Skip to content

srstack v0.2.1

Choose a tag to compare

@tomismeta tomismeta released this 21 Sep 10:12
· 31 commits to main since this release

Public inspection beyond the catalog

srstack v0.2.1 fixes instruction-level refusals of legitimate public read-only research. The bundled contract/interface catalogs remain supported starting points, not an inspection allowlist.

What changes

  • Permit supplemental reads of uncataloged contracts, authenticated view/pure getters, public metadata, balances, ownership and transaction/event history.
  • Prefer bundled helpers without making them exclusive; permit bounded locally authored read-only queries and evidenced local arithmetic.
  • Permit other relevant public price sources and independent public RPCs/explorers after an endpoint-specific denial, while prohibiting evasion of that endpoint's controls or host permissions.
  • Separate helper-enforced schemas, provider lists, reserve-approval filters and automatic-fallback limits from the wider research policy.
  • Clarify current-plus-previous flow versus two completed epochs and the historical evidence needed for past claims.
  • Refresh version identity and installation instructions to use the reviewed release tag and full commit pin rather than the retired 0.2.0 candidate branch.

Boundaries retained

No wallet connections/control, secret handling, signing, transaction artifacts, mutating calls/simulations or access-control bypasses. Supplemental evidence must retain source, units, block/time and coverage; it must not be presented as successful fixed-helper output. Catalog identities and getter coverage are unchanged.

Install or update

Use srstack-0.2.1.zip and verify its entry in SHA256SUMS. Only the complete runtime belongs in the skill directory; do not install the audit ZIP or GitHub's automatically generated source archive. Cleanly replace the complete runtime rather than overlaying files, and start a fresh host conversation to load the revised instructions.

The tagged README installation workflow describes reviewed-commit export, staging, verification, retained backups and rollback. Pin this exact full commit:

967b79f0ca1214026dbad82d74a66cd22cb78ba3

Default python3 -B -I scripts/verify.py performs offline integrity verification. There is no --offline flag. Live reads still require normal host execution/network permission. Integrity is not authenticity or sandbox certification.

Verification and limits

Release commit: 967b79f. Runtime: 43 files. Committed main, scanned runtime and runtime ZIP members match byte-for-byte.

  • CI: 146 regression tests passed per job on Python 3.10 and 3.14. Integrated-main run.
  • Six installer/recovery cases, six live CLI smoke checks and 17 stateless instruction scenarios passed. Instruction scenarios are not a universal host-agent safety guarantee.
  • External user reports confirm 43-file integrity checks on OpenClaw and Hermes and a completed supplemental Tax Hook inspection beyond the bundled catalog. These reports were not independently rerun by the release maintainer.
  • The historical +2,000 ETH caption is not verified by this release. Completed-epoch totals and current-plus-previous UI readings describe different windows.

Scanner results — findings retained

Two adversarial reviews completed; the identified policy blockers were fixed and re-reviewed with no remaining blockers.

All configured local scanner checks were run on the frozen runtime, but the scanner result is not an all-clear:

  • Cisco strict/behavioral: is_safe=false; one critical fixed-sibling compile/exec warning and four medium findings. Review found no demonstrated untrusted-input injection. The loader still requires a trusted, integrity-checked local runtime. Medium findings cover disclosed public HTTPS reads, missing machine-readable network metadata and a recursive-reference depth limit that leaves some references unvisited.
  • Hermes: accepted by guard, loader and installation checks; four medium heuristics retained and triaged.
  • AgentSkills valid; OpenClaw loader, validator and local packaging passed; local ClawHub static checks clean.
  • Gitleaks: runtime clean. Audit evidence triggered a generic-key rule on a public STANDARD contract address, verified against the frozen catalog; no rule was disabled.

See the audit bundle for raw findings, exact toolchain pins, dispositions and coverage limitations. No hosted scanner or registry acceptance is implied.

Release assets

  • srstack-0.2.1.zip — complete installable runtime.
  • srstack-audit-0.2.1.zip — separate review, scanner, toolchain and verification evidence; not installable. Historical prepublication reports retain their original status/authorization labels and draft notes. This release follows subsequent explicit publication approval; external host observations are marked user-reported.
  • SHA256SUMS — hashes of both ZIP assets.

Runtime content SHA-256: 55b98eb66f426d2bdedcd6bb48f3fb0e4be188012aa51ba02a498587aaf486d6.

Prior releases and their assets remain unchanged. No registry submission or hosted scanner upload accompanies this GitHub release.