Repository navigation
Skillware 0.5.8 and how to go about building secure, air-gapped AI Agents that actually work #420
rosspeili
announced in
Announcements
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
When developers build autonomous AI agents today, they quickly encounter a harsh production reality: LLMs are brilliant at high-level reasoning, but catastrophic at deterministic verification.
Ask a state-of-the-art vision model whether an uploaded passport is authentic, and it will give you a convincing narrative—while completely missing that the document number’s modulo-10 cyclic check digit failed, or that the facial photo was spliced using a neural patch. Worse, sending sensitive user IDs or biometric scans to third-party cloud APIs violates GDPR, HIPAA, and basic data sovereignty principles.
Skillware 0.5.8 bridges this gap. It introduces
security/deepfake_guard—an air-gapped forensic verification engine that runs entirely in-memory on CPU—alongside native async execution parity, automated web form mapping with anti-CSRF preservation, and an institutional supply-chain defense model called the Permissive Fortress.Whether you're building an autonomous KYC onboarding pipeline, an enterprise office automation assistant, or a multi-agent DeFi operations bot, here is everything you need to know about what Skillware is, what’s new in 0.5.8, and how to get started in minutes.
1. New to Skillware? Here’s How It Works
Skillware is an open-source Python framework providing modular, self-contained, and deterministic capability bundles ("skills") for AI agents.
Instead of letting an LLM hallucinate API calls or execute unvetted code, Skillware provides standardized, pre-packaged skill bundles across Security, Office, DeFi, Compliance, Data Engineering, Optimization, and Creative workflows.
The Four Facets of a Skill Bundle
Every Skillware skill lives under
skills/<category>/<skill_name>/and implements four clear contracts:manifest.yaml): Declares strict parameter and output schemas using JSON Schema, environment variables, dependencies, and safety constitutions.instructions.md): Explains to the LLM model when, why, and how to use the skill, detailing output semantics and operational edge cases.skill.py): Pure Python deterministic logic. No hidden sub-calls, no dynamiceval(), no unpredictable LLM hallucination in the execution path.test_skill.py): Exhaustive Pytest suites verifying parameter validation, boundary conditions, and mock executions before any skill touches production.Universal Multi-Model Compatibility
Skillware is host-agnostic. A single skill bundle compiles natively into tool/function calling formats for:
SkillLoader.to_gemini_tool())SkillLoader.to_claude_tool())SkillLoader.to_openai_tool())You can also execute skills directly in pure Python without an LLM:
2. What’s New in Skillware 0.5.8
The
0.5.8release introduces four foundational upgrades:🛡️ 1. Air-Gapped Media & Document Guard (
security/deepfake_guard)Running third-party cloud biometric APIs introduces severe privacy risks and operational latency.
security/deepfake_guardexecutes deterministic signal processing, frequency-domain analysis, and mathematical check digit validation strictly in-memory:(7, 3, 1)modulo-10 checksums across TD1 (3×30 ID cards), TD2 (2×36), and TD3 (2×44 passports), catching altered expiration dates, forged document numbers, and birth date tampering.trainedAlgorithmicMedia, Midjourney, DALL-E, Stable Diffusion).image_path), base64 payloads (image_base64), SSRF-guarded URLs (url), or raw MRZ text (mrz_string).🏰 2. The Permissive Fortress Architecture
As open-source AI agent tooling proliferates, supply-chain poisoning and rogue code execution are paramount concerns. Skillware 0.5.8 hardens its trust model under the MIT License:
CONTRIBUTING.md, accompanied by mandatory PR template verification.credential_fncallables viaBaseSkill.credential(key), allowing host applications to inject secrets per tenant without polluting globalos.environ.bandit -lll,pip-audit,ruff,mypy) paired withtests/test_security_audit.pybanning dynamic execution primitives (eval,exec,compile) across all registry skills.📝 3. Universal Web Form Mapping (
office/web_form_mapper)Autonomous agents frequently need to submit data to web portals, but fragile browser scraping breaks on dynamic tokens.
office/web_form_mappersolves this:legal_profilerecords.__VIEWSTATEinvariants.status: "needs_input".⚡ 4. Native Asynchronous Execution Parity
Multi-agent event loops require high-concurrency non-blocking I/O. Skillware 0.5.8 brings full async parity:
BaseSkill.aexecute(): Asynchronous skill invocation across all skills with automatic non-blocking threadpool offloading.SkillContext.aexecute(): Multi-skill context execution with semaphore-backed concurrency throttling viaSkillContext(max_concurrency=N).skillware.chains.arun_chain(): Asynchronous orchestration for multi-step skill pipelines with conditional branching and timeouts.3. Hands-On Code Walkthroughs: What’s Possible Now
Recipe 1: Air-Gapped Passport & MRZ Validation
Verify an identity document cryptographically without leaking PII to an external cloud endpoint:
If a fraudster altered the expiration date by a single digit, the cyclic modulo-10 algorithm immediately catches the forgery:
Recipe 2: High-Throughput Async Concurrency
Process hundreds of verification checks concurrently while enforcing resource limits:
Recipe 3: Pre-Flight KYC & Form Intake Chain
Chain multiple skills using
SkillContextto create a secure onboarding funnel:security/deepfake_guardchecks image forensics and passport checksums.compliance/pii_masker.office/web_form_mapper.4. What Is Possible in General with Skillware?
Skillware isn't just for KYC—it's an entire ecosystem of modular skills:
security/deepfake_guard(media & document forensics),security/prompt_injection_firewall(Layer-1 prompt defense & evasion deobfuscation),security/deceptive_ui_guard(dark pattern & malicious web detection).defi/evm_reader(read-only ERC-20/721 state & multicall queries),defi/token_security_scanner(honeypot/tax pre-trade audit),defi/evm_tx_handler(safe swaps & transfers).office/gmail_handler(email resolution & dispatch gates),office/pdf_form_filler(AcroForm inspection & filling),office/web_form_mapper(browser-free form discovery & submit).compliance/pii_masker(zero-leakage redaction),compliance/mica_module(EU MiCA crypto asset evaluation),compliance/tos_evaluator(contract policy checks).monitoring/token_limiter(sliding-window budget gates),monitoring/kpi_gate(agent metric tracking),optimization/context_optimizer(semantic compression).5. How to Get Started in 5 Minutes
Step 1: Install Skillware
To install with deepfake forensic extras:
pip install "skillware[security_deepfake_guard]"Step 2: Run Your First Agent Script
Create
agent.py:Step 3: Explore the CLI
Skillware ships with an interactive command-line interface:
6. How to Get Involved
Skillware is 100% open source under the MIT License and maintained by ARPA Hellenic Logical Systems.
We actively welcome contributors! Here is how you can jump in:
Give Skillware 0.5.8 a spin today and build AI agents that are truly robust, secure, and production-ready!
All reactions