Skip to content

feat(action-provider): add Agenda pre-sign evidence review - #1514

Open
vassiliylakhonin wants to merge 1 commit into
coinbase:mainfrom
vassiliylakhonin:feat/agenda-guard-action-provider
Open

vassiliylakhonin wants to merge 1 commit into
coinbase:mainfrom
vassiliylakhonin:feat/agenda-guard-action-provider

Conversation

@vassiliylakhonin

@vassiliylakhonin vassiliylakhonin commented Sep 23, 2026 •

Copy link
Copy Markdown

Summary

Adds an optional AgendaGuardActionProvider for reviewing caller-supplied EVM transaction evidence. This is an explicit AgentKit action, not automatic interception of other wallet actions.

Review boundary

  • Every returned result has is_safe: false: either reject or step_up_human_required.
  • Legacy local risk-denylist matches, unlimited approval patterns and suspicious intent can reject a proposal. The denylist is not a current authoritative sanctions dataset.
  • Single-transaction and optional daily-history comparisons use caller-reported values, not an authoritative wallet ledger. Missing history is not replaced with zero.
  • HTTP failures, HTTP 402, malformed responses and remote allow never authorize signing or broadcasting. A remote rejection can tighten the result.
  • Finite, nonnegative amounts/history and finite, positive configuration limits are validated.
  • EVM network support only; endpoint=None provides local review without sending evidence to the remote service. The default remote endpoint receives the supplied transaction evidence; redirects are disabled.
  • No signing, transaction execution, payment proofs, automatic paid retries or escrow payouts are implemented.

Verification

  • Provider regression suite: 43 passed, all provider HTTP calls and SDK analytics mocked.
  • Python package unit suite: 712 passed, 35 e2e/integration tests deselected.
  • Whole-package Ruff lint and formatting checks: passed.
  • git diff --check: passed.
  • Registered action description: 548 characters (checked directly). The existing check-description-length entry point cannot run in this upstream checkout because its referenced scripts module is absent.
  • Independent read-only candidate review found no surviving authorization bypass or concrete regression.
  • No funded transactions or live paid evaluations were performed.

Includes a changelog fragment and updated usage/privacy/payment documentation. The original unsigned contribution was replaced by a single GitHub-verified signed commit to follow CONTRIBUTING.md. Maintainer review is still required.

@cb-heimdall

cb-heimdall commented Sep 23, 2026 •

Copy link
Copy Markdown

🟡 Heimdall Review Status

Requirement Status More Info
Reviews 🟡 0/1
Denominator calculation
Show calculation
1 if user is bot 0
1 if user is external 0
2 if repo is sensitive 0
From .codeflow.yml 1
Additional review requirements
Show calculation
Max 0
0
From CODEOWNERS 0
Global minimum 0
Max 1
1
1 if commit is unverified 0
Sum 1

@github-actions github-actions Bot added documentation Improvements or additions to documentation action provider New action provider python labels Sep 23, 2026
@vassiliylakhonin
vassiliylakhonin force-pushed the feat/agenda-guard-action-provider branch from 2ddff11 to 32dce19 Compare October 2, 2026 09:42
@vassiliylakhonin vassiliylakhonin changed the title feat(action-provider): add Agenda Financial Guard pre-sign transaction firewall feat(action-provider): add Agenda pre-sign evidence review Oct 2, 2026
@vassiliylakhonin

Copy link
Copy Markdown
Author

Updated this existing PR after reviewing its authorization boundary. The action now always returns is_safe: false, with either rejection or mandatory human review; HTTP errors, payment-required responses and remote allowances cannot authorize signing. Caller-reported history is no longer fabricated as zero. Added finite-number validation, offline mode, EVM scoping, a changelog and accurate documentation.

Verification: 43 mocked provider regression tests and 712 package unit tests passed; package Ruff lint/format checks passed. No live paid evaluations or funded transfers were performed. The legacy description-length entry point references a missing upstream scripts module; the registered action description was checked directly (548 characters).

The contribution is now one GitHub-verified signed commit, replacing the initial unsigned commit. Ready for maintainer review; this remains an optional evidence-review action, not automatic wallet enforcement.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

action provider New action provider documentation Improvements or additions to documentation python

Development

Successfully merging this pull request may close these issues.

2 participants