GoCertius_MCP: Command for Claude Code

.claude/commands/evidence-lifecycle.md

evidence-lifecycle is a command for Claude Code from g-digital-by-Garrigues/GoCertius_MCP. It costs 0 tokens per session (1,373 once invoked), scanned A, original, MIT.

A workflow for grouping files as evidence in GoCertius, a system for managing and certifying case records. Each evidence group must be sealed before it becomes certified.

In plain words
What is it for?
Use it to locate or create a case file, create an evidence group, add one or more files, and seal the group for certification.
Why use it?
It prevents files from remaining in an unfinished capturing state. It also defines the case file, group, file name, title, and SHA-256 hash information needed for certification.

Command for Claude Code

Written for Claude Code: installed under .claude/. Also seen: positional $N argument; mentions Claude Code.

This is g-digital-by-Garrigues/GoCertius_MCP's own configuration. It tells Claude Code how to work on GoCertius_MCP itself, so it is not a mod to install elsewhere. Copy it as a starting point and replace the rules that are about this project. Everything GoCertius_MCP configures →

Reuse

Borrowing it

Nothing to install: this file belongs to g-digital-by-Garrigues/GoCertius_MCP. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.

Copy the file
curl -O https://raw.githubusercontent.com/g-digital-by-Garrigues/GoCertius_MCP/main/.claude/commands/evidence-lifecycle.md
Clone the repo
git clone --depth 1 https://github.com/g-digital-by-Garrigues/GoCertius_MCP

Made for: Claude Code.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for evidence-lifecycle

README.md
[![agentmods](https://agentmods.dev/badge/commands/g-digital-by-garrigues/gocertius_mcp/evidence-lifecycle/github.svg)](https://agentmods.dev/commands/g-digital-by-garrigues/gocertius_mcp/evidence-lifecycle)
Your own site
<a href="https://agentmods.dev/commands/g-digital-by-garrigues/gocertius_mcp/evidence-lifecycle"><img src="https://agentmods.dev/badge/commands/g-digital-by-garrigues/gocertius_mcp/evidence-lifecycle/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for evidence-lifecycle

Your own site · 80×15
<a href="https://agentmods.dev/commands/g-digital-by-garrigues/gocertius_mcp/evidence-lifecycle"><img src="https://agentmods.dev/badge/commands/g-digital-by-garrigues/gocertius_mcp/evidence-lifecycle.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 0 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 1,373 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00000 $0.01373
Opus 5 $0.00000 $0.00687
Sonnet 5 $0.00000 $0.00275
Haiku 4.5 $0.00000 $0.00137

Measured 11d ago against content hash e4e770c232c8, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-11, from the pricing page.

Security

Grade A, and why

evidence-lifecycle scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.claude/commands/evidence-lifecycle.md · 97 lines

How it starts

The opening of the file, as written. The whole thing — 97 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Evidence Lifecycle

Create and certify evidence in GoCertius. Evidence is always grouped: you create a group, add N evidences to it, then seal the group. Sealing is mandatory — an unsealed group stays in "capturing" state and is never certified.

Hierarchy

Case File
  └─ Evidence Group  (container; sealed once = certified)
       └─ Evidence   (one file per evidence item)

Required inputs

  • case_file_id — UUID of the target case file (call session_infocase_file_list if unknown)
  • use_case_id — UUID of the use case; reuse the one from an existing case file in the same account
  • One or more files to certify: for each file you need its fileName, a human title, and the SHA-256 hash of the file content

Flow

  1. Locate or create a case file

    • session_info → get userId
    • case_file_list with userId to find an existing case file
    • Or case_file_create if none exists (requires id UUID, name, description, useCaseId)
  2. Create an evidence group

    • evidence_group_create with a generated UUID id, name, evidenceType: "FILE", and caseFileId
    • Note the group UUID — needed for every evidence and the final seal
  3. Add evidence items (one call per file)

    Choose custody type based on who stores the file:

    EXTERNAL — you hold the file, GoCertius records the hash as proof of existence:

    • evidence_create with custodyType: "EXTERNAL", id, title, fileName, hash (SHA-256 hex, 64 chars), evidenceGroupId, caseFileId
    • The API may return a network error even when the evidence was persisted — verify with evidence_list if in doubt

    INTERNAL — GoCertius stores the file in S3, allowing the platform to verify the hash directly:

    • Easiest path — evidence_upload: pass the local file (filePath in stdio mode, or contentBase64) plus caseFileId, evidenceGroupId, title, fileName. It computes the SHA-256, registers the evidence, and uploads the bytes in one call — no manual hashing or PUT. Use this when the file is on the local machine.
    • Manual path — evidence_create with custodyType: "INTERNAL", same fields plus hash:
    • Response contains { uploadFileUrl, expiration } — a pre-signed S3 URL (valid ~10 min)
    • Upload the file: PUT <uploadFileUrl> with headers:
      • Content-Type: <mime-type>
      • x-amz-checksum-sha256: <sha256-base64> (SHA-256 of the file content, base64-encoded, not hex)
    • A 200 from S3 confirms the upload; GoCertius processes it asynchronously
    • Or pass fileUrl (public HTTPS, no redirect, <1 GiB) to evidence_create to have it download+upload automatically
    • Computing the base64 checksum: openssl dgst -sha256 -binary <file> | base64

Read the full file on GitHub · 97 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 11d ago First seen · 97 lines · 0 tokens per session scan A e4e770c232c8

Subscribe to this mod's changes

evidence-lifecycle is a command published in the GitHub repository g-digital-by-Garrigues/GoCertius_MCP (0 stars, last pushed 3d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 1,373 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.