Skip to content

feat: bundle TWZRD pre-sign x402 hook and verify proxy env forwarding - #43

Open
twzrd-sol wants to merge 1 commit into
BlockRunAI:mainfrom
twzrd-sol:feat/twzrd-before-sign
Open

twzrd-sol wants to merge 1 commit into
BlockRunAI:mainfrom
twzrd-sol:feat/twzrd-before-sign

Conversation

@twzrd-sol

Copy link
Copy Markdown

Python tools using their own x402 client currently have no bundled pre-sign wash hook. Add clawrouter_hermes.twzrd.create_before_sign_hook() and register the accompanying twzrd-before-sign skill through the existing plugin context. Installing the skill alone does not intercept payments: the tool must register the callback on its actual async x402 client.

The optional [twzrd] extra supports Python 3.11+ without changing base plugin dependencies or Python requirements. It uses the official x402 before-payment lifecycle and refuses flagged, unknown, partial, stale, or unavailable merchant-card evidence. Full negative wash evidence permits continuation; it is not a general merchant safety judgment. The intel service receives the selected payee and normal connection metadata.

Proxy environment forwarding already exists via dict(os.environ) into Popen; regression tests now cover explicit TWZRD_AUTO_GATE/TWZRD_FAIL_OPEN propagation and unchanged unset defaults. No redundant supervisor code or default-policy change. Reused/external proxies require their own configuration, and forwarding does not prove that the Node gate package resolved or activated. API-key billing and arbitrary Python tools remain outside this hook.

Validation:

  • Full suite: 142 passed, 4 skipped (existing optional/live/sibling checks).
  • Real EVM and SVM SDK signing: refusal calls the signer zero times; full negative evidence signs once. Allowed SVM client signature cryptographically verified with offline RPC fixtures.
  • HTTP 402 transport refuses without paid retry and preserves PaymentAbortedError as the wrapped cause.
  • Fresh wheel install with [twzrd], dependency compatibility check, packaged helper/skill smoke test passed.
  • Brand-numbers and diff checks passed; dedicated optional-extra CI job added.

The extra pins solana==0.36.10: 0.40.3 removes the synchronous RPC module x402 imports, while 0.36.6 conflicts with x402's solders requirement. No payments broadcast, runtime deployment, or independent adoption claimed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant