- ✓Open-source license (Apache-2.0)
- ✓Actively maintained (<30d)
- ✓Documented (README)
- !No description
git clone https://github.com/zapsoblige-hash/PolicyVault && cp PolicyVault/*.md ~/.claude/agents/Subagents overview
# PolicyVault **Non-custodial delegated-spending vaults on Kaspa L1 — for people and AI agents.** PolicyVault lets a vault **owner** hand a spending key to an **agent** — an employee, a service, a bot, or an AI agent — without handing over control of the funds. The spending policy is enforced by **Kaspa L1 consensus** through a covenant: even an agent who bypasses this entire application and talks directly to a Kaspa node cannot exceed the owner's policy. The authority model, stated once and everywhere enforced: > **AI MAY REQUEST. POLICYVAULT DETERMINISTICALLY DECIDES. > THE COVENANT ENFORCES. SIGNERS RETAIN CUSTODY.** ## Production status (honest labels) | Surface | Status | |---|---| | **Web / Agent platform** | Existing service at https://app.policy-vault.org; served health identifies the active build. The fullscale-rc40 replacement candidate (`79dec5f`) is pending independent acceptance, activation and publication. | | Current production source | Public v1.9.3 remains the published baseline. This tree is proposed v1.10.6, image `sha256:3919653b7316228d29c0196d329c3ee3550d07dad7ac9015ada6b98f1cc85a7c`; deployment is not implied by this candidate. | | Organizational M-of-N owner root (covenant v0.7) | Included in the replacement candidate. Mainnet activation follows independent review and the contained observation/reconciliation procedure. | | Rooted-vault owner operations in the browser (R7-05) + reservation/withdrawal guidance (F-6) | Included in the candidate; exact deployment state comes from served discovery and health. | | Hosted tenancy for every route family + generation gate (rc11 remediation) | **LIVE** — closes the rc8 findings (unauthenticated hosted builds, prototype-derived version selection, unsafe mainnet creation of the non-standard v0.4 generation) | | Post-launch live-stack review corrections (rc29: webhook target policy + DNS transport, SDK transport recovery key, legacy same-effect completion ownership, image/package LICENSE + NOTICE, privacy-safe runtime artifacts, recovery guidance) | **IN THIS SOURCE and in the `fullscale-rc29` image** — every finding of the independent read-only review of the running rc28 stack corrected RED-first with a permanent regression; the hosted deployment carries them once the served buildId reads `f217011`; installed SDK / mobile clients must upgrade for the transport correction | | Second post-launch review corrections (rc30: webhook response-socket lifetime bound; upstream Silverscript ISC notice beside the compiler and the reference program) | **IN THIS SOURCE and in the `fullscale-rc30` image** — both findings of the independent read-only launch review of the running rc29 stack corrected RED-first with a permanent real-socket regression; the hosted deployment carries them once the served buildId reads `9dbc5f7`; no SDK / mobile client byte changed | | Organization UI availability correction (rc31: organizational-root creation offered only where capability discovery advertises it; generation refusals say that address/amount changes cannot enable an unsupported mainnet generation; build errors scoped to the wizard) | **IN THIS SOURCE and in the `fullscale-rc31` image** — the owner-observed RC30 finding, corrected RED-first with a 13-case DOM regression that drives the real page and scripts (synthetic wallet, intercepted HTTP); browser presentation only — the server / SDK generation gates are unchanged and remain the authority; no SDK / mobile client byte changed | | MCP package (`policyvault-mcp` on npm) | Proposed `policyvault-mcp@1.6.2`; tarball SHA-256 `128403f81d4af7b73ae86a31a750d39ec21c28f518d214f4e678807c3dff0c14`. The registry identifies the delivered version. No genesis, signature or submission tool is exposed. | | Flagship wave 1 (v1.6.0 / v1.7.0) and wave 2 (v1.8.0) source | **INCLUDED and LIVE where applicable** (see their CHANGELOG entries; v0.6 stays FIXTURE VENUE ONLY / no mainnet swap; x402 facilitator PRODUCTION-READY, NOT deployed; MCP usage telemetry OFF) | | Covenant protocol v0.6 (atomic composability) | **COVENANT-BYTE-FROZEN** (2026-09-03): VM-verified on the real engine with production bytes and testnet-verified (live testnet-10 SELL + BUY). **FIXTURE VENUE ONLY** — no real DEX venue, no mainnet swap, no server/web/mobile/MCP surface, `deadlineDaa` is a pre-sign boundary and not a consensus expiry, and swaps are not economically viable below roughly 10 KAS. **PolicyVault is not a DEX and will not become one.** See `docs/postlaunch/v0.6-covenant-byte-freeze.md` | | v0.5 token-controller covenant (byte-frozen) + least-privilege discovery / console correctives + MCP 1.4.2 (v1.5.0) | **LIVE** — production runtime successor `fullscale-rc8` (buildId `1c02162`) deployed and automated-accepted on 2026-09-02: principal-scoped capability discovery, no dev-signer probe on production, zero privileged reads while signed out, opt-in wallet diagnostics; `policyvault-mcp@1.4.2` advertises only the tools a credential's scopes cover (server-side enforcement unchanged). The v0.5 TOKEN CONTROLLER covenant (`contracts/PolicyVault.v0.5.sil`, sha256 `c693aeff…`) ships as SOURCE — COVENANT-BYTE-FROZEN, VM-verified with production bytes and testnet-verified with one live lifecycle; NOT production (no v0.5 surface, no mainnet v0.5 vault). Illustrated onboarding walkthrough (presentation only). See CHANGELOG | | Distribution: MCP registry, agent examples, self-hosting (v1.4.0) | Source/distribution release — NO runtime change (production keeps buildId `6c3177f`): the MCP server is npm/registry-packaged (`policyvault-mcp`, `io.github.zapsoblige-hash/policyvault`), thin OpenAI-Agents-SDK/LangChain/CrewAI wiring examples ship in `examples/agents/`, and one-command self-hosting ships in `deploy/selfhost.sh` + `docs/selfhost-quickstart.md`; see CHANGELOG | | Bearer wallet-sessions + native mobile transport (v1.3.0) | **LIVE**: opt-in bearer wallet-session authentication for non-browser clients (authentication only — never signing authority or custody; cookie web auth unchanged), plus the native Android transport (explicit CapacitorHttp at the platform seam; no CORS widening, web client stays strict same-origin). The full bearer lifecycle was proven from the real packaged Android runtime against live production; see CHANGELOG | | Responsive client + quiet signed-out UX (v1.2.0) | Faster signed-in navigation (retained state, parallel reads, truthful progress states — pending is never success) and no spurious signed-out error toasts; see CHANGELOG | | Network-identity banner fix (v1.1.1) | The web client's network banner now derives from the server's node-verified `/network/status` and FAILS CLOSED to an explicit UNKNOWN state — never a stale or assumed network; see CHANGELOG | | In-app documentation discovery (v1.1.0) | Docs link + contextual help in the web client, deep-linking to https://docs.policy-vault.org — presentation-only successor; see CHANGELOG | | External-approver discovery fix (2026-08-27) | **DEPLOYED + AUTOMATED-ACCEPTED** (fail-closed availability defect, no funds/authority/privacy exposure; see CHANGELOG "Fixed". Acceptance was automated; no human acceptance test is claimed) | | Covenant protocol v0.4.1 | Mainnet-operational (real mainnet lifecycle evidence; see SECURITY.md for exactly what is proven and how) | | Covenant protocol v0.5 (token controller) | **COVENANT-BYTE-FROZEN** (2026-09-02): VM-verified on the real engine with production bytes and testnet-verified (live testnet-10 lifecycle, consensus-rejected negatives); **not production** — no server/API/web surface, no mainnet instance; see `docs/postlaunch/v0.5-covenant-byte-freeze.md` | | Python client, MCP server, x402/AP2 adapters, platform agent API | Shipped; covered by the automated conformance/integration suites in this repository | | **Native mobile (iOS/Android)** | **DEVELOPMENT — NOT YET PRODUCTION-CAPABLE.** The Android app (full Capacitor project in `mobile/`, incl. the native production transport and bearer sign-in) has been validated on a real emulator against live production — reads, full bearer auth lifecycle, fail-closed negatives — but production signing, store packaging, and camera/QR capture remain pending; do not build custody workflows on it yet | | Security assurance | **INTERNAL and evidence-based only**: independent internal AI falsification reviews of each exact candidate (the reviewer never repairs its own candidate), hostile / adversarial testing on the real Kaspa script engine with production bytes, RED-first reproduction with permanent regressions, production-shaped mechanical verification, live testnet-10 evidence, exact artifact and frozen-byte verification, and the owner's own live mainnet validation after each deployment. **No external professional security audit has occurred and none is part of PolicyVault's process** (owner policy, 2026-09-05); nothing in this repository claims otherwise | - **x402 FACILITATOR (`integrations/x402-facilitator/`, 2026-09-02):** DESIGN FROZEN (owner-authorized; `docs/postlaunch/x402-facilitator-design-freeze.md`) · IMPLEMENTED · UNIT-TESTED · ADVERSARIAL-TESTED · INTEGRATION-TESTED (real HTTP service + real PostgreSQL claim store) · TESTNET-VERIFIED (real KAS + real frozen-v0.5 token payments on testnet-10; `docs/testnet-x402-facilitator-evidence.json`). A separately deployed, unprivileged, READ-ONLY chain verification / settlement attestation service for the proposed Kaspa scheme `pv-x402-kaspa-exact-upfront/1` (network identifiers `kaspa:mainnet` / `kaspa:testnet-10` are PolicyVault's provisional CAIP-2-syntax identifiers — no upstream registration is claimed). It never signs, broadcasts, escrows, or charges. NOT a hosted production service (a separate owner gate); no upstream Kaspa x402 scheme exists, so it is not "x402-compatible" without that qualification. ## What the covenant enforces (consensus, not software) - **Owner-controlled vaults** — create, manage, pause, recover, close. -
What people ask about PolicyVault
What is zapsoblige-hash/PolicyVault?
+
zapsoblige-hash/PolicyVault is subagents for the Claude AI ecosystem with 1 GitHub stars.
How do I install PolicyVault?
+
You can install PolicyVault by cloning the repository (https://github.com/zapsoblige-hash/PolicyVault) or following the README instructions on GitHub. ClaudeWave also provides quick install blocks on this page.
Is zapsoblige-hash/PolicyVault safe to use?
+
Our security agent has analyzed zapsoblige-hash/PolicyVault and assigned a Trust Score of 77/100 (tier: Trusted). See the full breakdown of passed checks and flags on this page.
Who maintains zapsoblige-hash/PolicyVault?
+
zapsoblige-hash/PolicyVault is maintained by zapsoblige-hash. The last recorded GitHub activity is dated 2026-09-15, with 0 open issues.
Are there alternatives to PolicyVault?
+
Yes. On ClaudeWave you can browse similar subagents at /categories/agents, sorted by popularity or recent activity.
Deploy PolicyVault to your cloud
Ship this repo to production in minutes. Each platform spins up its own environment with editable env vars.
Maintain this repo? Add a badge to your README
Drop the badge into your GitHub README to show it's tracked on ClaudeWave. Each badge links back to this page and reflects the live Trust Score.
[](https://claudewave.com/repo/zapsoblige-hash-policyvault)<a href="https://claudewave.com/repo/zapsoblige-hash-policyvault"><img src="https://claudewave.com/api/badge/zapsoblige-hash-policyvault" alt="Featured on ClaudeWave: zapsoblige-hash/PolicyVault" width="320" height="64" /></a>More Subagents
The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.
The agent that grows with you
Java 面试 & 后端通用面试指南,覆盖计算机基础、数据库、分布式、高并发、系统设计与 AI 应用开发
Build Agentic workflows, RAG pipelines, with rich AI model and tool support on one collaborative workspace. Deploy on cloud, VPC, or self-hosted, so teams move from prototype to production without rebuilding the stack.
The agent engineering platform.
Makes your AI agent think like the laziest senior dev in the room. The best code is the code you never wrote.