42,828 packages matching “yotta-verify”
@yottameta/yotta-verify
v0.3.1 · 3 days ago
YuanXin (元信) — the pre-install security verifier for Agent skills: deterministic static scan (prompt injection + malicious patterns + SKILL.md integrity + permissions) that outputs a verdict and audited badges. Triggers before installing/evaluating any sk
No known vulnerabilities
@yottameta/yotta-publish-guard
v0.4.1 · 4 days ago
YuanShou (元守) — a generic zero-dependency Python 3.8+ pre-publish release guard (defaults to YottaMeta ownership, customizable to any publishing organization): check (full / github / self modes, optional yotta-security-audit / yotta-vetter / yotta-verify
No known vulnerabilities
@yottameta/yotta-verify-mcp
v0.4.2 · 3 days ago
YuanXinMCP (元信MCP) - the pre-install security scanner for Agent skills, exposed as a stdio MCP server: scan_skill (dir/package -> verdict + findings), generate_badge (audited badge), gate_check (CI gate), get_report (JSON/Markdown). Local offline static s
No known vulnerabilities
@yottameta/yotta-verify-mcp-plugin
v0.4.2 · 3 days ago
YuanXinMCP (元信MCP) — pre-install security scanning for Agent skills, packaged as a YottaMeta Agent Plugin.
No known vulnerabilities
@yottameta/yotta-guardian
v0.1.3 · 4 days ago
Yuandun (元盾) — cross-agent dangerous tool-call guardrail: a deterministic rule engine + pluggable intent verifier (model-agnostic) that evaluates exec/write/edit/read/run/shell calls and provides audit logs. Triggers when an agent is about to run a high-r
No known vulnerabilities
@yottameta/yotta-triage
v0.1.2 · 4 days ago
Yuanjian — a zero-dependency static malware triage engine for AI agents: MD5/SHA1/SHA256 hashes, magic-type detection, Shannon entropy, printable strings (ASCII/UTF-16LE) with URL/domain/IP/email/command/path/base64 classification, and PE/ELF header parsi
No known vulnerabilities
@yottameta/yotta-memory
v0.13.2 · 1 day ago
Yuanyi (元忆) — boundary-aware, file-based memory for AI agents. File-based, zero-dependency, diff/rollback-able; FACT/PREF/BOUND/COMMIT types (public shared / private isolated), user-level + project-level storage; v0.12 reliability baseline (init guard, tr
No known vulnerabilities
@yottameta/yotta-skills
v0.19.6 · 1 day ago
YuanGe (元阁) - orchestration routing, inventory, and one-command installer for the YottaMeta skill family (zero dependencies, Node.js only).
No known vulnerabilities
@yottameta/yotta-secret
v0.2.0 · 8 days ago
Yuanyao — a zero-dependency secret & credential leak scanner for AI agents: scans source code, config files, .env and git history for cloud API keys, private keys, credential assignments, URL-embedded credentials and high-entropy tokens using regex + entr
No known vulnerabilities
@yottameta/yotta-security-audit
v0.2.3 · 4 days ago
Yuan'an (元安) — detects malicious patterns in AI skills (13 detector classes) and system security baselines (Windows/Linux); purely read-only, zero-dependency and disciplined. Triggers on security audit / skill security check / malicious detection / supply
No known vulnerabilities
@yottameta/yotta-vetter
v0.2.3 · 19 days ago
Yuanshen (元审) — the security review protocol before installing any skill: a four-phase checklist (source → code → permissions → risk) + a lightweight checker, with deep-scan handoff to yotta-security-audit. Triggers before installing/evaluating any skill
No known vulnerabilities
@yottameta/yotta-present
v0.6.2 · 4 days ago
YuanCheng (元呈) — a universal result-presentation layer for AI agents: turn any AI output (JSON / Markdown / plain text) into a standard content object, pick a presentation form (conclusion card / table / checklist / prose / metric board / QA card / report
No known vulnerabilities
@yottameta/yotta-logwatch
v0.2.8 · 4 days ago
Yuancha — a zero-dependency security log analysis & detection engine for AI agents: parses auth/secure, Web access logs (common/combined), PowerShell script-block logs and Windows Event Log (Security/System, key=value / wevtutil text / XML exports) with t
No known vulnerabilities
@yottameta/yotta-workflow
v0.4.1 · 4 days ago
Cross-session / cross-project workflow standard for all AI agents: read the state on start, keep .workflow at the project root, persist logs/tasks/decisions while working, and leave a self-contained handoff anchor on finish. The project root is the state
No known vulnerabilities
@yottameta/yotta-chain
v0.1.2 · 20 days ago
Yuanlian — a zero-dependency supply-chain dependency validator for AI agents: detects dependency confusion (private package names resolved from public registries, mixed registries, suspicious registry URLs), lockfile consistency issues (missing entries, u
No known vulnerabilities
@yottameta/yotta-recon
v0.1.6 · 4 days ago
Yuanxi (元析) — cross-agent network recon skill: zero-dependency in-house port/service/version-fingerprint probing (no nmap) for security testing and asset inventory, with built-in authorization discipline (Scope Guard). Triggers when scanning networks/port
No known vulnerabilities
@yottameta/yotta-learn
v0.2.0 · 8 days ago
Yuanxi — a cross-agent learning-loop skill: captures mistakes, corrections and insights as reusable .learnings/ entries for later sessions and skill improvement. Triggers on command failure / user correction / a better approach / a missing capability / an
No known vulnerabilities
@yottameta/yotta-memory-plugin
v0.13.2 · 1 day ago
Yuanyi (元忆) — boundary-aware, file-based memory for AI agents, packaged as a YottaMeta Agent Plugin.
No known vulnerabilities
@yottameta/yotta-security-testing
v0.3.0 · 8 days ago
YuanCe (元测) — a disciplined, authorization-first AI security-testing methodology: a four-stage (recon → discovery → verification → reporting) web security testing workflow on authorized targets (self-owned assets / SRC bug bounty / CTF / local labs), with
No known vulnerabilities
@sigstore/verify
v4.1.2 · 1 month ago
Verification of Sigstore signatures
No known vulnerabilities