v0.5.7 — EVM operator config, evm_reader, token_security_scanner, addressbook public_0x, and catalog hubs
LatestSkillware 0.5.7 establishes the shared on-chain foundation for Web3/DeFi agents: a centralized EVM operator config layer (skillware evm, evm.yaml, 10 supported networks), the new deterministic defi/evm_reader state query skill, pre-trade token screening with defi/token_security_scanner, central address book public_0x contact resolution across mail and DeFi (skillware addressbook), a major Layer-1 defense upgrade for security/prompt_injection_firewall (v0.2.0), structured category hubs and sitemap discovery architecture, and hardened editable/PyPI package conflict resolution.
Install: pip install skillware==0.5.7 or pip install -U skillware or just pip install skillware
Update from 0.5.6: pip install -U skillware
Added
defi/evm_reader v0.1.0 (#367, #394)
- New read-only EVM chain state plane for Ethereum, Base, Arbitrum, Optimism, Polygon, BSC, Sepolia, MegaETH, and Arc.
- Deterministic queries without signing or private keys:
erc20_metadata: token name, symbol, decimals, and total supply.erc20_balance: high-precision decimal formatted and raw token balances.erc20_allowance: inspect spender allowances (includingrouter_v2alias).erc721_metadata,erc721_balance,erc721_owner_of: NFT metadata, ownership counts, and token ID owners.call_view: allowlisted view calls across standard contract presets.multicall: batch queries via Multicall3tryAggregatecapped safely at 50 calls.resolve_holder: contact alias topublic_0xresolution withneeds_inputcandidate disambiguation.
- Nine standard bundled ABI presets in
abis.py:erc20,erc721,erc1155,erc4626,univ2_pair,chainlink_feed,ownable,access_control, andmulticall3. - Zero bundle config duplication: 100% dynamic chain resolution and token shortcuts via
skillware.core.evm_config. - Examples & tooling:
examples/evm_reader_demo.py(offline mock execution + live RPC queries) and smoke test suite.
defi/token_security_scanner v0.1.0 (#365, #368)
- Read-only GoPlus Token Security scan (
scan,supported_chains) for pre-trade agent evaluation. - Normalizes honeypot, tax, ownership, proxy, and mint signals into stable
risk_tierandsignalsJSON. - Integrates with shared EVM operator config for dynamic network resolution.
- Recommended pre-trade pipeline:
defi/token_security_scanner→defi/evm_reader→defi/evm_tx_handler.
Core / CLI: Shared EVM Operator Config Layer (#379, #380)
- Central operator configuration layer separating JSON-RPC network settings and token shortcuts from skill bundles.
- Bundled defaults in
skillware/data/evm_defaults.yamlsupporting 10 networks (Ethereum, Base, Arbitrum, Optimism, Polygon, BSC, Sepolia, MegaETH, Arc, Anvil local). - Writable user config in
~/.config/skillware/evm.yamlcreated viaskillware evm init. - Precedence merge: bundled defaults → user
evm.yaml→ globalconfig.yaml/ project.skillware.yaml. - CLI subcommands:
skillware evm/evm show: inspection of resolved config, merge sources, and enabled chains.skillware evm init/init --yes: initialize writable operator config.skillware evm chains list: view enabled chains, RPC sources, and RPC readiness.skillware evm chain add: interactive wizard or CLI flags to add custom networks.skillware evm rpc enable <chain>: enable disabled networks.skillware evm tokens list: list registered ERC-20 contract shortcuts per chain.skillware evm token add: register custom tokens (--chain,--symbol,--address,--decimals).skillware evm validate: validate schema, duplicate chain IDs, and EIP-55 address formats.skillware evm open/open --dir: open operator config in system editor or file manager.
Core / CLI: Shared Address Book public_0x & defi/evm_tx_handler v0.3.0 (#373, #374, #381)
- Cross-skill contact identity in
addressbook.yamlsupportingpublic_0xalongside email and aliases. - Relaxed validation allowing mail-only (email), crypto-only (
public_0x), or dual-identity contacts. - CLI subcommands:
skillware addressbook list/list --with-wallet: table of contacts with wallet tags.skillware addressbook set-wallet <id> <0x...>: assign EIP-55 checksummed EVM address to contact.skillware addressbook add,edit,remove,validate,open.
defi/evm_tx_handlerv0.3.0 integrates recipient resolution:- Native and ERC-20 transfers by contact name or alias (e.g.
recipient: "alice"). - Halts deterministically with
status: "needs_input"when contact name matches multiple candidates. - Merges operator
evm.yamlat runtime for network resolution.
- Native and ERC-20 transfers by contact name or alias (e.g.
security/prompt_injection_firewall v0.2.0 (#273, #361)
- OWASP LLM01 Layer-1 trust-boundary input defense upgrade.
- Local evasion detection engine:
- Leetspeak deobfuscation and keyword scanning.
- Multi-token ROT13 decoding and token-reversal heuristics.
- Typoglycemia scrambled keyword recognition and mixed-script homoglyph normalization.
- Markdown and HTML image exfiltration channel detection.
- Academic and security advisory mention-vs-use false-positive controls.
- Operator policy telemetry:
policy_action(allow|flag|block),removed_span_count,sanitized_length_delta. - Finding enrichments:
decode_chain,decoded_preview. - Fail-closed soft resource caps protecting against RegEx DoS attacks.
Docs: Structured Catalog Discovery Architecture (#370, #377)
- Category landing pages at
docs/skills/<category>/README.mdwith catalog pages beside them (docs/skills/<category>/<skill_name>.md). - Central documentation sitemap at
docs/sitemap.md. - Standardized intent headers (
Solves:,Works with:,Runtime:) on all catalog pages. - Preserves 100% backward-compatible runtime IDs (
SkillLoader.load_skill("<category>/<skill_name>")).
CLI / Packaging: Version Display & Install Conflict Hardening (#333, #388)
- Hardened version display ensuring
get_package_version_display()never returnsNone. - Detection of editable clone vs PyPI wheel overlap via
assess_install_health(). - Startup stderr recovery hint and new
skillware doctor --installdiagnostic command with OS-specific fix commands. - Bundled helper scripts:
scripts/dev_install.shandscripts/dev_install.ps1.
Changed
- Security support window:
>= 0.5.7supported and patched;0.4.6 – 0.5.6silent;< 0.4.6unsupported advisory emitted. - Packaging extras: Added
defi_evm_reader = ["web3>=6.0.0"]and updateddefi/allunion extras inpyproject.toml. - Docs: Cross-linked
defi/evm_readeracross DeFi hub, agent loops, operator config, address book guides, and README category index. - Examples: Quick-start README example updated to Gemini +
office/gmail_handler(gemini_gmail_minimal.py).
What's possible today
1. Read-Only EVM State Queries without Keys (defi/evm_reader)
from skillware.core.loader import SkillLoader
bundle = SkillLoader.load_skill("defi/evm_reader")
skill = bundle["class"]()
# Format balance with correct decimals automatically
balance = skill.execute(
action="erc20_balance",
chain="ethereum",
contract="usdc", # Resolved via evm.yaml token registry
holder="alice", # Resolved via addressbook.yaml public_0x
)
print(balance["balance"], balance["symbol"]) # "1500.000000 USDC"
# Batched Multicall3 query
res = skill.execute(
action="multicall",
chain="ethereum",
calls=[
{"target": "0xA0b86991c6218b36c1d19D4a2e9Eb0cE3606eB48", "method": "decimals", "abi_preset": "erc20"},
{"target": "0xA0b86991c6218b36c1d19D4a2e9Eb0cE3606eB48", "method": "symbol", "abi_preset": "erc20"},
],
)2. Suggested Pre-Trade Verification Host Pipeline
[Untrusted Trade Request]
│
▼
`security/prompt_injection_firewall` (sanitize prompt & detect evasion)
│
▼
`defi/token_security_scanner` (honeypot, tax, proxy, mint risk report)
│
▼
`defi/evm_reader` (verify token decimals, holder balance & router allowance)
│
▼
`defi/evm_tx_handler` (quote Uni V2 swap, preview, sign & broadcast)
Upgrade notes
- EVM Operator Config: Run
skillware evm initto initialize a user-writable~/.config/skillware/evm.yamlwith the 10 bundled networks. Set RPC endpoints in.env(e.g.ETHEREUM_RPC_URL,BASE_RPC_URL). - Shared Address Book: Run
skillware addressbook initto manage contact identities withpublic_0xfor name-based crypto transfers and balance reads. - Citing: Zenodo concept DOI
10.5281/zenodo.21552745remains stable; record Skillware 0.5.7 for reproducibility (CITATION.cffupdated).
Full changelog
Contributors
Thanks to everyone who contributed to this release:
- @rosspeili —
defi/evm_readerskill bundle (#367, #394), EVM operator config layer &skillware evmCLI (#379, #380), shared addressbookpublic_0x&evm_tx_handlerv0.3.0 (#373, #374, #381), editable/PyPI overlap detection & version display hardening (#333, #388), release cut - @Hendobox —
defi/token_security_scannerv0.1.0 read-only GoPlus token honeypot/tax report (#365, #368) - @tusharjamunkar —
security/prompt_injection_firewallv0.2.0 evasion detection engine & telemetry upgrade (#273, #361) - @bd-c3 — structured catalog discovery architecture, category hubs, and sitemap (#370, #377)
- @HarshRajSinghania — glossary cross-links on category hubs and catalog pages (#363, #364)
- @Ammarbinyasir2007 — mock
ANTHROPIC_API_KEYinoffice/pdf_form_fillertest suite (#390)
Citation
Zenodo concept DOI: 10.5281/zenodo.21552745 — record Skillware v0.5.7 for reproducibility (CITATION.cff updated).