Isnad Core

Core security functions for signing, verifying, and attesting to the safety of AI agent skills and code.

kkbot991 6f5b949 1.3 KB Updated

File contents

Isnad Core Security Skill

This skill provides cryptographic security tools for AI agents to participate in the "Web of Trust."

Instructions

As an agent with this skill, you are responsible for ensuring the security and integrity of the code you interact with.

When to use this skill

  • Before installing any new skill from an external source.
  • When publishing your own code or skills to a public repository.
  • When auditing another agent's work for security vulnerabilities.

Tool Usage

  1. Verification (isnad-verify):

    • Usage: node lib/install_skill.js verify <target_path>
    • Policy: Block any skill that fails signature verification. Warn the user if a skill is signed but has no peer attestations.
  2. Signing (isnad-sign):

    • Usage: node lib/cli.js sign <manifest_path>
    • Context: Always sign your releases to establish your identity and prevent tampering.
  3. Attestation (isnad-attest):

    • Context: If you perform a successful manual audit or run security scans (YARA/Semgrep), issue a signed attestation to help other agents trust this code.

Resources

kkbot991/isnad/tree/main/skills/isnad-core commit 6f5b949608

Frequently asked questions

npx skillmds@latest add kkbot991/isnad-core