- @pyre/core: conservative classifier (classifyTokenAccount) + types + risk constants. EMPTY only when truly empty + classic-SPL + not frozen/delegated; Token-2022/unknown → UNSUPPORTED; frozen/delegated/NFT/valuable/over-threshold → PROTECTED_SKIP; TRANSMUTABLE only via explicit route hook (none in MVP). 43 unit tests incl. a "never says safe" assertion. - @pyre/solana: parseTokenAccounts (SPL + Token-2022 detection, NFT heuristic, rent, defensive owner cross-check) + tests. Tx builders remain Phase-2 stubs. - @pyre/config: loadConfig() from env. - @pyre/api: POST /api/scan — validates pubkey, recomputes classification server-side, CORS + rate-limit; DB persistence deferred. Live-RPC smoke OK. - @pyre/web: wallet-connect (Wallet Standard) + grouped scan UI, ember theme, trust wording (no "safe"); next.config transpiles @pyre/core; prod build OK. Built by 4 agents on a locked core contract; 2 audit agents (security: SOUND; build: 1 blocker → fixed). Stripped .js import extensions in @pyre/core so Turbopack resolves the source package. All typecheck + tests + build green. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@pyre/config
Shared configuration and environment loading for PYRE.
Purpose
Per §13: shared config and environment loading. Provides a typed Env interface
and a loadConfig() loader that maps the variables in the repo-root
.env.example into typed config.
Trust rule
There is intentionally no wallet private-key / mnemonic variable here, and there never will be (§3). All signing happens client-side in the user's wallet.
Variables (mirrors .env.example)
- Solana —
SOLANA_RPC_URL,SOLANA_RPC_WS_URL,SOLANA_CLUSTER - Database —
DATABASE_URL - Redis —
REDIS_URL - AI —
ANTHROPIC_API_KEY,OPENAI_API_KEY,IMAGE_GEN_PROVIDER,IMAGE_GEN_API_KEY - App URLs / ports —
WEB_PORT,API_PORT,WEB_PUBLIC_URL,API_PUBLIC_URL - Admin / security —
ADMIN_API_TOKEN,RATE_LIMIT_SCAN_PER_MIN - Classification thresholds —
PROTECTED_USD_THRESHOLD,MAX_PRICE_IMPACT_BPS,QUOTE_MAX_AGE_MS - Optional / later phases —
IPFS_OR_ARWEAVE_ENDPOINT,IPFS_OR_ARWEAVE_TOKEN,PUMPFUN_CREATOR_WALLET_PUBKEY(public key only)
Status
Skeleton. Defines Env; loadConfig() is a stub.
TODO
- Implement
loadConfig()— readprocess.env, validate/coerce, apply defaults, fail fast on missing required values. Never hardcode secrets.