A pre-execution firewall that turns Web3 social context and user mandates into policy before AI agents spend, sign, approve, call paid tools, or loop.
SafeIntent LoopGuard is a pre-execution risk firewall for AI agents and agentic wallets.
Web3 risk often starts before a wallet popup. Users hear urgent claims in X Spaces, Discord AMAs, Telegram voice notes, community chats, DMs, or fake support calls. An AI agent may turn that social pressure into paid MCP calls, x402-style payments, signatures, token approvals, delegation, or repeated tool loops.
SafeIntent receives three inputs: social context, the user's natural-language safety mandate, and the agent's planned actions. It detects persuasion and missing-proof signals, compiles user rules into machine-readable policy, checks wallet, payment, and tool conflicts, and returns an explainable ALLOW, WARN, ASK_MORE, or BLOCK decision.
The MVP includes four modules:
1. Social Context - detects urgency, persuasion, missing proof, and requested wallet actions.
2. Mandate Compiler - converts spoken or written user constraints into execution policy.
3. Loop Guard - catches paid MCP loops, tool poisoning, and read-only tasks drifting into signing or approval.
4. Intent Receipt - returns the decision, exact conflicts, risk score, and a safer rewrite.
SafeIntent does not execute transactions, request private keys or seed phrases, provide financial advice, or claim that a project is guaranteed safe. It operates as a deterministic, callable guard layer that other agents can invoke before execution.
<p>During this hackathon, SafeIntent LoopGuard progressed from product research and architecture design to a complete, deployed MVP.</p><p>Completed work:</p><p>- Defined the product as an <a href="http://OKX.AI">OKX.AI</a> ASP / A2MCP-shaped pre-execution guard.</p><p>- Built a shared deterministic TypeScript policy engine.</p><p>- Implemented social-risk detection, mandate compilation, paid-loop detection, wallet-action checks, tool-output injection checks, risk scoring, safe rewrite generation, and Intent-to-Action Receipts.</p><p>- Added three verified demo scenarios: fake urgent airdrop (BLOCK 100), paid MCP loop (ASK_MORE 34), and tool-poisoning drift (BLOCK 98).</p><p>- Exposed ASP-shaped JSON endpoints for health, scenarios, manifest, social-risk intake, mandate compilation, guard checks, and receipts.</p><p>- Built and refined a responsive React/Vite frontend with four interactive modules, generated hero media, a guard-action typewriter effect, modal detail views, and mobile and short-screen support.</p><p>- Deployed the current build to Cloudflare Pages.</p><p>- Completed desktop and mobile production QA, API smoke tests, sensitive-information scans, and deterministic engine tests.</p><p>- Re-recorded a 59-second demo from the current build with English narration, burned-in subtitles, and all four modules.</p><p>Current MVP:</p><p><a href="https://safeintent-loopguard.pages.dev/">https://safeintent-loopguard.pages.dev/</a></p><p></p>
<p>Bootstrapped / No external funding.</p><p>SafeIntent LoopGuard is currently an independently developed hackathon MVP. It has not raised external capital, issued a token, or accepted institutional investment. The next step is to validate agent integrations and a pay-per-guard-check or pay-per-full-receipt business model.</p>