feat(vetkeys): replace vetkd with vetkeys + encrypted-maps skills - #351
Merged
Conversation
Replace the outdated single `vetkd` skill with two skills split by abstraction level: - vetkeys: vetKD management API, symmetric key derivation, IBE, timelock, threshold BLS, offline public-key derivation, VRF (feature references ibe.md, bls-signing.md) - encrypted-maps: high-level access-controlled encrypted key-value storage (Rust macro / Motoko mixin), KeyManager, metadata variant Update to current libraries: @icp-sdk/vetkeys 0.5 (renamed from @dfinity/vetkeys), ic-vetkeys 0.9 (Rust) / 0.6 (Motoko), @icp-sdk/core frontend, modern ic-cdk API, correct cycle costs, library management helpers instead of hand-rolled Candid. Every code block verified against dfinity/examples and library source; Motoko snippets compiled on moc 1.13 / ic-vetkeys 0.6; cycle costs measured on a local replica. Closes #73, #272, #285, #286 Supersedes #158, #162, #308
Skill Validation ReportProject Checks |
There was a problem hiding this comment.
Pull request overview
Replaces the outdated vetkd skill with current, abstraction-specific vetKeys guidance.
Changes:
- Adds low-level
vetkeysand high-levelencrypted-mapsskills. - Adds IBE, BLS, metadata, and deployment guidance.
- Adds routing and output evaluations for both skills.
Reviewed changes
Copilot reviewed 9 out of 9 changed files in this pull request and generated 6 comments.
Show a summary per file
| File | Description |
|---|---|
.claude/CLAUDE.md |
Clarifies dependency documentation conventions. |
skills/vetkd/SKILL.md |
Removes obsolete vetKD guidance. |
skills/vetkeys/SKILL.md |
Adds updated core vetKeys guidance. |
skills/vetkeys/references/ibe.md |
Documents IBE and timelock flows. |
skills/vetkeys/references/bls-signing.md |
Documents threshold BLS signing. |
skills/encrypted-maps/SKILL.md |
Adds encrypted storage guidance. |
skills/encrypted-maps/references/metadata.md |
Covers custom metadata endpoints. |
evaluations/vetkeys.json |
Adds vetKeys behavior and routing evaluations. |
evaluations/encrypted-maps.json |
Adds EncryptedMaps behavior and routing evaluations. |
Suppressed comments (1)
skills/vetkeys/SKILL.md:210
- A context/input mismatch is reported as a verification or decryption error; it is not silent. This wording can lead consumers to ignore or misdiagnose the rejected promise/result.
6. **`context` and `input` must match end to end.** A different `context` (or a different `input`) produces a different key; decryption then fails silently. Keep them byte-identical across public-key, derive, and client verify/decrypt.
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
- Scope the "no canister sees the raw key" guarantee to the client-delivery pattern (threshold BLS and in-canister timelock intentionally expose key material to the canister) - context/input mismatch: decryptAndVerify throws (Rust returns an error) — reword the "fails silently" claims in the concept and pitfall - Standalone Motoko canisters: plain `let keyName` (frozen at first install, matching basic_vetkd) with an accurate immutability comment; drop the misleading `transient` re-read framing - BLS verify snippet: encode the message once and verify the same bytes; use the Motoko backend's signMessage/getMyVerificationKey names - encrypted-maps: resolve rootKey via safeGetCanisterEnv() (was referenced but never declared) - CODEOWNERS: retarget /skills/vetkd/ -> /skills/vetkeys/ and add /skills/encrypted-maps/ (@andreacerulli) - Add public/_redirects 301s for the vetkd -> vetkeys rename
…tocol @andreacerulli has left dfinity; retarget the renamed vetkd owner to the core-protocol team (credit for the original design remains in the PR).
Per review on #351: https-outcalls, multi-canister, and stable-memory move from @derlerd-dfinity to the @dfinity/core-protocol team.
schneiderstefan
approved these changes
Aug 12, 2026
marc0olo
enabled auto-merge (squash)
August 14, 2026 14:42
raymondk
approved these changes
Aug 14, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Replaces the outdated
vetkdskill with two skills split by abstraction level, updated to the current vetKeys libraries and verified end-to-end.vetkeys— the vetKD management API plus advanced primitives: symmetric key derivation, IBE, timelock encryption, threshold BLS signatures, offline public-key derivation, and VRF. Feature depth lives inreferences/ibe.mdandreferences/bls-signing.md.encrypted-maps— high-level, access-controlled encrypted key-value storage (the default for password managers / encrypted notes): the Rustexport_encrypted_maps_canister!macro, the MotokoEncryptedMapsCanistermixin, the TSEncryptedMapsclient, a shortKeyManagersection, and the metadata / custom-value-endpoint variant inreferences/metadata.md.Each skill's description routes to the other, so agents land on the right one (bidirectional routing verified in the trigger evals).
Why replace
vetkd?The shipped
vetkdskill was inaccurate against the current libraries. It used the renamed@dfinity/vetkeys(frozen at 0.4), told Motoko developers to hand-roll the management canister (a full Motokoic-vetkeyslibrary now exists), pinned Rustic-vetkeys0.6 (now 0.9), used the deprecatedic-cdkcall API, referenced a non-existenttoDerivedKeyMaterial(), and misstated cycle costs.What's corrected
@icp-sdk/vetkeys0.5 (renamed from@dfinity/vetkeys); frontend agent/identity from@icp-sdk/core, not@dfinity/agentic-vetkeys0.9 +ic-cdk0.20 +ic-cdk-management-canister; Motokoic-vetkeys0.6 (moc 1.13 / core 2.6.1)ic-cdk-management-canister,mo:ic-vetkeys/ManagementCanister) instead of hand-rolled Candid +actor "aaaaa-aa"VetKey.asDerivedKeyMaterial()→encryptMessage/decryptMessage(the old skill'stoDerivedKeyMaterial()does not exist)test_key_1andkey_1behave the same locally and on mainnet; helpers attach the amountverifyBlsSignature(DerivedPublicKey, …),persistent actor(compiles with or without--default-persistent-actors), and the Motoko-has-no-frontend-crypto asymmetry documentedVerification
Every code block is derived from the canonical
dfinity/examplessources (Rustmaster, Motoko from dfinity/examples#1475, frontendsmaster) and the library source. All Motoko snippets compiled verbatim onmoc 1.13.0/ic-vetkeys 0.6.0/core 2.6.1, in both mops configurations (bare and--default-persistent-actors). Cycle costs were measured on a local replica.npm run validatepasses for both skills.Honoring prior contributions
This supersedes and builds on prior community work — thank you both:
vetkeys/encrypted-mapssplit and the BLS / IBE / timelock scoping (Replace vetkd skill with a new vetkeys covering BLS, IBE, and timelock. #162, feat: Add encrypted-maps skill for vetKeys EncryptedMaps #158)Closes #73, #272, #285, #286.
Supersedes #158, #162, #308.
Evals
Output evals — all cases pass with the skill; strong with-skill vs baseline deltas
vetkeys
encrypted-maps
Trigger evals — 100% on both skills, including bidirectional routing
encrypted-maps)vetkeys)🤖 Generated with Claude Code