Back to skills
SKILL.md
Guava Suite
ASecurityPremium security suite for AI agents. Adds $GUAVA token-gated strict mode protection on top of guard-scanner. Features: 2-layer defense (static + runtime), Soul Lock, Memory Guard, on-chain identity verification via SoulRegistry V2. Requires $GUAVA token on Polygon Mainnet.
- 14 stars
- 0 votes
- 0 copies
- 2 views
- Added September 7, 2026
Works with
Security analysis
100/100Pro scans all 19 files and shows the line behind each finding
npx -y skills add modbender/skill-library-mcp --skill guava-suite --agent claude-codeAre you the author of Guava Suite?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/modbender-guava-suite)---
name: guava-suite
description: >
Premium security suite for AI agents.
Adds $GUAVA token-gated strict mode protection on top of guard-scanner.
Features: 2-layer defense (static + runtime), Soul Lock, Memory Guard,
on-chain identity verification via SoulRegistry V2.
Requires $GUAVA token on Polygon Mainnet.
homepage: https://github.com/koatora20/guava-suite
metadata:
openclaw:
emoji: "๐"
category: security
requires:
bins:
- node
env: []
files: ["services/*"]
primaryEnv: null
tags:
- security
- token-gate
- runtime-guard
- soul-lock
- polygon
- guava
---
# GuavaSuite ๐
Premium 2-layer security for AI agents โ powered by **$GUAVA** token gating.
## What It Does
GuavaSuite upgrades your guard-scanner from `enforce` (CRITICAL-only) to `strict` mode
(HIGH + CRITICAL blocking), plus adds these exclusive features:
| Feature | Free (guard-scanner) | Suite ($GUAVA) |
|---------|---------------------|----------------|
| Static Scan (129 patterns, 21 categories) | โ
| โ
|
| Runtime Guard (enforce) | โ
| โ
|
| **Runtime Guard (strict)** | โ | โ
|
| **Soul Lock** (SOUL.md integrity + auto-rollback) | โ | โ
|
| **Memory Guard** (L1-L5 ่จๆถใทในใใ ไฟ่ญท) | โ | โ
|
| **Zettel Memory** (ๅๅญ็ใใผใ+ใชใณใฏ+ๆค็ดข) | โ | โ
|
| **On-chain Identity** (SoulRegistry V2) | โ | โ
|
| Audit Log (JSONL) | โ
| โ
|
## Prerequisites
1. **guard-scanner** installed (`clawhub install guard-scanner`)
2. **$GUAVA tokens** on Polygon Mainnet (minimum 1M $GUAVA)
- Token: `0x25cBD481901990bF0ed2ff9c5F3C0d4f743AC7B8`
- Buy on [QuickSwap V2](https://quickswap.exchange/#/swap)
### How to Get $GUAVA
| Method | How |
|--------|-----|
| **่ถ
่ถ่
ใใฉใณ** (note.com membership) | ๆๅ้้ โ MetaMaskใงใฆใฉใฌใใใซ็ดๆฅ้ไป |
| **่ชๅใง่ณผๅ
ฅ** | QuickSwap V2 ใง MATIC โ $GUAVA swap |
> **ใปใญใฅใชใใฃๆน้**: $GUAVAใฎ้
ๅธใฏใในใฆMetaMaskใใใฎๆๅ้้ใง่กใใพใใ็งๅฏ้ตใในใฏใชใใใซๆธกใใใจใฏไธๅใใพใใใ
## Quick Start
### 1. Install
```bash
# Via clawhub (coming soon)
clawhub install guava-suite
# Or: git clone + setup
git clone https://github.com/koatora20/guava-suite.git
cd guava-suite && bash setup.sh
```
### 2. Activate
```bash
node services/license-api/src/activate.js --wallet 0xYOUR_WALLET_ADDRESS
```
This single command will:
1. Request a challenge nonce
2. Prompt you to sign with your wallet (EIP-712)
3. Verify your signature & check $GUAVA balance on Polygon
4. Save JWT locally & switch guard-scanner to `strict` mode
### 3. Check Status
```bash
node services/license-api/src/activate.js --status
```
### Deactivate
```bash
node services/license-api/src/activate.js --deactivate
```
## How Token Gating Works
```
You hold $GUAVA on Polygon
โ
โผ
Sign EIP-712 challenge
โ
โผ
LicenseService checks:
โโ Signature valid?
โโ $GUAVA balance โฅ 1M?
โ
โผ
JWT issued โ SuiteGate activated
โ
โผ
guard-scanner mode: strict
(HIGH + CRITICAL blocked)
```
## Architecture
- **SuiteGate** โ JWT-based fail-closed gate (grace period for network issues)
- **LicenseService** โ Nonce + EIP-712 signature + $GUAVA balance check + JWT issuance
- **TokenBalanceChecker** โ Polygon RPC ERC-20 balance verification (zero dependencies)
- **SuiteBridge** โ Connects SuiteGate status to guard-scanner runtime mode
- **SoulRegistry V2** โ On-chain identity verification (Polygon)
## External Endpoints
| URL | Data Sent | Purpose |
|-----|-----------|---------|
| `polygon-rpc.com` | Wallet address | $GUAVA balance check (read-only `eth_call`) |
## Security & Privacy
- **Read-only on-chain**: Only calls `balanceOf` โ no transactions, no approvals
- **Local JWT**: Tokens stored locally, never sent to external servers
- **Fail-closed**: If balance check fails, Suite features are disabled (not bypassed)
- **No telemetry**: Zero analytics or tracking
## License
Proprietary โ ยฉ 2026 Guava ๐ & Dee
Files in this skill
- ROADMAP.md
- SKILL.md
- STATUS.md
- docs/ADR-001-open-core-boundary.md
- docs/ARCH_SPLIT.md
- docs/GUAVA_SUITE_TOKEN_GATE_SPEC_V1.md
- docs/IMPLEMENTATION_PLAN_V1.md
- docs/TASKLIST_TWADA_V2.md
- docs/THREAT_MODEL.md
- docs/zettel-spec.md
- hardhat.config.js
- package.json
- scripts/soul-watchdog.sh
- scripts/zettel/antigravity_digest.py
- scripts/zettel/link_notes.py
- scripts/zettel/new_note.py
- scripts/zettel/search_expand.py
- scripts/zettel/session_digest_write.py
- scripts/zettel/weekly_curate.py
Attribution
Comments
Loading commentsโฆ