62 packages matching “yotta-vetter”
@yottameta/yotta-vetter
v0.2.3 · 19 days ago
Yuanshen (元审) — the security review protocol before installing any skill: a four-phase checklist (source → code → permissions → risk) + a lightweight checker, with deep-scan handoff to yotta-security-audit. Triggers before installing/evaluating any skill
No known vulnerabilities
@yottameta/yotta-publish-guard
v0.4.1 · 4 days ago
YuanShou (元守) — a generic zero-dependency Python 3.8+ pre-publish release guard (defaults to YottaMeta ownership, customizable to any publishing organization): check (full / github / self modes, optional yotta-security-audit / yotta-vetter / yotta-verify
No known vulnerabilities
@yottameta/yotta-guardian
v0.1.3 · 4 days ago
Yuandun (元盾) — cross-agent dangerous tool-call guardrail: a deterministic rule engine + pluggable intent verifier (model-agnostic) that evaluates exec/write/edit/read/run/shell calls and provides audit logs. Triggers when an agent is about to run a high-r
No known vulnerabilities
@yottameta/yotta-triage
v0.1.2 · 4 days ago
Yuanjian — a zero-dependency static malware triage engine for AI agents: MD5/SHA1/SHA256 hashes, magic-type detection, Shannon entropy, printable strings (ASCII/UTF-16LE) with URL/domain/IP/email/command/path/base64 classification, and PE/ELF header parsi
No known vulnerabilities
@yottameta/yotta-memory
v0.13.2 · 1 day ago
Yuanyi (元忆) — boundary-aware, file-based memory for AI agents. File-based, zero-dependency, diff/rollback-able; FACT/PREF/BOUND/COMMIT types (public shared / private isolated), user-level + project-level storage; v0.12 reliability baseline (init guard, tr
No known vulnerabilities
@yottameta/yotta-skills
v0.19.6 · 1 day ago
YuanGe (元阁) - orchestration routing, inventory, and one-command installer for the YottaMeta skill family (zero dependencies, Node.js only).
No known vulnerabilities
@yottameta/yotta-security-audit
v0.2.3 · 4 days ago
Yuan'an (元安) — detects malicious patterns in AI skills (13 detector classes) and system security baselines (Windows/Linux); purely read-only, zero-dependency and disciplined. Triggers on security audit / skill security check / malicious detection / supply
No known vulnerabilities
pi-vetter
v0.4.1 · 15 days ago
Security vetting for Pi extension packages — evidence-driven evaluation before install/update
No known vulnerabilities
@yottameta/yotta-present
v0.6.2 · 4 days ago
YuanCheng (元呈) — a universal result-presentation layer for AI agents: turn any AI output (JSON / Markdown / plain text) into a standard content object, pick a presentation form (conclusion card / table / checklist / prose / metric board / QA card / report
No known vulnerabilities
@yottameta/yotta-logwatch
v0.2.8 · 4 days ago
Yuancha — a zero-dependency security log analysis & detection engine for AI agents: parses auth/secure, Web access logs (common/combined), PowerShell script-block logs and Windows Event Log (Security/System, key=value / wevtutil text / XML exports) with t
No known vulnerabilities
@yottameta/yotta-workflow
v0.4.1 · 4 days ago
Cross-session / cross-project workflow standard for all AI agents: read the state on start, keep .workflow at the project root, persist logs/tasks/decisions while working, and leave a self-contained handoff anchor on finish. The project root is the state
No known vulnerabilities
@yottameta/yotta-recon
v0.1.6 · 4 days ago
Yuanxi (元析) — cross-agent network recon skill: zero-dependency in-house port/service/version-fingerprint probing (no nmap) for security testing and asset inventory, with built-in authorization discipline (Scope Guard). Triggers when scanning networks/port
No known vulnerabilities
@yottameta/yotta-verify-mcp
v0.4.2 · 3 days ago
YuanXinMCP (元信MCP) - the pre-install security scanner for Agent skills, exposed as a stdio MCP server: scan_skill (dir/package -> verdict + findings), generate_badge (audited badge), gate_check (CI gate), get_report (JSON/Markdown). Local offline static s
No known vulnerabilities
@yottameta/yotta-learn
v0.2.0 · 8 days ago
Yuanxi — a cross-agent learning-loop skill: captures mistakes, corrections and insights as reusable .learnings/ entries for later sessions and skill improvement. Triggers on command failure / user correction / a better approach / a missing capability / an
No known vulnerabilities
@yottameta/yotta-memory-plugin
v0.13.2 · 1 day ago
Yuanyi (元忆) — boundary-aware, file-based memory for AI agents, packaged as a YottaMeta Agent Plugin.
No known vulnerabilities
@yottameta/yotta-verify
v0.3.1 · 3 days ago
YuanXin (元信) — the pre-install security verifier for Agent skills: deterministic static scan (prompt injection + malicious patterns + SKILL.md integrity + permissions) that outputs a verdict and audited badges. Triggers before installing/evaluating any sk
No known vulnerabilities
@yottameta/yotta-security-testing
v0.3.0 · 8 days ago
YuanCe (元测) — a disciplined, authorization-first AI security-testing methodology: a four-stage (recon → discovery → verification → reporting) web security testing workflow on authorized targets (self-owned assets / SRC bug bounty / CTF / local labs), with
No known vulnerabilities
@yottameta/yotta-humanize
v0.2.0 · 8 days ago
Yuanzhen (元真) — AI-flavor remover for Chinese writing: a detector engine (24 rule classes + wordlists + statistical burstiness) that identifies and rewrites AI-typical Chinese text to make it read more naturally. Triggers when editing/polishing text, remo
No known vulnerabilities
@yottameta/yotta-code-quality
v0.4.0 · 9 days ago
Pair-style code quality reviewer: twelve book-grounded decay risks (R1-R6, T1-T6) plus release-safety and first-paint UX checks; Iron Law findings (Symptom -> Source -> Consequence -> Remedy) and 0-100 Health Score.
No known vulnerabilities
@yottameta/yotta-anti-shallow
v1.4.0 · 9 days ago
Anti-shallow AI output rules engine: force analyze-first / execute-after / self-check, curbing superficial output. Activates on intent for deep analysis, end-to-end verification, root-cause tracing, rigorous execution, meticulous checking; also applies au
No known vulnerabilities