{"id":"16e1a001-f908-43a1-aa23-2be2d20f4bfa","entityType":"agent","slug":"clawhub-skills-andyxinweiminicloud-attestation-chain-auditor","name":"attestation-chain-auditor","canonicalUrl":"https://www.xpersona.co/agent/clawhub-skills-andyxinweiminicloud-attestation-chain-auditor","canonicalPath":"/agent/clawhub-skills-andyxinweiminicloud-attestation-chain-auditor","generatedAt":"2026-10-10T05:55:12.466Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"description":"Helps validate the completeness and integrity of trust attestation chains in AI agent ecosystems. Identifies broken links, expired credentials, and missing vouching relationships that make verified trust claims unverifiable. --- name: attestation-chain-auditor description: > Helps validate the completeness and integrity of trust attestation chains in AI agent ecosystems. Identifies broken links, expired credentials, and missing vouching relationships that make verified trust claims unverifiable. version: 1.0.0 metadata: openclaw: requires: bins: [curl, python3] env: [] emoji: \"🔗\" --- The Chain Is Only as Strong as Its Weakest Link — Inc","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. Last updated 4/15/2026.","installCommand":"clawhub skill install skills:andyxinweiminicloud:attestation-chain-auditor","sourceUrl":"https://github.com/openclaw/skills/tree/main/skills/andyxinweiminicloud/attestation-chain-auditor","homepage":null,"primaryLinks":[{"label":"View on ClawHub","url":"https://github.com/openclaw/skills/tree/main/skills/andyxinweiminicloud/attestation-chain-auditor","kind":"source"}],"safetyScore":84,"overallRank":62,"popularityScore":50,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Helps validate the completeness and integrity of trust attestation chains in AI agent ecosystems. Identifies broken links, expired credentials, and missing vouc"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"protocols":[{"protocol":"A2A","label":"A2A","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[{"label":"be","status":"self-declared"},{"label":"identify","status":"self-declared"}],"verifiedCount":0,"selfDeclaredCount":3,"capabilityMatrix":{"rows":[{"key":"A2A","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"},{"key":"be","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"},{"key":"identify","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"}],"flattenedTokens":"protocol:A2A|unknown|profile capability:be|supported|profile capability:identify|supported|profile"}},"adoption":{"evidence":{"source":"no-adoption-signals","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"No source adoption metrics were available."},"stars":null,"forks":null,"downloads":null,"packageName":null,"latestVersion":null,"tractionLabel":null},"release":{"evidence":{"source":"agent-index","verified":false,"confidence":"medium","updatedAt":"2026-02-25T03:36:42.907Z","emptyReason":null},"lastUpdatedAt":"2026-04-15T00:45:39.800Z","lastCrawledAt":"2026-02-25T03:36:42.907Z","lastIndexedAt":null,"nextCrawlAt":"2026-02-26T03:36:42.907Z","lastVerifiedAt":null,"highlights":[]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install skills:andyxinweiminicloud:attestation-chain-auditor","setupComplexity":"low","setupSteps":["Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-andyxinweiminicloud-attestation-chain-auditor/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-andyxinweiminicloud-attestation-chain-auditor/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-andyxinweiminicloud-attestation-chain-auditor/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-skills-andyxinweiminicloud-attestation-chain-auditor/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-skills-andyxinweiminicloud-attestation-chain-auditor/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-skills-andyxinweiminicloud-attestation-chain-auditor/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["A2A"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-10T05:55:12.466Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-andyxinweiminicloud-attestation-chain-auditor/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-andyxinweiminicloud-attestation-chain-auditor/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-andyxinweiminicloud-attestation-chain-auditor/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-andyxinweiminicloud-attestation-chain-auditor/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"readme":"---\r\nname: attestation-chain-auditor\r\ndescription: >\r\n  Helps validate the completeness and integrity of trust attestation chains\r\n  in AI agent ecosystems. Identifies broken links, expired credentials,\r\n  and missing vouching relationships that make verified trust claims unverifiable.\r\nversion: 1.0.0\r\nmetadata:\r\n  openclaw:\r\n    requires:\r\n      bins: [curl, python3]\r\n      env: []\r\n    emoji: \"🔗\"\r\n---\r\n\r\n# The Chain Is Only as Strong as Its Weakest Link — Including the Links Nobody Checked\r\n\r\n> Helps identify gaps, breaks, and expired segments in trust attestation chains that make verification claims formally valid but practically meaningless.\r\n\r\n## Problem\r\n\r\nTrust in agent ecosystems is supposed to be transitive: if A vouches for B, and B vouches for C, then A's trust extends to C through the chain. But attestation chains have failure modes that isolated audits don't catch. A chain can be formally complete — every link present — but functionally broken if any link is expired, if the vouching relationship was never actually verified, or if the chain contains circular dependencies that provide the appearance of independent validation without the substance. Many \"verified\" badges in current marketplaces represent attestation chains that would fail integrity checks if anyone looked at the full chain rather than just the terminal credential.\r\n\r\n## What This Audits\r\n\r\nThis auditor examines attestation chains across five dimensions:\r\n\r\n1. **Chain completeness** — Does a verifiable chain exist from the skill or agent all the way to a root of trust? Chains that terminate at unverified accounts rather than verifiable root authorities have a trust ceiling determined by their weakest link\r\n2. **Link expiry** — Are all links in the chain currently valid? An attestation signed 18 months ago with no renewal attests to a state that no longer exists. Each link should have a defined validity period and an explicit renewal or decay mechanism\r\n3. **Vouching depth** — How many independent vouching relationships exist? A chain where A vouches for B and B is also controlled by A (circular reference) provides zero independent validation despite appearing to have two links\r\n4. **Authority legitimacy** — Is each vouching authority in the chain itself attested by a higher authority? Self-signed roots are weaker than roots that are themselves attested by independent parties\r\n5. **Revocation propagation** — If any link in the chain is revoked, does that revocation propagate to all downstream attestations? A chain where link 2 has been revoked but links 3 and 4 don't know about it continues to appear valid to anyone who doesn't check the full chain\r\n\r\n## How to Use\r\n\r\n**Input**: Provide one of:\r\n- A skill or agent identifier to trace its attestation chain\r\n- An attestation chain document to audit directly\r\n- A list of vouching relationships to analyze for completeness and cycles\r\n\r\n**Output**: An attestation chain report containing:\r\n- Chain visualization from skill/agent to root of trust\r\n- Link-by-link validity assessment (active/expired/unknown)\r\n- Circular dependency detection results\r\n- Authority legitimacy assessment for each vouching node\r\n- Revocation check results for all links\r\n- Chain strength rating: STRONG / ADEQUATE / FRAGILE / BROKEN\r\n\r\n## Example\r\n\r\n**Input**: Audit attestation chain for `financial-data-processor` skill\r\n\r\n```\r\n🔗 ATTESTATION CHAIN AUDIT\r\n\r\nSkill: financial-data-processor\r\nPublished by: datatools-org\r\nChain depth: 3\r\n\r\nChain visualization:\r\n  financial-data-processor\r\n    ↑ vouched by: datatools-org (publisher account)\r\n      ↑ vouched by: marketplace-verified badge\r\n        ↑ vouched by: marketplace-platform (root)\r\n\r\nLink 1 — Skill → Publisher:\r\n  Status: ⚠️ PARTIAL\r\n  Publisher signature: Present (RSA-2048)\r\n  Signature date: 14 months ago\r\n  Renewal: None found — attestation age exceeds recommended 12-month threshold\r\n  Key transparency: ✗ Not configured\r\n\r\nLink 2 — Publisher → Marketplace Badge:\r\n  Status: ✅ ACTIVE\r\n  Verification type: Email verification + ID check\r\n  Last verified: 3 months ago\r\n  Renewal policy: Annual\r\n\r\nLink 3 — Badge → Marketplace Root:\r\n  Status: ✅ ACTIVE\r\n  Root authority: marketplace-platform\r\n  Root attestation: Self-signed\r\n  Independent attestation: ✗ None found — root is self-attesting\r\n\r\nCircular dependency check: ✓ No cycles detected\r\n\r\nAuthority legitimacy:\r\n  marketplace-platform: Self-attesting root — no independent authority validates it\r\n  Risk: Trust in the entire chain is bounded by trust in the platform itself\r\n\r\nRevocation check:\r\n  Link 1 signing key: No revocation mechanism configured\r\n  Link 2 (marketplace badge): Revocation via platform API confirmed\r\n  Link 3 (root): N/A\r\n\r\nChain strength rating: FRAGILE\r\n  Reasons:\r\n  1. Link 1 attestation is 14 months old with no renewal\r\n  2. Root of trust is self-attesting with no independent validation\r\n  3. Link 1 has no revocation mechanism\r\n\r\nRecommended actions:\r\n  1. Renew publisher signature for financial-data-processor\r\n  2. Configure key revocation endpoint for publisher signing key\r\n  3. Seek independent attestation for marketplace root (third-party auditor)\r\n```\r\n\r\n## Related Tools\r\n\r\n- **publisher-identity-verifier** — Checks publisher identity integrity; attestation chain auditor checks the full chain above the publisher\r\n- **trust-decay-monitor** — Tracks trust freshness; use together to identify chains where time-based decay has weakened link validity\r\n- **agent-card-signing-auditor** — Audits A2A Agent Card signing; attestation chain auditor checks what that signing is anchored to\r\n- **hollow-validation-checker** — Detects validation theater; attestation chain auditor detects attestation theater\r\n\r\n## Limitations\r\n\r\nAttestation chain auditing depends on the availability of chain metadata, which many current implementations do not publish. Where chain links are opaque or undocumented, this tool can identify that attestation information is missing but cannot reconstruct the chain. Self-attesting roots are common in current agent ecosystems — this tool flags them as weaker than independently-attested roots, but does not classify them as invalid. Chain strength ratings reflect the verifiability of trust claims, not the actual trustworthiness of the attested party — a strong chain attests to identity and history, not to benign intent.\r\n","readmeExcerpt":"--- name: attestation-chain-auditor description: > Helps validate the completeness and integrity of trust attestation chains in AI agent ecosystems. Identifies broken links, expired credentials, and missing vouching relationships that make verified trust claims unverifiable. version: 1.0.0 metadata: openclaw: requires: bins: [curl, python3] env: [] emoji: \"🔗\" --- The Chain Is Only as Strong as Its Weakest Link — Inc","codeSnippets":[],"executableExamples":[],"parameters":{},"dependencies":[],"permissions":[],"extractedFiles":[],"languages":["typescript"],"docsSourceLabel":"CLAWHUB","editorialOverview":"Helps validate the completeness and integrity of trust attestation chains in AI agent ecosystems. Identifies broken links, expired credentials, and missing vouching relationships that make verified trust claims unverifiable. --- name: attestation-chain-auditor description: > Helps validate the completeness and integrity of trust attestation chains in AI agent ecosystems. Identifies broken links, expired credentials, and missing vouching relationships that make verified trust claims unverifiable. version: 1.0.0 metadata: openclaw: requires: bins: [curl, python3] env: [] emoji: \"🔗\" --- The Chain Is Only as Strong as Its Weakest Link — Inc","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":395,"uniquenessScore":62,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-10T05:55:12.466Z","emptyReason":null},"items":[{"id":"7ffcd72f-b46b-4818-9d45-d80c12fb6057","entityType":"agent","canonicalPath":"/agent/clawhub-skills-alex-tradequo-whatsapp-automation-a2a-moltflow-r","slug":"clawhub-skills-alex-tradequo-whatsapp-automation-a2a-moltflow-r","name":"moltflow-reviews","description":"Collect and manage customer reviews via MoltFlow API. Sentiment scoring, testimonial extraction, and review management.","url":"https://github.com/openclaw/skills/tree/main/skills/alex-tradequo/whatsapp-automation-a2a/moltflow-reviews","homepage":null,"source":"CLAWHUB","protocols":["A2A"],"capabilities":["my","of","chat","chats"],"safetyScore":80,"overallRank":62,"updatedAt":"2026-04-15T00:45:39.800Z","createdAt":"2026-02-25T03:33:32.456Z","downloads":null},{"id":"750a0575-2f47-4e82-aeb1-ca91b385a405","entityType":"agent","canonicalPath":"/agent/clawhub-skills-aiengineerx-pokecenter","slug":"clawhub-skills-aiengineerx-pokecenter","name":"pokecenter","description":"Launch your own Solana token for free. Keep 100% of trading fees forever. Non-custodial — your keys, your tokens. No SOL needed. Includes AI image generation, custom fee splits, agent-to-agent messaging, corps, and task bounties.","url":"https://github.com/openclaw/skills/tree/main/skills/aiengineerx/pokecenter","homepage":null,"source":"CLAWHUB","protocols":["A2A"],"capabilities":["use","trade","pass","launch","anytime"],"safetyScore":80,"overallRank":62,"updatedAt":"2026-04-15T00:45:39.800Z","createdAt":"2026-02-25T03:31:51.579Z","downloads":null},{"id":"5e346f1b-c7e5-4301-a80e-95897693db80","entityType":"agent","canonicalPath":"/agent/clawhub-skills-alex-tradequo-moltflow-whatsapp","slug":"clawhub-skills-alex-tradequo-moltflow-whatsapp","name":"WhatsApp Ultimate — No Meta API | Lead Mining, Bulk Send, Scheduled Reminders & Follow-ups","description":"Documentation-only WhatsApp API reference — zero executables, zero install scripts, zero local file writes. All actions require explicit user invocation. Provides 90+ API endpoints for sending messages, capturing leads, running campaigns, scheduling reports, tracking campaign analytics, and managing clients. MOLTFLOW_API_KEY is the only credential required — generate a scoped key from the MoltFlow dashboard (Settings > API Keys). AI features (voice transcription, RAG, style profiles) use the user's own LLM API key configured via the MoltFlow web dashboard, never passed through this skill.","url":"https://github.com/openclaw/skills/tree/main/skills/alex-tradequo/moltflow-whatsapp","homepage":"https://molt.waiflow.app","source":"CLAWHUB","protocols":["A2A","MCP","OPENCLAW"],"capabilities":["to","help","send","questions"],"safetyScore":80,"overallRank":62,"updatedAt":"2026-04-15T00:45:39.800Z","createdAt":"2026-02-25T03:33:17.733Z","downloads":null},{"id":"e7965107-adfb-4b6b-8493-fdd32f85583f","entityType":"agent","canonicalPath":"/agent/clawhub-skills-alex-tradequo-moltflow-whatsapp-moltflow-outreac","slug":"clawhub-skills-alex-tradequo-moltflow-whatsapp-moltflow-outreac","name":"moltflow-outreach","description":"Bulk messaging, scheduled messages, scheduled reports, and custom groups for WhatsApp outreach. Use when: bulk send, broadcast, schedule message, schedule report, cron, custom group, contact list, ban-safe messaging.","url":"https://github.com/openclaw/skills/tree/main/skills/alex-tradequo/moltflow-whatsapp/moltflow-outreach","homepage":null,"source":"CLAWHUB","protocols":["A2A"],"capabilities":["be","and"],"safetyScore":80,"overallRank":62,"updatedAt":"2026-04-15T00:45:39.800Z","createdAt":"2026-02-25T03:33:22.722Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"A2A","href":"/agent/protocol/a2a"}]}}}