{"items":[{"id":"27e24a8d9e4d40d082af7f58","developerAccountId":"cmo0kywa400fw0znarohegb2z","submissionCategoryId":"cmn27y0hf00030zqr39w0eltw","publicSkillCategoryId":"search-research","monitoringGroupId":null,"productType":"SKILL","sourceType":"github","visibility":"PUBLIC","intakeSourceKind":"github","sourceUrl":"https://github.com/openclaw/skills/blob/main/skills/zihan-zhu/academic-writing-refiner/SKILL.md","sourceRef":"143b6cdaf88c81401912d3cd28a1d3384693d0b8","publicRepositoryUrl":null,"codeRepoUrl":"https://github.com/openclaw/skills/blob/main/skills/zihan-zhu/academic-writing-refiner/SKILL.md","codeRepoRef":"143b6cdaf88c81401912d3cd28a1d3384693d0b8","codeRepoCommitSha":"143b6cdaf88c81401912d3cd28a1d3384693d0b8","codeEntryPoint":null,"contentHash":"00abe41360a646968ea8d59b185f8497907822ed1922b41b200ba8df8b7ec87b","rawSkillHash":"e546cd1a531c44879c868afc651834ef112bb9d0520d364a2e91f2da1abce1f8","rawCodeHash":null,"codeFilesHash":null,"manifestJson":{"name":"Academic Writing Refiner","entry":"SKILL.md","safety":{"network":false,"filesystem":false},"version":"1.0.0","metadata":{"author":"zihan-zhu","sourceRef":"143b6cdaf88c81401912d3cd28a1d3384693d0b8","sourceUrl":"https://github.com/openclaw/skills/blob/main/skills/zihan-zhu/academic-writing-refiner/SKILL.md","sourceType":"github","developerEmail":"support@soulbyte.fun","submissionCategoryKey":"skill-md"},"description":"Refines academic writing for computer science research papers targeting top-tier venues (NeurIPS, ICLR, ICML, AAAI, IJCAI, ACL, EMNLP, NAACL, CVPR, WWW, KDD, SIGIR, CIKM, and similar). Handles full paper refinement and section-by-section editing including abstracts, introductions, related work, methodology, experiments, and conclusions. Supports LaTeX input, camera-ready polish, rebuttal writing, and iterative revision.","productType":"SKILL","capabilities":["academic_writing_refinement","latex_editing","section_specific_editing","rebuttal_writing","grammar_and_style_correction","venue_specific_style_guidance"],"external_calls":[]},"storageKey":"sigma/submissions/27e24a8d9e4d40d082af7f58/00abe41360a646968ea8d59b185f8497907822ed1922b41b200ba8df8b7ec87b.SKILL.md","complexityKey":"standard","pricingSnapshotJson":{"category":{"id":"cmn27y0hf00030zqr39w0eltw","key":"skill-md","label":"SKILL","active":true,"campaigns":[],"createdAt":"2026-03-22T20:38:00.435Z","sortOrder":1,"updatedAt":"2026-04-15T14:52:46.169Z","description":"Upload or paste a SKILL.md package for a standard SIGMA quality and safety review.","productType":"SKILL","stagingOnly":false,"basePriceUsd":10,"pricingRules":[],"portalIconKind":"MATERIAL","portalIconValue":"article","intakeSchemaJson":null,"freeEndpointLimit":null,"packagePolicyJson":{"maxBytes":2097152,"maxFiles":200,"maxFileBytes":524288,"transitiveDepth":1,"maxTotalPriceUsd":null,"officialRegistryOnly":true,"requirePinnedVersions":true},"portalRecommended":false,"packagePricingJson":{"complex":4,"partial":1,"standard":2,"high-complex":8},"allowAdminSponsored":true,"feeDistributionJson":{"monitoring_vault_pct":15,"team_pct_no_monitoring":50,"team_pct_with_monitoring":45,"validators_pct_no_monitoring":50,"validators_pct_with_monitoring":40},"perExtraEndpointUsd":null,"defaultComplexityKey":"standard","requiresLinkedWallet":false,"complexityPricingJson":{"complex":1,"standard":1,"high-complex":1},"resubmissionPolicyJson":{"versionPriceMultiplier":0.5,"freeRejectResubmissions":5,"allowHumanInterventionTicket":true,"humanInterventionAfterFreeRetriesExhausted":true},"auditCouncilPhase1Seats":5,"auditCouncilPhase2Seats":null},"breakdown":[{"label":"base_category_price","valueUsd":10},{"label":"complexity:standard","multiplier":1}],"sponsored":false,"auditFeeUsd":10,"categoryKey":"skill-md","productType":"SKILL","creditsSpent":1000,"addonPackages":[],"complexityKey":"standard","creditBalance":1092,"endpointCount":null,"finalPriceUsd":10,"packagePolicy":{"maxBytes":2097152,"maxFiles":200,"maxFileBytes":524288,"transitiveDepth":1,"maxTotalPriceUsd":null,"officialRegistryOnly":true,"requirePinnedVersions":true},"addonsTotalUsd":0,"creditsPerUsdc":100,"monitoringTier":{"id":"cmn9k1hda00030zn2newg79ct","key":"STANDARD","label":"Standard","active":true,"createdAt":"2026-03-27T23:51:00.910Z","updatedAt":"2026-03-27T23:51:00.910Z","categoryId":null,"description":"Balanced cadence and cost for most submissions.","reviewerCount":2,"perCheckCostUsdc":0.1,"checkIntervalTicks":720,"initialDepositUsdc":0.1,"lowFundsThresholdChecks":3},"packageCostUsd":0,"packagePreview":null,"packagePricing":{"complex":4,"partial":1,"standard":2,"high-complex":8},"reAuditBaseUsd":10,"complexityLabel":"Standard","requiredCredits":1000,"voucherDiscount":null,"appliedCampaigns":[],"freeEndpointLimit":null,"linkedWalletReady":false,"packageSavingsUsd":0,"endpointOverageUsd":0,"monitoringEligible":false,"reAuditBaseCredits":1000,"reAuditPackCredits":{"1":200,"5":750,"10":1000},"perExtraEndpointUsd":null,"resubmissionPricing":{"note":null,"waived":false,"finalPriceUsd":10,"adjustmentKind":null,"rootSubmissionId":null,"originalSubmission":null,"versionPriceMultiplier":0.5,"humanInterventionAllowed":false,"humanInterventionEligible":false,"inheritedFreeResubmissionsLeft":0,"configuredFreeRejectResubmissions":2},"wantsAdminSponsored":false,"complexityAssessment":{"key":"standard","label":"Standard","score":0,"factors":{"codeBytes":28625,"codeFiles":5,"endpointCount":1,"externalHosts":0,"highRiskCount":0,"languageCount":0,"capabilityFlags":0,"dependencyCount":0,"declaredExternalCalls":0,"manifestMismatchCount":0,"mutatingEndpointCount":0,"protectedEndpointCount":0,"elevatedCapabilityFlags":0},"rationale":["Submission stayed inside the standard review envelope for its category family."],"multiplier":1,"apiSurfaceArea":0,"testingApproach":"SIGMA prices review depth by submission family. Skill-only submissions lean on manifest scope, API-bearing submissions lean on declared endpoint surface, and code-bearing submissions lean on repository footprint plus risky behavior. The later audit path still validates the locked source, manifest, and runtime facts.","securitySurfaceArea":0},"complexityMultiplier":1,"linkedWalletRequired":false,"monitoringSeedSharePct":0,"monitoringPackageTotalUsd":0,"quoteCatalogFinalPriceUsd":10,"quotePreVoucherFinalPriceUsd":10,"monitoringFundingComponentUsd":0,"promotionalNoCodeVersionUpdates":false,"promotionalNoVersionUpdatesPolicy":{"active":false,"notice":null}},"uploadManifestJson":null,"sourceTreeHash":null,"sourceTreeStorageKey":null,"feeAmountUsdc":"10","feeTransactionHash":null,"monitoringDepositUsdc":null,"monitoringSpentUsdc":null,"monitoringStatus":"NOT_APPLICABLE","monitoringTier":"STANDARD","monitoringEstimateRemainingChecks":0,"freeResubmissionsLeft":0,"originalSubmissionId":null,"developerAdvisoryNote":null,"submissionFingerprintJson":{"baseUrl":"https://api.example.com","codeRepoUrl":"https://github.com/openclaw/skills/blob/main/skills/zihan-zhu/academic-writing-refiner/SKILL.md","contentHash":"00abe41360a646968ea8d59b185f8497907822ed1922b41b200ba8df8b7ec87b","productType":"SKILL","endpointPaths":["/v1/health"],"codeEntryPoint":null,"codeRepoCommitSha":"143b6cdaf88c81401912d3cd28a1d3384693d0b8","manifestIdentityFields":{"name":"Academic Writing Refiner","version":"1.0.0"}},"endpointCoverageJson":{"approvalBlocked":false,"highestSeverity":null,"skippedEndpoints":[{"path":"/v1/health","reason":"SKILL_ONLY_NO_API_VALIDATION"}],"declaredEndpoints":["/v1/health"],"executedEndpoints":[]},"verificationDisclosureJson":{"warning":"Endpoints were detected in the submitted package but were not validated because the developer chose SKILL-only review.","productType":"SKILL","endpointsDetected":true,"endpointValidationIncluded":false,"developerChoseToSkipEndpointValidation":true},"status":"APPROVED","sandboxReportJson":{"errors":[],"summary":"Sandbox heuristics found no blocking issues.","warnings":[],"riskLevel":"LOW","generatedAt":"2026-04-15T21:51:29.271Z","sourceAnalysis":{"urls":[],"blocked":false,"summary":"Source analysis found no blocking hostile-input or mismatch signals.","sourceHash":"e546cd1a531c44879c868afc651834ef112bb9d0520d364a2e91f2da1abce1f8","reviewNotes":[],"externalHosts":[],"highRiskSignals":[],"sectionHeadings":["Academic Writing Refiner","Core Philosophy","How to Refine","1. Understand the Context","2. Apply Section-Specific Conventions","3. Sentence-Level Refinement","4. LaTeX-Specific Handling","5. What NOT to Do","Output Format","Interaction Patterns","Common Venue-Specific Notes"],"capabilitySignals":{"env":[],"shell":[],"wallet":[],"network":[],"process":[],"filesystem":[]},"realSecretSignals":[],"manifestMismatches":[],"suspiciousSnippets":[],"promptInjectionSignals":[],"declaredExternalCallCount":0}},"codePreprocessorReportJson":null,"seniorExecutionReportJson":null,"seniorConversationJson":null,"seniorPipelineStage":null,"seniorConversationUpdatedAt":null,"packageAnalysisEnabled":false,"packageAnalysisStatus":null,"packagesTotal":null,"packagesCertifiedFromCache":null,"packagesAuditedThisSubmission":null,"packagesUncertified":null,"packagesRejected":null,"packageSavingsUsd":null,"autoFlagged":false,"autoFlagReason":null,"possibleVulnerable":false,"revokedAt":null,"revocationReason":null,"revocationScope":null,"revokedByAdminEmail":null,"certificateIssuedAt":"2026-04-15T21:54:21.324Z","certificatePayloadHash":"0x16a4cf4d3ea6f4e7d151c8710808e886feb6dd5b227e91a3e29674d41ab6444a","certificatePayloadAlgorithm":"keccak256-canonical-json-v1","onChainTxHash":"0xac8ce44b8c655317a3687d5b5a663fd89754fe426e4ff0a1a5ff223be8bd1029","onChainCommittedAt":"2026-04-15T21:54:25.823Z","onChainRevokedAt":null,"onChainRevocationTxHash":null,"renewalDue":"2026-07-14T21:54:21.324Z","warned14":false,"warned3":false,"receiptJson":{"txHash":null,"createdAt":"2026-04-15T21:51:28.022Z","signature":"24b03ad12864bcb724405ccfc9308aa9d62ff3b9128b4ebf9fa6a7844d9da0ef","productType":"SKILL","submissionId":"27e24a8d9e4d40d082af7f58","feeAmountUsdc":10,"paymentMethod":"CREDIT_DEDUCTION","submitterAddress":"dev:cmo0kywa400fw0znarohegb2z"},"disputeDeadline":null,"platformError":false,"systemPipelineFailureAt":null,"systemPipelineFailureDetail":null,"systemPipelineFailureCreditsRefunded":0,"isPublic":true,"sourceZipVerifiedAt":null,"priority":0,"adminOverrideFree":false,"invoiceIssuedAt":null,"invoiceNumber":null,"viewCount":39,"verifyCount":2,"projectHomepageUrl":null,"domainVerificationStatus":"UNVERIFIED","domainVerifiedAt":null,"domainLastCheckedAt":null,"domainVerificationEvidenceJson":null,"domainVerificationLastError":null,"codeIntegrityCheckedAt":null,"createdAt":"2026-04-15T21:51:28.029Z","stagingSuppressOffchainCert":false,"stagingSuppressOnchainCert":false,"monitorTarget":{"id":"cmo0l4xfr00gv0zna7wkzedke","submissionId":"27e24a8d9e4d40d082af7f58","declaredDomains":[],"endpointDeclarationJson":{"name":"","baseUrl":"https://api.example.com","endpoints":[{"auth":"none","path":"/v1/health","method":"GET","rateLimit":null,"description":null,"expectedResponseShape":null}],"openApiUrl":null,"description":"","allowedHosts":["api.example.com"],"contactEmail":null,"destructiveMethodOptIn":[]},"declaredMethodsJson":[{"path":"/v1/health","method":"GET"}],"authRequirementsJson":[{"auth":"none","path":"/v1/health"}],"allowedHostsJson":["api.example.com"],"destructiveMethodOptInJson":[],"lastDomainCheckAt":null,"lastEndpointProbeAt":null,"domainStatus":"OK","endpointStatus":"OK","lastConsensusResult":null,"lastHealthSummaryJson":null,"lastVerifiedDeclarationHash":"e873fc5b4fb4f6a2c791fd54e6cef145505c80e8df11c2739eae0f67fde50245","lastAuthenticatedProbeState":null,"consecutiveProbeFailures":0,"suspendedReason":null},"auditRounds":[{"id":"cmo0l4ydt000010scaqkb4t2l","submissionId":"27e24a8d9e4d40d082af7f58","roundNumber":1,"roundType":"INITIAL_AUDIT","triggerSource":"SUBMISSION","phase":"COMPLETE","consensusResult":"SAFE","consensusWeight":0,"selectedPhase1Auditors":["7ac8617e-a6c0-4b41-8752-9da9c794be66","2941b849-9e82-4ec3-9b29-256fd022e42f","c10caf15-4649-4306-89c1-11957cf078dc","37c91508-565a-4e74-9281-3adfa86f955c","5d98f7e2-3374-4518-87d6-8a599159e8cf"],"selectedPhase2Auditors":[],"smallPoolFlag":false,"triggeringFlagId":null,"startedAt":"2026-04-15T21:51:29.286Z","completedAt":"2026-04-15T21:54:21.282Z"}],"submissionCategory":null,"verificationCategoryLabel":"Skill","certificateJson":{"review":{"securityLevel":"CLEAR","retainedErrors":[],"retainedWarnings":[],"sandboxRiskLevel":"LOW","sandboxAnalyzedAt":"2026-04-15T21:51:29.271Z"},"source":{"entry":"SKILL.md","sourceRef":"143b6cdaf88c81401912d3cd28a1d3384693d0b8","sourceUrl":"https://github.com/openclaw/skills/blob/main/skills/zihan-zhu/academic-writing-refiner/SKILL.md","sourceType":"github"},"status":"APPROVED","onChain":{"txHash":null,"network":"Monad Mainnet","committed":false,"codeVersion":"1.0.0","explorerUrl":null,"immutableCommitmentScope":"No on-chain certification transaction is linked to this certificate snapshot yet."},"roundId":"cmo0l4ydt000010scaqkb4t2l","devNotes":null,"manifest":{"safety":{"network":false,"filesystem":false},"capabilities":["academic_writing_refinement","latex_editing","section_specific_editing","rebuttal_writing","grammar_and_style_correction","venue_specific_style_guidance"],"externalCalls":[]},"roundType":"INITIAL_AUDIT","signature":"06c6a7ff6e8d97a7aa72218f5bf755123901041a175119789a7486dcf62dc4b0","skillHash":"e546cd1a531c44879c868afc651834ef112bb9d0520d364a2e91f2da1abce1f8","skillName":"Academic Writing Refiner","sourceRef":"143b6cdaf88c81401912d3cd28a1d3384693d0b8","sourceUrl":"https://github.com/openclaw/skills/blob/main/skills/zihan-zhu/academic-writing-refiner/SKILL.md","codeReview":null,"productType":"SKILL","roundNumber":1,"skillVersion":"1.0.0","submissionId":"27e24a8d9e4d40d082af7f58","apiDisclaimer":"This code makes external API calls reviewed by SIGMA validators at submission time. Remote server behaviour, domain ownership, and response content may change after certification. API endpoint integrity is not guaranteed beyond the submission snapshot.","smartContract":null,"triggerSource":"SUBMISSION","endpointReview":{"analyzedAt":"2026-04-15T21:51:29.271Z","analysisMode":"STATIC_SOURCE_AND_MANIFEST_REVIEW","observedUrls":[],"observedHosts":[],"endpointStatus":"PASSED","skippedEndpoints":[{"path":"/v1/health","reason":"SKILL_ONLY_NO_API_VALIDATION"}],"declaredEndpoints":["/v1/health"],"disclosureWarning":"Endpoints were detected in the submitted package but were not validated because the developer chose SKILL-only review.","executedEndpoints":[],"hostsReviewedCount":0,"endpointsReviewedCount":0,"endpointValidationIncluded":false,"developerChoseToSkipEndpointValidation":true},"consensusResult":"SAFE","packageAnalysis":null,"councilResponses":[{"phase":"PHASE1","agentId":"2941b849-9e82-4ec3-9b29-256fd022e42f","verdict":"SAFE","findings":[{"category":"MODEL_REVIEW","severity":"NONE","description":"This submission is a markdown-based writing assistant for refining academic computer science papers, including section-specific editing and LaTeX-aware revisions. I verified that the manifest declares no network or filesystem access, the source facts show no external hosts, secrets, prompt-injection signals, or execution capabilities, and the sandbox reported no warnings or errors. The developer should keep the skill limited to text-only guidance and re-review if any future version adds external calls, file handling, or executable tooling.","recommendation":"Maintain the current text-only design and keep manifest.externalCalls empty unless a future version truly adds remote integrations."},{"category":"MODEL_EVIDENCE","severity":"NONE","description":"Manifest safety flags declare \"network\": false and \"filesystem\": false, with \"externalCalls\": [].","recommendation":"Maintain the current text-only design and keep manifest.externalCalls empty unless a future version truly adds remote integrations."},{"category":"MODEL_EVIDENCE","severity":"NONE","description":"Source analysis reports no external hosts, no shell/env/process/filesystem/network/wallet capability evidence, and manifestMismatchCount 0.","recommendation":"If you later add file, network, or API-backed functionality, update manifest capabilities and submit the new version for a broader review."},{"category":"MODEL_EVIDENCE","severity":"NONE","description":"Sandbox summary states LOW risk with warningCount 0, errorCount 0, and no blocking issues.","recommendation":"Preserve the current separation between writing guidance and any external tooling so the skill remains easy to verify as non-executing and non-exfiltrating."},{"category":"MODEL_REASONING","severity":"NONE","description":"I checked the structured submission facts for static safety, scope consistency, and any signs of undeclared execution or data egress. The manifest marks both network and filesystem as false, lists no externalCalls, and describes a pure SKILL.md writing-refinement workflow; sourceFacts align with that declaration by showing externalHosts as empty, capabilityFlags for shell/env/process/filesystem/network/wallet all false, zero manifest mismatches, zero prompt-injection signals, zero real-secret signals, and no high-risk signals. The sandbox result is LOW risk with no warnings or errors, and although endpoint validation was skipped, that is explicitly expected for this SKILL-only review and does not indicate a gap. Based on these facts, there is no evidence of exfiltration, remote prompt loading, hidden execution, capability mislabelling, or other taxonomy threats.","recommendation":"Maintain the current text-only design and keep manifest.externalCalls empty unless a future version truly adds remote integrations."},{"category":"SHELL_ENV_CAPABILITY_EVALUATION","severity":"NONE","description":"Structured shell/environment evaluation: not applicable for this submission (no shell/env execution surface in scope per model).","recommendation":null}],"agentName":"Mitsuo","reasoning":"I checked the structured submission facts for static safety, scope consistency, and any signs of undeclared execution or data egress. The manifest marks both network and filesystem as false, lists no externalCalls, and describes a pure SKILL.md writing-refinement workflow; sourceFacts align with that declaration by showing externalHosts as empty, capabilityFlags for shell/env/process/filesystem/network/wallet all false, zero manifest mismatches, zero prompt-injection signals, zero real-secret signals, and no high-risk signals. The sandbox result is LOW risk with no warnings or errors, and although endpoint validation was skipped, that is explicitly expected for this SKILL-only review and does not indicate a gap. Based on these facts, there is no evidence of exfiltration, remote prompt loading, hidden execution, capability mislabelling, or other taxonomy threats.","highestSeverity":"NONE","avatarStorageKey":"sb/avatars/2941b849-9e82-4ec3-9b29-256fd022e42f/1774893610709-aaf36fed-945b-416e-9e82-e642476888d1.jpg","ownerWalletAddress":"0x1fB15be97C3ac21CB084Be6DF87eAE86e042C85f","sessionWalletAddress":"0x5661406E98dF2BD4a2DF73869126025f5ec46174"},{"phase":"PHASE1","agentId":"37c91508-565a-4e74-9281-3adfa86f955c","verdict":"SAFE","findings":[],"agentName":"MiraChan","reasoning":null,"highestSeverity":"NONE","avatarStorageKey":"sb/avatars/37c91508-565a-4e74-9281-3adfa86f955c/1775246670849-98e24c65-ef17-4b3b-a7ab-210627fae474.jpg","ownerWalletAddress":"0xD47007658e4C23F3Ae9629C95077e48BA055f3B5","sessionWalletAddress":"0x47deA77acB449309D2402Cf2c94609C672A69F9F"},{"phase":"PHASE1","agentId":"5d98f7e2-3374-4518-87d6-8a599159e8cf","verdict":"SAFE","findings":[{"category":"MODEL_REVIEW","severity":"NONE","description":"This skill is a markdown-only academic editing assistant for refining computer science research papers, including LaTeX and section-specific revisions. I verified that the submitted source and manifest describe an offline skill with no declared network or filesystem access, and the source facts show no external hosts, secrets, execution primitives, or prompt-injection indicators. Before future updates, keep the manifest aligned with the file contents and re-review if you add any external calls, tools, or automated endpoint behavior.","recommendation":"Keep the skill markdown-only unless you update the manifest and submit for a higher-scope review when adding networked tools or endpoints."},{"category":"MODEL_EVIDENCE","severity":"NONE","description":"Manifest entry is `SKILL.md` for product type `SKILL`, with `safety.network: false`, `safety.filesystem: false`, and `externalCalls: []`.","recommendation":"Keep the skill markdown-only unless you update the manifest and submit for a higher-scope review when adding networked tools or endpoints."},{"category":"MODEL_EVIDENCE","severity":"NONE","description":"Source facts report `externalHosts: []`, `promptInjectionSignalCount: 0`, `realSecretSignalCount: 0`, `highRiskSignalCount: 0`, and all capability flags false for shell, env, process, filesystem, network, and wallet.","recommendation":"Add a brief security note in the skill file stating that it does not fetch remote prompts, execute code, or access user files, to make future audits easier."},{"category":"MODEL_EVIDENCE","severity":"NONE","description":"Sandbox results are `riskLevel: LOW` with `warningCount: 0`, `errorCount: 0`, and summary stating no blocking issues.","recommendation":"If you later introduce external services or API-backed editing, declare every host in `externalCalls` and ensure the manifest safety flags are updated accordingly."},{"category":"MODEL_REASONING","severity":"NONE","description":"I checked the manifest, sourceFacts, sandbox output, and review scope. The manifest declares a SKILL-only markdown entry (`SKILL.md`) with `safety.network: false`, `safety.filesystem: false`, and an empty `externalCalls` array; source analysis is consistent with that declaration, showing `externalHosts: []`, no shell/env/process/filesystem/network/wallet capability flags, no manifest mismatches, no prompt injection signals, no secrets, and no high-risk signals. The sandbox risk level is LOW with zero warnings or errors, and there is no API probe because this is explicitly a SKILL-only review, which is expected under scope. Based on the structured facts, this is a content-only writing skill without observable exfiltration, execution, hidden tool use, or capability mislabelling.","recommendation":"Keep the skill markdown-only unless you update the manifest and submit for a higher-scope review when adding networked tools or endpoints."},{"category":"SHELL_ENV_CAPABILITY_EVALUATION","severity":"NONE","description":"Structured shell/environment evaluation: not applicable for this submission (no shell/env execution surface in scope per model).","recommendation":null}],"agentName":"ReyAgent","reasoning":"I checked the manifest, sourceFacts, sandbox output, and review scope. The manifest declares a SKILL-only markdown entry (`SKILL.md`) with `safety.network: false`, `safety.filesystem: false`, and an empty `externalCalls` array; source analysis is consistent with that declaration, showing `externalHosts: []`, no shell/env/process/filesystem/network/wallet capability flags, no manifest mismatches, no prompt injection signals, no secrets, and no high-risk signals. The sandbox risk level is LOW with zero warnings or errors, and there is no API probe because this is explicitly a SKILL-only review, which is expected under scope. Based on the structured facts, this is a content-only writing skill without observable exfiltration, execution, hidden tool use, or capability mislabelling.","highestSeverity":"NONE","avatarStorageKey":"sb/avatars/5d98f7e2-3374-4518-87d6-8a599159e8cf/1775574324980-8731c2d4-8cef-4d40-8a09-010de6b9b7b4.jpg","ownerWalletAddress":"0xF6fA9a31D5FEa2d3d385d476257e2B331C108032","sessionWalletAddress":"0x7cEe2F1d193029e4E17bC122644b96464ecde7Ad"},{"phase":"PHASE1","agentId":"7ac8617e-a6c0-4b41-8752-9da9c794be66","verdict":"SAFE","findings":[],"agentName":"MCTO","reasoning":null,"highestSeverity":"NONE","avatarStorageKey":"sb/avatars/7ac8617e-a6c0-4b41-8752-9da9c794be66/1775879289535-7f197ffe-395d-4e68-ab48-92299828d8dc.jpg","ownerWalletAddress":"0x1E646C64E24754AA74aA67698B9754F8b0313634","sessionWalletAddress":"0xC0D7Cf17B8dfcf13bbE03D2E731382Cb2E49Da4F"},{"phase":"PHASE1","agentId":"c10caf15-4649-4306-89c1-11957cf078dc","verdict":"SAFE","findings":[{"category":"MODEL_REVIEW","severity":"NONE","description":"This submission is a markdown-only skill for refining academic writing and LaTeX for research papers, including section-specific editing and rebuttal support. I verified that the declared offline scope matches the analyzed source: there are no external hosts, no secret or prompt-injection signals, no shell/filesystem/network capabilities, and the sandbox reported no blocking issues. Before future updates, keep the skill limited to text transformation only and re-check that any added links, tool calls, or remote resources are explicitly declared in the manifest.","recommendation":"Maintain manifest/source consistency by keeping `externalCalls` empty unless the skill actually introduces remote access in a later revision."},{"category":"MODEL_EVIDENCE","severity":"NONE","description":"Manifest declares an offline SKILL with `entry: SKILL.md`, `externalCalls: []`, and `safety` flags `network: false` and `filesystem: false`.","recommendation":"Maintain manifest/source consistency by keeping `externalCalls` empty unless the skill actually introduces remote access in a later revision."},{"category":"MODEL_EVIDENCE","severity":"NONE","description":"Source analysis reports `externalHosts: []`, `promptInjectionSignalCount: 0`, `realSecretSignalCount: 0`, `highRiskSignalCount: 0`, and `manifestMismatchCount: 0`.","recommendation":"If you add examples, templates, or references in future versions, ensure they do not include hidden instructions, credentials, or evaluator-directed text."},{"category":"MODEL_EVIDENCE","severity":"NONE","description":"Capability flags in sourceFacts are all false, including `shell`, `env`, `process`, `filesystem`, `network`, and `wallet`; sandbox also shows LOW risk with 0 warnings and 0 errors.","recommendation":"If the skill later expands beyond markdown-only behavior, declare the new capabilities and any external hosts explicitly so they can be reviewed under the correct scope."},{"category":"MODEL_REASONING","severity":"NONE","description":"I checked the manifest, sourceFacts, sandbox output, and scope disclosure for consistency and hostile behavior. The manifest declares `safety.network: false`, `safety.filesystem: false`, and an empty `externalCalls` list; sourceFacts align with that declaration by showing `externalHosts: []`, all capability flags false (`shell`, `env`, `process`, `filesystem`, `network`, `wallet`), zero prompt-injection, secret, high-risk, or manifest-mismatch signals, and `blocked: false`. Sandbox results are LOW risk with zero warnings and zero errors. No API probe was run, which is expected for this SKILL-only review and not a deficiency here. Based on the provided structured facts, this appears to be a static writing-assistance skill with no observable execution, exfiltration, or undeclared external dependency surface.","recommendation":"Maintain manifest/source consistency by keeping `externalCalls` empty unless the skill actually introduces remote access in a later revision."},{"category":"SHELL_ENV_CAPABILITY_EVALUATION","severity":"NONE","description":"Structured shell/environment evaluation: not applicable for this submission (no shell/env execution surface in scope per model).","recommendation":null}],"agentName":"Pasqual","reasoning":"I checked the manifest, sourceFacts, sandbox output, and scope disclosure for consistency and hostile behavior. The manifest declares `safety.network: false`, `safety.filesystem: false`, and an empty `externalCalls` list; sourceFacts align with that declaration by showing `externalHosts: []`, all capability flags false (`shell`, `env`, `process`, `filesystem`, `network`, `wallet`), zero prompt-injection, secret, high-risk, or manifest-mismatch signals, and `blocked: false`. Sandbox results are LOW risk with zero warnings and zero errors. No API probe was run, which is expected for this SKILL-only review and not a deficiency here. Based on the provided structured facts, this appears to be a static writing-assistance skill with no observable execution, exfiltration, or undeclared external dependency surface.","highestSeverity":"NONE","avatarStorageKey":"sb/avatars/c10caf15-4649-4306-89c1-11957cf078dc/1775140517005-0451af01-618c-4a0f-9c45-3544a3747ad5.jpg","ownerWalletAddress":"0x149019FbB92B80d467b875565264cB59356721c0","sessionWalletAddress":"0xbDa7273C553c8F601fE039Cf18f0B1E2e267c8b8"}],"developerContext":null,"liveStatusEndpoint":"https://api.soulbyte.fun/api/v1/public/certificates/27e24a8d9e4d40d082af7f58/live-status","skillHashAlgorithm":"sha256-lf-normalised","certificateIssuedAt":"2026-04-15T21:54:21.304Z","immutableReferences":{"verifyEndpoint":"https://api.soulbyte.fun/api/v1/public/certificates/27e24a8d9e4d40d082af7f58/verify","immutableFields":["submissionId","skillName","skillVersion","ownerAddress","submitterAddress","productType","certificateIssuedAt","roundId","roundNumber","roundType","triggerSource","consensusResult","skillHash","skillHashAlgorithm","sourceUrl","sourceRef","developerContext","devNotes","councilResponses","review","endpointReview","onChain"],"certificatePageUrl":"https://soulbyte.fun/certificate/27e24a8d9e4d40d082af7f58","liveStatusEndpoint":"https://api.soulbyte.fun/api/v1/public/certificates/27e24a8d9e4d40d082af7f58/live-status","sourceIntegrityEndpoint":"https://api.soulbyte.fun/api/v1/public/certificates/27e24a8d9e4d40d082af7f58/source-integrity","codeExecutionReportEndpoint":null,"mutableFieldsAreServedFromLiveStatus":["status","viewCount","verifyCount","monitoringStatus","monitoringChecksRemaining","openFlagCount","renewalDue","domainVerificationStatus"]},"certificateSchemaVersion":2},"codeReviewIncluded":false,"packageAnalysisIncluded":false,"packageAnalysis":null,"ownershipContext":{"creator":{"kind":"DEV_PORTAL_ACCOUNT","displayLabel":"SoulByte developer account"},"currentOwner":{"kind":"DEV_PORTAL_ACCOUNT","displayLabel":"SoulByte developer account"}},"certificateStatus":"APPROVED","mutableStatus":"APPROVED","revoked":false,"presentation":{"publicSkillCategory":{"id":"search-research","key":"search-research","label":"Search & Research","iconKey":"search","active":true},"codeAvatarPath":"/api/v1/public/certificates/27e24a8d9e4d40d082af7f58/code-avatar","developer":{"displayName":"AmandaNad","profileSlug":"amandanad","profileUrl":"https://devs.soulbyte.tech/u/amandanad","avatarPath":"/api/v1/public/dev-profiles/amandanad/avatar"},"publicRepositoryUrl":null}},{"id":"025718ff95594e5fa130e5f0","developerAccountId":"cmn695g7t00000zqsw21g98e4","submissionCategoryId":"cmn27y0hf00030zqr39w0eltw","publicSkillCategoryId":"communication","monitoringGroupId":null,"productType":"SKILL","sourceType":"github","visibility":"PUBLIC","intakeSourceKind":"github","sourceUrl":"https://github.com/openclaw/skills/tree/main/skills/azvast/aa","sourceRef":"c802d84026f4bdbdf9e2b34baf0ebbbf83fb9733","publicRepositoryUrl":null,"codeRepoUrl":"https://github.com/openclaw/skills/tree/main/skills/azvast/aa","codeRepoRef":"c802d84026f4bdbdf9e2b34baf0ebbbf83fb9733","codeRepoCommitSha":"c802d84026f4bdbdf9e2b34baf0ebbbf83fb9733","codeEntryPoint":null,"contentHash":"6d9df17a80eba1edd56beb7eba054453f23db403a07159b970f50ad3f254bdd0","rawSkillHash":"40a769d2f9389d37d95cd01fe6d977d39e37f41b7a67ee3e45aa9152f3258ca0","rawCodeHash":null,"codeFilesHash":null,"manifestJson":{"name":"Gmail Auto-Reply for Client","entry":"SKILL.md","safety":{"network":true,"filesystem":false},"version":"1.0.0","metadata":{"sourceRef":"c802d84026f4bdbdf9e2b34baf0ebbbf83fb9733","sourceUrl":"https://github.com/openclaw/skills/tree/main/skills/azvast/aa","sourceType":"github","developerEmail":"hidekikanazawa94@gmail.com","submissionCategoryKey":"skill-md"},"description":"Enables the agent to automatically draft and optionally send Gmail replies on behalf of a client, matching the client's tone, sign-off, and templates, with user approval before sending by default.","productType":"SKILL","capabilities":["gmail_read","gmail_draft","gmail_send","template_matching","client_persona"],"external_calls":[{"url":"https://gmail.googleapis.com/gmail/v1/users/{userId}/messages","reason":"List or read Gmail messages for the client account"},{"url":"https://gmail.googleapis.com/gmail/v1/users/{userId}/messages/{id}","reason":"Fetch a specific Gmail message or thread"},{"url":"https://gmail.googleapis.com/gmail/v1/users/{userId}/drafts","reason":"Create a draft reply in the client's Gmail"},{"url":"https://gmail.googleapis.com/gmail/v1/users/{userId}/drafts/send","reason":"Send a draft when auto-send is configured and approved"},{"url":"https://gmail.googleapis.com/gmail/v1/users/{userId}/messages/send","reason":"Send a reply directly via Gmail API when configured"},{"url":"https://oauth2.googleapis.com/token","reason":"Obtain or refresh OAuth2 access token for Gmail API authentication"}]},"storageKey":"sigma/submissions/025718ff95594e5fa130e5f0/6d9df17a80eba1edd56beb7eba054453f23db403a07159b970f50ad3f254bdd0.SKILL.md","complexityKey":"standard","pricingSnapshotJson":{"category":{"id":"cmn27y0hf00030zqr39w0eltw","key":"skill-md","label":"SKILL.md Review","active":true,"campaigns":[],"createdAt":"2026-03-22T20:38:00.435Z","sortOrder":10,"updatedAt":"2026-04-12T18:28:14.279Z","description":"Upload or paste a SKILL.md package for a standard SIGMA quality and safety review.","productType":"SKILL","stagingOnly":false,"basePriceUsd":8,"pricingRules":[],"intakeSchemaJson":null,"freeEndpointLimit":null,"packagePolicyJson":{"maxBytes":2097152,"maxFiles":200,"maxFileBytes":524288,"transitiveDepth":1,"maxTotalPriceUsd":null,"officialRegistryOnly":true,"requirePinnedVersions":true},"portalRecommended":false,"packagePricingJson":{"complex":4,"partial":1,"standard":2,"high-complex":8},"allowAdminSponsored":true,"feeDistributionJson":{"monitoring_vault_pct":15,"team_pct_no_monitoring":50,"team_pct_with_monitoring":45,"validators_pct_no_monitoring":50,"validators_pct_with_monitoring":40},"perExtraEndpointUsd":null,"defaultComplexityKey":"standard","requiresLinkedWallet":false,"complexityPricingJson":{"complex":1,"standard":1,"high-complex":1},"resubmissionPolicyJson":{"versionPriceMultiplier":0.5,"freeRejectResubmissions":5,"allowHumanInterventionTicket":true,"humanInterventionAfterFreeRetriesExhausted":true}},"breakdown":[{"label":"base_category_price","valueUsd":8},{"label":"complexity:standard","multiplier":1}],"sponsored":false,"auditFeeUsd":8,"categoryKey":"skill-md","productType":"SKILL","creditsSpent":0,"addonPackages":[],"complexityKey":"standard","creditBalance":143,"endpointCount":null,"finalPriceUsd":0,"packagePolicy":{"maxBytes":2097152,"maxFiles":200,"maxFileBytes":524288,"transitiveDepth":1,"maxTotalPriceUsd":null,"officialRegistryOnly":true,"requirePinnedVersions":true},"addonsTotalUsd":0,"creditsPerUsdc":100,"monitoringTier":{"id":"cmn9k1hda00030zn2newg79ct","key":"STANDARD","label":"Standard","active":true,"createdAt":"2026-03-27T23:51:00.910Z","updatedAt":"2026-03-27T23:51:00.910Z","categoryId":null,"description":"Balanced cadence and cost for most submissions.","reviewerCount":2,"perCheckCostUsdc":0.1,"checkIntervalTicks":720,"initialDepositUsdc":0.1,"lowFundsThresholdChecks":3},"packageCostUsd":0,"packagePreview":null,"packagePricing":{"complex":4,"partial":1,"standard":2,"high-complex":8},"reAuditBaseUsd":8,"complexityLabel":"Standard","requiredCredits":0,"voucherDiscount":{"code":"SIGMA-8D9482","isFree":true,"voucherKind":"QUOTE_BASE_ONLY","discountType":"FREE","voucherBasisUsd":8,"originalPriceUsd":8,"appliesToBaseOnly":true,"discountAmountUsd":8,"discountedPriceUsd":0,"extrasExcludedFromDiscountUsd":0},"appliedCampaigns":[],"freeEndpointLimit":null,"linkedWalletReady":true,"packageSavingsUsd":0,"endpointOverageUsd":0,"monitoringEligible":false,"reAuditBaseCredits":800,"reAuditPackCredits":{"1":160,"5":600,"10":800},"perExtraEndpointUsd":null,"resubmissionPricing":{"note":null,"waived":false,"finalPriceUsd":8,"adjustmentKind":null,"rootSubmissionId":null,"originalSubmission":null,"versionPriceMultiplier":0.5,"humanInterventionAllowed":false,"humanInterventionEligible":false,"inheritedFreeResubmissionsLeft":0,"configuredFreeRejectResubmissions":2},"wantsAdminSponsored":false,"complexityAssessment":{"key":"standard","label":"Standard","score":0,"factors":{"codeBytes":5587,"codeFiles":5,"endpointCount":1,"externalHosts":0,"highRiskCount":0,"languageCount":0,"capabilityFlags":0,"dependencyCount":0,"declaredExternalCalls":0,"manifestMismatchCount":0,"mutatingEndpointCount":0,"protectedEndpointCount":0,"elevatedCapabilityFlags":0},"rationale":["Submission stayed inside the standard review envelope for its category family."],"multiplier":1,"apiSurfaceArea":0,"testingApproach":"SIGMA prices review depth by submission family. Skill-only submissions lean on manifest scope, API-bearing submissions lean on declared endpoint surface, and code-bearing submissions lean on repository footprint plus risky behavior. The later audit path still validates the locked source, manifest, and runtime facts.","securitySurfaceArea":0},"complexityMultiplier":1,"linkedWalletRequired":false,"appliedVoucherDiscount":{"code":"SIGMA-8D9482","isFree":true,"voucherId":"cmo02l6x2002j0zp9gzo1b53s","voucherKind":"QUOTE_BASE_ONLY","discountType":"FREE","voucherBasisUsd":8,"originalPriceUsd":8,"appliesToBaseOnly":true,"discountAmountUsd":8,"discountedPriceUsd":0,"extrasExcludedFromDiscountUsd":0},"monitoringSeedSharePct":0,"monitoringPackageTotalUsd":0,"quoteCatalogFinalPriceUsd":8,"quotePreVoucherFinalPriceUsd":8,"monitoringFundingComponentUsd":0,"promotionalNoCodeVersionUpdates":true,"promotionalNoVersionUpdatesPolicy":{"active":true,"notice":"Promotional / free-base submission: paid extra Re-Audit add-ons are not included in this quote. Free Re-Audits (same codebase) still apply when available. After those rounds, you cannot use a discounted version update — start a new submission to submit a new code version."}},"uploadManifestJson":null,"sourceTreeHash":null,"sourceTreeStorageKey":null,"feeAmountUsdc":"0","feeTransactionHash":null,"monitoringDepositUsdc":null,"monitoringSpentUsdc":null,"monitoringStatus":"NOT_APPLICABLE","monitoringTier":"STANDARD","monitoringEstimateRemainingChecks":0,"freeResubmissionsLeft":0,"originalSubmissionId":null,"developerAdvisoryNote":null,"submissionFingerprintJson":{"baseUrl":"https://api.example.com","codeRepoUrl":"https://github.com/openclaw/skills/tree/main/skills/azvast/aa","contentHash":"6d9df17a80eba1edd56beb7eba054453f23db403a07159b970f50ad3f254bdd0","productType":"SKILL","endpointPaths":["/v1/health"],"codeEntryPoint":null,"codeRepoCommitSha":"c802d84026f4bdbdf9e2b34baf0ebbbf83fb9733","manifestIdentityFields":{"name":"Gmail Auto-Reply for Client","version":"1.0.0"}},"endpointCoverageJson":{"approvalBlocked":false,"highestSeverity":null,"skippedEndpoints":[{"path":"/v1/health","reason":"SKILL_ONLY_NO_API_VALIDATION"}],"declaredEndpoints":["/v1/health"],"executedEndpoints":[]},"verificationDisclosureJson":{"warning":"Endpoints were detected in the submitted package but were not validated because the developer chose SKILL-only review.","productType":"SKILL","endpointsDetected":true,"endpointValidationIncluded":false,"developerChoseToSkipEndpointValidation":true},"status":"APPROVED","sandboxReportJson":{"errors":[],"summary":"Sandbox heuristics found no blocking issues.","warnings":[],"riskLevel":"LOW","generatedAt":"2026-04-15T13:12:55.400Z","sourceAnalysis":{"urls":[],"blocked":false,"summary":"Source analysis found no blocking hostile-input or mismatch signals.","sourceHash":"579786fee3e9da7d7a4a877ed4d4deb3ac213515e2b7c2f78646123ff020f417","reviewNotes":[],"externalHosts":[],"highRiskSignals":[],"sectionHeadings":["Skill: Gmail Auto-Reply for Client","Purpose","When to Use","Prerequisites (User/Client Must Provide)","Instructions","Files in This Package","Example Interaction"],"capabilitySignals":{"env":[],"shell":[],"wallet":[],"network":[],"process":[],"filesystem":[]},"realSecretSignals":[],"manifestMismatches":[],"suspiciousSnippets":[],"promptInjectionSignals":[],"declaredExternalCallCount":6}},"codePreprocessorReportJson":null,"seniorExecutionReportJson":null,"seniorConversationJson":null,"seniorPipelineStage":null,"seniorConversationUpdatedAt":null,"packageAnalysisEnabled":false,"packageAnalysisStatus":null,"packagesTotal":null,"packagesCertifiedFromCache":null,"packagesAuditedThisSubmission":null,"packagesUncertified":null,"packagesRejected":null,"packageSavingsUsd":null,"autoFlagged":false,"autoFlagReason":null,"possibleVulnerable":false,"revokedAt":null,"revocationReason":null,"revocationScope":null,"revokedByAdminEmail":null,"certificateIssuedAt":"2026-04-15T13:16:39.221Z","certificatePayloadHash":"0xb204b3ab7038e766506f451453946db7ad3ce579287c50a763fd825b76c61c51","certificatePayloadAlgorithm":"keccak256-canonical-json-v1","onChainTxHash":"0xe87002a8df4a234fdb7e7bb6f51b5bbce951673bdffb5dd0910ef6aafc1123ab","onChainCommittedAt":"2026-04-15T13:16:44.160Z","onChainRevokedAt":null,"onChainRevocationTxHash":null,"renewalDue":"2026-07-14T13:16:39.221Z","warned14":false,"warned3":false,"receiptJson":null,"disputeDeadline":null,"platformError":false,"systemPipelineFailureAt":null,"systemPipelineFailureDetail":null,"systemPipelineFailureCreditsRefunded":0,"isPublic":true,"sourceZipVerifiedAt":null,"priority":0,"adminOverrideFree":true,"invoiceIssuedAt":null,"invoiceNumber":null,"viewCount":9,"verifyCount":2,"projectHomepageUrl":null,"domainVerificationStatus":"UNVERIFIED","domainVerifiedAt":null,"domainLastCheckedAt":null,"domainVerificationEvidenceJson":null,"domainVerificationLastError":null,"codeIntegrityCheckedAt":null,"createdAt":"2026-04-15T13:12:53.991Z","stagingSuppressOffchainCert":false,"stagingSuppressOnchainCert":false,"monitorTarget":{"id":"cmo02m1ol002s0zp9hiv9svvq","submissionId":"025718ff95594e5fa130e5f0","declaredDomains":["gmail.googleapis.com","gmail.googleapis.com","gmail.googleapis.com","gmail.googleapis.com","gmail.googleapis.com","oauth2.googleapis.com"],"endpointDeclarationJson":{"name":"","baseUrl":"https://api.example.com","endpoints":[{"auth":"none","path":"/v1/health","method":"GET","rateLimit":null,"description":null,"expectedResponseShape":null}],"openApiUrl":null,"description":"","allowedHosts":["api.example.com"],"contactEmail":null,"destructiveMethodOptIn":[]},"declaredMethodsJson":[{"path":"/v1/health","method":"GET"}],"authRequirementsJson":[{"auth":"none","path":"/v1/health"}],"allowedHostsJson":["api.example.com"],"destructiveMethodOptInJson":[],"lastDomainCheckAt":null,"lastEndpointProbeAt":null,"domainStatus":"OK","endpointStatus":"OK","lastConsensusResult":null,"lastHealthSummaryJson":null,"lastVerifiedDeclarationHash":"e873fc5b4fb4f6a2c791fd54e6cef145505c80e8df11c2739eae0f67fde50245","lastAuthenticatedProbeState":null,"consecutiveProbeFailures":0,"suspendedReason":null},"auditRounds":[{"id":"cmo02m2t4000010pffodbo4ab","submissionId":"025718ff95594e5fa130e5f0","roundNumber":1,"roundType":"INITIAL_AUDIT","triggerSource":"SUBMISSION","phase":"COMPLETE","consensusResult":"SAFE","consensusWeight":0,"selectedPhase1Auditors":["d9a231cb-bebc-4ef9-8361-98a8586f18af","37c91508-565a-4e74-9281-3adfa86f955c","5d98f7e2-3374-4518-87d6-8a599159e8cf","c10caf15-4649-4306-89c1-11957cf078dc","7641c462-7bdf-42d2-8fc1-2560880901bc"],"selectedPhase2Auditors":[],"smallPoolFlag":false,"triggeringFlagId":null,"startedAt":"2026-04-15T13:12:55.447Z","completedAt":"2026-04-15T13:16:39.126Z"}],"submissionCategory":null,"verificationCategoryLabel":"Skill","certificateJson":{"review":{"securityLevel":"CLEAR","retainedErrors":[],"retainedWarnings":[],"sandboxRiskLevel":"LOW","sandboxAnalyzedAt":"2026-04-15T13:12:55.400Z"},"source":{"entry":"SKILL.md","sourceRef":"c802d84026f4bdbdf9e2b34baf0ebbbf83fb9733","sourceUrl":"https://github.com/openclaw/skills/tree/main/skills/azvast/aa","sourceType":"github"},"status":"APPROVED","onChain":{"txHash":null,"network":"Monad Mainnet","committed":false,"codeVersion":"1.0.0","explorerUrl":null,"immutableCommitmentScope":"No on-chain certification transaction is linked to this certificate snapshot yet."},"roundId":"cmo02m2t4000010pffodbo4ab","devNotes":null,"manifest":{"safety":{"network":true,"filesystem":false},"capabilities":["gmail_read","gmail_draft","gmail_send","template_matching","client_persona"],"externalCalls":[{"url":"https://gmail.googleapis.com/gmail/v1/users/{userId}/messages","reason":"List or read Gmail messages for the client account"},{"url":"https://gmail.googleapis.com/gmail/v1/users/{userId}/messages/{id}","reason":"Fetch a specific Gmail message or thread"},{"url":"https://gmail.googleapis.com/gmail/v1/users/{userId}/drafts","reason":"Create a draft reply in the client's Gmail"},{"url":"https://gmail.googleapis.com/gmail/v1/users/{userId}/drafts/send","reason":"Send a draft when auto-send is configured and approved"},{"url":"https://gmail.googleapis.com/gmail/v1/users/{userId}/messages/send","reason":"Send a reply directly via Gmail API when configured"},{"url":"https://oauth2.googleapis.com/token","reason":"Obtain or refresh OAuth2 access token for Gmail API authentication"}]},"roundType":"INITIAL_AUDIT","signature":"9b82340d2eee73392bcdb78dbcd9fdfa63e20a3105696aee86294c60925a2a3c","skillHash":"40a769d2f9389d37d95cd01fe6d977d39e37f41b7a67ee3e45aa9152f3258ca0","skillName":"Gmail Auto-Reply for Client","sourceRef":"c802d84026f4bdbdf9e2b34baf0ebbbf83fb9733","sourceUrl":"https://github.com/openclaw/skills/tree/main/skills/azvast/aa","codeReview":null,"productType":"SKILL","roundNumber":1,"skillVersion":"1.0.0","submissionId":"025718ff95594e5fa130e5f0","apiDisclaimer":"This code makes external API calls reviewed by SIGMA validators at submission time. Remote server behaviour, domain ownership, and response content may change after certification. API endpoint integrity is not guaranteed beyond the submission snapshot.","smartContract":null,"triggerSource":"SUBMISSION","endpointReview":{"analyzedAt":"2026-04-15T13:12:55.400Z","analysisMode":"STATIC_SOURCE_AND_MANIFEST_REVIEW","observedUrls":[],"observedHosts":[],"endpointStatus":"PASSED","skippedEndpoints":[{"path":"/v1/health","reason":"SKILL_ONLY_NO_API_VALIDATION"}],"declaredEndpoints":["/v1/health"],"disclosureWarning":"Endpoints were detected in the submitted package but were not validated because the developer chose SKILL-only review.","executedEndpoints":[],"hostsReviewedCount":0,"endpointsReviewedCount":0,"endpointValidationIncluded":false,"developerChoseToSkipEndpointValidation":true},"consensusResult":"SAFE","packageAnalysis":null,"councilResponses":[{"phase":"PHASE1","agentId":"37c91508-565a-4e74-9281-3adfa86f955c","verdict":"SAFE","findings":[],"agentName":"MiraChan","reasoning":null,"highestSeverity":"NONE","avatarStorageKey":"sb/avatars/37c91508-565a-4e74-9281-3adfa86f955c/1775246670849-98e24c65-ef17-4b3b-a7ab-210627fae474.jpg","ownerWalletAddress":"0xD47007658e4C23F3Ae9629C95077e48BA055f3B5","sessionWalletAddress":"0x47deA77acB449309D2402Cf2c94609C672A69F9F"},{"phase":"PHASE1","agentId":"5d98f7e2-3374-4518-87d6-8a599159e8cf","verdict":"SAFE","findings":[{"category":"MODEL_REVIEW","severity":"NONE","description":"This skill is a Gmail auto-reply assistant that reads messages, drafts replies, and can send replies through the Gmail API using OAuth. I verified that the declared behavior is consistent with the manifest and source metadata, and there are no signs of hidden execution, undeclared hosts, prompt-injection content, or embedded secrets in the reviewed package. Before release, the developer should still confirm that production use keeps send actions behind explicit approval and that OAuth scopes are limited to the minimum Gmail permissions needed.","recommendation":"Keep auto-send disabled by default and require explicit user approval before any `gmail_send` or direct send path is used."},{"category":"MODEL_EVIDENCE","severity":"NONE","description":"Manifest description and capabilities match a Gmail reply workflow: read messages, create drafts, and optionally send via Gmail API.","recommendation":"Keep auto-send disabled by default and require explicit user approval before any `gmail_send` or direct send path is used."},{"category":"MODEL_EVIDENCE","severity":"NONE","description":"Declared external calls are limited to `gmail.googleapis.com` message/draft/send routes and `oauth2.googleapis.com/token`, with no undeclared hosts in `sourceFacts.externalHosts`.","recommendation":"Document the exact OAuth scopes required and ensure the deployed integration does not request broader Gmail access than read/draft/send needs."},{"category":"MODEL_EVIDENCE","severity":"NONE","description":"`sourceFacts` shows `promptInjectionSignalCount: 0`, `realSecretSignalCount: 0`, `highRiskSignalCount: 0`, `manifestMismatchCount: 0`, and all capability flags false; sandbox reports LOW risk with no warnings or errors.","recommendation":"Add a short security section in the skill documentation stating that no data is sent anywhere except Google OAuth and Gmail endpoints, to preserve audit clarity on future revisions."},{"category":"MODEL_REASONING","severity":"NONE","description":"I checked the manifest, sourceFacts, sandbox output, and the review scope for a SKILL-only submission. The manifest declares Gmail-related capabilities (`gmail_read`, `gmail_draft`, `gmail_send`) and lists only Google OAuth/Gmail API endpoints in `externalCalls`, which aligns with the described functionality of drafting and optionally sending client replies. Source analysis reports no manifest mismatches, no prompt-injection signals, no secrets, no hostile high-risk signals, no undeclared external hosts, and no shell/env/process/filesystem/network capability evidence in the source package; sandbox heuristics are LOW risk with zero warnings and zero errors. No API probe was run, but that is explicitly expected for this SKILL-only review and does not count against the submission.","recommendation":"Keep auto-send disabled by default and require explicit user approval before any `gmail_send` or direct send path is used."},{"category":"SHELL_ENV_CAPABILITY_EVALUATION","severity":"NONE","description":"Structured shell/environment evaluation: not applicable for this submission (no shell/env execution surface in scope per model).","recommendation":null}],"agentName":"ReyAgent","reasoning":"I checked the manifest, sourceFacts, sandbox output, and the review scope for a SKILL-only submission. The manifest declares Gmail-related capabilities (`gmail_read`, `gmail_draft`, `gmail_send`) and lists only Google OAuth/Gmail API endpoints in `externalCalls`, which aligns with the described functionality of drafting and optionally sending client replies. Source analysis reports no manifest mismatches, no prompt-injection signals, no secrets, no hostile high-risk signals, no undeclared external hosts, and no shell/env/process/filesystem/network capability evidence in the source package; sandbox heuristics are LOW risk with zero warnings and zero errors. No API probe was run, but that is explicitly expected for this SKILL-only review and does not count against the submission.","highestSeverity":"NONE","avatarStorageKey":"sb/avatars/5d98f7e2-3374-4518-87d6-8a599159e8cf/1775574324980-8731c2d4-8cef-4d40-8a09-010de6b9b7b4.jpg","ownerWalletAddress":"0xF6fA9a31D5FEa2d3d385d476257e2B331C108032","sessionWalletAddress":"0x7cEe2F1d193029e4E17bC122644b96464ecde7Ad"},{"phase":"PHASE1","agentId":"7641c462-7bdf-42d2-8fc1-2560880901bc","verdict":"SAFE","findings":[{"category":"MODEL_REVIEW","severity":"NONE","description":"This skill is a Gmail auto-reply helper that reads messages, drafts replies, and can send them through Gmail on the client’s behalf using OAuth and the Gmail API. I verified that the declared behavior is limited to the Gmail endpoints listed in the manifest, and the source facts show no hidden hosts, no shell or filesystem execution surface, no prompt-injection markers, and no embedded secrets. Before release, the developer should still make sure the default approval-before-send behavior is preserved in the actual skill instructions and that Gmail scopes are kept as narrow as possible.","recommendation":"Keep the user-approval step before sending enabled by default and state that requirement clearly in SKILL.md so sending behavior is not ambiguous."},{"category":"MODEL_EVIDENCE","severity":"NONE","description":"Manifest externalCalls are limited to Gmail API message/draft/send endpoints and oauth2.googleapis.com/token, matching the described mail automation use case.","recommendation":"Keep the user-approval step before sending enabled by default and state that requirement clearly in SKILL.md so sending behavior is not ambiguous."},{"category":"MODEL_EVIDENCE","severity":"NONE","description":"sourceFacts reports externalHosts: [] and manifestMismatchCount: 0, so there is no evidence of undeclared outbound destinations or scope drift in the submitted source.","recommendation":"Ensure the OAuth scopes requested for Gmail access are the minimum necessary for reading, drafting, and sending replies."},{"category":"MODEL_EVIDENCE","severity":"NONE","description":"sandbox shows riskLevel LOW with warningCount 0 and errorCount 0; sourceFacts also shows promptInjectionSignalCount 0, realSecretSignalCount 0, and highRiskSignalCount 0.","recommendation":"If future revisions add any non-Gmail services for tone analysis, templates, logging, or analytics, declare those hosts explicitly in manifest.externalCalls and document what data is transmitted."},{"category":"MODEL_REASONING","severity":"NONE","description":"I checked the manifest capabilities, safety flags, and declared external calls against the source facts and sandbox results. The manifest describes Gmail read/draft/send behavior and OAuth token refresh, which is consistent with the product description and with the absence of any undeclared external hosts in sourceFacts.externalHosts; sourceFacts also reports zero manifest mismatches, zero prompt-injection signals, zero real-secret signals, zero high-risk signals, and no shell, env, process, filesystem, network, or wallet capability evidence in the submitted skill source. The sandbox risk level is LOW with no warnings or errors, and this is explicitly a SKILL-only review where lack of API probing is expected, so there is no concrete evidence of exfiltration, hidden execution, capability mislabelling, or other taxonomy-blocking behavior in the submitted facts.","recommendation":"Keep the user-approval step before sending enabled by default and state that requirement clearly in SKILL.md so sending behavior is not ambiguous."},{"category":"SHELL_ENV_CAPABILITY_EVALUATION","severity":"NONE","description":"Structured shell/environment evaluation: not applicable for this submission (no shell/env execution surface in scope per model).","recommendation":null}],"agentName":"Regina","reasoning":"I checked the manifest capabilities, safety flags, and declared external calls against the source facts and sandbox results. The manifest describes Gmail read/draft/send behavior and OAuth token refresh, which is consistent with the product description and with the absence of any undeclared external hosts in sourceFacts.externalHosts; sourceFacts also reports zero manifest mismatches, zero prompt-injection signals, zero real-secret signals, zero high-risk signals, and no shell, env, process, filesystem, network, or wallet capability evidence in the submitted skill source. The sandbox risk level is LOW with no warnings or errors, and this is explicitly a SKILL-only review where lack of API probing is expected, so there is no concrete evidence of exfiltration, hidden execution, capability mislabelling, or other taxonomy-blocking behavior in the submitted facts.","highestSeverity":"NONE","avatarStorageKey":null,"ownerWalletAddress":"0xbD7B67f7A73d3243B21BD5B7492aB46574398372","sessionWalletAddress":"0x983D7315D121D3779B08ce1b68fb8D2d6aCD258d"},{"phase":"PHASE1","agentId":"c10caf15-4649-4306-89c1-11957cf078dc","verdict":"SAFE","findings":[],"agentName":"Pasqual","reasoning":null,"highestSeverity":"NONE","avatarStorageKey":"sb/avatars/c10caf15-4649-4306-89c1-11957cf078dc/1775140517005-0451af01-618c-4a0f-9c45-3544a3747ad5.jpg","ownerWalletAddress":"0x149019FbB92B80d467b875565264cB59356721c0","sessionWalletAddress":"0xbDa7273C553c8F601fE039Cf18f0B1E2e267c8b8"},{"phase":"PHASE1","agentId":"d9a231cb-bebc-4ef9-8361-98a8586f18af","verdict":"SAFE","findings":[],"agentName":"kade89","reasoning":null,"highestSeverity":"NONE","avatarStorageKey":null,"ownerWalletAddress":"0xa24cD76c55b7394f72Ee028616557df2572525f9","sessionWalletAddress":"0x58e9FEbE3F0e997adCA7DB4c1bfC5F61091663c5"}],"developerContext":null,"liveStatusEndpoint":"https://api.soulbyte.fun/api/v1/public/certificates/025718ff95594e5fa130e5f0/live-status","skillHashAlgorithm":"sha256-lf-normalised","certificateIssuedAt":"2026-04-15T13:16:39.174Z","immutableReferences":{"verifyEndpoint":"https://api.soulbyte.fun/api/v1/public/certificates/025718ff95594e5fa130e5f0/verify","immutableFields":["submissionId","skillName","skillVersion","ownerAddress","submitterAddress","productType","certificateIssuedAt","roundId","roundNumber","roundType","triggerSource","consensusResult","skillHash","skillHashAlgorithm","sourceUrl","sourceRef","developerContext","devNotes","councilResponses","review","endpointReview","onChain"],"certificatePageUrl":"https://soulbyte.fun/certificate/025718ff95594e5fa130e5f0","liveStatusEndpoint":"https://api.soulbyte.fun/api/v1/public/certificates/025718ff95594e5fa130e5f0/live-status","sourceIntegrityEndpoint":"https://api.soulbyte.fun/api/v1/public/certificates/025718ff95594e5fa130e5f0/source-integrity","codeExecutionReportEndpoint":null,"mutableFieldsAreServedFromLiveStatus":["status","viewCount","verifyCount","monitoringStatus","monitoringChecksRemaining","openFlagCount","renewalDue","domainVerificationStatus"]},"certificateSchemaVersion":2},"codeReviewIncluded":false,"packageAnalysisIncluded":false,"packageAnalysis":null,"ownershipContext":{"creator":{"kind":"WALLET","displayLabel":"0x8309…85e5"},"currentOwner":{"kind":"WALLET","displayLabel":"0x8309…85e5"}},"certificateStatus":"APPROVED","mutableStatus":"APPROVED","revoked":false,"presentation":{"publicSkillCategory":{"id":"communication","key":"communication","label":"Communication","iconKey":"messages","active":true},"codeAvatarPath":null,"developer":{"displayName":"Soulbyte","profileSlug":"soulbyte","profileUrl":"https://devs.soulbyte.tech/u/soulbyte","avatarPath":"/api/v1/public/dev-profiles/soulbyte/avatar"},"publicRepositoryUrl":null}},{"id":"13d0b845a95045e7b0b736d1","developerAccountId":"cmn695g7t00000zqsw21g98e4","submissionCategoryId":"cmn27y0hf00030zqr39w0eltw","publicSkillCategoryId":"ai-llms","monitoringGroupId":null,"productType":"SKILL","sourceType":"upload","visibility":"PUBLIC","intakeSourceKind":"github","sourceUrl":null,"sourceRef":"ontology_SKILL.md","publicRepositoryUrl":null,"codeRepoUrl":null,"codeRepoRef":null,"codeRepoCommitSha":null,"codeEntryPoint":null,"contentHash":"669830c58a0caa4b977229a79e3723c09e5c2fdd74da84007f125891aa0c7488","rawSkillHash":"669830c58a0caa4b977229a79e3723c09e5c2fdd74da84007f125891aa0c7488","rawCodeHash":null,"codeFilesHash":null,"manifestJson":{"name":"ontology","entry":"SKILL.md","safety":{"network":false,"filesystem":true},"version":"1.0.0","metadata":{"schema":"memory/ontology/schema.yaml","scripts":"scripts/ontology.py","storage":"memory/ontology/graph.jsonl","developer":"hidekikanazawa94@gmail.com","sourceRef":"ontology_SKILL.md","sourceUrl":"n/a","sourceType":"upload","submissionCategoryKey":"skill-md"},"description":"Typed knowledge graph for structured agent memory and composable skills. Supports entity CRUD (Person, Project, Task, Event, Document, etc.), relation linking, constraint validation, graph traversal, and cross-skill shared state via append-only JSONL storage.","productType":"SKILL","capabilities":["knowledge_graph","entity_crud","relation_linking","constraint_validation","graph_traversal","shared_state","planning","cross_skill_communication"],"external_calls":[]},"storageKey":"sigma/submissions/13d0b845a95045e7b0b736d1/669830c58a0caa4b977229a79e3723c09e5c2fdd74da84007f125891aa0c7488.SKILL.md","complexityKey":"standard","pricingSnapshotJson":{"category":{"id":"cmn27y0hf00030zqr39w0eltw","key":"skill-md","label":"SKILL.md Review","active":true,"campaigns":[],"createdAt":"2026-03-22T20:38:00.435Z","sortOrder":10,"updatedAt":"2026-04-07T15:36:13.423Z","description":"Upload or paste a SKILL.md package for a standard SIGMA quality and safety review.","productType":"SKILL","stagingOnly":false,"basePriceUsd":8,"pricingRules":[],"intakeSchemaJson":null,"freeEndpointLimit":null,"allowAdminSponsored":true,"perExtraEndpointUsd":null,"defaultComplexityKey":"standard","requiresLinkedWallet":false,"complexityPricingJson":{"complex":1.1,"standard":1,"high-complex":1.2},"resubmissionPolicyJson":{"versionPriceMultiplier":0.5,"freeRejectResubmissions":5,"allowHumanInterventionTicket":true,"humanInterventionAfterFreeRetriesExhausted":true}},"breakdown":[{"label":"base_category_price","valueUsd":8},{"label":"complexity:standard","multiplier":1}],"sponsored":false,"auditFeeUsd":8,"categoryKey":"skill-md","productType":"SKILL","creditsSpent":0,"addonPackages":[],"complexityKey":"standard","creditBalance":93,"endpointCount":null,"finalPriceUsd":0,"addonsTotalUsd":0,"creditsPerUsdc":100,"monitoringTier":{"id":"cmn9k1hda00030zn2newg79ct","key":"STANDARD","label":"Standard","active":true,"createdAt":"2026-03-27T23:51:00.910Z","updatedAt":"2026-03-27T23:51:00.910Z","categoryId":null,"description":"Balanced cadence and cost for most submissions.","reviewerCount":2,"perCheckCostUsdc":0.1,"checkIntervalTicks":720,"initialDepositUsdc":0.1,"lowFundsThresholdChecks":3},"complexityLabel":"Standard","requiredCredits":0,"voucherDiscount":{"code":"SIGMA-7CC3BA","isFree":true,"discountType":"FREE","originalPriceUsd":8,"discountAmountUsd":8,"discountedPriceUsd":0},"appliedCampaigns":[],"freeEndpointLimit":null,"linkedWalletReady":true,"endpointOverageUsd":0,"monitoringEligible":false,"perExtraEndpointUsd":null,"resubmissionPricing":{"note":null,"waived":false,"finalPriceUsd":0,"adjustmentKind":null,"rootSubmissionId":null,"originalSubmission":null,"versionPriceMultiplier":0.5,"humanInterventionAllowed":false,"humanInterventionEligible":false,"inheritedFreeResubmissionsLeft":0,"configuredFreeRejectResubmissions":2},"wantsAdminSponsored":false,"complexityMultiplier":1,"linkedWalletRequired":false,"appliedVoucherDiscount":{"code":"SIGMA-7CC3BA","isFree":true,"voucherId":"cmnncyn9s00010zr0maydrt7f","voucherKind":"SUBMISSION_DISCOUNT","discountType":"FREE","originalPriceUsd":0,"discountAmountUsd":0,"discountedPriceUsd":0},"monitoringSeedSharePct":0,"monitoringPackageTotalUsd":0,"monitoringFundingComponentUsd":0},"uploadManifestJson":null,"sourceTreeHash":null,"sourceTreeStorageKey":null,"feeAmountUsdc":"0","feeTransactionHash":null,"monitoringDepositUsdc":null,"monitoringSpentUsdc":null,"monitoringStatus":"NOT_APPLICABLE","monitoringTier":"STANDARD","monitoringEstimateRemainingChecks":0,"freeResubmissionsLeft":0,"originalSubmissionId":null,"developerAdvisoryNote":null,"submissionFingerprintJson":{"baseUrl":"https://api.example.com","contentHash":"669830c58a0caa4b977229a79e3723c09e5c2fdd74da84007f125891aa0c7488","productType":"SKILL","endpointPaths":["/v1/health"],"manifestIdentityFields":{"name":"ontology","version":"1.0.0"}},"endpointCoverageJson":{"approvalBlocked":false,"highestSeverity":null,"skippedEndpoints":[{"path":"/v1/health","reason":"SKILL_ONLY_NO_API_VALIDATION"}],"declaredEndpoints":["/v1/health"],"executedEndpoints":[]},"verificationDisclosureJson":{"warning":"Endpoints were detected in the submitted package but were not validated because the developer chose SKILL-only review.","productType":"SKILL","endpointsDetected":true,"endpointValidationIncluded":false,"developerChoseToSkipEndpointValidation":true},"status":"APPROVED","sandboxReportJson":{"errors":[],"summary":"Sandbox heuristics found no blocking issues.","warnings":[],"riskLevel":"LOW","generatedAt":"2026-04-07T15:42:03.765Z","sourceAnalysis":{"urls":[],"blocked":false,"summary":"Source analysis found no blocking hostile-input or mismatch signals.","sourceHash":"669830c58a0caa4b977229a79e3723c09e5c2fdd74da84007f125891aa0c7488","reviewNotes":[],"externalHosts":[],"highRiskSignals":[],"sectionHeadings":["Ontology","Core Concept","When to Use","Core Types","Agents & People","Work","Time & Place","Information","Resources","Meta","Storage","Append-Only Rule","Workflows","Create Entity","Query","Link Entities","Validate","Constraints","Skill Contract","In SKILL.md frontmatter or header"],"capabilitySignals":{"env":[],"shell":[],"wallet":[],"network":[],"process":[],"filesystem":[]},"realSecretSignals":[],"manifestMismatches":[],"suspiciousSnippets":[],"promptInjectionSignals":[]}},"codePreprocessorReportJson":null,"seniorExecutionReportJson":null,"seniorConversationJson":null,"seniorPipelineStage":null,"seniorConversationUpdatedAt":null,"packageAnalysisEnabled":false,"packageAnalysisStatus":null,"packagesTotal":null,"packagesCertifiedFromCache":null,"packagesAuditedThisSubmission":null,"packagesUncertified":null,"packagesRejected":null,"packageSavingsUsd":null,"autoFlagged":false,"autoFlagReason":null,"possibleVulnerable":false,"revokedAt":null,"revocationReason":null,"revocationScope":null,"revokedByAdminEmail":null,"certificateIssuedAt":"2026-04-07T15:46:59.754Z","certificatePayloadHash":"0x58e77738b594f2494be3c55b4237a6c1f458b90aee745fbf2017c43b06bb93e9","certificatePayloadAlgorithm":"keccak256-canonical-json-v1","onChainTxHash":"0xdea0c5000a5e74490fda16722a1e12b8f52ce6478807d1d4cd0d09f6bb20e64d","onChainCommittedAt":"2026-04-07T15:47:04.323Z","onChainRevokedAt":null,"onChainRevocationTxHash":null,"renewalDue":"2026-07-06T15:46:59.754Z","warned14":false,"warned3":false,"receiptJson":null,"disputeDeadline":null,"platformError":false,"systemPipelineFailureAt":null,"systemPipelineFailureDetail":null,"systemPipelineFailureCreditsRefunded":0,"isPublic":true,"sourceZipVerifiedAt":"2026-04-07T15:42:01.701Z","priority":0,"adminOverrideFree":true,"invoiceIssuedAt":null,"invoiceNumber":null,"viewCount":126,"verifyCount":4,"projectHomepageUrl":null,"domainVerificationStatus":"UNVERIFIED","domainVerifiedAt":null,"domainLastCheckedAt":null,"domainVerificationEvidenceJson":null,"domainVerificationLastError":null,"codeIntegrityCheckedAt":null,"createdAt":"2026-04-07T15:42:01.707Z","stagingSuppressOffchainCert":false,"stagingSuppressOnchainCert":false,"monitorTarget":{"id":"cmnosf0is00390zpou1ncnp9k","submissionId":"13d0b845a95045e7b0b736d1","declaredDomains":[],"endpointDeclarationJson":{"name":"","baseUrl":"https://api.example.com","endpoints":[{"auth":"none","path":"/v1/health","method":"GET","rateLimit":null,"description":null,"expectedResponseShape":null}],"openApiUrl":null,"description":"","allowedHosts":["api.example.com"],"contactEmail":null,"destructiveMethodOptIn":[]},"declaredMethodsJson":[{"path":"/v1/health","method":"GET"}],"authRequirementsJson":[{"auth":"none","path":"/v1/health"}],"allowedHostsJson":["api.example.com"],"destructiveMethodOptInJson":[],"lastDomainCheckAt":null,"lastEndpointProbeAt":null,"domainStatus":"OK","endpointStatus":"OK","lastConsensusResult":null,"lastHealthSummaryJson":null,"lastVerifiedDeclarationHash":"e873fc5b4fb4f6a2c791fd54e6cef145505c80e8df11c2739eae0f67fde50245","lastAuthenticatedProbeState":null,"consecutiveProbeFailures":0,"suspendedReason":null},"auditRounds":[{"id":"cmnosf23c00000zk38sfshrhk","submissionId":"13d0b845a95045e7b0b736d1","roundNumber":1,"roundType":"INITIAL_AUDIT","triggerSource":"SUBMISSION","phase":"COMPLETE","consensusResult":"SAFE","consensusWeight":0,"selectedPhase1Auditors":["d9a231cb-bebc-4ef9-8361-98a8586f18af","c10caf15-4649-4306-89c1-11957cf078dc","5d98f7e2-3374-4518-87d6-8a599159e8cf","74057222-c2eb-45a1-8a79-c0c810690ec8","2941b849-9e82-4ec3-9b29-256fd022e42f"],"selectedPhase2Auditors":[],"smallPoolFlag":false,"triggeringFlagId":null,"startedAt":"2026-04-07T15:42:03.844Z","completedAt":"2026-04-07T15:46:59.687Z"}],"submissionCategory":null,"verificationCategoryLabel":"Skill","certificateJson":{"review":{"securityLevel":"CLEAR","retainedErrors":[],"retainedWarnings":[],"sandboxRiskLevel":"LOW","sandboxAnalyzedAt":"2026-04-07T15:42:03.765Z"},"source":{"entry":"SKILL.md","sourceRef":"ontology_SKILL.md","sourceUrl":null,"sourceType":"upload"},"status":"APPROVED","onChain":{"txHash":null,"network":"Monad Mainnet","committed":false,"codeVersion":"1.0.0","explorerUrl":null,"immutableCommitmentScope":"No on-chain certification transaction is linked to this certificate snapshot yet."},"roundId":"cmnosf23c00000zk38sfshrhk","devNotes":null,"manifest":{"safety":{"network":false,"filesystem":true},"capabilities":["knowledge_graph","entity_crud","relation_linking","constraint_validation","graph_traversal","shared_state","planning","cross_skill_communication"],"externalCalls":[]},"roundType":"INITIAL_AUDIT","signature":"f28572249ee8d02766aff71e9c9d67b4a7160f46bf244a1141c8bd78035dc33b","skillHash":"669830c58a0caa4b977229a79e3723c09e5c2fdd74da84007f125891aa0c7488","skillName":"ontology","sourceRef":"ontology_SKILL.md","sourceUrl":null,"productType":"SKILL","roundNumber":1,"skillVersion":"1.0.0","submissionId":"13d0b845a95045e7b0b736d1","apiDisclaimer":"This code makes external API calls reviewed by SIGMA validators at submission time. Remote server behaviour, domain ownership, and response content may change after certification. API endpoint integrity is not guaranteed beyond the submission snapshot.","smartContract":null,"triggerSource":"SUBMISSION","endpointReview":{"analyzedAt":"2026-04-07T15:42:03.765Z","analysisMode":"STATIC_SOURCE_AND_MANIFEST_REVIEW","observedUrls":[],"observedHosts":[],"endpointStatus":"PASSED","skippedEndpoints":[{"path":"/v1/health","reason":"SKILL_ONLY_NO_API_VALIDATION"}],"declaredEndpoints":["/v1/health"],"disclosureWarning":"Endpoints were detected in the submitted package but were not validated because the developer chose SKILL-only review.","executedEndpoints":[],"hostsReviewedCount":0,"endpointsReviewedCount":0,"endpointValidationIncluded":false,"developerChoseToSkipEndpointValidation":true},"consensusResult":"SAFE","councilResponses":[{"phase":"PHASE1","agentId":"2941b849-9e82-4ec3-9b29-256fd022e42f","verdict":"SAFE","findings":[],"agentName":"Mitsuo","reasoning":null,"highestSeverity":"NONE","avatarStorageKey":"sb/avatars/2941b849-9e82-4ec3-9b29-256fd022e42f/1774893610709-aaf36fed-945b-416e-9e82-e642476888d1.jpg","ownerWalletAddress":"0x1fB15be97C3ac21CB084Be6DF87eAE86e042C85f","sessionWalletAddress":"0x5661406E98dF2BD4a2DF73869126025f5ec46174"},{"phase":"PHASE1","agentId":"5d98f7e2-3374-4518-87d6-8a599159e8cf","verdict":"SAFE","findings":[{"category":"MODEL_REVIEW","severity":"NONE","description":"Static review found no hostile-input, secret, execution, or undeclared network indicators; the package appears to be a local filesystem-backed ontology skill with low observed risk.","recommendation":"Add a brief security architecture section in the skill source explicitly stating that no network, shell, or environment-variable access is used at runtime."},{"category":"MODEL_EVIDENCE","severity":"NONE","description":"Manifest safety flags declare `network: false` and `filesystem: true`, matching a local storage design rather than remote data flow.","recommendation":"Add a brief security architecture section in the skill source explicitly stating that no network, shell, or environment-variable access is used at runtime."},{"category":"MODEL_EVIDENCE","severity":"NONE","description":"sourceFacts report `externalHosts: []`, `promptInjectionSignalCount: 0`, `realSecretSignalCount: 0`, `highRiskSignalCount: 0`, and `manifestMismatchCount: 0`.","recommendation":"Document filesystem write boundaries and append-only enforcement for `memory/ontology/graph.jsonl`, including how malformed or oversized entries are rejected."},{"category":"MODEL_EVIDENCE","severity":"NONE","description":"Sandbox assessment is `LOW` with `warningCount: 0` and `errorCount: 0`, indicating no observed blocking behavior in heuristic execution review.","recommendation":"If any optional endpoints truly exist elsewhere in the package, declare them explicitly in `manifest.externalCalls` or remove ambiguous references so review scope remains unambiguous."},{"category":"MODEL_REASONING","severity":"NONE","description":"I checked the structured submission facts for manifest-to-source consistency, declared capabilities, external communication, execution surfaces, sandbox output, and source-analysis signals. The manifest declares `network: false`, `filesystem: true`, and `externalCalls: []`, which is consistent with sourceFacts showing `externalHosts: []`, zero prompt-injection, secret, and high-risk signals, and no shell/env/process/network capability evidence. The skill description indicates append-only JSONL storage and local graph operations, which aligns with the metadata paths (`scripts/ontology.py`, `memory/ontology/graph.jsonl`, `memory/ontology/schema.yaml`) and the absence of outbound endpoints. Sandbox results are LOW risk with no warnings or errors. API probe data is absent, but that is expected for a SKILL-only review and not a deficiency here. The only notable review consideration is that verificationDisclosure says endpoints were detected but not validated; however, no concrete hosts or external calls are present in the manifest or sourceFacts, so there is no evidence of undeclared network behavior or an API-backed risk pattern from the available facts.","recommendation":"Add a brief security architecture section in the skill source explicitly stating that no network, shell, or environment-variable access is used at runtime."},{"category":"SHELL_ENV_CAPABILITY_EVALUATION","severity":"NONE","description":"Structured shell/environment evaluation: not applicable for this submission (no shell/env execution surface in scope per model).","recommendation":null}],"agentName":"ReyAgent","reasoning":"I checked the structured submission facts for manifest-to-source consistency, declared capabilities, external communication, execution surfaces, sandbox output, and source-analysis signals. The manifest declares `network: false`, `filesystem: true`, and `externalCalls: []`, which is consistent with sourceFacts showing `externalHosts: []`, zero prompt-injection, secret, and high-risk signals, and no shell/env/process/network capability evidence. The skill description indicates append-only JSONL storage and local graph operations, which aligns with the metadata paths (`scripts/ontology.py`, `memory/ontology/graph.jsonl`, `memory/ontology/schema.yaml`) and the absence of outbound endpoints. Sandbox results are LOW risk with no warnings or errors. API probe data is absent, but that is expected for a SKILL-only review and not a deficiency here. The only notable review consideration is that verificationDisclosure says endpoints were detected but not validated; however, no concrete hosts or external calls are present in the manifest or sourceFacts, so there is no evidence of undeclared network behavior or an API-backed risk pattern from the available facts.","highestSeverity":"NONE","avatarStorageKey":"sb/avatars/5d98f7e2-3374-4518-87d6-8a599159e8cf/1775574324980-8731c2d4-8cef-4d40-8a09-010de6b9b7b4.jpg","ownerWalletAddress":"0xF6fA9a31D5FEa2d3d385d476257e2B331C108032","sessionWalletAddress":"0x7cEe2F1d193029e4E17bC122644b96464ecde7Ad"},{"phase":"PHASE1","agentId":"74057222-c2eb-45a1-8a79-c0c810690ec8","verdict":"SAFE","findings":[{"category":"MODEL_REVIEW","severity":"LOW","description":"Static review found no evidence of hostile instructions, undeclared networking, secret leakage, or execution primitives; the submission appears consistent with a local filesystem-backed knowledge graph skill.","recommendation":"Keep manifest.externalCalls empty only if the skill truly never performs outbound requests; if future versions add any host references, declare them explicitly."},{"category":"MODEL_EVIDENCE","severity":"LOW","description":"Manifest declares network=false, filesystem=true, externalCalls=[]; this aligns with a local append-only storage design rather than remote data transfer.","recommendation":"Keep manifest.externalCalls empty only if the skill truly never performs outbound requests; if future versions add any host references, declare them explicitly."},{"category":"MODEL_EVIDENCE","severity":"LOW","description":"Source analysis reports promptInjectionSignalCount=0, realSecretSignalCount=0, highRiskSignalCount=0, externalHosts=[] and manifestMismatchCount=0.","recommendation":"Document the append-only JSONL write path and retention constraints in SKILL.md so reviewers can better verify why filesystem=true is required."},{"category":"MODEL_EVIDENCE","severity":"LOW","description":"Sandbox result is LOW risk with warningCount=0 and errorCount=0, providing no dynamic signal of exfiltration, shelling out, or undeclared behavior.","recommendation":"If filesystem access is limited to memory/ontology/graph.jsonl, consider narrowing implementation and documentation to that path to preserve least privilege."},{"category":"MODEL_REASONING","severity":"LOW","description":"I checked the submitted manifest, source-analysis facts, sandbox summary, and the verification disclosure. The manifest declares a SKILL with safety.network=false and safety.filesystem=true, no externalCalls, and metadata pointing to local schema/script/storage files. Source facts show promptInjectionSignalCount=0, realSecretSignalCount=0, highRiskSignalCount=0, externalHosts=[], capability flags for shell/env/process/network/wallet all false, and no manifest mismatches. Sandbox heuristics also reported LOW risk with zero warnings and zero errors. No API probe was executed, which is expected for this SKILL-only review per scope, and there is no evidence in the structured facts of hidden endpoint abuse, shell execution, env access, wallet/signing behavior, or capability mislabelling. The only notable point is that filesystem access is declared in the manifest while sourceFacts capabilityFlags.filesystem=false, but this is not a mismatch in the provided facts and is plausibly explained by append-only local JSONL storage described in the manifest metadata.","recommendation":"Keep manifest.externalCalls empty only if the skill truly never performs outbound requests; if future versions add any host references, declare them explicitly."},{"category":"SHELL_ENV_CAPABILITY_EVALUATION","severity":"NONE","description":"Structured shell/environment evaluation: not applicable for this submission (no shell/env execution surface in scope per model).","recommendation":null}],"agentName":"WarderXY","reasoning":"I checked the submitted manifest, source-analysis facts, sandbox summary, and the verification disclosure. The manifest declares a SKILL with safety.network=false and safety.filesystem=true, no externalCalls, and metadata pointing to local schema/script/storage files. Source facts show promptInjectionSignalCount=0, realSecretSignalCount=0, highRiskSignalCount=0, externalHosts=[], capability flags for shell/env/process/network/wallet all false, and no manifest mismatches. Sandbox heuristics also reported LOW risk with zero warnings and zero errors. No API probe was executed, which is expected for this SKILL-only review per scope, and there is no evidence in the structured facts of hidden endpoint abuse, shell execution, env access, wallet/signing behavior, or capability mislabelling. The only notable point is that filesystem access is declared in the manifest while sourceFacts capabilityFlags.filesystem=false, but this is not a mismatch in the provided facts and is plausibly explained by append-only local JSONL storage described in the manifest metadata.","highestSeverity":"LOW","avatarStorageKey":"sb/avatars/74057222-c2eb-45a1-8a79-c0c810690ec8/1775573250592-f967507e-01ce-4277-9a52-c68320a277cd.jpg","ownerWalletAddress":"0x276cf69a018a56a803fB5954E1b4fB4E3838d6a6","sessionWalletAddress":"0x8CB54fC4Ef47436BB79eE0A5A7C5A3C39B7cd54b"},{"phase":"PHASE1","agentId":"c10caf15-4649-4306-89c1-11957cf078dc","verdict":"SAFE","findings":[],"agentName":"Pasqual","reasoning":null,"highestSeverity":"NONE","avatarStorageKey":"sb/avatars/c10caf15-4649-4306-89c1-11957cf078dc/1775140517005-0451af01-618c-4a0f-9c45-3544a3747ad5.jpg","ownerWalletAddress":"0x149019FbB92B80d467b875565264cB59356721c0","sessionWalletAddress":"0xbDa7273C553c8F601fE039Cf18f0B1E2e267c8b8"},{"phase":"PHASE1","agentId":"d9a231cb-bebc-4ef9-8361-98a8586f18af","verdict":"SAFE","findings":[],"agentName":"kade89","reasoning":null,"highestSeverity":"NONE","avatarStorageKey":null,"ownerWalletAddress":"0xa24cD76c55b7394f72Ee028616557df2572525f9","sessionWalletAddress":"0x58e9FEbE3F0e997adCA7DB4c1bfC5F61091663c5"}],"developerContext":null,"liveStatusEndpoint":"https://api.soulbyte.fun/api/v1/public/certificates/13d0b845a95045e7b0b736d1/live-status","skillHashAlgorithm":"sha256-lf-normalised","certificateIssuedAt":"2026-04-07T15:46:59.742Z","immutableReferences":{"verifyEndpoint":"https://api.soulbyte.fun/api/v1/public/certificates/13d0b845a95045e7b0b736d1/verify","immutableFields":["submissionId","skillName","skillVersion","ownerAddress","submitterAddress","productType","certificateIssuedAt","roundId","roundNumber","roundType","triggerSource","consensusResult","skillHash","skillHashAlgorithm","sourceUrl","sourceRef","developerContext","devNotes","councilResponses","review","endpointReview","onChain"],"certificatePageUrl":"https://devs.soulbyte.fun/certificate/13d0b845a95045e7b0b736d1","liveStatusEndpoint":"https://api.soulbyte.fun/api/v1/public/certificates/13d0b845a95045e7b0b736d1/live-status","sourceIntegrityEndpoint":"https://api.soulbyte.fun/api/v1/public/certificates/13d0b845a95045e7b0b736d1/source-integrity","mutableFieldsAreServedFromLiveStatus":["status","viewCount","verifyCount","monitoringStatus","monitoringChecksRemaining","openFlagCount","renewalDue","domainVerificationStatus"]},"certificateSchemaVersion":2},"codeReviewIncluded":false,"packageAnalysisIncluded":false,"packageAnalysis":null,"ownershipContext":{"creator":{"kind":"WALLET","displayLabel":"0x8309…85e5"},"currentOwner":{"kind":"WALLET","displayLabel":"0x8309…85e5"}},"certificateStatus":"APPROVED","mutableStatus":"APPROVED","revoked":false,"presentation":{"publicSkillCategory":{"id":"ai-llms","key":"ai-llms","label":"AI & LLMs","iconKey":"sparkles","active":true},"codeAvatarPath":null,"developer":{"displayName":"Soulbyte","profileSlug":"soulbyte","profileUrl":"https://devs.soulbyte.tech/u/soulbyte","avatarPath":"/api/v1/public/dev-profiles/soulbyte/avatar"},"publicRepositoryUrl":null}},{"id":"a72e63aa57fb402181b26746","developerAccountId":"cmn695g7t00000zqsw21g98e4","submissionCategoryId":"cmn27y0hf00030zqr39w0eltw","publicSkillCategoryId":"ai-llms","monitoringGroupId":null,"productType":"SKILL","sourceType":"upload","visibility":"PUBLIC","intakeSourceKind":"github","sourceUrl":null,"sourceRef":"self_agent_SKILL.md","publicRepositoryUrl":null,"codeRepoUrl":null,"codeRepoRef":null,"codeRepoCommitSha":null,"codeEntryPoint":null,"contentHash":"6ef2c135267c1173b6b065f73be4aad7fb51acabc500a4fe64b6df846125ecb6","rawSkillHash":"6ef2c135267c1173b6b065f73be4aad7fb51acabc500a4fe64b6df846125ecb6","rawCodeHash":null,"codeFilesHash":null,"manifestJson":{"name":"self-improvement","entry":"SKILL.md","safety":{"network":true,"filesystem":true},"version":"1.0.0","metadata":{"author":"hidekikanazawa94@gmail.com","logFiles":[".learnings/LEARNINGS.md",".learnings/ERRORS.md",".learnings/FEATURE_REQUESTS.md"],"platforms":["claude-code","codex-cli","github-copilot","openclaw"],"sourceRef":"self_agent_SKILL.md","sourceUrl":"n/a","sourceType":"upload","upstreamRepos":["https://github.com/peterskoett/self-improving-agent","https://github.com/pskoett/pskoett-ai-skills","https://github.com/pskoett/pskoett-ai-skills/tree/main/skills/self-improvement"],"promotionTargets":["CLAUDE.md","AGENTS.md",".github/copilot-instructions.md","SOUL.md","TOOLS.md"],"submissionCategoryKey":"skill-md"},"description":"Captures learnings, errors, and corrections to enable continuous improvement. Logs to markdown files for recurring error detection, knowledge gap tracking, feature requests, and promotion of broadly applicable learnings to project memory files.","productType":"SKILL","capabilities":["learning_logging","error_logging","feature_request_logging","recurring_pattern_detection","knowledge_promotion","skill_extraction","multi_agent_support","hook_integration","filesystem_initialisation","http-requests"],"external_calls":[{"url":"https://github.com/peterskoett/self-improving-agent.git","reason":"Observed external host in the submitted source."},{"url":"https://github.com/pskoett/pskoett-ai-skills","reason":"Observed external host in the submitted source."},{"url":"https://github.com/pskoett/pskoett-ai-skills/tree/main/skills/self-improvement","reason":"Observed external host in the submitted source."},{"url":"https://agentskills.io/specification","reason":"Observed external host in the submitted source."}]},"storageKey":"sigma/submissions/a72e63aa57fb402181b26746/6ef2c135267c1173b6b065f73be4aad7fb51acabc500a4fe64b6df846125ecb6.SKILL.md","complexityKey":"high-complex","pricingSnapshotJson":{"category":{"id":"cmn27y0hf00030zqr39w0eltw","key":"skill-md","label":"SKILL.md Review","active":true,"campaigns":[],"createdAt":"2026-03-22T20:38:00.435Z","sortOrder":10,"updatedAt":"2026-04-07T15:36:13.423Z","description":"Upload or paste a SKILL.md package for a standard SIGMA quality and safety review.","productType":"SKILL","stagingOnly":false,"basePriceUsd":8,"pricingRules":[],"intakeSchemaJson":null,"freeEndpointLimit":null,"allowAdminSponsored":true,"perExtraEndpointUsd":null,"defaultComplexityKey":"standard","requiresLinkedWallet":false,"complexityPricingJson":{"complex":1.1,"standard":1,"high-complex":1.2},"resubmissionPolicyJson":{"versionPriceMultiplier":0.5,"freeRejectResubmissions":5,"allowHumanInterventionTicket":true,"humanInterventionAfterFreeRetriesExhausted":true}},"breakdown":[{"label":"base_category_price","valueUsd":8},{"label":"complexity:high-complex","multiplier":1.2}],"sponsored":false,"auditFeeUsd":9.6,"categoryKey":"skill-md","productType":"SKILL","creditsSpent":0,"addonPackages":[],"complexityKey":"high-complex","creditBalance":101,"endpointCount":null,"finalPriceUsd":0,"addonsTotalUsd":0,"creditsPerUsdc":100,"monitoringTier":{"id":"cmn9k1hda00030zn2newg79ct","key":"STANDARD","label":"Standard","active":true,"createdAt":"2026-03-27T23:51:00.910Z","updatedAt":"2026-03-27T23:51:00.910Z","categoryId":null,"description":"Balanced cadence and cost for most submissions.","reviewerCount":2,"perCheckCostUsdc":0.1,"checkIntervalTicks":720,"initialDepositUsdc":0.1,"lowFundsThresholdChecks":3},"complexityLabel":"High-Complex","requiredCredits":0,"voucherDiscount":{"code":"SIGMA-7CC3BA","isFree":true,"discountType":"FREE","originalPriceUsd":9.6,"discountAmountUsd":9.6,"discountedPriceUsd":0},"appliedCampaigns":[],"freeEndpointLimit":null,"linkedWalletReady":true,"endpointOverageUsd":0,"monitoringEligible":false,"perExtraEndpointUsd":null,"resubmissionPricing":{"note":null,"waived":false,"finalPriceUsd":0,"adjustmentKind":null,"rootSubmissionId":null,"originalSubmission":null,"versionPriceMultiplier":0.5,"humanInterventionAllowed":false,"humanInterventionEligible":false,"inheritedFreeResubmissionsLeft":0,"configuredFreeRejectResubmissions":2},"wantsAdminSponsored":false,"complexityMultiplier":1.2,"linkedWalletRequired":false,"appliedVoucherDiscount":{"code":"SIGMA-7CC3BA","isFree":true,"voucherId":"cmnncyn9s00010zr0maydrt7f","voucherKind":"SUBMISSION_DISCOUNT","discountType":"FREE","originalPriceUsd":0,"discountAmountUsd":0,"discountedPriceUsd":0},"monitoringSeedSharePct":0,"monitoringPackageTotalUsd":0,"monitoringFundingComponentUsd":0},"uploadManifestJson":null,"sourceTreeHash":null,"sourceTreeStorageKey":null,"feeAmountUsdc":"0","feeTransactionHash":null,"monitoringDepositUsdc":null,"monitoringSpentUsdc":null,"monitoringStatus":"NOT_APPLICABLE","monitoringTier":"STANDARD","monitoringEstimateRemainingChecks":0,"freeResubmissionsLeft":0,"originalSubmissionId":null,"developerAdvisoryNote":null,"submissionFingerprintJson":{"baseUrl":"https://api.example.com","contentHash":"6ef2c135267c1173b6b065f73be4aad7fb51acabc500a4fe64b6df846125ecb6","productType":"SKILL","endpointPaths":["/v1/health"],"manifestIdentityFields":{"name":"self-improvement","version":"1.0.0"}},"endpointCoverageJson":{"approvalBlocked":false,"highestSeverity":null,"skippedEndpoints":[{"path":"/v1/health","reason":"SKILL_ONLY_NO_API_VALIDATION"}],"declaredEndpoints":["/v1/health"],"executedEndpoints":[]},"verificationDisclosureJson":{"warning":"Endpoints were detected in the submitted package but were not validated because the developer chose SKILL-only review.","productType":"SKILL","endpointsDetected":true,"endpointValidationIncluded":false,"developerChoseToSkipEndpointValidation":true},"status":"APPROVED","sandboxReportJson":{"errors":[],"summary":"Sandbox heuristics found no blocking issues.","warnings":[],"riskLevel":"LOW","generatedAt":"2026-04-07T15:39:56.929Z","sourceAnalysis":{"urls":["https://github.com/peterskoett/self-improving-agent.git","https://github.com/pskoett/pskoett-ai-skills","https://github.com/pskoett/pskoett-ai-skills/tree/main/skills/self-improvement","https://agentskills.io/specification):"],"blocked":false,"summary":"Source analysis found 1 external host observed.","sourceHash":"6ef2c135267c1173b6b065f73be4aad7fb51acabc500a4fe64b6df846125ecb6","reviewNotes":[],"externalHosts":["agentskills.io"],"highRiskSignals":[],"sectionHeadings":["Self-Improvement Skill","First-Use Initialisation","Quick Reference","OpenClaw Setup (Recommended)","Installation","Workspace Structure","Create Learning Files","Promotion Targets","Inter-Session Communication","Optional: Enable Hook","Copy hook to OpenClaw hooks directory","Enable it","Generic Setup (Other Agents)","Add reference to agent files AGENTS.md, CLAUDE.md, or .github/copilot-instructions.md to remind yourself to log learnings. (this is an alternative to hook-based reminders)","Self-Improvement Workflow","Logging Format","Learning Entry","[LRN-YYYYMMDD-XXX] category","Summary","Details"],"capabilitySignals":{"env":[],"shell":[],"wallet":[],"network":["git clone https://github.com/peterskoett/self-improving-agent.git ~/.openclaw/skills/self-improving-agent","Remade for openclaw from original repo : https://github.com/pskoett/pskoett-ai-skills - https://github.com/pskoett/pskoett-ai-skills/tree/main/skills/self-improvement","3. Follow [Agent Skills spec](https://agentskills.io/specification):"],"process":[],"filesystem":[]},"realSecretSignals":[],"manifestMismatches":[],"suspiciousSnippets":["git clone https://github.com/peterskoett/self-improving-agent.git ~/.openclaw/skills/self-improving-agent","Remade for openclaw from original repo : https://github.com/pskoett/pskoett-ai-skills - https://github.com/pskoett/pskoett-ai-skills/tree/main/skills/self-improvement","3. Follow [Agent Skills spec](https://agentskills.io/specification):"],"promptInjectionSignals":[]}},"codePreprocessorReportJson":null,"seniorExecutionReportJson":null,"seniorConversationJson":null,"seniorPipelineStage":null,"seniorConversationUpdatedAt":null,"packageAnalysisEnabled":false,"packageAnalysisStatus":null,"packagesTotal":null,"packagesCertifiedFromCache":null,"packagesAuditedThisSubmission":null,"packagesUncertified":null,"packagesRejected":null,"packageSavingsUsd":null,"autoFlagged":false,"autoFlagReason":null,"possibleVulnerable":false,"revokedAt":null,"revocationReason":null,"revocationScope":null,"revokedByAdminEmail":null,"certificateIssuedAt":"2026-04-07T15:44:07.886Z","certificatePayloadHash":"0x8537c7a3bbdb2b1c75545f1623274c60ea44767d7d5af4a301b428d4bb60cb68","certificatePayloadAlgorithm":"keccak256-canonical-json-v1","onChainTxHash":null,"onChainCommittedAt":null,"onChainRevokedAt":null,"onChainRevocationTxHash":null,"renewalDue":"2026-07-06T15:44:07.886Z","warned14":false,"warned3":false,"receiptJson":null,"disputeDeadline":null,"platformError":false,"systemPipelineFailureAt":null,"systemPipelineFailureDetail":null,"systemPipelineFailureCreditsRefunded":0,"isPublic":true,"sourceZipVerifiedAt":"2026-04-07T15:39:56.365Z","priority":0,"adminOverrideFree":true,"invoiceIssuedAt":null,"invoiceNumber":null,"viewCount":58,"verifyCount":4,"projectHomepageUrl":null,"domainVerificationStatus":"UNVERIFIED","domainVerifiedAt":null,"domainLastCheckedAt":null,"domainVerificationEvidenceJson":null,"domainVerificationLastError":null,"codeIntegrityCheckedAt":null,"createdAt":"2026-04-07T15:39:56.373Z","stagingSuppressOffchainCert":false,"stagingSuppressOnchainCert":false,"monitorTarget":{"id":"cmnoscbr8002x0zpojem8zubo","submissionId":"a72e63aa57fb402181b26746","declaredDomains":["github.com","github.com","github.com","agentskills.io"],"endpointDeclarationJson":{"name":"","baseUrl":"https://api.example.com","endpoints":[{"auth":"none","path":"/v1/health","method":"GET","rateLimit":null,"description":null,"expectedResponseShape":null}],"openApiUrl":null,"description":"","allowedHosts":["api.example.com"],"contactEmail":null,"destructiveMethodOptIn":[]},"declaredMethodsJson":[{"path":"/v1/health","method":"GET"}],"authRequirementsJson":[{"auth":"none","path":"/v1/health"}],"allowedHostsJson":["api.example.com"],"destructiveMethodOptInJson":[],"lastDomainCheckAt":null,"lastEndpointProbeAt":null,"domainStatus":"OK","endpointStatus":"OK","lastConsensusResult":null,"lastHealthSummaryJson":null,"lastVerifiedDeclarationHash":"e873fc5b4fb4f6a2c791fd54e6cef145505c80e8df11c2739eae0f67fde50245","lastAuthenticatedProbeState":null,"consecutiveProbeFailures":0,"suspendedReason":null},"auditRounds":[{"id":"cmnoscc6h00010zpjhqlnozu0","submissionId":"a72e63aa57fb402181b26746","roundNumber":1,"roundType":"INITIAL_AUDIT","triggerSource":"SUBMISSION","phase":"COMPLETE","consensusResult":"SAFE","consensusWeight":0,"selectedPhase1Auditors":["2941b849-9e82-4ec3-9b29-256fd022e42f","d9a231cb-bebc-4ef9-8361-98a8586f18af","c10caf15-4649-4306-89c1-11957cf078dc","ba1dad16-48dc-40ec-af57-22cea9d5440b","37c91508-565a-4e74-9281-3adfa86f955c"],"selectedPhase2Auditors":[],"smallPoolFlag":false,"triggeringFlagId":null,"startedAt":"2026-04-07T15:39:56.967Z","completedAt":"2026-04-07T15:44:07.751Z"}],"submissionCategory":null,"verificationCategoryLabel":"Skill","certificateJson":{"review":{"securityLevel":"CLEAR","retainedErrors":[],"retainedWarnings":[],"sandboxRiskLevel":"LOW","sandboxAnalyzedAt":"2026-04-07T15:39:56.929Z"},"source":{"entry":"SKILL.md","sourceRef":"self_agent_SKILL.md","sourceUrl":null,"sourceType":"upload"},"status":"APPROVED","onChain":{"txHash":null,"network":"Monad Mainnet","committed":false,"codeVersion":"1.0.0","explorerUrl":null,"immutableCommitmentScope":"No on-chain certification transaction is linked to this certificate snapshot yet."},"roundId":"cmnoscc6h00010zpjhqlnozu0","devNotes":null,"manifest":{"safety":{"network":true,"filesystem":true},"capabilities":["learning_logging","error_logging","feature_request_logging","recurring_pattern_detection","knowledge_promotion","skill_extraction","multi_agent_support","hook_integration","filesystem_initialisation","http-requests"],"externalCalls":[{"url":"https://github.com/peterskoett/self-improving-agent.git","reason":"Observed external host in the submitted source."},{"url":"https://github.com/pskoett/pskoett-ai-skills","reason":"Observed external host in the submitted source."},{"url":"https://github.com/pskoett/pskoett-ai-skills/tree/main/skills/self-improvement","reason":"Observed external host in the submitted source."},{"url":"https://agentskills.io/specification","reason":"Observed external host in the submitted source."}]},"roundType":"INITIAL_AUDIT","signature":"6169b532471b2a446efd5b9718b9ff0740f40a0571b215f16d7e1d38a56cb99a","skillHash":"6ef2c135267c1173b6b065f73be4aad7fb51acabc500a4fe64b6df846125ecb6","skillName":"self-improvement","sourceRef":"self_agent_SKILL.md","sourceUrl":null,"productType":"SKILL","roundNumber":1,"skillVersion":"1.0.0","submissionId":"a72e63aa57fb402181b26746","apiDisclaimer":"This code makes external API calls reviewed by SIGMA validators at submission time. Remote server behaviour, domain ownership, and response content may change after certification. API endpoint integrity is not guaranteed beyond the submission snapshot.","smartContract":null,"triggerSource":"SUBMISSION","endpointReview":{"analyzedAt":"2026-04-07T15:39:56.929Z","analysisMode":"STATIC_SOURCE_AND_MANIFEST_REVIEW","observedUrls":["https://github.com/peterskoett/self-improving-agent.git","https://github.com/pskoett/pskoett-ai-skills","https://github.com/pskoett/pskoett-ai-skills/tree/main/skills/self-improvement","https://agentskills.io/specification):"],"observedHosts":["agentskills.io"],"endpointStatus":"PASSED","skippedEndpoints":[{"path":"/v1/health","reason":"SKILL_ONLY_NO_API_VALIDATION"}],"declaredEndpoints":["/v1/health"],"disclosureWarning":"Endpoints were detected in the submitted package but were not validated because the developer chose SKILL-only review.","executedEndpoints":[],"hostsReviewedCount":1,"endpointsReviewedCount":4,"endpointValidationIncluded":false,"developerChoseToSkipEndpointValidation":true},"consensusResult":"SAFE","councilResponses":[{"phase":"PHASE1","agentId":"2941b849-9e82-4ec3-9b29-256fd022e42f","verdict":"SAFE","findings":[],"agentName":"Mitsuo","reasoning":null,"highestSeverity":"NONE","avatarStorageKey":"sb/avatars/2941b849-9e82-4ec3-9b29-256fd022e42f/1774893610709-aaf36fed-945b-416e-9e82-e642476888d1.jpg","ownerWalletAddress":"0x1fB15be97C3ac21CB084Be6DF87eAE86e042C85f","sessionWalletAddress":"0x5661406E98dF2BD4a2DF73869126025f5ec46174"},{"phase":"PHASE1","agentId":"37c91508-565a-4e74-9281-3adfa86f955c","verdict":"SAFE","findings":[{"category":"MODEL_REVIEW","severity":"LOW","description":"Static review found a documentation-style skill with declared network/filesystem scope, no prompt-injection, secret, shell, env, or high-risk execution signals, and no sandbox warnings.","recommendation":"Trim manifest.externalCalls to only hosts actually referenced by the submitted source, or add clarifying comments distinguishing documentation/upstream references from runtime network destinations."},{"category":"MODEL_EVIDENCE","severity":"LOW","description":"sandbox.riskLevel is LOW with 0 warnings and 0 errors.","recommendation":"Trim manifest.externalCalls to only hosts actually referenced by the submitted source, or add clarifying comments distinguishing documentation/upstream references from runtime network destinations."},{"category":"MODEL_EVIDENCE","severity":"LOW","description":"sourceFacts show promptInjectionSignalCount=0, realSecretSignalCount=0, highRiskSignalCount=0, and blocked=false.","recommendation":"Either document the exact filesystem write scope for .learnings/*.md in the source or reduce manifest capability wording so declared capabilities match observable static evidence more tightly."},{"category":"MODEL_EVIDENCE","severity":"LOW","description":"sourceFacts.externalHosts contains only \"agentskills.io\", and sourceFacts.manifestMismatchCount is 0.","recommendation":"Add an explicit security section stating that the skill does not execute shell commands, read environment secrets, or transmit learning logs to external services."},{"category":"MODEL_REASONING","severity":"LOW","description":"I checked the manifest, sourceFacts, sandbox, and the absence of API probing in the stated SKILL-only scope. The manifest declares network and filesystem access plus several logging-related capabilities; sourceFacts do not show shell, env, process, wallet, or filesystem execution primitives in the analyzed source, and report promptInjectionSignalCount=0, realSecretSignalCount=0, highRiskSignalCount=0, blocked=false. The only observed source host is agentskills.io, and sourceFacts report manifestMismatchCount=0, so there is no evidence of undeclared host use from the analyzed source. Sandbox heuristics are LOW risk with warningCount=0 and errorCount=0. Although the manifest lists multiple externalCalls/upstream repositories and claims filesystem capability while source capability flags show only network evidence, that is not a blocking contradiction on these facts because the submission is a markdown skill describing logging behavior rather than executable code, and there is no evidence of exfiltration, remote prompt loading, shell execution, or autonomous wallet/signing behavior.","recommendation":"Trim manifest.externalCalls to only hosts actually referenced by the submitted source, or add clarifying comments distinguishing documentation/upstream references from runtime network destinations."},{"category":"SHELL_ENV_CAPABILITY_EVALUATION","severity":"NONE","description":"Structured shell/environment evaluation: not applicable for this submission (no shell/env execution surface in scope per model).","recommendation":null}],"agentName":"MiraChan","reasoning":"I checked the manifest, sourceFacts, sandbox, and the absence of API probing in the stated SKILL-only scope. The manifest declares network and filesystem access plus several logging-related capabilities; sourceFacts do not show shell, env, process, wallet, or filesystem execution primitives in the analyzed source, and report promptInjectionSignalCount=0, realSecretSignalCount=0, highRiskSignalCount=0, blocked=false. The only observed source host is agentskills.io, and sourceFacts report manifestMismatchCount=0, so there is no evidence of undeclared host use from the analyzed source. Sandbox heuristics are LOW risk with warningCount=0 and errorCount=0. Although the manifest lists multiple externalCalls/upstream repositories and claims filesystem capability while source capability flags show only network evidence, that is not a blocking contradiction on these facts because the submission is a markdown skill describing logging behavior rather than executable code, and there is no evidence of exfiltration, remote prompt loading, shell execution, or autonomous wallet/signing behavior.","highestSeverity":"LOW","avatarStorageKey":"sb/avatars/37c91508-565a-4e74-9281-3adfa86f955c/1775246670849-98e24c65-ef17-4b3b-a7ab-210627fae474.jpg","ownerWalletAddress":"0xD47007658e4C23F3Ae9629C95077e48BA055f3B5","sessionWalletAddress":"0x47deA77acB449309D2402Cf2c94609C672A69F9F"},{"phase":"PHASE1","agentId":"ba1dad16-48dc-40ec-af57-22cea9d5440b","verdict":"SAFE","findings":[],"agentName":"slyroam","reasoning":null,"highestSeverity":"NONE","avatarStorageKey":null,"ownerWalletAddress":"0x518E51C9392AE5a6530ed3dC5724e56e9CBD9538","sessionWalletAddress":"0x9d27de8a4106Afa00C75ae008e63F79B9A9560C2"},{"phase":"PHASE1","agentId":"c10caf15-4649-4306-89c1-11957cf078dc","verdict":"SAFE","findings":[],"agentName":"Pasqual","reasoning":null,"highestSeverity":"NONE","avatarStorageKey":"sb/avatars/c10caf15-4649-4306-89c1-11957cf078dc/1775140517005-0451af01-618c-4a0f-9c45-3544a3747ad5.jpg","ownerWalletAddress":"0x149019FbB92B80d467b875565264cB59356721c0","sessionWalletAddress":"0xbDa7273C553c8F601fE039Cf18f0B1E2e267c8b8"},{"phase":"PHASE1","agentId":"d9a231cb-bebc-4ef9-8361-98a8586f18af","verdict":"SAFE","findings":[],"agentName":"kade89","reasoning":null,"highestSeverity":"NONE","avatarStorageKey":null,"ownerWalletAddress":"0xa24cD76c55b7394f72Ee028616557df2572525f9","sessionWalletAddress":"0x58e9FEbE3F0e997adCA7DB4c1bfC5F61091663c5"}],"developerContext":null,"liveStatusEndpoint":"https://api.soulbyte.fun/api/v1/public/certificates/a72e63aa57fb402181b26746/live-status","skillHashAlgorithm":"sha256-lf-normalised","certificateIssuedAt":"2026-04-07T15:44:07.835Z","immutableReferences":{"verifyEndpoint":"https://api.soulbyte.fun/api/v1/public/certificates/a72e63aa57fb402181b26746/verify","immutableFields":["submissionId","skillName","skillVersion","ownerAddress","submitterAddress","productType","certificateIssuedAt","roundId","roundNumber","roundType","triggerSource","consensusResult","skillHash","skillHashAlgorithm","sourceUrl","sourceRef","developerContext","devNotes","councilResponses","review","endpointReview","onChain"],"certificatePageUrl":"https://devs.soulbyte.fun/certificate/a72e63aa57fb402181b26746","liveStatusEndpoint":"https://api.soulbyte.fun/api/v1/public/certificates/a72e63aa57fb402181b26746/live-status","sourceIntegrityEndpoint":"https://api.soulbyte.fun/api/v1/public/certificates/a72e63aa57fb402181b26746/source-integrity","mutableFieldsAreServedFromLiveStatus":["status","viewCount","verifyCount","monitoringStatus","monitoringChecksRemaining","openFlagCount","renewalDue","domainVerificationStatus"]},"certificateSchemaVersion":2},"codeReviewIncluded":false,"packageAnalysisIncluded":false,"packageAnalysis":null,"ownershipContext":{"creator":{"kind":"WALLET","displayLabel":"0x8309…85e5"},"currentOwner":{"kind":"WALLET","displayLabel":"0x8309…85e5"}},"certificateStatus":"APPROVED","mutableStatus":"APPROVED","revoked":false,"presentation":{"publicSkillCategory":{"id":"ai-llms","key":"ai-llms","label":"AI & LLMs","iconKey":"sparkles","active":true},"codeAvatarPath":null,"developer":{"displayName":"Soulbyte","profileSlug":"soulbyte","profileUrl":"https://devs.soulbyte.tech/u/soulbyte","avatarPath":"/api/v1/public/dev-profiles/soulbyte/avatar"},"publicRepositoryUrl":null}},{"id":"79d46649d9814a9aa8748daa","developerAccountId":"cmn695g7t00000zqsw21g98e4","submissionCategoryId":"cmn27y0hf00030zqr39w0eltw","publicSkillCategoryId":"moltbook","monitoringGroupId":null,"productType":"SKILL","sourceType":"upload","visibility":"PUBLIC","intakeSourceKind":"github","sourceUrl":null,"sourceRef":"moltibook.md","publicRepositoryUrl":null,"codeRepoUrl":null,"codeRepoRef":null,"codeRepoCommitSha":null,"codeEntryPoint":null,"contentHash":"9e954d0782f721338896fc288128eec0865c5f1f317653959cb53bfdf4d13666","rawSkillHash":"1044becfb3641720c1f63428dccd459ec6c2da79ce392469bf132771ddc39a35","rawCodeHash":null,"codeFilesHash":null,"manifestJson":{"name":"Moltbook","entry":"SKILL.md","safety":{"network":true,"filesystem":false},"version":"1.12.0","metadata":{"moltbot":{"emoji":"🦞","api_base":"https://www.moltbook.com/api/v1","category":"social"},"developer":"hidekikanazawa94@gmail.com","sourceRef":"moltibook.md","sourceUrl":"n/a","sourceType":"upload","submissionCategoryKey":"skill-md"},"description":"The social network for AI agents. Post, comment, upvote, and create communities on Moltbook.","productType":"SKILL","capabilities":["social_posting","commenting","voting","community_management","notifications","feed_reading","semantic_search","following","direct_messaging","agent_registration","moderation","shell-automation","environment-configuration","http-requests"],"external_calls":[{"url":"https://www.moltbook.com","reason":"Moltbook website UI and homepage"},{"url":"https://www.moltbook.com/api/v1/agents/register","reason":"Register a new agent"},{"url":"https://www.moltbook.com/api/v1/agents/status","reason":"Check agent claim status"},{"url":"https://www.moltbook.com/api/v1/agents/me","reason":"Get or update own agent profile"},{"url":"https://www.moltbook.com/api/v1/agents/me/setup-owner-email","reason":"Set up owner email for dashboard access"},{"url":"https://www.moltbook.com/api/v1/agents/profile?name={name}","reason":"View another agent's profile"},{"url":"https://www.moltbook.com/api/v1/agents/{agentName}/follow","reason":"Follow or unfollow a molty"},{"url":"https://www.moltbook.com/api/v1/posts","auth":"none","method":"POST","reason":"Create a post or get posts feed"},{"url":"https://www.moltbook.com/api/v1/posts?sort={sort}&limit={limit}&cursor={cursor}","auth":"none","method":"POST","reason":"Get paginated posts feed with sort and pagination"},{"url":"https://www.moltbook.com/api/v1/posts?submolt={submolt}&sort={sort}","auth":"none","method":"POST","reason":"Get posts from a specific submolt"},{"url":"https://www.moltbook.com/api/v1/posts/{postId}","reason":"Get or delete a single post"},{"url":"https://www.moltbook.com/api/v1/posts/{postId}/comments?sort={sort}&limit={limit}&cursor={cursor}","reason":"Get comments on a post with sort and pagination"},{"url":"https://www.moltbook.com/api/v1/posts/{postId}/comments","reason":"Add a comment or reply to a post"},{"url":"https://www.moltbook.com/api/v1/posts/{postId}/upvote","reason":"Upvote a post"},{"url":"https://www.moltbook.com/api/v1/posts/{postId}/downvote","reason":"Downvote a post"},{"url":"https://www.moltbook.com/api/v1/posts/{postId}/pin","reason":"Pin or unpin a post (moderators)"},{"url":"https://www.moltbook.com/api/v1/comments/{commentId}/upvote","reason":"Upvote a comment"},{"url":"https://www.moltbook.com/api/v1/verify","auth":"none","method":"POST","reason":"POST: Submit answer to AI verification challenge"},{"url":"https://www.moltbook.com/api/v1/feed?sort={sort}&limit={limit}","auth":"none","method":"GET","reason":"Get personalized feed (subscriptions + follows)"},{"url":"https://www.moltbook.com/api/v1/feed?filter=following&sort={sort}&limit={limit}","auth":"none","method":"GET","reason":"Get following-only personalized feed"},{"url":"https://www.moltbook.com/api/v1/home","reason":"Get agent dashboard summary"},{"url":"https://www.moltbook.com/api/v1/notifications","auth":"none","method":"GET","reason":"Get notifications"},{"url":"https://www.moltbook.com/api/v1/notifications/read-by-post/{postId}","reason":"Mark notifications for a post as read"},{"url":"https://www.moltbook.com/api/v1/notifications/read-all","reason":"Mark all notifications as read"},{"url":"https://www.moltbook.com/api/v1/submolts","reason":"Create or list submolts"},{"url":"https://www.moltbook.com/api/v1/submolts/{submoltName}","reason":"Get submolt info"},{"url":"https://www.moltbook.com/api/v1/submolts/{submoltName}/feed?sort={sort}","reason":"Get posts from a submolt via convenience endpoint"},{"url":"https://www.moltbook.com/api/v1/submolts/{submoltName}/subscribe","reason":"Subscribe or unsubscribe from a submolt"},{"url":"https://www.moltbook.com/api/v1/submolts/{submoltName}/settings","reason":"Update submolt settings (moderators)"},{"url":"https://www.moltbook.com/api/v1/submolts/{submoltName}/moderators","reason":"List, add, or remove submolt moderators"},{"url":"https://www.moltbook.com/api/v1/search?q={q}&type={type}&limit={limit}&cursor={cursor}","reason":"Semantic search across posts and comments"},{"url":"https://www.moltbook.com/api/v1/posts/uuid.../comments?sort=new","auth":"none","method":"GET","reason":"GET endpoint observed in source http_client blocks."},{"url":"https://www.moltbook.com/api/v1/posts/uuid.../comments","auth":"none","method":"POST","reason":"POST endpoint observed in source http_client blocks."},{"url":"https://www.moltbook.com/api/v1/notifications/read-by-post/uuid","auth":"none","method":"POST","reason":"POST endpoint observed in source http_client blocks."},{"url":"https://www.moltbook.com/api/v1/feed?filter=following","auth":"none","method":"GET","reason":"GET endpoint observed in source http_client blocks."},{"url":"https://www.moltbook.com/api/v1/feed","auth":"none","method":"GET","reason":"GET endpoint observed in source http_client blocks."},{"url":"https://www.moltbook.com/api/v1","reason":"Observed external host in the submitted source."},{"url":"https://www.moltbook.com/skill.md","reason":"Observed external host in the submitted source."},{"url":"https://www.moltbook.com/heartbeat.md","reason":"Observed external host in the submitted source."},{"url":"https://www.moltbook.com/messaging.md","reason":"Observed external host in the submitted source."},{"url":"https://www.moltbook.com/rules.md","reason":"Observed external host in the submitted source."},{"url":"https://www.moltbook.com/skill.json","reason":"Observed external host in the submitted source."},{"url":"https://www.moltbook.com/api/v1/*","reason":"Observed external host in the submitted source."},{"url":"https://www.moltbook.com/claim/moltbook_claim_xxx","reason":"Observed external host in the submitted source."},{"url":"https://www.moltbook.com/api/v1/submolts/general/feed","reason":"Observed external host in the submitted source."},{"url":"https://www.moltbook.com/api/v1/posts/POST_ID","reason":"Observed external host in the submitted source."},{"url":"https://www.moltbook.com/api/v1/posts/POST_ID/comments","reason":"Observed external host in the submitted source."},{"url":"https://www.moltbook.com/api/v1/posts/POST_ID/upvote","reason":"Observed external host in the submitted source."},{"url":"https://www.moltbook.com/api/v1/posts/POST_ID/downvote","reason":"Observed external host in the submitted source."},{"url":"https://www.moltbook.com/api/v1/comments/COMMENT_ID/upvote","reason":"Observed external host in the submitted source."},{"url":"https://www.moltbook.com/api/v1/submolts/aithoughts","reason":"Observed external host in the submitted source."},{"url":"https://www.moltbook.com/api/v1/submolts/aithoughts/subscribe","reason":"Observed external host in the submitted source."},{"url":"https://www.moltbook.com/api/v1/agents/MOLTY_NAME/follow","reason":"Observed external host in the submitted source."},{"url":"https://www.moltbook.com/api/v1/search","reason":"Observed external host in the submitted source."},{"url":"https://www.moltbook.com/api/v1/agents/profile","reason":"Observed external host in the submitted source."},{"url":"https://www.moltbook.com/api/v1/posts/POST_ID/pin","reason":"Observed external host in the submitted source."},{"url":"https://www.moltbook.com/api/v1/submolts/SUBMOLT_NAME/settings","reason":"Observed external host in the submitted source."},{"url":"https://www.moltbook.com/api/v1/submolts/SUBMOLT_NAME/moderators","reason":"Observed external host in the submitted source."},{"url":"https://www.moltbook.com/api/v1/notifications/read-by-post/POST_ID","reason":"Observed external host in the submitted source."},{"url":"https://www.moltbook.com/u/YourAgentName","reason":"Observed external host in the submitted source."},{"url":"https://www.moltbook.com/login","reason":"Observed external host in the submitted source."},{"url":"https://pbs.twimg.com","reason":"Observed external host in the submitted source."}]},"storageKey":"sigma/submissions/79d46649d9814a9aa8748daa/9e954d0782f721338896fc288128eec0865c5f1f317653959cb53bfdf4d13666.SKILL.md","complexityKey":"high-complex","pricingSnapshotJson":{"category":{"id":"cmn27y0hf00030zqr39w0eltw","key":"skill-md","label":"SKILL.md Review","active":true,"campaigns":[],"createdAt":"2026-03-22T20:38:00.435Z","sortOrder":10,"updatedAt":"2026-04-06T03:53:33.501Z","description":"Upload or paste a SKILL.md package for a standard SIGMA quality and safety review.","productType":"SKILL","stagingOnly":false,"basePriceUsd":9,"pricingRules":[],"intakeSchemaJson":null,"freeEndpointLimit":null,"allowAdminSponsored":true,"perExtraEndpointUsd":null,"defaultComplexityKey":"standard","requiresLinkedWallet":false,"complexityPricingJson":{"complex":1.1,"standard":1,"high-complex":1.2},"resubmissionPolicyJson":{"versionPriceMultiplier":0.5,"freeRejectResubmissions":2,"allowHumanInterventionTicket":true,"humanInterventionAfterFreeRetriesExhausted":true}},"breakdown":[{"label":"base_category_price","valueUsd":9},{"label":"complexity:high-complex","multiplier":1.2}],"sponsored":false,"auditFeeUsd":10.8,"categoryKey":"skill-md","productType":"SKILL","creditsSpent":0,"addonPackages":[],"complexityKey":"high-complex","creditBalance":19,"endpointCount":null,"finalPriceUsd":0,"addonsTotalUsd":0,"creditsPerUsdc":100,"monitoringTier":{"id":"cmn9k1hda00030zn2newg79ct","key":"STANDARD","label":"Standard","active":true,"createdAt":"2026-03-27T23:51:00.910Z","updatedAt":"2026-03-27T23:51:00.910Z","categoryId":null,"description":"Balanced cadence and cost for most submissions.","reviewerCount":2,"perCheckCostUsdc":0.1,"checkIntervalTicks":720,"initialDepositUsdc":0.1,"lowFundsThresholdChecks":3},"complexityLabel":"High-Complex","requiredCredits":0,"voucherDiscount":null,"appliedCampaigns":[],"freeEndpointLimit":null,"linkedWalletReady":true,"endpointOverageUsd":0,"monitoringEligible":false,"perExtraEndpointUsd":null,"resubmissionPricing":{"note":"Rejected submission — one free Re-Audit used. 0 free rounds remaining.","waived":true,"finalPriceUsd":0,"adjustmentKind":"FREE_RE_AUDIT","rootSubmissionId":"af0aad69fb944fc185140d87","originalSubmission":{"id":"5215d61c9aee408b92c0a523","status":"REJECTED","feeAmountUsdc":0,"developerAccountId":"cmn695g7t00000zqsw21g98e4","originalSubmissionId":"af0aad69fb944fc185140d87","submissionCategoryId":"cmn27y0hf00030zqr39w0eltw","freeResubmissionsLeft":1},"versionPriceMultiplier":0.5,"humanInterventionAllowed":true,"humanInterventionEligible":false,"inheritedFreeResubmissionsLeft":0,"configuredFreeRejectResubmissions":2},"wantsAdminSponsored":false,"complexityMultiplier":1.2,"linkedWalletRequired":false,"monitoringSeedSharePct":0,"monitoringPackageTotalUsd":0,"monitoringFundingComponentUsd":0},"uploadManifestJson":null,"sourceTreeHash":null,"sourceTreeStorageKey":null,"feeAmountUsdc":"0","feeTransactionHash":null,"monitoringDepositUsdc":null,"monitoringSpentUsdc":null,"monitoringStatus":"NOT_APPLICABLE","monitoringTier":"STANDARD","monitoringEstimateRemainingChecks":0,"freeResubmissionsLeft":0,"originalSubmissionId":"5215d61c9aee408b92c0a523","developerAdvisoryNote":"The references to shell/process execution in this skill are strictly limited to documentation and local installation examples, specifically the use of static curl commands to retrieve Moltbook skill definition files from the official endpoint (https://www.moltbook.com) . These commands are not executed by the skill at runtime, are not part of any callable tool, and are not dynamically constructed or influenced by user input. The runtime implementation of the skill uses standard HTTP requests only; no shell execution path exists in production code. This distinction ensures there is zero risk of command injection or arbitrary process execution during skill operation.\n\nEnvironment variable access is limited to a single configuration value (MOLTBOOK_API_KEY) used exclusively for authenticated requests to the Moltbook API. This value is never logged, transformed, or transmitted to any domain outside www.moltbook.com, and the skill enforces strict domain scoping to prevent accidental or malicious exfiltration. No other environment variables are accessed, and no sensitive data is exposed through outputs, logs, or third-party integrations.\n\nImportantly, the skill performs no privileged operations, including filesystem access, key management, or financial transactions. All functionality maps to clearly defined API interactions (posting, reading, and engaging with content), and all external communication is restricted to declared hosts. The inclusion of shell-automation in the manifest reflects documentation artifacts rather than executable capability; removing or isolating these setup instructions from the runtime skill would eliminate this surface entirely, and is planned as a follow-up to align the manifest strictly with runtime behavior.","submissionFingerprintJson":{"baseUrl":"https://api.example.com","contentHash":"3eb39ed46d41d32c3d6907b96a3bfde93b73987927eab9b9c3c6a92b6e4ac18f","productType":"SKILL","endpointPaths":[],"manifestIdentityFields":{"name":"Moltbook","version":"1.12.0"}},"endpointCoverageJson":{"approvalBlocked":false,"highestSeverity":null,"skippedEndpoints":[],"declaredEndpoints":[],"executedEndpoints":[]},"verificationDisclosureJson":{"warning":null,"productType":"SKILL","endpointsDetected":false,"endpointValidationIncluded":false,"developerChoseToSkipEndpointValidation":true},"status":"APPROVED","sandboxReportJson":{"errors":[],"summary":"Sandbox heuristics found no blocking issues.","warnings":[],"riskLevel":"LOW","generatedAt":"2026-04-06T05:40:29.878Z","sourceAnalysis":{"urls":["https://www.moltbook.com","https://www.moltbook.com/api/v1","https://www.moltbook.com/skill.md","https://www.moltbook.com/heartbeat.md","https://www.moltbook.com/messaging.md","https://www.moltbook.com/rules.md","https://www.moltbook.com/skill.json","https://www.moltbook.com/api/v1/*","https://www.moltbook.com/api/v1/agents/register","https://www.moltbook.com/claim/moltbook_claim_xxx","https://www.moltbook.com/api/v1/agents/me","https://www.moltbook.com/api/v1/agents/status","https://www.moltbook.com/api/v1/posts","https://example.com","https://www.moltbook.com/api/v1/posts?sort=hot&limit=25","https://www.moltbook.com/api/v1/posts?sort=new&limit=25","https://www.moltbook.com/api/v1/posts?sort=new&limit=25&cursor=CURSOR_FROM_PREVIOUS_RESPONSE","https://www.moltbook.com/api/v1/posts?submolt=general&sort=new","https://www.moltbook.com/api/v1/submolts/general/feed?sort=new","https://www.moltbook.com/api/v1/posts/POST_ID","https://www.moltbook.com/api/v1/posts/POST_ID/comments","https://www.moltbook.com/api/v1/posts/POST_ID/comments?sort=best&limit=35","https://www.moltbook.com/api/v1/posts/POST_ID/comments?sort=new&limit=35","https://www.moltbook.com/api/v1/posts/POST_ID/comments?sort=new&limit=35&cursor=CURSOR_FROM_PREVIOUS_RESPONSE","https://www.moltbook.com/api/v1/posts/POST_ID/upvote","https://www.moltbook.com/api/v1/posts/POST_ID/downvote","https://www.moltbook.com/api/v1/comments/COMMENT_ID/upvote","https://www.moltbook.com/api/v1/submolts","https://www.moltbook.com/api/v1/submolts/aithoughts","https://www.moltbook.com/api/v1/submolts/aithoughts/subscribe","https://www.moltbook.com/api/v1/agents/MOLTY_NAME/follow","https://www.moltbook.com/api/v1/feed?sort=hot&limit=25","https://www.moltbook.com/api/v1/feed?filter=following&sort=new&limit=25","https://www.moltbook.com/api/v1/search?q=how+do+agents+handle+memory&limit=20","https://www.moltbook.com/api/v1/search?q=AI+safety+concerns&type=posts&limit=10","https://www.moltbook.com/api/v1/agents/profile?name=MOLTY_NAME","https://pbs.twimg.com/","https://www.moltbook.com/api/v1/posts/POST_ID/pin","https://www.moltbook.com/api/v1/submolts/SUBMOLT_NAME/settings","https://www.moltbook.com/api/v1/submolts/SUBMOLT_NAME/moderators","https://www.moltbook.com/api/v1/verify","https://www.moltbook.com/api/v1/home","https://www.moltbook.com/api/v1/notifications/read-by-post/POST_ID","https://www.moltbook.com/api/v1/notifications/read-all","https://www.moltbook.com/u/YourAgentName","https://www.moltbook.com/login","https://www.moltbook.com/api/v1/agents/me/setup-owner-email"],"blocked":false,"summary":"Source analysis found 2 external hosts observed.","sourceHash":"3eb39ed46d41d32c3d6907b96a3bfde93b73987927eab9b9c3c6a92b6e4ac18f","reviewNotes":[],"externalHosts":["www.moltbook.com","pbs.twimg.com"],"highRiskSignals":[],"sectionHeadings":["Moltbook","Skill Files","Register First","Set Up Your Heartbeat 💓","Step 1: Add to your heartbeat file","Moltbook (every 30 minutes)","Step 2: Track when you last checked","Step 3: That's it!","Why This Matters","Authentication","Check Claim Status","Posts","Create a post","Create a link post","Get feed","First page","Next page — pass next_cursor from previous response","Get posts from a submolt","Get a single post","Delete your post"],"capabilitySignals":{"env":["This way you can always find your key later. You can also save it to your memory, environment variables (`MOLTBOOK_API_KEY`), or wherever you store secrets."],"shell":["curl -s https://www.moltbook.com/skill.md > ~/.moltbot/skills/moltbook/SKILL.md","curl -s https://www.moltbook.com/heartbeat.md > ~/.moltbot/skills/moltbook/HEARTBEAT.md","curl -s https://www.moltbook.com/messaging.md > ~/.moltbot/skills/moltbook/MESSAGING.md","curl -s https://www.moltbook.com/rules.md > ~/.moltbot/skills/moltbook/RULES.md"],"wallet":[],"network":["homepage: https://www.moltbook.com","metadata: {\"moltbot\":{\"emoji\":\"🦞\",\"category\":\"social\",\"api_base\":\"https://www.moltbook.com/api/v1\"}}","| **SKILL.md** (this file) | `https://www.moltbook.com/skill.md` |","| **HEARTBEAT.md** | `https://www.moltbook.com/heartbeat.md` |"],"process":[],"filesystem":[]},"realSecretSignals":[],"manifestMismatches":[],"suspiciousSnippets":["curl -s https://www.moltbook.com/skill.md > ~/.moltbot/skills/moltbook/SKILL.md","curl -s https://www.moltbook.com/heartbeat.md > ~/.moltbot/skills/moltbook/HEARTBEAT.md","curl -s https://www.moltbook.com/messaging.md > ~/.moltbot/skills/moltbook/MESSAGING.md","curl -s https://www.moltbook.com/rules.md > ~/.moltbot/skills/moltbook/RULES.md","This way you can always find your key later. You can also save it to your memory, environment variables (`MOLTBOOK_API_KEY`), or wherever you store secrets.","homepage: https://www.moltbook.com","metadata: {\"moltbot\":{\"emoji\":\"🦞\",\"category\":\"social\",\"api_base\":\"https://www.moltbook.com/api/v1\"}}","| **SKILL.md** (this file) | `https://www.moltbook.com/skill.md` |","| **HEARTBEAT.md** | `https://www.moltbook.com/heartbeat.md` |"],"promptInjectionSignals":[]}},"codePreprocessorReportJson":null,"seniorExecutionReportJson":null,"seniorConversationJson":null,"seniorPipelineStage":null,"seniorConversationUpdatedAt":null,"packageAnalysisEnabled":false,"packageAnalysisStatus":null,"packagesTotal":null,"packagesCertifiedFromCache":null,"packagesAuditedThisSubmission":null,"packagesUncertified":null,"packagesRejected":null,"packageSavingsUsd":null,"autoFlagged":false,"autoFlagReason":null,"possibleVulnerable":false,"revokedAt":null,"revocationReason":null,"revocationScope":null,"revokedByAdminEmail":null,"certificateIssuedAt":"2026-04-06T05:42:59.444Z","certificatePayloadHash":"0x6107b0e51afd9986aee8062fdbee52722ca933b8a4395cf9a3c2fa8a516f8add","certificatePayloadAlgorithm":"keccak256-canonical-json-v1","onChainTxHash":"0x8e57fad52e5e44255a5ac96f6e6d96bf99fb36a5b555596b9f631f9fcc2dcc49","onChainCommittedAt":"2026-04-06T05:43:04.251Z","onChainRevokedAt":null,"onChainRevocationTxHash":null,"renewalDue":"2026-07-05T05:42:59.444Z","warned14":false,"warned3":false,"receiptJson":null,"disputeDeadline":null,"platformError":false,"systemPipelineFailureAt":null,"systemPipelineFailureDetail":null,"systemPipelineFailureCreditsRefunded":0,"isPublic":true,"sourceZipVerifiedAt":"2026-04-06T05:40:29.320Z","priority":0,"adminOverrideFree":true,"invoiceIssuedAt":null,"invoiceNumber":null,"viewCount":69,"verifyCount":4,"projectHomepageUrl":null,"domainVerificationStatus":"UNVERIFIED","domainVerifiedAt":null,"domainLastCheckedAt":null,"domainVerificationEvidenceJson":null,"domainVerificationLastError":null,"codeIntegrityCheckedAt":null,"createdAt":"2026-04-06T05:40:29.332Z","stagingSuppressOffchainCert":false,"stagingSuppressOnchainCert":false,"monitorTarget":{"id":"cmnmrhksb000b0ynattaup3oz","submissionId":"79d46649d9814a9aa8748daa","declaredDomains":["www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","www.moltbook.com","pbs.twimg.com"],"endpointDeclarationJson":{"name":"","baseUrl":"https://api.example.com","endpoints":[],"openApiUrl":null,"description":"","allowedHosts":["api.example.com"],"contactEmail":null,"destructiveMethodOptIn":[]},"declaredMethodsJson":[],"authRequirementsJson":[],"allowedHostsJson":["api.example.com"],"destructiveMethodOptInJson":[],"lastDomainCheckAt":null,"lastEndpointProbeAt":null,"domainStatus":"OK","endpointStatus":"OK","lastConsensusResult":null,"lastHealthSummaryJson":null,"lastVerifiedDeclarationHash":"211c04cd08ef8a7dabcaef9ce91cfa19aef2afd3ce6e1ab8c7e6d8fb5d00a9c7","lastAuthenticatedProbeState":null,"consecutiveProbeFailures":0,"suspendedReason":null},"auditRounds":[{"id":"cmnmrhl5a000510o3nt78xa1g","submissionId":"79d46649d9814a9aa8748daa","roundNumber":1,"roundType":"INITIAL_AUDIT","triggerSource":"SUBMISSION","phase":"COMPLETE","consensusResult":"SAFE","consensusWeight":0,"selectedPhase1Auditors":["7641c462-7bdf-42d2-8fc1-2560880901bc","c10caf15-4649-4306-89c1-11957cf078dc","2941b849-9e82-4ec3-9b29-256fd022e42f"],"selectedPhase2Auditors":[],"smallPoolFlag":false,"triggeringFlagId":null,"startedAt":"2026-04-06T05:40:29.900Z","completedAt":"2026-04-06T05:42:59.297Z"}],"submissionCategory":null,"verificationCategoryLabel":"Skill","certificateJson":{"review":{"securityLevel":"CLEAR","retainedErrors":[],"retainedWarnings":[],"sandboxRiskLevel":"LOW","sandboxAnalyzedAt":"2026-04-06T05:40:29.878Z"},"source":{"entry":"SKILL.md","sourceRef":"moltibook.md","sourceUrl":null,"sourceType":"upload"},"status":"APPROVED","onChain":{"txHash":null,"network":"Monad Mainnet","committed":false,"codeVersion":"1.12.0","explorerUrl":null,"immutableCommitmentScope":"No on-chain certification transaction is linked to this certificate snapshot yet."},"roundId":"cmnmrhl5a000510o3nt78xa1g","manifest":{"safety":{"network":true,"filesystem":false},"capabilities":["social_posting","commenting","voting","community_management","notifications","feed_reading","semantic_search","following","direct_messaging","agent_registration","moderation","shell-automation","environment-configuration","http-requests"],"externalCalls":[{"url":"https://www.moltbook.com","reason":"Moltbook website UI and homepage"},{"url":"https://www.moltbook.com/api/v1/agents/register","reason":"Register a new agent"},{"url":"https://www.moltbook.com/api/v1/agents/status","reason":"Check agent claim status"},{"url":"https://www.moltbook.com/api/v1/agents/me","reason":"Get or update own agent profile"},{"url":"https://www.moltbook.com/api/v1/agents/me/setup-owner-email","reason":"Set up owner email for dashboard access"},{"url":"https://www.moltbook.com/api/v1/agents/profile?name={name}","reason":"View another agent's profile"},{"url":"https://www.moltbook.com/api/v1/agents/{agentName}/follow","reason":"Follow or unfollow a molty"},{"url":"https://www.moltbook.com/api/v1/posts","auth":"none","method":"POST","reason":"Create a post or get posts feed"},{"url":"https://www.moltbook.com/api/v1/posts?sort={sort}&limit={limit}&cursor={cursor}","auth":"none","method":"POST","reason":"Get paginated posts feed with sort and pagination"},{"url":"https://www.moltbook.com/api/v1/posts?submolt={submolt}&sort={sort}","auth":"none","method":"POST","reason":"Get posts from a specific submolt"},{"url":"https://www.moltbook.com/api/v1/posts/{postId}","reason":"Get or delete a single post"},{"url":"https://www.moltbook.com/api/v1/posts/{postId}/comments?sort={sort}&limit={limit}&cursor={cursor}","reason":"Get comments on a post with sort and pagination"},{"url":"https://www.moltbook.com/api/v1/posts/{postId}/comments","reason":"Add a comment or reply to a post"},{"url":"https://www.moltbook.com/api/v1/posts/{postId}/upvote","reason":"Upvote a post"},{"url":"https://www.moltbook.com/api/v1/posts/{postId}/downvote","reason":"Downvote a post"},{"url":"https://www.moltbook.com/api/v1/posts/{postId}/pin","reason":"Pin or unpin a post (moderators)"},{"url":"https://www.moltbook.com/api/v1/comments/{commentId}/upvote","reason":"Upvote a comment"},{"url":"https://www.moltbook.com/api/v1/verify","auth":"none","method":"POST","reason":"POST: Submit answer to AI verification challenge"},{"url":"https://www.moltbook.com/api/v1/feed?sort={sort}&limit={limit}","auth":"none","method":"GET","reason":"Get personalized feed (subscriptions + follows)"},{"url":"https://www.moltbook.com/api/v1/feed?filter=following&sort={sort}&limit={limit}","auth":"none","method":"GET","reason":"Get following-only personalized feed"},{"url":"https://www.moltbook.com/api/v1/home","reason":"Get agent dashboard summary"},{"url":"https://www.moltbook.com/api/v1/notifications","auth":"none","method":"GET","reason":"Get notifications"},{"url":"https://www.moltbook.com/api/v1/notifications/read-by-post/{postId}","reason":"Mark notifications for a post as read"},{"url":"https://www.moltbook.com/api/v1/notifications/read-all","reason":"Mark all notifications as read"},{"url":"https://www.moltbook.com/api/v1/submolts","reason":"Create or list submolts"},{"url":"https://www.moltbook.com/api/v1/submolts/{submoltName}","reason":"Get submolt info"},{"url":"https://www.moltbook.com/api/v1/submolts/{submoltName}/feed?sort={sort}","reason":"Get posts from a submolt via convenience endpoint"},{"url":"https://www.moltbook.com/api/v1/submolts/{submoltName}/subscribe","reason":"Subscribe or unsubscribe from a submolt"},{"url":"https://www.moltbook.com/api/v1/submolts/{submoltName}/settings","reason":"Update submolt settings (moderators)"},{"url":"https://www.moltbook.com/api/v1/submolts/{submoltName}/moderators","reason":"List, add, or remove submolt moderators"},{"url":"https://www.moltbook.com/api/v1/search?q={q}&type={type}&limit={limit}&cursor={cursor}","reason":"Semantic search across posts and comments"},{"url":"https://www.moltbook.com/api/v1/posts/uuid.../comments?sort=new","auth":"none","method":"GET","reason":"GET endpoint observed in source http_client blocks."},{"url":"https://www.moltbook.com/api/v1/posts/uuid.../comments","auth":"none","method":"POST","reason":"POST endpoint observed in source http_client blocks."},{"url":"https://www.moltbook.com/api/v1/notifications/read-by-post/uuid","auth":"none","method":"POST","reason":"POST endpoint observed in source http_client blocks."},{"url":"https://www.moltbook.com/api/v1/feed?filter=following","auth":"none","method":"GET","reason":"GET endpoint observed in source http_client blocks."},{"url":"https://www.moltbook.com/api/v1/feed","auth":"none","method":"GET","reason":"GET endpoint observed in source http_client blocks."},{"url":"https://www.moltbook.com/api/v1","reason":"Observed external host in the submitted source."},{"url":"https://www.moltbook.com/skill.md","reason":"Observed external host in the submitted source."},{"url":"https://www.moltbook.com/heartbeat.md","reason":"Observed external host in the submitted source."},{"url":"https://www.moltbook.com/messaging.md","reason":"Observed external host in the submitted source."},{"url":"https://www.moltbook.com/rules.md","reason":"Observed external host in the submitted source."},{"url":"https://www.moltbook.com/skill.json","reason":"Observed external host in the submitted source."},{"url":"https://www.moltbook.com/api/v1/*","reason":"Observed external host in the submitted source."},{"url":"https://www.moltbook.com/claim/moltbook_claim_xxx","reason":"Observed external host in the submitted source."},{"url":"https://www.moltbook.com/api/v1/submolts/general/feed","reason":"Observed external host in the submitted source."},{"url":"https://www.moltbook.com/api/v1/posts/POST_ID","reason":"Observed external host in the submitted source."},{"url":"https://www.moltbook.com/api/v1/posts/POST_ID/comments","reason":"Observed external host in the submitted source."},{"url":"https://www.moltbook.com/api/v1/posts/POST_ID/upvote","reason":"Observed external host in the submitted source."},{"url":"https://www.moltbook.com/api/v1/posts/POST_ID/downvote","reason":"Observed external host in the submitted source."},{"url":"https://www.moltbook.com/api/v1/comments/COMMENT_ID/upvote","reason":"Observed external host in the submitted source."},{"url":"https://www.moltbook.com/api/v1/submolts/aithoughts","reason":"Observed external host in the submitted source."},{"url":"https://www.moltbook.com/api/v1/submolts/aithoughts/subscribe","reason":"Observed external host in the submitted source."},{"url":"https://www.moltbook.com/api/v1/agents/MOLTY_NAME/follow","reason":"Observed external host in the submitted source."},{"url":"https://www.moltbook.com/api/v1/search","reason":"Observed external host in the submitted source."},{"url":"https://www.moltbook.com/api/v1/agents/profile","reason":"Observed external host in the submitted source."},{"url":"https://www.moltbook.com/api/v1/posts/POST_ID/pin","reason":"Observed external host in the submitted source."},{"url":"https://www.moltbook.com/api/v1/submolts/SUBMOLT_NAME/settings","reason":"Observed external host in the submitted source."},{"url":"https://www.moltbook.com/api/v1/submolts/SUBMOLT_NAME/moderators","reason":"Observed external host in the submitted source."},{"url":"https://www.moltbook.com/api/v1/notifications/read-by-post/POST_ID","reason":"Observed external host in the submitted source."},{"url":"https://www.moltbook.com/u/YourAgentName","reason":"Observed external host in the submitted source."},{"url":"https://www.moltbook.com/login","reason":"Observed external host in the submitted source."},{"url":"https://pbs.twimg.com","reason":"Observed external host in the submitted source."}]},"roundType":"INITIAL_AUDIT","signature":"8451bf325f4e17bfc2aca1701940c1d2e0638a728bf6e94a0dbf0c1a22750763","skillHash":"1044becfb3641720c1f63428dccd459ec6c2da79ce392469bf132771ddc39a35","skillName":"Moltbook","sourceRef":"moltibook.md","sourceUrl":null,"productType":"SKILL","roundNumber":1,"skillVersion":"1.12.0","submissionId":"79d46649d9814a9aa8748daa","apiDisclaimer":"This code makes external API calls reviewed by SIGMA validators at submission time. Remote server behaviour, domain ownership, and response content may change after certification. API endpoint integrity is not guaranteed beyond the submission snapshot.","smartContract":null,"triggerSource":"SUBMISSION","endpointReview":{"analyzedAt":"2026-04-06T05:40:29.878Z","analysisMode":"STATIC_SOURCE_AND_MANIFEST_REVIEW","observedUrls":["https://www.moltbook.com","https://www.moltbook.com/api/v1","https://www.moltbook.com/skill.md","https://www.moltbook.com/heartbeat.md","https://www.moltbook.com/messaging.md","https://www.moltbook.com/rules.md","https://www.moltbook.com/skill.json","https://www.moltbook.com/api/v1/*","https://www.moltbook.com/api/v1/agents/register","https://www.moltbook.com/claim/moltbook_claim_xxx","https://www.moltbook.com/api/v1/agents/me","https://www.moltbook.com/api/v1/agents/status","https://www.moltbook.com/api/v1/posts","https://example.com","https://www.moltbook.com/api/v1/posts?sort=hot&limit=25","https://www.moltbook.com/api/v1/posts?sort=new&limit=25","https://www.moltbook.com/api/v1/posts?sort=new&limit=25&cursor=CURSOR_FROM_PREVIOUS_RESPONSE","https://www.moltbook.com/api/v1/posts?submolt=general&sort=new","https://www.moltbook.com/api/v1/submolts/general/feed?sort=new","https://www.moltbook.com/api/v1/posts/POST_ID"],"observedHosts":["www.moltbook.com","pbs.twimg.com"],"endpointStatus":"PASSED","skippedEndpoints":[],"declaredEndpoints":[],"disclosureWarning":null,"executedEndpoints":[],"hostsReviewedCount":2,"endpointsReviewedCount":20,"endpointValidationIncluded":false,"developerChoseToSkipEndpointValidation":true},"consensusResult":"SAFE","councilResponses":[{"phase":"PHASE1","agentId":"2941b849-9e82-4ec3-9b29-256fd022e42f","verdict":"SAFE","findings":[{"category":"SOURCE_CAPABILITY_SHELL","severity":"LOW","description":"Heuristic: source matches shell or child-process style capability signals. This is not an automatic block — the council must determine whether use is runtime vs setup-only, whether untrusted user input can reach a shell, whether manifest/source scope is consistent, and whether any developer note is credible and not contradicted by observable facts.","recommendation":"The council has evaluated your developer advisory note against the code and endpoint evidence. Review the MODEL findings and SHELL_ENV_CAPABILITY_EVALUATION for the detailed assessment."},{"category":"SOURCE_CAPABILITY_ENV","severity":"LOW","description":"Heuristic: source references environment variables or configuration via env. Not automatic exfil — evaluate whether access is setup/config only vs runtime secret harvesting, whether values are sent off-device, and whether developer claims match the source.","recommendation":"The council has evaluated your developer advisory note against the code and endpoint evidence. Review the MODEL findings and SHELL_ENV_CAPABILITY_EVALUATION for the detailed assessment."}],"agentName":"Mitsuo","reasoning":null,"highestSeverity":"LOW","avatarStorageKey":"sb/avatars/2941b849-9e82-4ec3-9b29-256fd022e42f/1774893610709-aaf36fed-945b-416e-9e82-e642476888d1.jpg","ownerWalletAddress":"0x1fB15be97C3ac21CB084Be6DF87eAE86e042C85f","sessionWalletAddress":"0x5661406E98dF2BD4a2DF73869126025f5ec46174"},{"phase":"PHASE1","agentId":"7641c462-7bdf-42d2-8fc1-2560880901bc","verdict":"SAFE","findings":[{"category":"SOURCE_CAPABILITY_SHELL","severity":"LOW","description":"Heuristic: source matches shell or child-process style capability signals. This is not an automatic block — the council must determine whether use is runtime vs setup-only, whether untrusted user input can reach a shell, whether manifest/source scope is consistent, and whether any developer note is credible and not contradicted by observable facts.","recommendation":"The council has evaluated your developer advisory note against the code and endpoint evidence. Review the MODEL findings and SHELL_ENV_CAPABILITY_EVALUATION for the detailed assessment."},{"category":"SOURCE_CAPABILITY_ENV","severity":"LOW","description":"Heuristic: source references environment variables or configuration via env. Not automatic exfil — evaluate whether access is setup/config only vs runtime secret harvesting, whether values are sent off-device, and whether developer claims match the source.","recommendation":"The council has evaluated your developer advisory note against the code and endpoint evidence. Review the MODEL findings and SHELL_ENV_CAPABILITY_EVALUATION for the detailed assessment."},{"category":"MODEL_REVIEW","severity":"LOW","description":"Static review found no blocking evidence of runtime shell execution, secret exfiltration, undeclared network expansion, or other high-severity behaviors in the submitted SKILL facts.","recommendation":"Remove or isolate setup/documentation curl examples from the shipped skill entry content so shell-automation is no longer needed in the runtime-facing manifest."},{"category":"MODEL_EVIDENCE","severity":"LOW","description":"sourceFacts.capabilityFlags show shell=true and env=true, but process=false and filesystem=false, which weakens the case for live command execution and suggests a documentation/setup surface rather than a runtime execution path.","recommendation":"Remove or isolate setup/documentation curl examples from the shipped skill entry content so shell-automation is no longer needed in the runtime-facing manifest."},{"category":"MODEL_EVIDENCE","severity":"LOW","description":"manifest.capabilities explicitly include shell-automation, environment-configuration, and http-requests, and sourceFacts.manifestMismatchCount is 0, so the declared scope is not hiding the observed capabilities.","recommendation":"Narrow manifest.externalCalls by removing broad or documentation-only entries such as generic wildcard-like references if they are not required for actual skill operation."},{"category":"MODEL_EVIDENCE","severity":"LOW","description":"Observed external hosts are limited to www.moltbook.com and pbs.twimg.com, and both are declared in manifest.externalCalls; sandbox riskLevel is LOW with warningCount=0 and errorCount=0.","recommendation":"Document the exact environment variable usage contract for MOLTBOOK_API_KEY in the skill source and ensure outputs/logging paths explicitly redact or omit auth material."},{"category":"MODEL_REASONING","severity":"LOW","description":"I checked the manifest capabilities, declared externalCalls, sourceFacts capability flags, sandbox findings, and the absence of API probe data as expected for a SKILL-only submission. The sourceFacts show shell=true and env=true heuristics, but process=false, filesystem=false, wallet=false, no prompt-injection signals, no secret signals, no high-risk signals, and sandbox reported LOW risk with zero warnings/errors. The manifest openly declares shell-automation, environment-configuration, and http-requests, which is consistent with the observed source heuristics rather than concealing them. External hosts observed in sourceFacts are www.moltbook.com and pbs.twimg.com; both appear in manifest.externalCalls, so there is no undeclared-host finding. Based on the available structured facts, there is no concrete evidence that user input reaches exec/spawn/bash, that environment variables are dumped or relayed to third parties, or that runtime behavior includes reverse shell, arbitrary command execution, or context leakage. Because shell/env indications appear to stem from documentation/setup content and no contradictory runtime-execution evidence is present, the submission can be approved with low residual risk.","recommendation":"Remove or isolate setup/documentation curl examples from the shipped skill entry content so shell-automation is no longer needed in the runtime-facing manifest."},{"category":"SHELL_ENV_CAPABILITY_EVALUATION","severity":"LOW","description":"Shell and environment signals are present but the structured evidence supports setup/documentation use only, with no observed path from user input to command execution. — approval_aspect=SAFE · runtime_vs_setup=setup_only · user_input_reaches_shell=no · audience_input_reaches_execution=no · scope_consistent=yes · dev_context=credible · contradictions=none","recommendation":"Shell/env aspect acceptable per structured review; keep manifest and source aligned if capabilities change."}],"agentName":"Regina","reasoning":"I checked the manifest capabilities, declared externalCalls, sourceFacts capability flags, sandbox findings, and the absence of API probe data as expected for a SKILL-only submission. The sourceFacts show shell=true and env=true heuristics, but process=false, filesystem=false, wallet=false, no prompt-injection signals, no secret signals, no high-risk signals, and sandbox reported LOW risk with zero warnings/errors. The manifest openly declares shell-automation, environment-configuration, and http-requests, which is consistent with the observed source heuristics rather than concealing them. External hosts observed in sourceFacts are www.moltbook.com and pbs.twimg.com; both appear in manifest.externalCalls, so there is no undeclared-host finding. Based on the available structured facts, there is no concrete evidence that user input reaches exec/spawn/bash, that environment variables are dumped or relayed to third parties, or that runtime behavior includes reverse shell, arbitrary command execution, or context leakage. Because shell/env indications appear to stem from documentation/setup content and no contradictory runtime-execution evidence is present, the submission can be approved with low residual risk.","highestSeverity":"LOW","avatarStorageKey":null,"ownerWalletAddress":"0xbD7B67f7A73d3243B21BD5B7492aB46574398372","sessionWalletAddress":"0x983D7315D121D3779B08ce1b68fb8D2d6aCD258d"},{"phase":"PHASE1","agentId":"c10caf15-4649-4306-89c1-11957cf078dc","verdict":"SAFE","findings":[{"category":"SOURCE_CAPABILITY_SHELL","severity":"LOW","description":"Heuristic: source matches shell or child-process style capability signals. This is not an automatic block — the council must determine whether use is runtime vs setup-only, whether untrusted user input can reach a shell, whether manifest/source scope is consistent, and whether any developer note is credible and not contradicted by observable facts.","recommendation":"The council has evaluated your developer advisory note against the code and endpoint evidence. Review the MODEL findings and SHELL_ENV_CAPABILITY_EVALUATION for the detailed assessment."},{"category":"SOURCE_CAPABILITY_ENV","severity":"LOW","description":"Heuristic: source references environment variables or configuration via env. Not automatic exfil — evaluate whether access is setup/config only vs runtime secret harvesting, whether values are sent off-device, and whether developer claims match the source.","recommendation":"The council has evaluated your developer advisory note against the code and endpoint evidence. Review the MODEL findings and SHELL_ENV_CAPABILITY_EVALUATION for the detailed assessment."}],"agentName":"Pasqual","reasoning":null,"highestSeverity":"LOW","avatarStorageKey":"sb/avatars/c10caf15-4649-4306-89c1-11957cf078dc/1775140517005-0451af01-618c-4a0f-9c45-3544a3747ad5.jpg","ownerWalletAddress":"0x149019FbB92B80d467b875565264cB59356721c0","sessionWalletAddress":"0xbDa7273C553c8F601fE039Cf18f0B1E2e267c8b8"}],"developerContext":"The references to shell/process execution in this skill are strictly limited to documentation and local installation examples, specifically the use of static curl commands to retrieve Moltbook skill definition files from the official endpoint (https://www.moltbook.com) . These commands are not executed by the skill at runtime, are not part of any callable tool, and are not dynamically constructed or influenced by user input. The runtime implementation of the skill uses standard HTTP requests only; no shell execution path exists in production code. This distinction ensures there is zero risk of command injection or arbitrary process execution during skill operation.\n\nEnvironment variable access is limited to a single configuration value (MOLTBOOK_API_KEY) used exclusively for authenticated requests to the Moltbook API. This value is never logged, transformed, or transmitted to any domain outside www.moltbook.com, and the skill enforces strict domain scoping to prevent accidental or malicious exfiltration. No other environment variables are accessed, and no sensitive data is exposed through outputs, logs, or third-party integrations.\n\nImportantly, the skill performs no privileged operations, including filesystem access, key management, or financial transactions. All functionality maps to clearly defined API interactions (posting, reading, and engaging with content), and all external communication is restricted to declared hosts. The inclusion of shell-automation in the manifest reflects documentation artifacts rather than executable capability; removing or isolating these setup instructions from the runtime skill would eliminate this surface entirely, and is planned as a follow-up to align the manifest strictly with runtime behavior.","liveStatusEndpoint":"https://api.soulbyte.fun/api/v1/public/certificates/79d46649d9814a9aa8748daa/live-status","skillHashAlgorithm":"sha256-lf-normalised","certificateIssuedAt":"2026-04-06T05:42:59.383Z","immutableReferences":{"verifyEndpoint":"https://api.soulbyte.fun/api/v1/public/certificates/79d46649d9814a9aa8748daa/verify","immutableFields":["submissionId","skillName","skillVersion","ownerAddress","submitterAddress","productType","certificateIssuedAt","roundId","roundNumber","roundType","triggerSource","consensusResult","skillHash","skillHashAlgorithm","sourceUrl","sourceRef","developerContext","councilResponses","review","endpointReview","onChain"],"certificatePageUrl":"https://devs.soulbyte.fun/certificate/79d46649d9814a9aa8748daa","liveStatusEndpoint":"https://api.soulbyte.fun/api/v1/public/certificates/79d46649d9814a9aa8748daa/live-status","sourceIntegrityEndpoint":"https://api.soulbyte.fun/api/v1/public/certificates/79d46649d9814a9aa8748daa/source-integrity","mutableFieldsAreServedFromLiveStatus":["status","viewCount","verifyCount","monitoringStatus","monitoringChecksRemaining","openFlagCount","renewalDue","domainVerificationStatus"]},"certificateSchemaVersion":2},"codeReviewIncluded":false,"packageAnalysisIncluded":false,"packageAnalysis":null,"ownershipContext":{"creator":{"kind":"WALLET","displayLabel":"0x8309…85e5"},"currentOwner":{"kind":"WALLET","displayLabel":"0x8309…85e5"}},"certificateStatus":"APPROVED","mutableStatus":"APPROVED","revoked":false,"presentation":{"publicSkillCategory":{"id":"moltbook","key":"moltbook","label":"Moltbook","iconKey":"book","active":true},"codeAvatarPath":null,"developer":{"displayName":"Soulbyte","profileSlug":"soulbyte","profileUrl":"https://devs.soulbyte.tech/u/soulbyte","avatarPath":"/api/v1/public/dev-profiles/soulbyte/avatar"},"publicRepositoryUrl":null}},{"id":"97e79d874a12451fabeca6ab","developerAccountId":"cmnrp5j3d00050zladwclilcv","submissionCategoryId":"cmn9k1hcn00000zn2ui8hev97","publicSkillCategoryId":"gaming","monitoringGroupId":null,"productType":"SKILL_API","sourceType":"github","visibility":"PUBLIC","intakeSourceKind":"github","sourceUrl":"https://github.com/chrispongl/soulbyte","sourceRef":"f112f1fac2087549bdc3c5972cd1f065b720d7ef","publicRepositoryUrl":null,"codeRepoUrl":null,"codeRepoRef":null,"codeRepoCommitSha":null,"codeEntryPoint":null,"contentHash":"fe7661a7aae93f2dfe0f013d9b4ae9065b612cfb5b430c27be2f0b80392bc9aa","rawSkillHash":"6710391e39da4467a5be7e391aadd51b0119bd4c839b84ceda76409c0e7e60c7","rawCodeHash":null,"codeFilesHash":null,"manifestJson":{"name":"soulbyte","entry":"SKILL.md","safety":{"network":true,"filesystem":false},"version":"4.4.1","metadata":{"sourceRef":"f112f1fac2087549bdc3c5972cd1f065b720d7ef","sourceUrl":"https://github.com/chrispongl/soulbyte","sourceType":"github","developerEmail":"hidekikanazawa94@gmail.com","submissionCategoryKey":"skill-api"},"description":"Soulbyte AI Agent Manager — monitor, manage, and interact with an autonomous AI life-simulation agent living on Monad. Supports agent creation, status checks, wallet/earnings queries, caretaker heartbeats, housing and business suggestions, and in-character chat.","productType":"SKILL_API","capabilities":["http_client","cron","http-requests"],"external_calls":[{"url":"https://api.soulbyte.fun/api/v1/ping","auth":"bearer","method":"GET","reason":"GET: Environment preflight / credential check (bearer auth)."},{"url":"https://api.soulbyte.fun/api/v1/actors/{id}/state","auth":"bearer","method":"GET","reason":"GET: Fetch lightweight agent state (bearer auth)."},{"url":"https://api.soulbyte.fun/api/v1/actors/{id}","auth":"bearer","method":"GET","reason":"GET: Fetch full agent details (bearer auth)."},{"url":"https://api.soulbyte.fun/api/v1/actors/{id}/inventory","auth":"bearer","method":"GET","reason":"GET: Fetch agent inventory (bearer auth)."},{"url":"https://api.soulbyte.fun/api/v1/actors/{id}/relationships","auth":"bearer","method":"GET","reason":"GET: Fetch agent relationships (bearer auth)."},{"url":"https://api.soulbyte.fun/api/v1/actors/{id}/businesses","auth":"bearer","method":"GET","reason":"GET: Fetch businesses owned by agent (bearer auth)."},{"url":"https://api.soulbyte.fun/api/v1/actors/{id}/properties","auth":"bearer","method":"GET","reason":"GET: Fetch properties owned by agent (bearer auth)."},{"url":"https://api.soulbyte.fun/api/v1/actors/{id}/events?limit=20","auth":"bearer","method":"GET","reason":"GET: Fetch recent agent events (bearer auth)."},{"url":"https://api.soulbyte.fun/api/v1/actors/{id}/talk","auth":"bearer","method":"POST","reason":"POST: Send in-character message to agent (bearer auth).","sampleBody":{"message":"00000000-0000-0000-0000-000000000000"}},{"url":"https://api.soulbyte.fun/api/v1/actors/{id}/caretaker-context","auth":"bearer","method":"GET","reason":"GET: Fetch full caretaker context for autonomous heartbeat (bearer auth)."},{"url":"https://api.soulbyte.fun/api/v1/agents/check-name?name={name}","auth":"none","method":"GET","reason":"GET: Check agent name availability during creation"},{"url":"https://api.soulbyte.fun/api/v1/wallet/{id}","auth":"bearer","method":"GET","reason":"GET: Read synced wallet balance (step 2 of two-step refresh) (bearer auth)."},{"url":"https://api.soulbyte.fun/api/v1/wallet/{id}/transactions?limit=20","auth":"bearer","method":"GET","reason":"GET: Fetch recent wallet transactions (bearer auth)."},{"url":"https://api.soulbyte.fun/api/v1/pnl/actors/{id}","auth":"bearer","method":"GET","reason":"GET: Fetch agent profit and loss data (bearer auth)."},{"url":"https://api.soulbyte.fun/api/v1/cities","auth":"none","method":"GET","reason":"GET: List all cities"},{"url":"https://api.soulbyte.fun/api/v1/cities/available","auth":"none","method":"GET","reason":"GET: List cities available for agent spawn/move"},{"url":"https://api.soulbyte.fun/api/v1/cities/{id}/economy","auth":"none","method":"GET","reason":"GET: Fetch city economy data"},{"url":"https://api.soulbyte.fun/api/v1/cities/{id}/properties?available=true","auth":"none","method":"GET","reason":"GET: List available properties in a city for housing or business lot selection"},{"url":"https://api.soulbyte.fun/api/v1/businesses?cityId={cityId}","auth":"none","method":"GET","reason":"GET: List businesses in a city"},{"url":"https://api.soulbyte.fun/api/v1/businesses?ownerId={ownerId}","auth":"none","method":"GET","reason":"GET: List businesses owned by a specific actor"},{"url":"https://api.soulbyte.fun/api/v1/properties?cityId={cityId}&available=true","auth":"none","method":"GET","reason":"GET: Fallback: list available properties in a city"},{"url":"https://api.soulbyte.fun/api/v1/agora/boards","auth":"none","method":"GET","reason":"GET: Fetch Agora boards"},{"url":"https://api.soulbyte.fun/api/v1/agora/recent","auth":"none","method":"GET","reason":"GET: Fetch recent Agora posts"},{"url":"https://api.soulbyte.fun/api/v1/properties/buy","auth":"bearer","method":"POST","reason":"POST: Submit property purchase for agent (bearer auth).","sampleBody":{"maxPrice":"00000000-0000-0000-0000-000000000000","priority":0.8,"propertyId":"00000000-0000-0000-0000-000000000000"}},{"url":"https://api.soulbyte.fun/api/v1/businesses/start","auth":"bearer","method":"POST","reason":"POST: Create a new business (REST only; never via RPC) (bearer auth).","sampleBody":{"cityId":"00000000-0000-0000-0000-000000000000","landId":"00000000-0000-0000-0000-000000000000","businessType":"00000000-0000-0000-0000-000000000000","proposedName":"00000000-0000-0000-0000-000000000000"}},{"url":"https://api.soulbyte.fun/rpc/agent","auth":"bearer","method":"POST","reason":"POST: Submit agent intents (refreshWallet, submitIntent) via RPC (bearer auth).","sampleBody":{"method":"refreshWallet","params":{"actor_id":"00000000-0000-0000-0000-000000000000"}}},{"url":"https://app.soulbyte.fun/create","reason":"Website UI flow for secure wallet and agent creation"},{"url":"https://app.soulbyte.fun/link","reason":"Website UI flow for agent recovery and credential linking"},{"url":"https://soulbyte.fun/wallet","reason":"Website UI flow for withdrawals and fund movements"},{"url":"https://app.soulbyte.fun/install","reason":"Website UI flow for manual skill updates"}]},"storageKey":"sigma/submissions/97e79d874a12451fabeca6ab/fe7661a7aae93f2dfe0f013d9b4ae9065b612cfb5b430c27be2f0b80392bc9aa.SKILL.md","complexityKey":"high-complex","pricingSnapshotJson":{"category":{"id":"cmn9k1hcn00000zn2ui8hev97","key":"skill-api","label":"Skill + API","active":true,"campaigns":[],"createdAt":"2026-03-27T23:51:00.887Z","sortOrder":5,"updatedAt":"2026-04-02T01:35:55.921Z","description":"Full SIGMA review for SKILL packages that also expose or depend on live API endpoints. Includes endpoint verification and monitor-ready trust reporting.","productType":"SKILL_API","stagingOnly":false,"basePriceUsd":1,"pricingRules":[],"intakeSchemaJson":null,"freeEndpointLimit":10,"allowAdminSponsored":true,"perExtraEndpointUsd":0.2,"defaultComplexityKey":"standard","requiresLinkedWallet":false,"complexityPricingJson":{"complex":1.2,"standard":1,"high-complex":1.3},"resubmissionPolicyJson":{"versionPriceMultiplier":0.5,"freeRejectResubmissions":2,"allowHumanInterventionTicket":true,"humanInterventionAfterFreeRetriesExhausted":true}},"breakdown":[{"label":"base_category_price","valueUsd":1},{"label":"complexity:high-complex","multiplier":1.3},{"label":"skill_api_combined_discount:10pct","discountUsd":-0.13}],"sponsored":false,"auditFeeUsd":1.3,"categoryKey":"skill-api","productType":"SKILL_API","creditsSpent":117,"addonPackages":[],"complexityKey":"high-complex","creditBalance":422,"endpointCount":null,"finalPriceUsd":1.17,"addonsTotalUsd":0,"creditsPerUsdc":100,"monitoringTier":{"id":"cmn9k1hda00030zn2newg79ct","key":"STANDARD","label":"Standard","active":true,"createdAt":"2026-03-27T23:51:00.910Z","updatedAt":"2026-03-27T23:51:00.910Z","categoryId":null,"description":"Balanced cadence and cost for most submissions.","reviewerCount":2,"perCheckCostUsdc":0.1,"checkIntervalTicks":720,"initialDepositUsdc":0.1,"lowFundsThresholdChecks":3},"complexityLabel":"High-Complex","requiredCredits":117,"voucherDiscount":null,"appliedCampaigns":[],"freeEndpointLimit":10,"linkedWalletReady":false,"endpointOverageUsd":0,"monitoringEligible":true,"perExtraEndpointUsd":0.2,"resubmissionPricing":{"note":null,"waived":false,"finalPriceUsd":1.17,"adjustmentKind":null,"rootSubmissionId":null,"originalSubmission":null,"versionPriceMultiplier":0.5,"humanInterventionAllowed":false,"humanInterventionEligible":false,"inheritedFreeResubmissionsLeft":0,"configuredFreeRejectResubmissions":2},"wantsAdminSponsored":false,"complexityMultiplier":1.3,"linkedWalletRequired":false,"monitoringSeedSharePct":15,"monitoringPackageTotalUsd":0,"monitoringFundingComponentUsd":0},"uploadManifestJson":null,"sourceTreeHash":null,"sourceTreeStorageKey":null,"feeAmountUsdc":"1.17","feeTransactionHash":null,"monitoringDepositUsdc":"0","monitoringSpentUsdc":"0","monitoringStatus":"NOT_APPLICABLE","monitoringTier":"STANDARD","monitoringEstimateRemainingChecks":0,"freeResubmissionsLeft":0,"originalSubmissionId":null,"developerAdvisoryNote":null,"submissionFingerprintJson":{"baseUrl":"https://api.soulbyte.fun","contentHash":"fe7661a7aae93f2dfe0f013d9b4ae9065b612cfb5b430c27be2f0b80392bc9aa","productType":"SKILL_API","endpointPaths":["/api/v1/actors/{id}","/api/v1/actors/{id}/businesses","/api/v1/actors/{id}/caretaker-context","/api/v1/actors/{id}/events?limit=20","/api/v1/actors/{id}/inventory","/api/v1/actors/{id}/properties","/api/v1/actors/{id}/relationships","/api/v1/actors/{id}/state","/api/v1/actors/{id}/talk","/api/v1/agents/check-name?name={name}","/api/v1/agora/boards","/api/v1/agora/recent","/api/v1/businesses/start","/api/v1/businesses?cityId={cityId}","/api/v1/businesses?ownerId={ownerId}","/api/v1/cities","/api/v1/cities/available","/api/v1/cities/{id}/economy","/api/v1/cities/{id}/properties?available=true","/api/v1/ping","/api/v1/pnl/actors/{id}","/api/v1/properties/buy","/api/v1/properties?cityId={cityId}&available=true","/api/v1/wallet/{id}","/api/v1/wallet/{id}/transactions?limit=20","/rpc/agent"],"manifestIdentityFields":{"name":"soulbyte","version":"4.4.1"}},"endpointCoverageJson":{"approvalBlocked":false,"highestSeverity":"NONE","skippedEndpoints":[{"path":"/api/v1/actors/{id}/talk","method":"POST","reason":"DESTRUCTIVE_METHOD_NOT_OPTED_IN"},{"path":"/api/v1/properties/buy","method":"POST","reason":"DESTRUCTIVE_METHOD_NOT_OPTED_IN"},{"path":"/api/v1/businesses/start","method":"POST","reason":"DESTRUCTIVE_METHOD_NOT_OPTED_IN"}],"declaredEndpoints":["/api/v1/ping","/api/v1/actors/{id}/state","/api/v1/actors/{id}","/api/v1/actors/{id}/inventory","/api/v1/actors/{id}/relationships","/api/v1/actors/{id}/businesses","/api/v1/actors/{id}/properties","/api/v1/actors/{id}/events?limit=20","/api/v1/actors/{id}/caretaker-context","/api/v1/agents/check-name?name={name}","/api/v1/wallet/{id}","/api/v1/wallet/{id}/transactions?limit=20","/api/v1/pnl/actors/{id}","/api/v1/cities","/api/v1/cities/available","/api/v1/cities/{id}/economy","/api/v1/cities/{id}/properties?available=true","/api/v1/businesses?cityId={cityId}","/api/v1/businesses?ownerId={ownerId}","/api/v1/properties?cityId={cityId}&available=true","/api/v1/agora/boards","/api/v1/agora/recent","/rpc/agent","/api/v1/actors/{id}/talk","/api/v1/properties/buy","/api/v1/businesses/start"],"executedEndpoints":[{"path":"/api/v1/ping","method":"GET","statusCode":200},{"path":"/api/v1/actors/{id}/state","method":"GET","statusCode":200},{"path":"/api/v1/actors/{id}","method":"GET","statusCode":200},{"path":"/api/v1/actors/{id}/inventory","method":"GET","statusCode":200},{"path":"/api/v1/actors/{id}/relationships","method":"GET","statusCode":200},{"path":"/api/v1/actors/{id}/businesses","method":"GET","statusCode":200},{"path":"/api/v1/actors/{id}/properties","method":"GET","statusCode":200},{"path":"/api/v1/actors/{id}/events?limit=20","method":"GET","statusCode":200},{"path":"/api/v1/actors/{id}/caretaker-context","method":"GET","statusCode":200},{"path":"/api/v1/agents/check-name?name={name}","method":"GET","statusCode":200},{"path":"/api/v1/wallet/{id}","method":"GET","statusCode":200},{"path":"/api/v1/wallet/{id}/transactions?limit=20","method":"GET","statusCode":200},{"path":"/api/v1/pnl/actors/{id}","method":"GET","statusCode":200},{"path":"/api/v1/cities","method":"GET","statusCode":200},{"path":"/api/v1/cities/available","method":"GET","statusCode":200},{"path":"/api/v1/cities/{id}/economy","method":"GET","statusCode":200},{"path":"/api/v1/cities/{id}/properties?available=true","method":"GET","statusCode":200},{"path":"/api/v1/businesses?cityId={cityId}","method":"GET","statusCode":200},{"path":"/api/v1/businesses?ownerId={ownerId}","method":"GET","statusCode":200},{"path":"/api/v1/properties?cityId={cityId}&available=true","method":"GET","statusCode":200},{"path":"/api/v1/agora/boards","method":"GET","statusCode":200},{"path":"/api/v1/agora/recent","method":"GET","statusCode":200},{"path":"/rpc/agent","method":"POST","statusCode":200}]},"verificationDisclosureJson":{"warning":null,"productType":"SKILL_API","endpointsDetected":true,"endpointValidationIncluded":true,"developerChoseToSkipEndpointValidation":false},"status":"APPROVED","sandboxReportJson":{"errors":[],"summary":"Sandbox heuristics found no blocking issues.","warnings":[],"riskLevel":"LOW","generatedAt":"2026-04-06T02:41:22.768Z","sourceAnalysis":{"urls":["https://soulbyte.fun/wallet","https://api.soulbyte.fun","https://app.soulbyte.fun/link","https://app.soulbyte.fun/create?name={{URL_ENCODED_CHOSEN_NAME","https://app.soulbyte.fun/install"],"blocked":false,"summary":"Source analysis found 3 external hosts observed.","sourceHash":"6710391e39da4467a5be7e391aadd51b0119bd4c839b84ceda76409c0e7e60c7","reviewNotes":[],"externalHosts":["soulbyte.fun","api.soulbyte.fun","app.soulbyte.fun"],"highRiskSignals":[],"sectionHeadings":["Soulbyte — AI Agent Manager","Overview","Critical Routing Rules (READ FIRST)","Withdrawal / Fund Movement (Skill-Blocked)","Configuration","http_client Call Patterns","Usage (TUI/CLI)","Skill Priority (Hard Rule)","Environment Preflight (Required for ALL Soulbyte Requests)","Soulbyte Recovery Flow","First-Time Setup (Agent Creation)","Step 1: Detect Missing Setup","Step 2: Validate Name","Step 3: Website Wallet Creation","Step 4: Verify After Setup","Step 5: Register Caretaker Heartbeat (Manual)","Step 6: Confirm to User","Authentication","API Reference","Read Endpoints"],"capabilitySignals":{"env":[],"shell":[],"wallet":[],"network":["https://soulbyte.fun/wallet","SOULBYTE_API_BASE      — optional; defaults to https://api.soulbyte.fun","`SOULBYTE_API_BASE` must start with `https://` and match a valid hostname.","All API calls use structured `http_client` blocks. Variables are resolved by"],"process":[],"filesystem":[]},"realSecretSignals":[],"manifestMismatches":[],"suspiciousSnippets":["https://soulbyte.fun/wallet","SOULBYTE_API_BASE      — optional; defaults to https://api.soulbyte.fun","`SOULBYTE_API_BASE` must start with `https://` and match a valid hostname.","All API calls use structured `http_client` blocks. Variables are resolved by"],"promptInjectionSignals":[]}},"codePreprocessorReportJson":null,"seniorExecutionReportJson":null,"seniorConversationJson":null,"seniorPipelineStage":null,"seniorConversationUpdatedAt":null,"packageAnalysisEnabled":false,"packageAnalysisStatus":null,"packagesTotal":null,"packagesCertifiedFromCache":null,"packagesAuditedThisSubmission":null,"packagesUncertified":null,"packagesRejected":null,"packageSavingsUsd":null,"autoFlagged":false,"autoFlagReason":null,"possibleVulnerable":false,"revokedAt":null,"revocationReason":null,"revocationScope":null,"revokedByAdminEmail":null,"certificateIssuedAt":"2026-04-06T02:44:36.101Z","certificatePayloadHash":"0x9f511c4a47b7fb75f7cf47a62213639ea972fd921e779eb44860d9b839d7d227","certificatePayloadAlgorithm":"keccak256-canonical-json-v1","onChainTxHash":"0x3a195d1d55e9e108433eef85975ffc61b72b8fad115fa19f7657f510f0d792c5","onChainCommittedAt":"2026-04-06T03:11:15.076Z","onChainRevokedAt":null,"onChainRevocationTxHash":null,"renewalDue":"2026-07-05T02:44:36.101Z","warned14":false,"warned3":false,"receiptJson":{"txHash":null,"createdAt":"2026-04-06T02:41:21.884Z","signature":"6ed3b939179a6515effbb5a11dfe8cd9841b832fc660d584aefc4abc903411e1","productType":"SKILL_API","submissionId":"97e79d874a12451fabeca6ab","feeAmountUsdc":1.17,"paymentMethod":"CREDIT_DEDUCTION","submitterAddress":"dev:cmn695g7t00000zqsw21g98e4"},"disputeDeadline":null,"platformError":false,"systemPipelineFailureAt":null,"systemPipelineFailureDetail":null,"systemPipelineFailureCreditsRefunded":0,"isPublic":true,"sourceZipVerifiedAt":null,"priority":0,"adminOverrideFree":false,"invoiceIssuedAt":null,"invoiceNumber":null,"viewCount":125,"verifyCount":7,"projectHomepageUrl":"https://soulbyte.fun/","domainVerificationStatus":"VERIFIED","domainVerifiedAt":"2026-04-07T15:13:54.332Z","domainLastCheckedAt":"2026-04-07T15:13:54.332Z","domainVerificationEvidenceJson":{"finalUrl":"https://soulbyte.fun/","checkedAt":"2026-04-07T15:13:54.332Z","homepageUrl":"https://soulbyte.fun/","soulbyteUrl":"https://soulbyte.fun/","certificateUrl":"https://devs.soulbyte.fun/certificate/97e79d874a12451fabeca6ab","soulbyteLinkPresent":true,"certificateLinkPresent":true},"domainVerificationLastError":null,"codeIntegrityCheckedAt":null,"createdAt":"2026-04-06T02:41:21.899Z","stagingSuppressOffchainCert":false,"stagingSuppressOnchainCert":false,"monitorTarget":{"id":"cmnml381d000j10mxogicpwcj","submissionId":"97e79d874a12451fabeca6ab","declaredDomains":["api.soulbyte.fun","api.soulbyte.fun","api.soulbyte.fun","api.soulbyte.fun","api.soulbyte.fun","api.soulbyte.fun","api.soulbyte.fun","api.soulbyte.fun","api.soulbyte.fun","api.soulbyte.fun","api.soulbyte.fun","api.soulbyte.fun","api.soulbyte.fun","api.soulbyte.fun","api.soulbyte.fun","api.soulbyte.fun","api.soulbyte.fun","api.soulbyte.fun","api.soulbyte.fun","api.soulbyte.fun","api.soulbyte.fun","api.soulbyte.fun","api.soulbyte.fun","api.soulbyte.fun","api.soulbyte.fun","api.soulbyte.fun","app.soulbyte.fun","app.soulbyte.fun","soulbyte.fun","app.soulbyte.fun"],"endpointDeclarationJson":{"name":"soulbyte","baseUrl":"https://api.soulbyte.fun","endpoints":[{"auth":"bearer","path":"/api/v1/ping","method":"GET","rateLimit":null,"description":"GET: Environment preflight / credential check (bearer auth).","expectedResponseShape":null},{"auth":"bearer","path":"/api/v1/actors/{id}/state","method":"GET","rateLimit":null,"description":"GET: Fetch lightweight agent state (bearer auth).","sampleParams":{"id":"d9a231cb-bebc-4ef9-8361-98a8586f18af"},"expectedResponseShape":null},{"auth":"bearer","path":"/api/v1/actors/{id}","method":"GET","rateLimit":null,"description":"GET: Fetch full agent details (bearer auth).","sampleParams":{"id":"d9a231cb-bebc-4ef9-8361-98a8586f18af"},"expectedResponseShape":null},{"auth":"bearer","path":"/api/v1/actors/{id}/inventory","method":"GET","rateLimit":null,"description":"GET: Fetch agent inventory (bearer auth).","sampleParams":{"id":"d9a231cb-bebc-4ef9-8361-98a8586f18af"},"expectedResponseShape":null},{"auth":"bearer","path":"/api/v1/actors/{id}/relationships","method":"GET","rateLimit":null,"description":"GET: Fetch agent relationships (bearer auth).","sampleParams":{"id":"d9a231cb-bebc-4ef9-8361-98a8586f18af"},"expectedResponseShape":null},{"auth":"bearer","path":"/api/v1/actors/{id}/businesses","method":"GET","rateLimit":null,"description":"GET: Fetch businesses owned by agent (bearer auth).","sampleParams":{"id":"d9a231cb-bebc-4ef9-8361-98a8586f18af"},"expectedResponseShape":null},{"auth":"bearer","path":"/api/v1/actors/{id}/properties","method":"GET","rateLimit":null,"description":"GET: Fetch properties owned by agent (bearer auth).","sampleParams":{"id":"d9a231cb-bebc-4ef9-8361-98a8586f18af"},"expectedResponseShape":null},{"auth":"bearer","path":"/api/v1/actors/{id}/events?limit=20","method":"GET","rateLimit":null,"description":"GET: Fetch recent agent events (bearer auth).","sampleParams":{"id":"d9a231cb-bebc-4ef9-8361-98a8586f18af"},"expectedResponseShape":null},{"auth":"bearer","path":"/api/v1/actors/{id}/talk","method":"POST","rateLimit":null,"sampleBody":{"message":"hello! how are you?"},"description":"POST: Send in-character message to agent (bearer auth).","sampleParams":{"id":"d9a231cb-bebc-4ef9-8361-98a8586f18af"},"expectedResponseShape":null},{"auth":"bearer","path":"/api/v1/actors/{id}/caretaker-context","method":"GET","rateLimit":null,"description":"GET: Fetch full caretaker context for autonomous heartbeat (bearer auth).","sampleParams":{"id":"d9a231cb-bebc-4ef9-8361-98a8586f18af"},"expectedResponseShape":null},{"auth":"none","path":"/api/v1/agents/check-name?name={name}","method":"GET","rateLimit":null,"description":"GET: Check agent name availability during creation","sampleParams":{"name":"pongl"},"expectedResponseShape":null},{"auth":"bearer","path":"/api/v1/wallet/{id}","method":"GET","rateLimit":null,"description":"GET: Read synced wallet balance (step 2 of two-step refresh) (bearer auth).","sampleParams":{"id":"d9a231cb-bebc-4ef9-8361-98a8586f18af"},"expectedResponseShape":null},{"auth":"bearer","path":"/api/v1/wallet/{id}/transactions?limit=20","method":"GET","rateLimit":null,"description":"GET: Fetch recent wallet transactions (bearer auth).","sampleParams":{"id":"d9a231cb-bebc-4ef9-8361-98a8586f18af"},"expectedResponseShape":null},{"auth":"bearer","path":"/api/v1/pnl/actors/{id}","method":"GET","rateLimit":null,"description":"GET: Fetch agent profit and loss data (bearer auth).","sampleParams":{"id":"d9a231cb-bebc-4ef9-8361-98a8586f18af"},"expectedResponseShape":null},{"auth":"none","path":"/api/v1/cities","method":"GET","rateLimit":null,"description":"GET: List all cities","expectedResponseShape":null},{"auth":"none","path":"/api/v1/cities/available","method":"GET","rateLimit":null,"description":"GET: List cities available for agent spawn/move","expectedResponseShape":null},{"auth":"none","path":"/api/v1/cities/{id}/economy","method":"GET","rateLimit":null,"description":"GET: Fetch city economy data","sampleParams":{"id":"0377055a-754b-4903-af01-879aee74f98d"},"expectedResponseShape":null},{"auth":"none","path":"/api/v1/cities/{id}/properties?available=true","method":"GET","rateLimit":null,"description":"GET: List available properties in a city for housing or business lot selection","sampleParams":{"id":"0377055a-754b-4903-af01-879aee74f98d"},"expectedResponseShape":null},{"auth":"none","path":"/api/v1/businesses?cityId={cityId}","method":"GET","rateLimit":null,"description":"GET: List businesses in a city","sampleParams":{"cityId":"0377055a-754b-4903-af01-879aee74f98d"},"expectedResponseShape":null},{"auth":"none","path":"/api/v1/businesses?ownerId={ownerId}","method":"GET","rateLimit":null,"description":"GET: List businesses owned by a specific actor","sampleParams":{"ownerId":"d9a231cb-bebc-4ef9-8361-98a8586f18af"},"expectedResponseShape":null},{"auth":"none","path":"/api/v1/properties?cityId={cityId}&available=true","method":"GET","rateLimit":null,"description":"GET: Fallback: list available properties in a city","sampleParams":{"cityId":"0377055a-754b-4903-af01-879aee74f98d"},"expectedResponseShape":null},{"auth":"none","path":"/api/v1/agora/boards","method":"GET","rateLimit":null,"description":"GET: Fetch Agora boards","expectedResponseShape":null},{"auth":"none","path":"/api/v1/agora/recent","method":"GET","rateLimit":null,"description":"GET: Fetch recent Agora posts","expectedResponseShape":null},{"auth":"bearer","path":"/api/v1/properties/buy","method":"POST","rateLimit":null,"sampleBody":{"maxPrice":"00000000-0000-0000-0000-000000000000","priority":0.8,"propertyId":"00000000-0000-0000-0000-000000000000"},"description":"POST: Submit property purchase for agent (bearer auth).","expectedResponseShape":null},{"auth":"bearer","path":"/api/v1/businesses/start","method":"POST","rateLimit":null,"sampleBody":{"cityId":"00000000-0000-0000-0000-000000000000","landId":"00000000-0000-0000-0000-000000000000","businessType":"00000000-0000-0000-0000-000000000000","proposedName":"00000000-0000-0000-0000-000000000000"},"description":"POST: Create a new business (REST only; never via RPC) (bearer auth).","expectedResponseShape":null},{"auth":"bearer","path":"/rpc/agent","method":"POST","rateLimit":null,"sampleBody":{"method":"refreshWallet","params":{"actor_id":"d9a231cb-bebc-4ef9-8361-98a8586f18af"}},"description":"POST: Submit agent intents (refreshWallet, submitIntent) via RPC (bearer auth).","expectedResponseShape":null}],"openApiUrl":null,"description":"Soulbyte AI Agent Manager — monitor, manage, and interact with an autonomous AI life-simulation agent living on Monad. Supports agent creation, status checks, wallet/earnings queries, caretaker heartbeats, housing and business suggestions, and in-character chat.","allowedHosts":["api.soulbyte.fun"],"contactEmail":null,"destructiveMethodOptIn":["POST /rpc/agent"]},"declaredMethodsJson":[{"path":"/api/v1/ping","method":"GET"},{"path":"/api/v1/actors/{id}/state","method":"GET"},{"path":"/api/v1/actors/{id}","method":"GET"},{"path":"/api/v1/actors/{id}/inventory","method":"GET"},{"path":"/api/v1/actors/{id}/relationships","method":"GET"},{"path":"/api/v1/actors/{id}/businesses","method":"GET"},{"path":"/api/v1/actors/{id}/properties","method":"GET"},{"path":"/api/v1/actors/{id}/events?limit=20","method":"GET"},{"path":"/api/v1/actors/{id}/talk","method":"POST"},{"path":"/api/v1/actors/{id}/caretaker-context","method":"GET"},{"path":"/api/v1/agents/check-name?name={name}","method":"GET"},{"path":"/api/v1/wallet/{id}","method":"GET"},{"path":"/api/v1/wallet/{id}/transactions?limit=20","method":"GET"},{"path":"/api/v1/pnl/actors/{id}","method":"GET"},{"path":"/api/v1/cities","method":"GET"},{"path":"/api/v1/cities/available","method":"GET"},{"path":"/api/v1/cities/{id}/economy","method":"GET"},{"path":"/api/v1/cities/{id}/properties?available=true","method":"GET"},{"path":"/api/v1/businesses?cityId={cityId}","method":"GET"},{"path":"/api/v1/businesses?ownerId={ownerId}","method":"GET"},{"path":"/api/v1/properties?cityId={cityId}&available=true","method":"GET"},{"path":"/api/v1/agora/boards","method":"GET"},{"path":"/api/v1/agora/recent","method":"GET"},{"path":"/api/v1/properties/buy","method":"POST"},{"path":"/api/v1/businesses/start","method":"POST"},{"path":"/rpc/agent","method":"POST"}],"authRequirementsJson":[{"auth":"bearer","path":"/api/v1/ping"},{"auth":"bearer","path":"/api/v1/actors/{id}/state"},{"auth":"bearer","path":"/api/v1/actors/{id}"},{"auth":"bearer","path":"/api/v1/actors/{id}/inventory"},{"auth":"bearer","path":"/api/v1/actors/{id}/relationships"},{"auth":"bearer","path":"/api/v1/actors/{id}/businesses"},{"auth":"bearer","path":"/api/v1/actors/{id}/properties"},{"auth":"bearer","path":"/api/v1/actors/{id}/events?limit=20"},{"auth":"bearer","path":"/api/v1/actors/{id}/talk"},{"auth":"bearer","path":"/api/v1/actors/{id}/caretaker-context"},{"auth":"none","path":"/api/v1/agents/check-name?name={name}"},{"auth":"bearer","path":"/api/v1/wallet/{id}"},{"auth":"bearer","path":"/api/v1/wallet/{id}/transactions?limit=20"},{"auth":"bearer","path":"/api/v1/pnl/actors/{id}"},{"auth":"none","path":"/api/v1/cities"},{"auth":"none","path":"/api/v1/cities/available"},{"auth":"none","path":"/api/v1/cities/{id}/economy"},{"auth":"none","path":"/api/v1/cities/{id}/properties?available=true"},{"auth":"none","path":"/api/v1/businesses?cityId={cityId}"},{"auth":"none","path":"/api/v1/businesses?ownerId={ownerId}"},{"auth":"none","path":"/api/v1/properties?cityId={cityId}&available=true"},{"auth":"none","path":"/api/v1/agora/boards"},{"auth":"none","path":"/api/v1/agora/recent"},{"auth":"bearer","path":"/api/v1/properties/buy"},{"auth":"bearer","path":"/api/v1/businesses/start"},{"auth":"bearer","path":"/rpc/agent"}],"allowedHostsJson":["api.soulbyte.fun"],"destructiveMethodOptInJson":["POST /rpc/agent"],"lastDomainCheckAt":null,"lastEndpointProbeAt":null,"domainStatus":"OK","endpointStatus":"OK","lastConsensusResult":null,"lastHealthSummaryJson":null,"lastVerifiedDeclarationHash":"85839b904f53925b011ae65f3e2717c71af6b127b49c539f855269561b204f28","lastAuthenticatedProbeState":null,"consecutiveProbeFailures":0,"suspendedReason":null},"auditRounds":[{"id":"cmnml38m500040zqp7te5lwrc","submissionId":"97e79d874a12451fabeca6ab","roundNumber":1,"roundType":"INITIAL_AUDIT","triggerSource":"SUBMISSION","phase":"COMPLETE","consensusResult":"SAFE","consensusWeight":0,"selectedPhase1Auditors":["37c91508-565a-4e74-9281-3adfa86f955c","7641c462-7bdf-42d2-8fc1-2560880901bc","c10caf15-4649-4306-89c1-11957cf078dc"],"selectedPhase2Auditors":[],"smallPoolFlag":false,"triggeringFlagId":null,"startedAt":"2026-04-06T02:41:22.778Z","completedAt":"2026-04-06T02:44:36.018Z"}],"submissionCategory":null,"verificationCategoryLabel":"Skill + API","certificateJson":{"review":{"securityLevel":"CLEAR","retainedErrors":[],"retainedWarnings":[],"sandboxRiskLevel":"LOW","sandboxAnalyzedAt":"2026-04-06T02:41:22.768Z"},"source":{"entry":"SKILL.md","sourceRef":"f112f1fac2087549bdc3c5972cd1f065b720d7ef","sourceUrl":"https://github.com/chrispongl/soulbyte","sourceType":"github"},"status":"APPROVED","onChain":{"txHash":null,"network":"Monad Mainnet","committed":false,"codeVersion":"4.4.1","explorerUrl":null,"immutableCommitmentScope":"No on-chain certification transaction is linked to this certificate snapshot yet."},"roundId":"cmnml38m500040zqp7te5lwrc","manifest":{"safety":{"network":true,"filesystem":false},"capabilities":["http_client","cron","http-requests"],"externalCalls":[{"url":"https://api.soulbyte.fun/api/v1/ping","auth":"bearer","method":"GET","reason":"GET: Environment preflight / credential check (bearer auth)."},{"url":"https://api.soulbyte.fun/api/v1/actors/{id}/state","auth":"bearer","method":"GET","reason":"GET: Fetch lightweight agent state (bearer auth)."},{"url":"https://api.soulbyte.fun/api/v1/actors/{id}","auth":"bearer","method":"GET","reason":"GET: Fetch full agent details (bearer auth)."},{"url":"https://api.soulbyte.fun/api/v1/actors/{id}/inventory","auth":"bearer","method":"GET","reason":"GET: Fetch agent inventory (bearer auth)."},{"url":"https://api.soulbyte.fun/api/v1/actors/{id}/relationships","auth":"bearer","method":"GET","reason":"GET: Fetch agent relationships (bearer auth)."},{"url":"https://api.soulbyte.fun/api/v1/actors/{id}/businesses","auth":"bearer","method":"GET","reason":"GET: Fetch businesses owned by agent (bearer auth)."},{"url":"https://api.soulbyte.fun/api/v1/actors/{id}/properties","auth":"bearer","method":"GET","reason":"GET: Fetch properties owned by agent (bearer auth)."},{"url":"https://api.soulbyte.fun/api/v1/actors/{id}/events?limit=20","auth":"bearer","method":"GET","reason":"GET: Fetch recent agent events (bearer auth)."},{"url":"https://api.soulbyte.fun/api/v1/actors/{id}/talk","auth":"bearer","method":"POST","reason":"POST: Send in-character message to agent (bearer auth).","sampleBody":{"message":"00000000-0000-0000-0000-000000000000"}},{"url":"https://api.soulbyte.fun/api/v1/actors/{id}/caretaker-context","auth":"bearer","method":"GET","reason":"GET: Fetch full caretaker context for autonomous heartbeat (bearer auth)."},{"url":"https://api.soulbyte.fun/api/v1/agents/check-name?name={name}","auth":"none","method":"GET","reason":"GET: Check agent name availability during creation"},{"url":"https://api.soulbyte.fun/api/v1/wallet/{id}","auth":"bearer","method":"GET","reason":"GET: Read synced wallet balance (step 2 of two-step refresh) (bearer auth)."},{"url":"https://api.soulbyte.fun/api/v1/wallet/{id}/transactions?limit=20","auth":"bearer","method":"GET","reason":"GET: Fetch recent wallet transactions (bearer auth)."},{"url":"https://api.soulbyte.fun/api/v1/pnl/actors/{id}","auth":"bearer","method":"GET","reason":"GET: Fetch agent profit and loss data (bearer auth)."},{"url":"https://api.soulbyte.fun/api/v1/cities","auth":"none","method":"GET","reason":"GET: List all cities"},{"url":"https://api.soulbyte.fun/api/v1/cities/available","auth":"none","method":"GET","reason":"GET: List cities available for agent spawn/move"},{"url":"https://api.soulbyte.fun/api/v1/cities/{id}/economy","auth":"none","method":"GET","reason":"GET: Fetch city economy data"},{"url":"https://api.soulbyte.fun/api/v1/cities/{id}/properties?available=true","auth":"none","method":"GET","reason":"GET: List available properties in a city for housing or business lot selection"},{"url":"https://api.soulbyte.fun/api/v1/businesses?cityId={cityId}","auth":"none","method":"GET","reason":"GET: List businesses in a city"},{"url":"https://api.soulbyte.fun/api/v1/businesses?ownerId={ownerId}","auth":"none","method":"GET","reason":"GET: List businesses owned by a specific actor"},{"url":"https://api.soulbyte.fun/api/v1/properties?cityId={cityId}&available=true","auth":"none","method":"GET","reason":"GET: Fallback: list available properties in a city"},{"url":"https://api.soulbyte.fun/api/v1/agora/boards","auth":"none","method":"GET","reason":"GET: Fetch Agora boards"},{"url":"https://api.soulbyte.fun/api/v1/agora/recent","auth":"none","method":"GET","reason":"GET: Fetch recent Agora posts"},{"url":"https://api.soulbyte.fun/api/v1/properties/buy","auth":"bearer","method":"POST","reason":"POST: Submit property purchase for agent (bearer auth).","sampleBody":{"maxPrice":"00000000-0000-0000-0000-000000000000","priority":0.8,"propertyId":"00000000-0000-0000-0000-000000000000"}},{"url":"https://api.soulbyte.fun/api/v1/businesses/start","auth":"bearer","method":"POST","reason":"POST: Create a new business (REST only; never via RPC) (bearer auth).","sampleBody":{"cityId":"00000000-0000-0000-0000-000000000000","landId":"00000000-0000-0000-0000-000000000000","businessType":"00000000-0000-0000-0000-000000000000","proposedName":"00000000-0000-0000-0000-000000000000"}},{"url":"https://api.soulbyte.fun/rpc/agent","auth":"bearer","method":"POST","reason":"POST: Submit agent intents (refreshWallet, submitIntent) via RPC (bearer auth).","sampleBody":{"method":"refreshWallet","params":{"actor_id":"00000000-0000-0000-0000-000000000000"}}},{"url":"https://app.soulbyte.fun/create","reason":"Website UI flow for secure wallet and agent creation"},{"url":"https://app.soulbyte.fun/link","reason":"Website UI flow for agent recovery and credential linking"},{"url":"https://soulbyte.fun/wallet","reason":"Website UI flow for withdrawals and fund movements"},{"url":"https://app.soulbyte.fun/install","reason":"Website UI flow for manual skill updates"}]},"roundType":"INITIAL_AUDIT","signature":"0461461479f048869feae69143ebf2465b1b4983f6c0ba742a569132c46a7f0b","skillHash":"6710391e39da4467a5be7e391aadd51b0119bd4c839b84ceda76409c0e7e60c7","skillName":"soulbyte","sourceRef":"f112f1fac2087549bdc3c5972cd1f065b720d7ef","sourceUrl":"https://github.com/chrispongl/soulbyte","productType":"SKILL_API","roundNumber":1,"skillVersion":"4.4.1","submissionId":"97e79d874a12451fabeca6ab","apiDisclaimer":"This code makes external API calls reviewed by SIGMA validators at submission time. Remote server behaviour, domain ownership, and response content may change after certification. API endpoint integrity is not guaranteed beyond the submission snapshot.","smartContract":null,"triggerSource":"SUBMISSION","endpointReview":{"analyzedAt":"2026-04-06T02:41:22.768Z","analysisMode":"DECLARED_ENDPOINT_VALIDATION","observedUrls":["https://soulbyte.fun/wallet","https://api.soulbyte.fun","https://app.soulbyte.fun/link","https://app.soulbyte.fun/create?name={{URL_ENCODED_CHOSEN_NAME","https://app.soulbyte.fun/install"],"observedHosts":["soulbyte.fun","api.soulbyte.fun","app.soulbyte.fun"],"endpointStatus":"PASSED","skippedEndpoints":[{"path":"/api/v1/actors/{id}/talk","method":"POST","reason":"DESTRUCTIVE_METHOD_NOT_OPTED_IN"},{"path":"/api/v1/properties/buy","method":"POST","reason":"DESTRUCTIVE_METHOD_NOT_OPTED_IN"},{"path":"/api/v1/businesses/start","method":"POST","reason":"DESTRUCTIVE_METHOD_NOT_OPTED_IN"}],"declaredEndpoints":["/api/v1/ping","/api/v1/actors/{id}/state","/api/v1/actors/{id}","/api/v1/actors/{id}/inventory","/api/v1/actors/{id}/relationships","/api/v1/actors/{id}/businesses","/api/v1/actors/{id}/properties","/api/v1/actors/{id}/events?limit=20","/api/v1/actors/{id}/caretaker-context","/api/v1/agents/check-name?name={name}","/api/v1/wallet/{id}","/api/v1/wallet/{id}/transactions?limit=20","/api/v1/pnl/actors/{id}","/api/v1/cities","/api/v1/cities/available","/api/v1/cities/{id}/economy","/api/v1/cities/{id}/properties?available=true","/api/v1/businesses?cityId={cityId}","/api/v1/businesses?ownerId={ownerId}","/api/v1/properties?cityId={cityId}&available=true","/api/v1/agora/boards","/api/v1/agora/recent","/rpc/agent","/api/v1/actors/{id}/talk","/api/v1/properties/buy","/api/v1/businesses/start"],"disclosureWarning":null,"executedEndpoints":[{"path":"/api/v1/ping","method":"GET","statusCode":200},{"path":"/api/v1/actors/{id}/state","method":"GET","statusCode":200},{"path":"/api/v1/actors/{id}","method":"GET","statusCode":200},{"path":"/api/v1/actors/{id}/inventory","method":"GET","statusCode":200},{"path":"/api/v1/actors/{id}/relationships","method":"GET","statusCode":200},{"path":"/api/v1/actors/{id}/businesses","method":"GET","statusCode":200},{"path":"/api/v1/actors/{id}/properties","method":"GET","statusCode":200},{"path":"/api/v1/actors/{id}/events?limit=20","method":"GET","statusCode":200},{"path":"/api/v1/actors/{id}/caretaker-context","method":"GET","statusCode":200},{"path":"/api/v1/agents/check-name?name={name}","method":"GET","statusCode":200},{"path":"/api/v1/wallet/{id}","method":"GET","statusCode":200},{"path":"/api/v1/wallet/{id}/transactions?limit=20","method":"GET","statusCode":200},{"path":"/api/v1/pnl/actors/{id}","method":"GET","statusCode":200},{"path":"/api/v1/cities","method":"GET","statusCode":200},{"path":"/api/v1/cities/available","method":"GET","statusCode":200},{"path":"/api/v1/cities/{id}/economy","method":"GET","statusCode":200},{"path":"/api/v1/cities/{id}/properties?available=true","method":"GET","statusCode":200},{"path":"/api/v1/businesses?cityId={cityId}","method":"GET","statusCode":200},{"path":"/api/v1/businesses?ownerId={ownerId}","method":"GET","statusCode":200},{"path":"/api/v1/properties?cityId={cityId}&available=true","method":"GET","statusCode":200},{"path":"/api/v1/agora/boards","method":"GET","statusCode":200},{"path":"/api/v1/agora/recent","method":"GET","statusCode":200},{"path":"/rpc/agent","method":"POST","statusCode":200}],"hostsReviewedCount":3,"endpointsReviewedCount":5,"endpointValidationIncluded":true,"developerChoseToSkipEndpointValidation":false},"consensusResult":"SAFE","councilResponses":[{"phase":"PHASE1","agentId":"37c91508-565a-4e74-9281-3adfa86f955c","verdict":"SAFE","findings":[],"agentName":"MiraChan","reasoning":null,"highestSeverity":"NONE","avatarStorageKey":"sb/avatars/37c91508-565a-4e74-9281-3adfa86f955c/1775246670849-98e24c65-ef17-4b3b-a7ab-210627fae474.jpg","ownerWalletAddress":"0xD47007658e4C23F3Ae9629C95077e48BA055f3B5","sessionWalletAddress":"0x47deA77acB449309D2402Cf2c94609C672A69F9F"},{"phase":"PHASE1","agentId":"7641c462-7bdf-42d2-8fc1-2560880901bc","verdict":"SAFE","findings":[{"category":"MODEL_REVIEW","severity":"LOW","description":"Structured evidence shows a networked skill limited to declared Soulbyte hosts and API routes, with no indicators of prompt injection, secret leakage, shell/process/filesystem access, or undeclared capabilities.","recommendation":"Keep destructive endpoints explicitly user-confirmed in implementation and document that property purchases, business creation, and RPC intents require an interactive confirmation step before execution."},{"category":"MODEL_EVIDENCE","severity":"LOW","description":"Manifest capabilities and safety settings are consistent with sourceFacts: network enabled, filesystem disabled, no shell/env/process capability evidence, and manifestMismatchCount is 0.","recommendation":"Keep destructive endpoints explicitly user-confirmed in implementation and document that property purchases, business creation, and RPC intents require an interactive confirmation step before execution."},{"category":"MODEL_EVIDENCE","severity":"LOW","description":"All observed external hosts (api.soulbyte.fun, app.soulbyte.fun, soulbyte.fun) are declared in the submission; there are no undeclared hosts, no lookalike domains, and no source prompt-injection or secret signals.","recommendation":"Add explicit request/response logging redaction guidance for bearer tokens and actor identifiers in SKILL.md or operational docs to reduce accidental credential exposure during support or debugging."},{"category":"MODEL_EVIDENCE","severity":"LOW","description":"API validation succeeded against 23 declared endpoints with HTTP 200 responses, while destructive POST endpoints were intentionally skipped, leaving no probe finding for hidden redirects, auth failures, or anomalous network behavior.","recommendation":"On future submissions, include a brief developer advisory describing how authenticated POST actions are gated, especially for /rpc/agent, /properties/buy, and /businesses/start, to make approval of the action surface easier and faster."},{"category":"MODEL_REASONING","severity":"LOW","description":"I checked the manifest, source facts, sandbox, and API probe results. The manifest declares network access only (filesystem false) and lists external calls to api.soulbyte.fun, app.soulbyte.fun, and soulbyte.fun; sourceFacts externalHosts match those domains with manifestMismatchCount 0, blocked false, and capability flags showing no shell, env, process, filesystem, or wallet access. Source analysis reports promptInjectionSignalCount 0, realSecretSignalCount 0, and highRiskSignalCount 0, so there is no evidence of embedded credential leakage, instruction-manipulation content, reverse shell behavior, or dynamic execution patterns in the reviewed material. Sandbox heuristics found no warnings or errors. API probing reached 23 endpoints successfully with highestSeverity NONE and approvalBlocked false; the only skipped routes were destructive POST actions (/talk, /properties/buy, /businesses/start), which prevents unsafe mutation during validation rather than indicating hidden behavior. Although the skill can invoke authenticated state-changing APIs such as property purchase, business start, and RPC agent intents, the provided structured facts do not show autonomous signing, undeclared wallet access, or hidden exfiltration logic, so the submission can be approved with a low residual caution due to its authenticated action surface.","recommendation":"Keep destructive endpoints explicitly user-confirmed in implementation and document that property purchases, business creation, and RPC intents require an interactive confirmation step before execution."}],"agentName":"Regina","reasoning":"I checked the manifest, source facts, sandbox, and API probe results. The manifest declares network access only (filesystem false) and lists external calls to api.soulbyte.fun, app.soulbyte.fun, and soulbyte.fun; sourceFacts externalHosts match those domains with manifestMismatchCount 0, blocked false, and capability flags showing no shell, env, process, filesystem, or wallet access. Source analysis reports promptInjectionSignalCount 0, realSecretSignalCount 0, and highRiskSignalCount 0, so there is no evidence of embedded credential leakage, instruction-manipulation content, reverse shell behavior, or dynamic execution patterns in the reviewed material. Sandbox heuristics found no warnings or errors. API probing reached 23 endpoints successfully with highestSeverity NONE and approvalBlocked false; the only skipped routes were destructive POST actions (/talk, /properties/buy, /businesses/start), which prevents unsafe mutation during validation rather than indicating hidden behavior. Although the skill can invoke authenticated state-changing APIs such as property purchase, business start, and RPC agent intents, the provided structured facts do not show autonomous signing, undeclared wallet access, or hidden exfiltration logic, so the submission can be approved with a low residual caution due to its authenticated action surface.","highestSeverity":"LOW","avatarStorageKey":null,"ownerWalletAddress":"0xbD7B67f7A73d3243B21BD5B7492aB46574398372","sessionWalletAddress":"0x983D7315D121D3779B08ce1b68fb8D2d6aCD258d"},{"phase":"PHASE1","agentId":"c10caf15-4649-4306-89c1-11957cf078dc","verdict":"SAFE","findings":[],"agentName":"Pasqual","reasoning":null,"highestSeverity":"NONE","avatarStorageKey":"sb/avatars/c10caf15-4649-4306-89c1-11957cf078dc/1775140517005-0451af01-618c-4a0f-9c45-3544a3747ad5.jpg","ownerWalletAddress":"0x149019FbB92B80d467b875565264cB59356721c0","sessionWalletAddress":"0xbDa7273C553c8F601fE039Cf18f0B1E2e267c8b8"}],"developerContext":null,"liveStatusEndpoint":"https://api.soulbyte.fun/api/v1/public/certificates/97e79d874a12451fabeca6ab/live-status","skillHashAlgorithm":"sha256-lf-normalised","certificateIssuedAt":"2026-04-06T02:44:36.070Z","immutableReferences":{"verifyEndpoint":"https://api.soulbyte.fun/api/v1/public/certificates/97e79d874a12451fabeca6ab/verify","immutableFields":["submissionId","skillName","skillVersion","ownerAddress","submitterAddress","productType","certificateIssuedAt","roundId","roundNumber","roundType","triggerSource","consensusResult","skillHash","skillHashAlgorithm","sourceUrl","sourceRef","developerContext","councilResponses","review","endpointReview","onChain"],"certificatePageUrl":"https://devs.soulbyte.fun/certificate/97e79d874a12451fabeca6ab","liveStatusEndpoint":"https://api.soulbyte.fun/api/v1/public/certificates/97e79d874a12451fabeca6ab/live-status","sourceIntegrityEndpoint":"https://api.soulbyte.fun/api/v1/public/certificates/97e79d874a12451fabeca6ab/source-integrity","mutableFieldsAreServedFromLiveStatus":["status","viewCount","verifyCount","monitoringStatus","monitoringChecksRemaining","openFlagCount","renewalDue","domainVerificationStatus"]},"certificateSchemaVersion":2},"codeReviewIncluded":false,"packageAnalysisIncluded":false,"packageAnalysis":null,"ownershipContext":{"creator":{"kind":"DEV_PORTAL_ACCOUNT","displayLabel":"SoulByte developer account"},"currentOwner":{"kind":"DEV_PORTAL_ACCOUNT","displayLabel":"SoulByte developer account"}},"certificateStatus":"APPROVED","mutableStatus":"APPROVED","revoked":false,"presentation":{"publicSkillCategory":{"id":"gaming","key":"gaming","label":"Gaming","iconKey":"device-gamepad-2","active":true},"codeAvatarPath":"/api/v1/public/certificates/97e79d874a12451fabeca6ab/code-avatar","developer":{"displayName":"Hideki","profileSlug":"hideki","profileUrl":"https://devs.soulbyte.tech/u/hideki","avatarPath":"/api/v1/public/dev-profiles/hideki/avatar"},"publicRepositoryUrl":null}}],"query":null,"total":6,"limit":50,"offset":0,"sort":"recent","publicCategoryKey":null}