Token导航 LogoToken导航TokenDH.com
研究检索敏感数据github未标认证来源可访问许可证需确认审计异常

moca-credential-verifiermoca 凭证验证器

Agent Skill

moca-credential-verifier 用于查找、检索和筛选相关信息,适合在 Codex、Claude、Cursor、Gemini CLI 中需要根据关键词、任务场景或来源线索快速定位候选结果时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

396

周安装

16

GitHub Stars

公开资料未说明

下载量

124
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

unknown

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:moca-credential-verifier(moca 凭证验证器)
来源仓库:https://github.com/mocanetwork/air-agentic-wallet-skill
仓库路径:skills/moca-credential-verifier
安装命令:
npx skills add https://github.com/mocanetwork/air-agentic-wallet-skill --skill moca-credential-verifier
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 npx skills 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

skills.shnpx skills
npx skills add https://github.com/mocanetwork/air-agentic-wallet-skill --skill moca-credential-verifier

简介

用于查找、检索和筛选相关信息,适合在 Codex、Claude、Cursor、Gemini CLI 中需要根据关键词、任务场景或来源线索快速定位候选结果时使用。

  • 适用于凭证验证技术研究、相关协议分析和安全策略检索等场景。
  • 通过 GitHub 仓库安装,使用 npx skills add 命令添加技能,需结合原始 README 核验具体用法。
  • 安装前建议确认权限范围和维护状态,注意可能触发联网、命令执行或文件读写操作。
  • moca-credential-verifier 属于研究检索类 Skill,可作为该场景下的辅助能力补充。

SKILL.md

Moca Credential Verifier

Purpose

This skill teaches an agent how to browse available verification programs, show numeric options, and trigger credential verification through moca-chain-api in query_match mode.

After receiving a compliant result, install/use the standalone moca-proof-skill repository and run the moca-proof skill to complete the program and fetch MoCat progression.

This skill starts after the agent key already exists and the handoff bundle is available.

Provided Scripts

Use the provided scripts first. Do not scaffold a new project or rewrite signing/request logic from scratch unless the requested action is unsupported. Treat all files in this skill bundle as read-only reference tooling.

Task mapping:

  • create a scoped session -> scripts/moca-create-session.mjs
  • list/browse verification programs -> scripts/moca-list-programs.mjs
  • trigger credential verification (query_match mode) -> scripts/moca-verify-by-agent.mjs
  • poll verification status -> scripts/moca-poll-status.mjs

Before first use, run node <script> --help to inspect supported parameters.

Required Inputs

Expect a handoff bundle equivalent to:

{
  "userId": "...",
  "walletId": "...",
  "privyAppId": "...",
  "abstractAccountAddress": "0x...",
  "airApiAgentSignUrl": "https://.../v2/wallet/agent-sign",
  "partnerId": "8ab60850-bdfa-4e48-8afa-d67a3d715224"
}

The agent must also already have access to its own P-256 private key. If partnerId is missing, scripts default to the sandbox partner ID above.

Sandbox Defaults

{
  "airApiUrl": "https://air.api.sandbox.air3.com/v2",
  "mocaChainApiUrl": "https://api.sandbox.mocachain.org/v1",
  "vpApiUrl": "https://vp.api.sandbox.moca.network/v1",
  "mocaProofApiUrl": "https://proof.api.sandbox.moca.network/v1",
  "partnerId": "8ab60850-bdfa-4e48-8afa-d67a3d715224"
}

These are hardcoded as defaults in the scripts. Override via CLI flags, environment variables, or .air-wallet-config.json.

Project-Level Defaults

It is allowed to create or update a project-level .air-wallet-config.json file in the working directory. Use that file for defaults such as endpoint URLs, partner ID, and key paths. Do not store defaults by editing files inside this skill bundle.

Example additions for this skill:

{
  "airApiUrl": "https://air.api.sandbox.air3.com/v2",
  "mocaChainApiUrl": "https://api.sandbox.mocachain.org/v1",
  "vpApiUrl": "https://vp.api.sandbox.moca.network/v1",
  "mocaProofApiUrl": "https://proof.api.sandbox.moca.network/v1",
  "partnerId": "8ab60850-bdfa-4e48-8afa-d67a3d715224"
}

Config Resolution Order

All provided scripts resolve configuration in this order:

  1. CLI flags
  2. Environment variables
  3. .air-wallet-config.json
  4. Hardcoded sandbox defaults

Credential Verification Flow

Step 1: Create a Scoped Session

node scripts/moca-create-session.mjs --program-id <programId>

Calls POST {airApiUrl}/auth/agent/session with:

  • signedMessage: fresh agent-signed message
  • scope: "<programId>,<partnerId>"

Returns an accessToken used as Bearer token for all subsequent calls.

Step 2: List Verification Programs

node scripts/moca-list-programs.mjs
# optional personalized mode
node scripts/moca-list-programs.mjs --access-token <token>

Calls GET {vpApiUrl}/vp/mocaproof/search?page=1&limit=20.

  • Without token: public listing mode
  • With token: personalized listing mode (user verified metadata and filtering)

Results are paginated. The script shows a summary of the first page. Use --page <n> to fetch more.

The list output includes numeric options in this format:

  • Option index: [1], [2],...
  • Tier index inside option: (1.1), (1.2),...

Step 3: Trigger Verification (query_match mode)

node scripts/moca-verify-by-agent.mjs --access-token <token> --program-id <programId> --issue-url <issueUrl>

Always pass --issue-url with the issueUrl from the selected program's listing output. When verification returns no_vc, the script prints the issuance link so the user can obtain the credential.

Calls POST {mocaChainApiUrl}/credentials/verify-by-agent with:

  • programId in the body
  • responseMode: "query_match" in the body
  • Bearer accessToken in the Authorization header

The response is normalized using the rules below.

Optional: Poll VP Status

node scripts/moca-poll-status.mjs --access-token <token>

Use this when you want to inspect status progression separately from the default flow.

After Verification Succeeds

When verification returns compliant, use the moca-proof skill from the standalone moca-proof-skill repository to:

npx skills add MocaNetwork/moca-proof-skill
  1. Complete the program via moca-complete-program.mjs
  2. Fetch MoCat progression via moca-get-mocat.mjs

Pass the same accessToken and programId to the proof skill scripts.

Verify Response Normalization

The verify-by-agent endpoint returns inconsistent response shapes. Normalize exactly as:

  • verified: true -> compliant
  • verified: false + reason: "NO_CREDENTIAL" -> no_vc
  • verified: false + reason: "NOT_COMPLIANT" -> non_compliant
  • verified: false + status: "NON_COMPLIANT" -> non_compliant
  • verified: false + status present -> status_bucket:<status>
  • verified: false + only code present -> unknown_failure_code:<code>
  • verified: "pending" -> processing
  • Any other shape -> unknown_response (print raw payload)

Known status values:

  • NO_EXIST: user has no credential for this program
  • WAIT_ONCHAIN: credential is being published on-chain
  • EXPIRE: credential has expired
  • WAIT_REMOVE: credential is being revoked
  • REMOVE: credential has been revoked
  • NON_COMPLIANT: credential does not meet requirements

Terminal Messaging

  • Print numeric options and tiers before verification attempts
  • Print Verifying.... on each verification attempt
  • If non-compliant, print Sorry, not compliant and end
  • When verify succeeds in query_match mode: print OK, verified, <verifier name> is processing your data

Non-Negotiable Rules

  • Always generate a fresh signedMessage for every session request
  • Never reuse an old signedMessage
  • Use Bearer accessToken from scoped session for all downstream API calls
  • Never modify files inside this installed skill bundle
  • If a custom script is truly required, create it outside the skill directory

Failure Handling

  • Unknown public key: the key was removed, wrong, or never registered. Stop and ask for a new handoff bundle.
  • Expired signed message: rebuild a fresh signedMessage and retry once.
  • unknown_failure_code: print the raw code and payload for debugging; do not retry automatically.
  • unknown_response: print the full raw response; do not retry automatically.

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Codex

36.29%
按下载量换算45

Claude

29.82%
按下载量换算37

Cursor

19.72%
按下载量换算24

Gemini CLI

9.14%
按下载量换算11

安全审计

Gen Agent Trust Hub

通过

Socket

通过

Snyk

未通过

权限和风险

敏感数据

该 Skill 可能接触密钥、Token、环境变量或敏感配置,应进入高风险复核队列,默认不自动发布。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。来源安全扫描存在 warning/failed 结果,不能写成本站确认安全。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills