Skip to main content

asrpm Overview

asrpm is Vorpal Engineering's reference client for the Agent Skill Registry (ERC-8239) — a protocol for publishing, discovering, and verifying agent skills as on-chain artifacts. The CLI resolves skill identifiers to their on-chain manifests, verifies the fetched bytes against the registry's integrity commitments, and installs, registers, updates, and publishes skills.

What is the Agent Skill Registry?​

The Agent Skill Registry (ASR) treats every skill as an ERC-721 token. The registry stores a manifestHash commitment alongside the token’s URI, allowing clients to check fetched manifest bytes against the on-chain record. Each skill exposes one or more "targets" — host-specific representations such as a Claude Code SKILL.md, a Cursor rule, an MCP server, or a CLI binary — each with its own URI and integrity hash.

The result is a content-addressed, self-verifying distribution surface for agent capabilities: any client can fetch a skill from any URI and prove it received the bytes the author registered.

Key Concepts​

TermDescription
skillIdInteger identifier on a SkillRegistry contract.
SkillRegistryERC-721 contract storing tokenURI(skillId) and manifestHashes(skillId).
ManifestJSON document describing the skill (name, description, version, license, targets, etc.).
TargetPer-host materialization of the skill. Each carries its own uri, integrity, and format.
Integrity<algorithm>:<hex> digest, e.g. keccak256:97837f… or sha256:4a8b…. Required on every target.
Fully qualified addresseip155:<chainId>:<registry>:<skillId> — uniquely names a skill across chains and registries.

The fully qualified form is a protocol identifier. Current CLI commands accept a numeric skill ID; configure the RPC and registry separately.

See the ERC-8239 specification for the complete protocol model, including client conformance, manifest schema, and registry contract surface.

Key Features​

  • Onchain Resolution — Resolves skill identifiers via tokenURI(skillId) and manifestHashes(skillId) on a configured EVM chain with a compatible registry
  • Integrity Verification — Validates fetched manifest bytes against the registry's manifestHash commitment, and target body bytes against the selected target’s declared integrity
  • Local Install Index — Tracks installed skills in ~/.asrpm/installs.json, keyed by (chainId, registry, skillId), so list and uninstall can use local records; install and update resolve current chain state
  • Authoring Workflow — register mints new skill tokens; publish releases new versions on existing tokens (owner-only)
  • Foundry Keystore Integration — Reads encrypted keys from ~/.foundry/keystores/ on demand; no plaintext key custody in the CLI
  • Sepolia Defaults — Ships with a Sepolia RPC endpoint and registry address; read-only commands require access to that RPC and the referenced deployment
  • Embedded Bootstrap Skill — asrpm bootstrap prints a built-in SKILL.md for injecting ASR awareness into an agent session without installing

How Verification Works​

Every install or verify pass runs the same content-addressed pipeline:

  1. Resolve — Call tokenURI(skillId) and manifestHashes(skillId) on the configured SkillRegistry.
  2. Fetch manifest — Dereference the returned URI. Supported schemes: https://, http://, data:. (The ipfs:// scheme is intentionally not supported — use the gateway HTTPS URL your pinning provider serves.)
  3. Verify manifest hash — When the registry commitment is nonzero, confirm that keccak256(manifestBytes) equals the registry's manifestHashes(skillId) value. Mismatches abort the operation.
  4. Pick target — Select the targets[] entry whose kind matches the install target (e.g. claude-code-skill for Claude Code).
  5. Fetch body — Dereference the target's uri.
  6. Verify body integrity — Confirm the fetched bytes match the target's <algorithm>:<hex> integrity value.
  7. Install or report — install writes the verified bytes to disk and records the install in ~/.asrpm/installs.json. verify performs the same checks without writing.

The current CLI skips manifest-hash comparison when the registry returns an all-zero hash. In that case, target integrity is still checked, but the manifest is not authenticated against an on-chain commitment. resolve also reports an unreadable commitment without aborting; check its hash status before relying on the output.

ASR provides integrity, not safety. A successful hash comparison establishes that the fetched bytes match the recorded commitment. It makes no claim about whether those bytes are correct, useful, or safe to run. Inspect skills with asrpm resolve or asrpm verify --view before installing.

Use Cases​

  • Agent Skill Distribution — Publish Claude Code skills, Cursor rules, or MCP servers as on-chain, content-addressed artifacts
  • Verifiable Agent Environments — Check installed content against published hashes. The CLI resolves the current manifest; it does not pin or retrieve historical versions by version string
  • Multi-Host Skills — Ship a single skill with multiple per-host targets (claude-code-skill, cursor-rule, mcp-server, …) under one identifier
  • Decentralized Authorship — Skills are minted as ERC-721 tokens; ownership and transfer are handled on-chain

The manifest can describe multiple target kinds, but the current CLI installs only claude-code-skill targets. Dependency metadata is not automatically resolved or installed.

Source Code​

View the source code and contribute on GitHub: vorpalengineering/asrpm.

See the ERC-8239 specification for full protocol details.