---
name: oracle-protocol-builder
description: Use when the user wants Oracle to build EVM, Solana, or Bitcoin protocol artifacts. Chain-native gates; prepare-only; not a firm audit.
---

# Protocol builder

Oracle scaffolds EVM contracts, Solana programs, and Bitcoin spending policies, then
prepares unsigned side effects only after the matching chain gate is green. The user
signs. Custody boundary unchanged.

## Security gate (v1)

Before any template deploy prepare:

1. `forge test` must pass on the template
2. Slither runs when installed (optional skip if missing; set `REQUIRE_SLITHER=1` to hard-require)
3. JS `runProtocolTemplateGate` / `prepareTemplateDeploy` refuse otherwise

```js
// list
data.call("protocol-templates", "list")
// gate
data.call("protocol-templates", "gate", { templateId: "safe-erc20" })
// unsigned deploy prepare (stamped)
data.call("protocol-templates", "prepareDeploy", {
  templateId: "safe-erc20",
  chainId: 8453,
  args: [name, symbol, supply, initialHolder, initialOwner],
})
```

CLI: `npm run protocol:gate -- safe-erc20`

## Native protocol builders

```js
// Native catalog
data.call("protocol-templates", "listNative")

// Solana Anchor program scaffold. programId is caller-generated public identity;
// Oracle never accepts or emits its secret key.
data.call("protocol-templates", "buildNative", {
  templateId: "solana-safe-vault",
  projectName: "treasury_vault",
  network: "devnet",
  programId,
  authority,
  unlockDelaySlots: 1200,
})

// Bitcoin Taproot policy scaffold. Returns descriptor/address/scripts, not a PSBT.
data.call("protocol-templates", "buildNative", {
  templateId: "bitcoin-tapscript-vault",
  projectName: "cold_treasury",
  network: "signet",
  threshold: 2,
  signerPubkeys,
  recoveryPubkey,
  recoveryDelayBlocks: 144,
})
```

Both are `GUIDED_BUILD`, not `ADAPTER_READY`: the result is a hashed source/policy
bundle. Solana still requires `anchor build`, `anchor test`, and cluster simulation.
Bitcoin still requires descriptor compilation and spend-path tests on regtest or
signet before funding. Neither operation deploys, funds, signs, or broadcasts.

## Shipped template: `safe-erc20`

- Fixed supply, mint once in constructor (no hidden mint)
- Ownable2Step + pause
- No tax / blacklist / max-tx / upgrade proxy
- Foundry tests included

## Honesty

**Reviewed templates + automated tests ≠ a paid Solidity, Solana, or Bitcoin audit.**

Docs and prepare envelopes always set `firmAudit: false` and carry the disclaimer.
Mainnet TVL → independent firm audit.

## Required order (custom work)

1. Authority model  
2. Threat model  
3. Chain-native tests (Foundry, Anchor, or regtest/signet policy vectors)
4. Static analysis when available
5. Gate green
6. Prepare unsigned only
7. User signs + verify source

## Refusal line

Refuse hidden drains, honeypots, wash-trading systems, undisclosed tax switches, fake TVL, or any contract whose main purpose is deceiving buyers.
