Dulcechat — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Dulcechat (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Multi-channel chatbot for DulceGestion - a pastry shop management SaaS.
Channels (in/out) Brain Data
+----------------+ +----------------+ +------------------+
| Telegram |--->| |--->| RAG (docs) |
| Web Widget |--->| Bot Engine |--->| MCP Tools |
| WhatsApp |--->| |--->| Claude LLM |
+----------------+ +----------------+ +------------------+Adapter pattern - each layer has swappable implementations:
TypeScript, Express, telegraf, ws, @anthropic-ai/sdk, @modelcontextprotocol/sdk, Voyage AI (embeddings), vitest
# Install
npm install
# Configure
cp .env.example .env
# Edit .env with your keys
# Index documentation for RAG
npm run index-docs
# Run
npm run dev| Variable | Description |
|---|---|
TELEGRAM_TOKEN | Bot token from @BotFather |
ANTHROPIC_API_KEY | Claude API key |
VOYAGE_API_KEY | Voyage AI key (for embeddings) |
DULCEGESTION_API_URL | DulceGestion API endpoint |
LLM_ADAPTER | claude or hardcoded |
PORT | HTTP server port (default: 3002) |
SESSION_TTL_MINUTES | Chat session timeout |
WIDGET_ALLOWED_ORIGIN | CORS origin for widget |
| Script | Description |
|---|---|
npm run dev | Start with hot reload |
npm start | Start in production |
npm test | Run tests |
npm run index-docs | Generate RAG embeddings from docs/flows/ |
npm run mcp | Start MCP stdio server (for Claude Desktop/Code) |
Use with Claude Desktop or Claude Code:
{
"mcpServers": {
"dulcegestion": {
"command": "npx",
"args": ["tsx", "src/mcp/server.ts"],
"cwd": "/path/to/dulcechat",
"env": {
"DULCEGESTION_API_URL": "http://localhost:3001/api",
"DULCEGESTION_AUTH_TOKEN": "your-jwt-token"
}
}
}
}Add to any page:
<script src="https://your-server/dulcechat/widget.js" data-token="USER_JWT"></script>src/
channels/ # Messaging adapters (Telegram, Web, WhatsApp)
llm/ # LLM adapters (Claude, hardcoded)
mcp/ # MCP tools and server
tools/ # Individual tool implementations
rag/ # RAG system (chunker, embeddings, retriever)
session/ # In-memory session store with TTL
engine.ts # Core orchestrator
index.ts # Entry point
docs/flows/ # User documentation for RAG indexing
widget/ # Embeddable chat widget (HTML + JS)src/mcp/tools/your-tool.ts implementing McpToolsrc/index.ts~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.