HelloFugu

Skills

Your agent installs code. Somebody should have read it first.

An agent gains its abilities by installing add-ons from open sources nobody checks. That is a live attack surface: instructions hidden inside a tool description that hijack the agent, a price checker that quietly reads your keys, a clean first version followed by a poisoned second one. One bad add-on empties the wallet, and the agent does it to itself.

So an auditor puts money down, reads a build, is paid when the verdict stands, and loses the money when it does not. Below, every add-on carries what is actually known about it, and five of the seven states are ways of not knowing.

Curated examples. The registry answered, and it holds nothing that matches.

These records are curated EXAMPLES shipped with the backend to exercise every audit status. They are not real skills, authors, or auditors, and nothing here is installable. Every example carries example: true and an id prefixed with 'example-'. Every record below carries an example tag and an id beginning example-. Nothing here is installable, and no author or auditor named below is a real one.

How it got here
  1. 1the skill registry, answered, but empty, 0 items
  2. 2bundled examples, answered, 2 itemsThese records are curated EXAMPLES shipped with the backend to exercise every audit status. They are not real skills, authors, or auditors, and nothing here is installable. Every example carries example: true and an id prefixed with 'example-'.

Every skill on record

  • Never auditedexample

    Gas Estimator (example, never audited)

    Plugin · v0.3.1 · Fugugent example author

    Nobody has ever audited this skill. We know nothing about what it does.

    Declares: Estimates the gas cost of a transaction from recent base fees. Nobody has requested an audit of this skill, which is why it appears as UNAUDITED rather than as safe.

    FreeSee what we know →
  • Audit requestedexample

    Log Shipper (example, RFQ open)

    Plugin · v1.1.0 · Fugugent example author

    An audit has been funded, and no auditor has produced a verdict yet.

    Declares: Ships agent run logs to a configured HTTPS endpoint. An audit has been requested and funded, but no auditor has been selected yet, so there is no verdict to report.

    $15.00 / versionRead the audit →

Seven statuses, and only one of them means safe

Colour is never the only difference between two of them: each has its own wording, its own glyph and its own border texture, so the seven stay seven in grayscale as well.

The status is worked out from the audits actually held. There is no column anywhere that a publisher, an auditor or this page could write by hand.

We checked, and it is clean1 of 7

  • Passed audit

    The only status that means safe. The audited digest equals the digest being served, and the evidence is held.

We checked, and it is dangerous1 of 7

  • Failed audit

    Knowledge, not ignorance. This build was examined and found harmful, a different thing from never having been looked at.

We do not know5 of 7

  • Audit is for an older build

    The rug-pull shape: a clean v1 followed by a v2 nobody checked. A verdict is bound to the digest it examined and does not travel.

  • Audit inconclusive

    An audit that reached no verdict has still told us something real, and it is not rounded to either clean or dangerous.

  • Audit running

    Work in progress is not a result. A partial pipeline clears nothing.

  • Audit requested

    Money put at stake is a promise about the future, not a statement about the code.

  • Never audited

    The default state of everything on an open registry, and the state most installs happen in today.