Skip to content

Built with Strands Agents on AWS

Stop the agent before it signs the drain.

AgentShield reviews every transaction your trading agents propose, blocks drains and honeypots, and pages you only for judgment calls.

Proposals hitting the shield, in the ratio the recorder has seenAllowed-Blocked-Held-
Animated view of transaction proposals reaching the shield. Allowed ones pass, blocked ones bounce off, held ones wait for a human.
Transactions checked
Blocked before signing
Settled without a human
Average decision time
Indicators on-chain

Real attacks, recorded verdicts.

Each case below is a scenario on Base mainnet contracts and the last verdict the recorder stored for it. The highlighted text is what tried to steer the agent.

How a check works

  1. Intent, sources, transaction

    Your agent sends what the human asked for, what it read, and the transaction it wants to sign.

  2. Rules first

    Caps, known drainers, Morse and hidden-Unicode payloads, and live Base checks. A critical failure blocks outright.

  3. Investigation

    A Strands agent works the case with seven tools, then an isolated reviewer that never sees its reasoning scores the hijack risk.

  4. Verdict

    Allow, block, or hold for a human. Every step is recorded, and models can tighten a verdict but never loosen it.

final = strictest(gate1_floor, gate2_reviewer, orchestrator)# a hijacked model can cause a false block, never a false allow

One call before you sign.

Wrap your signer with the Python or TypeScript SDK. It sends the check, waits on review when needed, and never signs without an allow.

ALLOW
guard() calls your signer
BLOCK
raises, nothing is signed
QUARANTINE
waits for an operator to approve or deny
Unreachable
fails closed by default

Agents without an account can pay per check over x402: $0.001 fast, $0.01 with the full investigation, USDC on Base Sepolia.

$ pip install ./sdk/python
from agentshield import Shield, Blocked, ShieldUnavailable, request_from_tx

shield = Shield("https://agentshield-lyart.vercel.app", mode="agent")

req = request_from_tx(
    tx,
    intent="Approve the DEX router so I can swap 250 USDC",
    sources=[tool_output],  # what the agent read
    agent_id="desk-rebalancer-02",
)

try:
    tx_hash = shield.guard(req, lambda _: w3.eth.send_transaction(tx))
except Blocked as e:
    log.warning("not signed: %s", e.verdict.operator_summary)
except ShieldUnavailable:
    log.error("shield unreachable, not signed")

What it runs on

Strands Agents

An orchestrator with seven request-scoped tools, a Gate 2 reviewer as a separate agent with structured output, and hooks that turn every model turn and tool call into the trace you see in the console.

agent = Agent(model, tools=build_tools(ctx),
              hooks=[TraceHooks(trace)])
reviewer = Agent(model, structured_output_model=Gate2Assessment)

Base

Live bytecode, calldata decoding and simulation on mainnet, plus a stake-gated threat registry on Base Sepolia at 0x7F030f…e82e.

ClickHouse

Every verdict and trace step, with latency and anomaly analytics.

x402

Pay per check.