Skip to content

Releases: BlockRunAI/Franklin

v3.49.6 — money that may have moved is never sent twice

Choose a tag to compare

@VickyXAI VickyXAI released this 08 Oct 01:38

Shell commands no longer see the wallet key. Bash, background tasks,
hooks, MCP servers, Grep and git subprocesses used to inherit
BLOCKRUN_WALLET_KEY, BASE_CHAIN_WALLET_KEY, SOLANA_WALLET_KEY and
BLOCKRUN_API_KEY from Franklin's environment, so a script could sign
payments outside every guard. Those variables are now removed before any
subprocess starts. Behavior change: an MCP server or hook that relied on
inheriting one of them must now set it in its own env config, which is
still passed through.

Polymarket withdrawals go only to your own wallet, and are never doubled.
withdraw now refuses any recipient other than the agent wallet. Before it
submits, it records the signed transfer. If the response is lost, a retry
re-broadcasts the same signed transaction instead of signing a new one. A
retry that finds the earlier withdrawal settled, reverted or expired reports
that result and stops; it does not start another withdrawal in the same call.
A withdrawal counts as resolved only once there is a receipt. A nonce that
has moved on proves nothing about it.

Trade plans now authorize exactly what they name. Execution is matched
against the specific field (mint, token address, or Polymarket token or
condition id plus outcome), not loosely. Each plan line has its own budget.
The budget is reserved when the trade is approved, and given back only when
the order provably never reached the venue. A timeout or a 5xx from the
exchange keeps the reservation and the session bet cap, and Franklin is told
to check open orders and positions before trying again. Plans created before
this version that have already been partly spent must be proposed again.

Ambiguous payment outcomes are reconciled first. The system prompt now
treats a timeout, a 5xx (including "upstream response lost"), a dropped
connection or a missing receipt as an unknown outcome, not a failure. This
applies to built-in tools, scripts and MCP tools alike. Franklin must
reconcile by transaction hash, nonce and balances before any new payment,
and may only re-broadcast the same signed transaction.

v3.49.5 — the README matches what Franklin is

Choose a tag to compare

@VickyXAI VickyXAI released this 06 Oct 14:01
ef942bd

Documentation only; no code changes.

The README now describes Franklin as the agent with a wallet rather than a
coding tool. The comparison is against chat apps, agent frameworks and trading
bots, on spending, approvals and guardrails. The demos, router examples and
price table use current models. The tool and command lists match what ships:
60+ tools, plus /goal, /loop, /market and /moa. A new Safety and
security
section explains how trades, the wallet key, network calls and the
local panel are protected.

v3.49.4 — security: five ways to reach the wallet key, closed

Choose a tag to compare

@VickyXAI VickyXAI released this 05 Oct 08:45
481ec12

A webhook could be redirected into the local panel. WebhookPost used its
own, weaker host check and followed redirects without re-checking them, so a
public URL that redirected to localhost:3100/api/wallet/secret handed the
wallet private key back to the model. It now uses the same guard as
WebFetch and re-checks every redirect.

The panel's wallet and spend routes now need the page's own token. A
request with no Origin header used to count as trusted. Each panel process
now creates a random token that only its own page knows. Reading the key,
importing a wallet, buying a number and every other state change require it.
Calling those routes with curl no longer works.

Connecting to a malicious MCP server could run commands on your machine.
The OAuth sign-in opened the server's authorization URL through a shell, so
$(...) in that URL was executed. The URL is now checked as http(s) and
handed to the browser opener with no shell in between.

Grep, Glob and BrowserX could read the wallet key. Grep with an
explicit path read ~/.blockrun/.session, and BrowserX could open
file:// URLs and local servers. Grep and Glob now skip the key files.
BrowserX opens only public http(s) pages, and checks where the page ended up
before returning its contents. As a backstop, the exact wallet and account
key values are scrubbed from every tool result.

Read no longer returns host credentials without asking. Read is
auto-approved, and it returned ~/.ssh, ~/.aws, ~/.config/solana/id.json
and similar files. It now refuses those, from the same list Write and
Edit use. If you need one of them, open it yourself or let Bash ask for
approval.

Franklin Agent 3.49.3 — security: the local panel only answers local requests

Choose a tag to compare

@VickyXAI VickyXAI released this 04 Oct 14:57

Fixes GHSA-jx74-262x-94p3 (path traversal in the local panel). The
dashboard that franklin panel serves on localhost built a file path from the
session id in /api/sessions/:id without checking it, so a request like
/api/sessions/..%2Ffranklin-audit returned other files under ~/.blockrun:
the audit log of every model call, the cost log, the trade log. Session ids
that resolve outside the sessions folder are now refused everywhere sessions
are read or written.

Every panel route now answers only local requests. The wallet routes
already required a local caller, but read-only routes such as session history
did not, and the live event stream allowed any website to subscribe. Every
route now requires a loopback connection and a localhost Host header, which
also blocks DNS-rebinding pages in your browser.

Reported by Rajnish Tiwari through GitHub private vulnerability reporting.
Thank you.

Franklin Agent 3.49.2 — sub-agents obey the spend controls, one swap cap, skill budgets enforced

Choose a tag to compare

@VickyXAI VickyXAI released this 04 Oct 14:22
14a6df3

Sub-agents can no longer act outside the money controls. A sub-agent
(the Agent tool) ran its tools directly, skipping permissions, user hooks,
the PreSpend hook and the trade-plan gate, so in principle it could trade
without an approved TradePlan. Its own model calls were also never counted,
so --max-spend could not see them. Every tool a sub-agent calls now goes
through the same checks as a top-level call, and outside an agent session it
refuses to run tools at all. Its model spend counts toward --max-spend, and
it stops mid-run once it reaches what is left of the budget instead of running
up to 30 turns.

The 10-swap safety cap is now 10, not 30. Jupiter, 0x on Base and 0x
gasless each kept their own counter, so the "10 live swaps per process" cap
allowed 10 per venue. They now share one counter (FRANKLIN_LIVE_SWAP_CAP
still overrides it).

A skill's budget-cap-usd is enforced. It was parsed and shown in
franklin skills but never applied. A turn started with /skill-name now
stops once its spend reaches the skill's cap, and /retry keeps the cap.

Concurrent sessions in franklin serve keep their spend separate. Live
spend was one process-wide number, so agents running side by side counted
each other's spend against their own --max-spend. Each session now has its
own counter.

Franklin Agent 3.49.1 — music on Arc, media prompts keep their context, dependency patches

Choose a tag to compare

@VickyXAI VickyXAI released this 04 Oct 06:20
d95bac6

Slow music tracks no longer fail. For a track that outruns the inline
window, the gateway answers 202 with a job to poll and charges nothing until
the track is ready. MusicGen read that 202 as the final answer and reported
"No track URL returned from API" on every chain. It now polls the job, like
ImageGen and VideoGen.

Music works on Arc. Arc's facilitator (Circle) refused the music poll
because the gateway signs the music request and its poll with different time
windows. When a poll refuses the original authorization, MusicGen signs the
poll's own challenge. A job settles once, so this cannot charge twice.
Verified live on Arc: a 79-second track, charged $0.1585 once.

Image, video and music prompts carry the context they refer to (#185).
Asking for "an infographic of these numbers" sent the image model no
numbers, so it invented some. The media model sees only the prompt, never
the chat; the desktop media modes and the tool descriptions now tell the
agent to write the referenced figures, names and text into the prompt and
never to invent data. Every result shows Prompt sent: …, so you can see
exactly what the model was given.

Dependency advisories patched (#186). sharp 0.35.5, axios 1.20.0,
undici, fast-uri, js-yaml, brace-expansion, hono and ip-address move to
patched releases within their current ranges. npm audit drops from 50
entries (25 high) to 42 (19 high). The remaining six have no upstream fix;
each is documented on #194 as unreachable or deferred.

Every Arc payment path checked live. Chat, ExaSearch, ExaReadUrls,
DeFiLlama, prediction markets, MultiChainRPC, phone lookup, the BlockRun
tool, ImageGen, MusicGen, VideoGen and a headless agent turn all paid on Arc:
each was signed for Arc USDC and charged exactly its quoted price.

Franklin Agent 3.49.0 — pay on Arc

Choose a tag to compare

@VickyXAI VickyXAI released this 03 Oct 01:45
7c827e5

Arc is a third payment chain. Circle's Arc (chain 5042) joins Base and
Solana. franklin setup arc, franklin arc, or the Arc button on the panel's
wallet page at localhost:3100 selects it. Arc uses the same wallet key as Base,
so the address you already funded on Base also receives USDC on Arc; Solana
keeps its own key.

Balances read Arc USDC, not Base. franklin balance, the Wallet tool,
/wallet, the panel, franklin doctor, Slack and Telegram, and the spend
guard all show the Arc balance on Arc, read through the Arc gateway. A failed
read is reported as unknown, never as an empty wallet.

Payments sign for the right chain. Franklin now requires @blockrun/llm
3.19. Older versions signed every payment over Base's USDC domain whatever the
gateway asked, which Arc rejects. Verified live: a paid call on Arc settled
$0.004073 from the wallet.

Smaller fixes. /wallet import validated an EVM key as a Solana key on any
chain other than Base. The panel shows an Arc funding QR code; card purchase
(Coinbase) cannot deliver to Arc, so on Arc the panel says so instead of
offering it.

Franklin Agent 3.48.0 — an account refusal can no longer spend from your wallet

Choose a tag to compare

@VickyXAI VickyXAI released this 03 Oct 01:00
a6d4702

Out of account credit no longer means "pay from the wallet instead."
With an API key set, a 402 from the account gateway is a credit refusal. The
agent loop already treated it that way on the first request, but its
tool_choice retry did not, and neither did thirteen paid tools (ExaSearch,
MultiChainRPC, Surf, PredictionMarket, DeFiLlama, ImageGen, VideoGen,
MusicGen, Voice, Phone, Modal, RealFace, the BlockRun gateway tool), the
prefetch research call or the trading data client. Each one handed any 402 to
the wallet signer. If that 402 carried an x402 challenge, the wallet signed
and paid for a request you had routed to your account. Every gateway call now
checks which rail its own request went out on before it answers a 402, and
an account refusal surfaces as the gateway's error. Use --wallet when you
want the wallet to pay. A source-level test fails if any new gateway 402
handler skips the check.

A broken remote picker policy can no longer break the model list. A
policy snapshot missing its default view, shortcut map or group membership used
to pass validation, replace the cached policy and make later reads throw.
Model Core now validates the picker structure before accepting a snapshot.
Franklin keeps the last good policy and its ETag, still applies live gateway
prices, and recovers on the next valid snapshot without a restart.

Nine new gateway models are priced and pinned. GPT-6 Astra / Sol / Luna,
GPT-5.1, Claude Fable 5.1 / Opus 5.5 / Sonnet 5.5 and Grok 4.6 / 4.7 have
fallback prices, context windows, vision support where it applies, and
explicit version shortcuts. Bare aliases are unchanged.

Pricing copy matches what the gateway charges. Chat is provider cost with
no markup, plus $0.001 per call; the 5% applies only to media. Fallback prices
for Sonnet 5, DeepSeek V4 Pro, GPT-5.6 Terra Pro / Luna Pro and Gemini 3.6
Flash now match the live catalog. Auto-routing decisions are unchanged.

Franklin 3.47.0 — new models reach the picker without a Franklin release

Choose a tag to compare

@VickyXAI VickyXAI released this 30 Sep 08:59
245e93b

Model lists and prices now refresh without waiting on a Franklin release.
Picker rows, price estimates and the model list used to be hand-edited here and
drifted every time the gateway rotated a model. Franklin now reads the shared
BlockRun Model Core: the runtime
is pinned to a commit, and on refresh it pulls the public policy snapshot plus
the active gateway's live /v1/models. New chat models and price changes show
up within five minutes. Base, Solana and account keys keep separate caches, and
the account key is only ever sent to the account gateway, never to the public
snapshot host.

Your shortcuts still mean what they meant. Shared policy may add aliases,
but it cannot retarget one Franklin already ships — opus, sonnet, claude,
grok, gemini and every free shortcut resolve exactly as in 3.46.0. A remote
catalog edit cannot change which model runs, or what it costs, behind your back.

The picker stays curated. Auto plus the policy's curated groups are in the
main list; every other available chat model is one keystroke away behind +more
(Ctrl+A), not dumped into the default view.

If the snapshot host is down, you still get the live gateway. An unreachable
policy host (a GitHub outage, a network that blocks raw.githubusercontent.com)
keeps the last good policy and still refreshes gateway rows; the two fetches
run in parallel, so the worst case is one 4-second timeout, not two. With no
network at all the bundled snapshot is used and the picker says it is offline.
Startup warms the catalog in the background rather than waiting on it.

FRANKLIN_CATALOG_OFFLINE=1 skips catalog network requests entirely;
BLOCKRUN_MODEL_CATALOG_URL overrides the snapshot URL (empty disables remote
policy updates).

Franklin Desktop 0.2.0-beta.3

Pre-release

Choose a tag to compare

@github-actions github-actions released this 03 Sep 02:57
1e8b18b

Franklin Desktop Beta for macOS Apple Silicon and Windows x64.

What's improved

  • Codex Agent import now starts a real runtime. Agent Studio detects a local Codex CLI and manages its app-server lifecycle over stdio, including start and stop state.
  • Team Cloud works on fresh Solana-first installs. Franklin creates and reuses a local Base identity wallet for SIWE without changing the selected payment chain.
  • Packaged Team login no longer loses its signing modules. Noble curve and hash dependencies resolve correctly from the installed app.
  • The installer is leaner. The optional CodeGraph native runtime is no longer bundled into Desktop; Franklin continues cleanly without it.
  • Dependency fixes are included. The affected Axios and qs dependency paths are updated, and the lockfile is reproducible with CI's npm version.

Downloads

  • Franklin-0.2.0-beta.3-arm64.dmg for Apple Silicon Macs
  • Franklin.Setup.0.2.0-beta.3.exe for Windows x64
  • SHA256SUMS.txt for download verification

These beta installers are currently unsigned. On first launch, macOS or Windows may ask you to confirm that you want to open the app.