docs › Bring your own agent
Bring your own agent
Connect Claude Code, Codex or a custom bot to a running dexterm over MCP or the loopback agent bus, with server-side capability tiers and an untrusted-by-default security model.
Generated against dexterm/app at commit 8c2906f. dexterm is a terminal you can let your own agent drive — Claude Code, Codex, an OpenClaw-style agent or a custom bot — without ever handing it your keys. Every agent is untrusted by default: it authenticates as itself, runs at a capability tier you grant, and nothing it does can arm, sign, confirm, raise a cap, change the confirmation gate, or touch a wallet, a mandate or the signer.
Two ways to connect#
- MCP (stdio).
claude mcp add dexterm -- dexterm mcpgives any Claude Code the read-only tool surface plus the agent packs: the dexterm skills (trench-scan,rug-check,token-dossier) are offered as MCP prompts, and the knowledge base, case files and skills as MCP resources, so your agent gets the same playbooks the built-in analyst uses. - Loopback agent bus. A WebSocket + JSON-RPC 2.0 server bound to
127.0.0.1for live work: subscribe to the data firehose (new pairs, trades, alerts, screen state), call read and navigation tools, and create proposals. Register an agent, then connect with the TS or Python SDK, ordexterm agent connect.
$ dexterm agent add scanbot --tier observe # prints a one-time token (shown once)
$ export DEXTERM_AGENT_TOKEN=dxa_… # paste it into your agent's env, never a flag
$ dexterm agent serve --fixtures --roster # run the bus on fixtures + the roster popup
$ dexterm agent connect --name scanbot --watch 30 # subscribe and watch the streamCapability tiers (enforced server-side)#
The tier comes from your registry at connection time, never from anything the agent sends; a client may only ask to run below its grant.
| tier | what it can do |
|---|---|
observe | read tools (screener, token, dossier, holders, trades, candles, rugcheck, dev history, KB, cases, LARP checks) and live stream subscriptions |
annotate | + non-financial UI navigation and the agent's own notes/tags on coins |
propose | + proposals (alerts, order-plan drafts, watchlist adds) that appear labelled with the agent and that you confirm with a keypress |
No tier can arm, sign, send, raise or change a cap, change the gate, or reach a wallet/mandate/signer: no such tool exists in the table, and a "never-list" refuses the shape of such a request before any lookup.
Untrusted by default#
Every agent is treated as potentially compromised or buggy:
- Per-agent identity. A salted-hashed bearer token (shown once, stored only as a hash, constant-time verified); rotate or remove it to revoke instantly. One agent can never wear another's name.
- The gate. One function every call passes on every transport: session open, name not on the never-list, tier sufficient, arguments valid against a closed schema and within a size cap, rate limits and quotas with room, and an idempotency key on every proposal.
- Rate, quota and flood control. Reads/min, navigation/10s and proposals/hour are per agent; sustained refusals trip a breaker that auto-pauses the agent.
- Prompt firewall. Every untrusted string an agent receives (token names, bios, tweets, fetched page text) is wrapped and sanitised; terminal-escape, bidi-override and zero-width characters are stripped from every result, event and audit line.
- Proposals, never actions. An order-plan proposal is a draft with
armed: false, full stop; only your physical keypress arms it, and the signer-side caps still apply. - Roster + audit. The roster popup lists every connected agent (name, tier, last activity, reads/proposals, rate usage) with per-agent pause and kick, and the full audit log records every connect, call, refusal, proposal and disconnect.
Red-team coverage#
The security model is proven by a malicious-agent suite that drives the real bus with 41 escalation, exfiltration, financial, spoof, flood, replay, quota and UI-injection attempts — every one refused (or neutralised) and recorded in the audit log. A capture-ready worked demo runs Claude Code over MCP on the trench-scan skill, a custom stream-subscribing agent proposing an alert, and the malicious agent failing every escalation, all on fixtures.
Fixtures only in the demo and tests: no wallets, no mainnet, no network for the bus path.