Optional pre-sign transaction guard: catch approval/Permit2 drains before the wallet signs
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 5/5
- Thời gian dự kiến
- Hơn một tuần
- Mức phù hợp với người mới
- 35/100
- Loại issue
- Tài liệu
- Độ rõ ràng
- Cần làm rõ
- Mức độ hoạt động
- Ít trao đổi
- Công nghệ
- python, typescript
- Lĩnh vực
- blockchain, security
Hướng nghiên cứu
Payload nêu EthAccountWalletProvider, CdpEvmWalletProvider, send_transaction và coinbase-agentkit==0.7.4, nhưng không có tệp repository hoặc test nào. Hãy bắt đầu bằng việc xác định các entry point của provider đó và kiểm tra cách các giao dịch được ký và broadcast; công việc được xem là hoàn tất khi có một pattern opt-in đã được thống nhất và ghi chép, cùng coverage cho hành vi chặn trước khi ký đã nêu.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Summary
Sharing a small, optional pre-sign safety hook in case it is useful to AgentKit users, and to get the team's read on whether it belongs as a documented pattern. Feedback very welcome — including "this belongs in a wallet layer, not here."
Disclosure: I maintain chain-signer, the library referenced below. This is an optional integration suggestion, not a dependency ask.
The gap
AgentKit's wallet providers screen recipients (sanctions / known-bad addresses), which is great. What they don't do today is decode the calldata of the transaction the agent is about to sign. Most agent fund-loss in 2026 hasn't come from sending to a sanctioned address — it has come from an agent being talked into signing an unlimited approve(), a setApprovalForAll(true), a Permit2 allowance, or the same drain hidden inside a multicall / Safe / ERC-4337 execute. A recipient check doesn't see any of that, because the malicious party is the spender in the calldata, not the to of the tx. (Write-up with reproduced 2026 incident shapes: https://gist.github.com/Kevthetech143/f4b940b2b31d457bd593c3d6df9f65c4)
A small, dependency-light option
chain-signer is a pip-installable, offline, no-API-key, no-network static decoder. preflight(tx) decodes an unsigned EVM tx and returns HIGH/MED/LOW flags for the known drain patterns (unlimited/large approval, increaseAllowance, setApprovalForAll, ERC-20 transferFrom, ERC-721/1155 safeTransferFrom, ERC-2612/DAI/Permit2 permits, proxy upgradeTo, EIP-7702 delegation, and drains nested in multicall / Multicall3 / Safe multiSend / 4337 execute). It's a static complement to recipient screening and to simulation — not a replacement — and it runs in-process with no external call.
Proposed shape (opt-in wrapper, verified against coinbase-agentkit==0.7.4)
from chain_signer import preflight
from web3.types import TxParams
from coinbase_agentkit.wallet_providers import EthAccountWalletProvider # or CdpEvmWalletProvider
class PreflightBlocked(Exception): ...
def preflight_guard(tx: dict, *, on_block: str = "raise"):
report = preflight(tx) # offline, no key, no network
highs = [f for f in report.get("risk_flags", []) if f.get("severity") == "HIGH"]
if highs and on_block == "raise":
raise PreflightBlocked("blocked before signing: " + ", ".join(f["code"] for f in highs))
return None if highs else tx
class GuardedEthAccountWalletProvider(EthAccountWalletProvider):
def send_transaction(self, transaction: TxParams):
preflight_guard(dict(transaction), on_block="raise") # raises BEFORE sign + broadcast
return super().send_transaction(transaction)
Behavior (real provider instantiated, send_transaction called on a malicious unlimited approve() — raised before any broadcast):
BLOCKED pre-broadcast: chain-signer blocked a HIGH-risk tx before signing: unlimited_approval
Off by default; zero behavior change unless a user opts in.
Honest limits (stated up front)
This is static decoding, so it won't catch a novel/obfuscated drain it can't decode (those get a LOW "unknown" flag, not a block); it's EVM-only; and it does not stop a redirected legitimate transfer (moving real funds to an attacker) — that's a recipient-allowlist / value-cap concern, which AgentKit's policy layer already addresses and which chain-signer's separate check_action gate also covers. Best used alongside recipient screening + simulation for high-value actions.
Happy to open a PR adding this as a documented optional example if the team thinks it fits, or to just leave it here as a pattern for anyone who wants it.
- Ngôn ngữ chính
- TypeScript
- Star
- 1.3k
- Fork
- 842
- Chỉ số merge pull request
- Không có pull request nào được merge trong 30 ngày
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của coinbase/agentkit
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
Maintainer thường phản hồi trong vòng 1 ngày
-
coinbase-agentkit 0.7.x fails on fresh install: imports solana.rpc.api, which solana>=0.37 removedCó thể đã có người làm @JulienKervarrec đã nhận 16 ngày trước. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Community Action Provider: Agent Safe paid_fetch, x402 payments where the model only picks the URLĐang mở
Độ khó 4/5 1-2 ngày Mức phù hợp với người mới 15/100
coinbase/agentkit#1544 · 6 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 25/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 42/100
coinbase/agentkit#1539 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của coinbase/agentkit
Issue tương tự
-
Mondriaan
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 88/100
knaw-huc/textannoviz#709 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Add: YRF Music NepalĐang mởstreams:add
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 62/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
walletbeat/walletbeat#1558 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
hawk-digital-environments/HAWKI#438 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
good first issue
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
OktoLabsAI/okto-pulse#114 ·
Maintainer thường phản hồi trong vòng 1 ngày