v0.4.0
Reviewed commit: fc3014155aeda0a182b45b146fb0a65b5913ceac.
Changes
- Bounded NET Advance analytics, concise inspection/provenance views, explicit coverage and count reconciliation, and consistent full-evidence checkpoints.
- Expanded RFV/Reports accounting, current publisher-methodology checks, dynamic V4 discovery and clearer component/evidence summaries.
- Standalone offline package verification, immutable-commit exports with sibling receipts, deterministic runtime archives and pinned Linux/macOS CI.
- Release review fixes: permission/integrity failures now stop LP/Predict/House fallbacks and final rechecks; excluded maintenance modules cannot shadow runtime verification modules. Release-status wording now requires immutable evidence rather than relying on the version string.
Verification and security
- 222 tests passed in all four final-commit CI jobs: Ubuntu 24.04/macOS 14 × Python 3.10/3.14. CI results. Hosted manifest/runtime hashes match the frozen release.
- Final-export CLI smoke checks exercised LP/Predict/House denial handling and offline Advance provenance. Denied collectors returned partial evidence with zero subsequent RPC requests. No fresh live-chain acceptance is claimed.
- Independent AI-assisted accounting/evidence, package adversarial and runtime-security reviews completed; identified code defects were fixed and independently closed. These are not human audits.
The automated scanner results are not all clean. Raw findings, severities, failures, exact-input identities and independent dispositions are preserved in the separate audit archive:
| Gate | Recorded result |
|---|---|
| Cisco Skill Scanner 2.1.0 | Automated FAIL: 3 CRITICAL, 15 MEDIUM, 1 LOW. Six local analyzers; all 179 files and 13 Python contexts loaded. |
| Hermes standalone SkillsGuard | Safe, allowed without force; 3 MEDIUM warnings retained. |
| OpenClaw official standalone validator/packager | Both passed; all 179 archive members match the frozen input. |
| Gitleaks 8.30.1 package/history | Raw exit 1 retained: 19 package and 27 history findings across 38 commits. All individually supported as public addresses, recomputed file hashes or static provenance labels; no unresolved credentials. |
| Gitleaks public audit payload | 113 frozen evidence files scanned; raw exit 1 retained. All 62 findings individually verified as 28 file hashes and 34 public-address occurrences; no unresolved credentials. |
Cisco's real fixed-host networking capabilities, metadata-schema mismatch, file-count warning and reference-depth limitations were explicitly retained and reviewed. Exact-context policy-text matches were reviewed as lexical false positives. A separate security reviewer accepted those current-context dispositions without changing the raw FAIL verdict. Complete physical-file loading does not establish deeper/anchor-aware semantic traversal beyond the scanner's depth limit.
The sanitized public audit payload received its own secret scan; its reports were appended afterward, so no recursive scan of those reports or the final ZIP is claimed. Scanner-process isolation is not certification of a consuming agent host. No remote cloud/LLM security analysis, deployed-contract safety certification, registry submission or host installation is claimed.
Assets and integrity
netstack-0.4.0.zip— installable 179-file runtime package.netstack-audit-0.4.0.zip— review/scan evidence and limitations; not an installable skill.SHA256SUMS— checksums for both ZIPs. Download all three into one directory and runshasum -a 256 -c SHA256SUMS.
Runtime ZIP SHA-256:
00cdcb26278a9b48d4438859fbca02daf5ad64639e9d2daa1fd5904bc32e37f7
Manifest SHA-256:
ca9922b71002761437096662ffa64e22e0b3dd4acc2ce00999fc51871b5276e9
Declared runtime digest:
af12bb1f809d6f3bab3675a24d8e750ea47e0e029e1d95a59b399a42ca1214d1
The annotated tag and checksums are unsigned integrity evidence, not a publisher signature or authentication. Review the exact revision and audit before installing; preserve the sibling receipt outside the runtime tree.