---
name: oracle-agentic-crypto
description: Choose current crypto-agent standards by leverage and custody risk instead of adopting every new primitive.
---

# Agentic crypto stack

Use the narrowest surface that completes the task.

## Available now

- Uniswap v4: quote and inspect hook permissions/code/pool state; prepare guarded unsigned Universal Router calldata only for static-fee, zero-hook pools.
- x402 v2: inspect `PAYMENT-REQUIRED` and prepare an exact-payment template under explicit network, asset, recipient, and atomic caps.
- ERC-8004: inspect and prepare agent identity metadata without inventing registry deployments.
- Permit2: surface the exact approval requirement for reviewed swap routes. Never infer unlimited approval.
- Intents and aggregators: compare CoW, 1inch, 0x, ParaSwap, LI.FI, Across, Relay, and native pools net of gas, fees, timing, and signing semantics.
- Simulation and receipts: simulate prepared EVM calls, bind guard data to calldata, then reconcile the real receipt after user-authorized execution.

## Next, only behind wallet capability checks

- EIP-5792 wallet call batches for wallet-mediated multi-call UX.
- EIP-7702 delegated EOAs and ERC-4337 smart accounts for scoped account behavior.
- ERC-7579 modules and ERC-7715 permissions for session-limited capabilities.
- EIP-7739 defensive typed-data validation for smart-account signatures.
- EIP-7710 delegation chains when x402 or wallet tooling can prove revocation, expiry, target, selector, token, and spend caps.

These are not execution-ready merely because a wallet or SDK advertises them. Before arming any of them, require chain support, exact implementation/version, revocation path, expiry, selector and destination allowlists, token caps, simulation, and receipt reconciliation.

## Decision rule

1. Read-only discovery first.
2. Prepare an unsigned or typed-data artifact with explicit bounds.
3. Keep hosted Oracle keyless and prepare-only.
4. Use armed-local signing only for a user-requested action through an already reviewed signer surface.
5. Treat unattended scheduling, session keys, delegated accounts, and recurring x402 payments as a separate risk class.

Avoid vendor AI gateways inside providers. Providers return deterministic external data or prepared artifacts; Prime/Oracle remains the reasoning harness.

Canonical references: https://eips.ethereum.org/EIPS/eip-5792, https://eips.ethereum.org/EIPS/eip-7702, https://eips.ethereum.org/EIPS/eip-4337, https://eips.ethereum.org/EIPS/eip-7579, https://eips.ethereum.org/EIPS/eip-7715, https://eips.ethereum.org/EIPS/eip-7739, https://eips.ethereum.org/EIPS/eip-7710, https://www.erc8004.org/, and https://docs.uniswap.org/contracts/permit2/overview

## follow --mirror (wallet-follow to prepared intent)

`oracle follow <address> --chain <name> --mirror --max-usd <n>` watches a
followed wallet's own transactions (polling `wallet-watch.mjs`, no websockets)
and converts each genuine buy/sell into a PREPARED, unsigned mirror intent
through `signal-to-prepare.mjs`'s existing NO_TRADE path, the same
enforcement every cold signal goes through, not a parallel gate. Every
emitted intent stays `requiresWalletSignature:true`, `backendSigner:false`,
`executionAllowed:false`; the owner must still review and sign a real trade.

Two custody-relevant design points:

- A transfer only counts as a followed-wallet action when the wallet
  initiated the TRANSACTION (`tx.from`), not merely when it appears as the
  `from`/`to` of the ERC20 log. This is the same rule the Robinhood persona
  uses so airdrop bait does not read as conviction. Someone else spamming
  a token into the wallet's balance never triggers a mirror.
- A GoPlus honeypot/token-security check runs before any intent is prepared.
  A flagged token refuses with the reason; a check that could not be
  completed (upstream down, no data) is also treated as flagged. Fail
  closed, never fail open.

State (dedupe by tx hash, per-day USD spend) persists to
`~/.config/oracle/follow-mirror.json` (or `$ORACLE_CONFIG_DIR/follow-mirror.json`),
atomically written. `oracle follow status [<address>]` lists what is on disk
without polling the chain again. Implementation: `src/agentic/follow-mirror.mjs`.
