Skip to content
Back to skills

Guava Suite

ASecurity

Premium security suite for AI agents. Adds $GUAVA token-gated strict mode protection on top of guard-scanner. Features: 2-layer defense (static + runtime), Soul Lock, Memory Guard, on-chain identity verification via SoulRegistry V2. Requires $GUAVA token on Polygon Mainnet.

  • 14 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 7, 2026
ai-agentsgobashnodegitapisecurity

Works with

  • api

Security analysis

A100/100

Pro scans all 19 files and shows the line behind each finding

Scanned September 7, 2026

npx -y skills add modbender/skill-library-mcp --skill guava-suite --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Guava Suite?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Guava Suite
[![Security: A โ€” Skills Directory](https://www.skillsdirectory.com/api/skills/modbender-guava-suite/badge)](https://www.skillsdirectory.com/skills/modbender-guava-suite)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: guava-suite
description: >
  Premium security suite for AI agents.
  Adds $GUAVA token-gated strict mode protection on top of guard-scanner.
  Features: 2-layer defense (static + runtime), Soul Lock, Memory Guard,
  on-chain identity verification via SoulRegistry V2.
  Requires $GUAVA token on Polygon Mainnet.
homepage: https://github.com/koatora20/guava-suite
metadata:
  openclaw:
    emoji: "๐Ÿˆ"
    category: security
    requires:
      bins:
        - node
      env: []
    files: ["services/*"]
    primaryEnv: null
    tags:
      - security
      - token-gate
      - runtime-guard
      - soul-lock
      - polygon
      - guava
---

# GuavaSuite ๐Ÿˆ

Premium 2-layer security for AI agents โ€” powered by **$GUAVA** token gating.

## What It Does

GuavaSuite upgrades your guard-scanner from `enforce` (CRITICAL-only) to `strict` mode
(HIGH + CRITICAL blocking), plus adds these exclusive features:

| Feature | Free (guard-scanner) | Suite ($GUAVA) |
|---------|---------------------|----------------|
| Static Scan (129 patterns, 21 categories) | โœ… | โœ… |
| Runtime Guard (enforce) | โœ… | โœ… |
| **Runtime Guard (strict)** | โŒ | โœ… |
| **Soul Lock** (SOUL.md integrity + auto-rollback) | โŒ | โœ… |
| **Memory Guard** (L1-L5 ่จ˜ๆ†ถใ‚ทใ‚นใƒ†ใƒ ไฟ่ญท) | โŒ | โœ… |
| **Zettel Memory** (ๅŽŸๅญ็š„ใƒŽใƒผใƒˆ+ใƒชใƒณใ‚ฏ+ๆคœ็ดข) | โŒ | โœ… |
| **On-chain Identity** (SoulRegistry V2) | โŒ | โœ… |
| Audit Log (JSONL) | โœ… | โœ… |

## Prerequisites

1. **guard-scanner** installed (`clawhub install guard-scanner`)
2. **$GUAVA tokens** on Polygon Mainnet (minimum 1M $GUAVA)
   - Token: `0x25cBD481901990bF0ed2ff9c5F3C0d4f743AC7B8`
   - Buy on [QuickSwap V2](https://quickswap.exchange/#/swap)

### How to Get $GUAVA

| Method | How |
|--------|-----|
| **่ถ…่ถŠ่€…ใƒ—ใƒฉใƒณ** (note.com membership) | ๆ‰‹ๅ‹•้€้‡‘ โ€” MetaMaskใงใ‚ฆใ‚ฉใƒฌใƒƒใƒˆใซ็›ดๆŽฅ้€ไป˜ |
| **่‡ชๅˆ†ใง่ณผๅ…ฅ** | QuickSwap V2 ใง MATIC โ†’ $GUAVA swap |

> **ใ‚ปใ‚ญใƒฅใƒชใƒ†ใ‚ฃๆ–น้‡**: $GUAVAใฎ้…ๅธƒใฏใ™ในใฆMetaMaskใ‹ใ‚‰ใฎๆ‰‹ๅ‹•้€้‡‘ใง่กŒใ„ใพใ™ใ€‚็ง˜ๅฏ†้ตใ‚’ใ‚นใ‚ฏใƒชใƒ—ใƒˆใซๆธกใ™ใ“ใจใฏไธ€ๅˆ‡ใ—ใพใ›ใ‚“ใ€‚

## Quick Start

### 1. Install

```bash
# Via clawhub (coming soon)
clawhub install guava-suite

# Or: git clone + setup
git clone https://github.com/koatora20/guava-suite.git
cd guava-suite && bash setup.sh
```

### 2. Activate

```bash
node services/license-api/src/activate.js --wallet 0xYOUR_WALLET_ADDRESS
```

This single command will:
1. Request a challenge nonce
2. Prompt you to sign with your wallet (EIP-712)
3. Verify your signature & check $GUAVA balance on Polygon
4. Save JWT locally & switch guard-scanner to `strict` mode

### 3. Check Status

```bash
node services/license-api/src/activate.js --status
```

### Deactivate

```bash
node services/license-api/src/activate.js --deactivate
```

## How Token Gating Works

```
   You hold $GUAVA on Polygon
           โ”‚
           โ–ผ
   Sign EIP-712 challenge
           โ”‚
           โ–ผ
   LicenseService checks:
   โ”œโ”€ Signature valid?
   โ”œโ”€ $GUAVA balance โ‰ฅ 1M?
   โ”‚
   โ–ผ
   JWT issued โ†’ SuiteGate activated
           โ”‚
           โ–ผ
   guard-scanner mode: strict
   (HIGH + CRITICAL blocked)
```

## Architecture

- **SuiteGate** โ€” JWT-based fail-closed gate (grace period for network issues)
- **LicenseService** โ€” Nonce + EIP-712 signature + $GUAVA balance check + JWT issuance
- **TokenBalanceChecker** โ€” Polygon RPC ERC-20 balance verification (zero dependencies)
- **SuiteBridge** โ€” Connects SuiteGate status to guard-scanner runtime mode
- **SoulRegistry V2** โ€” On-chain identity verification (Polygon)

## External Endpoints

| URL | Data Sent | Purpose |
|-----|-----------|---------|
| `polygon-rpc.com` | Wallet address | $GUAVA balance check (read-only `eth_call`) |

## Security & Privacy

- **Read-only on-chain**: Only calls `balanceOf` โ€” no transactions, no approvals
- **Local JWT**: Tokens stored locally, never sent to external servers
- **Fail-closed**: If balance check fails, Suite features are disabled (not bypassed)
- **No telemetry**: Zero analytics or tracking

## License

Proprietary โ€” ยฉ 2026 Guava ๐Ÿˆ & Dee

Files in this skill

  • ROADMAP.md1.9 KB
  • SKILL.md4.2 KB
  • STATUS.md2 KB
  • docs/ADR-001-open-core-boundary.md1.2 KB
  • docs/ARCH_SPLIT.md1.1 KB
  • docs/GUAVA_SUITE_TOKEN_GATE_SPEC_V1.md2.8 KB
  • docs/IMPLEMENTATION_PLAN_V1.md1.5 KB
  • docs/TASKLIST_TWADA_V2.md2.4 KB
  • docs/THREAT_MODEL.md1.1 KB
  • docs/zettel-spec.md1.1 KB
  • hardhat.config.js425 B
  • package.json1.2 KB
  • scripts/soul-watchdog.sh5.3 KB
  • scripts/zettel/antigravity_digest.py6.7 KB
  • scripts/zettel/link_notes.py2.4 KB
  • scripts/zettel/new_note.py1.7 KB
  • scripts/zettel/search_expand.py4.8 KB
  • scripts/zettel/session_digest_write.py8.6 KB
  • scripts/zettel/weekly_curate.py1.5 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading commentsโ€ฆ