Agent Plugin Package Check
@sigilcore/plugin-attest creates and verifies tamper-evident records for
Agent Plugin packages. It can also inspect a package for schema and capability
issues. The source repository is private; the reviewed runtime is distributed
publicly through npm.
Install
Use Node.js22.22.2 or later on a supported runtime:
Inspect a package
Sign a package
Set the externally pinned trust configuration and TSA endpoint, then provide an Ed25519 private JWK through a local file:Verify offline
Set the same externally pinned trust values, then verify the complete package:JavaScript API
Install the package locally to use its public profile, attestation, capability, package-schema, snapshot, and trust modules:support@sigilcore.com. Do not attach
private keys, credentials, or private trust material.