bolthub — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited bolthub (Plugin) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Source code for every publicly published bolthub.ai package — the npm @bolthub/* scope and the bolthub / bolthub-verify PyPI packages.
bolthub is an API marketplace where AI agents discover and pay for HTTP APIs per-call over Lightning (L402). These packages are the client side of that: payment clients, MCP servers, a CLI, and origin-verification middleware.
| Package | Registry | Directory | What it is |
|---|---|---|---|
@bolthub/agent | npm | packages/agent | L402 payment client — wallet adapters (LND, LNbits, Phoenixd, NWC, WebLN), 402 challenge handling, session cache |
@bolthub/mcp-registry | npm | packages/mcp-registry | MCP server exposing the whole bolthub marketplace to AI agents |
@bolthub/mcp-bridge | npm | packages/mcp-bridge | MCP server for a single bolthub gateway (one tool per endpoint) |
@bolthub/cli | npm | packages/cli | Terminal client for the marketplace |
@bolthub/verify | npm | packages/verify | Gateway signature verification middleware (Express/Fastify/Node) |
bolthub | PyPI | packages/agent-python | Python L402 client |
bolthub-verify | PyPI | packages/verify-python | Python gateway signature verification (Flask/Django/FastAPI) |
packages/shared is internal (never published); it is here because @bolthub/mcp-bridge bundles it.
The bolthub platform (gateway, API, web app) lives in a private monorepo. The SDK packages above are developed there and synced to this repository, which is the publish origin: releases are tagged here and built + published by CI with npm provenance, so what's on npm is verifiably built from this public source.
Issues and PRs are welcome here. Accepted changes are applied to the monorepo first, then sync back out with the next release.
Published dist/ bundles are built with Bun from this source and ship source maps with embedded sources, so the tarball itself is readable.
# provenance: confirm the tarball was built from this repo by GitHub Actions
npm audit signatures
# or rebuild and compare yourself
git clone https://github.com/signaltech-org/bolthub-sdk
cd bolthub-sdk && bun install
cd packages/mcp-registry && bun run buildSee SECURITY.md for the trust model (what touches your wallet credentials and what doesn't) and how to report vulnerabilities.
bun install
bun testEach TypeScript package builds with bun run build from its directory (@bolthub/agent must be built before the packages that bundle it).
MIT
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.