{"id":"ec518533-2846-4a34-8339-cf1753eeda74","entityType":"agent","slug":"matrix-meta-hex-vetter","name":"hex-vetter","canonicalUrl":"https://www.xpersona.co/agent/matrix-meta-hex-vetter","canonicalPath":"/agent/matrix-meta-hex-vetter","generatedAt":"2026-10-09T18:09:42.684Z","source":"GITHUB_OPENCLEW","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-04-15T05:21:22.124Z","emptyReason":null},"description":"Physical-layer hex auditing for skills. Detects hidden binary data, control characters, and encoding-based attacks. --- name: hex-vetter version: 0.1.0 description: Physical-layer hex auditing for skills. Detects hidden binary data, control characters, and encoding-based attacks. author: Matrix-Meta license: GPL-3.0 tags: - security - hex - audit - binary-analysis --- hex-vetter 🔬 Physical-layer hex auditing skill forects hidden binary data AI agents. Det, control characters, and encoding-based attacks. Overview hex-vetter perfor","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1 GitHub stars reported by the source. Last updated 4/15/2026.","installCommand":"git clone https://github.com/Matrix-Meta/hex-vetter.git","sourceUrl":"https://github.com/Matrix-Meta/hex-vetter","homepage":null,"primaryLinks":[{"label":"View Source","url":"https://github.com/Matrix-Meta/hex-vetter","kind":"source"}],"safetyScore":94,"overallRank":31.9,"popularityScore":8,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Physical-layer hex auditing for skills. Detects hidden binary data, control characters, and encoding-based attacks. --- name: hex-vetter version: 0.1.0 descript"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-04-15T05:21:22.124Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[{"label":"a","status":"self-declared"},{"label":"results","status":"self-declared"}],"verifiedCount":0,"selfDeclaredCount":3,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"},{"key":"a","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"},{"key":"results","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile capability:a|supported|profile capability:results|supported|profile"}},"adoption":{"evidence":{"source":"GITHUB OPENCLEW","verified":false,"confidence":"medium","updatedAt":"2026-04-15T05:21:22.124Z","emptyReason":null},"stars":1,"forks":0,"downloads":null,"packageName":null,"latestVersion":null,"tractionLabel":"1 GitHub stars"},"release":{"evidence":{"source":"agent-index","verified":false,"confidence":"medium","updatedAt":"2026-04-15T01:15:43.340Z","emptyReason":null},"lastUpdatedAt":"2026-04-15T05:21:22.124Z","lastCrawledAt":"2026-04-15T01:15:43.340Z","lastIndexedAt":null,"nextCrawlAt":"2026-04-16T01:15:43.340Z","lastVerifiedAt":null,"highlights":[]},"execution":{"evidence":{"source":"GITHUB OPENCLEW","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"git clone https://github.com/Matrix-Meta/hex-vetter.git","setupComplexity":"low","setupSteps":["Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/matrix-meta-hex-vetter/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/matrix-meta-hex-vetter/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/matrix-meta-hex-vetter/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/matrix-meta-hex-vetter/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/matrix-meta-hex-vetter/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/matrix-meta-hex-vetter/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"GITHUB_OPENCLEW","generatedAt":"2026-10-09T18:09:42.684Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/matrix-meta-hex-vetter/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/matrix-meta-hex-vetter/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/matrix-meta-hex-vetter/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/matrix-meta-hex-vetter/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"GITHUB OPENCLEW","verified":false,"confidence":"high","updatedAt":"2026-04-15T05:21:22.124Z","emptyReason":null},"readme":"---\nname: hex-vetter\nversion: 0.1.0\ndescription: Physical-layer hex auditing for skills. Detects hidden binary data, control characters, and encoding-based attacks.\nauthor: Matrix-Meta\nlicense: GPL-3.0\ntags:\n  - security\n  - hex\n  - audit\n  - binary-analysis\n---\n\n# hex-vetter 🔬\n\nPhysical-layer hex auditing skill forects hidden binary data AI agents. Det, control characters, and encoding-based attacks.\n\n## Overview\n\nhex-vetter performs deep hex-level analysis of files to detect what text-based reviewers miss. It's designed for security audits of skill packages, detecting hidden payloads, obfuscated code, and suspicious binary data.\n\n## Installation\n\n```bash\ngit clone https://github.com/Matrix-Meta/hex-vetter.git\ncd hex-vetter\nnpm install\n```\n\n## Usage\n\n### Command Line\n\n```bash\n# Scan a single file\nnode vet.js <file_path>\n\n# Scan a directory recursively\nnode scan_all.js <directory_path>\n\n# Verify file integrity\nnode verify.js <file_path>\n```\n\n### As a Module\n\n```javascript\nconst { scanFile } = require('./vet.js');\nconst result = await scanFile('/path/to/file.bin');\n\nconsole.log(result.riskLevel);    // 'LOW', 'MEDIUM', 'HIGH'\nconsole.log(result.flags);       // Array of detected issues\nconsole.log(result.hexDump);      // Formatted hex output\n```\n\n## What It Detects\n\n| Flag | Description |\n|------|-------------|\n| `NULL_BYTES` | Null bytes (0x00) - signs of binary injection or file padding |\n| `CONTROL_CHARS` | Control characters (0x01-0x1F) - hidden terminal sequences |\n| `UNICODE_OVERRIDE` | Unicode directional overrides (LRO, RLO, etc.) |\n| `HIGH_NON_ASCII` | High ratio of non-ASCII bytes - Base64 or encoded payloads |\n| `MAGIC_BYTES` | Known magic bytes/signatures |\n| `SUSPICIOUS_PATTERN` | Pattern matching for common attack signatures |\n\n## API Reference\n\n### scanFile(filePath)\n\nScans a single file and returns analysis results.\n\n```javascript\nconst { scanFile } = require('./vet.js');\n\nconst result = await scanFile('./some file.js');\n// Returns: { riskLevel, flags, hexDump, details }\n```\n\n### scanDirectory(dirPath)\n\nRecursively scans all files in a directory.\n\n```javascript\nconst { scanDirectory } = require('./scan_all.js');\n\nconst results = await scanDirectory('./skills/');\n// Returns: Array of scan results for each file\n```\n\n### verifyIntegrity(filePath)\n\nVerifies file integrity using stored checksums.\n\n```javascript\nconst { verifyIntegrity } = require('./verify.js');\n\nconst result = await verifyIntegrity('./starfragment.js');\n// Returns: { valid, expected, actual }\n```\n\n## Risk Levels\n\n- **🟢 LOW**: Normal file, no suspicious content detected\n- **🟡 MEDIUM**: Some flags detected, manual review recommended\n- **🔴 HIGH**: Significant suspicious content, MUST be manually reviewed\n\n## Security Policy\n\n1. **Mandatory Review**: Any file flagged as 🔴 **HIGH RISK** MUST be manually inspected by a human or a trusted agent before the skill is used.\n\n2. **False Positives**: Risk ratings are heuristic. Common false positives include:\n   - `.env` mentions in `.npmignore`\n   - Documentation with encoded examples\n   - Compressed assets\n\n3. **Agent Action**: If an agent performs an audit and finds HIGH RISK, it MUST:\n   - Notify the user immediately\n   - Provide the specific reason (e.g., signature match vs. binary data)\n   - Suggest next steps for manual review\n\n## Architecture\n\n```\nhex-vetter/\n├── starfragment.js       # Core module (self-modifying storage)\n├── scan_all.js          # Recursive directory scanner\n├── verify.js            # Integrity verification\n├── vet.js               # Main entry point\n├── .primal_anchor       # Timestamp seed (gitignored)\n├── .gitignore\n├── LICENSE              # GPLv3\n├── README.md\n└── SKILL.md            # This file\n```\n\n## Self-Modifying Storage\n\nThe `starfragment.js` module uses self-modifying storage - it reads and writes data from/to its own file at runtime. Constants are encoded and stored as valid JavaScript comments at the end of the source file.\n\n## License\n\nGNU General Public License v3 (GPLv3) - See LICENSE file for details.\n\n## Contributing\n\nIssues and pull requests are welcome on GitHub:\nhttps://github.com/Matrix-Meta/hex-vetter\n","readmeExcerpt":"--- name: hex-vetter version: 0.1.0 description: Physical-layer hex auditing for skills. Detects hidden binary data, control characters, and encoding-based attacks. author: Matrix-Meta license: GPL-3.0 tags: - security - hex - audit - binary-analysis --- hex-vetter 🔬 Physical-layer hex auditing skill forects hidden binary data AI agents. Det, control characters, and encoding-based attacks. Overview hex-vetter perfor","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"git clone https://github.com/Matrix-Meta/hex-vetter.git\ncd hex-vetter\nnpm install"},{"language":"bash","snippet":"# Scan a single file\nnode vet.js <file_path>\n\n# Scan a directory recursively\nnode scan_all.js <directory_path>\n\n# Verify file integrity\nnode verify.js <file_path>"},{"language":"javascript","snippet":"const { scanFile } = require('./vet.js');\nconst result = await scanFile('/path/to/file.bin');\n\nconsole.log(result.riskLevel);    // 'LOW', 'MEDIUM', 'HIGH'\nconsole.log(result.flags);       // Array of detected issues\nconsole.log(result.hexDump);      // Formatted hex output"},{"language":"javascript","snippet":"const { scanFile } = require('./vet.js');\n\nconst result = await scanFile('./some file.js');\n// Returns: { riskLevel, flags, hexDump, details }"},{"language":"javascript","snippet":"const { scanDirectory } = require('./scan_all.js');\n\nconst results = await scanDirectory('./skills/');\n// Returns: Array of scan results for each file"},{"language":"javascript","snippet":"const { verifyIntegrity } = require('./verify.js');\n\nconst result = await verifyIntegrity('./starfragment.js');\n// Returns: { valid, expected, actual }"}],"parameters":{},"dependencies":[],"permissions":[],"extractedFiles":[],"languages":["typescript"],"docsSourceLabel":"GITHUB OPENCLEW","editorialOverview":"Physical-layer hex auditing for skills. Detects hidden binary data, control characters, and encoding-based attacks. --- name: hex-vetter version: 0.1.0 description: Physical-layer hex auditing for skills. Detects hidden binary data, control characters, and encoding-based attacks. author: Matrix-Meta license: GPL-3.0 tags: - security - hex - audit - binary-analysis --- hex-vetter 🔬 Physical-layer hex auditing skill forects hidden binary data AI agents. Det, control characters, and encoding-based attacks. Overview hex-vetter perfor","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":370,"uniquenessScore":65,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-04-15T05:21:22.124Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-04-15T05:21:22.124Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-09T18:09:42.684Z","emptyReason":null},"items":[{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-10T18:48:31.762Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/github_openclew","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}