier support — discover, verify, and execute dossiers without copy-pasting URLs:
claude mcp add dossier --scope user -- npx @ai-dossier/mcp-server
Then ask Claude: "List available dossiers" or "Run the scaffold-typescript-project dossier".
<details> <summary>Alternative: Claude Code plugin (auto-updates)</summary>/plugin marketplace add imboard-ai/ai-dossier
/plugin install dossier-mcp-server@ai-dossier
Add to claude_desktop_config.json or your MCP client's config file:
{
"mcpServers": {
"dossier": {
"command": "npx",
"args": ["-y", "@ai-dossier/mcp-server"]
}
}
}
3. Create your own dossier
Initialize dossier in your project (sets up ~/.dossier/, hooks, and MCP config):
npx @ai-dossier/cli init
Then create a dossier:
npx @ai-dossier/cli create my-workflow
This scaffolds a .ds.md file you can edit. A dossier is just Markdown with a JSON frontmatter block:
---dossier
{
"title": "My Workflow",
"version": "1.0.0",
"protocol_version": "1.0",
"status": "draft",
"objective": "Describe what this automates",
"risk_level": "low"
}
---
# My Workflow
## Actions
1. Step one — what to do
2. Step two — what to verify
## Validation
- Expected outcome was achieved
See the Authoring Guide for the full spec, or browse the Dossier Registry for real-world examples.
Why Use Dossier?
"Isn't this just a skill?" Yes — a dossier is a skill. The difference is everything a plain skill (like a Claude Code SKILL.md) lacks:
Plain skill (SKILL.md) | Dossier | |
|---|---|---|
| Trust | Unsigned — anyone can tamper | Checksum + cryptographic signature, verified before run |
| Versioning | Informal | Semantic versioning you can pin |
| Distribution | Copy-paste / per-tool | Registry — discoverable, ai-dossier install-skill |
| Portability | Locked to one tool | Same file runs on Claude, ChatGPT, Cursor, any LLM |
| Validation | None | Built-in success criteria |
Trigger skills bridge the two: a thin SKILL.md whose job is to invoke a versioned, signed dossier (ai-dossier run <registry-path>) — you keep the natural-language trigger and gain signing, versioning, and registry distribution.
"How about AGENTS.md files?" Different job: AGENTS.md explains your project; a dossier automates a workflow. They're complementary.
Architecture
graph TB
subgraph Packages["@ai-dossier packages"]
Core["@ai-dossier/core\nParsing, verification,\nlinting, risk assessment"]
CLI["@ai-dossier/cli\nCommand-line tool\nverify, sign, search, run"]
MCP["@ai-dossier/mcp-server\nMCP integration for\nClaude Code & others"]
Registry["@ai-dossier/registry\nVercel serverless API\nDiscover & publish"]
end
subgraph Inputs["Dossier Files"]
DS[".ds.md\nImmutable instructions\nJSON frontmatter + Markdown"]
DSW[".dsw.md\nMutable working files\nExecution state"]
end
subgraph Consumers["AI Agents"]
Claude["Claude Code"]
ChatGPT["ChatGPT"]
Cursor["Cursor"]
Other["Any LLM"]
end
DS --> Core
DSW --> Core
Core --> CLI
Core --> MCP
CLI --> Registry
MCP --> Claude
MCP --> ChatGPT
MCP --> Cursor
MCP --> Other
CLI -->|"verify & run"| Consumers
style Core fill:#e3f2fd,stroke:#1565c0,color:#0d47a1
style CLI fill:#e8f5e9,stroke:#2e7d32,color:#1b5e20
style MCP fill:#fff3e0,stroke:#ef6c00,color:#e65100
style Registry fill:#f3e5f5,stroke:#6a1b9a,color:#4a148c
style DS fill:#fff9c4,stroke:#f9a825,color:#f57f17
style DSW fill:#fff9c4,stroke:#f9a825,color:#f57f17
Verification Pipeline
Every dossier goes through a multi-stage security pipeline before execution:
flowchart TD
Start(["dossier verify file.ds.md"]) --> Parse["Parse frontmatter\n+ Markdown body"]
Parse --> Checksum{"Checksum\nverification"}
Checksum -->|"SHA-256 match"| SigCheck{"Signature\nverification"}
Checksum -->|"mismatch"| Block["BLOCK execution\nContent tampered"]
SigCheck -->|"valid + trusted"| Risk["Risk assessment"]
SigCheck -->|"valid + untrusted"| Risk
SigCheck -->|"unsigned"| Risk
SigCheck -->|"invalid"| Block
Risk -->|"low"| Safe["SAFE to execute"]
Risk -->|"medium/high"| Caution["PROCEED with caution"]
Risk -->|"critical + unsigned"| Block
style Start fill:#e3f2fd,stroke:#1565c0,color:#0d47a1
style Safe fill:#e8f5e9,stroke:#2e7d32,color:#1b5e20
style Caution fill:#fff3e0,stroke:#ef6c00,color:#e65100
style Block fill:#ffebee,stroke:#c62828,color:#b71c1c
style Checksum fill:#f5f5f5,stroke:#616161,color:#212121
style SigCheck fill:#f5f5f5,stroke:#616161,color:#212121
style Risk fill:#f5f5f5,stroke:#616161,color:#212121
See ARCHITECTURE.md for the full system architecture.
Examples
| Example | Use Case |
|---|---|
| Scaffold TypeScript Project | Scaffold a production-ready TS project with CI, testing, linting |
| Context Engineering Best Practices | Reference guide for writing effective AI agent context files |
Browse the Dossier Registry for the full collection — DevOps, databases, data science, security, and more.
# Search from the CLI
npx @ai-dossier/cli search deploy
Security & Verification
flowchart LR
Author["Author"] -->|"signs"| Dossier[".ds.md"]
Dossier -->|"distributed via"| Registry["Registry / URL"]
Registry -->|"fetched by"| CLI["CLI / MCP"]
CLI -->|"verifies"| Checks["Checksum\n+ Signature\n+ Risk Level"]
Checks -->|"safe"| Execute["Execute"]
Checks -->|"blocked"| Reject["Reject"]
style Author fill:#e3f2fd,stroke:#1565c0,color:#0d47a1
style Dossier fill:#fff9c4,stroke:#f9a825,color:#f57f17
style Checks fill:#fff3e0,stroke:#ef6c00,color:#e65100
style Execute fill:#e8f5e9,stroke:#2e7d32,color:#1b5e20
style Reject fill:#ffebee,stroke:#c62828,color:#b71c1c
- Use the CLI tool (
ai-dossier verify) to verify checksums/signatures before execution - Prefer MCP mode for sandboxed, permissioned operations
- External reference declaration: Dossiers that fetch or link to external URLs must declare them in
external_referenceswith trust levels. The linter flags undeclared URLs, and the MCP server'sread_dossiertool returnssecurity_noticesfor any undeclared external URLs found in the body. This mitigates transitive trust risks from unvetted external content. - See SECURITY_STATUS.md for current guarantees and limitations
Registry & Multi-Registry Support
The CLI supports multiple registries for discovering, publishing, and sharing dossiers across teams and organizations.
flowchart LR
CLI["dossier CLI"] -->|"parallel query"| R1["Public Registry\ndossier-registry.vercel.app"]
CLI -->|"parallel query"| R2["Internal Registry\ndossier.company.com"]
CLI -->|"parallel query"| R3["Mirror Registry\nmirror.example.com"]
R1 -->|"results"| Merge["Merge results\n(partial failure OK)"]
R2 -->|"results"| Merge
R3 -->|"error"| Merge
Merge --> User["User sees\ncombined results"]
style CLI fill:#e3f2fd,stroke:#1565c0,color:#0d47a1
style Merge fill:#e8f5e9,stroke:#2e7d32,color:#1b5e20
style R3 fill:#ffebee,stroke:#c62828,color:#b71c1c
- Multi-registry: Configure multiple registries (public, internal, mirrors) queried in parallel
- HTTPS enforcement: All registry URLs must use HTTPS to protect credentials in transit
- Per-registry credentials: Each registry has isolated authentication — a compromised token cannot access other registries
- Project-level config: Add a
.dossierrc.jsonto your project for team-shared registry settings
# Add a private registry
dossier config --add-registry internal --url https://dossier.company.com
# List configured registries
dossier config --list-registries
See the CLI documentation for full registry management options.
Adopter Playbooks
- Solo Dev: paste a
.ds.mdinto your LLM and run via MCP or CLI - OSS Maintainer: add
/dossiers+ a CI check that runs the Reality Check on your README - Platform Team: start with init -> deploy -> rollback dossiers; wire secrets & scanners
Detailed playbooks in docs/guides/adopter-playbooks.md
Documentation
| Getting Started | Quick Start · Installation · MCP in 60 Seconds · Your First Dossier · FAQ |
| Reference | Protocol · Specification · Schema · JSON Schema |
| Guides | Authoring Guidelines · Dossier Guide · CI/CD Integration · Execution Tracing · Adopter Playbooks · Examples |
| Packages | CLI · MCP Server · Core Library · Registry |
| Project | Architecture · Contributing · Security · Changelog |
Philosophy
"A skill tells an agent what to do. A dossier lets you trust it."
Dossiers take the skill — a reusable instruction set any AI can run — and add the things that make it safe to share: a verifiable signature, a pinnable version, and a registry to distribute it through.
The dossier standard enables:
- Trust: cryptographic signatures and checksums, verified before execution
- Versioning: semantic versions you can pin and upgrade deliberately
- Distribution: a registry that makes skills discoverable and installable
- Portability: any project, any workflow, any LLM — no vendor lock-in
- Adaptability: agents understand context and adjust behavior
Dossier: Portable, Verifiable Skills for Any LLM Skills you can trust.
License
This project is licensed under the GNU Affero General Public License v3.0 (AGPL-3.0). You are free to use, copy, modify, and distribute it, provided that any modified versions or network services using this software also make their source code available under the same license.
References
See REFERENCES.md for the full list of academic references and industry research supporting the dossier approach.
常见问题
ai.imboard/dossier 是什么?
面向 dossier automation standard 的 MCP server,使 LLMs 能发现、验证并执行 dossiers 自动化流程。
相关 Skills
Claude接口
by anthropics
面向接入 Claude API、Anthropic SDK 或 Agent SDK 的开发场景,自动识别项目语言并给出对应示例与默认配置,快速搭建 LLM 应用。
✎ 想把Claude能力接进应用或智能体,用claude-api上手快、兼容Anthropic与Agent SDK,集成路径清晰又省心
RAG架构师
by alirezarezvani
聚焦生产级RAG系统设计与优化,覆盖文档切块、检索链路、索引构建、召回评估等关键环节,适合搭建可扩展、高准确率的知识库问答与检索增强应用。
✎ 面向RAG落地,把知识库、向量检索和生成链路系统串联起来,做架构设计时更清晰,也更少踩坑。
多智能体架构
by alirezarezvani
聚焦多智能体系统架构设计,梳理 Supervisor、Swarm、分层和 Pipeline 等模式,覆盖角色定义、通信协作与性能评估,适合规划稳健可扩展的 AI agent 编排方案。
✎ 帮你系统解决多智能体应用的架构设计与协同编排难题,适合构建复杂 AI 工作流,成熟度高、社区认可也很亮眼。
相关 MCP Server
知识图谱记忆
编辑精选by Anthropic
Memory 是一个基于本地知识图谱的持久化记忆系统,让 AI 记住长期上下文。
✎ 帮 AI 和智能体补上“记不住”的短板,用本地知识图谱沉淀长期上下文,连续对话更聪明,数据也更可控。
顺序思维
编辑精选by Anthropic
Sequential Thinking 是让 AI 通过动态思维链解决复杂问题的参考服务器。
✎ 这个服务器展示了如何让 Claude 像人类一样逐步推理,适合开发者学习 MCP 的思维链实现。但注意它只是个参考示例,别指望直接用在生产环境里。
by deusdata
持久化的代码库知识图谱,可跨会话保留上下文,在 session 重启或上下文压缩后仍能继续使用。
✎ 专治 AI 编程助手“会话失忆”,把代码库沉淀为持久知识图谱,重启或压缩上下文后也能无缝续上开发状态。