Pair with the worker-side simplification on the librefang PR — the worker is now a pure transport (no key material, no signing) and this repo's CI takes over signature production. scripts/sign-plugins-index.mjs reads REGISTRY_PRIVATE_KEY from a GitHub Actions secret, signs plugins-index.json with Ed25519, and writes plugins-index.json.sig alongside it. Aborts loudly when the secret is missing so a misconfigured CI can't silently ship an unsigned payload. The workflow now runs build → sign → commit (.json + .sig) → push → poke worker /refresh. The worker fetches the committed .json + .sig verbatim and stores both — the daemon then verifies against the embedded pubkey it ships with. Closes PR review CRITICAL #1: the worker is no longer a sign-anything oracle reachable via REGISTRY_REFRESH_TOKEN. Trust root is now this repo's branch protection + Actions secret scope, not a token any CI job that can talk to stats.librefang.ai can use to mint signatures. Note: the keypair was rotated as part of this change (PR not yet merged so no daemon TOFU pins exist). New pubkey: ClGa0Ucap8NdrKAy1rw9Tt6A9I8eg4zJ53+xIuKMuq0= The plugins-index.json.sig committed here is signed with the matching new private key, in lockstep with the daemon EMBEDDED_REGISTRY_PUBKEY constant and all three worker [vars] entries.
Scripts
Utility scripts for maintaining the LibreFang registry.
validate.py
Validates all TOML content files across the registry.
python scripts/validate.py
What It Checks
Per content type:
- Providers -- required fields, valid tiers, non-negative costs, no duplicate model IDs
- Agents -- required fields (name, description, module), name matches directory
- Hands -- required fields (id, name, description), valid category, [agent] section, id matches directory
- Integrations -- required fields (id, name), [transport] section, id matches filename
- Skills -- [skill] section with name, [runtime] with valid type
- Plugins -- name matches directory, [hooks] section, hook files exist
Cross-type checks:
- Routing alias collisions between agents and hands (reported as warnings)
- Cross-file duplicate model IDs within the same provider
Requirements
- Python 3.11+ (uses
tomllib) - Or Python 3.8+ with
pip install tomli
Exit Codes
0-- all checks passed1-- one or more validation errors