gblin-treasury-risk-regime
GBLIN on Base for AI agents: risk regime, treasury plan for idle USDC, mint and redeem at NAV. Free.
- 0.6.4
- Version
- remote + npm
- Transport
- 24
- Tools
Security review
Review passedReviewed 1d ago.
- tools: 24 tools scanned
- metadata: scanned
- packages: 1 checked
No findings.
Tools (24)
risk.regime
Current BTC/ETH risk regime (calm | elevated | crash) and the matching risk posture, read live from GBLIN's on-chain Crash Shield on Base (60-second cache). Free and unsigned; a signed version that verifies offline is a separate paid x402 HTTP endpoint.
risk.attestation_sample
Static, permanently expired sample of the signed Risk Attestation (sample: true), with the same fields and EIP-712 schema as the signed one, for building and testing parsers and verifiers.
protocol.stats
Cumulative public counters of GBLIN's x402 endpoints: paid calls, unique payer wallets, USDC earned, with methodology disclosure. Cached 5 min.
protocol.info
GBLIN llms.txt as plain text: contract addresses, endpoints, prices, payment flow, field contract of the attestation.
receipts.seal
Appends the hashes of an AI action to GBLIN's public RFC 6962 transparency log and returns a portable receipt: Ed25519 signature, inclusion proof, operator-signed C2SP checkpoint, and the latest on-chain anchor (EAS on Base, daily). Demo mode only over MCP: 5 seals per day per IP, receipts marked demo: true; unlimited sealing is a separate paid x402 HTTP endpoint. Provenance is self-reported: a receipt proves that the record existed at that time, not that the action happened. The action, agent_id, tool and meta strings are published in the log exactly as given. Fields not listed in the schema are ignored and not recorded.
receipts.get
Receipt #index from GBLIN's receipts log, re-signed (Ed25519 is deterministic) with a fresh inclusion proof, the current signed checkpoint and the latest on-chain anchor. Free.
receipts.verify
Verifies a gblin-receipt/v1 JSON with pure math, without a log lookup and without trusting this server: leaf hash, Ed25519 signature, RFC 6962 inclusion proof, C2SP checkpoint signature and verifier-key hash. These are the same checks as the zero-dependency verify-receipt.mjs script that runs offline; the consistency check against the on-chain anchor is available separately at GET /v1/verify/:index.
coherence.report
Kept/violated tallies for GBLIN's pre-registered, hash-pinned promises (attestation uptime, counter honesty), probed every 10 minutes; each closed UTC day is sealed on Base as an EAS attestation (schema 0x9f433a96…). Self-observation only in v0. Free.
treasury.state
Reads the current GBLIN protocol state on Base mainnet: NAV in USD, basket composition with dynamic weights, Crash Shield status and whether the NAV is reliable.
treasury.quote
Preview a buy (ETH→GBLIN) or sell (GBLIN→ETH) without executing. Returns expected output, safe minOut with dynamic slippage buffer (2.5% normal / 4% during Crash Shield), and fee breakdown. Read-only.
treasury.health
Analyzes an agent wallet's treasury: GBLIN, USDC and ETH balances, whether the ETH covers an exit at the live gas price, and the redemption cooldown. When daily_burn_usd is given it adds days of USDC runway and a split that keeps seven days of spend in USDC and treats only the surplus as a candidate for GBLIN. Free by default; a 0.003 USDC charge applies only when the server operator sets MCP_PAYWALL=true.
treasury.plan
Turns idle USDC into a reviewable plan in one call: operating cash = max(reserve_usd, daily_burn_usd x days), the surplus above it, a simulation of minting that surplus into GBLIN at NAV (fees read live from the vault, estimated exit value today, round-trip cost), the same simulation for a trial amount (100 USDC by default), and the blockers (Crash Shield, redemption cooldown, ETH for the exit). Read-only: nothing is executed and nothing is advised. GBLIN is crypto exposure (cbBTC, WETH, USDC), not cash and not yield.
treasury.nav_history
NAV per GBLIN share over time, read from the chain at past blocks, beside the ETH/USD and BTC/USD oracle prices the vault itself uses, with the change of each over the window and the NAV's largest drawdown. The series starts at the deployment of the vault in service and can be compared with holding ETH or BTC over the same span.
actions.prepare
Builds the unsigned transactions for an operation on the GBLIN vault, in the order they are sent. Actions: mint_with_eth (amount in ETH), mint_with_weth (amount in WETH), mint_with_usdc (amount in USDC, through the Zap), redeem_in_kind (amount in shares; pro rata basket tokens, no fee, no price feed), exit_to_eth (amount in shares, through the Zap, all or nothing), exit_to_usdc (amount = the USDC needed), bid (trade with the rebalancing auction; row optional, the largest gap by default). Every output bound is non-zero and every step through the vault or the Zap carries its gas limit. Nothing is signed or sent: the steps are returned to the caller.
actions.preview
Simulates a list of transactions in sequence against the latest Base block, as if the wallet sent them one after the other, before anything is signed. Each step sees the state the previous ones left (an approval before a mint works). Accepts steps with target or to, calldata or data, and optional value and gas. Returns, per step, whether it would succeed, the gas it uses, whether the gas limit it carries is enough, and the decoded revert reason when it fails; and the net token and ETH movements for the wallet. State can change before transactions land: a successful preview is evidence, not a guarantee.
actions.status
Reports what a sent Base transaction did: pending, succeeded, reverted or not found; its block and confirmations; the fee paid; the net token movements for the sender (GBLIN shares minted or redeemed, USDC, basket tokens); and, when it reverted, the decoded reason.
governance.state
Reads GBLIN protocol governance: whether the GBLIN vault is owned by the 48-hour timelock, the timelock's minimum delay and grace period, role member counts, and any pending asset-addition proposal on the vault. With an operation_id it also reports the status of that timelock operation. Read-only.
auction.state
Read the GBLIN rebalancing auction on Base. The vault does not rebalance itself and pays nobody to do it: when a basket row drifts past its band it holds a Dutch auction, and whoever trades with it toward the target weights is the counterparty, at the oracle price adjusted by a premium that starts at a discount and rises to a cap over one ramp. Returns, per row, the side the vault takes, the gap in ETH, the token and amount the bidder hands over, and unsigned calldata (approval + bid). The premium is the whole reward; nothing is paid out of the vault.
payments.prepare
Builds a gasless GBLIN payment. The vault's share token implements EIP-3009, so the holder signs an authorization and anybody can carry it on chain: the payer needs no ETH. Returns the EIP-712 message to sign (its domain is read from the token, not assumed), the calldata that carries the signed authorization, and the x402 'exact' payload for paying an HTTP endpoint in GBLIN. Method 'receive' lets only the named recipient submit the authorization, so nobody can front-run the transfer; method 'transfer' suits an x402 facilitator, which submits on the seller's behalf. With relay: true it also returns a second authorization that pays a relayer's fee in GBLIN. No private key is requested, held or transmitted: the signature is produced by the caller's own wallet.
payments.verify
Checks a signed GBLIN authorization against the chain before any gas is spent on it. Recovers the signer from the EIP-712 digest (and asks the wallet itself through ERC-1271 when the payer is a contract), then checks the validity window against on-chain time, whether the nonce has already been used or cancelled, and whether the payer still holds the amount. Returns a verdict and the ready calldata when it would settle, the failing reason when it would not. These are the checks an x402 facilitator runs, so a 'would_settle' verdict means the payment can be carried.
payments.relay
GBLIN's relay carries a signed GBLIN payment on chain for a payer that holds no ETH. Takes the payment and the relay fee, each as { authorization, signature }, both signed by the payer's wallet. The relay checks both against the chain, simulates them and submits them in one transaction through Multicall3: either both settle or neither does. The fee is paid in GBLIN at the live NAV. Returns the transaction hash and its outcome. This tool moves funds: it carries the authorizations exactly as signed.
attestation.verify
Verifies a GBLIN Risk Attestation, the object returned by GBLIN's /api/x402/attestation, or a proof-of-diligence attached by a peer agent. Free. Runs four checks: (1) integrity, by recomputing the EIP-712 attestation_id; (2) authenticity, by recovering the signer when a signature is present and comparing it with GBLIN's published attestor; (3) freshness, against on-chain time (10-minute validity); (4) live drift, by comparing the attested regime with the current on-chain regime.
search
Searches GBLIN's documentation and live state and returns matching documents: the agent API summary, the protocol's README and documents (governance, deployments, review record), the MCP server and library READMEs, the public pages, one card per MCP tool, and a snapshot of the live vault state. Returns {results: [{id, title, url}]}, where each id identifies a full document. Read-only and free.
fetch
Returns the full text of one GBLIN document by its id: {id, title, text, url, metadata}. Documents are the protocol's public documentation, the tool cards and the live vault state. Read-only and free.