setup-api-key — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited setup-api-key (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Guide the user through obtaining and configuring a Vapi API key for the voice AI platform.
Tell the user:
To set up Vapi, open the API keys page in the Vapi Dashboard: https://dashboard.vapi.ai/org/api-keys
>
(Need an account? Create one at https://dashboard.vapi.ai/signup first)
>
If you don't have an API key yet: 1. Click "Create Key" 2. Name your key (e.g., "development") 3. Copy the key immediately — it is only shown once
>
Paste your API key here when ready.
Then wait for the user's next message which should contain the API key.
Once the user provides the API key:
curl -s -o /dev/null -w "%{http_code}" https://api.vapi.ai/assistant \
-H "Authorization: Bearer <the-api-key>"Check if a .env file exists. If so, append to it. If not, create one:
VAPI_API_KEY=<the-api-key>Your Vapi API key is configured and stored in.envasVAPI_API_KEY.
>
You can now use Vapi's API to create assistants, make calls, and build voice AI agents.
>
Keep this key safe — do not commit it to version control.
Check if .gitignore exists and contains .env. If not, add it:
.envAll Vapi skills expect the API key in the VAPI_API_KEY environment variable. The base URL for all API requests is:
https://api.vapi.aiAuthentication is via Bearer token:
Authorization: Bearer $VAPI_API_KEYThis skills repository includes a Vapi documentation MCP server (vapi-docs) that gives your AI agent access to the full Vapi knowledge base. Use the searchDocs tool to look up anything beyond what this skill covers — advanced configuration, troubleshooting, SDK details, and more.
Auto-configured: If you cloned or installed these skills, the MCP server is already configured via .mcp.json (Claude Code), .cursor/mcp.json (Cursor), or .vscode/mcp.json (VS Code Copilot).
Manual setup: If your agent doesn't auto-detect the config, run:
claude mcp add vapi-docs -- npx -y mcp-remote https://docs.vapi.ai/_mcp/serverSee the README for full setup instructions across all supported agents.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.