Skip to content

Releases: tomismeta/srstack

srstack v0.3.0

Choose a tag to compare

@tomismeta tomismeta released this 27 Sep 21:09

Host-native research and history-first projections

srstack v0.3.0 moves Standard Reserve research into the agent's existing host-authorized tools. Reviewed knowledge and optional offline calculations replace the bundled protocol clients; questions drive the work, not a fixed command catalog.

What changes

  • Retire the bundled snapshot, price, history and diagnostic clients. No RPC transport, active-deployment router, wallet connector or background service is installed.
  • Add question-oriented contract/capability guides and reviewed interface inventories: 19 dated contract bindings, 15 interfaces, 905 ABI entries and 25 scoped capabilities. Dated identities are discovery leads, not current routing authority or deployed-behavior certification.
  • Bundle optional standard-library calculation helpers, a thin offline JSON CLI, research/round schemas and explicitly fictional worked examples. Agents may use, adapt or ignore them; no particular language, helper or data format is required for an answer.
  • Start next-round close projections from relevant curated history. Report both an exact last-sold linear trend and a structural estimate with a descriptive ±1 sample-standard-deviation band. Keep policy opening, executable inventory-conditional quote, observed close and floor distinct; future floor remains unknown.
  • Add six runnable projection recipes, durable external round-dataset guidance, partial-evidence handling and the zero-inventory phantom-price guard. A decaying getter is not purchasable inventory and does not itself advance the round.
  • Make selected-interface authentication, bounded recovery/checkpoint plans, canonical event coverage, earned-origin attribution and claim-level uncertainty explicit without imposing a research wizard or tool allowlist.
  • Fix compact scientific-notation inputs exhausting calculator resources before magnitude rejection. Keep the Hermes description within 60 characters and install only the complete reviewed runtime export.

Boundaries retained

No wallet signing, signature requests or transaction submission/broadcast. Explicit unsigned-artifact preparation remains separately authorized; a buying question does not authorize preparation or execution. Host permissions, access controls, credential protection, private-data consent, untrusted-source handling and evidence integrity remain mandatory.

No live deployment, price, balance, funding origin or complete historical dataset is supplied as a package default. ABI coverage is not source/bytecode correspondence. Conditional calculations and forecasts require explicit evidence and assumptions; missing facts cannot become zero or verified outcomes. No new runtime third-party dependency or network/wallet authority is introduced.

Install or update

Use srstack-0.3.0.zip and verify its entry in SHA256SUMS. Only the complete runtime belongs in the skill directory; do not install the audit ZIP or GitHub's automatic source archive. Cleanly replace the complete runtime rather than overlaying files, retain rollback, and refresh discovery/start a fresh host conversation. Keep curated live research outside the installed tree.

The tagged README installation workflow covers review, committed export, staging, verification and recovery. Pin this exact full commit:

8501397e6ca196d424ccad5090826ce7ae078718

Verification now runs from the reviewed source checkout outside discovery using maintenance/package.py; the retired scripts/verify.py is not part of this release. The documented workflow resolves the explicit release tag or supplied full commit and compares installed membership/bytes with that commit. Python 3.10+ is needed only for repository maintenance or optional calculation helpers, not skill loading. Integrity is not authenticity or sandbox certification.

Verification and limits

Release commit: 8501397. Runtime: 72 files. Committed release export and runtime ZIP members match byte-for-byte; CI verifies deterministic packaging.

  • 76 regression tests passed per CI job: 20 packaging, 14 inventory and 42 research checks on Ubuntu Python 3.10/3.14 and macOS Python 3.14. Integrated-main CI.
  • All six documented calculation recipes executed from the final standalone committed export. Tag-selection smoke verified annotated-tag peeling and failure when the tag is absent, even with a same-named branch.
  • Historical fresh-session acceptance exposed three failures that were corrected and re-exercised; three new projection cases passed separately. These scoped runs are not a fresh all-scenarios model/live pass on the release pin.
  • User-reported dogfooding migrated 19 rounds, checked 10/19 rounds with 44 archive/header checks, checked a six-round forecasting cohort with 42 further checks, and passed fresh projection questions. These reports were not independently rerun here. Archive/header observations do not establish complete interior event ordering or exact first/last purchase-event coverage; the 50-to-40 capacity transition remains a comparability caveat.
  • The owner approved a bounded 0.3.0 release based on the accumulated dogfooding and review. Outstanding deployed accrual/lazy-roll/reset correspondence, attributable earned-only funding, refund/flow attribution and complete canonical history remain disclosed evidence gaps, not passed gates. Host loading and calculation checks do not establish universal safety or live-provider capability.

Scanner results — findings retained

The complete prior ten-check local security/native-host checklist was repeated on the hardened candidate. This is not an all-clear security verdict:

  • Cisco AI Defense 2.1.0 strict/behavioral: is_safe=true, with one low file-count finding and one medium recursive-reference-depth finding retained. The trace records 18 depth cutoffs and 170 reference occurrences; 17 unique existing references were not yet visited at their cutoff observations. This is not exhaustive semantic coverage.
  • Hermes current reviewed source: native parser/loader/default-preprocessing/quarantine/install checks passed with exact resource bytes; guard accepted the skill with four medium heuristics retained. Native AST audit found no findings across both runtime Python files.
  • AgentSkills valid; pinned OpenClaw loader, official validator and packaging passed; pinned local ClawHub static moderation clean. These pinned offline implementations are not current hosted registry approval.
  • Gitleaks found no leaks in the hardened runtime, then-reachable Git history or retained audit evidence. Bandit found no runtime issues and retained 14 low maintenance/test subprocess warnings. Final audited maintenance/reference-validator and Cisco environments had no known dependency vulnerabilities; srstack runtime has no third-party Python dependencies.
  • Manual review reproduced and fixed the compact-exponent resource-exhaustion issue. Before/after CLI evidence and the bounded regression are retained. No unresolved high/critical finding was reported by the executed scans; that does not prove absence of vulnerabilities.

Final changes since the full scanner/native review are limited to README release/scope wording, installation tag selection and the manifest. Executable files, entrypoint and all other runtime resources are byte-identical. The full scanner/native suite is not represented as freshly rerun on that final documentation delta. See the audit bundle for exact candidate identities, toolchain pins, raw findings, dispositions, CI and coverage limits.

Release assets

  • srstack-0.3.0.zip — complete installable runtime.
  • srstack-audit-0.3.0.zip — separate security/native-host/toolchain/verification evidence; not installable. Historical HOLD and prepublication labels retain their original meaning; subsequent scope/publication approvals are recorded separately.
  • SHA256SUMS — hashes of both ZIPs.

Runtime content SHA-256: 288c8dcde2204336b3a15a5f79ea00e98d2c4618d4c590dfb77fde43ebaa53c5.

Prior releases and their assets remain unchanged. MIT is unchanged. ClawHub publication and hosted review are deferred; no registry submission, terms acceptance or hosted scanner upload accompanies this GitHub release.

srstack v0.2.2

Choose a tag to compare

@tomismeta tomismeta released this 21 Sep 12:18

Analysis, forecasts and user-directed workflows

srstack v0.2.2 removes instruction-level refusals of requested analysis and workflows. Bundled catalogs and helpers are starting points, not a capability allowlist.

What changes

  • Permit conditional accrual/time-to-target calculations, forecasts, fee/net estimates, strategy comparisons and proposal analysis with explicit inputs and assumptions.
  • Permit consent-scoped local/private-data analysis, exports, reports and caches; host-authorized authenticated research; approved dependencies and custom tools; and explicitly requested bounded monitoring/schedules where the host supports them.
  • Permit supplemental contracts, interfaces and sources, unsigned transaction preparation, informational how-to workflows and nonbroadcast calls, quoters, gas estimates, traces and simulations.
  • Judge the actual tool invocation, including nested/batched effects, rather than banning a tool because it also exposes unused signing/submission methods.
  • Expand routing to research / inspect / analyse / workflows. Keep bundled helper schemas and checks narrow without turning them into agent-wide refusals.
  • Update installation to the reviewed release tag/full commit and keep the skill description within Hermes' authoring limit.

Boundaries retained

No wallet signing, signature requests or transaction submission/broadcast, including delegation and submission of pre-signed transactions. Host-authorized read-only account/address access is permitted; SIWE/signature login is not. Host permissions, access controls, credential protection, private-data consent, untrusted-source handling and evidence integrity remain mandatory.

No new simulator, scheduler, wallet engine or cataloged deployment is bundled. The retired scenario helper is not restored. Other workflows require actual host capabilities or inspectable task code; unavailable capabilities and unknown facts cannot be fabricated. No new Second Mandate deployment is claimed.

Install or update

Use srstack-0.2.2.zip and verify its entry in SHA256SUMS. Only the complete runtime belongs in the skill directory; do not install the audit ZIP or GitHub's automatic source archive. Cleanly replace the complete runtime rather than overlaying files, retain rollback, and start a fresh host conversation.

The tagged README installation workflow covers review, committed export, staging, verification and recovery. Pin this exact full commit:

619bc244b5709925f7fc3e8c9f6af346739eef31

Default python3 -B -I scripts/verify.py performs offline integrity verification. There is no --offline flag. Execution/network access still requires normal host permission. Integrity is not authenticity or sandbox certification.

Verification and limits

Release commit: 619bc24. Runtime: 43 files. Committed release, scanned export and runtime ZIP members match byte-for-byte; runtime packaging is deterministic.

  • 146 regression tests passed per CI job on Python 3.10 and 3.14. Integrated-main CI.
  • Six final installer/recovery cases passed. Tag-selection smoke tests verified annotated-tag peeling and failure when the requested tag is absent, even with a same-named branch.
  • Historical dogfood evidence includes 35 stateless policy scenarios, a real isolated local CSV/Python/export workflow and six live helper checks. Final changes since that dogfood pin affect only release installation wording and its manifest; policy/helper bytes are unchanged. These are not represented as newly rerun release model/live checks.
  • Two external user reports passed conditional calculations (including the assumed 23.59-day scenario), strategy comparisons, synthetic CSV outputs, unsigned preparation and nonbroadcast simulations, with no unnecessary refusals or signing/submission reported. These reports were not independently rerun. A no-revert simulation is not a completed transaction or verified payout.
  • Authenticated browser and native scheduling integrations remain untested. Model checks and host loading do not establish universal safety or tool-approval enforcement.

Scanner results — findings retained

Prior adversarial policy/runtime reviews cleared the dogfood policy; final release installation/security review found no actionable findings or blockers.

All 10 configured local scans/probes were freshly executed on frozen release bytes. This is not an all-clear security verdict:

  • Cisco strict/behavioral: is_safe=false, one critical fixed-sibling compile/exec finding and four medium findings. No demonstrated untrusted-input injection was found in review; trusted package provenance and protection against local modification remain prerequisites. Medium findings cover disclosed public HTTPS requests, missing machine-readable network metadata and incomplete recursive-reference coverage. The price unreferenced_executable signal is retained. Fresh trace: 10 depth-4 cutoffs and 14 existing-unvisited reference occurrences.
  • Hermes guard accepted the skill with four medium heuristics retained. Loader/default/install, all four parser validations including new-skill authoring, and resource-byte comparisons passed.
  • AgentSkills valid; OpenClaw loader, official validator and packaging passed; local ClawHub static checks clean. Runtime Gitleaks found no findings. Audit-evidence Gitleaks flagged one public STANDARD contract address; verified against the frozen catalog and retained as a false positive without disabling any rule.

See the separate audit bundle for exact toolchain pins, raw findings, dispositions and coverage limits. No hosted scanner or registry acceptance is implied.

Release assets

  • srstack-0.2.2.zip — complete installable runtime.
  • srstack-audit-0.2.2.zip — separate review/scanner/toolchain/verification evidence; not installable. Historical dogfood and prepublication labels are retained as historical evidence; user-reported observations are identified separately.
  • SHA256SUMS — hashes of both ZIPs.

Runtime content SHA-256: 71c6a0683f7993e86e0bbad510423b3b112ec1621873bad817a7fef49aaadc9a.

Prior releases and their assets remain unchanged. No registry submission or hosted scanner upload accompanies this GitHub release.

srstack v0.2.1

Choose a tag to compare

@tomismeta tomismeta released this 21 Sep 10:12

Public inspection beyond the catalog

srstack v0.2.1 fixes instruction-level refusals of legitimate public read-only research. The bundled contract/interface catalogs remain supported starting points, not an inspection allowlist.

What changes

  • Permit supplemental reads of uncataloged contracts, authenticated view/pure getters, public metadata, balances, ownership and transaction/event history.
  • Prefer bundled helpers without making them exclusive; permit bounded locally authored read-only queries and evidenced local arithmetic.
  • Permit other relevant public price sources and independent public RPCs/explorers after an endpoint-specific denial, while prohibiting evasion of that endpoint's controls or host permissions.
  • Separate helper-enforced schemas, provider lists, reserve-approval filters and automatic-fallback limits from the wider research policy.
  • Clarify current-plus-previous flow versus two completed epochs and the historical evidence needed for past claims.
  • Refresh version identity and installation instructions to use the reviewed release tag and full commit pin rather than the retired 0.2.0 candidate branch.

Boundaries retained

No wallet connections/control, secret handling, signing, transaction artifacts, mutating calls/simulations or access-control bypasses. Supplemental evidence must retain source, units, block/time and coverage; it must not be presented as successful fixed-helper output. Catalog identities and getter coverage are unchanged.

Install or update

Use srstack-0.2.1.zip and verify its entry in SHA256SUMS. Only the complete runtime belongs in the skill directory; do not install the audit ZIP or GitHub's automatically generated source archive. Cleanly replace the complete runtime rather than overlaying files, and start a fresh host conversation to load the revised instructions.

The tagged README installation workflow describes reviewed-commit export, staging, verification, retained backups and rollback. Pin this exact full commit:

967b79f0ca1214026dbad82d74a66cd22cb78ba3

Default python3 -B -I scripts/verify.py performs offline integrity verification. There is no --offline flag. Live reads still require normal host execution/network permission. Integrity is not authenticity or sandbox certification.

Verification and limits

Release commit: 967b79f. Runtime: 43 files. Committed main, scanned runtime and runtime ZIP members match byte-for-byte.

  • CI: 146 regression tests passed per job on Python 3.10 and 3.14. Integrated-main run.
  • Six installer/recovery cases, six live CLI smoke checks and 17 stateless instruction scenarios passed. Instruction scenarios are not a universal host-agent safety guarantee.
  • External user reports confirm 43-file integrity checks on OpenClaw and Hermes and a completed supplemental Tax Hook inspection beyond the bundled catalog. These reports were not independently rerun by the release maintainer.
  • The historical +2,000 ETH caption is not verified by this release. Completed-epoch totals and current-plus-previous UI readings describe different windows.

Scanner results — findings retained

Two adversarial reviews completed; the identified policy blockers were fixed and re-reviewed with no remaining blockers.

All configured local scanner checks were run on the frozen runtime, but the scanner result is not an all-clear:

  • Cisco strict/behavioral: is_safe=false; one critical fixed-sibling compile/exec warning and four medium findings. Review found no demonstrated untrusted-input injection. The loader still requires a trusted, integrity-checked local runtime. Medium findings cover disclosed public HTTPS reads, missing machine-readable network metadata and a recursive-reference depth limit that leaves some references unvisited.
  • Hermes: accepted by guard, loader and installation checks; four medium heuristics retained and triaged.
  • AgentSkills valid; OpenClaw loader, validator and local packaging passed; local ClawHub static checks clean.
  • Gitleaks: runtime clean. Audit evidence triggered a generic-key rule on a public STANDARD contract address, verified against the frozen catalog; no rule was disabled.

See the audit bundle for raw findings, exact toolchain pins, dispositions and coverage limitations. No hosted scanner or registry acceptance is implied.

Release assets

  • srstack-0.2.1.zip — complete installable runtime.
  • srstack-audit-0.2.1.zip — separate review, scanner, toolchain and verification evidence; not installable. Historical prepublication reports retain their original status/authorization labels and draft notes. This release follows subsequent explicit publication approval; external host observations are marked user-reported.
  • SHA256SUMS — hashes of both ZIP assets.

Runtime content SHA-256: 55b98eb66f426d2bdedcd6bb48f3fb0e4be188012aa51ba02a498587aaf486d6.

Prior releases and their assets remain unchanged. No registry submission or hosted scanner upload accompanies this GitHub release.

srstack v0.2.0

Choose a tag to compare

@tomismeta tomismeta released this 20 Sep 18:55

Research and inspection, without the planner

srstack v0.2.0 is the independent, read-only Standard Reserve skill focused on source-grounded research and bounded public inspection. It publishes the exact reviewed candidate commit and runtime ZIP; no post-review usability redesign is included.

What changes

  • Two routes: research and inspect. The pre-release strategy simulator, assumption-intake workflow, scripts/scenario.py, fictional fixture and verifier --offline flag are removed. Future-return requests receive qualitative research, not a replacement simulator.
  • Compact charter reads. A normal charter snapshot contains the requested owner, branches, pending balance and supported current-rate equivalent. --detail full opts into broader context and raw evidence. Current-rate equivalents are not promised earnings.
  • Expanded fixed inspection. Auction controllers/pending ownership, CentralBank queued policy/recycling, FeeSplitter current/queued allocations and team ETH liability, and vault controls are supported. snapshot.py treasury --asset ADDRESS checks same-block reserve approval before selected-asset holdings/pool reads. Unknown token/internal-ledger scales remain explicitly raw; queued settings do not replace current policy.
  • Bounded auction and buyback history. history.py license, charter and buybacks use finite ranges and request/log/byte/time budgets. The default lookback is one million blocks, not a promised time interval. Empty checked windows are not all-time absence. Buyback totals are event-accounted, not independently reconciled transfers or aggregate protocol burns.
  • Better operational boundaries. Original bounded HTTP-denial diagnostics, clean replacement/rollback, and an external full-commit installation record improve troubleshooting without retries around denial or host-permission bypasses.
  • Second Mandate research, not invented deployments. Announced strategy and sample positions remain distinct from observed holdings, deployed functionality and holder revenue rights.

Install or update

Use srstack-0.2.0.zip and verify its entry in SHA256SUMS. Only that complete runtime belongs in the skill directory; do not install the audit ZIP or GitHub's automatically generated source archive. Cleanly replace older versions rather than overlaying files, since the planner was removed.

The tagged README installation workflow describes staging, integrity verification, retained backups and rollback. Its reviewed-commit workflow can be used with this exact full commit:

660bdd315688e3962c40e65839764fcf5f6fa766

Frozen wording: the approved package still describes itself as an unpublished/candidate snapshot and includes the candidate branch installation example. That describes its prepublication review state; this GitHub release and annotated tag establish publication. No runtime bytes were changed merely to remove that wording. Pin the full commit above, not the moving branch or version string. Start a fresh host conversation after loading; replacing the files does not reset other chats.

Release checkout: the merged feature/v0.2.0 branch is retired. In README installation step 1, replace both occurrences of feature/v0.2.0 (the git clone --branch and git fetch origin arguments) with v0.2.0. Leave the remaining commands unchanged and confirm the resolved full commit matches the pin above. The permanent release tag and attached runtime ZIP remain available.

Default python3 -B -I scripts/verify.py is offline integrity verification. There is no --offline flag. Live helpers still require normal host execution/network permission. Integrity is not authenticity or sandbox certification.

Verification and limits

Release commit: 660bdd3. Runtime: 43 files, 16 source records, 115 parameter records and 14 publisher-listed identities. The fixed interface has 128 calls, nine getter roles and eleven authentication roles; this is not a complete contract audit.

  • CI: 146 regressions passed per job on Python 3.10 and 3.14. Reviewed-commit run.
  • Installer: six success/replacement/rollback/rejection cases passed using the actual installation instructions.
  • Live smoke: protocol/auction/treasury reads and approval-based withholding were exercised. A million-block buyback scan completed all 100 windows and observed four events. That scan preceded the final one-line auction final-anchor error-flag fix; the exact committed export separately exercised treasury, license history and buyback history. Approved reserve-asset positive decoding was covered deterministically, not established by a live approved-asset smoke.
  • Independent adversarial review: runtime/ABI/accounting and package/execution/documentation reviews completed. An auction completeness flag and build/install path-bound mismatch were reproduced and fixed with regressions. Conservative transitive authentication was retained and documented.
  • Exact bytes: the committed export, final scanned runtime and runtime ZIP members match byte-for-byte.

Scanner results — findings retained

Cisco Skill Scanner 2.1.0, strict static/behavioral: 1 critical and 4 medium findings. This is not a clean scanner verdict. The critical flags exec(compile(...)) used to load the literal, descriptor-checked local snapshot.py sibling. Review found no caller/network-controlled executable input under the documented trusted-runtime preflight; the design was not disguised or weakened to silence the scanner. The medium findings cover two intentional fixed network clients, reference nesting and a declaration-channel conflict: Cisco expects optional compatibility frontmatter, while the pinned OpenClaw packager rejects it. Python/network requirements remain explicit in the integrity-bound skill body. Full findings and dispositions are attached.

Gitleaks 8.30.1 found no secrets in the final runtime directory. AgentSkills validation passed. Hermes normal guard allowed the temporary installation, and all 43 loaded resources matched. OpenClaw eligibility, official validation and local packaging passed; packaged members matched the runtime. Local ClawHub static moderation was clean; this is not hosted registry approval. Release evidence/assets receive a separate secret scan before upload.

Scans used pinned tooling, isolated temporary state and an offline sandbox. No findings were suppressed. These checks do not certify model-driven host behavior, smart-contract security, historical completeness, solvency or future returns. Trusted package/interpreter integrity and host approval enforcement remain external prerequisites.

Release assets

  • srstack-0.2.0.zip — complete installable runtime.
  • srstack-audit-0.2.0.zip — separate sanitized review, scanner, toolchain and verification evidence; not installable. Historical prepublication reports retain their original status labels; the publication record distinguishes the approved release.
  • SHA256SUMS — hashes of both ZIP assets.

Runtime content SHA-256: 673265f5b78c36b695aa2715ccb20bd7e78f5125fcdf9ebe2c8578a526f9ea40.

Prior releases and their assets remain unchanged. No registry submission or hosted scanner upload accompanies this GitHub release.

srstack v0.1.3

Choose a tag to compare

@tomismeta tomismeta released this 18 Sep 22:56

Easier installation and direct helper commands

srstack v0.1.3 improves the ergonomics of the independent, read-only Standard Reserve skill. Financial models, canonical parameters, planner schema/model 1 and live-reader targets are unchanged.

What improves for users and agents

  • Install a complete, verified bundle. The README now separates normal pinned-release installation from reviewed-commit/isolated review. The normal workflow checks the runtime ZIP checksum, safely stages and verifies it, preserves the old installation outside discovery roots, and restores it if final verification fails. It does not require downloading the audit ZIP.

  • Use explicit helper arguments instead of stdin plumbing. New commands cover protocol/auction/charter snapshots, price and gross-value reads, and the fixed fictional example. No-argument JSON stdin remains supported; calculation and result schemas are unchanged.

    python3 -B -I scripts/snapshot.py charter --id 1
    python3 -B -I scripts/price.py --amount-standard 2220.9
    python3 -B -I scripts/scenario.py --example

    These are example inputs, not a claim about your position. Live reads and helper execution still require normal host permission.

  • Verify first, smoke only when requested. python3 -B -I scripts/verify.py checks complete runtime membership and hashes without launching a child or fetching data. --offline adds only the fictional example and rejects live flags. --charter 1 --price explicitly checks one live charter plus its gross pending-balance valuation. Stage status, bounded failure details and elapsed time distinguish integrity failures from helper failures; incomplete checks never pass.

  • Know what a quick test should do. The docs cover the three-route menu, offline explanations, direct inspection and the common charter USD question: one charter snapshot, then one price read using the exact pending amount. Stage timing is not a promise about model, discovery or approval latency.

Update your installed copy

Use the attached runtime ZIP, verify its entry in SHA256SUMS, and follow the normal pinned-release installation instructions. Preserve customizations in the retained backup; do not overlay an old install, install a full repository/source-code archive, or install the audit ZIP. Confirm the actual loaded path/version in a fresh host conversation.

The verifier establishes integrity against its manifest, not authenticity. Review/pin the release and trust the outer checksum before executing package code. There are no wallet operations, dependency installers, credential lookups, telemetry or permission bypasses in the runtime helpers.

Scope and verification

Release commit: 9d82fcd. The runtime contains 45 files, 12 source records, 115 parameters and 14 entities.

  • CI: all 136 tests per job passed on Python 3.10 and 3.14, including verifier containment/failure boundaries and deterministic packaging. Final candidate run.
  • Runtime and installer: default/offline diagnostics passed with network denied; nine installer success/rejection/rollback cases passed using the actual README shell block with local release URLs. The fictional example's complete output matched v0.1.2 byte-for-byte. Live snapshots, quotes, cross-check, exact-amount gross valuation and the combined diagnostic were exercised. An initial protocol RPC HTTP failure and its later successful same-command invocation are both retained.
  • Native OMP: menu and packaged research required no live helpers; charter USD used one snapshot plus one price call with the exact amount; the fictional example ran once; the denial scenario refused wrappers/PTY/YOLO without tools. The host truncated the fictional numerical display, so the model did not invent outcomes or rerun it; complete helper output was independently checked. These targeted checks are not full Hermes/OpenClaw model-host certification.
  • Pinned repeat scans: Cisco Skill Scanner 2.1.0 strict static/behavioral analysis reported 0 high/critical and 3 medium findings; all 45 files were independently inventoried, with recursive-reference depth limits retained. The normal unmodified Hermes community guard allowed installation without force, with 3 medium warnings; discovery and all 45 resources in default/raw/preprocessed modes passed. Local ClawHub moderation was clean; its nonfatal Bun diagnostic is retained. Gitleaks 8.30.1 found no secrets in the runtime, all 21 reachable commits, or the final scanned evidence/assets.

The initial candidate was blocked by Hermes for README installer environment reads. The final installer takes explicitly selected paths as positional arguments instead; the unchanged guard then passed. The rejected attempt, final findings and dispositions remain in the audit evidence. No findings were suppressed. Scanner tooling ran with isolated state, verified source/dependencies, and kernel-enforced home/write/network boundaries; this is bounded release evidence, not a smart-contract audit or sandbox guarantee.

Release assets

Tagged SKILL.md is available for inspection; importing that one file is not a complete installation. Published v0.1.2 remains unchanged.

srstack v0.1.2

Choose a tag to compare

@tomismeta tomismeta released this 18 Sep 21:59

Clearer supply accounting, broader inspection and smoother host workflows

srstack 0.1.2 adds permanent-burn decomposition, launch-restriction and Hook-control context, and more direct question routing. It remains an independent, read-only Agent Skill with no wallet or transaction path.

What improves for users and agents

  • See what permanently reduces the supply ceiling. Protocol and public-charter snapshots separate permanent token burns from retired ledger value alongside the existing total. Deposits remain conversions into re-mintable ledger credit, not permanent cap reduction; cumulative counters do not identify daily buyback purchases.
  • Get a useful charter overview without special wording. A broad “Show charter 1” request includes branches, accrued STANDARD, available current-stream daily equivalent, protocol-wide permanent removal and cap/gate context from one snapshot. Balance-only requests remain narrow; market pricing is added only when requested.
  • Distinguish enabled restrictions from active ones. New observations cover the holding-cap amount and enabled/active flags, Pool Manager gate, Hook launch schedule and pending ownership. Observed Registry/Pool Manager addresses are not new callable targets or independently checked bindings. None of these flags guarantees a transfer or sale will settle.
  • Keep announced changes separate from deployed rules. The reviewed @0xbeans proposal is attributed as proposal context: 12-hour branch auctions, a 50/50 immediate-burn/incentive-vault split and buy-side-only incremental POL. It does not silently replace canonical parameters, halve license costs, double daily dilution or change the separate buyback-burn vault.
  • Plan with clearer limits. Guidance explains epoch-rollover downtime, unsupported intraday auctions/incentive distributions/POL mechanics, and the difference between an approved sensitivity and a settlement-aware forecast. Planner calculations and canonical economic parameters remain unchanged.
  • Handle host approvals deliberately. Agents select a permitted input path and stop when approval cannot be obtained instead of trying wrappers, PTYs or disabled guards. The bundled fictional example has a fixed file-redirection path, still subject to normal host permission. Installation guidance also avoids leaving the shell in a deleted working directory.

Explanation-only questions use the relevant packaged resource without unnecessary RPC reads or planner intake. Failed Hook reads preserve available charter/token accounting as partial results; inconsistent complete burn decomposition suppresses only the affected derived total.

Try Use srstack. Show charter 1, ask whether the holding cap is active, or ask how the developer proposals differ from the documented rules and fixed planner.

Update your installed copy

Download srstack-0.1.2.zip and verify it with SHA256SUMS. Preserve local customizations outside skill-discovery roots, then replace the old installation cleanly. Install the complete srstack/ folder, including release-manifest.json; do not overlay files, update only SKILL.md, or copy the full repository.

Use the attached runtime ZIP, not GitHub’s automatic Source code archives. The separate audit archive is not an installable skill. Start a fresh conversation and confirm the loaded version, revision and path.

The helpers use Python 3.10+ and its standard library, with the documented filesystem protections. Public reads require no API key. Planner schema/model and helper schema remain 1. Shared price fallback and optional provider cross-checking are retained. No published v0.1.0 or v0.1.1 tag or asset is changed.

Scope and verification

Final release commit: 2b66dc15bd9d0c5466d6976cb44d748cc5da5134.

  • Automated checks: 26 planner, 25 snapshot, 38 pricing and 14 packaging tests passed in final-commit CI on Python 3.10 and 3.14: 103 checks per job. Deterministic ZIP output matches the clean exact-commit export.
  • Native workflows: fresh Oh My Pi sessions on the final commit exercised the broad charter overview, approved offline fixture and refusal to bypass an already-reported approval denial. The planner may use a permitted environment pipeline and recover output with a repeat invocation; this is not a universal latency guarantee or a test of Hermes’ approval engine.
  • Live helper checks: all ten additive snapshot fields were present, burn components reconciled to permanent removal, and DEX Screener pricing with the GeckoTerminal cross-check worked. Raw financial observations are not bundled into the skill or audit archive.
  • External host feedback: testers reported successful fresh-session installation and useful answers in OpenClaw 2026.8.1 and Hermes Agent v0.20.6 on the earlier d0bac878 candidate. These are attributed reports, not final-commit native-host tests or sandbox proof. Hermes one-shot approval friction remains material; its reported fictional planner run used --yolo, which is not evidence that normal approvals work and is not recommended by the skill.
  • Hermes: pinned-source metadata checks, normal community quarantine/install, discovery and all 44 resources passed. Skills Guard returned safe/allowed without force, retaining one medium warning for the README’s maintainer git clone example. The same source and dependency versions were used as before, with Python 3.14.6 rather than 3.13.7; platform wheel provenance is recorded.
  • ClawHub: pinned-source local slug, metadata, full-file hashing and static moderation checks passed; moderation reported clean. This is not hosted registry acceptance. The prior nonfatal Bun tsconfig diagnostic remains disclosed.
  • Cisco Skill Scanner 2.1.0: strict offline static and behavioral checks reported no high/critical findings. Behavioral analysis here is static AST/dataflow, not live candidate execution. The same three medium warnings remain: nested documentation references and necessary HTTPS primitives in the snapshot and price readers. All 44 files were independently inventoried and byte-matched; recursive semantic coverage remains bounded. Findings and dispositions are retained, with no rules suppressed.
  • Gitleaks 8.30.1: no credentials detected in the runtime or all 19 reachable repository commits. Sanitized audit evidence and final release assets are also checked before publication.

Scanner checks used verified pinned tool artifacts, credential-free environments and tested kernel restrictions on personal-home reads, outside-workspace writes, candidate writes and scanner network access. Those controls describe the audit environment, not automatic enforcement on every installed host. Corrected provisioning/probe harness attempts and nonfatal diagnostics are retained rather than presented as candidate defects or silently discarded.

Prices remain provider-reported indicative marks, not executable quotes. Retrieval/cache age is not quote age, and separate provider/chain observations are not atomic. Source/interface review is not a smart-contract security audit. No independent human security audit, hosted ClawHub submission, VirusTotal or remote LLM security scan is claimed. NVIDIA/SkillSpector integration remains deferred. A skill prompt is not a sandbox; projections are not forecasts or guaranteed returns.

Release assets

  • srstack-0.1.2.zip — installable 44-file runtime under srstack/ (43 manifest-listed content files plus the manifest).
  • srstack-audit-0.1.2.zip — separate sanitized verification reports, tool provenance, retained findings and scope limits; not an installable skill.
  • SHA256SUMS — SHA-256 checksums for both archives.

Pinned entrypoint: https://raw.githubusercontent.com/tomismeta/srstack/2b66dc15bd9d0c5466d6976cb44d748cc5da5134/SKILL.md

srstack v0.1.1

Choose a tag to compare

@tomismeta tomismeta released this 16 Sep 02:32

Current prices, clearer valuations and explicit projection choices

srstack 0.1.1 adds a shared STANDARD price reader for research, gross accrued-balance valuation and optional current-price projection inputs. It remains an independent, read-only Agent Skill with no wallet or transaction path.

What improves for users and agents

  • Get STANDARD prices without broad web searches. The fixed reader checks the exact Robinhood canonical ETH/STANDARD pool and token identities. It reports USD and ETH prices with provider attribution, retrieval time and explicit limits.
  • Use a labelled availability fallback. DEX Screener remains primary; GeckoTerminal can supply the quote if the primary is temporarily unavailable. The fallback and reason are visible. Identity, malformed-data, certificate and access-denial failures are not bypassed. Explicit provider selection disables automatic switching.
  • Cross-check when requested. Compare the two fixed providers and see separate quotes and percentage differences. The reader never averages providers, chooses the higher quote or mixes one provider's USD price with the other's ETH price. Each invocation makes at most two bounded requests.
  • Value accrued balances without overstating proceeds. Current-value questions reuse the price reader's exact local multiplication. A charter snapshot supplies its accrued STANDARD-denominated ledger amount; the result is a gross market mark before withdrawal and trading costs, not wallet holdings, net exit proceeds or a charter resale value. Quantities and charter IDs are not sent to price providers.
  • Choose projection prices explicitly. When the price basis is missing, agents offer current prices, hypothetical prices or both before fetching. Supplied prices take precedence, complete offline examples stay offline, and holding a current price constant into the future remains an explicit assumption. The scenario engine remains offline.

Try Use srstack inspect price, Cross-check the current STANDARD price, or ask for the gross value of a supplied amount or public charter's accrued balance.

Update your installed copy

Download srstack-0.1.1.zip and verify it with SHA256SUMS. Preserve local customizations outside skill-discovery roots, then replace the old installation cleanly. Install the complete srstack/ folder, including release-manifest.json; do not overlay files, update only SKILL.md, or copy the full repository.

Use the attached runtime ZIP, not GitHub's automatic Source code archives. The separate audit archive is not an installable skill. Start a fresh conversation and confirm the loaded version, revision and path.

The helpers use Python 3.10+ and its standard library, with the documented filesystem protections. Public price reads require no API key. Planner schema/model and helper schema remain 1. No published v0.1.0 tag or asset was changed.

Scope and verification

Final release commit: a96b4d65ba530abb6b740b939b286ce366ff1a58.

  • Automated checks: 26 planner, 20 snapshot, 38 pricing and 14 packaging tests passed in final-commit CI on Python 3.10 and 3.14: 98 checks per job.
  • Native workflows: eight fresh Oh My Pi sessions exercised price-choice consent, supplied-price precedence, current and comparison cases, gross charter valuation, offline planning, explicit GeckoTerminal selection and provider cross-checking against the exported candidate. These are not native Hermes/OpenClaw model-session claims.
  • Live helper checks: both providers and cross-check output worked. A separately labelled controlled-primary-timeout probe exercised the real GeckoTerminal fallback without a third request; it does not claim an actual DEX Screener outage.
  • Hermes: pinned-source metadata/name/size checks, normal community quarantine/install, discovery and all 44 resources passed. Skills Guard returned safe/allowed without force, retaining one medium warning for the README's maintainer git clone example.
  • ClawHub: pinned-source local slug, metadata, full-file hashing and static moderation checks passed; moderation reported clean. This is not hosted registry acceptance. A non-fatal Bun tsconfig diagnostic remains disclosed.
  • Cisco Skill Scanner 2.1.0: strict offline static and behavioral checks reported no high/critical findings. Three medium warnings remain: nested documentation references and the necessary HTTPS primitives in the snapshot and price readers. Their dispositions are included; no rules were suppressed.
  • Gitleaks 8.30.1: no credentials detected in the runtime or all 17 reachable repository commits. Sanitized audit evidence and final release assets were also checked before publication.

Scanner checks used verified pinned tool artifacts, credential-free environments and tested kernel restrictions on personal-home reads, outside-workspace writes, candidate writes and scanner network access. Those controls describe the audit environment, not automatic enforcement on every installed host.

Prices are provider-reported indicative marks, not executable quotes. Neither consumed pool response supplies a price-observation timestamp; retrieval/cache age is not quote age, and separate provider/chain observations are not atomic. More digits or cross-check agreement does not establish independent truth. No independent human security audit, Solidity audit, hosted ClawHub submission, VirusTotal or remote LLM security scan is claimed. A skill prompt is not a sandbox; projections are not forecasts or guaranteed returns.

Release assets

  • srstack-0.1.1.zip — installable 44-file runtime under srstack/ (43 manifest-listed content files plus the manifest).
  • srstack-audit-0.1.1.zip — separate sanitized verification reports, tool provenance, retained findings and scope limits; not an installable skill.
  • SHA256SUMS — SHA-256 checksums for both archives.

Pinned entrypoint: https://raw.githubusercontent.com/tomismeta/srstack/a96b4d65ba530abb6b740b939b286ce366ff1a58/SKILL.md

srstack v0.1.0

Choose a tag to compare

@tomismeta tomismeta released this 15 Sep 20:43

Read-only research, guided planning and live public inspection

srstack 0.1.0 is the initial release of an independent Agent Skill for Standard Reserve research, hypothetical strategy comparisons and bounded public contract reads. One skill provides three routes: research, plan and inspect.

What users and agents can do

  • Research documented mechanics. Follow source-linked explanations of charters, withdrawals, issuance, auctions, reserves and fees, with evidence gaps kept explicit.
  • Compare expansion strategies using approved assumptions. A guided conversation prepares inputs for keep, selective-expansion and aggressive-expansion comparisons. Documented mode checks known constraints; stress mode reports explicitly approved departures. The fixed planner runs offline.
  • Read current public state. Inspect protocol, auction and selected public-charter state using a fixed publisher-ABI reader on Robinhood Chain. Each invocation uses one checked block; separate invocations are not an atomic combined snapshot.
  • Distinguish known identities from read coverage. The catalog contains 14 publisher-listed identities, with selected live reads across six contracts. Publisher attribution and ABI provenance are not independently verified Solidity source code.
  • Keep unavailable information unavailable. No stored balances, auction statuses, recap metrics or verification verdicts are used as live-state fallbacks. Unavailable auctions do not produce purchasable quotes; inactive or unknown emissions do not produce active daily-rate estimates.

Install your copy

Download srstack-0.1.0.zip and verify its hash against SHA256SUMS. Install the complete srstack/ folder, including its manifest, into the intended host's configured skill directory. Preserve local customizations outside discovery roots and replace an old installation cleanly; do not overlay files or copy only SKILL.md.

Use the attached runtime ZIP, not GitHub's automatic Source code archives. Do not install .git, maintenance tools, CI files or the audit archive. Start a fresh conversation and confirm the loaded revision and path with Use srstack.

Packaged research requires a resource reader. The two fixed helpers require permitted Python 3.10+ execution and the documented filesystem protections; live inspection additionally requires access to the fixed public RPC. No pip dependencies, RPC credentials or wallet connector are required by the helpers. Planner schema/model remain 1.

Scope and verification

Final release commit: b13b90109e6b81bb5bc778dd5166b65e8603fc8d.

  • Automated checks: 26 planner, 20 snapshot and 14 packaging tests passed in final-commit CI on Python 3.10 and 3.14. Final exported planner and live protocol-reader smoke checks also passed.
  • Hermes: pinned-source metadata validation, normal community quarantine/install, discovery and all 42 resource reads passed. Skills Guard returned safe/allowed without force, retaining one medium warning for the README's maintainer git clone example.
  • ClawHub: pinned-source local metadata, slug, file/hash and static moderation checks passed; moderation reported clean. This is not hosted registry acceptance. A non-fatal Bun diagnostic and dependency-lock path normalization are disclosed in the evidence.
  • Cisco Skill Scanner 2.1.0: strict offline static and behavioral checks reported no high/critical findings. Two medium warnings remain: nested documentation references and the necessary outbound HTTPS primitive. Their review dispositions are included; no scanner rules were suppressed.
  • Gitleaks 8.30.1: no credentials detected in the runtime package or all 14 reachable repository commits.

Scanner checks ran with a minimal credential-free environment and tested kernel restrictions on personal-home reads, writes outside the audit workspace, candidate writes and scanner network access. Maintainer-reported native Hermes/OpenClaw trials apply to their recorded earlier candidates; they are not represented as final-tag sandbox tests.

This is not an independent human security audit, Solidity audit, universal host-isolation guarantee or zero-findings claim. No hosted ClawHub submission, remote LLM security analysis or VirusTotal scan was performed. A skill prompt is not a sandbox. The package does not connect wallets, sign, prepare executable transactions or perform financial actions; hypothetical comparisons are not forecasts or guaranteed returns.

Release assets

  • srstack-0.1.0.zip — installable 42-file runtime package under srstack/ (41 manifest-listed content files plus release-manifest.json).
  • srstack-audit-0.1.0.zip — separate sanitized validation evidence, tool provenance, retained findings and scope limits. Not an installable skill.
  • SHA256SUMS — SHA-256 checksums for both archives.

Pinned entrypoint: https://raw.githubusercontent.com/tomismeta/srstack/b13b90109e6b81bb5bc778dd5166b65e8603fc8d/SKILL.md