vault-ipc — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited vault-ipc (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Unified Unix socket replacing the old two-socket model (x402-signer.sock + openmm-creds.sock).
/tmp/openmm.sock (override via OPENMM_SOCKET env var)0600 (owner-only)openmm serve after interactive vault unlockJSON messages over the socket, dispatched by type:
{ "type": "sign_payment", "payload": {} }
→ { "signature": "0x..." }
{ "type": "get_credentials", "exchange": "mexc" }
→ { "apiKey": "...", "secret": "..." }
{ "type": "ping" }
→ { "status": "ok", "wallet": "0x...", "exchanges": ["mexc", "gateio"] }Private key is decrypted inline, used once, and goes out of scope immediately. It is NEVER held in a long-lived variable.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.