Vercel AI SDK
Safety checks for AI SDK agents that pay
presign-guard-ai-sdk gives an AI SDK agent four tools to call before it signs or pays. The tools only check: they never sign, pay or move anything themselves. They work with AI SDK 5, 6 and 7.
Install
npm install presign-guard-ai-sdk ai zod
Try it without a wallet
With no payment set up, the token, signing and endpoint checks answer with the free quick check: the verdict only, a few per hour, marked free: true.
import { generateText, isStepCount } from 'ai';
import { fizzlTools } from 'presign-guard-ai-sdk';
const { text } = await generateText({
model: 'anthropic/claude-sonnet-5.5',
tools: fizzlTools(),
prompt:
'Is USDC (0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913) on Base safe to buy, ' +
'and is https://ichimoku-signal.fizzl.eu/signal/BTC-USDT safe to pay?',
stopWhen: isStepCount(5),
});
console.log(text);
The tools
| Tool | What it checks | Full check | Free quick check |
|---|---|---|---|
check_before_signing | A transaction, token approval or signature (permit, Permit2) before signing: drainers, unlimited approvals, look-alike dapps. Green / orange / red with reasons. | $0.01 | verdict only |
check_token | A token before buying, holding or accepting it: honeypots, rug-pull signs, look-alikes. Solana and EVM chains. | $0.01 | verdict and grade |
check_wallet_approvals | Every open token approval of an EVM wallet, and which ones to revoke. | $0.02 | none |
check_endpoint_before_paying | An x402 or MPP paid API before paying it: go / caution / no_go, the cheapest option that settles, budget, track record, bait signs. | $0.001 | go / caution / no_go with the problems found |
Pick some with fizzlTools({ only: ['check_endpoint_before_paying'] }). A failed check comes back as { error, message }, so the model can tell its user; it is never thrown.
The full checks: pay per call over x402
Give the tools an x402-paying fetch. The agent pays each check in USDC on Base from its own wallet.
import { generateText, isStepCount } from 'ai';
import { wrapFetchWithPayment, x402Client } from '@x402/fetch';
import { ExactEvmScheme } from '@x402/evm/exact/client';
import { privateKeyToAccount } from 'viem/accounts';
import { fizzlTools } from 'presign-guard-ai-sdk';
// A check never costs more than $0.02: cap every payment.
const payer = new x402Client().setSpendControls({ maxAmountPerPayment: '$0.02' });
payer.register('eip155:8453', new ExactEvmScheme(privateKeyToAccount(process.env.AGENT_KEY)));
const { text } = await generateText({
model: 'anthropic/claude-sonnet-5.5',
tools: { ...fizzlTools({ fetch: wrapFetchWithPayment(fetch, payer) }), ...yourOtherTools },
system:
'Before you pay any API, call check_endpoint_before_paying. Before you sign anything, ' +
'call check_before_signing. Never continue on red or no_go.',
prompt: 'Buy the BTC funding rate from https://api.example.com/funding for at most $0.05',
stopWhen: isStepCount(8),
});
Or prepaid credits
Buy a pack once (presign-guard: 100 checks for $0.80; x402 Doctor: 1000 preflights for $0.80), then pass the keys:
fizzlTools({ creditKeys: { presign: process.env.PRESIGN_CREDIT_KEY, doctor: process.env.DOCTOR_CREDIT_KEY } });
Options
| Option | Default | |
|---|---|---|
fetch | global fetch | An x402-paying fetch, or plain fetch with credit keys |
creditKeys | none | { presign, doctor }, sent as x-credit-key |
only | all four | Tool names to include |
free | true | Fall back to the free quick check when a check can't be paid |
timeoutMs | 30000 | Per check |
More
- npm: presign-guard-ai-sdk ยท source on GitHub
- Python and LangChain: pip install fizzl
- Want the wallet to stop the agent itself, not just tell the model? The Fizzl agent wallet