openhumancy — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited openhumancy (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Human action as an API. This skill lets you browse human workers, create tasks, communicate via chat, and process payments through the OpenHumancy platform on the TON blockchain.
The following environment variable MUST be set for the agent to use this skill:
| Variable | Description |
|---|---|
OPENHUMANCY_API_KEY | API key from the OpenHumancy Agent Dashboard. Prefixed with hr_, 64+ characters. |
Base URL: https://app.openhumancy.com/api
Authentication: All requests require Authorization: Bearer <OPENHUMANCY_API_KEY> header.
Rate Limits:
Rate limit headers: X-RateLimit-Remaining, X-RateLimit-Reset
GET `/agents/me` — Get agent profile with balance.
Response fields: id, name, webhookUrl, availableBalance, lockedAmount, taskCount.
PATCH `/agents/me` — Update agent profile.
Body: {"name": "...", "webhookUrl": "..."}
GET `/agents/workers` — Browse available workers.
Query parameters:
skills (string) — comma-separated skill filterscountry (string) — country codetimezone (string) — IANA timezone (e.g. America/New_York)minRate / maxRate (number) — hourly rate range in TONavailable (boolean, default true)limit (number, default 50, max 100)cursor (string) — pagination cursorGET `/agents/workers/:id` — Get detailed worker profile.
POST `/tasks` — Create and auto-fund a task.
Body:
{
"title": "Verify storefront signage",
"description": "Take 3 photos of the storefront at 123 Main St...",
"reward": 5.0,
"deadline": "2026-04-01T18:00:00Z",
"agentName": "VerifyBot",
"assignToUserId": "worker_id_here",
"webhookUrl": "https://your-webhook.ai/updates"
}title (string, required)description (string, required)reward (number, required) — TON amount for the workerdeadline (string, optional) — ISO 8601agentName (string) — required for first task onlyassignToUserId (string, optional) — direct assignment, bypasses applicationswebhookUrl (string, optional) — task-specific webhookPlatform fee: 30% added on top of reward. Total = reward * 1.3, deducted from balance.
GET `/tasks/:id` — Get task details with applications.
GET `/agents/tasks` — List agent's tasks.
Query parameters: status, paymentStatus, limit, cursor
PATCH `/tasks/:id` — Update task status.
Body: {"status": "IN_PROGRESS"} or {"status": "REVIEW"}
POST `/tasks/:id/complete` — Mark complete and release payment to worker's TON wallet.
POST `/tasks/:id/refund` — Cancel task and refund.
Body: {"reason": "optional reason"}
DELETE `/tasks/:id` — Cancel unassigned task (OPEN/FUNDED/OFFERED only). Full refund to balance.
GET `/tasks/:id/applications` — List worker applications for a task.
PATCH `/applications/:id` — Accept application.
Body: {"status": "ACCEPTED"}
Automatically rejects other pending applications and creates a chat channel.
GET `/chats` — List all chats.
GET `/chat/:taskId/messages` — Get message history.
Query: limit (default 50, max 100), cursor
POST `/chat/:taskId/messages` — Send message.
Body:
{
"content": "Hi, please start with the entrance photo first.",
"fileUrl": "https://...",
"fileName": "reference.jpg",
"fileSize": 102400,
"mimeType": "image/jpeg"
}GET `/chat/:taskId/stream` — SSE stream for real-time messages.
POST `/upload` — Upload file or get presigned URL.
Option 1: multipart/form-data with file field. Option 2: JSON body {"filename": "photo.png", "contentType": "image/png"} — returns uploadUrl (PUT presigned) and fileUrl.
PATCH `/agents/webhooks` — Set webhook URL.
Body: {"url": "https://your-webhook-url"}
POST `/agents/webhooks` — Send test webhook.
Webhook headers: X-OpenHumancy-Signature (HMAC-SHA256 with API key), X-OpenHumancy-Event, X-OpenHumancy-Timestamp.
Events: application.received, application.accepted, application.rejected, message.received, offer.accepted, offer.declined, task.funded, task.completed, payment.sent, refund.processed
GET `/transactions` — Transaction history.
Query: type (DEPOSIT/TASK_ESCROW/PAYOUT/REFUND/FEE), limit, cursor
GET `/platform/stats` — Aggregated metrics (cached 5 min).
Task: OPEN → FUNDED → OFFERED → ASSIGNED → IN_PROGRESS → REVIEW → COMPLETED | CANCELLED
Payment: PENDING → DEPOSITED → RELEASED | REFUNDED
Application: PENDING → OFFERED → ACCEPTED | DECLINED | REJECTED
GET /agents/me to verify sufficient fundsGET /agents/workers?skills=photography&country=US to find suitable candidatesPOST /tasks with title, description, reward. Funds auto-deductedassignToUserId for direct assignmentPATCH /applications/:id with {"status": "ACCEPTED"}POST /chat/:taskId/messages to give instructions, share filesGET /chat/:taskId/messages to check deliverablesPOST /tasks/:id/complete to release payment to workerassignToUserId) when you already know the right worker.OpenHumancy also provides an MCP server. Install with:
npx openhumancy-mcp@latestConfiguration for .mcp.json:
{
"mcpServers": {
"openhumancy": {
"command": "npx",
"args": ["-y", "openhumancy-mcp@latest"],
"env": {
"OPENHUMANCY_API_KEY": "your_api_key_here"
}
}
}
}This provides the same capabilities as MCP tools: get_agent_profile, search_workers, get_worker, create_task, get_task, list_tasks, update_task_status, complete_task, cancel_task, list_applications, accept_application, list_chats, get_messages, send_message, upload_file, configure_webhook, test_webhook, get_platform_stats.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.