AI agent for blockchain developers
Oracle Dependency Risk Agent
Know what each external dependency can do to the contract and add safeguards that are tested
What it does
A lending contract trusts a price feed. If the feed goes stale or a thin pool is manipulated, the contract can lose funds. This agent lists every external dependency in the contract: price oracles, other contracts, bridges and admin keys. For each it checks how often it updates, how far it can deviate, how much liquidity stands behind it and who can change it. It then simulates failures on a fork: a stale price, a price jump of 30%, a manipulated pool, and a paused dependency. It measures the effect on the contract, such as bad debt or locked funds, and proposes safeguards: staleness checks, bounds, a second source or a pause. It retests each safeguard. The developer approves changes. Edge case: a safeguard blocks normal use during a volatile day, so the agent tunes the bound.
How it works
Follow the arrows from top to bottom. The orange dashed arrow is the loop: when a check fails, the agent goes back and tries again.
Read the steps as a list
- Release planned or dependency change
- List external calls, oracles, bridges and admin controls
- Check update rate, deviation limits, liquidity and control of each
- Simulate stale, jumped, manipulated and paused cases on a fork
- Measure the loss or lockup in each case
- Propose safeguards for the worst cases
- Developer approves which safeguards to buildThe agent waits here for your OK.
- Add the safeguards in a branch and rerun the simulations
- Do the safeguards stop the losses in all cases?If not: strengthen or combine safeguards and test again. Back to step 5.
- Does normal use still work on a volatile-day replay?If not: loosen the bound or add a grace period and retest. Back to step 5.
- Dependency risk report and tested safeguards
How it decides
It ranks dependencies by the loss they could cause and proposes the lightest safeguard that holds in the simulations without blocking normal use.
- Require a staleness check for any price older than the feed's stated heartbeat
- Test a 30% price jump and a 1-hour stale price on every oracle
- Treat a dependency with admin control by one key as high risk
- Prefer a second price source over wider bounds
Make it yours
Every agent is a starting point. You choose these settings for your own situation.
- Failure cases to simulate
- Staleness limits per feed
- Price jump size (default 30%)
- Network and fork block
- Risk ranking rules
What keeps you in control
It always asks you first
- Developer approves safeguards
- Security lead approves changes to admin controls
Hard limits
- Simulate only on forks, never on live networks
- Never send transactions with real funds
It stops when
- Done: all high-risk dependencies have tested safeguards
- Stop: a dependency cannot be made safe and should be replaced
Set it up
We guide you through the set-up, step by step
Members get the full set-up guide for this agent. No technical skills needed: you copy, paste and upload.
- One set of instructions to paste into your AI, with the clicks for ChatGPT, Claude, Microsoft 365 Copilot, Gemini and Grok
- The agent then walks you through connecting your own data, one source at a time
- A downloadable copy with the flow chart, the rules and the full guide