Open-ended research without wallet execution
netstack 0.3.2 makes concrete user-operated instructions, calculations, forecasts and supplemental research first-class, while keeping wallet operation and transaction execution prohibited. The LP, Predict and House collector scripts are byte-identical to v0.3.1; no Book runner is added.
What improves for users and agents
- Explain the action without executing it. Betting/trading mechanics, approvals, funding, confirmations, settlement and withdrawal can be explained concretely. The agent still cannot access or connect wallets, sign, approve, submit transactions or prepare ready-to-execute transaction artifacts.
- Investigate beyond bundled coverage. Catalogs, ABIs, helpers and quick-pass recipes are starting points, not research-wide allowlists. Host-authorized analysis code, delegation, non-wallet authentication, local research inputs, read-only quotes and isolated non-broadcasting simulations remain available. Ordinary access controls, confidentiality and evidence honesty still apply.
- Calculate and model explicitly. Accrual, forecasts, time-to-target and annualization are allowed with stated assumptions, units and limits. Observed, derived and hypothetical results remain distinct; permission to model does not mean adding unwanted forecasts.
- Get to the Book market first. Mechanics questions start with a small applicable market snapshot rather than a frontend bundle crawl. Established Book context and a unique match support proceeding under an explicit assumption; genuine ambiguity receives a focused clarification. UI sources are inspected when relevant, with current assets discovered from HTML/imports and old hashes retained as historical evidence.
- Keep funding, slip amounts and fees separate. A 100 USDG deposit is not 100 wsNET or a display-$100 bet. Risk-on BET and risk-off WIN fields have different bases. Displayed, chain-derived and hypothetical fees are labeled separately; a signed-out 3% placeholder is not a verified quote. Frontend code and a successful eth_call do not prove deployed economic semantics.
- Make policy discoverable and dogfood reproducible. The governing guardrail is at references/guardrail.md; SKILL keeps compact routing and the wallet boundary. Synthetic fantasy fixtures are separate from live Book prompts. Known-address helper gaps and true index misses have distinct cases. Fresh-session instructions distinguish host capability limits from skill refusals and avoid attributing wallet refusal solely to the skill.
Update your installed copy
Download netstack-0.3.2.zip and install the complete manifest-listed package plus release-manifest.json into a clean target. Back up customizations outside the active skill directory first. Do not overlay the old copy, install only SKILL.md, or include tests, audit artifacts, .git or local handoffs. Clean replacement removes the obsolete root netstack-guardrail.md.
Verify file hashes, commit and actual loaded path. Start a fresh external conversation/session; the installing chat cannot replace its retained context. A missing browser or broken host CLI limits what can be observed, not whether research and explanations are permitted. General knowledge needs no Python; the unchanged optional runner uses Python 3.10+ on macOS/Linux under normal host permissions. No registry submission or automatic host installation is performed.
Scope and verification
- 35 regression tests passed against the extracted final install ZIP. All 145 members match the frozen input.
- Five final-release synthetic response probes exercised unique-match mechanics, deposit/display/fee arithmetic, wallet refusal with explanation, accrual models and uncatalogued research. No live tool calls were made by those probes.
- 31 prior-candidate response replays and two independent reviews are retained separately with their candidate identity. The final metadata/publication edits do not make those earlier runs fresh final-release host tests.
- Earlier user-reported Hermes and OpenClaw dogfood is contextual evidence for the tested commits, not native-host certification of these final bytes. September 21 Book source review was static text inspection, not clicked UI, a signed-in fee quote or deployed-contract verification.
The skill is not a sandbox. No guarantee of host enforcement, current liquidity, settlement, solvency or smart-contract safety follows from these checks.
Security review
The prior release's pinned local tools were rerun on the exact final package. Raw findings and failures are retained, not suppressed:
| Check | Result and limits |
|---|---|
| Cisco Skill Scanner 2.1.0 | Automated gate failed: 2 CRITICAL, 11 MEDIUM, 1 LOW records, including repeated matches. Six local analyzers completed; all four Python contexts were analyzed. |
| Hermes Skills Guard | Safe; installation allowed without force. Three MEDIUM findings retained: file count, the manual clone example and a policy-text signature in the relocated guardrail. Standalone scan only. |
| OpenClaw validator/packager | Passed. All 145 generated members match the frozen input. Format/local packaging, not native-host certification. |
| Gitleaks 8.30.1 | Zero unresolved credentials after review. Twelve package findings and twenty history findings across 28 commits were individually classified as public addresses or independently recomputed file hashes. Raw scans exit 1, not clean scans. |
Cisco is not a clean result. Its existing critical signature flags fixed-host DNS/socket networking in the unchanged collector. Fresh source review confirms fixed public-RPC routing, public-address validation, verified TLS, read-only request validation and redirect refusal; no private-data exfiltration chain was identified in that reviewed path. This is the networking code previously released with the maintainer's explicit retained-finding acceptance.
The new critical policy-text match is disclosed separately. The YARA conversation-theft pattern spans the privacy paragraph that explicitly prohibits sending conversation history, keys and credentials to unrelated destinations. The new medium autonomy matches include the prohibition on indefinite retries and isolated-simulation/inert-test wording. Context and exact matched spans support false-positive dispositions; these are new scanner indicators, not an unchanged prior count. The automated severities and duplicate records remain intact. No wording, rule or severity was weakened to obtain a green result.
Other retained findings concern the HTTPS primitive, nested compatibility-field interoperability, reference depth and file count. Hermes' new-location policy signature matches a negated statement: new evidence does not authorize automatic policy changes. All reviewed findings and residual limits are documented in the separate audit archive.
Scans ran locally with sanitized environments and tested network-denying process restrictions. No remote security analyzer or native-host sandbox certification is claimed. Manual review is not a formal information-flow proof, an independent human audit or a guarantee against unknown defects. The public audit payload also receives a separate secret scan; its own follow-up reports are appended afterward, not recursively rescanned as a final ZIP.
Release assets: netstack-0.3.2.zip is the installable package. netstack-audit-0.3.2.zip contains separate security findings, review dispositions, exact-input receipts, tool provenance and synthetic verification evidence, not an installable skill. Verify both with SHA256SUMS.