Manifest Reference
The Skill Manifest File is the JSON document that describes a skill: its name, version, license, the host-specific representations (targets) it ships, and optional dependency, taxonomy, and provenance metadata.
When a skill is registered on-chain, the manifest's keccak256 hash is stored in manifestHashes(skillId) on the SkillRegistry. Clients fetch the manifest from tokenURI(skillId), check a nonzero hash, then fetch and verify the selected target body against its declared integrity. Any byte-level change to the manifest invalidates the on-chain commitment.
This page documents the schema implemented by asrpm. See the ERC-8239 specification for the normative definition.
Top-Level Fields
| Field | Type | Required | Description |
|---|---|---|---|
type | string | optional | Manifest type discriminator (e.g. skill) |
name | string | recommended | Short, human-readable skill name. Used as the install directory name (sanitized). |
description | string | recommended | One-line description of what the skill does |
image | string | optional | URL to an icon or banner image |
version | string | recommended | Semver string for this skill release |
license | string | recommended | SPDX license identifier (e.g. MIT, Apache-2.0) |
keywords | string[] | optional | Tags for discovery |
homepage | string | optional | Project homepage URL |
repository | string | optional | Source repository URL |
author | Author | optional | Author identification |
targets | Target[] | required | Per-host materializations of the skill |
requirements | object | optional | Free-form host or runtime requirements |
taxonomy | object | optional | Free-form classification metadata |
dependencies | SkillReference[] | optional | Other skills this skill depends on |
supersedes | SkillReference | optional | Skill this release supersedes |
status | string | optional | Lifecycle status. deprecated triggers a client warning. |
Unknown fields are tolerated by asrpm and ignored when parsing JSON. Required fields here describe an installable manifest; the parser does not enforce every schema or metadata convention. A zero registry hash skips manifest authentication in the current CLI.
Target
A Target describes one way the skill is materialized for a particular host — a Claude Code SKILL.md, a Cursor rule, an MCP server, a CLI binary, etc. A skill manifest must include at least one target.
| Field | Type | Required | Description |
|---|---|---|---|
kind | string | required | Host identifier (e.g. claude-code-skill, cursor-rule, mcp-server). Clients pick a target by matching their host's expected kind. |
version | string | optional | Per-target version, if it diverges from the manifest's version |
runtime | string | optional | Runtime hint for the host (e.g. interpreter version) |
installation | string | optional | Free-form installation notes for hosts that need them |
uri | string | required | URI to the target body. Supported schemes: https://, http://, data:. (ipfs:// is intentionally not supported.) |
integrity | string | required | <algorithm>:<hex> digest of the body bytes (see Integrity Format) |
format | string | optional | Body format; the current CLI accepts only file (also the default) |
Target Kinds
asrpm v1 installs targets with kind = "claude-code-skill" into ~/.claude/skills/<name>/SKILL.md. Other kinds can be represented in the manifest, but the CLI does not install them or traverse dependency graphs.
Author convention is to use a stable, hyphenated, host-prefixed identifier:
| Kind | Description |
|---|---|
claude-code-skill | Claude Code SKILL.md body |
cursor-rule | Cursor rules file |
mcp-server | Manifest pointing to an MCP server bundle |
cli-binary | Pre-built CLI binary |
The list is not normative — hosts and authors may define new kinds. asrpm --target claude-code selects the first target whose kind is exactly claude-code-skill. Other --target values are currently rejected.
Author
| Field | Type | Required | Description |
|---|---|---|---|
name | string | optional | Human-readable author name |
url | string | optional | Author homepage |
agentId | number | optional | ERC-8004 agent identifier, if the author is itself an on-chain agent |
agentRegistry | string | optional | Address of the agent registry, qualified with the chain (e.g. eip155:1:0x...) |
SkillReference
A SkillReference points to another skill in the registry (or a different registry). Used by dependencies[] and supersedes.
| Field | Type | Required | Description |
|---|---|---|---|
skillId | number | required | Token ID of the referenced skill |
skillRegistry | string | optional | Chain-qualified registry address (e.g. eip155:11155111:0x8239…). Descriptive metadata; the current CLI does not resolve this reference. |
version | string | optional | Version or version constraint metadata; not enforced by the current CLI |
dependencies and supersedes describe relationships only. The current CLI neither installs dependencies nor retrieves historical versions from these fields.
Integrity Format
The integrity field uses an OCI-style algorithm-prefixed hex digest:
<algorithm>:<hex>
| Algorithm | Notes |
|---|---|
keccak256 | Recommended for EVM-native skills; matches the manifestHash commitment algorithm |
sha256 | Recommended for interoperability with non-EVM tooling |
Both supported algorithms produce a 32-byte digest, represented by 64 hexadecimal characters. For example, the SHA-256 digest of the three UTF-8 bytes abc (no newline) is:
sha256:ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad
asrpm verifies the digest by recomputing the hash over the exact bytes returned from the target's URI and comparing to the declared value. Any mismatch aborts the install or verify operation.
URI Schemes
The manifest URI (written to tokenURI) and each target's uri must use one of the following schemes:
| Scheme | Notes |
|---|---|
https:// | Recommended for hosted content. Subject to gateway availability. |
http:// | Supported but discouraged. |
data: | Inline content (base64 or URL-encoded). Recommended for small bodies — the URI is self-contained and does not depend on a gateway. |
The ipfs:// scheme is intentionally not supported by asrpm. Use the HTTPS gateway URL your pinning provider serves (e.g. https://gateway.pinata.cloud/ipfs/<cid>).
Status
The status field is a lifecycle marker. Recognized values:
| Value | Effect |
|---|---|
| (unset) | Standard skill, no warning |
deprecated | asrpm emits a warning in the human-readable resolve, verify, and install output |
Other values are tolerated but have no client-side effect.
Example Manifest
A self-contained example with one claude-code-skill target served from a data: URI. Its SHA-256 digest matches the decoded body, including its final newline:
{
"type": "skill",
"name": "asrpm-example",
"description": "Explain the Agent Skill Registry.",
"version": "0.1.0",
"license": "MIT",
"keywords": ["asr", "erc-8239", "agent-skill", "claude-code"],
"homepage": "https://github.com/vorpalengineering/asrpm",
"repository": "https://github.com/vorpalengineering/asrpm",
"author": {
"name": "Vorpal Engineering",
"url": "https://vorpalengineering.com"
},
"targets": [
{
"kind": "claude-code-skill",
"version": "0.1.0",
"uri": "data:text/markdown;charset=utf-8;base64,LS0tCm5hbWU6IGFzcnBtLWV4YW1wbGUKZGVzY3JpcHRpb246IEV4cGxhaW4gdGhlIEFnZW50IFNraWxsIFJlZ2lzdHJ5LgotLS0KCkV4cGxhaW4gaG93IG1hbmlmZXN0cyBhbmQgdGFyZ2V0IGludGVncml0eSBoYXNoZXMgd29yay4K",
"integrity": "sha256:7e0f6562bc661b91ab0e112700cbb0bbadee4208c1772ae8f3b616a0bf1da779",
"format": "file"
}
]
}
An illustrative manifest with multiple targets and dependencies follows. Its URLs, abbreviated hashes, and author registry are placeholders; replace them with actual values before publishing.
{
"name": "example-skill",
"version": "1.2.0",
"license": "Apache-2.0",
"author": {
"name": "Example Author",
"agentId": 42,
"agentRegistry": "eip155:1:0xAgentRegistry..."
},
"targets": [
{
"kind": "claude-code-skill",
"uri": "https://example.com/skill.md",
"integrity": "keccak256:abc123...",
"format": "file"
},
{
"kind": "cursor-rule",
"uri": "https://example.com/rule.mdc",
"integrity": "sha256:def456...",
"format": "file"
}
],
"dependencies": [
{
"skillId": 0,
"skillRegistry": "eip155:11155111:0x8239AAbaa1A44338bEeFAAf4C3a373d2a18D5DC4",
"version": "^0.1.0"
}
],
"supersedes": {
"skillId": 17,
"version": "1.1.0"
}
}
Authoring Tips
- The manifest URI must serve byte-identical content to the local file you hashed. Any change — trailing newline, key reordering, whitespace — invalidates the on-chain commitment and causes integrity verification to fail for downstream clients.
- Prefer
data:URIs for small manifests and target bodies. They are self-contained and avoid gateway availability issues. - When hosting on IPFS, register the gateway HTTPS URL (e.g.
https://gateway.pinata.cloud/ipfs/<cid>) rather thanipfs://<cid>. Integrity verification works regardless of gateway choice. - Use the
asrpm-prepare.shhelper to handle the body-encoding, hashing, and manifest-splicing steps in one pass.
See Also
- ERC-8239 specification — the normative protocol definition
asrpmCLI Reference —register,publish, and authoring helpers