Token导航 LogoToken导航TokenDH.com
效率敏感数据clawhub未标认证来源可访问clear审计提醒

mpps-attestationMPPS 认证

Agent Skill

用于辅助测试设计、自动化测试、用例整理和回归验证。它适合让 Agent 编写单元测试、端到端测试、测试计划或根据失败日志定位问题。使用时需要确认项目测试框架、运行命令和夹具数据,避免为了通过测试而改坏真实逻辑;涉及浏览器或外部服务时,应区分本地模拟、测试环境和生产环境。

总安装

6,084

周安装

251

GitHub Stars

公开资料未说明

下载量

1,988
OpenClaw

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

MIT-0

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:mpps-attestation(MPPS 认证)
来源仓库:https://github.com/gdlg-ai/mpps-attestation
安装命令:
openclaw skills install mpps-attestation
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 OpenClaw 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

ClawHubOpenClaw
openclaw skills install mpps-attestation

简介

为代理商免费认证。对您的数据进行哈希处理,发布到 api.mpps.io,获取签名收据。 10 个免费/小时 + 10 个认证/天。

SKILL.md

name
mpps-attestation
description
Create tamper-proof receipts for AI agent work. Hash artifacts or action manifests, POST to api.mpps.io, get an HSM-signed receipt. No API key.
license
MIT
homepage
https://mpps.io/skills
metadata
author
gdlg-ai
version
1.4.0
source
https://github.com/gdlg-ai/mpps.io
compatibility
Requires curl or any HTTP client. Network access to api.mpps.io.

mpps-attestation

Create tamper-proof receipts for agent actions via mpps.io. No API key. No SDK required. One HTTP call.

Source: https://github.com/gdlg-ai/mpps.io (MIT) Docs: https://github.com/gdlg-ai/mpps.io/blob/main/docs/api.md

When to use

  • After completing a task, receipt the final artifact hash
  • After generating code, data, images, reports, or release bundles
  • Before and after important workflow steps to build an audit trail
  • When publishing a skill, plugin, package, or API output that users should verify
  • After a payment or delivery workflow, receipt what was sent or received

Create a structured action receipt

Use /v1/receipts when you know what action happened and which artifacts it produced.

ARTIFACT_HASH=$(sha256sum "$ARTIFACT_PATH" | awk '{print "sha256:" $1}')

curl -s -X POST https://api.mpps.io/v1/receipts \
  -H "Content-Type: application/json" \
  -d "{
    \"action\": \"agent.task.complete\",
    \"subject\": \"$ARTIFACT_PATH\",
    \"artifact_hashes\": [
      {\"label\": \"$ARTIFACT_PATH\", \"sha256\": \"$ARTIFACT_HASH\"}
    ],
    \"context\": {
      \"repo\": \"${GITHUB_REPOSITORY:-local}\",
      \"commit\": \"${GIT_COMMIT:-unknown}\"
    }
  }"

Returns: uuid, receipt_type, manifest_hash, manifest, timestamp, HSM signature, and verify_url.

Create a raw hash receipt

Use /v1/notarize when you only need to anchor one hash.

HASH=$(echo -n "$DATA" | sha256sum | awk '{print "sha256:" $1}')
curl -s -X POST https://api.mpps.io/v1/notarize \
  -H "Content-Type: application/json" \
  -d "{\"content_hash\": \"$HASH\"}"

Python

import hashlib
import requests

artifact = b"agent output bytes"
h = "sha256:" + hashlib.sha256(artifact).hexdigest()

receipt = requests.post(
    "https://api.mpps.io/v1/receipts",
    json={
        "action": "agent.task.complete",
        "subject": "output.json",
        "artifact_hashes": [{"label": "output.json", "sha256": h}],
        "context": {"runner": "codex"},
    },
    timeout=30,
).json()

print(receipt["uuid"])
print(receipt["verify_url"])

Verify

curl https://api.mpps.io/v1/verify/mpps_att_0c27bebca6dc4bd6

For structured receipts, recompute the manifest hash if you need stronger evidence:

python3 - <<'PY'
import hashlib, json

r = json.load(open("receipt.json"))
manifest = r["manifest"]
canonical = json.dumps(manifest, sort_keys=True, separators=(",", ":")).encode()
print("sha256:" + hashlib.sha256(canonical).hexdigest())
print(r["manifest_hash"])
PY

Privacy

Send hashes and small labels, not raw private content. Avoid hashing short secrets directly; use larger payloads or a salt. Do not put secrets, customer data, raw prompts, or private source text in context.

Key facts

  • Free: 10 structured receipts or raw hash receipts per hour
  • Certified metadata receipts: 10 free/day
  • No registration, no API key, no credentials
  • HSM-signed with AWS KMS
  • Stored 10 years in AWS S3 Object Lock, Compliance Mode
  • agent_id is a weak source fingerprint, not authenticated identity
  • Open source: https://github.com/gdlg-ai/mpps.io
  • Security: https://github.com/gdlg-ai/mpps.io/blob/main/SECURITY.md
  • Verification: https://github.com/gdlg-ai/mpps.io/blob/main/docs/verify.md

适合场景

01

OpenClaw 用户查找和安装 Skill 时

02

用户想查找某类 Agent Skill 时

03

需要根据任务场景推荐可安装能力包时

04

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

补充不同宿主或平台的使用分布数据

能力 5

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

OpenClaw

87.84%
按下载量换算1,746

安全审计

VirusTotal

可疑

ClawScan

通过

Static analysis

通过

权限和风险

敏感数据

该 Skill 可能接触密钥、Token、环境变量或敏感配置,应进入高风险复核队列,默认不自动发布。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。来源安全扫描存在 warning/failed 结果,不能写成本站确认安全。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills