INTENT
Transaction intent और calldata decode करें।
Security Core, SafeSign और transaction-security integrations के पीछे reusable analysis और policy layer है। यह request को decode करता है, intent को payload से मिलाता है, authority और uncertainty दिखाता है और execution को user के explicit control में छोड़ता है।

किसी detector को oracle नहीं माना जाता और missing evidence कभी silent allow नहीं बनना चाहिए।
Transaction intent और calldata decode करें।
Approvals, Permit और Permit2 scope दिखाएँ।
Destinations, chain context और contract relationships inspect करें।
Simulation को mutable execution assumptions से compare करें।
Deterministic policies और escalation rules लागू करें।
Final user decision के लिए readable evidence बनाएँ।
Engine interpretation को authorization से अलग रखता है और keys लेने या auto-broadcast किए बिना integrations की सहायता करता है।
Wallet request और उपलब्ध integration context प्राप्त करें।
Methods, parameters, typed data, approvals और supported PSBT को normalize करें।
Policy, simulation, destination और execution-context signals जोड़ें।
Material risk और uncertainty समझाएँ; authorization user या calling product के पास रहे।
Product contract सीमित है: analyze और explain. Signing authority Security Core के बाहर रहती है।
Requests, typed data, approvals, addresses, simulation outputs और integration से मिला policy context.
Seed phrases, private-key custody, auto-sign, auto-broadcast या unilateral transaction execution.
हर अपरिवर्तनीय अनुमति एक ही रास्ते से गुजरती है। UTXO Suite हर चरण को पढ़ने योग्य बनाता है — और उस एक चरण पर रुक जाता है जो उसका कभी नहीं होना चाहिए: हस्ताक्षर।
कोई wallet, dApp या agent हस्ताक्षर मांगता है। अभी किसी पर भरोसा नहीं किया जाता।
UTXO Suiteअनुरोध एक मानक रूप में डिकोड होता है: method, chain, origin, parameters।
UTXO Suiteअनुरोध वास्तव में क्या करता है, साफ शब्दों में: transfer, approval, delegation या permit।
UTXO Suiteप्रतिपक्ष, स्रोत और अपेक्षित परिणाम। Simulation प्रमाण है, oracle कभी नहीं।
UTXO Suiteभारित संकेत: असीमित अधिकार, अनजान code, अभी बने contracts, बेमेल गंतव्य।
UTXO Suiteआपके नियम उसी प्रमाण पर निर्धारित रूप से लागू: एक policy, अनुमान नहीं।
UTXO SuiteALLOW, WARN, REVIEW या BLOCK। BLOCK को कोई दूसरी परत कभी नरम नहीं करती।
UTXO Suiteआप स्पष्ट रूप से अनुमति देते हैं। ALLOW भी हस्ताक्षर नहीं है।
आपजो bytes अभी हस्ताक्षरित होंगे, उनकी तुलना ठीक उन्हीं bytes से होती है जो आपने देखे थे।
UTXO Suiteअलग-थलग signer wallet के भीतर है। UTXO Suite कभी key या seed नहीं रखता।
Vigi Walletवैकल्पिक। हस्ताक्षरित लेनदेन स्वतः प्रसारित लेनदेन नहीं होता।
Vigi Walletchain पर वास्तव में जो हुआ, उसे आपसे किए गए वादे से मिलाया जाता है।
UTXO Suiteकोई भी निर्णय हस्ताक्षर नहीं है। अनुमति हमेशा आपकी है।
अज्ञात कभी सुरक्षित नहीं बनता। जो प्रमाण नहीं है, वह नहीं है।
SafeSign human review surface है; Security Core उसके नीचे reusable engine है।
SafeSign देखें →Security Core को evidence graph model करना चाहिए: facts, provenance, freshness, policy matches, contradictions और unknowns; single opaque score नहीं।
हर primitive structured evidence + provenance दे ताकि policy UI strings नहीं, facts पर reason करे।
Chain-specific requests को stable internal representation में बदलें, payload mutate किए बिना।
बताएं signature अभी या बाद में क्या authorize कर सकती है: value, token spend, order, delegation या PSBT।
Origin, chain, contract relationships, freshness, simulation और intelligence को source provenance के साथ जोड़ें।
Unlimited approval, new destination, value threshold या chain mismatch जैसे deterministic conditions evaluate करें।
Facts, source, timestamps, contradictions और dependencies retain करें ताकि हर decision reconstruct हो सके।
Structured evidence को consequences में translate करें, uncertainty को score के पीछे छिपाए बिना।
Unknown evidence को स्पष्ट रूप से unknown रहना चाहिए। Missing analysis कभी चुपचाप ALLOW नहीं बनना चाहिए।
Confirmation से पहले exact request और origin लें।
Generic risk logic से पहले request family पहचानें।
Methods, parameters, authority और destinations normalize करें।
जहाँ उपलब्ध हो contract, policy, freshness और simulation context जोड़ें।
Reconstructed authority को user के stated intent से compare करें।
ALLOW, WARN, REVIEW या BLOCK स्पष्ट reasons और unknowns के साथ लौटाएं।
Control wallet या signer को लौटाएं। Analysis कभी silently sign या broadcast न करे।
Security Core को evidence graph model करना चाहिए: facts, provenance, freshness, policy matches, contradictions और unknowns; single opaque score नहीं।
{
"requestType": "eip712",
"origin": "https://app.example",
"chainId": 1,
"method": "eth_signTypedData_v4",
"intent": { "action": "swap", "asset": "USDC" },
"payload": "<original wallet payload>"
}{
"decision": "REVIEW",
"confidence": "partial",
"authority": [{ "type": "token_spend", "scope": "unlimited" }],
"evidence": [{ "signal": "new_spender", "severity": "high" }],
"unknowns": ["future_execution_state"],
"payloadIntegrity": "unchanged"
}Unknown evidence को स्पष्ट रूप से unknown रहना चाहिए। Missing analysis कभी चुपचाप ALLOW नहीं बनना चाहिए।
Unknown evidence को स्पष्ट रूप से unknown रहना चाहिए। Missing analysis कभी चुपचाप ALLOW नहीं बनना चाहिए।
Guess न करें। Request preserve करें, unsupported surface दिखाएं और review मांगें।
unsupported → REVIEWStatic/context evidence जारी रखें, लेकिन missing simulation स्पष्ट करें।
simulation: unavailable → confidence: partialIntent और decoded authority mismatch को first-class evidence मानें।
intent != authority → REVIEW/BLOCK policyTime-sensitive intelligence में freshness metadata जरूरी है ताकि पुराने observations current facts न लगें।
observedAt + ttl → freshnessहर material signal में provenance, freshness और deterministic fact, heuristic तथा external intelligence का स्पष्ट distinction होना चाहिए।