srstack v0.2.1
Public inspection beyond the catalog
srstack v0.2.1 fixes instruction-level refusals of legitimate public read-only research. The bundled contract/interface catalogs remain supported starting points, not an inspection allowlist.
What changes
- Permit supplemental reads of uncataloged contracts, authenticated view/pure getters, public metadata, balances, ownership and transaction/event history.
- Prefer bundled helpers without making them exclusive; permit bounded locally authored read-only queries and evidenced local arithmetic.
- Permit other relevant public price sources and independent public RPCs/explorers after an endpoint-specific denial, while prohibiting evasion of that endpoint's controls or host permissions.
- Separate helper-enforced schemas, provider lists, reserve-approval filters and automatic-fallback limits from the wider research policy.
- Clarify current-plus-previous flow versus two completed epochs and the historical evidence needed for past claims.
- Refresh version identity and installation instructions to use the reviewed release tag and full commit pin rather than the retired 0.2.0 candidate branch.
Boundaries retained
No wallet connections/control, secret handling, signing, transaction artifacts, mutating calls/simulations or access-control bypasses. Supplemental evidence must retain source, units, block/time and coverage; it must not be presented as successful fixed-helper output. Catalog identities and getter coverage are unchanged.
Install or update
Use srstack-0.2.1.zip and verify its entry in SHA256SUMS. Only the complete runtime belongs in the skill directory; do not install the audit ZIP or GitHub's automatically generated source archive. Cleanly replace the complete runtime rather than overlaying files, and start a fresh host conversation to load the revised instructions.
The tagged README installation workflow describes reviewed-commit export, staging, verification, retained backups and rollback. Pin this exact full commit:
967b79f0ca1214026dbad82d74a66cd22cb78ba3
Default python3 -B -I scripts/verify.py performs offline integrity verification. There is no --offline flag. Live reads still require normal host execution/network permission. Integrity is not authenticity or sandbox certification.
Verification and limits
Release commit: 967b79f. Runtime: 43 files. Committed main, scanned runtime and runtime ZIP members match byte-for-byte.
- CI: 146 regression tests passed per job on Python 3.10 and 3.14. Integrated-main run.
- Six installer/recovery cases, six live CLI smoke checks and 17 stateless instruction scenarios passed. Instruction scenarios are not a universal host-agent safety guarantee.
- External user reports confirm 43-file integrity checks on OpenClaw and Hermes and a completed supplemental Tax Hook inspection beyond the bundled catalog. These reports were not independently rerun by the release maintainer.
- The historical +2,000 ETH caption is not verified by this release. Completed-epoch totals and current-plus-previous UI readings describe different windows.
Scanner results — findings retained
Two adversarial reviews completed; the identified policy blockers were fixed and re-reviewed with no remaining blockers.
All configured local scanner checks were run on the frozen runtime, but the scanner result is not an all-clear:
- Cisco strict/behavioral: is_safe=false; one critical fixed-sibling compile/exec warning and four medium findings. Review found no demonstrated untrusted-input injection. The loader still requires a trusted, integrity-checked local runtime. Medium findings cover disclosed public HTTPS reads, missing machine-readable network metadata and a recursive-reference depth limit that leaves some references unvisited.
- Hermes: accepted by guard, loader and installation checks; four medium heuristics retained and triaged.
- AgentSkills valid; OpenClaw loader, validator and local packaging passed; local ClawHub static checks clean.
- Gitleaks: runtime clean. Audit evidence triggered a generic-key rule on a public STANDARD contract address, verified against the frozen catalog; no rule was disabled.
See the audit bundle for raw findings, exact toolchain pins, dispositions and coverage limitations. No hosted scanner or registry acceptance is implied.
Release assets
- srstack-0.2.1.zip — complete installable runtime.
- srstack-audit-0.2.1.zip — separate review, scanner, toolchain and verification evidence; not installable. Historical prepublication reports retain their original status/authorization labels and draft notes. This release follows subsequent explicit publication approval; external host observations are marked user-reported.
- SHA256SUMS — hashes of both ZIP assets.
Runtime content SHA-256: 55b98eb66f426d2bdedcd6bb48f3fb0e4be188012aa51ba02a498587aaf486d6.
Prior releases and their assets remain unchanged. No registry submission or hosted scanner upload accompanies this GitHub release.