docs+chore: security policy + bounty tiers, audit addendum, Saltant/ProtonUK endpoints, testnet chainId fix - #81
Merged
Conversation
…t/ProtonUK endpoints SECURITY.md: publish bounty tiers (anchored on what has been paid: 20k XSS, 15k slash evasion, 5k each for this round), a duplicate rule (fixed on main or deployed on chain before the report = duplicate), and ask reporters to test against current main and compare the on-chain code hash. Three of the last four external reports targeted a stale commit. Scope now names shipped defaults explicitly; the obsolete Docker-private-key limitation is replaced with the proton CLI keychain and a2a key notes. docs/SECURITY_AUDIT.md: addendum for the 0xgons batch-2 reports (#77, #78, #80, 10k bounty); A2A #7/#8 residual marked fixed (#70/#71). Endpoints: replace proton.eosusa.io in shipped defaults, SDK NETWORKS, plugin/runner fallbacks, skills and docs with producer endpoints that serve chain RPC and Hyperion /v2 on one host — Saltant (api-xprnetwork-main.saltant.io) with ProtonUK (proton.protonuk.io) as the alternative; both verified (table reads, get_actions, head lag < 0.2s). smart-contracts maps nodeos-only hosts to Saltant and testnet to Saltant's testnet Hyperion. deploy-service CSP updated to match. Fix: frontend and deploy-service frontend hardcoded the wrong testnet chain id (71ee83bcf20d…); the real one (from tn1 and Saltant testnet get_info) is 71ee83bcf521…abeaf3d3dd, which the SDK already used. The smart-contracts SKILL.md testnet id was also wrong.
This was referenced Sep 22, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Three changes in this PR:
SECURITY.mdnow includes bounty tiers based on past payouts, a duplicate rule, a "test against current main and the on-chain code hash" section, rules of engagement, and explicit scope that covers shipped defaults.docs/SECURITY_AUDIT.mdgets an addendum for the 0xgons batch-2 reports (security: Telegram /run bypass, A2A default authz, agent-card SSRF redirect #77, test(agentvalid): cancelchal flag-desync regression #78, chore: retire the Docker installer path and GHCR images #80, and the 10k bounty). A2A refactor: route signing through proton CLI (key isolation) #7/docs(readme): align with proton CLI as primary path; demote Docker #8 are marked as fixed.proton.eosusa.iois replaced everywhere it shipped with Saltant (api-xprnetwork-main.saltant.io), with ProtonUK (proton.protonuk.io) as the alternative. Each of these serves chain RPC and Hyperion/v2from the same host, and both passed verification.Bug fix: the frontend and the deploy-service frontend hardcoded the wrong testnet chain id. That breaks wallet login and signing on testnet.
SDK tests pass (299). Typecheck is clean for openclaw and the agent. Both touched skills build, and the template copies are still in sync.
The runtime default changes in
sdk, the plugin and the runner only reach third parties with the next SDK/openclaw publish.