add-matrix — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited add-matrix (Agent Skill) and scored it 96/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 1 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Adds Matrix support via the Chat SDK bridge.
NanoClaw doesn't ship channels in trunk. This skill copies the Matrix adapter in from the channels branch.
Skip to Credentials if all of these are already in place:
src/channels/matrix.ts existssrc/channels/matrix-registration.test.ts existssrc/channels/index.ts contains import './matrix.js';@beeper/chat-adapter-matrix is listed in package.json dependenciesOtherwise continue. Every step below is safe to re-run.
git fetch origin channelsgit show origin/channels:src/channels/matrix.ts > src/channels/matrix.ts
git show origin/channels:src/channels/matrix-registration.test.ts > src/channels/matrix-registration.test.tsAppend to src/channels/index.ts (skip if the line is already present):
import './matrix.js';pnpm install @beeper/[email protected]The adapter's published dist references matrix-js-sdk/lib/... without .js extensions, which fails under Node 22 strict ESM resolution. Add the missing extensions (idempotent — safe to re-run):
node -e '
const fs = require("fs"), path = require("path");
const root = "node_modules/.pnpm";
const dir = fs.readdirSync(root).find(d => d.startsWith("@beeper+chat-adapter-matrix@"));
if (!dir) { console.log("Matrix adapter not installed"); process.exit(0); }
const f = path.join(root, dir, "node_modules/@beeper/chat-adapter-matrix/dist/index.js");
fs.writeFileSync(f, fs.readFileSync(f, "utf8").replace(
/from "(matrix-js-sdk\/lib\/[^"]+?)(?<!\.js)"/g, "from \"$1.js\""
));
console.log("Patched", f);
'Re-run this after every pnpm install that touches the adapter.
pnpm run build
pnpm exec vitest run src/channels/matrix-registration.test.tsBoth must be clean before proceeding. matrix-registration.test.ts is the one integration test: it imports the real channel barrel and asserts the registry contains matrix. It goes red if the import './matrix.js'; line is deleted or drifts, if the barrel fails to evaluate, or if @beeper/chat-adapter-matrix isn't installed (the import throws) — so it also implicitly verifies the dependency from step 4. The adapter also calls core's createChatSdkBridge(...); that typed core-API consumption is guarded by pnpm run build.
End-to-end message delivery against a real Matrix homeserver is verified manually once the service is running — see Next Steps.
The bot needs its own Matrix account — separate from the user's account. This is required because Matrix cannot send DMs to yourself.
andybot on matrix.org)@andybot:matrix.org)Option A: Username + Password (simpler)
No extra steps — just use the bot account's credentials directly. The adapter logs in automatically.
MATRIX_BASE_URL=https://matrix.org
MATRIX_USERNAME=andybot
MATRIX_PASSWORD=your-bot-password
MATRIX_USER_ID=@andybot:matrix.org
MATRIX_BOT_USERNAME=AndyOption B: Access Token (recommended for production)
Get an access token from Element: sign into the bot account → Settings > Help & About > Access Token (under Advanced). Or via API:
curl -XPOST 'https://matrix.org/_matrix/client/r0/login' \
-d '{"type":"m.login.password","user":"andybot","password":"..."}'MATRIX_BASE_URL=https://matrix.org
MATRIX_ACCESS_TOKEN=your-access-token
MATRIX_USER_ID=@andybot:matrix.org
MATRIX_BOT_USERNAME=AndyMATRIX_INVITE_AUTOJOIN=true # Auto-accept room invites (default: true)
MATRIX_INVITE_AUTOJOIN_ALLOWLIST=@you:matrix.org # Only accept invites from these users
MATRIX_RECOVERY_KEY=your-recovery-key # Enable E2EE cross-signing
MATRIX_DEVICE_ID=NANOCLAW01 # Stable device ID across restartsAdd the chosen env vars to .env, then sync:
mkdir -p data/env && cp .env data/env/envIf you're in the middle of /setup, return to the setup flow now.
Otherwise, run /manage-channels to wire this channel to an agent group.
matrix!abc123:matrix.org) and optional aliases (like #general:matrix.org).openDM to resolve the room automatically. For group rooms, in Element click the room name > Settings > Advanced — the "Internal room ID" is the platform ID (starts with !). Or use a room alias like #general:matrix.org.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.