Skip to content

v0.5.7 — EVM operator config, evm_reader, token_security_scanner, addressbook public_0x, and catalog hubs

Latest

Choose a tag to compare

@rosspeili rosspeili released this 29 Sep 12:28
· 3 commits to main since this release

Skillware 0.5.7 establishes the shared on-chain foundation for Web3/DeFi agents: a centralized EVM operator config layer (skillware evm, evm.yaml, 10 supported networks), the new deterministic defi/evm_reader state query skill, pre-trade token screening with defi/token_security_scanner, central address book public_0x contact resolution across mail and DeFi (skillware addressbook), a major Layer-1 defense upgrade for security/prompt_injection_firewall (v0.2.0), structured category hubs and sitemap discovery architecture, and hardened editable/PyPI package conflict resolution.

Install: pip install skillware==0.5.7 or pip install -U skillware or just pip install skillware

Update from 0.5.6: pip install -U skillware


Added

defi/evm_reader v0.1.0 (#367, #394)

  • New read-only EVM chain state plane for Ethereum, Base, Arbitrum, Optimism, Polygon, BSC, Sepolia, MegaETH, and Arc.
  • Deterministic queries without signing or private keys:
    • erc20_metadata: token name, symbol, decimals, and total supply.
    • erc20_balance: high-precision decimal formatted and raw token balances.
    • erc20_allowance: inspect spender allowances (including router_v2 alias).
    • erc721_metadata, erc721_balance, erc721_owner_of: NFT metadata, ownership counts, and token ID owners.
    • call_view: allowlisted view calls across standard contract presets.
    • multicall: batch queries via Multicall3 tryAggregate capped safely at 50 calls.
    • resolve_holder: contact alias to public_0x resolution with needs_input candidate disambiguation.
  • Nine standard bundled ABI presets in abis.py: erc20, erc721, erc1155, erc4626, univ2_pair, chainlink_feed, ownable, access_control, and multicall3.
  • Zero bundle config duplication: 100% dynamic chain resolution and token shortcuts via skillware.core.evm_config.
  • Examples & tooling: examples/evm_reader_demo.py (offline mock execution + live RPC queries) and smoke test suite.

defi/token_security_scanner v0.1.0 (#365, #368)

  • Read-only GoPlus Token Security scan (scan, supported_chains) for pre-trade agent evaluation.
  • Normalizes honeypot, tax, ownership, proxy, and mint signals into stable risk_tier and signals JSON.
  • Integrates with shared EVM operator config for dynamic network resolution.
  • Recommended pre-trade pipeline: defi/token_security_scanner → defi/evm_reader → defi/evm_tx_handler.

Core / CLI: Shared EVM Operator Config Layer (#379, #380)

  • Central operator configuration layer separating JSON-RPC network settings and token shortcuts from skill bundles.
  • Bundled defaults in skillware/data/evm_defaults.yaml supporting 10 networks (Ethereum, Base, Arbitrum, Optimism, Polygon, BSC, Sepolia, MegaETH, Arc, Anvil local).
  • Writable user config in ~/.config/skillware/evm.yaml created via skillware evm init.
  • Precedence merge: bundled defaults → user evm.yaml → global config.yaml / project .skillware.yaml.
  • CLI subcommands:
    • skillware evm / evm show: inspection of resolved config, merge sources, and enabled chains.
    • skillware evm init / init --yes: initialize writable operator config.
    • skillware evm chains list: view enabled chains, RPC sources, and RPC readiness.
    • skillware evm chain add: interactive wizard or CLI flags to add custom networks.
    • skillware evm rpc enable <chain>: enable disabled networks.
    • skillware evm tokens list: list registered ERC-20 contract shortcuts per chain.
    • skillware evm token add: register custom tokens (--chain, --symbol, --address, --decimals).
    • skillware evm validate: validate schema, duplicate chain IDs, and EIP-55 address formats.
    • skillware evm open / open --dir: open operator config in system editor or file manager.

Core / CLI: Shared Address Book public_0x & defi/evm_tx_handler v0.3.0 (#373, #374, #381)

  • Cross-skill contact identity in addressbook.yaml supporting public_0x alongside email and aliases.
  • Relaxed validation allowing mail-only (email), crypto-only (public_0x), or dual-identity contacts.
  • CLI subcommands:
    • skillware addressbook list / list --with-wallet: table of contacts with wallet tags.
    • skillware addressbook set-wallet <id> <0x...>: assign EIP-55 checksummed EVM address to contact.
    • skillware addressbook add, edit, remove, validate, open.
  • defi/evm_tx_handler v0.3.0 integrates recipient resolution:
    • Native and ERC-20 transfers by contact name or alias (e.g. recipient: "alice").
    • Halts deterministically with status: "needs_input" when contact name matches multiple candidates.
    • Merges operator evm.yaml at runtime for network resolution.

security/prompt_injection_firewall v0.2.0 (#273, #361)

  • OWASP LLM01 Layer-1 trust-boundary input defense upgrade.
  • Local evasion detection engine:
    • Leetspeak deobfuscation and keyword scanning.
    • Multi-token ROT13 decoding and token-reversal heuristics.
    • Typoglycemia scrambled keyword recognition and mixed-script homoglyph normalization.
    • Markdown and HTML image exfiltration channel detection.
  • Academic and security advisory mention-vs-use false-positive controls.
  • Operator policy telemetry: policy_action (allow | flag | block), removed_span_count, sanitized_length_delta.
  • Finding enrichments: decode_chain, decoded_preview.
  • Fail-closed soft resource caps protecting against RegEx DoS attacks.

Docs: Structured Catalog Discovery Architecture (#370, #377)

  • Category landing pages at docs/skills/<category>/README.md with catalog pages beside them (docs/skills/<category>/<skill_name>.md).
  • Central documentation sitemap at docs/sitemap.md.
  • Standardized intent headers (Solves:, Works with:, Runtime:) on all catalog pages.
  • Preserves 100% backward-compatible runtime IDs (SkillLoader.load_skill("<category>/<skill_name>")).

CLI / Packaging: Version Display & Install Conflict Hardening (#333, #388)

  • Hardened version display ensuring get_package_version_display() never returns None.
  • Detection of editable clone vs PyPI wheel overlap via assess_install_health().
  • Startup stderr recovery hint and new skillware doctor --install diagnostic command with OS-specific fix commands.
  • Bundled helper scripts: scripts/dev_install.sh and scripts/dev_install.ps1.

Changed

  • Security support window: >= 0.5.7 supported and patched; 0.4.6 – 0.5.6 silent; < 0.4.6 unsupported advisory emitted.
  • Packaging extras: Added defi_evm_reader = ["web3>=6.0.0"] and updated defi / all union extras in pyproject.toml.
  • Docs: Cross-linked defi/evm_reader across DeFi hub, agent loops, operator config, address book guides, and README category index.
  • Examples: Quick-start README example updated to Gemini + office/gmail_handler (gemini_gmail_minimal.py).

What's possible today

1. Read-Only EVM State Queries without Keys (defi/evm_reader)

from skillware.core.loader import SkillLoader

bundle = SkillLoader.load_skill("defi/evm_reader")
skill = bundle["class"]()

# Format balance with correct decimals automatically
balance = skill.execute(
    action="erc20_balance",
    chain="ethereum",
    contract="usdc",  # Resolved via evm.yaml token registry
    holder="alice",   # Resolved via addressbook.yaml public_0x
)
print(balance["balance"], balance["symbol"])  # "1500.000000 USDC"

# Batched Multicall3 query
res = skill.execute(
    action="multicall",
    chain="ethereum",
    calls=[
        {"target": "0xA0b86991c6218b36c1d19D4a2e9Eb0cE3606eB48", "method": "decimals", "abi_preset": "erc20"},
        {"target": "0xA0b86991c6218b36c1d19D4a2e9Eb0cE3606eB48", "method": "symbol", "abi_preset": "erc20"},
    ],
)

2. Suggested Pre-Trade Verification Host Pipeline

[Untrusted Trade Request]
         │
         ▼
`security/prompt_injection_firewall` (sanitize prompt & detect evasion)
         │
         ▼
`defi/token_security_scanner` (honeypot, tax, proxy, mint risk report)
         │
         ▼
`defi/evm_reader` (verify token decimals, holder balance & router allowance)
         │
         ▼
`defi/evm_tx_handler` (quote Uni V2 swap, preview, sign & broadcast)

Upgrade notes

  • EVM Operator Config: Run skillware evm init to initialize a user-writable ~/.config/skillware/evm.yaml with the 10 bundled networks. Set RPC endpoints in .env (e.g. ETHEREUM_RPC_URL, BASE_RPC_URL).
  • Shared Address Book: Run skillware addressbook init to manage contact identities with public_0x for name-based crypto transfers and balance reads.
  • Citing: Zenodo concept DOI 10.5281/zenodo.21552745 remains stable; record Skillware 0.5.7 for reproducibility (CITATION.cff updated).

Full changelog

CHANGELOG.md — 0.5.7


Contributors

Thanks to everyone who contributed to this release:

  • @rosspeili — defi/evm_reader skill bundle (#367, #394), EVM operator config layer & skillware evm CLI (#379, #380), shared addressbook public_0x & evm_tx_handler v0.3.0 (#373, #374, #381), editable/PyPI overlap detection & version display hardening (#333, #388), release cut
  • @Hendobox — defi/token_security_scanner v0.1.0 read-only GoPlus token honeypot/tax report (#365, #368)
  • @tusharjamunkar — security/prompt_injection_firewall v0.2.0 evasion detection engine & telemetry upgrade (#273, #361)
  • @bd-c3 — structured catalog discovery architecture, category hubs, and sitemap (#370, #377)
  • @HarshRajSinghania — glossary cross-links on category hubs and catalog pages (#363, #364)
  • @Ammarbinyasir2007 — mock ANTHROPIC_API_KEY in office/pdf_form_filler test suite (#390)

Citation

Zenodo concept DOI: 10.5281/zenodo.21552745 — record Skillware v0.5.7 for reproducibility (CITATION.cff updated).