dexterm

docs › Bring your own agent

Bring your own agent

Connect Claude Code, Codex or a custom bot to a running dexterm over MCP or the loopback agent bus, with server-side capability tiers and an untrusted-by-default security model.

Generated against dexterm/app at commit 8c2906f. dexterm is a terminal you can let your own agent drive — Claude Code, Codex, an OpenClaw-style agent or a custom bot — without ever handing it your keys. Every agent is untrusted by default: it authenticates as itself, runs at a capability tier you grant, and nothing it does can arm, sign, confirm, raise a cap, change the confirmation gate, or touch a wallet, a mandate or the signer.

Two ways to connect#

  • MCP (stdio). claude mcp add dexterm -- dexterm mcp gives any Claude Code the read-only tool surface plus the agent packs: the dexterm skills (trench-scan, rug-check, token-dossier) are offered as MCP prompts, and the knowledge base, case files and skills as MCP resources, so your agent gets the same playbooks the built-in analyst uses.
  • Loopback agent bus. A WebSocket + JSON-RPC 2.0 server bound to 127.0.0.1 for live work: subscribe to the data firehose (new pairs, trades, alerts, screen state), call read and navigation tools, and create proposals. Register an agent, then connect with the TS or Python SDK, or dexterm agent connect.
$ dexterm agent add scanbot --tier observe        # prints a one-time token (shown once)
$ export DEXTERM_AGENT_TOKEN=dxa_…                 # paste it into your agent's env, never a flag
$ dexterm agent serve --fixtures --roster         # run the bus on fixtures + the roster popup
$ dexterm agent connect --name scanbot --watch 30 # subscribe and watch the stream

Capability tiers (enforced server-side)#

The tier comes from your registry at connection time, never from anything the agent sends; a client may only ask to run below its grant.

tierwhat it can do
observeread tools (screener, token, dossier, holders, trades, candles, rugcheck, dev history, KB, cases, LARP checks) and live stream subscriptions
annotate+ non-financial UI navigation and the agent's own notes/tags on coins
propose+ proposals (alerts, order-plan drafts, watchlist adds) that appear labelled with the agent and that you confirm with a keypress

No tier can arm, sign, send, raise or change a cap, change the gate, or reach a wallet/mandate/signer: no such tool exists in the table, and a "never-list" refuses the shape of such a request before any lookup.

Untrusted by default#

Every agent is treated as potentially compromised or buggy:

  • Per-agent identity. A salted-hashed bearer token (shown once, stored only as a hash, constant-time verified); rotate or remove it to revoke instantly. One agent can never wear another's name.
  • The gate. One function every call passes on every transport: session open, name not on the never-list, tier sufficient, arguments valid against a closed schema and within a size cap, rate limits and quotas with room, and an idempotency key on every proposal.
  • Rate, quota and flood control. Reads/min, navigation/10s and proposals/hour are per agent; sustained refusals trip a breaker that auto-pauses the agent.
  • Prompt firewall. Every untrusted string an agent receives (token names, bios, tweets, fetched page text) is wrapped and sanitised; terminal-escape, bidi-override and zero-width characters are stripped from every result, event and audit line.
  • Proposals, never actions. An order-plan proposal is a draft with armed: false, full stop; only your physical keypress arms it, and the signer-side caps still apply.
  • Roster + audit. The roster popup lists every connected agent (name, tier, last activity, reads/proposals, rate usage) with per-agent pause and kick, and the full audit log records every connect, call, refusal, proposal and disconnect.

Red-team coverage#

The security model is proven by a malicious-agent suite that drives the real bus with 41 escalation, exfiltration, financial, spoof, flood, replay, quota and UI-injection attempts — every one refused (or neutralised) and recorded in the audit log. A capture-ready worked demo runs Claude Code over MCP on the trench-scan skill, a custom stream-subscribing agent proposing an alert, and the malicious agent failing every escalation, all on fixtures.

Fixtures only in the demo and tests: no wallets, no mainnet, no network for the bus path.