ce-proof
everyinc/compound-engineering-plugin
Publish, read, comment on, and edit markdown documents in Proof—a collaborative editor for specs, plans, and drafts.
What is ce-proof?
Proof is a collaborative markdown editor accessible via HTTP API at proofeditor.ai. Use it to publish local markdown files as shareable links, read and edit shared documents, add comments and suggestions, and pull docs back to local files. Ideal for sharing specs, plans, drafts, and publishing handoffs from planning workflows.
- Publish local markdown files to Proof and generate shareable tokenized links
- Read and retrieve the full content of shared Proof documents
- Add comments, replies, suggestions, and tracked changes to documents
- Edit document content with scoped operations (replace, insert, delete)
- Pull Proof documents down to local markdown files
- Manage document presence and track agent identity on edits
How to install ce-proof
npx skills add https://github.com/everyinc/compound-engineering-plugin --skill ce-proof- Access to proofeditor.ai API
- Read references/api.md before first use to understand endpoints and error handling
- Read references/workflows.md before creating, sharing, or pulling documents
How to use ce-proof
- 1.Read the local markdown file you want to publish
- 2.POST the file contents to Proof's share/markdown endpoint to create a new document
- 3.Capture and persist both the accessToken and ownerSecret from the response
- 4.Share the tokenized URL (tokenUrl) with users—never share bare document links
- 5.To edit: GET /api/agent/<slug>/v3/document to read current state, then POST operations (replace, insert, delete, suggest, comment) to /api/agent/<slug>/v3/edit
- 6.To pull a document: GET /api/agent/<slug>/v3/document and write the markdown content to a local file
- 7.Use MCP tools (proof_share_markdown, proof_v3_document, proof_v3_edit, etc.) if available in your harness; otherwise use HTTP recipes
Use cases
- Share a specification or plan markdown file with stakeholders via a Proof link
- Review a shared Proof document and add comments or suggestions for feedback
- Publish a handoff document from a planning workflow (ce-brainstorm, ce-ideate, ce-plan) to Proof
- Collaborate on a draft by making tracked-change suggestions instead of direct edits
- Pull a collaboratively edited Proof document back to a local file for further processing
- Teams sharing specifications, plans, and design documents
- Agents publishing handoffs from planning or brainstorming workflows
- Users collaborating on markdown-based documentation
- Project leads distributing drafts and specs to stakeholders
ce-proof FAQ
At creation, capture both accessToken (for everyday read/edit/presence) and ownerSecret (for owner-level operations like delete). Keep ownerSecret separate and secure; never commit it to repos. If a signed-in Every user claims the doc, ownerSecret is revoked and delete requires the owner's session instead.
Yes, if you have the shareToken from the tokenized link. Use GET /api/agent/<slug>/v3/document to read the current state, then POST operations to /api/agent/<slug>/v3/edit. Pass the token as shareToken for edits on docs you don't own.
The anchor text matched more than once. Use the candidates from error.candidates to disambiguate with occurrence, before, or after parameters. Never assume silent first-match or blind-retry; always specify which occurrence you mean.
Publishing is one-way. The local file remains canonical; changes in Proof do not sync back to disk. If you want the edited version locally, pull the document back down to a file.
No. Emptying markdown does not remove comment marks, quotes, or commentary. Anyone with the share credential can still read them. To fully remove a document and its history, delete it using ownerSecret (if unclaimed) or the owner's session (if claimed).
Full instructions (SKILL.md)
Source of truth, from everyinc/compound-engineering-plugin.
name: ce-proof description: Publish, read, comment on, or edit markdown in Proof. Use for Proof links, sharing specs/plans/drafts, or publish handoffs from planning workflows; avoid proofread, math, evidence, or proof-of-concept meanings. allowed-tools:
- Bash
- Read
- Write
- WebFetch
Proof - Collaborative Markdown Editor
Proof is a collaborative document editor for humans and agents. It is reached through the hosted web API at https://www.proofeditor.ai, over HTTP from Bash.
Outcome: the user holds a working tokenized Proof link, or the doc carries the read, comment, suggestion, or edit they asked for.
Done: the operation is confirmed at its own level, and the user has the result plus a short summary. A create is confirmed by the tokenUrl it returned. A mutation is confirmed by ok: true; on a 202 or a partial: true response, confirm by re-reading v3/document. A pull is confirmed by the local file it wrote, and a read by the content it returned.
Read references/api.md before the first Proof read or mutation, HTTP or MCP. It defines the endpoints: share/markdown, the v3 document and edit endpoints, presence, title, and DELETE /api/documents/<slug>. It also carries the operation tables, the error and retry classes, and the curl permission hint for Claude Code.
Read references/workflows.md before reviewing a shared doc, before creating and sharing one, and before pulling a doc to a local file. Those flows have exact recipes there.
If typed proof_* MCP tools are already available in the harness (proof_share_markdown, proof_v3_document, proof_v3_edit, proof_presence, proof_document_title, proof_document_delete, proof_report_bug), prefer them. Otherwise use the HTTP recipes. In MCP mode the server injects by, X-Agent-Id, and presence identity. Pass the ?token= value from the Proof URL as shareToken for edits and presence on docs the signed-in user does not own.
Delete authority is unchanged in MCP mode. An unclaimed doc still needs its ownerSecret, and a claimed doc needs its owner's session. An editor accessToken passed as shareToken cannot delete.
Identity
Every write is attributed with both fields, and they do not vary. The machine ID is ai:compound-engineering, sent as by on every op and as the X-Agent-Id header. The display name is Compound Engineering, sent as name on POST /presence, set once per doc session so Proof binds it to that agent ID. A caller may pass a different identity pair when a distinct sub-agent should own the doc. Never improvise a variant such as ai:compound.
Credentials and boundaries
accessTokenis the everyday bearer for read, edit, presence, and events.ownerSecretcarries owner authority only — delete and other owner-level ops — and is never the everyday bearer. Capture both at create time, and persistownerSecretfor the session separately fromaccessToken, in shell vars or equivalent; it is required for owner delete while the doc is unclaimed. Neither belongs in repo-tracked files, commits, or durable logs, andownerSecretnever appears in user-facing copy.- Hand humans the tokenized link (
tokenUrl), never a bare/d/<slug>— the token in that link is also what lets a signed-in user claim an ownerless doc. - Public creates are ownerless until a signed-in Every user claims the doc in the browser. Claiming permanently revokes
ownerSecretwhileaccessTokenkeeps working, so delete then needs the owner's Every session — ask the owner, or use their session token. Two responses mean the secret was revoked: a403withcode: "DOCUMENT_DELETE_FORBIDDEN"andreason: "CREDENTIAL_NOT_OWNER", or a401when presenting the creationownerSecret. Stop using the secret rather than retrying.reason: "DOCUMENT_HAS_NO_OWNER"is the opposite: the doc is still unclaimed, so only the originalownerSecretcan delete it and an Every session cannot. - Never put secrets, credentials, API keys, private tokens, or sensitive personal data into a Proof doc unless the user explicitly approves, and never silently replace a repo-tracked project doc with a Proof link.
- Emptying the markdown does not scrub comment marks. Quotes and commentary stay readable to anyone with the share credential, so a content wipe is not a privacy cleanup. Deleting the document is — with
ownerSecretwhile the doc is unclaimed, or as the owner after a claim. - Do not auto-delete after a publish handoff. Review docs must linger. Delete when the user asks, or when finishing an explicitly ephemeral scratch doc.
Publish mode
The primary use is one-way publishing. Read an existing local markdown file in full, post its contents as the new doc's body, and hand the user the shareable URL. The local file stays canonical — publishing syncs nothing back to disk.
Two entry points share those mechanics. One is a bare user request naming a local markdown file ("share this to proof", "get me a proof link for this doc"); ask which file only if it is ambiguous, and expect no upstream caller. The other is a handoff from ce-brainstorm, ce-ideate, or ce-plan passing the file path and title.
Only publish markdown. If the source is an HTML unified plan, return the local browser/open path instead of uploading it. When publishing a unified plan, label the title by readiness when it is known, e.g. Plan: <title> (requirements-only) or Plan: <title> (implementation-ready).
Publish the source file's bytes, never hand-written or placeholder content. references/workflows.md gives the jq --rawfile recipe that escapes newlines, quotes, and backticks correctly. After a publish handoff, show the user the URL and return control.
Editing
GET /api/agent/<slug>/v3/document and POST /api/agent/<slug>/v3/edit are the only endpoints an agent reads from and writes to. Comments, replies, resolutions, suggestions, and content changes are all operations in the v3 edit body, so a path you did not read in references/api.md is one you invented.
Read v3/document as the source of truth before editing. Then choose the narrowest operation that expresses the change: a scoped replace, insert, or delete for prose; suggest when the change should be visible as tracked changes; set_document only when the user asks for a whole-doc replacement, or the change cannot be expressed narrowly. Targets are visible text in markdown, never raw markdown syntax or block refs.
comments[] and suggestions[] from that read are the review state. Reply, resolve, unresolve, accept, or reject by id. v3 has no delete-comment op. A comment marked orphaned: true is still readable and replyable, but its old quote is no longer a live anchor.
Errors that mean stop and check, before retrying anything:
TARGET_AMBIGUOUS— the anchor matched more than once and nothing changed. Disambiguate withoccurrence/before/afterfromerror.candidates; never assume silent first-match, and never blind-retry a comment.retryable: false— fix the request.retryable: truewitherror.current— re-resolve targets againstcurrent, then retry once.202/PENDING, orok: falsewithpartial: true— the write may have committed. Re-readv3/documentbefore chaining or reporting success, and retry only the failed op (a repeatedIdempotency-Keyreplays safely).- Still failing after a fresh read and one safe retry — report the bug per
references/api.mdrather than looping.
Pulling a doc down to a local file overwrites that file. When the pull is a side effect of some other action rather than something the user asked for, confirm the path first.
Related skills
More from everyinc/compound-engineering-plugin and the wider catalog.

ce-release-notes
Look up recent compound-engineering plugin releases and answer questions about past changes with version citations.

ce-report-bug
Report bugs in the compound-engineering plugin with structured information and automated GitHub issue creation.

ce-resolve-pr-feedback
Resolve PR review feedback by evaluating, fixing, and replying to comments left on pull requests.

ce-riffrec-feedback-analysis
Analyze recorded product feedback into structured bug reports and requirements evidence.

ce-sessions
Search and synthesize coding agent session history across Claude Code, Codex, and Cursor.

ce-setup
Check Compound Engineering health, validate repo config, and scaffold new Compound Packs.