1.7k Downloads
Overview
Command-line tool to cryptographically sign and verify OpenClaw skill folders using ed25519 keys, including trust management and provenance chains.
Key Advantages
1.Provides strong integrity protection for skill folders via SHA-256 manifests signed with ed25519 keys.
2.Detects any modified, added, or removed files after signing, reducing risk of silent tampering.
3.Implements a simple trust model for authors via public-key fingerprints and a local trusted-authors list.
4.Offers provenance chain (isnād) inspection to see the full signing history of a skill folder.
5.Minimal runtime footprint: a single Python file plus the widely used `cryptography` library dependency.
Use Cases
- Verifying downloaded or shared skills before installing or executing them in an agent environment.
- Signing skills before publication so others can authenticate authorship and detect later modifications.
- Periodic integrity audits of a local skill library to detect unauthorized or accidental changes.
- CI/CD pipelines that sign build artifacts (skill folders) and verify them before deployment.
- Collaborative teams exchanging skills with verified authorship and trackable signing history.
Evaluation Scores
8.7
/ 10
Reliability
7.8
Functionality
8.7
Usability
8.8
Safety
9.3
Performance
9.0
Compatibility
8.5
Based on 1 evaluation · Latest: 3/19/2026
Download Trend
Loading...
Evaluation History (1)
8.7/103/19/2026▼
OS: darwin-x64LLM: anthropic/claude-opus-4.6
**Judgement:** A focused, technically sound signing/verification utility that can significantly improve integrity and provenance management for OpenClaw skill folders, assuming `cryptography` is available and teams are willing to manage keys.
**What it does well**
- Uses modern primitives (SHA-256 + ed25519) to sign skill-folder manifests and verify them later.
- Catches a broad range of tampering (modified, added, or deleted files) relative to the original signed state.
- Provides clear CLI commands: `keygen`, `sign`, `verify`, `inspect`, `trust`, `trusted`, and `chain`.
- Maintains a local trust list so you can distinguish trusted vs. untrusted signers.
- Provenance chain (isnād) is especially useful to understand multi-author or re-signed skills over time.
**Key risks & limitations**
- **Key management risk:** Loss or compromise of the private key means you either lose signing continuity or an attacker could sign malicious skills in your name. There’s no built-in revocation or rotation policy.
- **Local-only trust model:** Trust is stored locally; different machines or environments may have inconsistent trust sets unless explicitly synchronized.
- **No code-safety guarantees:** It ensures integrity and authorship, but does not analyze or sandbox the skill code—signed code can still be malicious.
- **Operational overhead:** Teams must adopt processes for distributing public keys, updating trusted lists, and deciding trust policies.
**Recommended scenarios**
- You distribute or consume skills across machines or teams and want a straightforward way to verify that folders are unmodified and actually authored by specific identities.
- You operate a skill marketplace or internal registry and want a lightweight signing standard for submissions.
- You run agents in sensitive environments (production, regulated contexts) and need periodic integrity audits of installed skills.
- You want reproducible, auditable provenance chains for skills as they evolve and are re-signed by different maintainers.
Comments (0)
No comments yet. Be the first!