Agent skill

Content Addressable Storage Immutability

by divinevideo in divinevideo/divine-mobile

CRITICAL: Never modify files in content-addressable storage systems where the filename IS the content hash (SHA256, IPFS CID, etc.).

MPL-2.0Auto-check passedSecurity

Install Content Addressable Storage Immutability

skills CLI
$ npx skills add divinevideo/divine-mobile --skill content-addressable-storage-immutability -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install divinevideo/divine-mobile content-addressable-storage-immutability --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/divinevideo/divine-mobile.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/content-addressable-storage-immutability .claude/skills/content-addressable-storage-immutability && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
content-addressable-storage-immutability
GitHub stars
266
Token cost
~984 tokens
SKILL.md length
257 words
Files
1
Skills in repo
103
Repo updated
First seen
Licence
MPL-2.0

At a glance

CRITICAL: Never modify files in content-addressable storage systems where the filename IS the content hash (SHA256, IPFS CID, etc.).

  • Works in 4 steps: "It's just moving metadata" - Still… → "We'll update the hash reference" - Now… → "No one will notice" - Verification… → …
  • Working with Blossom protocol
  • SKILL.md covers Problem, Context / Trigger Conditions, The Fundamental Rule and What Goes Wrong, plus 6 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Content Addressable Storage Immutability is an agent skill from divinevideo/divine-mobile. CRITICAL: Never modify files in content-addressable storage systems where the filename IS the content hash (SHA256, IPFS CID, etc.). Use when: (1) Working with Blossom protocol, IPFS, or any CAS system, (2) Considering "optimizing" stored files (faststart, compression), (3) Implementing transcoding or processing pipelines for hash-identified content, (4) Building on top of ProofMode or any cryptographic verification system. Modifying files in place breaks hash verification and content integrity.

Its SKILL.md is about 980 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Cryptography. The licence is MPL-2.0.

When your agent uses it

  • Working with Blossom protocol
  • Considering optimizing stored files (faststart
  • Implementing transcoding
  • Processing pipelines for hash-identified content

Example prompts

  • “optimizing”
  • “/content-addressable-storage-immutability”

Requirements

  • Docker

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. "It's just moving metadata" - Still changes bytes, still breaks hash
  2. "We'll update the hash reference" - Now you have dangling references everywhere
  3. "No one will notice" - Verification systems WILL notice
  4. "It's an optimization" - Optimize derivatives, not originals

What it can do on your machine

Read from SKILL.md and the folder at commit 4c622be. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are rust).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • en.wikipedia.org
    • github.com
    • docs.ipfs.tech

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Content Addressable Storage Immutability loads about 984 tokens when it runs. Until then it costs about 135 tokens; SKILL.md has 257 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~135
When it runs · the whole SKILL.md, loaded when a task matches
~984

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from divinevideo/divine-mobile at commit 4c622be, republished under its MPL-2.0 licence (© divinevideo). 257 words, ~984 tokens.

Download SKILL.mdSave it as .claude/skills/content-addressable-storage-immutability/SKILL.md (or your agent's skills folder).
name
content-addressable-storage-immutability
description
CRITICAL: Never modify files in content-addressable storage systems where the filename IS the content hash (SHA256, IPFS CID, etc.). Use when: (1) Working with Blossom protocol, IPFS, or any CAS system, (2) Considering "optimizing" stored files (faststart, compression), (3) Implementing transcoding or processing pipelines for hash-identified content, (4) Building on top of ProofMode or any cryptographic verification system. Modifying files in place breaks hash verification and content integrity.
author
Claude Code
version
1.0.0
date
2026-01-31

Content-Addressable Storage Immutability

Problem

In content-addressable storage (CAS) systems, files are identified by their content hash. If you modify a file in place (even "harmless" optimizations), the content no longer matches its identifier, breaking the entire system's integrity guarantees.

Context / Trigger Conditions

  • Working with Blossom protocol (files at /{sha256})
  • Working with IPFS (files at /ipfs/{CID})
  • Any system where filename = hash of content
  • Considering file optimizations like:
    • MP4 faststart (moving moov atom)
    • Image optimization/compression
    • Metadata stripping
    • Format conversion
  • Systems using ProofMode or cryptographic verification

The Fundamental Rule

NEVER modify a file stored at its content hash.

The hash IS the identity. Change the content → change the hash → file is now at wrong address.

What Goes Wrong

Original file: abc123... (hash) → contains bytes X
After "optimization": abc123... (hash) → contains bytes Y

Result:
- Hash abc123 no longer verifies
- ProofMode signatures invalid
- Content-addressable lookups return wrong data
- Cryptographic proofs broken
- Data integrity compromised

Solution: Store Derivatives Separately

If you need optimized/processed versions, store them at separate paths:

/{hash}                    ← Original file (NEVER MODIFY)
/{hash}/hls/master.m3u8    ← HLS transcoded version
/{hash}/faststart.mp4      ← Faststart optimized version
/{hash}/thumb.jpg          ← Thumbnail
/{hash}/720p.mp4           ← Resolution variant

The original stays byte-for-byte identical. Derivatives live in subdirectories.

Implementation Pattern

rust
// WRONG - modifies original
async fn process_video(hash: &str) {
    let path = format!("/{}", hash);
    let video = download(&path);
    let optimized = apply_faststart(video);
    upload(&path, optimized);  // ❌ BREAKS HASH!
}

// RIGHT - creates derivative
async fn process_video(hash: &str) {
    let original_path = format!("/{}", hash);
    let derivative_path = format!("/{}/faststart.mp4", hash);

    let video = download(&original_path);
    let optimized = apply_faststart(video);
    upload(&derivative_path, optimized);  // ✓ Original untouched
}

Verification

  • Original file hash still verifies: sha256sum file == filename
  • ProofMode signatures still valid
  • Content lookups return expected data

Common Mistakes

  1. "It's just moving metadata" - Still changes bytes, still breaks hash
  2. "We'll update the hash reference" - Now you have dangling references everywhere
  3. "No one will notice" - Verification systems WILL notice
  4. "It's an optimization" - Optimize derivatives, not originals

Notes

  • This applies to ANY content-addressable system, not just Blossom
  • IPFS, Git objects, Docker layers all follow this principle
  • If you need the optimized version as primary, the client should upload it that way
  • Transcoding to new formats (HLS, DASH) is fine because they're clearly separate files

References

© divinevideo, MPL-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/content-addressable-storage-immutability of divinevideo/divine-mobile.

Open the folder on GitHubat commit 4c622be

Compare with similar skills

Content Addressable Storage Immutability next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Content Addressable Storage Immutability compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Content Addressable Storage Immutability this skilldivinevideo/divine-mobile266—~984Automated safety check: PassMPL-2.0
Bom Explorecdxgen/cdxgen1.1k—~1.2kAutomated safety check: PassApache-2.0
Webcrypt MCPputervision/state-memory-mcp111—~847Automated safety check: PassMIT
Security Reviewvalory-xyz/open-autonomy129—~11kAutomated safety check: NotesApache-2.0
Hashcat Password Recovery WorkflowAgentSecOps/SecOpsAgentKit2201 repos~3.3kAutomated safety check: NotesCustom licence
Altllm Portal Authinternet-court/internet-court-skill6.4k1 repos~632Automated safety check: PassISC

Similar skills

  • Bom Explore

    cdxgen/cdxgen

    Explores and triages a CycloneDX BOM interactively with the cdxi REPL, using built-in commands for dependency trees, licenses, services, cryptographic assets, audit findings, evidence occurrences…

    1.1k GitHub stars~1.2k tokensUpdated yesterday
    SecurityAuto-check passed
  • Webcrypt MCP

    putervision/state-memory-mcp

    Teaches the agent to use the WebCrypt MCP server for AES-256-GCM symmetric encryption, RSA-4096 hybrid encryption, key generation, digital signatures, hashing, and post-quantum cryptography.

    111 GitHub stars~847 tokensUpdated 5 days ago
    SecurityAuto-check passed
  • Security Review

    valory-xyz/open-autonomy

    Security review of an open-autonomy agent service — cryptographic key handling, dynamic code execution, ABCI authentication and replay, secret exposure, dependency supply chain, and deployment…

    129 GitHub stars~11k tokensUpdated 24 days ago
    SecurityAuto-check: notes
  • Hashcat Password Recovery Workflow

    AgentSecOps/SecOpsAgentKit

    Guides authorized password-hash recovery with hashcat for security audits, forensic cases and policy testing, starting with an explicit authorization check before any cracking runs.

    220 GitHub starsUsed in 1 repo~3.3k tokens
    SecurityAuto-check: notes
  • Altllm Portal Auth

    internet-court/internet-court-skill

    A skill your agent uses when the user asks to log in or out with a wallet session, fetch a wallet sign-in challenge, verify an externally signed challenge, or troubleshoot AltLLM Portal wallet login…

    6.4k GitHub starsUsed in 1 repo~632 tokens
    SecurityAuto-check passed
  • Crypto Analysis

    hypnguyen1209/offensive-claude

    A skill your agent uses when assessing cryptography — TLS/PKI auditing, RSA/ECC key attacks, ECDSA nonce lattice recovery, symmetric/AEAD misuse, JWT/JOSE forgery, hash cracking, post-quantum…

    386 GitHub stars~2.2k tokensUpdated 11 days ago
    SecurityAuto-check passed

More from divinevideo/divine-mobile

All 103 skills in this repo
  • Fix ArgoCD ExternalSecret deployment failing with "namespace X is not permitted in project Y".

    266 GitHub stars~931 tokensUpdated today
    Auto-check passed
  • Art Direct

    divinevideo/divine-mobile

    Art direction for any content — reads text, PDF, Word, HTML, PPT, then proposes 2-3 creative directions with photography style, mood, and visual language.

    266 GitHub stars~4.8k tokensUpdated today
    Auto-check passed
  • Async Await Null Race Condition

    divinevideo/divine-mobile

    Fix "Null check operator used on a null value" errors when an object is set to null during an async await.

    266 GitHub stars~881 tokensUpdated today
    Auto-check passed
  • AWS V4 Signing Custom Headers Gcs

    divinevideo/divine-mobile

    Add custom metadata headers (x-amz-meta-) to AWS v4 signed requests for GCS S3-compatible API.

    266 GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Bash Herestring Newline Secrets

    divinevideo/divine-mobile

    Fix password/secret authentication failures caused by trailing newlines when creating Google Cloud secrets (or similar) with bash here-strings.

    266 GitHub stars~791 tokensUpdated today
    Auto-check passed
  • Fix silent video/media processing failures caused by URL extraction code that filters on file extensions (.mp4, .webm, .webp).

    266 GitHub stars~1.1k tokensUpdated today
    Auto-check passed

Categories

Questions about Content Addressable Storage Immutability

What does Content Addressable Storage Immutability do?

CRITICAL: Never modify files in content-addressable storage systems where the filename IS the content hash (SHA256, IPFS CID, etc.). Content Addressable Storage Immutability is an agent skill from divinevideo/divine-mobile.).

When should I use Content Addressable Storage Immutability?

Content Addressable Storage Immutability fits situations like: working with Blossom protocol; considering optimizing stored files (faststart; implementing transcoding; processing pipelines for hash-identified content.

How do I install Content Addressable Storage Immutability in Claude Code?

Run `npx skills add divinevideo/divine-mobile --skill content-addressable-storage-immutability -a claude-code`. Or copy the skill folder (.agents/skills/content-addressable-storage-immutability in divinevideo/divine-mobile) into .claude/skills/content-addressable-storage-immutability in your project. Claude Code loads it when a task matches its description.

How do I install Content Addressable Storage Immutability in Codex?

Run `npx skills add divinevideo/divine-mobile --skill content-addressable-storage-immutability -a codex`. Or copy the skill folder (.agents/skills/content-addressable-storage-immutability in divinevideo/divine-mobile) into .agents/skills/content-addressable-storage-immutability in your project. Codex loads it when a task matches its description.

Can I use Content Addressable Storage Immutability in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add divinevideo/divine-mobile --skill content-addressable-storage-immutability -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/content-addressable-storage-immutability, .gemini/skills/content-addressable-storage-immutability, .github/skills/content-addressable-storage-immutability and .opencode/skills/content-addressable-storage-immutability in your project.

What does Content Addressable Storage Immutability need to run?

SKILL.md names no scripts, command-line tools or credentials: Content Addressable Storage Immutability is instructions for the agent only. Our summary lists: Docker.

Does Content Addressable Storage Immutability access the network?

SKILL.md names 3 domains. As links in the text: en.wikipedia.org, github.com and docs.ipfs.tech. This is read from the text; nothing was executed.

Is Content Addressable Storage Immutability safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Content Addressable Storage Immutability use?

Content Addressable Storage Immutability is published under the MPL-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Content Addressable Storage Immutability use?

About 984 tokens (SKILL.md is roughly 3.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Content Addressable Storage Immutability?

Skills that share tags, products or a category with Content Addressable Storage Immutability: Bom Explore (cdxgen/cdxgen, 1.1k stars), Webcrypt MCP (putervision/state-memory-mcp, 111 stars), Security Review (valory-xyz/open-autonomy, 129 stars) and Hashcat Password Recovery Workflow (AgentSecOps/SecOpsAgentKit, 220 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Content Addressable Storage Immutability?

divinevideo (a GitHub organization) maintains it in divinevideo/divine-mobile, which has 266 GitHub stars. The repository holds 103 skills in this directory. The repository was last updated on October 8, 2026.

Source: divinevideo/divine-mobile on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.