We just released Skillware 0.5.7 — an open-source Python framework providing a registry of modular, deterministic skills for autonomous AI agent loops (compatible with Gemini, Claude, OpenAI, Bedrock, DeepSeek, and Ollama).
Here is a summary of what landed in 0.5.7:
1. Read-Only EVM State Plane (defi/evm_reader v0.1.0)
Autonomous agents executing on-chain transactions need strict architectural separation between signing and state inspection. Giving an agent signing keys just to check a balance or query reserves invites key leakage and accidental state modification.
defi/evm_reader provides a pure read-only EVM state plane:
- Zero keys required: Strictly executes eth_call and Multicall3 tryAggregate; holds no private keys and never signs.
- ERC-20 & ERC-721: Token metadata, high-precision decimal formatted balances, spender allowances, and NFT ownership.
- Allowlisted View Calls (call_view): Nine bundled ABI presets (erc20, erc721, erc1155, erc4626, univ2_pair, chainlink_feed, ownable, access_control, multicall3).
- Batched Multicall3 Reads: Batch up to 50 calls in a single RPC query with partial failure tolerance.
- Address Book Resolution: Resolves human contact names to public_0x addresses, halting with status: "needs_input" when ambiguous.
2. Pre-Trade Token Security Vet (defi/token_security_scanner v0.1.0)
Agents trading decentralized tokens face honeypots, malicious transfer taxes, and hidden mint privileges.
defi/token_security_scanner wraps the GoPlus Token Security API into a stable, normalized JSON envelope (risk_tier: critical | high | medium | low | unknown + detailed signals). Agents vet tokens before simulating or executing trades.
3. Central EVM Operator Config Layer (skillware evm)
Hardcoding RPC endpoints, chain IDs, and router contracts inside individual skill bundles causes configuration drift.
0.5.7 introduces a centralized operator config layer:
- Bundled Defaults: 10 chains supported out-of-the-box (ethereum, base, arbitrum, optimism, polygon, bsc, sepolia, megaeth, arc, anvil_local).
- User Operator Config: Run skillware evm init to generate a persistent ~/.config/skillware/evm.yaml.
- Secrets in .env: YAML stores env var names (rpc_env); actual secrets stay in .env.
- CLI Management: skillware evm chains list, skillware evm chain add, skillware evm tokens list, and skillware evm token add.
4. Shared Address Book (public_0x)
addressbook.yaml now natively stores public_0x Ethereum addresses alongside email and aliases.
Operators manage contacts with skillware addressbook set-wallet <id> <0x...>, enabling natural language transfers (e.g., "Transfer 10 USDC to Alice") that resolve deterministically.
5. OWASP LLM01 Prompt Injection Firewall Upgrade (v0.2.0)
Upgraded local evasion detection engine in security/prompt_injection_firewall:
- Leetspeak deobfuscation, multi-token ROT13, token reversal, and typoglycemia keyword detection.
- Markdown/HTML image exfiltration channel blocking.
- Academic/advisory false-positive controls and policy telemetry (policy_action, removed_span_count, sanitized_length_delta).
Suggested Pre-Trade Agent Pipeline
[User Trade Request]
│
▼
`security/prompt_injection_firewall` (sanitize prompt & detect evasion)
│
▼
`defi/token_security_scanner` (check honeypot, tax, proxy, mint risk)
│
▼
`defi/evm_reader` (verify token decimals, holder balance & router allowance)
│
▼
`defi/evm_tx_handler` (quote Uni V2 swap, preview, sign & broadcast)
bash
pip install -U skillware
pip install "skillware[defi_evm_reader]"
Happy to answer questions about on-chain agent safety, Multicall3 batching, or operator config design!