diff --git a/.github/scripts/regenerate-selat-runtime-lock.sh b/.github/scripts/regenerate-selat-runtime-lock.sh index 2a5c813..629d7ab 100755 --- a/.github/scripts/regenerate-selat-runtime-lock.sh +++ b/.github/scripts/regenerate-selat-runtime-lock.sh @@ -53,6 +53,11 @@ done # Resolve registry metadata and integrity only in a disposable directory. The # generated lock is copied into the plugin after all validation passes. TMP="$(mktemp -d "${TMPDIR:-/tmp}/selat-runtime-lock.XXXXXX")" +# Resolve symlinks: on macOS $TMPDIR is /var/folders/… -> /private/var/…, and +# npm keys the generated lock relative to the unresolved --prefix, so every +# package lands under "../../private/var/…" instead of "node_modules/…" and +# the verification below can't find them. +TMP="$(cd "$TMP" && pwd -P)" trap 'rm -rf "$TMP"' EXIT TMP_MANIFEST="$TMP/package.json" TMP_LOCK="$TMP/package-lock.json" diff --git a/README.md b/README.md index f7974ee..2c111d7 100644 --- a/README.md +++ b/README.md @@ -14,13 +14,13 @@ Copy this into your coding agent (Claude Code, Codex, Cursor, Gemini CLI, …) a Prefer to do it yourself? See [**Install per harness**](#install-per-harness) below. On a supported harness, use the plugin installer (reviewed pin + lock, `npm ci --ignore-scripts`). The no-plugin fallback is the **pinned** CLI in [guides/generic.md](guides/generic.md) -(`@selat-ai/selat-cli@0.17.3 --ignore-scripts` — not `@latest`). Agents: the step-by-step +(`@selat-ai/selat-cli@0.17.5 --ignore-scripts` — not `@latest`). Agents: the step-by-step runbook is [**install.md**](install.md). > **Marketplace repo: [`SELAT-AI/selat-plugins`](https://github.com/SELAT-AI/selat-plugins)** — > the third SELAT distribution surface (after the npm package and the published skill). > Prefer the plugin install below (reviewed pin + lock). The no-plugin fallback is -> [guides/generic.md](guides/generic.md): `npm i -g @selat-ai/selat-cli@0.17.3 --ignore-scripts` +> [guides/generic.md](guides/generic.md): `npm i -g @selat-ai/selat-cli@0.17.5 --ignore-scripts` > then `selat init`. Do not install `@latest` as the payment path. ## What this is @@ -80,7 +80,7 @@ auto-approved; anything that spends or moves money (`selat run`, `selat skill ru | Gemini CLI | [guides/gemini-cli.md](guides/gemini-cli.md) | `gemini extensions install https://github.com/SELAT-AI/selat-plugins` (no spend hook, no locked runner; `--auto-update` is not the default) | | OpenClaw | [guides/openclaw.md](guides/openclaw.md) | `openclaw plugins install selat --marketplace https://github.com/SELAT-AI/selat-plugins` (bundle auto-detect) | | Hermes | [guides/hermes.md](guides/hermes.md) | `hermes plugins install SELAT-AI/selat-plugins/plugins/selat-hermes --enable` — the subdirectory path is required (the bare repo form buries the plugin at `plugins/selat-plugins/plugins/selat-hermes/`; see the guide). The plugin vendors the pin + lock and installs the reviewed runner | -| Any other / none | [guides/generic.md](guides/generic.md) | `npm i -g @selat-ai/selat-cli@0.17.3 --ignore-scripts` then `selat init` (not `@latest`) | +| Any other / none | [guides/generic.md](guides/generic.md) | `npm i -g @selat-ai/selat-cli@0.17.5 --ignore-scripts` then `selat init` (not `@latest`) | After install, every harness runs the same first-time setup (self-custody): diff --git a/guides/gemini-cli.md b/guides/gemini-cli.md index f9d8007..3bcb3ad 100644 --- a/guides/gemini-cli.md +++ b/guides/gemini-cli.md @@ -36,7 +36,7 @@ The Gemini variant differs from the Claude/Codex plugin: SELAT pays from **your own Circle Agent Wallet** (MPC self-custody) — it never holds your keys or funds, and never creates a wallet for you. Gemini does not install the locked runner. If `selat` is not already the reviewed plugin prefix, install the pinned -CLI from [generic.md](generic.md) (`@selat-ai/selat-cli@0.17.3 --ignore-scripts` — not +CLI from [generic.md](generic.md) (`@selat-ai/selat-cli@0.17.5 --ignore-scripts` — not `@latest`). Then run onboarding yourself: ```bash diff --git a/guides/generic.md b/guides/generic.md index da59528..0756068 100644 --- a/guides/generic.md +++ b/guides/generic.md @@ -11,7 +11,7 @@ Install the **pinned** CLI (the same version the plugin lock reviews). Do **not* `@latest` as a payment runner: ```bash -npm i -g @selat-ai/selat-cli@0.17.3 --ignore-scripts +npm i -g @selat-ai/selat-cli@0.17.5 --ignore-scripts ``` The exact pin lives in `plugins/selat/hooks-handlers/selat-cli.version`. If that file diff --git a/install.md b/install.md index 619178c..93322af 100644 --- a/install.md +++ b/install.md @@ -110,7 +110,7 @@ Prefer a plugin install above when your harness supports one — that path uses reviewed pin + lock and `npm ci --ignore-scripts`. If there is no plugin, install the **pinned** CLI (not `@latest`): ```bash -npm i -g @selat-ai/selat-cli@0.17.3 --ignore-scripts +npm i -g @selat-ai/selat-cli@0.17.5 --ignore-scripts ``` The exact pin is `plugins/selat/hooks-handlers/selat-cli.version`. See [guides/generic.md](guides/generic.md). diff --git a/plugins/selat-hermes/selat-cli.version b/plugins/selat-hermes/selat-cli.version index c73fb12..1568422 100644 --- a/plugins/selat-hermes/selat-cli.version +++ b/plugins/selat-hermes/selat-cli.version @@ -3,4 +3,4 @@ # automation bumps THIS file after vetting a release, so what installs is exactly # what was reviewed (never a floating `latest`). SELAT_CLI_SPEC overrides it. # Format: one bare semver on its own line; lines starting with # are comments. -0.17.3 \ No newline at end of file +0.17.5 \ No newline at end of file diff --git a/plugins/selat-hermes/selat-runtime-package-lock.json b/plugins/selat-hermes/selat-runtime-package-lock.json index 49b2d45..7a035f8 100644 --- a/plugins/selat-hermes/selat-runtime-package-lock.json +++ b/plugins/selat-hermes/selat-runtime-package-lock.json @@ -1,16 +1,16 @@ { "name": "@selat-ai/plugin-runtime-lock", - "version": "0.17.3", + "version": "0.17.5", "lockfileVersion": 3, "requires": true, "packages": { "": { "name": "@selat-ai/plugin-runtime-lock", - "version": "0.17.3", + "version": "0.17.5", "dependencies": { - "@selat-ai/selat-cli": "0.17.3", - "@selat-ai/selat-discovery": "0.25.1", - "@selat-ai/selat-pay": "0.11.2" + "@selat-ai/selat-cli": "0.17.5", + "@selat-ai/selat-discovery": "0.26.1", + "@selat-ai/selat-pay": "0.12.0" } }, "node_modules/@adraffy/ens-normalize": { @@ -29,9 +29,9 @@ } }, "node_modules/@circle-fin/x402-batching": { - "version": "3.4.0", - "resolved": "https://registry.npmjs.org/@circle-fin/x402-batching/-/x402-batching-3.4.0.tgz", - "integrity": "sha512-oUwIX8ltS3Tto9Ac23/7ISeVmYQLLxy14/8EopSchBF7K4wNGwzIwlQG5CMJ7iprxy/Br1ipcsW41qBy5h6/EQ==", + "version": "3.5.0", + "resolved": "https://registry.npmjs.org/@circle-fin/x402-batching/-/x402-batching-3.5.0.tgz", + "integrity": "sha512-BG4weseV3Q9Qpoo1MmFz588t5PQ210s6KxS1qVs9xEj6V4f771/JMrc7C4q/9pqnokl5wXxSxq6SGcsB5mL9SQ==", "license": "Apache-2.0", "engines": { "node": ">=18" @@ -132,13 +132,13 @@ } }, "node_modules/@selat-ai/selat-cli": { - "version": "0.17.3", - "resolved": "https://registry.npmjs.org/@selat-ai/selat-cli/-/selat-cli-0.17.3.tgz", - "integrity": "sha512-ZL2OA5NOR9qYaAvaDOn2lI57X4BqvmB5QYPq8tgN40CvkdMt1PvDUaaPL2ZfKhARNnzF+xzAaVTnUrMwh1uHOQ==", + "version": "0.17.5", + "resolved": "https://registry.npmjs.org/@selat-ai/selat-cli/-/selat-cli-0.17.5.tgz", + "integrity": "sha512-STcIyfSGW8l7v6fI0x/pQ7kqFIDBa/6ArcKedlpC4DIALDR7smIrpUtu2OYeriwsWBYP7i9WNwPGlSs1gUk0nw==", "license": "Apache-2.0", "dependencies": { - "@selat-ai/selat-discovery": "^0.25.0", - "@selat-ai/selat-pay": "^0.11.2", + "@selat-ai/selat-discovery": "^0.26.1", + "@selat-ai/selat-pay": "^0.12.0", "qrcode-generator": "2.0.4" }, "bin": { @@ -149,9 +149,9 @@ } }, "node_modules/@selat-ai/selat-discovery": { - "version": "0.25.1", - "resolved": "https://registry.npmjs.org/@selat-ai/selat-discovery/-/selat-discovery-0.25.1.tgz", - "integrity": "sha512-V5LqNF0RU38mwCNXdkzZHSA3r0pJNhCUqsJw1c5IESO/qqZTzYyVkKbeUlfdrdZ8xI6UxMQkGvq+4WQBYZylEg==", + "version": "0.26.1", + "resolved": "https://registry.npmjs.org/@selat-ai/selat-discovery/-/selat-discovery-0.26.1.tgz", + "integrity": "sha512-1C3rTSNzcD5iY8v/hq+gjIxGJKGjWheehBwHrQmpZD/dP0sAh9xAPHQBTL8hdnsfEB//Bi5ZMAwEdZht1SkZxA==", "license": "Apache-2.0", "dependencies": { "@circle-fin/x402-batching": "^3.1.2", @@ -161,7 +161,7 @@ "node": ">=18.0.0" }, "peerDependencies": { - "@circle-fin/cli": ">=1.0.0" + "@circle-fin/cli": ">=1.1.1" }, "peerDependenciesMeta": { "@circle-fin/cli": { @@ -170,12 +170,12 @@ } }, "node_modules/@selat-ai/selat-pay": { - "version": "0.11.2", - "resolved": "https://registry.npmjs.org/@selat-ai/selat-pay/-/selat-pay-0.11.2.tgz", - "integrity": "sha512-u0vp96Q1thRrSBkMjFTF9sf+sWzwyfIPPC/gykGDxz7Nqcxs/JiMeMY/r9WV1nrCWhdaIMS/kIT38W94rriffA==", + "version": "0.12.0", + "resolved": "https://registry.npmjs.org/@selat-ai/selat-pay/-/selat-pay-0.12.0.tgz", + "integrity": "sha512-QLQ5g9XdFWCkEhtg70mHi/BL1efJuSfGqDyQWy6jroLEDodqFCkC0SeQVec3Xo2WqVMWaDWezEHvRHmOcP+LbQ==", "license": "Apache-2.0", "dependencies": { - "@circle-fin/x402-batching": "^3.1.2", + "@circle-fin/x402-batching": "^3.5.0", "@selat-ai/siwx-lib": "^0.1.2", "dotenv": "^17.4.2", "viem": "^2.48.8" @@ -202,9 +202,9 @@ } }, "node_modules/@x402/core": { - "version": "2.25.0", - "resolved": "https://registry.npmjs.org/@x402/core/-/core-2.25.0.tgz", - "integrity": "sha512-5Ys0XYz3FKutxVKoXC46R/XPT/oaAbuj7ahzrlVHwQxZJPH9u6u91IOh0ztz+7G/zYGsaXR8l3ety205QtEnUw==", + "version": "2.26.0", + "resolved": "https://registry.npmjs.org/@x402/core/-/core-2.26.0.tgz", + "integrity": "sha512-8dlXip9u0JjyELzzFz48vntuMajvUjA8IYpitfaW423m53bR49amZDIn3n4gXRYoNEKzGB9Rtn8at35WHz61cA==", "license": "Apache-2.0", "peer": true, "dependencies": { @@ -935,9 +935,9 @@ "license": "MIT" }, "node_modules/nan": { - "version": "2.28.0", - "resolved": "https://registry.npmjs.org/nan/-/nan-2.28.0.tgz", - "integrity": "sha512-fTsDz99OTq2sVePhGdp4qQhggZFtKr64ZNVyVajRKtMOkJxYekplBh577PiJB12v/D3s2E5cGtOI45LWp6rnLQ==", + "version": "2.29.0", + "resolved": "https://registry.npmjs.org/nan/-/nan-2.29.0.tgz", + "integrity": "sha512-GlGk3HIvitbvs+LT3g6XUP1kpirKNvmDFwF/bmo6XNWSb/eYEs/O4bfgIEIXCZ+lIOTS5xNwDvSGMw6FJdAhtA==", "license": "MIT" }, "node_modules/node-addon-api": { @@ -958,9 +958,9 @@ } }, "node_modules/ox": { - "version": "0.14.44", - "resolved": "https://registry.npmjs.org/ox/-/ox-0.14.44.tgz", - "integrity": "sha512-O54qXXHEk4ySamMSyBpI0AeBegS5frxU6+LA6Jb9Sf6kMOxcTNaxYmwZfpOu22DIQsdKfgQxHq8EsAGaoBQScA==", + "version": "0.14.45", + "resolved": "https://registry.npmjs.org/ox/-/ox-0.14.45.tgz", + "integrity": "sha512-jpsQ+p0JZh9mKCxxzxz0d5qFHZZg2/O9xW18IpEC/dNXXPVqmDJ0c//9RMz0CILkbSGPA42+cbU0fC/ghwJ03w==", "funding": [ { "type": "github", @@ -1209,9 +1209,9 @@ } }, "node_modules/viem": { - "version": "2.56.3", - "resolved": "https://registry.npmjs.org/viem/-/viem-2.56.3.tgz", - "integrity": "sha512-vUObq3GO7D3lz9gPNEE/xd5jIUnMbeVDWewh252o54pDEDlW4pDe6FEd/qTGL5RyK52cGHMM7kQ3wjxhilEvkQ==", + "version": "2.56.7", + "resolved": "https://registry.npmjs.org/viem/-/viem-2.56.7.tgz", + "integrity": "sha512-8YXhttIOKikDnTLj4byvGQmF43Gi0FtEfxUWd6OqSJiuz9bxNYNGmzlS8ZaNiYSKUEfs5vmNprvwPIki9Lk4YA==", "funding": [ { "type": "github", @@ -1226,7 +1226,7 @@ "@scure/bip39": "1.6.0", "abitype": "1.2.3", "isows": "1.0.7", - "ox": "0.14.44", + "ox": "0.14.45", "ws": "8.21.0" }, "peerDependencies": { @@ -1254,9 +1254,9 @@ } }, "node_modules/which-typed-array": { - "version": "1.1.22", - "resolved": "https://registry.npmjs.org/which-typed-array/-/which-typed-array-1.1.22.tgz", - "integrity": "sha512-fvO4ExWMFsqyhG3AiPAObMuY1lxaqgYcxbc49CNdWDDECOJNgQyvsOWVwbZc+qf3rzRtxojBK+CMEv0Ld5CYpw==", + "version": "1.1.23", + "resolved": "https://registry.npmjs.org/which-typed-array/-/which-typed-array-1.1.23.tgz", + "integrity": "sha512-JMh8aK+1B/0bk/YNupICmH5MgCq6yNLKYQUfsZtSDLLCCmxUkHjUY+oOlIa90lO7lHN1woAfpenLdlKpXy9o+A==", "license": "MIT", "dependencies": { "available-typed-arrays": "^1.0.7", diff --git a/plugins/selat-hermes/selat-runtime-package.json b/plugins/selat-hermes/selat-runtime-package.json index 545f843..b9483f7 100644 --- a/plugins/selat-hermes/selat-runtime-package.json +++ b/plugins/selat-hermes/selat-runtime-package.json @@ -1,12 +1,12 @@ { "name": "@selat-ai/plugin-runtime-lock", "private": true, - "version": "0.17.3", + "version": "0.17.5", "description": "Locked SELAT plugin runtime closure; update only through the coordinated SELAT release process.", "dependencies": { - "@selat-ai/selat-cli": "0.17.3", - "@selat-ai/selat-discovery": "0.25.1", - "@selat-ai/selat-pay": "0.11.2" + "@selat-ai/selat-cli": "0.17.5", + "@selat-ai/selat-discovery": "0.26.1", + "@selat-ai/selat-pay": "0.12.0" }, "overrides": { "ws": "8.21.0" diff --git a/plugins/selat/.claude-plugin/plugin.json b/plugins/selat/.claude-plugin/plugin.json index d0fbb27..ab5ea94 100644 --- a/plugins/selat/.claude-plugin/plugin.json +++ b/plugins/selat/.claude-plugin/plugin.json @@ -1,6 +1,6 @@ { "name": "selat", - "version": "0.1.11", + "version": "0.1.12", "description": "Discover and call paid AI capabilities via a two-tier loop \u2014 vetted multi-step skills first, then a federated x402 / MPP endpoint catalog (image/video/audio generation, translation, web scraping, data enrichment, real-time data, on-chain actions). Payments settle from your own Circle Agent Wallet (MPC self-custody \u2014 SELAT never holds your keys or funds). Wraps the published @selat-ai/selat-cli (bundles @selat-ai/selat-discovery + @selat-ai/selat-pay) and ships the 'selat-discovery' driver skill.", "author": { "name": "SELAT", diff --git a/plugins/selat/.codex-plugin/plugin.json b/plugins/selat/.codex-plugin/plugin.json index 02ace8b..c921a74 100644 --- a/plugins/selat/.codex-plugin/plugin.json +++ b/plugins/selat/.codex-plugin/plugin.json @@ -1,6 +1,6 @@ { "name": "selat", - "version": "0.1.11", + "version": "0.1.12", "description": "Discover and call paid AI capabilities via a two-tier loop — vetted multi-step skills first, then a federated x402 / MPP endpoint catalog (image/video/audio generation, translation, web scraping, data enrichment, real-time data, on-chain actions). Payments settle from your own Circle Agent Wallet (MPC self-custody — SELAT never holds your keys or funds). Wraps the published @selat-ai/selat-cli and ships the 'selat-discovery' driver skill.", "author": { "name": "SELAT", "url": "https://selat.ai" }, "homepage": "https://selat.ai", diff --git a/plugins/selat/.cursor-plugin/plugin.json b/plugins/selat/.cursor-plugin/plugin.json index 630e11d..fade304 100644 --- a/plugins/selat/.cursor-plugin/plugin.json +++ b/plugins/selat/.cursor-plugin/plugin.json @@ -1,7 +1,7 @@ { "name": "selat", "description": "Discover and call paid AI capabilities via a two-tier loop — vetted multi-step skills first, then a federated x402 / MPP endpoint catalog (image/video/audio generation, translation, web scraping, data enrichment, real-time data, on-chain actions). Payments settle from your own Circle Agent Wallet (MPC self-custody — SELAT never holds your keys or funds). Wraps the published @selat-ai/selat-cli (bundles @selat-ai/selat-discovery + @selat-ai/selat-pay) and ships the 'selat-discovery' driver skill.", - "version": "0.1.11", + "version": "0.1.12", "author": { "name": "SELAT" }, diff --git a/plugins/selat/hooks-handlers/selat-cli.version b/plugins/selat/hooks-handlers/selat-cli.version index c73fb12..1568422 100644 --- a/plugins/selat/hooks-handlers/selat-cli.version +++ b/plugins/selat/hooks-handlers/selat-cli.version @@ -3,4 +3,4 @@ # automation bumps THIS file after vetting a release, so what installs is exactly # what was reviewed (never a floating `latest`). SELAT_CLI_SPEC overrides it. # Format: one bare semver on its own line; lines starting with # are comments. -0.17.3 \ No newline at end of file +0.17.5 \ No newline at end of file diff --git a/plugins/selat/hooks-handlers/selat-runtime-package-lock.json b/plugins/selat/hooks-handlers/selat-runtime-package-lock.json index 49b2d45..7a035f8 100644 --- a/plugins/selat/hooks-handlers/selat-runtime-package-lock.json +++ b/plugins/selat/hooks-handlers/selat-runtime-package-lock.json @@ -1,16 +1,16 @@ { "name": "@selat-ai/plugin-runtime-lock", - "version": "0.17.3", + "version": "0.17.5", "lockfileVersion": 3, "requires": true, "packages": { "": { "name": "@selat-ai/plugin-runtime-lock", - "version": "0.17.3", + "version": "0.17.5", "dependencies": { - "@selat-ai/selat-cli": "0.17.3", - "@selat-ai/selat-discovery": "0.25.1", - "@selat-ai/selat-pay": "0.11.2" + "@selat-ai/selat-cli": "0.17.5", + "@selat-ai/selat-discovery": "0.26.1", + "@selat-ai/selat-pay": "0.12.0" } }, "node_modules/@adraffy/ens-normalize": { @@ -29,9 +29,9 @@ } }, "node_modules/@circle-fin/x402-batching": { - "version": "3.4.0", - "resolved": "https://registry.npmjs.org/@circle-fin/x402-batching/-/x402-batching-3.4.0.tgz", - "integrity": "sha512-oUwIX8ltS3Tto9Ac23/7ISeVmYQLLxy14/8EopSchBF7K4wNGwzIwlQG5CMJ7iprxy/Br1ipcsW41qBy5h6/EQ==", + "version": "3.5.0", + "resolved": "https://registry.npmjs.org/@circle-fin/x402-batching/-/x402-batching-3.5.0.tgz", + "integrity": "sha512-BG4weseV3Q9Qpoo1MmFz588t5PQ210s6KxS1qVs9xEj6V4f771/JMrc7C4q/9pqnokl5wXxSxq6SGcsB5mL9SQ==", "license": "Apache-2.0", "engines": { "node": ">=18" @@ -132,13 +132,13 @@ } }, "node_modules/@selat-ai/selat-cli": { - "version": "0.17.3", - "resolved": "https://registry.npmjs.org/@selat-ai/selat-cli/-/selat-cli-0.17.3.tgz", - "integrity": "sha512-ZL2OA5NOR9qYaAvaDOn2lI57X4BqvmB5QYPq8tgN40CvkdMt1PvDUaaPL2ZfKhARNnzF+xzAaVTnUrMwh1uHOQ==", + "version": "0.17.5", + "resolved": "https://registry.npmjs.org/@selat-ai/selat-cli/-/selat-cli-0.17.5.tgz", + "integrity": "sha512-STcIyfSGW8l7v6fI0x/pQ7kqFIDBa/6ArcKedlpC4DIALDR7smIrpUtu2OYeriwsWBYP7i9WNwPGlSs1gUk0nw==", "license": "Apache-2.0", "dependencies": { - "@selat-ai/selat-discovery": "^0.25.0", - "@selat-ai/selat-pay": "^0.11.2", + "@selat-ai/selat-discovery": "^0.26.1", + "@selat-ai/selat-pay": "^0.12.0", "qrcode-generator": "2.0.4" }, "bin": { @@ -149,9 +149,9 @@ } }, "node_modules/@selat-ai/selat-discovery": { - "version": "0.25.1", - "resolved": "https://registry.npmjs.org/@selat-ai/selat-discovery/-/selat-discovery-0.25.1.tgz", - "integrity": "sha512-V5LqNF0RU38mwCNXdkzZHSA3r0pJNhCUqsJw1c5IESO/qqZTzYyVkKbeUlfdrdZ8xI6UxMQkGvq+4WQBYZylEg==", + "version": "0.26.1", + "resolved": "https://registry.npmjs.org/@selat-ai/selat-discovery/-/selat-discovery-0.26.1.tgz", + "integrity": "sha512-1C3rTSNzcD5iY8v/hq+gjIxGJKGjWheehBwHrQmpZD/dP0sAh9xAPHQBTL8hdnsfEB//Bi5ZMAwEdZht1SkZxA==", "license": "Apache-2.0", "dependencies": { "@circle-fin/x402-batching": "^3.1.2", @@ -161,7 +161,7 @@ "node": ">=18.0.0" }, "peerDependencies": { - "@circle-fin/cli": ">=1.0.0" + "@circle-fin/cli": ">=1.1.1" }, "peerDependenciesMeta": { "@circle-fin/cli": { @@ -170,12 +170,12 @@ } }, "node_modules/@selat-ai/selat-pay": { - "version": "0.11.2", - "resolved": "https://registry.npmjs.org/@selat-ai/selat-pay/-/selat-pay-0.11.2.tgz", - "integrity": "sha512-u0vp96Q1thRrSBkMjFTF9sf+sWzwyfIPPC/gykGDxz7Nqcxs/JiMeMY/r9WV1nrCWhdaIMS/kIT38W94rriffA==", + "version": "0.12.0", + "resolved": "https://registry.npmjs.org/@selat-ai/selat-pay/-/selat-pay-0.12.0.tgz", + "integrity": "sha512-QLQ5g9XdFWCkEhtg70mHi/BL1efJuSfGqDyQWy6jroLEDodqFCkC0SeQVec3Xo2WqVMWaDWezEHvRHmOcP+LbQ==", "license": "Apache-2.0", "dependencies": { - "@circle-fin/x402-batching": "^3.1.2", + "@circle-fin/x402-batching": "^3.5.0", "@selat-ai/siwx-lib": "^0.1.2", "dotenv": "^17.4.2", "viem": "^2.48.8" @@ -202,9 +202,9 @@ } }, "node_modules/@x402/core": { - "version": "2.25.0", - "resolved": "https://registry.npmjs.org/@x402/core/-/core-2.25.0.tgz", - "integrity": "sha512-5Ys0XYz3FKutxVKoXC46R/XPT/oaAbuj7ahzrlVHwQxZJPH9u6u91IOh0ztz+7G/zYGsaXR8l3ety205QtEnUw==", + "version": "2.26.0", + "resolved": "https://registry.npmjs.org/@x402/core/-/core-2.26.0.tgz", + "integrity": "sha512-8dlXip9u0JjyELzzFz48vntuMajvUjA8IYpitfaW423m53bR49amZDIn3n4gXRYoNEKzGB9Rtn8at35WHz61cA==", "license": "Apache-2.0", "peer": true, "dependencies": { @@ -935,9 +935,9 @@ "license": "MIT" }, "node_modules/nan": { - "version": "2.28.0", - "resolved": "https://registry.npmjs.org/nan/-/nan-2.28.0.tgz", - "integrity": "sha512-fTsDz99OTq2sVePhGdp4qQhggZFtKr64ZNVyVajRKtMOkJxYekplBh577PiJB12v/D3s2E5cGtOI45LWp6rnLQ==", + "version": "2.29.0", + "resolved": "https://registry.npmjs.org/nan/-/nan-2.29.0.tgz", + "integrity": "sha512-GlGk3HIvitbvs+LT3g6XUP1kpirKNvmDFwF/bmo6XNWSb/eYEs/O4bfgIEIXCZ+lIOTS5xNwDvSGMw6FJdAhtA==", "license": "MIT" }, "node_modules/node-addon-api": { @@ -958,9 +958,9 @@ } }, "node_modules/ox": { - "version": "0.14.44", - "resolved": "https://registry.npmjs.org/ox/-/ox-0.14.44.tgz", - "integrity": "sha512-O54qXXHEk4ySamMSyBpI0AeBegS5frxU6+LA6Jb9Sf6kMOxcTNaxYmwZfpOu22DIQsdKfgQxHq8EsAGaoBQScA==", + "version": "0.14.45", + "resolved": "https://registry.npmjs.org/ox/-/ox-0.14.45.tgz", + "integrity": "sha512-jpsQ+p0JZh9mKCxxzxz0d5qFHZZg2/O9xW18IpEC/dNXXPVqmDJ0c//9RMz0CILkbSGPA42+cbU0fC/ghwJ03w==", "funding": [ { "type": "github", @@ -1209,9 +1209,9 @@ } }, "node_modules/viem": { - "version": "2.56.3", - "resolved": "https://registry.npmjs.org/viem/-/viem-2.56.3.tgz", - "integrity": "sha512-vUObq3GO7D3lz9gPNEE/xd5jIUnMbeVDWewh252o54pDEDlW4pDe6FEd/qTGL5RyK52cGHMM7kQ3wjxhilEvkQ==", + "version": "2.56.7", + "resolved": "https://registry.npmjs.org/viem/-/viem-2.56.7.tgz", + "integrity": "sha512-8YXhttIOKikDnTLj4byvGQmF43Gi0FtEfxUWd6OqSJiuz9bxNYNGmzlS8ZaNiYSKUEfs5vmNprvwPIki9Lk4YA==", "funding": [ { "type": "github", @@ -1226,7 +1226,7 @@ "@scure/bip39": "1.6.0", "abitype": "1.2.3", "isows": "1.0.7", - "ox": "0.14.44", + "ox": "0.14.45", "ws": "8.21.0" }, "peerDependencies": { @@ -1254,9 +1254,9 @@ } }, "node_modules/which-typed-array": { - "version": "1.1.22", - "resolved": "https://registry.npmjs.org/which-typed-array/-/which-typed-array-1.1.22.tgz", - "integrity": "sha512-fvO4ExWMFsqyhG3AiPAObMuY1lxaqgYcxbc49CNdWDDECOJNgQyvsOWVwbZc+qf3rzRtxojBK+CMEv0Ld5CYpw==", + "version": "1.1.23", + "resolved": "https://registry.npmjs.org/which-typed-array/-/which-typed-array-1.1.23.tgz", + "integrity": "sha512-JMh8aK+1B/0bk/YNupICmH5MgCq6yNLKYQUfsZtSDLLCCmxUkHjUY+oOlIa90lO7lHN1woAfpenLdlKpXy9o+A==", "license": "MIT", "dependencies": { "available-typed-arrays": "^1.0.7", diff --git a/plugins/selat/hooks-handlers/selat-runtime-package.json b/plugins/selat/hooks-handlers/selat-runtime-package.json index 545f843..b9483f7 100644 --- a/plugins/selat/hooks-handlers/selat-runtime-package.json +++ b/plugins/selat/hooks-handlers/selat-runtime-package.json @@ -1,12 +1,12 @@ { "name": "@selat-ai/plugin-runtime-lock", "private": true, - "version": "0.17.3", + "version": "0.17.5", "description": "Locked SELAT plugin runtime closure; update only through the coordinated SELAT release process.", "dependencies": { - "@selat-ai/selat-cli": "0.17.3", - "@selat-ai/selat-discovery": "0.25.1", - "@selat-ai/selat-pay": "0.11.2" + "@selat-ai/selat-cli": "0.17.5", + "@selat-ai/selat-discovery": "0.26.1", + "@selat-ai/selat-pay": "0.12.0" }, "overrides": { "ws": "8.21.0" diff --git a/plugins/selat/package.json b/plugins/selat/package.json index b59241f..752288f 100644 --- a/plugins/selat/package.json +++ b/plugins/selat/package.json @@ -1,7 +1,7 @@ { "name": "selat", "displayName": "SELAT", - "version": "0.1.11", + "version": "0.1.12", "description": "Discover and call paid AI capabilities via a two-tier loop — vetted multi-step skills first, then a federated x402 / MPP endpoint catalog (image/video/audio generation, translation, web scraping, data enrichment, real-time data, on-chain actions). Payments settle from your own Circle Agent Wallet (MPC self-custody — SELAT never holds your keys or funds). Wraps the published @selat-ai/selat-cli (bundles @selat-ai/selat-discovery + @selat-ai/selat-pay) and ships the 'selat-discovery' driver skill.", "publisher": "SELAT", "author": "SELAT", diff --git a/plugins/selat/skills/selat-discovery/SKILL.md b/plugins/selat/skills/selat-discovery/SKILL.md index 7f8d606..92e4c36 100644 --- a/plugins/selat/skills/selat-discovery/SKILL.md +++ b/plugins/selat/skills/selat-discovery/SKILL.md @@ -20,8 +20,8 @@ description: >- > @selat-ai/selat-discovery SKILL.md (bundled inside @selat-ai/selat-cli) remains the > source of truth for exact subcommand flags, output shapes, and any commands added > after the pinned CLI version. Where they conflict, the published skill wins. The -> command surface below was verified against @selat-ai/selat-cli@0.17.2 and -> @selat-ai/selat-discovery@0.25.1. +> command surface below was verified against @selat-ai/selat-cli@0.17.5 and +> @selat-ai/selat-discovery@0.26.1. SELAT is a capability layer for AI agents. It does two things a flat capability index doesn't: it checks **vetted skills first**, and it pays from the **user's own wallet** — @@ -63,7 +63,11 @@ holds keys or balance. So: `circle` commands. `selat fund` and any paid call still need explicit approval **and an armed session budget** (`selat budget start`); `selat freeze` is the kill switch — never auto-fund or auto-pay. -- A `--raw-key` dev mode exists but is **not for production** — do not steer users to it. +- There is no local-key signing mode. Every signature goes through the Circle Agent Wallet + (MPC); never suggest a private-key or `--raw-key` path — the flag no longer exists. That + includes Arc mainnet: `selat fund --chain arc` deposits from the agent wallet like any other + chain (direct method only — no eco on Arc) and needs Circle CLI >= 1.1.1, which `selat init` + installs or upgrades to automatically. - Before any spend, surface the cost and get the user's go-ahead. Spending limits are set via `selat setup-policy` (recommended before deposits > $20); funding via `selat fund`. Both are user-driven money actions — never run them unprompted. @@ -107,9 +111,8 @@ selat skill run [--param value ...] [--max-amount ] [--chain ] ``` `selat skill run` takes the skill's own params as `--flags` (manifest keys map 1:1). -Three names are reserved overrides applied to every step, not passed as params: -`--max-amount ` (per-call cost cap), `--chain ` (force a settlement chain), -and `--raw-key` (dev-only EOA signing — do not steer users to it). +Two names are reserved overrides applied to every step, not passed as params: +`--max-amount ` (per-call cost cap) and `--chain ` (force a settlement chain). If a vetted skill covers the task, prefer it: it's a known-good, capped workflow. Pass `--max-amount` to hold the spend to a number the user approved. @@ -241,8 +244,8 @@ Actor input is per-Actor (e.g. `{"username":["natgeo"],"resultsLimit":3}`) — r | `selat history` | Show locally recorded Gateway micropayments | no | | `selat spend` | Unified spend report: settled spend + Apify token utilization (read-only) | no | -> Flag surface verified against @selat-ai/selat-cli@0.17.2 (`lib/commands/run.mjs`, -> `lib/commands/skill.mjs`) and @selat-ai/selat-discovery@0.25.1: +> Flag surface verified against @selat-ai/selat-cli@0.17.5 (`lib/commands/run.mjs`, +> `lib/commands/skill.mjs`) and @selat-ai/selat-discovery@0.26.1: > • `selat search ""` (`lib/commands/search.mjs`) is FREE discovery — the same > ranker as `selat run` in its no-`--pick` mode, so it never settles. Flags: `--top N` > (default 5), `--json` (for agents/hooks), `--explain` (why each match is/isn't @@ -266,8 +269,8 @@ Actor input is per-Actor (e.g. `{"username":["natgeo"],"resultsLimit":3}`) — r > `{ runner, cmd, argv, env? }`, the resolved spawn tuple the paid run would execute. > Spawn it directly (no shell) to run exactly what was quoted; `command` beside it is > the shell-quoted human display of the same thing, not something to re-parse. -> • `selat skill run ` accepts the skill's params as `--flags` plus three reserved -> overrides: `--max-amount `, `--chain `, `--raw-key`. +> • `selat skill run ` accepts the skill's params as `--flags` plus two reserved +> overrides: `--max-amount `, `--chain `. > • `--max-amount` is also the mandatory cost cap on the underlying `selat-pay` engine. > • `selat doctor` prints sectioned diagnostics (Binaries · Agent-payment skill · Circle > CLI · Agent Wallet · Spending policy (per chain) · selat-pay · Config · Router