sponsored-transactions — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited sponsored-transactions (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
# Suiperpower telemetry. Routes through the CLI so projects.json + Convex stay in sync.
# Silent on failure so the skill never blocks. Opt out: SUIPERPOWER_TELEMETRY=off.
#
# AGENT NOTE: when this skill finishes, run the matching completion command:
# suiperpower track sponsored-transactions build completed
# Or use "failed" / "aborted" if it ended that way.
command -v suiperpower >/dev/null 2>&1 && suiperpower track sponsored-transactions build started >/dev/null 2>&1 &
trueIf TEL_PROMPTED is no, before doing real work, ask the user:
Help suiperpower get better. We track which skills get used and how long they take. No code, no file paths, no PII. Change anytime in ~/.suiperpower/config.json.>
A) Sure, anonymous B) No thanks
Write the answer to ~/.suiperpower/config.json telemetryTier field and create ~/.suiperpower/.telemetry-prompted. Then continue.
Sets up sponsored transactions so the project pays gas on behalf of users. Stands up a gas station (self-hosted or third-party), wires the dual-signature flow (sponsor signs the gas, user signs the data), and verifies a real sponsored transaction settles on chain before declaring done. Refuses to ship a stub.
find-next-sui-idea first.scaffold-project first.If you activated this and the user actually wants something else, consult skills/SKILL_ROUTER.md and hand off.
.suiperpower/build-context.md. Read it if present.If unclear, interview the user for:
.suiperpower/build-context.md: ## sponsored-transactions session, <timestamp>
- sponsor address: <0x...>
- sponsor balance source: <faucet | manual | top-up service>
- first sponsored tx digest: <digest>
- allowlist policy: <description>
- rate limit policy: <description>
- open issues: <list>The skill never deletes files outside the integration source path without explicit user confirmation.
.suiperpower/build-context.md if it exists.gasData placeholders.gasData (sponsor's coin, gas budget, sponsor address), signs.senderSig.sponsor and sender are present in the on-chain tx with their addresses..suiperpower/build-context.md..suiperpower/intent.md exists and the session was non-trivial (new sponsored-tx integration, allowlist or rate-limit policy, sponsor key custody choice), recommend verify-against-intent as the next step so the abuse model and dual-signature flow are checked before shipping.intent.md exists and the session was non-trivial, surface that gap once: offer clarify-intent to backfill, do not force it.Before reporting done, the skill asks itself the following and refuses to declare success if any answer is no:
If any answer is no, the skill reports the gap and works through it before claiming the integration is complete.
On-demand references (load when relevant to the user's question):
references/gas-station-flow.md: End-to-end dual-signature flow with code.references/sponsor-pitfalls.md: Abuse vectors, rate-limiting patterns, key custody, replay protection.references/sponsor-allowlist.md: Constructing a tx allowlist that resists obvious bypasses.Knowledge docs (load when scope expands beyond what is in references):
skills/data/sui-knowledge/04-protocols-and-sdks.md: SDK ecosystem context.claude "/suiper:sponsored-transactions <your message>"codex "/sponsored-transactions <your message>"grok, then /sponsored-transactions <your message> in the session~/.cursor/rules/sponsored-transactions.mdc and reference it.If you activated this and the user actually wants something else, consult skills/SKILL_ROUTER.md and hand off.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.