# Chainlink Confidential Ai Attester Skill

> Chainlink Confidential AI Attester: submit private documents to an LLM inside an AWS Nitro Enclave and get back a cryptographically attested result — raw documents never leave the TEE. Use for these hackathon scenarios: (1) undercollateralized DeFi lending — upload a bank statement, get an attested approved/denied JSON decision without exposing financials on-chain; (2) accredited investor verific…

- **Type:** Skill
- **Install:** `agentstack add skill-smartcontractkit-chainlink-agent-skills-chainlink-confidential-ai-attester-skill`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [smartcontractkit](https://agentstack.voostack.com/s/smartcontractkit)
- **Installs:** 0
- **Category:** [Cloud & Infrastructure](https://agentstack.voostack.com/c/cloud-infrastructure)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [smartcontractkit](https://github.com/smartcontractkit)
- **Source:** https://github.com/smartcontractkit/chainlink-agent-skills/tree/main/chainlink-confidential-ai-attester-skill

## Install

```sh
agentstack add skill-smartcontractkit-chainlink-agent-skills-chainlink-confidential-ai-attester-skill
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# Chainlink Confidential AI Attester

Runs LLM inference inside Trusted Execution Environment (TEE). Documents go in, LLM analysis comes out — the raw documents are never stored or exposed.

**Beta product for the EthGlobal NYC hackathon.** Get an API key at the **Chainlink booth** or via the **#partner-chainlink channel in the EthGlobal Discord**.

Playground UI: `https://confidential-ai-dev-preview.cldev.cloud/playground` — easiest way to try it. Everything there maps 1:1 to the API calls below.

---

## Workflow 1 — Submit: `POST /v1/inference`

Auth: `Authorization: Bearer $API_KEY` — always use an env var, never hardcode.

Request shape:
```json
{
  "model": "gemma4",
  "system_prompt": "",
  "prompt": "...",
  "resources": [{ "filename": "doc.pdf", "content_type": "application/pdf", "content_base64": "" }],
  "cre_callback": { "url": "https://..." }
}
```

- `cre_callback` is optional — omit it and poll instead.
- Models: `gemma4` (images/general, default), `qwen3.6` (long text).
- Prefer PNG over PDF for demos — PDF preprocessing can take up to 5 minutes.

Response: `202 Accepted` → `{ "id": "...", "status": "queued" }` — save the `id`.

For curl examples and multi-language snippets → [references/code-examples.md](references/code-examples.md)  
For full request/response spec, error codes, resource types → [references/api-reference.md](references/api-reference.md)

---

## Workflow 2 — Poll: `GET /v1/inference/{id}`

Poll every 2–5 s until `status` is `completed` or `failed`.

Key fields on completion: `output` (LLM text), `usage`, `completed_at`.

For error symptoms → [references/troubleshooting.md](references/troubleshooting.md)

---

## Writing Prompts That Work

Always enforce JSON output with two layers:
1. **System prompt** — keep the default unless you have a specific reason to change it.
2. **User prompt** — binary question + exact JSON schema to return

For per-use-case prompt templates (lending, KYC, accredited investor, proof of reserves) → [references/prompts.md](references/prompts.md)

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [smartcontractkit](https://github.com/smartcontractkit)
- **Source:** [smartcontractkit/chainlink-agent-skills](https://github.com/smartcontractkit/chainlink-agent-skills)
- **License:** MIT

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** yes
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-smartcontractkit-chainlink-agent-skills-chainlink-confidential-ai-attester-skill
- Seller: https://agentstack.voostack.com/s/smartcontractkit
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
