Releases: hellno/deckard
Release list
v0.0.1-alpha
Source-only release — no prebuilt binary is attached. Build from source:
see the README build instructions.
A manual, unsigned, testnet-only.apppath is documented in
docs/RELEASING.md.
⚠️ Pre-1.0 alpha. Testnet / throwaway keys only — do not use with real funds.
No third-party security audit has been performed.
First tagged alpha. Deckard is a self-custodial wallet built around a key-less proposer
and a process-isolated signer: an agent (or the app) can propose a transaction, but only
the daemon holds the key, and on any real-value chain a human approves before it signs.
The trust mechanisms are built and de-risked and the core flows work end to end; this is
still experimental software. See STATUS.md for the beat-by-beat state and
DESIGN.md for the design system.
Licensed under AGPL-3.0-or-later (see LICENSE and NOTICE).
Forked from the deck GPUI starter (0BSD, which
permits relicensing), now its own project.
Workspace (a virtual Cargo workspace, all crates under crates/): deckard-app (the GPUI
app, binary deckard), deckard-core (the headless engine: provider / verified reads,
balances, HD keys, keystore, and the key-less shield builder), deckard-contract (the
frozen wire contract), deckard-signerd (the process-isolated signer daemon), deckard-mcp
(the agent sidecar), deckard-browser-bridge (the dapp bridge), and deckard-wallet-client
(the socket client).
Added
Wallet and money
- Encrypted BIP-39 keystore. Generate or import a seed; it is sealed at rest in an
Argon2id + XChaCha20-Poly1305 envelope and never leaves the device. - Onboarding. A four-step create flow: set a passphrase with a live strength meter, back
up the recovery phrase behind a hold-to-reveal grid, verify it by position, then a Ready
screen with your new, copyable address. A progress rail shows where you are. - Live on-chain balances, read over an
alloyprovider and batched through Multicall3,
with a public / shielded composition and a roughly 20-second auto-refresh on the wallet home. - Helios-verified reads. Mainnet reads are checked against an embedded Helios light client
instead of trusting one RPC, with aReadStatusbadge surfaced in the app. - Send native ETH to a
0xaddress or ENS name, with a clear-signing review. - Swap tokens via CoW Protocol: a live quote, a minimum-received and slippage review, and
an off-chain order that settles on the CoW orderbook. - Shield to a private Railgun balance (the shield hero): move public ETH into a private
balance through the key-less shield builder, signed and broadcast by the daemon. - Receive. Your address plus a QR code, with one-click copy.
Agents and oversight
- First-class agent surface. Agents appear in the sidebar beside wallets; select one to
see and edit its policy (per-transaction cap, daily budget, allowed actions and assets) and
reach Pause, Rotate, Adjust, and Revoke. - Activity feed. A daemon-backed, day-grouped audit log of every proposed, approved,
denied, and executed action (who acted, the real amount, the on-chain result with tx hash,
and whether it was auto- or human-approved), with a top STOP that revokes all agent
authority and zeroizes the key. deckard-mcpagent sidecar. One key-less binary that is both a CLI and an MCP stdio
server for Claude Desktop, exposing themcp.v0.1six-tool profile (wallet address, balance,
policy, shield, execute, revoke-all). It holds no key; every write is an intent the daemon
gates and signs.- Headless agent runner.
just demo-agentdrives a hands-free watch-and-shield loop
against the live policy, respecting over-cap refusals and human denials. - Chain capability registry. One source of truth in
deckard-corefor per-chain RPC,
explorer, native asset, protocol support, and verified-reads trust tier. Launch refuses to
start if the RPC reports a chain id that does not match.
Dapp connectivity
- EIP-1193 browser bridge. A local loopback bridge exposes
eth_chainId,eth_accounts,
andeth_requestAccountsto an unpacked browser extension, announces itself via EIP-6963 so
dapps can discover it among other injected providers, and emits basic provider events.
Interface
- Bundled fonts and an enforced design system. The app ships Schibsted Grotesk for the UI
and JetBrains Mono for money and addresses, and routes every screen through a shared
widgets.rsvocabulary so address truncation, caution lines, and status glyphs cannot drift
per file. The two-signal actor model (amber = human, cyan = agent) is wired throughout. - Editorial layout. An oversized monospace balance hero, whitespace-and-hairline hierarchy
instead of cards, and a compact agent presence row on the home that links to the agent's
policy. - Command palette v2. Fuzzy search across every command, arrow-key navigation, inline
shortcuts, and frecency ranking. Every user-facing action is reachable from⌘K.
Project and tooling
- Source-only release workflow. A
v*tag runs the full CI gate, then publishes a GitHub
Release built from the version's CHANGELOG section.scripts/release-check.shvalidates the
tag shape, that every crate is at the tagged version, and that the changelog section exists. - Demo recipes.
just demo/demo-fund/demo-deposit/demo-check/demo-bridge
stand up a forked Sepolia, a funded wallet, and the app againstpolicy.demo.json, with a
"DEMO FORK, not mainnet" banner when running on a fork. - QA harnesses. Playwright suites that smoke-test the browser extension and the WalletBeat
provider surface on bundled Chromium, deterministic and fund-free. - Supply-chain gates. A blocking
cargo-denyadvisories gate, a bans / licenses / sources
gate, and a daily off-PR re-scan that files tracking issues on new advisories. - Contributor surface.
CONTRIBUTING.md,SECURITY.md,CODE_OF_CONDUCT.md,
THREAT-MODEL.md,docs/RELEASING.md, and GitHub issue and PR templates. - Agentic-engineering policy. A workspace-wide lint / CI policy that denies
todo!,
dbg!, and ignoredResults, with a documented Definition of Done.
Changed
- The confirm gesture is a
⌘↵key-cap, not hold-to-confirm. A short arm-delay keeps a
keypress carried over from the previous screen from approving a money move. - Clear-signing review is transaction-as-hero. The amount dominates in monospace, the
recipient and network are prominent, fees and routes are quiet, and irreversibility reads in
red. - The agent guardrail defaults to deny on every real-value chain. On mainnet, every L2
mainnet, and any unknown chain id, an auto-Allowis downgraded to a human approval.
Sepolia and local anvil stay hands-free by design; adding a new real chain can never silently
turn the brake off. - Daemon error reasons are redacted at the boundary. RPC URLs are scrubbed to
scheme://hostso API keys never reach an agent transcript, and the Railgun viewing key is
held inZeroizingwith a redactingDebug. cargo-denyyanks warn instead of block, so a yanked transitive dependency does not gate
unrelated PRs; real advisories still block immediately.
Fixed
- Agent-path shields show up on refresh. The refresh button resyncs the shielded balance
too, so a shield driven throughdeckard-mcpis visible immediately instead of at the next
unlock. - The Atlas policy card renders the daemon's live policy (cap, daily budget, spent today,
allowlist, approval mode, STOP state) instead of hardcoded placeholders. - Swap confirms in one hold. It waits for the relayer approval to mine, then submits,
instead of asking you to approve and then hold a second time. - Repeating the same swap amount works. The replay guard treats an idempotent approval
differently from a send or shield, which stay strictly double-spend guarded.
Security
- Process isolation. The signing key lives only inside
deckard-signerd, reached over a
0600Unix domain socket; the GUI never holds it. STOP zeroizes the in-memory secret. - Capability-gated approval. The daemon honors a human
Resolveonly on a private socket
pair inherited from the app, so a same-uid process can propose intents but cannot self-approve. - Hardened daemon launch. The daemon is spawned with a cleared environment (no
LD_PRELOAD/DYLD_INSERT_LIBRARIES/ inherited$PATH) and, in release builds, only after
verifying the one canonical daemon binary beside the app. This closes loader-injection and
binary-substitution paths to the key. - Durable daily spend cap. The cap is written before signing (reserve-before-sign), survives
a restart, rolls over forward-only on the UTC day, and is not reset by a daemon crash-loop. - Keystore fails closed on CSPRNG failure. Every secure random fill returns an error rather
than panicking if the OS CSPRNG is unavailable, so onboarding degrades gracefully instead of
crashing mid-backup. - Verified reads by default on mainnet (Helios), never trusting a single third-party RPC.
- Keystore at rest in an Argon2id + XChaCha20-Poly1305 envelope; secrets stay in
Zeroizingand are never logged orDebug-printed. - Frozen Deny-reason vocabulary. Refusals route through roughly thirty documented
const
tags, with a build-time scan that rejects raw literals, so an agent can recover against a
stable, typo-free vocabulary. #![forbid(unsafe_code)]indeckard-core(the trust core); the app crate sets
unsafe_code = "deny".
Notes
- Definition of Done (all must hold):
cargo fmt --all --checkis clean;just checkis
green (c...