在安装或发布前,为待审查的 skill 包生成结构化风险报告。
编程
Settlement Witness
在本地核验 SAR v0.1 结算回执的 Ed25519 签名与 RFC 8785 规范化摘要。
它能做什么
完全在本地完成 SAR v0.1 结算回执的密码学校验,无需联网。从已签名的核心字段重新计算规范化摘要,比对 `receipt_id`,再用内置公钥注册表验证 Ed25519 签名。输出 JSON 结果,包含 `valid`、`receipt_id`、`kid`、三种结论之一(`PASS`/`FAIL`/`INDETERMINATE`)以及错误列表。随包附带 fixture,可通过 `--self-test` 自检,并能验证篡改回执确实会被拒。
什么时候用它
- 在信任其他 agent 的「任务完成」声明前先验签
- 把回执接到下游动作前确认其有效
- 将回执作为证据使用前进行核验
- 离线核验涉及结算或支付环节的声明
技能文档
New in 0.1.0: local-first verification. Receipt cryptography is verified entirely on your machine — no network required. Network is optional and only used when you explicitly request remote receipt issuance or resolution.
SettlementWitness
Verify SAR v0.1 settlement receipts locally. Optionally request DefaultVerifier-signed receipts.
When to use
- Before trusting a task-complete claim from another agent
- Before chaining downstream actions to an agent output
- Before using a receipt as evidence
- Before acting on a settlement- or payment-adjacent claim
- When you prefer a local, offline verifier
First run (offline, no network needed)
Run the self-test against all bundled fixtures:
python3 scripts/verify_receipt.py --self-test
Expected output: self_test_passed: true with all four fixtures [OK].
Verify a single receipt
python3 scripts/verify_receipt.py fixtures/sar-v0.1-pass.json
Returns JSON:
{
"valid": true,
"receipt_id": "sha256:...",
"kid": "sar-prod-ed25519-01",
"verdict": "PASS",
"errors": []
}
Tamper test (should fail)
python3 scripts/verify_receipt.py fixtures/tampered-receipt.json
Returns valid: false with errors listing the digest mismatch and signature
failure. This proves the verifier actually rejects tampered receipts.
How to interpret results
| Field | Meaning |
|---|---|
valid: true | Receipt digest and Ed25519 signature both verified |
valid: false | Receipt failed cryptographic verification |
verdict: PASS | The signed outcome claims the spec was met |
verdict: FAIL | The signed outcome claims the spec was not met |
verdict: INDETERMINATE | The issuer signed an honest uncertainty state |
errors: [...] | What specifically failed |
PASS, FAIL, and INDETERMINATE are all valid signed outcomes when
valid: true — they represent what the issuer attested, not post-hoc
interpretation.
What works offline vs what uses the network
Fully offline (no network):
- Parsing a SAR v0.1 receipt JSON
- Recomputing the canonical digest from signed core fields
- Verifying
receipt_idmatches the digest - Verifying the Ed25519 signature against the bundled public key registry
- All four bundled fixture checks (
--self-test)
Optional network (only when you explicitly ask):
- Requesting a new DefaultVerifier-signed receipt — signing keys stay server-side by design, so issuance requires the remote service
- Resolving a receipt ID
- Refreshing the public key registry
- Chain or correlation lookups
If DefaultVerifier is offline, local verification of existing receipts still works. The service being unavailable does not invalidate receipts you already have.
Optional remote receipt issuance
To request a signed receipt from DefaultVerifier (requires network):
curl -sS https://defaultverifier.com/settlement-witness \
-H "Content-Type: application/json" \
-d '{"task_id":"your-task-id","spec":{"expected":"value"},"output":{"expected":"value"}}'
The REST endpoint returns a signed SAR v0.1 receipt. You can then verify it
locally with scripts/verify_receipt.py.
Public key registry: https://defaultverifier.com/.well-known/sar-keys.json
Receipt explorer: https://defaultverifier.com/verified
Safety boundaries
DefaultVerifier issues signed evidence about whether a receipt is cryptographically valid. It does not:
- Execute user tasks
- Approve or reject actions
- Release, hold, or custody funds
- Prove legal settlement finality
- Prove payment finality
- Control downstream agent behavior
Acting on a verified receipt is the responsibility of the system or agent that reads it.
Environment
Override the public key registry path if needed:
SAR_KEYS_REGISTRY_PATH=/path/to/keys.json python3 scripts/verify_receipt.py receipt.json
Provenance
Operator: Default Settlement Verifier
Repository: https://github.com/nutstrut/default-settlement-verifier
Homepage: https://defaultverifier.com
相关技能
通过托管 MCP 接入 OpenTask 智能体市场,发布服务、参与竞标与交付,并完成非托管加密付款路由。
Expose a local @moneydevkit/agent-wallet as a Nostr Wallet Connect (NIP-47) wallet-service (systemd user service).
Handle approved login, identity, checkout, donation, subscription, payment pages, and typed action approvals through the magicpay CLI.
面向 AI 代理的端到端加密对等网络:gossip 订阅发布、CRDT 同步、MLS 群组加密、NAT 穿透,无需任何中心服务器。
通过普通 HTTP 调用,为 AI 智能体打造身份、生成 SOUL.md、永久归档,并追踪其演变轨迹。