mirror of
https://github.com/outbackdingo/optimclaw.git
synced 2026-08-25 14:53:34 +00:00
Implements hybrid-custody NEAR key management where the agent holds scoped function-call keys for routine operations while high-value operations require explicit user approval through the existing channel approval flow. Core infrastructure: - Ed25519 key generation/import via ed25519-dalek (not near-crypto) - AES-256-GCM encrypted storage via existing SecretsStore - Hand-rolled borsh-serializable NEAR transaction types - NEP-413 intent signing and MPC chain signature support - Configurable policy engine with transaction analysis pipeline - Daily spend tracking with automatic midnight UTC reset - Encrypted backup/restore with Argon2id KDF - CLI subcommands: generate, import, list, info, remove, export, policy, backup, restore - NEAR ed25519 secret key leak detection (Critical/Block) - WASM sign-payload host function (keys never enter WASM memory) - KeyManager wired into AgentDeps for agent-wide access Security invariants: private keys never reach the LLM or WASM boundary, signing happens in host Rust code with Zeroize on drop, every transaction is analyzed before signing, most-restrictive policy rule wins. Co-Authored-By: Claude Opus 4.6 <[email protected]>
129 lines
3.4 KiB
TOML
129 lines
3.4 KiB
TOML
[package]
|
|
name = "ironclaw"
|
|
version = "0.1.0"
|
|
edition = "2024"
|
|
rust-version = "1.85"
|
|
description = "Secure personal AI assistant that protects your data and expands its capabilities on the fly"
|
|
license = "MIT OR Apache-2.0"
|
|
|
|
[dependencies]
|
|
# Async runtime
|
|
tokio = { version = "1", features = ["full"] }
|
|
tokio-stream = { version = "0.1", features = ["sync"] }
|
|
futures = "0.3"
|
|
|
|
# HTTP client
|
|
reqwest = { version = "0.12", default-features = false, features = ["json", "rustls-tls", "stream"] }
|
|
|
|
# Serialization
|
|
serde = { version = "1", features = ["derive"] }
|
|
serde_json = "1"
|
|
|
|
# Database
|
|
deadpool-postgres = "0.14"
|
|
tokio-postgres = { version = "0.7", features = ["with-uuid-1", "with-chrono-0_4", "with-serde_json-1"] }
|
|
postgres-types = { version = "0.2", features = ["with-serde_json-1"] }
|
|
refinery = { version = "0.8", features = ["tokio-postgres"] }
|
|
|
|
# Error handling
|
|
thiserror = "2"
|
|
anyhow = "1"
|
|
|
|
# Logging
|
|
tracing = "0.1"
|
|
tracing-subscriber = { version = "0.3", features = ["env-filter", "json"] }
|
|
|
|
# Configuration
|
|
dotenvy = "0.15"
|
|
|
|
# Core types
|
|
uuid = { version = "1", features = ["v4", "serde"] }
|
|
chrono = { version = "0.4", features = ["serde"] }
|
|
rust_decimal = { version = "1", features = ["serde", "serde-with-str", "db-tokio-postgres", "maths"] }
|
|
rust_decimal_macros = "1"
|
|
|
|
# Async traits
|
|
async-trait = "0.1"
|
|
|
|
# CLI
|
|
clap = { version = "4", features = ["derive", "env"] }
|
|
|
|
# Terminal
|
|
crossterm = "0.28"
|
|
rustyline = { version = "17", features = ["derive", "with-file-history"] }
|
|
termimad = "0.34"
|
|
|
|
# Channel integrations
|
|
axum = { version = "0.8", features = ["ws"] }
|
|
tower = "0.5"
|
|
tower-http = { version = "0.6", features = ["trace", "cors"] }
|
|
|
|
# Safety/sanitization
|
|
regex = "1"
|
|
aho-corasick = "1"
|
|
|
|
# Filesystem paths
|
|
dirs = "6"
|
|
|
|
# Secrecy for sensitive values
|
|
secrecy = { version = "0.10", features = ["serde"] }
|
|
|
|
# URL encoding for OAuth flow
|
|
urlencoding = "2"
|
|
|
|
# Open URLs in browser
|
|
open = "5"
|
|
|
|
# Vector embeddings for semantic search
|
|
# The postgres feature provides ToSql/FromSql for postgres-types (shared by tokio-postgres)
|
|
pgvector = { version = "0.4", features = ["postgres"] }
|
|
|
|
# WASM sandbox for untrusted tool execution
|
|
wasmtime = { version = "28", features = ["component-model"] }
|
|
wasmtime-wasi = "28" # WASI support for component model
|
|
wasmparser = "0.220" # WASM binary parsing for validation
|
|
|
|
# Cryptography for secrets management
|
|
aes-gcm = "0.10"
|
|
hkdf = "0.12"
|
|
sha2 = "0.10"
|
|
blake3 = "1"
|
|
rand = "0.8"
|
|
|
|
# NEAR key management (ed25519 signing, borsh serialization, base58 encoding)
|
|
ed25519-dalek = { version = "2", features = ["rand_core", "zeroize"] }
|
|
borsh = { version = "1", features = ["derive"] }
|
|
bs58 = "0.5"
|
|
argon2 = "0.5"
|
|
zeroize = { version = "1", features = ["derive"] }
|
|
|
|
# Docker sandbox
|
|
bollard = "0.18"
|
|
|
|
# HTTP proxy for sandboxed network access
|
|
hyper = { version = "1.5", features = ["server", "http1", "http2"] }
|
|
hyper-util = { version = "0.1", features = ["server", "tokio", "http1", "http2"] }
|
|
http-body-util = "0.1"
|
|
bytes = "1"
|
|
base64 = "0.22.1"
|
|
|
|
# macOS keychain
|
|
[target.'cfg(target_os = "macos")'.dependencies]
|
|
security-framework = "3"
|
|
|
|
# Linux secret-service (GNOME Keyring, KWallet)
|
|
[target.'cfg(target_os = "linux")'.dependencies]
|
|
secret-service = { version = "4", features = ["rt-tokio-crypto-rust"] }
|
|
zbus = "4"
|
|
|
|
[dev-dependencies]
|
|
tokio-test = "0.4"
|
|
tokio-tungstenite = "0.26"
|
|
testcontainers-modules = { version = "0.11", features = ["postgres"] }
|
|
pretty_assertions = "1"
|
|
tempfile = "3"
|
|
|
|
[features]
|
|
default = []
|
|
integration = []
|