srstack v0.1.2
Clearer supply accounting, broader inspection and smoother host workflows
srstack 0.1.2 adds permanent-burn decomposition, launch-restriction and Hook-control context, and more direct question routing. It remains an independent, read-only Agent Skill with no wallet or transaction path.
What improves for users and agents
- See what permanently reduces the supply ceiling. Protocol and public-charter snapshots separate permanent token burns from retired ledger value alongside the existing total. Deposits remain conversions into re-mintable ledger credit, not permanent cap reduction; cumulative counters do not identify daily buyback purchases.
- Get a useful charter overview without special wording. A broad “Show charter 1” request includes branches, accrued STANDARD, available current-stream daily equivalent, protocol-wide permanent removal and cap/gate context from one snapshot. Balance-only requests remain narrow; market pricing is added only when requested.
- Distinguish enabled restrictions from active ones. New observations cover the holding-cap amount and enabled/active flags, Pool Manager gate, Hook launch schedule and pending ownership. Observed Registry/Pool Manager addresses are not new callable targets or independently checked bindings. None of these flags guarantees a transfer or sale will settle.
- Keep announced changes separate from deployed rules. The reviewed @0xbeans proposal is attributed as proposal context: 12-hour branch auctions, a 50/50 immediate-burn/incentive-vault split and buy-side-only incremental POL. It does not silently replace canonical parameters, halve license costs, double daily dilution or change the separate buyback-burn vault.
- Plan with clearer limits. Guidance explains epoch-rollover downtime, unsupported intraday auctions/incentive distributions/POL mechanics, and the difference between an approved sensitivity and a settlement-aware forecast. Planner calculations and canonical economic parameters remain unchanged.
- Handle host approvals deliberately. Agents select a permitted input path and stop when approval cannot be obtained instead of trying wrappers, PTYs or disabled guards. The bundled fictional example has a fixed file-redirection path, still subject to normal host permission. Installation guidance also avoids leaving the shell in a deleted working directory.
Explanation-only questions use the relevant packaged resource without unnecessary RPC reads or planner intake. Failed Hook reads preserve available charter/token accounting as partial results; inconsistent complete burn decomposition suppresses only the affected derived total.
Try Use srstack. Show charter 1, ask whether the holding cap is active, or ask how the developer proposals differ from the documented rules and fixed planner.
Update your installed copy
Download srstack-0.1.2.zip and verify it with SHA256SUMS. Preserve local customizations outside skill-discovery roots, then replace the old installation cleanly. Install the complete srstack/ folder, including release-manifest.json; do not overlay files, update only SKILL.md, or copy the full repository.
Use the attached runtime ZIP, not GitHub’s automatic Source code archives. The separate audit archive is not an installable skill. Start a fresh conversation and confirm the loaded version, revision and path.
The helpers use Python 3.10+ and its standard library, with the documented filesystem protections. Public reads require no API key. Planner schema/model and helper schema remain 1. Shared price fallback and optional provider cross-checking are retained. No published v0.1.0 or v0.1.1 tag or asset is changed.
Scope and verification
Final release commit: 2b66dc15bd9d0c5466d6976cb44d748cc5da5134.
- Automated checks: 26 planner, 25 snapshot, 38 pricing and 14 packaging tests passed in final-commit CI on Python 3.10 and 3.14: 103 checks per job. Deterministic ZIP output matches the clean exact-commit export.
- Native workflows: fresh Oh My Pi sessions on the final commit exercised the broad charter overview, approved offline fixture and refusal to bypass an already-reported approval denial. The planner may use a permitted environment pipeline and recover output with a repeat invocation; this is not a universal latency guarantee or a test of Hermes’ approval engine.
- Live helper checks: all ten additive snapshot fields were present, burn components reconciled to permanent removal, and DEX Screener pricing with the GeckoTerminal cross-check worked. Raw financial observations are not bundled into the skill or audit archive.
- External host feedback: testers reported successful fresh-session installation and useful answers in OpenClaw 2026.8.1 and Hermes Agent v0.20.6 on the earlier
d0bac878candidate. These are attributed reports, not final-commit native-host tests or sandbox proof. Hermes one-shot approval friction remains material; its reported fictional planner run used--yolo, which is not evidence that normal approvals work and is not recommended by the skill. - Hermes: pinned-source metadata checks, normal community quarantine/install, discovery and all 44 resources passed. Skills Guard returned safe/allowed without force, retaining one medium warning for the README’s maintainer
git cloneexample. The same source and dependency versions were used as before, with Python 3.14.6 rather than 3.13.7; platform wheel provenance is recorded. - ClawHub: pinned-source local slug, metadata, full-file hashing and static moderation checks passed; moderation reported clean. This is not hosted registry acceptance. The prior nonfatal Bun tsconfig diagnostic remains disclosed.
- Cisco Skill Scanner 2.1.0: strict offline static and behavioral checks reported no high/critical findings. Behavioral analysis here is static AST/dataflow, not live candidate execution. The same three medium warnings remain: nested documentation references and necessary HTTPS primitives in the snapshot and price readers. All 44 files were independently inventoried and byte-matched; recursive semantic coverage remains bounded. Findings and dispositions are retained, with no rules suppressed.
- Gitleaks 8.30.1: no credentials detected in the runtime or all 19 reachable repository commits. Sanitized audit evidence and final release assets are also checked before publication.
Scanner checks used verified pinned tool artifacts, credential-free environments and tested kernel restrictions on personal-home reads, outside-workspace writes, candidate writes and scanner network access. Those controls describe the audit environment, not automatic enforcement on every installed host. Corrected provisioning/probe harness attempts and nonfatal diagnostics are retained rather than presented as candidate defects or silently discarded.
Prices remain provider-reported indicative marks, not executable quotes. Retrieval/cache age is not quote age, and separate provider/chain observations are not atomic. Source/interface review is not a smart-contract security audit. No independent human security audit, hosted ClawHub submission, VirusTotal or remote LLM security scan is claimed. NVIDIA/SkillSpector integration remains deferred. A skill prompt is not a sandbox; projections are not forecasts or guaranteed returns.
Release assets
srstack-0.1.2.zip— installable 44-file runtime undersrstack/(43 manifest-listed content files plus the manifest).srstack-audit-0.1.2.zip— separate sanitized verification reports, tool provenance, retained findings and scope limits; not an installable skill.SHA256SUMS— SHA-256 checksums for both archives.
Pinned entrypoint: https://raw.githubusercontent.com/tomismeta/srstack/2b66dc15bd9d0c5466d6976cb44d748cc5da5134/SKILL.md