Skip to content

srstack v0.2.2

Choose a tag to compare

@tomismeta tomismeta released this 21 Sep 12:18
· 19 commits to main since this release

Analysis, forecasts and user-directed workflows

srstack v0.2.2 removes instruction-level refusals of requested analysis and workflows. Bundled catalogs and helpers are starting points, not a capability allowlist.

What changes

  • Permit conditional accrual/time-to-target calculations, forecasts, fee/net estimates, strategy comparisons and proposal analysis with explicit inputs and assumptions.
  • Permit consent-scoped local/private-data analysis, exports, reports and caches; host-authorized authenticated research; approved dependencies and custom tools; and explicitly requested bounded monitoring/schedules where the host supports them.
  • Permit supplemental contracts, interfaces and sources, unsigned transaction preparation, informational how-to workflows and nonbroadcast calls, quoters, gas estimates, traces and simulations.
  • Judge the actual tool invocation, including nested/batched effects, rather than banning a tool because it also exposes unused signing/submission methods.
  • Expand routing to research / inspect / analyse / workflows. Keep bundled helper schemas and checks narrow without turning them into agent-wide refusals.
  • Update installation to the reviewed release tag/full commit and keep the skill description within Hermes' authoring limit.

Boundaries retained

No wallet signing, signature requests or transaction submission/broadcast, including delegation and submission of pre-signed transactions. Host-authorized read-only account/address access is permitted; SIWE/signature login is not. Host permissions, access controls, credential protection, private-data consent, untrusted-source handling and evidence integrity remain mandatory.

No new simulator, scheduler, wallet engine or cataloged deployment is bundled. The retired scenario helper is not restored. Other workflows require actual host capabilities or inspectable task code; unavailable capabilities and unknown facts cannot be fabricated. No new Second Mandate deployment is claimed.

Install or update

Use srstack-0.2.2.zip and verify its entry in SHA256SUMS. Only the complete runtime belongs in the skill directory; do not install the audit ZIP or GitHub's automatic source archive. Cleanly replace the complete runtime rather than overlaying files, retain rollback, and start a fresh host conversation.

The tagged README installation workflow covers review, committed export, staging, verification and recovery. Pin this exact full commit:

619bc244b5709925f7fc3e8c9f6af346739eef31

Default python3 -B -I scripts/verify.py performs offline integrity verification. There is no --offline flag. Execution/network access still requires normal host permission. Integrity is not authenticity or sandbox certification.

Verification and limits

Release commit: 619bc24. Runtime: 43 files. Committed release, scanned export and runtime ZIP members match byte-for-byte; runtime packaging is deterministic.

  • 146 regression tests passed per CI job on Python 3.10 and 3.14. Integrated-main CI.
  • Six final installer/recovery cases passed. Tag-selection smoke tests verified annotated-tag peeling and failure when the requested tag is absent, even with a same-named branch.
  • Historical dogfood evidence includes 35 stateless policy scenarios, a real isolated local CSV/Python/export workflow and six live helper checks. Final changes since that dogfood pin affect only release installation wording and its manifest; policy/helper bytes are unchanged. These are not represented as newly rerun release model/live checks.
  • Two external user reports passed conditional calculations (including the assumed 23.59-day scenario), strategy comparisons, synthetic CSV outputs, unsigned preparation and nonbroadcast simulations, with no unnecessary refusals or signing/submission reported. These reports were not independently rerun. A no-revert simulation is not a completed transaction or verified payout.
  • Authenticated browser and native scheduling integrations remain untested. Model checks and host loading do not establish universal safety or tool-approval enforcement.

Scanner results — findings retained

Prior adversarial policy/runtime reviews cleared the dogfood policy; final release installation/security review found no actionable findings or blockers.

All 10 configured local scans/probes were freshly executed on frozen release bytes. This is not an all-clear security verdict:

  • Cisco strict/behavioral: is_safe=false, one critical fixed-sibling compile/exec finding and four medium findings. No demonstrated untrusted-input injection was found in review; trusted package provenance and protection against local modification remain prerequisites. Medium findings cover disclosed public HTTPS requests, missing machine-readable network metadata and incomplete recursive-reference coverage. The price unreferenced_executable signal is retained. Fresh trace: 10 depth-4 cutoffs and 14 existing-unvisited reference occurrences.
  • Hermes guard accepted the skill with four medium heuristics retained. Loader/default/install, all four parser validations including new-skill authoring, and resource-byte comparisons passed.
  • AgentSkills valid; OpenClaw loader, official validator and packaging passed; local ClawHub static checks clean. Runtime Gitleaks found no findings. Audit-evidence Gitleaks flagged one public STANDARD contract address; verified against the frozen catalog and retained as a false positive without disabling any rule.

See the separate audit bundle for exact toolchain pins, raw findings, dispositions and coverage limits. No hosted scanner or registry acceptance is implied.

Release assets

  • srstack-0.2.2.zip — complete installable runtime.
  • srstack-audit-0.2.2.zip — separate review/scanner/toolchain/verification evidence; not installable. Historical dogfood and prepublication labels are retained as historical evidence; user-reported observations are identified separately.
  • SHA256SUMS — hashes of both ZIPs.

Runtime content SHA-256: 71c6a0683f7993e86e0bbad510423b3b112ec1621873bad817a7fef49aaadc9a.

Prior releases and their assets remain unchanged. No registry submission or hosted scanner upload accompanies this GitHub release.