Files
librefang-registry/scripts
Evan Hu 74745f1f20 ci: sign plugins-index.json in-repo, drop worker signing dependency
Pair with the worker-side simplification on the librefang PR — the
worker is now a pure transport (no key material, no signing) and this
repo's CI takes over signature production.

scripts/sign-plugins-index.mjs reads REGISTRY_PRIVATE_KEY from a GitHub
Actions secret, signs plugins-index.json with Ed25519, and writes
plugins-index.json.sig alongside it. Aborts loudly when the secret is
missing so a misconfigured CI can't silently ship an unsigned payload.

The workflow now runs build → sign → commit (.json + .sig) → push →
poke worker /refresh. The worker fetches the committed .json + .sig
verbatim and stores both — the daemon then verifies against the
embedded pubkey it ships with.

Closes PR review CRITICAL #1: the worker is no longer a sign-anything
oracle reachable via REGISTRY_REFRESH_TOKEN. Trust root is now this
repo's branch protection + Actions secret scope, not a token any CI
job that can talk to stats.librefang.ai can use to mint signatures.

Note: the keypair was rotated as part of this change (PR not yet
merged so no daemon TOFU pins exist). New pubkey:
  ClGa0Ucap8NdrKAy1rw9Tt6A9I8eg4zJ53+xIuKMuq0=
The plugins-index.json.sig committed here is signed with the matching
new private key, in lockstep with the daemon EMBEDDED_REGISTRY_PUBKEY
constant and all three worker [vars] entries.
2026-05-05 01:02:58 +09:00
..

Scripts

Utility scripts for maintaining the LibreFang registry.

validate.py

Validates all TOML content files across the registry.

python scripts/validate.py

What It Checks

Per content type:

  • Providers -- required fields, valid tiers, non-negative costs, no duplicate model IDs
  • Agents -- required fields (name, description, module), name matches directory
  • Hands -- required fields (id, name, description), valid category, [agent] section, id matches directory
  • Integrations -- required fields (id, name), [transport] section, id matches filename
  • Skills -- [skill] section with name, [runtime] with valid type
  • Plugins -- name matches directory, [hooks] section, hook files exist

Cross-type checks:

  • Routing alias collisions between agents and hands (reported as warnings)
  • Cross-file duplicate model IDs within the same provider

Requirements

  • Python 3.11+ (uses tomllib)
  • Or Python 3.8+ with pip install tomli

Exit Codes

  • 0 -- all checks passed
  • 1 -- one or more validation errors