bitfence Risk Oracle

io.github.bitfenceaiv0.7.7更新於 Oct 8, 2026

Pre-transaction token risk checks for autonomous agents on six chains. Read-only; paid via x402.

已驗證Streamable HTTP可網頁執行FinanceSecurity & Monitoring

概覽

AI 產生的概覽

在助理進行兌換或轉帳前,為六條鏈上的代幣提供結構化的交易前風險評分。

功能
bitfence 是針對自主代理的唯讀風險預言機。在代理兌換、轉帳或與某個代幣互動之前,它會在不到一秒內回傳結構化評估:0-100 的綜合評分、信心值、行動建議,以及目前生效的斷路器旗標。風險拆分為六類,涵蓋出場完整性(蜜罐行為、賣出稅、凍結權限)、供給完整性、流動性完整性、持有者與內部人風險、來源追溯,以及市場完整性。同一套評分引擎透過 HTTP/JSON API、本 MCP 伺服器、Rust 綁定,以及據稱即將推出的 Coinbase AgentKit 提供者對外提供。
適用情境
當助理或代理即將兌換、轉帳或以其他方式與某個代幣互動,而你希望先做一次機器可讀的安全檢查時使用。它鎖定的是那些提供兌換與轉帳動作、卻沒有系統性交易前檢查的代理框架,也適合想要結構化欄位、而非給人看的錢包彈出視窗的呼叫方。
執行需求
透過 streamable HTTP 連線到 api.bitfence.ai 的遠端 MCP 端點,不需要在本機安裝。宣告中沒有提到帳號、API 金鑰或註冊。每次查詢透過 x402 在 Base 上以 USDC 付費,風險查詢每次 0.10 美元,情境查詢每次 0.20 美元,因此呼叫方需要一個有餘額且支援 x402 的錢包以及網路存取。
安裝前請注意
查詢要付費:透過 x402 在 Base 上以 USDC 支付,風險查詢每次 0.10 美元,情境查詢每次 0.20 美元,因此反覆查詢的代理會花掉真實資金。此伺服器被描述為唯讀,本身不會簽署或廣播交易。評分引擎原始碼未公開,因此確切的斷路器門檻、訊號權重與成熟度邏輯並未發布;綜合評分與信心值應視為一項輸入,而非保證。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 bitfence Risk Oracle,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Web executable,透過 Streamable HTTP。 遠端服務在工作區中設定後即可從網頁執行環境執行。

其他 MCP 客戶端

把它新增到你客戶端的 mcpServers 設定中。

{
  "mcpServers": {
    "bitfence": {
      "type": "http",
      "url": "https://api.bitfence.ai/mcp"
    }
  }
}

README

bitfence

The risk layer agents can't skip.

bitfence is a pre-transaction token risk oracle for autonomous AI agents operating on Solana, Base, Ethereum, Arbitrum, BSC, and HyperEVM. Before an agent swaps, transfers, or interacts with a token, bitfence returns a structured risk assessment in under a second: a composite score, confidence value, action recommendation, and any active circuit-breaker flags.

  • Live on Solana, Base, Ethereum, Arbitrum, BSC, and HyperEVM
  • HTTP API · MCP server · Rig (Rust) — Coinbase AgentKit coming soon
  • $0.10 per risk query in USDC on Base via x402 — no API keys

🔗 bitfence.ai · 📄 Whitepaper · 𝕏 @bitfenceai


Why this exists

Autonomous agents now hold keys, read mandates, and broadcast transactions without a human in the loop. The agent frameworks shipping today expose swap and transfer actions with no systematic pre-transaction safety check. The risk-assessment tooling that exists was built for a human reading a wallet pop-up — not a machine routing on structured fields.

bitfence fills the gap: a pre-intent token risk layer designed for machine consumption. Neutral, transparent, agent-native, per-call priced. It is complementary to existing wallet-grade tools, not competitive with them.

What it scores

Risk is decomposed into six categories — each a distinct mechanism by which a holder's position is destroyed — and assembled into a 0–100 composite with maturity-aware scoring and structured circuit-breaker overrides.

CategoryWhat it covers
Exit IntegrityHoneypot behaviour (measured by bitfence's own transaction simulation on EVM chains), sell/transfer taxes and their modifiability, freeze authority, transfer blocking
Supply IntegrityMint authority, hidden ownership, owner-editable balances, permanent delegates, upgradeable proxies, selfdestruct, metadata mutability
Liquidity IntegrityLP lock and burn status, unlock schedule, pool depth, deployer-held LP, pool age
Holder & Insider RiskTop-holder share, deployer share, holder count, sniper/insider/bundler cohorts, holder wallet ages
ProvenanceDeployer track record, observed prior rugs, vendor scam verdicts, launchpad lifecycle, verification registries
Market IntegrityWash-trade ratios, old-wallet flow share, price/volume divergence

Circuit breakers override the composite: measured threats (honeypot, confiscatory sell tax, selfdestruct) block even trusted tokens; heuristic flags floor the score for any token outside the curated trusted-token registry. The reported confidence value reflects only the data sources actually consulted, with cross-source disagreements excluded.

The full methodology is in the whitepaper.

Integration surfaces

The same scoring engine is exposed through four interfaces. Each returns the same RiskAssessment structure.

  • HTTP/JSON API — for any caller that speaks HTTP
  • MCP server — for tool-calling LLM agents (Claude Desktop, MCP-enabled IDEs)
  • Coinbase AgentKit — ActionProvider coming soon
  • Rig (Rust) — typed in-process tool binding for Rust-native agents

For integration details, contact [email protected].

Pricing and access

  • $0.10 per risk query, $0.20 per contextual query in USDC on Base via x402
  • Implemented against the Coinbase CDP facilitator
  • No accounts, no API keys, no signups
  • Listed on the Coinbase x402 Bazaar

Open-source posture

Documentation, whitepaper, and integration surfaces are open under Apache 2.0. The scoring engine source remains closed for security reasons: publishing exact circuit-breaker thresholds, signal weights, and maturity logic would let adversarial token deployers engineer tokens that sit immediately below the trigger points, defeating the protection bitfence provides to agents downstream. This trade-off is discussed in the whitepaper.

A publishable methodology document — one useful to other Ethereum security teams without exposing trigger logic to deployers — is in active development.

Security

See SECURITY.md for vulnerability disclosure.

License

Apache License 2.0

來源:README.md,提交 ff33298

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v0.7.7最新Sep 16, 2026