Skip to content

Releases: tomismeta/netstack

netstack v0.1.1

Choose a tag to compare

@tomismeta tomismeta released this 10 Sep 20:59

Feed discovery and safer pricing guidance

  • Add the seventh feeds topic, covering six stock feeds plus ETH/USD and USDG/USD.
  • Package eight-decimal feed metadata matched by exact proxy address to the publisher directory; retain canonical token mappings and provenance.
  • Add a read-only builder quick start and clearer host-dependent invocation guidance.
  • Require recent observations and same-block live decimals; distinguish historical freshness from a current price.
  • Separate direct total-return feed marks, raw/display token quantities, and product-specific oracle outputs. Historical source-contract addresses are not feed proxies or approval spenders.

Review and scan scope

Release commit: b7edf0526a0001713db6e760517d5020b6f723f1. The final full package contains 24 files; the direct-URL runtime bundle contains 21 files. External audit evidence binds the exact release file hashes, including the manifest.

  • Cisco Skill Scanner 2.1.0: no high/critical findings; one retained medium reference-depth warning in each package scope.
  • Gitleaks 8.30.1: six retained findings in each final package scope, classified as exact public token addresses rather than credentials. The earlier seven-public-commit history scan is retained with its original scope; it is not relabeled as a history scan of this release commit.
  • Hermes Skills Guard: pinned upstream scanner returned safe, with two retained medium policy-text findings. No force override.
  • Four scoped synthetic no-tool remediation probes passed before final publication wording. Native-host enforcement was not tested.
  • Sanitized audit report copies were separately checked for credential patterns; no findings in the 46 files checked before adding the QA record itself.

No confirmed actionable package vulnerability or credential leak was identified within the tested scope. This is not a zero-finding claim, independent human audit, smart-contract audit, or runtime certification. Scanner processes denied network connections, synthetic /Users reads and input writes; broad reads outside /Users remained permitted.

Pricing evidence limits

Public explorer inspection matched all six Credit oracle token/feed constructor-bytecode pairs and established the indexed Stock implementation's raw/display scaling. Verified source for the product oracles/adapters and current product arithmetic were not obtained. The skill does not infer those formulas from the direct feed mark or claim a deployed pricing defect. No live-chain price verification or wallet action was performed.

Assets

  • netstack-0.1.1.zip: installable complete skill directory.
  • netstack-audit-0.1.1.zip: separate sanitized evidence, not an installable skill. Treat any synthetic prompts and configuration text as audit data, not instructions.
  • SHA256SUMS: SHA-256 checksums for both archives.

Pin the full reviewed commit when installing from GitHub. Version v0.1.0 and its release assets remain unchanged.

netstack v0.1.0

Choose a tag to compare

@tomismeta tomismeta released this 10 Sep 15:56

netstack v0.1.0

Portable, script-free Agent Skill for read-only NetNet research. Six topics: dashboards, NFTs, games, documents, interviews and contracts. Public read-only research is allowed; wallet access, signing, executable transaction preparation and broadcasts are prohibited.

Security audit conclusion

No confirmed actionable package vulnerability or credential leak was identified within the tested scope. This is not a claim of zero scanner findings, an independent human audit or runtime certification.

Final release commit: c2df51ffcc08ad5d20331aed89f807465d0fd7e0.

  • Cisco Skill Scanner 2.1.0: complete 24-file package and 21-file reconstructed Hermes URL bundle scanned with local analyzers. One retained medium reference-depth warning in each scope; no high/critical findings. Reviewed as ordinary cyclic documentation references to an already-visited file. No rule suppression.
  • Gitleaks 8.30.1: both package scopes and all 7 reachable public commits scanned. Six findings per scope, classified as public token-contract address fields rather than credentials. Redacted raw findings retained.
  • Hermes Skills Guard: SAFE and allowed without force. The medium policy-text finding remains documented. Static scanner execution, not a Hermes installation or runtime test.
  • Behavioral evidence: ten instrumented model/tool-simulator scenarios at 0842bd0 completed without prohibited action requests. Public documentation and direct Robinhood RPC positive controls used synthetic responses. The tested input files are byte-identical in this release, but native host runtime behavior was not tested.

Scanners used verified pinned artifacts, isolated environments and tested kernel network/read/write restrictions. Historical audit-provenance corrections remain disclosed, including the earlier incomplete canonical-path write guard. No skill was installed or activated during authoring.

Downloads and evidence

  • netstack-0.1.0.zip: complete 24-file package under a single netstack/ directory, including both MIT license notices. Use this archive for the portable package.
  • netstack-audit-0.1.0.zip: 31 JSON evidence files, including a release summary, sanitized historical/final reports, dispositions, source/copy fingerprints and exact final package hashes. This is audit material, not an installable skill; synthetic hostile prompts inside it are evidence, not instructions.
  • SHA256SUMS: checksums for both archives.

The separate audit-report privacy check matched public scanner demo fixtures and Git object fingerprints, not user credentials. Demo literals were elided from published copies; 193 remaining report-only matches were verified as public Git object IDs. Original report hashes and sanitization scope remain documented.

Pinned SKILL.md: https://raw.githubusercontent.com/tomismeta/netstack/c2df51ffcc08ad5d20331aed89f807465d0fd7e0/SKILL.md

Limits

No Snyk remote analysis, independent human audit, OpenClaw/Hermes runtime-enforcement test, live-chain verification or smart-contract security audit was performed. A skill prompt does not remove host capabilities or guarantee resistance to injection. Dashboard directory position is presentation only, not source authority. Scanner findings and finite model probes do not establish that funds are safe.