yellowgram

Open source

Tools

Paid

  • Current · Open source

    SurfacePin

    Pin the surface. Catch the silent drift.

    An exact hash of an MCP server’s tools, resources, and prompts. When the surface changes and the pin does not, CI fails.

  • Current · Open source

    Keel

    Observe first. Idle is success.

    Self-run Morpho Regime B observe, score, and REFERENCE_ONLY draft for wstETH–WETH. DEMO defaults; you sign; idle with zero eligible is success.

  • Current · Open source

    L2 Send Guard

    Abort the bad send. Before it broadcasts.

    A multi-L2 JSON-RPC proxy that simulates eth_sendRawTransaction, aborts definite reverts, and optionally fences agent spend with a thin allowlist and caps. No key custody.

  • Current · Open source

    send-approve-bound

    Bound the approve. Before it sends.

    Non-custodial at-send gate for ERC-20/721/1155 approval calldata — per-token spender allowlist + caps; unlimited always denied. Compose after send-allow. No keys/sim.

  • Current · Open source

    send-allow

    Allow the destination. Cap the native.

    Non-custodial JSON-RPC middleware: address allowlist and optional native spend caps in front of eth_sendRawTransaction. No simulation. Complementary to L2 Send Guard.

  • Current · Open source

    send-idempotency

    Remember the key. Refuse the conflict.

    Non-custodial at-send idempotency: a client key remembers the payload hash or a prior deny; a different payload conflicts; a down store fails closed. Not a nonce lease.

  • Current · Open source

    recv-sweep-brake

    Brake the sweep. Until it is clear.

    No-auto-sweep fence: sweep_policy.enabled defaults off; quarantine is clear, quarantine, or toxic; a send of non-clear is denied sweep_braked. No keys, signing, or auto-move.

  • Current · Open source

    send-permit2-bound

    Pin Permit2. Bound the calldata.

    Non-custodial at-send gate: pin Permit2 by chain and bound approve, permit, and permitTransferFrom calldata. No phishing UX. Compose after send-approve-bound. No keys. No simulation.

  • Current · Open source

    recv-approval-watch

    Watch the approval. Fail closed.

    Receive-side watch for Approval and ApprovalForAll where the agent is owner or spender. Emits unexpected_approval. clearanceFromWatch fails closed. Revoke-intent never signs.

SurfacePin

A pin, a check, a failed build.

An exact hash of an MCP server’s tools, resources, and prompts. When the surface changes and the pin does not, CI fails.

01

Pin

Record an exact hash of the MCP tools, resources, and prompts.

02

Check

Compare the live surface with the pin.

03

Fail

An unexpected change fails CI until the pin is updated.

Install

npx surfacepin@1.5.0

yellowgram/surfacepin

Keel

Observe, score, draft.

Self-run Morpho Regime B observe, score, and REFERENCE_ONLY draft for wstETH–WETH. DEMO defaults; you sign; idle with zero eligible is success.

01

Observe

Read public wstETH–WETH markets on Morpho V1, Regime B.

02

Score

Score those markets against the sleeve rules.

03

Draft

Write a REFERENCE_ONLY action for you to sign. Idle when none qualify.

Install

git clone https://github.com/yellowgram/keel-morpho && cd keel-morpho && cp config.example.json config.json

yellowgram/keel-morpho

L2 Send Guard

Proxy, simulate, halt.

A multi-L2 JSON-RPC proxy that simulates eth_sendRawTransaction, aborts definite reverts, and optionally fences agent spend with a thin allowlist and caps. No key custody.

01

Proxy

Point the wallet HTTP transport at the local Guard.

02

Simulate

Definite reverts abort before broadcast; policy can stop the rest.

03

Halt

Agents treat policy deny as non-retryable and do not rebroadcast the same raw.

Install

npx l2-send-guard@0.5.0

yellowgram/l2-safety-proxy

send-approve-bound

Bound, cap, deny.

Non-custodial at-send gate for ERC-20/721/1155 approval calldata — per-token spender allowlist + caps; unlimited always denied. Compose after send-allow. No keys/sim.

01

Bound

Allow only listed spenders on that token.

02

Cap

Hold ERC-20 approve and increaseAllowance to the raw cap.

03

Deny

Refuse unlimited approvals before the send.

Install

npx send-approve-bound@0.1.0

yellowgram/send-approve-bound

send-allow

Allow, cap, deny.

Non-custodial JSON-RPC middleware: address allowlist and optional native spend caps in front of eth_sendRawTransaction. No simulation. Complementary to L2 Send Guard.

01

Allow

Forward only when the destination is allowlisted.

02

Cap

Hold native value to the per-address and global caps.

03

Deny

Refuse a definite policy miss before broadcast.

Install

npx send-allow@0.1.0

yellowgram/send-allow

send-idempotency

Remember, conflict, halt.

Non-custodial at-send idempotency: a client key remembers the payload hash or a prior deny; a different payload conflicts; a down store fails closed. Not a nonce lease.

01

Remember

Store the client key against the hash of the signed raw bytes.

02

Conflict

Refuse the same key when the payload differs.

03

Halt

Fail closed when the store is down.

Install

npx send-idempotency@0.1.0

yellowgram/send-idempotency

recv-sweep-brake

Classify, hold, deny.

No-auto-sweep fence: sweep_policy.enabled defaults off; quarantine is clear, quarantine, or toxic; a send of non-clear is denied sweep_braked. No keys, signing, or auto-move.

01

Classify

Label inbound clear, quarantine, or toxic.

02

Hold

Leave the brake on until an asset is explicitly clear.

03

Deny

Refuse a send of non-clear funds. No auto-move.

Install

npx recv-sweep-brake@0.1.0

yellowgram/recv-sweep-brake

send-permit2-bound

Pin, bound, deny.

Non-custodial at-send gate: pin Permit2 by chain and bound approve, permit, and permitTransferFrom calldata. No phishing UX. Compose after send-approve-bound. No keys. No simulation.

01

Pin

Accept Permit2 only at the address pinned for that chain.

02

Bound

Hold amount, expiration, and spender to the policy.

03

Deny

Refuse an unpinned or over-cap call before the send.

Install

npx send-permit2-bound@0.1.0

yellowgram/send-permit2-bound

recv-approval-watch

Watch, emit, hold.

Receive-side watch for Approval and ApprovalForAll where the agent is owner or spender. Emits unexpected_approval. clearanceFromWatch fails closed. Revoke-intent never signs.

01

Watch

Read Approval and ApprovalForAll where the agent is owner or spender.

02

Emit

Flag an unexpected grant. Unlimited stays unexpected unless opted in.

03

Hold

Fail clearance closed while the watch is unhealthy. Never sign a revoke.

Install

npx recv-approval-watch@0.1.0

yellowgram/recv-approval-watch

Contact

Ask about a tool

SurfacePin, Keel, L2 Send Guard, send-approve-bound, send-allow, send-idempotency, recv-sweep-brake, send-permit2-bound, or recv-approval-watch. Email hello@yellowgram.dev or use the form.

In development