setup-chip — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited setup-chip (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Use this skill for CHIP Collect payment integration work.
Read references/chip-collect-docs.md before giving factual API guidance or writing integration code. It contains all downloaded CHIP Collect markdown pages plus embedded OpenAPI blocks from:
https://docs.chip-in.asia/chip-collect/overview/introduction
Read references/account-setup.md when user asks how to register, which API keys are needed, where credentials come from, or what dashboard setup is required.
https://gate.chip-in.asia/api/v1/Authorization: Bearer <secret key> for every request.price: 100 equals RM 1.00.POST /purchases/, then use response checkout_url.GET /purchases/{id}/, or webhook events.4444 3333 2222 1111 non-3DS, 5555 5555 5555 4444 3DS, CVC 123, expiry >= current month/year.X-Signature is base64 RSA PKCS#1 v1.5 over SHA256 digest of raw request body.GET /public_key/; webhook public key: Webhook.public_key.GET /payment_methods/, usually with brand_id and currency.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.