Skill Audit — On-Chain Provenance Registry
Commands
/check-skill
Look up on-chain provenance for a skill before installing.
- Read all three tables (registry, audits, vouches) for the given skill ID
- Compute trust level from audit verdicts
- Display: trust badge, author, hash, version, audit history, vouch count
/audit-skill
Submit an audit verdict (requires IQ tokens in wallet).
Severities: S (secure), L (low), M (medium), H (high), C (critical)
Optionally run ZeroLeaks first and inscribe full report via codeIn.
/vouch-skill [score]
Community endorsement. Score 1-5 (default 5).
/register-skill
Register a local skill with on-chain hash.
- Read skill.md at given path
- Normalize and SHA-256 hash the content
- Write registration row with short hash (first 8 hex chars)
Trust Badges
- MALICIOUS: BLOCK installation, warn user
- FLAGGED: Strong warning
- CAUTIONED: Mild warning
- VERIFIED: Green checkmark
- AUDITED: Has audits but not yet verified secure
- REGISTERED: In registry, no audits yet
- UNKNOWN: Not in registry — warn "no on-chain provenance"
- Hash mismatch: Warn "content differs from registered version"
Implementation
Package: @rocketlabs/skill-audit
const { checkSkill, registerSkill, auditSkill, vouchForSkill, hashSkill } = require('@rocketlabs/skill-audit');
checkSkill({ connection, skillId, rpcUrl })
Returns: { trustLevel, skill, audits, vouches, summary }
Free (RPC read only, no SOL needed).
registerSkill({ connection, signer, skillId, author, shortHash, version, codeInTx, rpcUrl })
Writes to skill_registry table. Public — anyone can register.
auditSkill({ connection, signer, skillId, auditor, severity, categories, codeInTx, rpcUrl })
Writes to skill_audits table. IQ-token-gated — signer must hold IQ tokens.
Severity: S/L/M/H/C. Categories: dir,enc,per,soc,tec,cre,mny,cot,pol,asc,ctx,sem,too,sir,ech
vouchForSkill({ connection, signer, skillId, voucher, score, rpcUrl })
Writes to skill_vouches table. Public — anyone can vouch. Score 1-5.
hashSkill(content)
Returns: { fullHash, shortHash } — SHA-256 of normalized content.
On-Chain Architecture
- Program:
9KLLchQVJpGkw4jPuUmnvqESdR7mtNCYr3qS4iQLabs
- DB Root ID:
skill-audit
- Tables: skill_registry (public), skill_audits (IQ-gated), skill_vouches (public)
- Row limit: ~100 bytes. Full data via codeIn inscriptions.
- Reads are free. Only writes cost SOL.
- Append-only. No in-place updates. Version counter for re-registration.
Prerequisites
@iqlabs-official/solana-sdk v0.1.1+ (CommonJS required)
@solana/web3.js v1.x
- Solana wallet for writes
- IQ tokens for audit writes (token mint:
3uXACfojUrya7VH51jVC1DCHq3uzK4A7g469Q954LABS)
- Buffer monkey-patch applied (handled automatically by the package)
1---2name: skill-audit3description: On-chain skill provenance registry. Check, register, audit, and vouch for agent skills on Solana. Use when evaluating skill safety, registering new skills, or looking up provenance before installation.4---5
6# Skill Audit — On-Chain Provenance Registry
7
8## Commands
9
10### /check-skill <name>
11Look up on-chain provenance for a skill before installing.
121. Read all three tables (registry, audits, vouches) for the given skill ID
132. Compute trust level from audit verdicts
143. Display: trust badge, author, hash, version, audit history, vouch count
15
16### /audit-skill <name> <severity>
17Submit an audit verdict (requires IQ tokens in wallet).
18Severities: S (secure), L (low), M (medium), H (high), C (critical)
19Optionally run ZeroLeaks first and inscribe full report via codeIn.
20
21### /vouch-skill <name> [score]
22Community endorsement. Score 1-5 (default 5).
23
24### /register-skill <path>
25Register a local skill with on-chain hash.
261. Read skill.md at given path
272. Normalize and SHA-256 hash the content
283. Write registration row with short hash (first 8 hex chars)
29
30## Trust Badges
31- MALICIOUS: BLOCK installation, warn user
32- FLAGGED: Strong warning
33- CAUTIONED: Mild warning
34- VERIFIED: Green checkmark
35- AUDITED: Has audits but not yet verified secure
36- REGISTERED: In registry, no audits yet
37- UNKNOWN: Not in registry — warn "no on-chain provenance"
38- Hash mismatch: Warn "content differs from registered version"
39
40## Implementation
41
42Package: [`@rocketlabs/skill-audit`](https://www.npmjs.com/package/@rocketlabs/skill-audit)
43
44```javascript
45const { checkSkill, registerSkill, auditSkill, vouchForSkill, hashSkill } = require('@rocketlabs/skill-audit');
46```
47
48### checkSkill({ connection, skillId, rpcUrl })
49Returns: `{ trustLevel, skill, audits, vouches, summary }`
50Free (RPC read only, no SOL needed).
51
52### registerSkill({ connection, signer, skillId, author, shortHash, version, codeInTx, rpcUrl })
53Writes to `skill_registry` table. Public — anyone can register.
54
55### auditSkill({ connection, signer, skillId, auditor, severity, categories, codeInTx, rpcUrl })
56Writes to `skill_audits` table. IQ-token-gated — signer must hold IQ tokens.
57Severity: S/L/M/H/C. Categories: dir,enc,per,soc,tec,cre,mny,cot,pol,asc,ctx,sem,too,sir,ech
58
59### vouchForSkill({ connection, signer, skillId, voucher, score, rpcUrl })
60Writes to `skill_vouches` table. Public — anyone can vouch. Score 1-5.
61
62### hashSkill(content)
63Returns: `{ fullHash, shortHash }` — SHA-256 of normalized content.
64
65## On-Chain Architecture
66
67- **Program:** `9KLLchQVJpGkw4jPuUmnvqESdR7mtNCYr3qS4iQLabs`
68- **DB Root ID:** `skill-audit`
69- **Tables:** skill_registry (public), skill_audits (IQ-gated), skill_vouches (public)
70- **Row limit:** ~100 bytes. Full data via codeIn inscriptions.
71- **Reads are free.** Only writes cost SOL.
72- **Append-only.** No in-place updates. Version counter for re-registration.
73
74## Prerequisites
75- `@iqlabs-official/solana-sdk` v0.1.1+ (CommonJS required)
76- `@solana/web3.js` v1.x
77- Solana wallet for writes
78- IQ tokens for audit writes (token mint: `3uXACfojUrya7VH51jVC1DCHq3uzK4A7g469Q954LABS`)
79- Buffer monkey-patch applied (handled automatically by the package)