Skip to content

Add Wasit to the ecosystem skills - #136

Merged
stellar-triage-bot[bot] merged 2 commits into
stellar:mainfrom
dzakwannajmi:add-wasit-ecosystem-card
Oct 8, 2026
Merged

stellar-triage-bot[bot] merged 2 commits into
stellar:mainfrom
dzakwannajmi:add-wasit-ecosystem-card

Conversation

@dzakwannajmi

Copy link
Copy Markdown
Contributor

Wasit is an open-source conformance tester for x402 and MPP on Stellar, published as @wasit-dev/cli and @wasit-dev/server on npm. It runs the real payment flow against a live service and then verifies the settlement independently through Stellar RPC, reading the token contract's own transfer event rather than trusting what the service reported, so a service that answers 200 without settling is caught instead of passed.

Every check is mapped to a written spec clause in a published catalogue, and the skill points an agent at that catalogue rather than letting it infer pass criteria from a check's name. The suite covers the x402 flow and both MPP modes, charge and channel, including the negative cases a channel has to reject: a commitment that does not advance the cumulative, a replayed challenge, and a captured commitment re-presented against a fresh challenge.

It complements the official agentic-payments skill rather than overlapping it. That skill explains the protocols; this one checks an implementation of them. Work on it so far has produced three reproducible defect reports against the official SDK, filed upstream as stellar-mpp-sdk#66, #67 and #70.

Testnet only, and explicitly not a security audit: no source or bytecode is read. The skill states both limits up front so an agent does not overclaim on the tool's behalf.

Copilot AI balanced review requested due to automatic review settings September 20, 2026 09:16
@kaankacar

Copy link
Copy Markdown
Contributor

🤖 Automated message from Kaan's Automated Triage Bot.

👀 Picked this up — a review will follow shortly.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The entry follows the established ecosystem card structure with no unresolved issues.

Review effort: Balanced
Findings: None

What changed in this PR

Adds Wasit’s Stellar payment-protocol conformance testing skill to the ecosystem catalogue.

Changes:

  • Adds a Wasit ecosystem card with its capabilities, repository label, and skill URL.
File Description
site/​src/​data/​skills.ts Registers the Wasit ecosystem skill card.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@dzakwannajmi

Copy link
Copy Markdown
Contributor Author

Hi, a friendly check-in on this listing when you have a moment. Since it was
opened, Wasit 0.5.0 has shipped, and its checks caught stellar-mpp-sdk#82,
which the SDK maintainers fixed in #83 before it reached a release. Happy to
adjust the card if anything is needed.

@stellar-triage-bot

Copy link
Copy Markdown
Contributor

🤖 Automated message from the Stellar Triage Bot.

Thanks for Wasit, and sorry for the wait. Checking settlement against the token's own transfer event is a strong design. I read the skill, the CLI, the MCP server and core. The flags, tool names, env vars, check IDs and the MPP-13 opt-in all match the SKILL.md. The x402 path is safe too: its signer is bound to testnet.

One item blocks the listing:

  • MPP-01 can pay on mainnet when the target asks for it. runMppChargeChecks (packages/core/src/mpp/charge.ts) never reads methodDetails.network from the challenge. The configured network only picks the RPC for the check after payment. The charge() client in @stellar/mpp@0.7.1 takes its network from the challenge (resolveNetworkId(request.methodDetails?.network)). It also has a default pubnet RPC (dist/constants.js). So a target that advertises stellar:pubnet gets a signed mainnet transfer for the amount it chooses, if the MPP_PAYER_SECRET account holds mainnet funds. This conflicts with "Testnet only" in the SKILL.md. It also conflicts with "pubnet has no default RPC endpoint" in SECURITY.md and docs/design/scope-boundary.md. Please refuse to pay when the challenge network differs from the configured network, and say so in the docs.

Also, please merge main into your branch. site/src/data/skills.ts now conflicts, because the Stellar Registry card was appended after your base. Keep both entries.

When both are in, I will re-check and merge.

Keeps both sides of site/src/data/skills.ts: the Stellar Registry,
Scopuly Wallet and Blux cards added on main, then the Wasit card.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@dzakwannajmi

Copy link
Copy Markdown
Contributor Author

Thanks for the careful read. Both are in.

MPP-01 and the challenge's network. Fixed in 0.7.0, on npm since 2026-10-08 (release, fix, advisory GHSA-wm3g-w88q-73xx). MPP-01 now reads methodDetails.network the way @stellar/mpp's client does (absent means testnet) and refuses any network but the run's before anything is signed: on the unpaid read, and again on the exact challenge mppx pays, since mppx requests the target a second time. That gives ERROR (configuration), with nothing signed. The payment goes through the run's RPC endpoint, never the SDK's default, so pubnet has no default endpoint for the payment either. While checking this we also found mppx paying up to three times when a target keeps answering 402; MPP-01 now pays once.

SKILL.md ("Testnet only"), SECURITY.md and docs/design/scope-boundary.md say so. The runs, including a live refusal of a stellar:pubnet challenge from the official charge server, are in docs/evidence/2026-10-08-0.7.0-verification-runs.md, part 1.

main is merged into this branch, with both sides of site/src/data/skills.ts kept: the Stellar Registry, Scopuly Wallet and Blux cards, then Wasit.

@stellar-triage-bot

Copy link
Copy Markdown
Contributor

🤖 Automated message from the Stellar Triage Bot.

Thanks for the quick and careful fix, and for the advisory. Both items are resolved.

  • MPP-01 network. I read 5f0d8b2 and the published @wasit-dev/core@0.7.0. The check refuses a foreign network on the unpaid challenge and again inside createCredential. That is the exact call mppx 0.8.14 makes before it signs. It reads the network the same way resolveNetworkId in @stellar/mpp@0.7.1 does. The payment now uses the run's RPC, and maxPaymentRetries: 1 stops repeat payments. The SKILL.md, SECURITY.md and scope-boundary.md all match.
  • Branch. main is merged. The diff is now one clean ECOSYSTEM_CARDS entry after Blux, and the card URL resolves.
  • New x402 chains. The payment policy filters to the run's network, and the EVM and Solana adapters list only testnets. So a target cannot move those payments to a mainnet either.

The held site-ci run needs a maintainer to approve it. For a data-only card, a read of the entry is enough, so I am merging now.

@stellar-triage-bot stellar-triage-bot Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verified: clean ECOSYSTEM_CARDS append; MPP-01 network fix confirmed in @wasit-dev/core 0.7.0.

@stellar-triage-bot
stellar-triage-bot Bot merged commit 390fbce into stellar:main Oct 8, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants