ag9
Installation
SKILL.md
ag9 — Know Your Agent
ag9 proves two things about an agent that no other layer proves together:
- A real human owns this agent — palm-bound via VeryAI. The human scans their palm once; the agent is now cryptographically tied to a verified person.
- A real model is operating — reverse CAPTCHA. Three challenge families (byte transforms, constrained generation, structured extraction) that capable LLMs can solve in seconds and humans/scripts cannot.
Both live at https://api.ag9.ai. Note the two base URLs:
- Path A (human ownership) uses
https://api.ag9.ai/v1/agent/... - Path B (reverse CAPTCHA) uses
https://api.ag9.ai/challenge,/verify, and/.well-known/jwks.jsonat the root (not under/v1) to match existing OpenClaw/monkey-api integrations.
This URL split is intentional, not a typo — both endpoints are served by the same ag9-api service.
What this skill accesses on your machine
~/.openclaw/identity/device.json(read). Used for Path A only. The skill readsdeviceId,publicKeyPem, andprivateKeyPemto sign registration/verification challenges. The private key never leaves your machine — only the base64publicKey,message, andsignatureare sent to ag9. Path B (reverse CAPTCHA) does not touch this file.- No other filesystem access. No disk writes. No background processes. No outbound network calls other than
https://api.ag9.ai.