Instruction-only. Verifiable.
What you buy here is text. This page says exactly what is in it, how to check that you received what we published, and what we cannot promise.
What a purchase contains
- A plain
.mdfile: the skill as text, for ChatGPT, Gemini, Claude Projects or any assistant that takes instructions. - A
.zipfor Claude Skills holding one folder with two text files:SKILL.md, byte-identical to the plain.md, andREADME.md, the install steps.
There are no scripts, no executables, no macros, no installers and no code for your machine to run. The files make no network calls and carry no telemetry. They cannot, because they are text. The plain .md files contain no web addresses at all. The README names our install guides on authority.md as plain text.
You can confirm the zip layout yourself: unzip -l on any of our zips lists one folder and two files, and nothing else.
How to verify a file
We publish a SHA-256 hash for every shipped file at /hashes.json, 765 items in all, computed from the files themselves each time the site is built. Hash your download and compare.
- Open /hashes.json and find your item by its slug, under
personas,toolsorplaybooks. - Hash the file you received. On macOS or Linux:shasum -a 256 meeting-pre-read-skill.md
On Windows PowerShell:
Get-FileHash meeting-pre-read-skill.md -Algorithm SHA256 - Compare the result with the manifest entry. For the Meeting Pre-Read Tool, the manifest currently lists:meeting-pre-read-skill.md 4d0191b287bf350d4bb59262857de4fd73736f533366d5eb28361c6fd25bc610 meeting-pre-read.zip 11525293d22f793b6888b4444080f2b4141d5987a08fdefe3f4c1f5244b7c7ae
If the hashes match, the file is the one we published. If they do not, do not use it, and tell us. The zip hash matches the zip we email because both are built by the same packager with fixed timestamps, so the same content always produces the same bytes.
What we never do
- Run code on your machine, or ship anything that could.
- Collect data from inside a skill. Nothing in a file reports how, where or whether you use it.
- Ask for your API keys, your assistant account or access to your files.
- Change a published file without its hash changing with it.
One honest footnote on tracking: the delivery email is sent through an email provider that records whether the email was opened. The files attached to it record nothing.
What this does not cover
- We cannot vouch for how your assistant handles any file. Any instruction you load into an AI shapes what it does, including ours. Read a skill before you load it, as you would any instruction you hand a colleague.
- A matching hash proves the file is the one we published. It does not prove the content is right for your situation. The frameworks are generated with AI from each subject's public record and can contain errors; see the terms.
- If you edit a file, its hash will change. That is expected.
- Payments are handled by Stripe and email delivery by our email provider. Their security is theirs; what we do with your details is in the privacy policy.
- How well a skill performs with a given model is a separate question. See how we test.
Reporting a problem
If you find a file that does not match its published hash, a way our files or site could harm a user, or anything else that looks wrong, email hello@authority.md with the subject “Security disclosure”. Say what you found and how to reproduce it. The same inbox takes everything else, and a person reads it.