Principles
- Non-custodial. No contract holds funds between calls. Shares always land in the owner’s wallet.
- Approve contracts, not agents. You approve
PlanRegistryandLoanGuard, never the agent’s address. - The agent decides, the contracts bound. Off-chain logic chooses when; on-chain rules cap how much.
- Everything is recorded. Runs, reasons and rescues are on-chain and public.
Roles
Worst cases
The app asks for a limited allowance (12 runs’ worth), not an unlimited one, and offers a one-tap Revoke, which bounds the damage of a compromised owner per user. The mainnet owner must be a multisig.
Upgradeability
Both contracts are UUPS proxies (OpenZeppelin 5) with ERC-7201 namespaced storage,_disableInitializers() in the constructor and Ownable2Step admin. New fields are only appended; nothing is reordered. Every upgrade is verified on BscScan.
Agent-side protections (mainnet path)
- Agentic Wallet session and daily limit are checked before any money is pulled.
- A submitted swap is never refunded automatically; pending orders are reported, not retried.
- Exactly the shares a swap produced are delivered.
- Explicit slippage (default 1%); the executable price must also pass the Guard.
- A run with money still out blocks new buys for that plan until settled.
- Failed buys back off 30 minutes. Unfunded plans get no on-chain entries (no gas griefing).