# SCRIPTMASTERLABS — Canonical Agent Guide

> **Single human-readable machine entry point for SCRIPTMASTERLABS.** Agents should start here, then resolve structured truth from the linked canonical manifests. Do not infer current product, runtime, payment, or listing state from historical repository files.

Last updated: 2026-09-18
Canonical brand: **SCRIPTMASTERLABS**
Legal entity: **Script Master Labs, LLC**
Website: `https://scriptmasterlabs.com/`

## Authority order

When two SML artifacts disagree, use this order:

1. Fresh HTTP response / fresh `PAYMENT-REQUIRED` challenge from the execution origin being called.
2. `https://scriptmasterlabs.com/.well-known/route-authority.json`
3. `https://scriptmasterlabs.com/.well-known/current-products.json`
4. `https://scriptmasterlabs.com/.well-known/product-intents.json`
5. `https://scriptmasterlabs.com/agents.json`
6. `https://scriptmasterlabs.com/llms.txt`
7. This `agent.md` guide.
8. Historical docs, listing packs, compatibility code, archived workflows, and legacy deployment artifacts are non-authoritative unless a current manifest explicitly references them.

`current-products.json` is the lifecycle overlay for products added or materially changed after the older product-intent snapshot. Its purpose is to prevent a new product from disappearing from discovery merely because settlement verification, launch wiring, or production promotion is still in progress.

## Current production authority

Source control / change authority: **GitLab**.
Primary production runtime: **Render**.
Current paid API origin: **SqueezeOS** at `https://squeezeos-api.onrender.com`.

Legacy `.github/` workflows, GitHub references, Vercel files, compatibility bridges, and archived deployment material may remain in repository history for provenance or isolated subprojects. Their presence does **not** make them current SCRIPTMASTERLABS production authority.

## Payment authority

Canonical rail for SqueezeOS-served paid products: **x402 v2**, **Coinbase CDP**, **USDC on Base mainnet (`eip155:8453`)**.

Never cache a receiving address, amount, network, asset, or payment header from documentation. Resolve live terms from the target resource immediately before payment. Product-specific first-party manifests may explicitly declare additional supported rails.

A `402` response is a payment challenge, not proof of payment. `PAYMENT-SIGNATURE` is authorization, not settlement. Settlement is not accepted delivery. Count successful commerce only after independently verified settlement and usable accepted delivery.

## Canonical product routing

Route by requested job, not by whichever product name an agent happens to know.

- Realtime multimodal economic control plane / voice x402 buyer → **SML LIVE / Executive Agent Runtime**
- Verify provider before trust or spend → **Provider Trust / TrustBeforePay**
- Delegate scoped actions into a browser the user authenticated themselves → **GhostKey**
- Broad API/tool routing → **SqueezeOS**
- Discover x402 paid APIs or inspect fresh payment requirements → **x402 Gateway / x402 Preflight**
- Robinhood prediction-market evidence + tokenized-stock/RWA intelligence → **Robinhood RWA Intelligence**
- Software package docs/dependency/vulnerability evidence → **ScriptDocs**
- Buy or run a complete versioned agent path with recovery edges + receipt → **GraphForge**
- Determine whether an artifact/package record is current and publisher-authoritative → **CANON**
- One public URL → structured extraction → **SML Web Scraping**
- One safe public URL → LLM-ready Markdown → **Agent Web Access / URL to Markdown**
- Unknown source → web research + evidence → **SML Web Research**
- Verify a market-data claim → **Fact Verification**
- One US equity quote → **SML Stock Quote**
- FX reference conversion → **SML Currency Conversion**

### GhostKey runtime boundary

Canonical MCP: `https://ghostkey-mcp.onrender.com/mcp`

Current live GhostKey v0.2.0 exposes status/catalog/quote/policy plus scoped Session Bridge tools for create, status, action and revoke. The browser remains user-authenticated. GhostKey does not export cookies, passwords or session tokens, does not automate CAPTCHA, and does not autonomously spend. Paid execution families remain staged rather than advertised as callable. Use **x402 Gateway**, not GhostKey, when the requested job is general x402 paid-API discovery or payment-requirement inspection.

## Specialized current products

### GraphForge

Runtime: `https://sml-graphforge.onrender.com`
Manifest: `https://sml-graphforge.onrender.com/.well-known/graphforge.json`
MCP: `https://sml-graphforge.onrender.com/mcp`

Current production truth: **live and quote-aware**. GraphForge v0 sells versioned execution graphs rather than prompt packs or isolated API endpoints. Its first-party manifest declares Base + Arc USDC support, caller signing, no custody, and no autonomous spend.

Current commerce boundary: a protected end-to-end payment test is still being completed. Do **not** represent GraphForge as having a verified successful paid run, verified settlement, stranger purchase, or accepted-delivery payment proof until that test is independently complete. The payment-testing agent/runtime path must not be disturbed by documentation work.

### CANON

Canonical page: `https://scriptmasterlabs.com/canon`
Runtime contract: `https://squeezeos-api.onrender.com/api/canon/info`
Publisher manifest: `https://scriptmasterlabs.com/.well-known/canon.json`
Publisher keyset: `https://scriptmasterlabs.com/.well-known/canon-keys.json`

Current production truth: **live**. CANON resolves whether an artifact is current by combining live registry evidence with cryptographically verified publisher freshness manifests. Free single resolution, publisher inspection and mirror audit are available without a subscription. Bulk resolution accepts up to 100 items for `0.01 USDC` per accepted delivery through x402 v2 on Base mainnet.

Truth boundary: registry-owned facts remain registry authority. Verified publisher intent can add publisher status and canonical-location evidence, but a publisher/registry version disagreement becomes an explicit `conflict`; CANON does not silently choose a winner. CANON does not guarantee package safety, ownership, search ranking, adoption, or malicious intent.

## Outbound / reply product-link policy

When SCRIPTMASTERLABS is reaching out or replying, include canonical product links **only when they materially help the recipient** understand, evaluate, integrate, list, cover, or buy the relevant capability. Do not attach an unrelated promotional footer to every message.

Current outbound-safe preset:

1. **LIVEWIRE** — `https://scriptmasterlabs.com/livewire-prediction-market-intelligence`
2. **Robinhood Prediction Markets + RWA Intelligence** — `https://scriptmasterlabs.com/robinhood-rwa-intelligence`
   - Use the focused prediction page when the recipient's intent is specifically Robinhood prediction-market API/MCP: `https://scriptmasterlabs.com/robinhood-prediction-market-api`
3. **CANON** — `https://scriptmasterlabs.com/canon`
4. **Provider Trust** — `https://scriptmasterlabs.com/provider-trust-api`
5. **x402 Gateway / x402 Preflight** — `https://scriptmasterlabs.com/x402-gateway`

Usage rules:

- Lead with the product already being discussed.
- Normally include only **2–3 relevant links**. Use all five only when broad portfolio context is useful, such as partnership introductions, registry/directory submissions, media/ecosystem outreach, or buyer discovery.
- Suppress the block when links are unrelated or would distract from a narrow support, billing, security, privacy, or incident reply.
- Before sending, re-resolve current lifecycle truth from `route-authority.json`, `current-products.json`, `product-intents.json`, and `flagship-products.json`.
- Do **not** promote a product whose current authoritative state says it is not live, not listable, staged, or still payment-verification-in-progress.
- Prefer canonical human landing pages in outreach. Send raw MCP/runtime/OpenAPI endpoints only when the recipient asks for technical integration details.
- This preset is a convenience layer, **not authority**. Current lifecycle and execution-origin evidence always win.

## Machine discovery

- Entity: `https://scriptmasterlabs.com/.well-known/entity.json`
- Route authority: `https://scriptmasterlabs.com/.well-known/route-authority.json`
- Current product lifecycle overlay: `https://scriptmasterlabs.com/.well-known/current-products.json`
- Product intent authority: `https://scriptmasterlabs.com/.well-known/product-intents.json`
- Agent catalog: `https://scriptmasterlabs.com/agents.json`
- LLM buyer guide: `https://scriptmasterlabs.com/llms.txt`
- Service directory: `https://scriptmasterlabs.com/.well-known/sml-services.json`
- Executive runtime: `https://scriptmasterlabs.com/.well-known/sml-executive-agent.json`
- SML LIVE: `https://scriptmasterlabs.com/.well-known/live-agent.json`
- Robinhood prediction authority: `https://scriptmasterlabs.com/.well-known/robinhood-prediction-market-context.json`
- GraphForge manifest: `https://sml-graphforge.onrender.com/.well-known/graphforge.json`
- CANON product card: `https://scriptmasterlabs.com/.well-known/canon-product.json`
- CANON publisher manifest: `https://scriptmasterlabs.com/.well-known/canon.json`
- CANON publisher keyset: `https://scriptmasterlabs.com/.well-known/canon-keys.json`
- x402: `https://squeezeos-api.onrender.com/.well-known/x402`
- MCP: `https://squeezeos-api.onrender.com/mcp`
- OpenAPI: `https://squeezeos-api.onrender.com/.well-known/openapi.json`
- RSS: `https://scriptmasterlabs.com/feed.xml`

## Start with free preflight where available

1. Domain Enrich — demo: `https://squeezeos-api.onrender.com/api/enrich/demo` — contract: `https://squeezeos-api.onrender.com/api/enrich/info`
2. Web Extract One-Shot — demo: `https://squeezeos-api.onrender.com/api/web/demo` — contract: `https://squeezeos-api.onrender.com/api/web/once-info`
3. Geo/Cities — `https://squeezeos-api.onrender.com/api/geo/info`
4. FX Convert — `https://squeezeos-api.onrender.com/api/fx/info`
5. Robinhood prediction evidence — `https://sml-robinhood-rwa-intelligence.onrender.com/api/prediction/info`
6. Paid Prediction Intelligence contract — `https://squeezeos-api.onrender.com/api/prediction/intelligence/info`
7. Paid RWA Intelligence contract — `https://squeezeos-api.onrender.com/api/rwa/info`
8. GraphForge discovery/status — `https://sml-graphforge.onrender.com/graphforge/status`
9. CANON single resolution — `https://squeezeos-api.onrender.com/api/canon/resolve`
10. CANON mirror audit — `https://squeezeos-api.onrender.com/api/canon/audit-mirror`

## Non-negotiable truth boundaries

- Discover/preflight before spend when the product supports it.
- Fresh execution-origin payment terms override cached marketing prices.
- No SML documentation grants an agent permission to spend.
- Caller-defined authority and spend policy control authorization.
- The model/browser must not receive an unrestricted wallet private key.
- Free routes remain free; protected paid payloads must not leak through free evidence routes.
- Missing evidence stays missing/partial; do not fabricate market data, odds, volume, attention, settlement, demand, or adoption.
- Internal tests, controlled buyers, owner-funded calls, and SML-owned wallets are not stranger demand.
- Provider identity is **SCRIPTMASTERLABS**; use **Script Master Labs, LLC** only where a legal entity name is required.
- A product may be discoverable while payment verification is still in progress. Preserve the explicit lifecycle state; do not collapse it into a generic commerce-success claim.

Motto: **Truth First. Proof Always. Pay Only for Accepted Delivery.**
