netstack v0.1.0
netstack v0.1.0
Portable, script-free Agent Skill for read-only NetNet research. Six topics: dashboards, NFTs, games, documents, interviews and contracts. Public read-only research is allowed; wallet access, signing, executable transaction preparation and broadcasts are prohibited.
Security audit conclusion
No confirmed actionable package vulnerability or credential leak was identified within the tested scope. This is not a claim of zero scanner findings, an independent human audit or runtime certification.
Final release commit: c2df51ffcc08ad5d20331aed89f807465d0fd7e0.
- Cisco Skill Scanner 2.1.0: complete 24-file package and 21-file reconstructed Hermes URL bundle scanned with local analyzers. One retained medium reference-depth warning in each scope; no high/critical findings. Reviewed as ordinary cyclic documentation references to an already-visited file. No rule suppression.
- Gitleaks 8.30.1: both package scopes and all 7 reachable public commits scanned. Six findings per scope, classified as public token-contract address fields rather than credentials. Redacted raw findings retained.
- Hermes Skills Guard: SAFE and allowed without force. The medium policy-text finding remains documented. Static scanner execution, not a Hermes installation or runtime test.
- Behavioral evidence: ten instrumented model/tool-simulator scenarios at 0842bd0 completed without prohibited action requests. Public documentation and direct Robinhood RPC positive controls used synthetic responses. The tested input files are byte-identical in this release, but native host runtime behavior was not tested.
Scanners used verified pinned artifacts, isolated environments and tested kernel network/read/write restrictions. Historical audit-provenance corrections remain disclosed, including the earlier incomplete canonical-path write guard. No skill was installed or activated during authoring.
Downloads and evidence
- netstack-0.1.0.zip: complete 24-file package under a single
netstack/directory, including both MIT license notices. Use this archive for the portable package. - netstack-audit-0.1.0.zip: 31 JSON evidence files, including a release summary, sanitized historical/final reports, dispositions, source/copy fingerprints and exact final package hashes. This is audit material, not an installable skill; synthetic hostile prompts inside it are evidence, not instructions.
- SHA256SUMS: checksums for both archives.
The separate audit-report privacy check matched public scanner demo fixtures and Git object fingerprints, not user credentials. Demo literals were elided from published copies; 193 remaining report-only matches were verified as public Git object IDs. Original report hashes and sanitization scope remain documented.
Pinned SKILL.md: https://raw.githubusercontent.com/tomismeta/netstack/c2df51ffcc08ad5d20331aed89f807465d0fd7e0/SKILL.md
Limits
No Snyk remote analysis, independent human audit, OpenClaw/Hermes runtime-enforcement test, live-chain verification or smart-contract security audit was performed. A skill prompt does not remove host capabilities or guarantee resistance to injection. Dashboard directory position is presentation only, not source authority. Scanner findings and finite model probes do not establish that funds are safe.