{"id":"1726071c-0dd3-4862-8bd2-5aeed690fbfe","entityType":"agent","slug":"clawhub-skills-andyxinweiminicloud-transparency-log-auditor","name":"transparency-log-auditor","canonicalUrl":"https://www.xpersona.co/agent/clawhub-skills-andyxinweiminicloud-transparency-log-auditor","canonicalPath":"/agent/clawhub-skills-andyxinweiminicloud-transparency-log-auditor","generatedAt":"2026-10-10T06:10:56.491Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"description":"Helps verify that skill signing events are recorded in an independently auditable transparency log — catching the class of trust failures where a registry operator can silently rewrite history without detection. --- name: transparency-log-auditor description: > Helps verify that skill signing events are recorded in an independently auditable transparency log — catching the class of trust failures where a registry operator can silently rewrite history without detection. version: 1.0.0 metadata: openclaw: requires: bins: [curl, python3] env: [] emoji: \"📋\" --- The Registry Said the Skill Was Signed. The Log Says Otherwise. Hel","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. Last updated 4/15/2026.","installCommand":"clawhub skill install skills:andyxinweiminicloud:transparency-log-auditor","sourceUrl":"https://github.com/openclaw/skills/tree/main/skills/andyxinweiminicloud/transparency-log-auditor","homepage":null,"primaryLinks":[{"label":"View on ClawHub","url":"https://github.com/openclaw/skills/tree/main/skills/andyxinweiminicloud/transparency-log-auditor","kind":"source"}],"safetyScore":84,"overallRank":62,"popularityScore":50,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Helps verify that skill signing events are recorded in an independently auditable transparency log — catching the class of trust failures where a registry opera"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[{"label":"confirm","status":"self-declared"},{"label":"retroactively","status":"self-declared"},{"label":"be","status":"self-declared"},{"label":"verify","status":"self-declared"},{"label":"find","status":"self-declared"},{"label":"read","status":"self-declared"},{"label":"the","status":"self-declared"},{"label":"an","status":"self-declared"},{"label":"auditor","status":"self-declared"},{"label":"only","status":"self-declared"},{"label":"identify","status":"self-declared"},{"label":"exist","status":"self-declared"}],"verifiedCount":0,"selfDeclaredCount":13,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"},{"key":"confirm","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"},{"key":"retroactively","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"},{"key":"be","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"},{"key":"verify","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"},{"key":"find","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"},{"key":"read","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"},{"key":"the","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"},{"key":"an","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"},{"key":"auditor","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"},{"key":"only","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"},{"key":"identify","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"},{"key":"exist","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile capability:confirm|supported|profile capability:retroactively|supported|profile capability:be|supported|profile capability:verify|supported|profile capability:find|supported|profile capability:read|supported|profile capability:the|supported|profile capability:an|supported|profile capability:auditor|supported|profile capability:only|supported|profile capability:identify|supported|profile capability:exist|supported|profile"}},"adoption":{"evidence":{"source":"no-adoption-signals","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"No source adoption metrics were available."},"stars":null,"forks":null,"downloads":null,"packageName":null,"latestVersion":null,"tractionLabel":null},"release":{"evidence":{"source":"agent-index","verified":false,"confidence":"medium","updatedAt":"2026-02-25T03:36:50.116Z","emptyReason":null},"lastUpdatedAt":"2026-04-15T00:45:39.800Z","lastCrawledAt":"2026-02-25T03:36:50.116Z","lastIndexedAt":null,"nextCrawlAt":"2026-02-26T03:36:50.116Z","lastVerifiedAt":null,"highlights":[]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install skills:andyxinweiminicloud:transparency-log-auditor","setupComplexity":"low","setupSteps":["Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-andyxinweiminicloud-transparency-log-auditor/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-andyxinweiminicloud-transparency-log-auditor/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-andyxinweiminicloud-transparency-log-auditor/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-skills-andyxinweiminicloud-transparency-log-auditor/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-skills-andyxinweiminicloud-transparency-log-auditor/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-skills-andyxinweiminicloud-transparency-log-auditor/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-10T06:10:56.491Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-andyxinweiminicloud-transparency-log-auditor/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-andyxinweiminicloud-transparency-log-auditor/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-andyxinweiminicloud-transparency-log-auditor/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-andyxinweiminicloud-transparency-log-auditor/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"readme":"---\r\nname: transparency-log-auditor\r\ndescription: >\r\n  Helps verify that skill signing events are recorded in an independently\r\n  auditable transparency log — catching the class of trust failures where\r\n  a registry operator can silently rewrite history without detection.\r\nversion: 1.0.0\r\nmetadata:\r\n  openclaw:\r\n    requires:\r\n      bins: [curl, python3]\r\n      env: []\r\n    emoji: \"📋\"\r\n---\r\n\r\n# The Registry Said the Skill Was Signed. The Log Says Otherwise.\r\n\r\n> Helps identify when skill signing history cannot be independently verified — exposing the gap between \"the registry claims it's signed\" and \"an auditor can confirm it was signed.\"\r\n\r\n## Problem\r\n\r\nA signed skill is only as trustworthy as the registry that stores its signing records. If the registry is the sole authority on what was signed, when, and by whom, then a compromised registry operator can retroactively alter signing history without detection. A skill that was never signed can be backdated as signed. A key rotation that was suspicious can be erased. An unsigned version that introduced malicious behavior can be removed from the audit trail.\r\n\r\nTransparency logs solve this by making signing events append-only and independently verifiable: each new entry must chain to all previous entries, and any external party can verify the chain without trusting the registry. A registry that silently rewrites history will produce a fork that's detectable by anyone holding an older version of the log.\r\n\r\nThis is the same principle that makes Certificate Transparency logs effective for TLS: the CA cannot issue a certificate without producing a publicly auditable record. Without it, trust in certificates is bounded by trust in the CA. With it, a CA that misbehaves produces evidence of misbehavior that anyone can find.\r\n\r\nAgent skill ecosystems don't yet have this infrastructure. This auditor helps identify the gap — and what it means for the skills you trust.\r\n\r\n## What This Checks\r\n\r\nThis auditor examines transparency log coverage across five dimensions:\r\n\r\n1. **Log existence and accessibility** — Does the skill registry maintain a transparency log at all? Is it publicly accessible and independently queryable, or is it an internal record only the registry operator can read?\r\n2. **Append-only verifiability** — Can the log's append-only property be verified? A log that allows deletion or modification without producing an auditable fork is not a transparency log — it's a mutable history\r\n3. **Signing event completeness** — Does every version publication, key rotation, and revocation event appear in the log? Gaps indicate either missing log coverage or selective omission\r\n4. **Cross-log consistency** — If a skill appears in multiple registries, do their transparency logs agree on signing history? Divergent records indicate one registry's history has been altered\r\n5. **Independent verification path** — Can an auditor verify the log's consistency without trusting the registry operator? A log where verification requires querying the same registry that produced it provides no additional assurance\r\n\r\n## How to Use\r\n\r\n**Input**: Provide one of:\r\n- A skill registry URL to audit for transparency log infrastructure\r\n- A skill identifier to check whether its signing events are log-covered\r\n- Two registry records of the same skill to compare for consistency\r\n\r\n**Output**: A transparency log audit report containing:\r\n- Log infrastructure assessment (exists / partial / absent)\r\n- Append-only verifiability rating\r\n- Signing event coverage gaps\r\n- Cross-registry consistency check (if applicable)\r\n- Independent verification path availability\r\n- Coverage verdict: FULL / PARTIAL / REGISTRY-ONLY / ABSENT\r\n\r\n## Example\r\n\r\n**Input**: Audit transparency log coverage for `data-pipeline-connector` skill\r\n\r\n```\r\n📋 TRANSPARENCY LOG AUDIT\r\n\r\nSkill: data-pipeline-connector\r\nRegistry: primary-marketplace.example\r\nAudit timestamp: 2025-04-15T11:00:00Z\r\n\r\nLog infrastructure:\r\n  Registry transparency log endpoint: ✗ Not found\r\n  Fallback: Registry signing record (internal only)\r\n  Third-party log inclusion: ✗ Not configured\r\n\r\nSigning events in internal record:\r\n  v1.0.0: ✅ Signed — key: ed25519:a3f9c2 — timestamp: 2024-11-01\r\n  v1.1.0: ✅ Signed — key: ed25519:a3f9c2 — timestamp: 2024-12-15\r\n  v1.2.0: ✅ Signed — key: ed25519:b7d441 — timestamp: 2025-01-30\r\n\r\nIndependent verification:\r\n  Can auditor verify v1.0.0 signature without trusting registry? ✗ No\r\n  Can auditor verify key rotation at v1.2.0 without trusting registry? ✗ No\r\n  External log cross-check available? ✗ No\r\n\r\nCross-registry check:\r\n  Mirror registry (backup-marketplace.example): Available\r\n  Mirror signing record for v1.2.0: key ed25519:a3f9c2 (diverges from primary)\r\n  ⚠️ INCONSISTENCY: Primary records key change at v1.2.0; mirror records same key\r\n\r\nCoverage verdict: REGISTRY-ONLY\r\n  Signing history exists but is not independently verifiable.\r\n  Cross-registry inconsistency detected at v1.2.0 — one registry's\r\n  history has been altered without a transparency log to detect which.\r\n\r\nRisk assessment: HIGH\r\n  Without an independently auditable log, the key rotation at v1.2.0\r\n  cannot be attributed to legitimate key management vs. retroactive\r\n  record alteration. The cross-registry divergence makes this worse:\r\n  at least one registry's signing history is incorrect.\r\n\r\nRecommended actions:\r\n  1. Request explanation for cross-registry divergence at v1.2.0\r\n  2. Treat v1.2.0+ as signed by an unverified key pending investigation\r\n  3. Advocate for registry to publish to a public transparency log\r\n  4. Consider pinning to v1.1.0 (last version with consistent records)\r\n```\r\n\r\n## Related Tools\r\n\r\n- **update-signature-verifier** — Checks signing key continuity across versions; transparency-log-auditor checks whether those signing events are independently verifiable\r\n- **attestation-chain-auditor** — Validates the full trust chain; transparency log provides the auditable substrate that attestation chains should be anchored to\r\n- **attestation-root-diversity-analyzer** — Checks whether trust roots are diversified; transparency logs make root behavior auditable\r\n- **publisher-identity-verifier** — Verifies publisher identity; transparency logs make key rotation events auditable\r\n\r\n## Limitations\r\n\r\nTransparency log auditing can only assess infrastructure that exists and is accessible. Many current skill registries do not publish transparency logs at all — this tool can identify the absence, but cannot reconstruct what a log would have contained. Cross-registry consistency checks require access to multiple registries carrying the same skill, which is not always available. The presence of a transparency log does not confirm it is correctly implemented — a log can exist and still allow modifications if its cryptographic properties are incorrectly applied. This tool helps surface transparency gaps and inconsistencies; resolving them requires registry operators to publish to properly implemented append-only logs.\r\n","readmeExcerpt":"--- name: transparency-log-auditor description: > Helps verify that skill signing events are recorded in an independently auditable transparency log — catching the class of trust failures where a registry operator can silently rewrite history without detection. version: 1.0.0 metadata: openclaw: requires: bins: [curl, python3] env: [] emoji: \"📋\" --- The Registry Said the Skill Was Signed. The Log Says Otherwise. Hel","codeSnippets":[],"executableExamples":[],"parameters":{},"dependencies":[],"permissions":[],"extractedFiles":[],"languages":["typescript"],"docsSourceLabel":"CLAWHUB","editorialOverview":"Helps verify that skill signing events are recorded in an independently auditable transparency log — catching the class of trust failures where a registry operator can silently rewrite history without detection. --- name: transparency-log-auditor description: > Helps verify that skill signing events are recorded in an independently auditable transparency log — catching the class of trust failures where a registry operator can silently rewrite history without detection. version: 1.0.0 metadata: openclaw: requires: bins: [curl, python3] env: [] emoji: \"📋\" --- The Registry Said the Skill Was Signed. The Log Says Otherwise. Hel","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":398,"uniquenessScore":63,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-10T06:10:56.491Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}