register-on-dashclaw — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited register-on-dashclaw (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Register any AI agent as a governed entity on a DashClaw instance. This includes the meta act of registering this very agent on DashClaw.
curl -X POST "$DASHCLAW_BASE_URL/api/agents" \
-H "x-api-key: $DASHCLAW_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"agent_id": "my-agent",
"agent_name": "My Agent",
"description": "What this agent does",
"capabilities": ["deploy", "api_call", "file_write"]
}'import { DashClaw } from 'dashclaw';
const claw = new DashClaw({
baseUrl: process.env.DASHCLAW_BASE_URL,
apiKey: process.env.DASHCLAW_API_KEY,
agentId: 'my-agent'
});
// Agent is auto-registered on first guard call or action creation
// Explicit registration is optional but recommended for metadataHeartbeats let DashClaw know your agent is alive. Missing heartbeats trigger the "Agent Silent" signal (>10 min).
// Single heartbeat
await claw.heartbeat({ status: 'online', metadata: { version: '1.0.0' } });
// Auto-heartbeat (v1 SDK)
import { DashClaw } from 'dashclaw/legacy';
const claw = new DashClaw({ baseUrl, apiKey, agentId: 'my-agent' });
claw.startHeartbeat({ interval: 60000 }); // Every 60 seconds
// Stop when shutting down
claw.stopHeartbeat();# Python
claw.heartbeat(status="online", metadata={"version": "1.0.0"})Scope guard policies to a specific agent:
curl -X POST "$DASHCLAW_BASE_URL/api/policies" \
-H "x-api-key: $DASHCLAW_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"name": "my-agent-deploy-gate",
"agent_id": "my-agent",
"type": "approval_gate",
"mode": "enforce",
"conditions": {
"action_types": ["deploy"],
"risk_score_min": 50
},
"action": "require_approval",
"reason": "All deploys by my-agent require approval"
}'For production, register your agent's public key for action signing:
// V1 SDK — register identity
import { DashClaw } from 'dashclaw/legacy';
const claw = new DashClaw({ baseUrl, apiKey, agentId: 'my-agent' });
await claw.registerIdentity({
publicKeyPem: myPublicKey,
algorithm: 'Ed25519',
agentName: 'My Agent'
});
// Revoke an identity when agent is decommissioned
await claw.revokeIdentity('my-agent');Signature enforcement is runtime-toggleable from /settings?tab=identity. When enabled, all actions must be signed with the registered key.
If the DashClaw instance has DASHCLAW_CLOSED_ENROLLMENT=true, agents must be pre-registered before they can call guard or create actions. Register first, then instrument.
This agent — dashclaw-agent — can be registered on DashClaw as a governed agent. Here's how:
export DASHCLAW_BASE_URL=http://localhost:3000
export DASHCLAW_API_KEY=your-api-key
export DASHCLAW_AGENT_ID=dashclaw-agentcurl -X POST "$DASHCLAW_BASE_URL/api/agents" \
-H "x-api-key: $DASHCLAW_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"agent_id": "dashclaw-agent",
"agent_name": "DashClaw Agent",
"description": "The definitive DashClaw expert. Helps developers integrate, configure, troubleshoot, and build DashClaw. Governs itself on DashClaw.",
"capabilities": ["sdk-integration", "policy-creation", "troubleshooting", "codebase-contribution", "compliance", "drift-detection"]
}'# The agent that governs agents should govern itself
curl -X POST "$DASHCLAW_BASE_URL/api/policies" \
-H "x-api-key: $DASHCLAW_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"name": "dashclaw-agent-self-governance",
"agent_id": "dashclaw-agent",
"type": "risk_threshold",
"mode": "enforce",
"conditions": { "risk_score_min": 70 },
"action": "require_approval",
"reason": "DashClaw agent practices what it preaches — high-risk actions require approval"
}'If running this agent in Claude Code, install the pretool/posttool hooks (see setup-dashclaw skill) so every tool call is governed by DashClaw.
const claw = new DashClaw({
baseUrl: process.env.DASHCLAW_BASE_URL,
apiKey: process.env.DASHCLAW_API_KEY,
agentId: 'dashclaw-agent'
});
// Report presence
await claw.heartbeat({ status: 'online', metadata: {
version: '1.0.0',
type: 'gitagent',
skills: 8,
meta: 'I govern myself on the platform I help build'
}});An agent that governs agents, governed by the platform it represents. That's DashClaw.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.