Marketplace

commitment

unrated

Unrated (not enough evidence yet)

Signature verified (ed25519)no evidence yet
Installs (k-anonymous)no evidence yet
Install success rateno evidence yet
Post-install survivalno evidence yet

Rating starts once every component has real evidence. Missing evidence is stated, never faked as zero.

repoops/commitment · verb · by repoops

Install
npx repoops

https://www.repoops.ai/marketplace/install/repoops/commitment

The link opens this pack. The command installs the RepoOps app and carries no pack id, so the two are not the same artifact. Installing a pack by id checks its ed25519 signature against your repo's trust list and lands it HELD for your approval, so nothing runs until you approve. That path is built but is not in a shipped command yet.

What install does.

  1. Resolves this id. The signed-pack path (fetch, ed25519 signature checked against your repo's trust list, no skip path for a tampered or unsigned pack) is built but is not in a shipped command yet: npx repoops installs the desktop app, not a pack.
  2. Installed from the app's Marketplace tab, a first-party catalog entry comes from the copy already on this machine, so nothing is fetched and there is no signature to verify.
  3. Lands the pack HELD as one inert proposal. Nothing runs, nothing edits a file.
  4. You approve or reject it on your Marketplace tab. Approval runs no code: it keeps the note, and for a signal-rule pack it writes that pack's regex rules where your next scan reads them. Reject deletes the note and writes nothing.