by VibeTensor
Attestix - Attestation Infrastructure for AI Agents. DID-based agent identity, W3C Verifiable Credentials, EU AI Act compliance layer, delegation chains, and reputation scoring. 47 MCP tools across 9 modules.
# Add to your Claude Code skills
git clone https://github.com/VibeTensor/attestixSee how attestix compares with popular alternatives.
attestix is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by VibeTensor. Attestix - Attestation Infrastructure for AI Agents. DID-based agent identity, W3C Verifiable Credentials, EU AI Act compliance layer, delegation chains, and reputation scoring. 47 MCP tools across 9 modules. It has 577 GitHub stars.
attestix's catalog security scan is still queued. You can run an instant dependency and prompt-injection check now with the "Scan for vulnerabilities" button above.
Clone the repository with "git clone https://github.com/VibeTensor/attestix" and add it to your Claude Code skills directory (see the Installation section above).
attestix is primarily written in Python. It is open-source under VibeTensor on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh attestix against similar tools.
No comments yet. Be the first to share your thoughts!
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
The deep catalog scan for this skill is still queued. Run an instant dependency check now instead.
# Stable 0.4.0:
pip install attestix
# Pre-release 0.4.1rc1 (opt in with --pre):
pip install --pre attestix
Stable 0.4.0 ships only the canonical
attestix.*namespace. The older flat layout (from services... import,from auth... import, ...) keeps working via thin deprecation shims that emit aDeprecationWarningon first import and are scheduled for removal in v0.5.0. Update imports tofrom attestix.services... importat your earliest convenience.
attestix status # System overview
attestix init --name MyBot # Create agent identity
attestix compliance <agent-id> # Check EU AI Act compliance
attestix verify <agent-id> # Verify identity cryptographically
attestix audit <agent-id> # View hash-chained audit trail
attestix credential --list # List W3C Verifiable Credentials
pip install fastapi uvicorn
uvicorn attestix.api.main:app --reload # Swagger docs at http://localhost:8000/docs
pip install streamlit
streamlit run demo/webapp/app.py # Opens at http://localhost:8501
python examples/quickstart.py # Full 9-module workflow in 0.1 seconds
Attestix credentials are issued once (Python core or cloud) and verify
anywhere. Six independent verifier implementations share one conformance
suite (spec/verify/v1): verify offline, no Python runtime, zero trust in the
issuer. The verifiers are verifier-only: issuance stays in the Python core.
| Language | Install | Status |
|---|---|---|
| Python | pip install attestix |
live (full lib: issue + verify) |
| JS / TS | npm install attestix |
live (attestix-js) |
| Go | go get github.com/VibeTensor/attestix-go |
live (attestix-go) |
| Rust | cargo add attestix |
live (attestix-rs) |
| Java | com.vibetensor:attestix:0.4.0 |
publishing soon (attestix-java) |
| R | install.packages("attestix") |
coming to CRAN (attestix-r) |
Every verifier checks the same canonical-JSON form (RFC 8785)
and Ed25519 signatures (RFC 8032) against
the shared spec/verify/v1
vectors. Verify in the browser at https://attestix.io/verify, or read the
bundle wire-format at https://attestix.io/spec/bundle/v1.
On August 2, 2026, the EU AI Act enforcement begins. Fines reach EUR 35M or 7% of global revenue.
Existing compliance tools (Credo AI, Holistic AI, Vanta) are organizational dashboards. None produce machine-readable, cryptographically verifiable proof that an AI agent can present to another agent, regulator, or system.
Agent identity is fragmenting across walled gardens (Microsoft Entra, AWS AgentCore, Google A2A, ERC-8004). No single tool combines agent identity + EU AI Act compliance + verifiable credentials in one protocol.
Attestix fills this gap.
| Module | Tools | What it does |
|---|---|---|
| Identity | 8 | Unified Agent Identity Tokens (UAITs) bridging MCP OAuth, A2A, DIDs, and API keys. GDPR Article 17 erasure |
| Agent Cards | 3 | Parse, generate, and discover A2A-compatible agent cards |
| DID | 3 | Create and resolve W3C Decentralized Identifiers (did:key, did:web) |
| Delegation | 4 | UCAN-style capability delegation with EdDSA-signed JWT tokens |
| Reputation | 3 | Recency-weighted trust scoring (0.0 - 1.0) with category breakdown |
| Compliance | 7 | EU AI Act risk profiles, conformity assessments (Article 43), Annex V declarations |
| Credentials | 8 | W3C Verifiable Credentials with Ed25519Signature2020 proofs, presentations |
| Provenance | 5 | Training data provenance (Article 10), model lineage (Article 11), hash-chained audit trail (Article 12) |
| Blockchain | 6 | Anchor artifact hashes to Base L2 via Ethereum Attestation Service, Merkle batching |
Add to your Claude Code config (~/.claude.json):
{
"mcpServers": {
"attestix": {
"type": "stdio",
"command": "python",
"args": ["-m", "attestix.main"]
}
}
}
Then ask Claude:
"Create an identity for my data analysis agent with capabilities: data_analysis, reporting"
from attestix.services.identity_service import IdentityService
from attestix.services.compliance_service import ComplianceService
from attestix.services.credential_service import CredentialService
identity_svc = IdentityService()
compliance_svc = ComplianceService()
credential_svc = CredentialService()
# 1. Create an agent identity
agent = identity_svc.create_identity(
display_name="MyAgent",
source_protocol="manual",
capabilities=["data_analysis", "reporting"],
description="Analyzes quarterly financial data",
issuer_name="VibeTensor",
expiry_days=365,
)
agent_id = agent["agent_id"] # attestix:f9bdb7a94ccb40f1
agent_did = agent["issuer"]["did"] # did:key:z6Mk...
# 2. Create a compliance profile
profile = compliance_svc.create_compliance_profile(
agent_id=agent_id,
risk_category="limited",
provider_name="VibeTensor",
intended_purpose="Analyzes quarterly financial data",
)
# 3. Issue a verifiable credential
credential = credential_svc.issue_credential(
subject_id=agent_id,
credential_type="AgentIdentityCredential",
issuer_name="VibeTensor",
claims={"capabilities": ["data_analysis", "reporting"]},
expiry_days=365,
)
print(credential["proof"]["type"]) # Ed25519Signature2020
For a complete end-to-end walkthrough covering all 9 modules, run the quickstart:
python examples/quickstart.py
git clone https://github.com/VibeTensor/attestix.git
cd attestix
pip install -r requirements.txt
python -m attestix.main
Take a high-risk AI agent from zero to fully compliant:
1. create_agent_identity --> UAIT with DID (Ed25519 signed)
2. record_training_data --> Article 10 data governance
3. record_model_lineage --> Article 11 technical documentation
4. create_compliance_profile --> Risk categorization + obligations
5. record_conformity_assessment --> Article 43 third-party assessment
6. generate_declaration_of_conformity --> Annex V declaration + W3C VC
7. create_verifiable_presentation --> Signed VP for regulator
High-risk systems are blocked from self-assessment:
record_conformity_assessment(assessment_type="self", ...)
--> ERROR: "High-risk AI systems require third_party conformity assessment"
Full