srstack v0.1.0
Read-only research, guided planning and live public inspection
srstack 0.1.0 is the initial release of an independent Agent Skill for Standard Reserve research, hypothetical strategy comparisons and bounded public contract reads. One skill provides three routes: research, plan and inspect.
What users and agents can do
- Research documented mechanics. Follow source-linked explanations of charters, withdrawals, issuance, auctions, reserves and fees, with evidence gaps kept explicit.
- Compare expansion strategies using approved assumptions. A guided conversation prepares inputs for keep, selective-expansion and aggressive-expansion comparisons. Documented mode checks known constraints; stress mode reports explicitly approved departures. The fixed planner runs offline.
- Read current public state. Inspect protocol, auction and selected public-charter state using a fixed publisher-ABI reader on Robinhood Chain. Each invocation uses one checked block; separate invocations are not an atomic combined snapshot.
- Distinguish known identities from read coverage. The catalog contains 14 publisher-listed identities, with selected live reads across six contracts. Publisher attribution and ABI provenance are not independently verified Solidity source code.
- Keep unavailable information unavailable. No stored balances, auction statuses, recap metrics or verification verdicts are used as live-state fallbacks. Unavailable auctions do not produce purchasable quotes; inactive or unknown emissions do not produce active daily-rate estimates.
Install your copy
Download srstack-0.1.0.zip and verify its hash against SHA256SUMS. Install the complete srstack/ folder, including its manifest, into the intended host's configured skill directory. Preserve local customizations outside discovery roots and replace an old installation cleanly; do not overlay files or copy only SKILL.md.
Use the attached runtime ZIP, not GitHub's automatic Source code archives. Do not install .git, maintenance tools, CI files or the audit archive. Start a fresh conversation and confirm the loaded revision and path with Use srstack.
Packaged research requires a resource reader. The two fixed helpers require permitted Python 3.10+ execution and the documented filesystem protections; live inspection additionally requires access to the fixed public RPC. No pip dependencies, RPC credentials or wallet connector are required by the helpers. Planner schema/model remain 1.
Scope and verification
Final release commit: b13b90109e6b81bb5bc778dd5166b65e8603fc8d.
- Automated checks: 26 planner, 20 snapshot and 14 packaging tests passed in final-commit CI on Python 3.10 and 3.14. Final exported planner and live protocol-reader smoke checks also passed.
- Hermes: pinned-source metadata validation, normal community quarantine/install, discovery and all 42 resource reads passed. Skills Guard returned safe/allowed without force, retaining one medium warning for the README's maintainer
git cloneexample. - ClawHub: pinned-source local metadata, slug, file/hash and static moderation checks passed; moderation reported clean. This is not hosted registry acceptance. A non-fatal Bun diagnostic and dependency-lock path normalization are disclosed in the evidence.
- Cisco Skill Scanner 2.1.0: strict offline static and behavioral checks reported no high/critical findings. Two medium warnings remain: nested documentation references and the necessary outbound HTTPS primitive. Their review dispositions are included; no scanner rules were suppressed.
- Gitleaks 8.30.1: no credentials detected in the runtime package or all 14 reachable repository commits.
Scanner checks ran with a minimal credential-free environment and tested kernel restrictions on personal-home reads, writes outside the audit workspace, candidate writes and scanner network access. Maintainer-reported native Hermes/OpenClaw trials apply to their recorded earlier candidates; they are not represented as final-tag sandbox tests.
This is not an independent human security audit, Solidity audit, universal host-isolation guarantee or zero-findings claim. No hosted ClawHub submission, remote LLM security analysis or VirusTotal scan was performed. A skill prompt is not a sandbox. The package does not connect wallets, sign, prepare executable transactions or perform financial actions; hypothetical comparisons are not forecasts or guaranteed returns.
Release assets
srstack-0.1.0.zip— installable 42-file runtime package undersrstack/(41 manifest-listed content files plusrelease-manifest.json).srstack-audit-0.1.0.zip— separate sanitized validation evidence, tool provenance, retained findings and scope limits. Not an installable skill.SHA256SUMS— SHA-256 checksums for both archives.
Pinned entrypoint: https://raw.githubusercontent.com/tomismeta/srstack/b13b90109e6b81bb5bc778dd5166b65e8603fc8d/SKILL.md