[{"slug":"ZV-2026-0298","server_name":"mcp.crank.ing","severity":"breaking","title":"mcp.crank.ing: Tool assign_ticket was removed.","summary":"[breaking] Tool assign_ticket was removed. [breaking] Tool crank_dependency_status was removed. [breaking] Tool crank_prompt_health was removed. [breaking] Tool get_support_dashboard was removed. [breaking] Tool get_support_ticket was removed. [breaking] Tool go_live_status was removed. [breaking] Tool list_support_tickets was removed. [breaking] Tool list_turnkey_drift_backlog was removed. [breaking] Tool note_create was removed. [breaking] Tool reconcile_turnkey_policy was removed. [breaking] Tool reply_to_ticket was removed. [breaking] Tool set_integrator_share was removed. [breaking] Tool set_ticket_priority was removed. [breaking] Tool update_ticket_status was removed. [safe] Description of approve_proposal changed (4% word delta). [safe] Description of authorize_session_signer changed (2% word delta). [safe] Description of bulk_send_social changed (3% word delta). [safe] Description of cancel_perp_order changed (12% word delta). [safe] Description of check_claim_status changed (4% word delta). [safe] Description of clear_agnta_grant changed (4% word delta). [safe] Description of clone_strategy changed (6% word delta). [safe] Description of close_perp_position changed (9% word delta). [safe] Description of create_execution_intent changed (5% word delta). [safe] Description of declare_jurisdiction changed (4% word delta). [safe] Description of discover_strategies changed (6% word delta). [safe] Description of equity_quote changed (11% word delta). [safe] Description of flash_loan changed (3% word delta). [safe] Description of fund_wallet changed (3% word delta). [safe] Description of get_crank_score changed (3% word delta). [safe] Description of get_ilo_adoption_status changed (11% word delta). [safe] Description of get_leaderboard changed (5% word delta). [safe] Description of get_ooda_status changed (6% word delta). [safe] Description of get_quests changed (4% word delta). [safe] Description of get_quotes changed (9% word delta). [safe] Description of get_scor","changes":[{"kind":"tool_removed","tool":"assign_ticket","detail":"Tool `assign_ticket` was removed.","severity":"breaking"},{"kind":"tool_removed","tool":"crank_dependency_status","detail":"Tool `crank_dependency_status` was removed.","severity":"breaking"},{"kind":"tool_removed","tool":"crank_prompt_health","detail":"Tool `crank_prompt_health` was removed.","severity":"breaking"},{"kind":"tool_removed","tool":"get_support_dashboard","detail":"Tool `get_support_dashboard` was removed.","severity":"breaking"},{"kind":"tool_removed","tool":"get_support_ticket","detail":"Tool `get_support_ticket` was removed.","severity":"breaking"},{"kind":"tool_removed","tool":"go_live_status","detail":"Tool `go_live_status` was removed.","severity":"breaking"},{"kind":"tool_removed","tool":"list_support_tickets","detail":"Tool `list_support_tickets` was removed.","severity":"breaking"},{"kind":"tool_removed","tool":"list_turnkey_drift_backlog","detail":"Tool `list_turnkey_drift_backlog` was removed.","severity":"breaking"},{"kind":"tool_removed","tool":"note_create","detail":"Tool `note_create` was removed.","severity":"breaking"},{"kind":"tool_removed","tool":"reconcile_turnkey_policy","detail":"Tool `reconcile_turnkey_policy` was removed.","severity":"breaking"},{"kind":"tool_removed","tool":"reply_to_ticket","detail":"Tool `reply_to_ticket` was removed.","severity":"breaking"},{"kind":"tool_removed","tool":"set_integrator_share","detail":"Tool `set_integrator_share` was removed.","severity":"breaking"},{"kind":"tool_removed","tool":"set_ticket_priority","detail":"Tool `set_ticket_priority` was removed.","severity":"breaking"},{"kind":"tool_removed","tool":"update_ticket_status","detail":"Tool `update_ticket_status` was removed.","severity":"breaking"},{"kind":"description_changed","tool":"approve_proposal","after":"Approve a pending PROPOSAL within its TTL, then re-dispatch it\n(non-custodial control plane).\n\nFlips a propose-mode proposal (see set_permission_mode) from pending to\napproved, then immediately re-invokes the original deferred tool call\n(stored ``tool_name`` + ``params``) through this same dispatch table. On\nredispatch failure the proposal stays APPROVED (not silently EXECUTED or\nPENDING) -- call this again to retry. See ``wallets.approve_proposal``.","before":"Approve a pending PROPOSAL within its TTL, then re-dispatch it\n(non-custodial control plane, ENG-63e1517a).\n\nFlips a propose-mode proposal (see set_permission_mode) from pending to\napproved, then immediately re-invokes the original deferred tool call\n(stored ``tool_name`` + ``params``) through this same dispatch table. On\nredispatch failure the proposal stays APPROVED (not silently EXECUTED or\nPENDING) -- call this again to retry. See ``wallets.approve_proposal``.","detail":"Description of `approve_proposal` changed (4% word delta).","severity":"safe","descriptionDelta":0.039215686274509776},{"kind":"description_changed","tool":"authorize_session_signer","after":"Authorize a delegated session signer for an agent wallet (non-custodial).\n\nsigner_pubkey is a keypair the USER creates and holds -- ONLY its PUBLIC\nkey ever crosses this call (hard rule 1). Once authorized, calls that\ncarry this signer_pubkey are trade-only: the gate rejects any transfer/\nwithdraw/close-account/authority-change instruction targeting a\ndestination outside the wallet's own accounts (docs/\nSESSION_SIGNER_DESIGN.md). capabilities: subset of swap|perp|lend|stake,\nempty/omitted = full default set. expires_at: optional ISO 8601 hard\nexpiry. Effective on the very next call using this signer_pubkey.\nOn a Lane 2 wallet this raises BROWSER_CONFIRMATION_REQUIRED -- call\nrequest_session_signer_authorization instead: minting a\nsigner is a trust grant and must be owner-approved in the browser, never\nin-chat.","before":"Authorize a delegated session signer for an agent wallet (non-custodial).\n\nsigner_pubkey is a keypair the USER creates and holds -- ONLY its PUBLIC\nkey ever crosses this call (hard rule 1). Once authorized, calls that\ncarry this signer_pubkey are trade-only: the gate rejects any transfer/\nwithdraw/close-account/authority-change instruction targeting a\ndestination outside the wallet's own accounts (docs/\nSESSION_SIGNER_DESIGN.md). capabilities: subset of swap|perp|lend|stake,\nempty/omitted = full default set. expires_at: optional ISO 8601 hard\nexpiry. Effective on the very next call using this signer_pubkey.\nOn a Lane 2 wallet this raises BROWSER_CONFIRMATION_REQUIRED -- call\nrequest_session_signer_authorization instead (ENG-b35851ed): minting a\nsigner is a trust grant and must be owner-approved in the browser, never\nin-chat.","detail":"Description of `authorize_session_signer` changed (2% word delta).","severity":"safe","descriptionDelta":0.020618556701030966},{"kind":"description_changed","tool":"bulk_send_social","after":"Distribute one token to many X handles in one call (non-custodial).\n\n``recipients`` is a list of ``{recipient_handle, amount, message?}`` dicts\n(``recipient`` accepted as an alias; ``amount`` in base units; ``message`` an\noptional per-recipient note). Locks each amount of ``token`` (mint) from\n``sender_wallet`` into a fresh claim escrow and returns the ``create_claim``\ninstructions batched into as few UNSIGNED transactions as fit -- the sender\nsigns + broadcasts every returned tx. Each send carries its crank.ing claim\nlink, the bearer ``claim_code`` (returned once, embed per tweet), and the\n``transaction_index`` of the tx that funds it. Anti-abuse gated (account age,\nverified wallet, per-sender daily limit counting the whole batch). platform: x.\n\n``idempotency_key`` (optional): a client-generated UUID.\nRetrying with the same key + same args replays the original result (same\nclaim_codes/links) instead of locking a second batch of escrows.","before":"Distribute one token to many X handles in one call (non-custodial, ENG-bfeacb2c).\n\n``recipients`` is a list of ``{recipient_handle, amount, message?}`` dicts\n(``recipient`` accepted as an alias; ``amount`` in base units; ``message`` an\noptional per-recipient note). Locks each amount of ``token`` (mint) from\n``sender_wallet`` into a fresh claim escrow and returns the ``create_claim``\ninstructions batched into as few UNSIGNED transactions as fit -- the sender\nsigns + broadcasts every returned tx. Each send carries its crank.ing claim\nlink, the bearer ``claim_code`` (returned once, embed per tweet), and the\n``transaction_index`` of the tx that funds it. Anti-abuse gated (account age,\nverified wallet, per-sender daily limit counting the whole batch). platform: x.\n\n``idempotency_key`` (ENG-ac7961aa, optional): a client-generated UUID.\nRetrying with the same key + same args replays the original result (same\nclaim_codes/links) instead of locking a second batch of escrows.","detail":"Description of `bulk_send_social` changed (3% word delta).","severity":"safe","descriptionDelta":0.028846153846153855},{"kind":"description_changed","tool":"cancel_perp_order","after":"Cancel a resting perp order on its venue (non-custodial).\n\n``jurisdiction``: cancel is geo-gated too --\nsee place_perp_order.\n\n``idempotency_key`` (optional): a client-generated UUID.\nRetrying with the same key + same args replays the original result instead\nof re-cancelling the order.\n\n``signed_transaction`` / ``verify`` (two-phase execution):\nsee place_perp_order. A cancel moves no position, so confirming the\nsignature landed IS the verification -- no state re-read is declared.","before":"Cancel a resting perp order on its venue (non-custodial).\n\n``jurisdiction`` (ENG-27ae391a, gap RAILS-4): cancel is geo-gated too --\nsee place_perp_order.\n\n``idempotency_key`` (ENG-ac7961aa, optional): a client-generated UUID.\nRetrying with the same key + same args replays the original result instead\nof re-cancelling the order.\n\n``signed_transaction`` / ``verify`` (ENG-dc70e40b, two-phase execution):\nsee place_perp_order. A cancel moves no position, so confirming the\nsignature landed IS the verification -- no state re-read is declared.","detail":"Description of `cancel_perp_order` changed (12% word delta).","severity":"safe","descriptionDelta":0.12068965517241381},{"kind":"description_changed","tool":"check_claim_status","after":"Sender-facing claim status of a social send (FREE read).\n\nLook up by ``claim_id`` (the send id) OR ``recipient`` (X handle); optionally\nscope a recipient lookup to one ``sender_wallet``. Returns ``{\"sends\": [...]}``\neach with status (pending/claimed/expired/returned), claim_date, returned_at,\nrecipient_wallet, amount, claim_link, expiry_ts, and expires_in_seconds (a live\ncountdown, 0 once expired). Never exposes the claim-code secret.","before":"Sender-facing claim status of a social send (FREE read, ENG-bfeacb2c).\n\nLook up by ``claim_id`` (the send id) OR ``recipient`` (X handle); optionally\nscope a recipient lookup to one ``sender_wallet``. Returns ``{\"sends\": [...]}``\neach with status (pending/claimed/expired/returned), claim_date, returned_at,\nrecipient_wallet, amount, claim_link, expiry_ts, and expires_in_seconds (a live\ncountdown, 0 once expired). Never exposes the claim-code secret.","detail":"Description of `check_claim_status` changed (4% word delta).","severity":"safe","descriptionDelta":0.038461538461538436},{"kind":"description_changed","tool":"clear_agnta_grant","after":"Remove a wallet's AGNTA DelegationGrant cap opt-in (non-custodial\ncontrol plane).\n\nLOOSENS enforcement (removes a cap constraining every value-bearing call\non top of WalletPolicy) -- for a Lane 2 wallet this raises\nBROWSER_CONFIRMATION_REQUIRED: call request_agnta_grant_clear instead and\nhave the user approve it in their own browser. A non-Lane-2 wallet clears\ndirectly.","before":"Remove a wallet's AGNTA DelegationGrant cap opt-in (non-custodial\ncontrol plane, ENG-a515480a).\n\nLOOSENS enforcement (removes a cap constraining every value-bearing call\non top of WalletPolicy) -- for a Lane 2 wallet this raises\nBROWSER_CONFIRMATION_REQUIRED: call request_agnta_grant_clear instead and\nhave the user approve it in their own browser. A non-Lane-2 wallet clears\ndirectly.","detail":"Description of `clear_agnta_grant` changed (4% word delta).","severity":"safe","descriptionDelta":0.04347826086956519},{"kind":"description_changed","tool":"clone_strategy","after":"Clone a published strategy config to a wallet (records attribution).\n\nReturns the config_template to deploy via the strategy create tools. The\nclone is attributed to the template author for the clone-creator fee share\n(15% of the tech fee on clone actions). Free to clone.","before":"Clone a published strategy config to a wallet (records attribution).\n\nReturns the config_template to deploy via the strategy create tools. The\nclone is attributed to the template author for the clone-creator fee share\n(15% of the tech fee on clone actions, MB#13669). Free to clone.","detail":"Description of `clone_strategy` changed (6% word delta).","severity":"safe","descriptionDelta":0.0625},{"kind":"description_changed","tool":"close_perp_position","after":"Close a perp position (full/partial) on its venue (non-custodial).\n\nposition_id is venue-native (for Drift it is the market symbol). close_pct in\n(0, 100]. Returns an UNSIGNED tx / signing payload to sign + broadcast.\n\n``jurisdiction``: closes are geo-gated too --\nsee place_perp_order.\n\n``idempotency_key`` (optional): a client-generated UUID.\nRetrying with the same key + same args replays the original result instead\nof re-closing the position.\n\n``signed_transaction`` / ``verify`` (two-phase execution):\nsee place_perp_order -- re-call with the signed payload and Crank relays it\nby custody tier and verifies the result.","before":"Close a perp position (full/partial) on its venue (non-custodial).\n\nposition_id is venue-native (for Drift it is the market symbol). close_pct in\n(0, 100]. Returns an UNSIGNED tx / signing payload to sign + broadcast.\n\n``jurisdiction`` (ENG-27ae391a, gap RAILS-4): closes are geo-gated too --\nsee place_perp_order.\n\n``idempotency_key`` (ENG-ac7961aa, optional): a client-generated UUID.\nRetrying with the same key + same args replays the original result instead\nof re-closing the position.\n\n``signed_transaction`` / ``verify`` (ENG-dc70e40b, two-phase execution):\nsee place_perp_order -- re-call with the signed payload and Crank relays it\nby custody tier and verifies the result.","detail":"Description of `close_perp_position` changed (9% word delta).","severity":"safe","descriptionDelta":0.08860759493670889},{"kind":"description_changed","tool":"create_execution_intent","after":"Create a propose-only execution intent; returns an approval URL to hand to the user.\n\nLane 1 (non-custodial default): builds the unsigned swap transaction\nserver-side, persists it as an intent, and returns\n{intent_id, approval_url}. NOTHING executes until the user opens the\napproval URL in their browser and signs with their own wallet. This\ntool never signs and never sees a key. amount is in input-token base\nunits. The quote includes the technology service fee. After the user\napproves, poll get_intent_status and report ONLY the persisted\non-chain state (CONFIRMED before any success claim).\n\nFEE PARITY (follow-up to ):\nthe on-chain technology service fee baked into the unsigned tx is now\nresolved through the SAME discount-aware pipeline as ``jupiter_swap``\n-- the tokenized-security classification is resolved ONCE here via\nthe authoritative registry-backed classifier (parity with\n``jupiter_swap``'s call site) and, together with ``pay_in_crank``,\ndetermines the quoted ``platformFeeBps``. Without this an intent\nproposed via this Lane 1 rail could be fee-classified differently\nfrom the identical swap executed via ``jupiter_swap``. Decision:\n``pay_in_crank`` IS exposed here (not just ``is_security``) -- the\nfee rate is a quote-time input baked into the unsigned tx before the\nuser ever reaches the approve page, so an agent must be able to\nrequest the pay-in-$CRANK discount at proposal time, same as it can\non the direct swap path.\n\nGEO GATE: when either leg is a tokenized\nsecurity this call is geo-gated (Reg S = no US persons) and\nOFAC-screened, same control ``jupiter_swap``/``trade_equity``\nenforce -- ``jurisdiction`` declares the caller's jurisdiction once,\n``ip`` is the caller's origin IP for the Reg-S IP layer.","before":"Create a propose-only execution intent; returns an approval URL to hand to the user.\n\nLane 1 (non-custodial default): builds the unsigned swap transaction\nserver-side, persists it as an intent, and returns\n{intent_id, approval_url}. NOTHING executes until the user opens the\napproval URL in their browser and signs with their own wallet. This\ntool never signs and never sees a key. amount is in input-token base\nunits. The quote includes the technology service fee. After the user\napproves, poll get_intent_status and report ONLY the persisted\non-chain state (CONFIRMED before any success claim).\n\nFEE PARITY (ENG-8f3fb6d6, follow-up to ENG-254cf6b4/ENG-5a051af4):\nthe on-chain technology service fee baked into the unsigned tx is now\nresolved through the SAME discount-aware pipeline as ``jupiter_swap``\n-- the tokenized-security classification is resolved ONCE here via\nthe authoritative registry-backed classifier (parity with\n``jupiter_swap``'s call site) and, together with ``pay_in_crank``,\ndetermines the quoted ``platformFeeBps``. Without this an intent\nproposed via this Lane 1 rail could be fee-classified differently\nfrom the identical swap executed via ``jupiter_swap``. Decision:\n``pay_in_crank`` IS exposed here (not just ``is_security``) -- the\nfee rate is a quote-time input baked into the unsigned tx before the\nuser ever reaches the approve page, so an agent must be able to\nrequest the pay-in-$CRANK discount at proposal time, same as it can\non the direct swap path.\n\nGEO GATE (ENG-185ad857, gap RAILS-3): when either leg is a tokenized\nsecurity this call is geo-gated (Reg S = no US persons) and\nOFAC-screened, same control ``jupiter_swap``/``trade_equity``\nenforce -- ``jurisdiction`` declares the caller's jurisdiction once,\n``ip`` is the caller's origin IP for the Reg-S IP layer.","detail":"Description of `create_execution_intent` changed (5% word delta).","severity":"safe","descriptionDelta":0.04790419161676651},{"kind":"description_changed","tool":"declare_jurisdiction","after":"Declare your wallet's jurisdiction for geo-gated trading.\n\nGap: before this tool, the ONLY way to declare a\njurisdiction was the ``jurisdiction=`` param on ``trade_equity`` -- an\nagent that only ever used perps/short/leverage tools had no write path at\nall, and the fail-safe unknown-jurisdiction-DENIED rule permanently\nrefused it. Call this ONCE (or pass ``jurisdiction=`` directly on any\nperps/short/leverage/trade_equity tool) and the declaration is remembered\nfor 90 days across EVERY geo-gated framework (tokenized equities under\nReg S, perps/synthetic-shorting/leverage under the CFTC posture).\n\n``jurisdiction`` is an ISO-3166-1 alpha-2 country code (e.g. \"US\", \"GB\",\n\"SG\") -- YOUR OWN self-declaration of where you are, never advice or a\nrecommendation (hard rules 2/5-8). A US-person declaration does not\nunblock US-restricted venues; it makes the DENIED reason explicit rather\nthan \"jurisdiction_unknown\". Re-declaring overwrites the prior value.","before":"Declare your wallet's jurisdiction for geo-gated trading (ENG-27ae391a).\n\nGap RAILS-4 (ENG-23f0e18a): before this tool, the ONLY way to declare a\njurisdiction was the ``jurisdiction=`` param on ``trade_equity`` -- an\nagent that only ever used perps/short/leverage tools had no write path at\nall, and the fail-safe unknown-jurisdiction-DENIED rule permanently\nrefused it. Call this ONCE (or pass ``jurisdiction=`` directly on any\nperps/short/leverage/trade_equity tool) and the declaration is remembered\nfor 90 days across EVERY geo-gated framework (tokenized equities under\nReg S, perps/synthetic-shorting/leverage under the CFTC posture).\n\n``jurisdiction`` is an ISO-3166-1 alpha-2 country code (e.g. \"US\", \"GB\",\n\"SG\") -- YOUR OWN self-declaration of where you are, never advice or a\nrecommendation (hard rules 2/5-8). A US-person declaration does not\nunblock US-restricted venues; it makes the DENIED reason explicit rather\nthan \"jurisdiction_unknown\". Re-declaring overwrites the prior value.","detail":"Description of `declare_jurisdiction` changed (4% word delta).","severity":"safe","descriptionDelta":0.04347826086956519},{"kind":"description_changed","tool":"discover_strategies","after":"Browse published strategies (read-only, free). Crypto-only.\n\nstrategy_type filters to one of the 16 Crank strategy types (empty = all).\nsort ranks by clones|sharpe|return|sortino|win_rate|drawdown (default clones).","before":"Browse published strategies (read-only, free). Crypto-only (MB#13761).\n\nstrategy_type filters to one of the 16 Crank strategy types (empty = all).\nsort ranks by clones|sharpe|return|sortino|win_rate|drawdown (default clones).","detail":"Description of `discover_strategies` changed (6% word delta).","severity":"safe","descriptionDelta":0.06451612903225812},{"kind":"description_changed","tool":"equity_quote","after":"Read-only Jupiter quote for a tokenized-equity trade (no execution).\n\namount is in base units of the INPUT token (USDC for buy, the equity for\nsell). Returns expected output, price impact, effective fee, slippage, and\nthe SEC disclaimer. ``venue_hint`` is\nADVISORY, never required -- see trade_equity.","before":"Read-only Jupiter quote for a tokenized-equity trade (no execution).\n\namount is in base units of the INPUT token (USDC for buy, the equity for\nsell). Returns expected output, price impact, effective fee, slippage, and\nthe SEC disclaimer. ``venue_hint`` (ENG-fc290438/ENG-00ebde90, MB#18215) is\nADVISORY, never required -- see trade_equity.","detail":"Description of `equity_quote` changed (11% word delta).","severity":"safe","descriptionDelta":0.11111111111111116},{"kind":"description_changed","tool":"flash_loan","after":"Marginfi flash loan for arbitrage (non-custodial, atomic).\n\ninstructions are JSON ix executed between borrow + repay legs. Returns a\nsingle UNSIGNED base64 tx that reverts unless repaid in-transaction. The\nborrowed token is authenticity-verified first; set allow_unverified=true to\nborrow an unverified mint at your own risk. Past the daily free tier an x402\npayment_header is required.\n\n``idempotency_key`` (optional): a client-generated UUID.\nRetrying with the same key + same args replays the original result instead\nof re-issuing the flash loan tx.","before":"Marginfi flash loan for arbitrage (non-custodial, atomic).\n\ninstructions are JSON ix executed between borrow + repay legs. Returns a\nsingle UNSIGNED base64 tx that reverts unless repaid in-transaction. The\nborrowed token is authenticity-verified first; set allow_unverified=true to\nborrow an unverified mint at your own risk. Past the daily free tier an x402\npayment_header is required.\n\n``idempotency_key`` (ENG-7ded4fb8, optional): a client-generated UUID.\nRetrying with the same key + same args replays the original result instead\nof re-issuing the flash loan tx.","detail":"Description of `flash_loan` changed (3% word delta).","severity":"safe","descriptionDelta":0.0273972602739726},{"kind":"description_changed","tool":"fund_wallet","after":"Fund a wallet with fiat via MoonPay (card/bank/Apple Pay -> USDC).\n\nReturns a hosted checkout_url for the user to complete payment + a\nsession_id to poll with get_onramp_status. Purchased USDC settles directly\nto wallet_address (non-custodial). payment_method: card | bank | apple_pay.\nThe fee is charged on amount_usd notional past the daily free tier (x402\npayment_header).\n\n``idempotency_key`` (optional): a client-generated UUID.\nRetrying with the same key + same args replays the original result (same\ncheckout_url/session_id) instead of creating a second MoonPay session.","before":"Fund a wallet with fiat via MoonPay (card/bank/Apple Pay -> USDC).\n\nReturns a hosted checkout_url for the user to complete payment + a\nsession_id to poll with get_onramp_status. Purchased USDC settles directly\nto wallet_address (non-custodial). payment_method: card | bank | apple_pay.\nThe fee is charged on amount_usd notional past the daily free tier (x402\npayment_header).\n\n``idempotency_key`` (ENG-7ded4fb8, optional): a client-generated UUID.\nRetrying with the same key + same args replays the original result (same\ncheckout_url/session_id) instead of creating a second MoonPay session.","detail":"Description of `fund_wallet` changed (3% word delta).","severity":"safe","descriptionDelta":0.031746031746031744},{"kind":"description_changed","tool":"get_crank_score","after":"A wallet's Crank Score reputation breakdown (FREE read).\n\nReturns total_score, per-activity components (trade / staking / strategy /\nsocial / claim), sybil_flagged + penalty_bps, and the score-gated perks it\nunlocks under ``gates``: fee_discount_bps (additional technology service fee\ndiscount), daily_send_limit (higher social-send cap), priority_access, and\nthe gate tier (0-3). Score accrues from on-platform activity; circular\nfunding between wallets is flagged + penalised. Well-formed zeros for an\nunscored wallet.","before":"A wallet's Crank Score reputation breakdown (FREE read, ENG-95f335be).\n\nReturns total_score, per-activity components (trade / staking / strategy /\nsocial / claim), sybil_flagged + penalty_bps, and the score-gated perks it\nunlocks under ``gates``: fee_discount_bps (additional technology service fee\ndiscount), daily_send_limit (higher social-send cap), priority_access, and\nthe gate tier (0-3). Score accrues from on-platform activity; circular\nfunding between wallets is flagged + penalised. Well-formed zeros for an\nunscored wallet.","detail":"Description of `get_crank_score` changed (3% word delta).","severity":"safe","descriptionDelta":0.031746031746031744},{"kind":"description_changed","tool":"get_ilo_adoption_status","after":"The ILO adoption gate -- one machine-checkable readiness read (free).\n\nPublished Engaij, Inc. policy: the ILO proceeds only once\nCrank has 1,000 active users, where an active user has at least 5 executed\nCrank transactions inside a rolling 7-day window. Signups do not count.\nReturns gate_met (active_users >= 1000), active_users, near_active_users,\nusers_with_any_tx and the pinned transaction definition. A transaction is\nan EXECUTED trade only -- a recorded swap (broadcast signature required),\na perp open, or a user-initiated perp close; reads, quotes, unexecuted\nintents, paper trades, liquidations and devnet activity never count.\n``cluster=devnet`` exposes the same metric for pre-launch observability;\nthe gate itself is the mainnet number. Aggregate counts only, no\nper-wallet data. Informational readiness metric; not a promise of any\nlaunch, outcome or timeline.","before":"The ILO adoption gate -- one machine-checkable readiness read (free).\n\nAndrew's decision (MB#20076, ENG-5de0ede9): the ILO proceeds only once\nCrank has 1,000 active users, where an active user has at least 5 executed\nCrank transactions inside a rolling 7-day window. Signups do not count.\nReturns gate_met (active_users >= 1000), active_users, near_active_users,\nusers_with_any_tx and the pinned transaction definition. A transaction is\nan EXECUTED trade only -- a recorded swap (broadcast signature required),\na perp open, or a user-initiated perp close; reads, quotes, unexecuted\nintents, paper trades, liquidations and devnet activity never count.\n``cluster=devnet`` exposes the same metric for pre-launch observability;\nthe gate itself is the mainnet number. Aggregate counts only, no\nper-wallet data. Informational readiness metric; not a promise of any\nlaunch, outcome or timeline.","detail":"Description of `get_ilo_adoption_status` changed (11% word delta).","severity":"safe","descriptionDelta":0.10679611650485432},{"kind":"description_changed","tool":"get_leaderboard","after":"Top published strategies ranked by a verified backtest metric (free).\n\nCrypto-only -- equity templates excluded. sort in sharpe|return|\nsortino|win_rate|drawdown|clones (default sharpe). Each entry carries factual\nbacktest metrics + the on-chain attestation hash; no return promises (rule 8).","before":"Top published strategies ranked by a verified backtest metric (free).\n\nCrypto-only -- equity templates excluded (MB#13761). sort in sharpe|return|\nsortino|win_rate|drawdown|clones (default sharpe). Each entry carries factual\nbacktest metrics + the on-chain attestation hash; no return promises (rule 8).","detail":"Description of `get_leaderboard` changed (5% word delta).","severity":"safe","descriptionDelta":0.050000000000000044},{"kind":"description_changed","tool":"get_ooda_status","after":"Wake-on-condition consent + usage status.\n\nReturns opted_in, daily_wake_budget, wakes_used_today, skips_today, and\nrecent_wakes -- including SKIPPED_BUDGET / SKIPPED_SPEND_CAP rows, so a\nskipped wake is exactly as visible as a completed one, never silent.\nAlso returns the usage-vs-fee-revenue kill threshold config and state: kill_threshold_enabled, kill_threshold_ratio,\nkill_window_days, and -- if this wallet was auto-killed -- kill_switched_at\nand kill_reason, so a wallet can see why wakes stopped.\n\nWorkflow: status/observe step -- check this to see whether the background\nworker is watching, and what it did (or skipped) recently.","before":"Wake-on-condition consent + usage status (ENG-8c57afc3).\n\nReturns opted_in, daily_wake_budget, wakes_used_today, skips_today, and\nrecent_wakes -- including SKIPPED_BUDGET / SKIPPED_SPEND_CAP rows, so a\nskipped wake is exactly as visible as a completed one, never silent.\nAlso returns the usage-vs-fee-revenue kill threshold config and state\n(ENG-574a0e66/ENG-d7bc9d28): kill_threshold_enabled, kill_threshold_ratio,\nkill_window_days, and -- if this wallet was auto-killed -- kill_switched_at\nand kill_reason, so a wallet can see why wakes stopped.\n\nWorkflow: status/observe step -- check this to see whether the background\nworker is watching, and what it did (or skipped) recently.","detail":"Description of `get_ooda_status` changed (6% word delta).","severity":"safe","descriptionDelta":0.05633802816901412},{"kind":"description_changed","tool":"get_quests","after":"Live Crank Score quests + a wallet's progress (FREE read).\n\nTime-bounded, admin-configured campaigns (e.g. \"Trade $1000 this week = 500\npts\"). Each quest carries its tracked costly metric, target_value,\nreward_points, the active window, and -- when ``wallet_address`` is given --\nthe wallet's progress_value + completion state. Carries the ``disclaimer``.","before":"Live Crank Score quests + a wallet's progress (FREE read, ENG-b0150c40).\n\nTime-bounded, admin-configured campaigns (e.g. \"Trade $1000 this week = 500\npts\"). Each quest carries its tracked costly metric, target_value,\nreward_points, the active window, and -- when ``wallet_address`` is given --\nthe wallet's progress_value + completion state. Carries the ``disclaimer``.","detail":"Description of `get_quests` changed (4% word delta).","severity":"safe","descriptionDelta":0.04347826086956519},{"kind":"description_changed","tool":"get_quotes","after":"Read-only Jupiter quote for a token pair (no execution).\n\namount is in base units of input_token. Returns routes, price impact, fees,\nand estimated output. ``venue_hint``\nis ADVISORY, never required -- see jupiter_swap.\n\nPass ``wallet_address`` (optional) to preview the DISCOUNTED\ntechnology service fee that wallet will actually pay -- its volume tier plus\n$CRANK staker / ``pay_in_crank`` / Crank Score discounts. Omit it for the\nbase rate. This stays a free read either way.","before":"Read-only Jupiter quote for a token pair (no execution).\n\namount is in base units of input_token. Returns routes, price impact, fees,\nand estimated output. ``venue_hint`` (ENG-fc290438/ENG-00ebde90, MB#18215)\nis ADVISORY, never required -- see jupiter_swap.\n\nPass ``wallet_address`` (optional, ENG-5a051af4) to preview the DISCOUNTED\ntechnology service fee that wallet will actually pay -- its volume tier plus\n$CRANK staker / ``pay_in_crank`` / Crank Score discounts. Omit it for the\nbase rate. This stays a free read either way.","detail":"Description of `get_quotes` changed (9% word delta).","severity":"safe","descriptionDelta":0.08695652173913049},{"kind":"description_changed","tool":"get_score","after":"User-facing Crank Score: rank, multiplier, metrics + quests (FREE).\n\nThe campaign-layer view on top of ``get_crank_score``. Returns total_score,\nleaderboard rank + percentile, the applied multiplier_bps (streak /\nearly-adopter / strategy-creator), the wallet's costly-action ``metrics``\n(fee_volume_usd, strategies_published, clones_spawned, referrals_activated,\nactive_days), and its live ``quests`` with progress. Points come ONLY from\ncostly actions (anti-farm). ``disclaimer``: score MAY inform a future token\ndistribution -- no fixed conversion ratio, no entitlement.","before":"User-facing Crank Score: rank, multiplier, metrics + quests (FREE, ENG-b0150c40).\n\nThe campaign-layer view on top of ``get_crank_score``. Returns total_score,\nleaderboard rank + percentile, the applied multiplier_bps (streak /\nearly-adopter / strategy-creator), the wallet's costly-action ``metrics``\n(fee_volume_usd, strategies_published, clones_spawned, referrals_activated,\nactive_days), and its live ``quests`` with progress. Points come ONLY from\ncostly actions (anti-farm). ``disclaimer``: score MAY inform a future token\ndistribution -- no fixed conversion ratio, no entitlement.","detail":"Description of `get_score` changed (3% word delta).","severity":"safe","descriptionDelta":0.031746031746031744},{"kind":"description_changed","tool":"get_score_leaderboard","after":"Top-N Crank Score leaderboard (FREE read).\n\nRanked descending by total_score. ``limit`` caps at the admin-configured\nleaderboard_size. Each entry: rank, wallet_address, total_score, the\nbase/action/quest components, multiplier_bps, streak_days, percentile. Also\nreturns total_participants and the pre-token ``disclaimer``. (Distinct from\n``get_leaderboard``, which ranks strategy templates.)","before":"Top-N Crank Score leaderboard (FREE read, ENG-b0150c40).\n\nRanked descending by total_score. ``limit`` caps at the admin-configured\nleaderboard_size. Each entry: rank, wallet_address, total_score, the\nbase/action/quest components, multiplier_bps, streak_days, percentile. Also\nreturns total_participants and the pre-token ``disclaimer``. (Distinct from\n``get_leaderboard``, which ranks strategy templates.)","detail":"Description of `get_score_leaderboard` changed (4% word delta).","severity":"safe","descriptionDelta":0.0444444444444444},{"kind":"description_changed","tool":"get_source_weights","after":"Source-effectiveness weight table (free read).\n\nPer (source, signal_type, regime): graded evaluation counts, the smoothed\neffectiveness weight (social sources hold a low prior until sufficiently\ngraded -- the anti-gaming cold start), the fleet Layer-2 multiplier from\nreleased k-anonymous insights, and the combined weighted value the\ncomposite effectiveness_weighted transform consumes. Historical grading\nstatistics only -- descriptive, never advice. Not financial advice.\n\nWorkflow: COMPOSE step -- read alongside list_signal_catalog to pick\nstreams with a real graded track record before authoring a definition.","before":"Source-effectiveness weight table (free read; ENG-bfb7ace4).\n\nPer (source, signal_type, regime): graded evaluation counts, the smoothed\neffectiveness weight (social sources hold a low prior until sufficiently\ngraded -- the anti-gaming cold start), the fleet Layer-2 multiplier from\nreleased k-anonymous insights, and the combined weighted value the\ncomposite effectiveness_weighted transform consumes. Historical grading\nstatistics only -- descriptive, never advice. Not financial advice.\n\nWorkflow: COMPOSE step -- read alongside list_signal_catalog to pick\nstreams with a real graded track record before authoring a definition.","detail":"Description of `get_source_weights` changed (3% word delta).","severity":"safe","descriptionDelta":0.02898550724637683},{"kind":"description_changed","tool":"get_token_classification","after":"Standardised tokenized-stock classification for a mint or symbol.\n\nRead-only. Returns every classification dimension -- backing_status\n(fully/treasury backed, synthetic, unknown), liquidity_tier (tier_1/2/3 /\nilliquid, from Jupiter price impact), issuer_verified (Metaplex authority\nmatch), market_data_quality (live/stale/none) -- plus the derived composite\nrisk (low/medium/high/blocked) and last_verified_at. FAIL-SAFE: a registered\nbut unscored token, an inactive token, or an unregistered token reports\ntradeable=false. trade_equity enforces this same composite risk.","before":"Standardised tokenized-stock classification for a mint or symbol (ENG-b34b5493).\n\nRead-only. Returns every classification dimension -- backing_status\n(fully/treasury backed, synthetic, unknown), liquidity_tier (tier_1/2/3 /\nilliquid, from Jupiter price impact), issuer_verified (Metaplex authority\nmatch), market_data_quality (live/stale/none) -- plus the derived composite\nrisk (low/medium/high/blocked) and last_verified_at. FAIL-SAFE: a registered\nbut unscored token, an inactive token, or an unregistered token reports\ntradeable=false. trade_equity enforces this same composite risk.","detail":"Description of `get_token_classification` changed (3% word delta).","severity":"safe","descriptionDelta":0.030303030303030276},{"kind":"description_changed","tool":"journal_append","after":"Record a decision in your private, wallet-scoped journal (free write).\n\nYour durable memory on Crank: rationale, intended action, and optional\nexpectations (e.g. {\"direction\": \"up\", \"horizon\": \"24h\"}) are stored as\none opaque body only you can read back; the system later attributes\nrealised P&L from on-chain-verified fills and marks prices at\n1h/24h/7d/30d horizons. idempotency_key makes replays safe (offline\nqueues / batch agents). Link evidence via signal_ids / suggestion_id /\nstrategy_id (your own strategies only). Autonomous strategy executions\nare journaled for you automatically -- use this to add the\nagent-authored layer on top.\n\n``tx_signature`` (optional): pass the\nsignature a swap/perp/lend/stake tool just returned to link this\ndecision to its verified on-chain fill -- the proof the Layer 2\ncontribution firewall needs. Unknown signature for this wallet -> 404.\nIf omitted, the wallet's most recent CONFIRMED transaction within a\nshort window is auto-linked as a best-effort fallback -- explicit is\nstill more reliable, pass it whenever you have it.\n\nWorkflow: DECIDE step -- journal before (or as) you act; query it back\nwith journal_query / get_my_performance.","before":"Record a decision in your private, wallet-scoped journal (free write).\n\nYour durable memory on Crank: rationale, intended action, and optional\nexpectations (e.g. {\"direction\": \"up\", \"horizon\": \"24h\"}) are stored as\none opaque body only you can read back; the system later attributes\nrealised P&L from on-chain-verified fills and marks prices at\n1h/24h/7d/30d horizons. idempotency_key makes replays safe (offline\nqueues / batch agents). Link evidence via signal_ids / suggestion_id /\nstrategy_id (your own strategies only). Autonomous strategy executions\nare journaled for you automatically -- use this to add the\nagent-authored layer on top.\n\n``tx_signature`` (optional, ENG-9975a2a8/ENG-791a262d): pass the\nsignature a swap/perp/lend/stake tool just returned to link this\ndecision to its verified on-chain fill -- the proof the Layer 2\ncontribution firewall needs. Unknown signature for this wallet -> 404.\nIf omitted, the wallet's most recent CONFIRMED transaction within a\nshort window is auto-linked as a best-effort fallback -- explicit is\nstill more reliable, pass it whenever you have it.\n\nWorkflow: DECIDE step -- journal before (or as) you act; query it back\nwith journal_query / get_my_performance.","detail":"Description of `journal_append` changed (2% word delta).","severity":"safe","descriptionDelta":0.021276595744680882},{"kind":"description_changed","tool":"jupiter_swap","after":"Execute a token swap via Jupiter (non-custodial).\n\nWithout signed_transaction: returns an UNSIGNED base64 transaction for your\nwallet to sign + broadcast. With signed_transaction: broadcasts the\ncaller-signed tx and returns tx_signature. amount is in base units of\ninput_token. Includes the Crank technology service fee when a referral fee\naccount is configured -- collected ON-CHAIN via Jupiter's platformFeeBps, deducted from swap output. Swaps are NOT additionally gated by\nx402 (that would double-charge the same fee), so\npayment_header stays a no-op here (jupiter_swap is not in x402 PAID_TOOLS).\npay_in_crank is NO LONGER a no-op: the on-chain rate is now\nderived from this wallet's volume tier and $CRANK staker / pay-in-$CRANK /\nCrank Score discounts, so a discounted wallet is quoted a lower\nplatformFeeBps -- the same schedule x402 applies to perps/lend/stake.\n\nSECURITY: the output_token is run through multi-layer authenticity\nverification before any tx is built; an unverified/suspicious/fake token is\nblocked (UNVERIFIED_TOKEN). Set allow_unverified=true to trade an unverified\ntoken at your own risk (hard scam signals are never overridable).\n\n``venue_hint`` is ADVISORY, never\nrequired -- spot routes via Jupiter aggregation (the only spot venue\ntoday); an unknown hint raises, omitting it is unchanged from before.\n\nWorkflow: EXECUTE step -- deploy the directional/allocation leg after the risk\nphase capped the size. Non-custodial. Get a price first with get_quotes.\nSee get_trading_workflow.\n\n``idempotency_key`` (optional): a client-generated UUID.\nRetrying the SAME call (build or broadcast) with the same key + same args\nreplays the original result instead of re-executing -- guards against a\ntimeout-then-retry double-swap. Reuse the SAME key across the build call\nand its signed_transaction broadcast retry (they dedupe independently);\na NEW key means a genuinely new swap.\n\n``verify`` (default True): when broadcasting\n(signed_transaction supplied), await on-chain confirmation and re-read\nthe output_token balance -- the response gains a ``verification`` block\n({confirmed, slot, post_state, expected_vs_actual}). Gate follow-on\ndecisions on ``verification.confirmed``, never on tx_signature alone.\nSet False to skip for latency-sensitive callers. Verify any prior\nsignature later with the standalone ``verify_transaction`` tool.\n\nGEO GATE: when either leg is a tokenized\nsecurity this call is geo-gated (Reg S = no US persons) and OFAC-screened,\nsame control ``trade_equity`` enforces -- ``jurisdiction`` declares the\ncaller's jurisdiction once (persisted for next time), ``ip`` is the\ncaller's origin IP for the additional Reg-S IP layer. Non-security swaps\nare unaffected.","before":"Execute a token swap via Jupiter (non-custodial).\n\nWithout signed_transaction: returns an UNSIGNED base64 transaction for your\nwallet to sign + broadcast. With signed_transaction: broadcasts the\ncaller-signed tx and returns tx_signature. amount is in base units of\ninput_token. Includes the Crank technology service fee when a referral fee\naccount is configured -- collected ON-CHAIN via Jupiter's platformFeeBps\n(MB#13601), deducted from swap output. Swaps are NOT additionally gated by\nx402 (ENG-1521ec28: that would double-charge the same fee), so\npayment_header stays a no-op here (jupiter_swap is not in x402 PAID_TOOLS).\npay_in_crank is NO LONGER a no-op (ENG-5a051af4): the on-chain rate is now\nderived from this wallet's volume tier and $CRANK staker / pay-in-$CRANK /\nCrank Score discounts, so a discounted wallet is quoted a lower\nplatformFeeBps -- the same schedule x402 applies to perps/lend/stake.\n\nSECURITY: the output_token is run through multi-layer authenticity\nverification before any tx is built; an unverified/suspicious/fake token is\nblocked (UNVERIFIED_TOKEN). Set allow_unverified=true to trade an unverified\ntoken at your own risk (hard scam signals are never overridable).\n\n``venue_hint`` (ENG-fc290438/ENG-00ebde90, MB#18215) is ADVISORY, never\nrequired -- spot routes via Jupiter aggregation (the only spot venue\ntoday); an unknown hint raises, omitting it is unchanged from before.\n\nWorkflow: EXECUTE step -- deploy the directional/allocation leg after the risk\nphase capped the size. Non-custodial. Get a price first with get_quotes.\nSee get_trading_workflow.\n\n``idempotency_key`` (ENG-7ded4fb8, optional): a client-generated UUID.\nRetrying the SAME call (build or broadcast) with the same key + same args\nreplays the original result instead of re-executing -- guards against a\ntimeout-then-retry double-swap. Reuse the SAME key across the build call\nand its signed_transaction broadcast retry (they dedupe independently);\na NEW key means a genuinely new swap.\n\n``verify`` (ENG-df8afe93, default True): when broadcasting\n(signed_transaction supplied), await on-chain confirmation and re-read\nthe output_token balance -- the response gains a ``verification`` block\n({confirmed, slot, post_state, expected_vs_actual}). Gate follow-on\ndecisions on ``verification.confirmed``, never on tx_signature alone.\nSet False to skip for latency-sensitive callers. Verify any prior\nsignature later with the standalone ``verify_transaction`` tool.\n\nGEO GATE (ENG-185ad857, gap RAILS-3): when either leg is a tokenized\nsecurity this call is geo-gated (Reg S = no US persons) and OFAC-screened,\nsame control ``trade_equity`` enforces -- ``jurisdiction`` declares the\ncaller's jurisdiction once (persisted for next time), ``ip`` is the\ncaller's origin IP for the additional Reg-S IP layer. Non-security swaps\nare unaffected.","detail":"Description of `jupiter_swap` changed (6% word delta).","severity":"safe","descriptionDelta":0.056451612903225756},{"kind":"description_changed","tool":"lend_borrow","after":"Borrow against deposited collateral (non-custodial).\n\nReturns an UNSIGNED base64 tx + current health factor (pre-borrow estimate).\namount in base units of borrow_token. Deposit collateral first. Past the\ndaily free tier an x402 payment_header is required. The borrowed token is\nauthenticity-verified first; set allow_unverified=true to borrow an unverified\ntoken at your own risk.\n\n``idempotency_key`` (optional): a client-generated UUID.\nRetrying with the same key + same args replays the original result instead\nof re-borrowing.\n\n``signed_transaction`` / ``verify`` (two-phase execution):\nsee lend_deposit -- re-call with the signed tx and Crank broadcasts it,\nconfirms it on-chain, and re-reads the borrowed balance + obligation health.","before":"Borrow against deposited collateral (non-custodial).\n\nReturns an UNSIGNED base64 tx + current health factor (pre-borrow estimate).\namount in base units of borrow_token. Deposit collateral first. Past the\ndaily free tier an x402 payment_header is required. The borrowed token is\nauthenticity-verified first; set allow_unverified=true to borrow an unverified\ntoken at your own risk.\n\n``idempotency_key`` (ENG-7ded4fb8, optional): a client-generated UUID.\nRetrying with the same key + same args replays the original result instead\nof re-borrowing.\n\n``signed_transaction`` / ``verify`` (ENG-dc70e40b, two-phase execution):\nsee lend_deposit -- re-call with the signed tx and Crank broadcasts it,\nconfirms it on-chain, and re-reads the borrowed balance + obligation health.","detail":"Description of `lend_borrow` changed (4% word delta).","severity":"safe","descriptionDelta":0.03529411764705881},{"kind":"description_changed","tool":"lend_deposit","after":"Deposit assets to earn yield on Kamino or Marginfi (non-custodial).\n\nReturns an UNSIGNED base64 tx to sign + broadcast, plus supply APY. amount\nis in base units of token. protocol: kamino | marginfi -- pin one to keep\nexact prior behaviour. Marginfi needs marginfi_account (create via the\nsidecar). Past the daily free tier an x402 payment_header is required. The\ndeposited token is authenticity-verified first; set allow_unverified=true\nto supply an unverified token at own risk.\n\n``venue_hint`` / auto-route: pass ``protocol=\"auto\"`` (or\n``\"\"``) -- optionally with ``venue_hint`` as an advisory alias, same\nnaming as jupiter_swap/trade_equity -- to route through the SAME\nprimary+fallback health-failover the internal earn/lending trade bridge\nalready applies: an empty rate snapshot on the primary\nprotocol fails over to the configured fallback. Extends this tool instead\nof adding a separate earn_quote/trade_earn surface, so lend_deposit is now\nthe one first-class MCP path for both a pinned protocol and an\nauto-routed deposit. A router-resolved call also carries the\nsmart-contract counterparty-risk disclosure in the response\n(``disclosures``), matching the internal bridge.\n\nWorkflow: EXECUTE step (yield leg) -- supply idle stables/tokens after\ncomparing get_lending_rates; monitor with get_health_factor. See\nget_trading_workflow.\n\n``idempotency_key`` (optional): a client-generated UUID.\nRetrying with the same key + same args replays the original result instead\nof re-depositing.\n\n``signed_transaction`` / ``verify`` (two-phase execution):\nre-call this tool with the SIGNED base64 tx and Crank broadcasts it, then\nawaits on-chain confirmation and re-reads BOTH the deposited token's\nbalance and the obligation's health -- the response carries a real\n``verification`` block ({confirmed, slot, post_state, expected_vs_actual}).\nGate follow-on borrowing on ``verification.confirmed``, never on\ntx_signature alone. verify=false skips only the confirmation wait. When\nthe build leg auto-routed (protocol=\"auto\"), pass back the SAME resolved\n``protocol`` the build response reported -- re-resolving from \"auto\"/\nvenue_hint again on the completion leg could pick a different venue if\nhealth changed between calls.","before":"Deposit assets to earn yield on Kamino or Marginfi (non-custodial).\n\nReturns an UNSIGNED base64 tx to sign + broadcast, plus supply APY. amount\nis in base units of token. protocol: kamino | marginfi -- pin one to keep\nexact prior behaviour. Marginfi needs marginfi_account (create via the\nsidecar). Past the daily free tier an x402 payment_header is required. The\ndeposited token is authenticity-verified first; set allow_unverified=true\nto supply an unverified token at own risk.\n\n``venue_hint`` / auto-route (ENG-a01f7fd6): pass ``protocol=\"auto\"`` (or\n``\"\"``) -- optionally with ``venue_hint`` as an advisory alias, same\nnaming as jupiter_swap/trade_equity -- to route through the SAME\nprimary+fallback health-failover the internal earn/lending trade bridge\nalready applies (ENG-fc290438): an empty rate snapshot on the primary\nprotocol fails over to the configured fallback. Extends this tool instead\nof adding a separate earn_quote/trade_earn surface, so lend_deposit is now\nthe one first-class MCP path for both a pinned protocol and an\nauto-routed deposit. A router-resolved call also carries the\nsmart-contract counterparty-risk disclosure in the response\n(``disclosures``), matching the internal bridge.\n\nWorkflow: EXECUTE step (yield leg) -- supply idle stables/tokens after\ncomparing get_lending_rates; monitor with get_health_factor. See\nget_trading_workflow.\n\n``idempotency_key`` (ENG-7ded4fb8, optional): a client-generated UUID.\nRetrying with the same key + same args replays the original result instead\nof re-depositing.\n\n``signed_transaction`` / ``verify`` (ENG-dc70e40b, two-phase execution):\nre-call this tool with the SIGNED base64 tx and Crank broadcasts it, then\nawaits on-chain confirmation and re-reads BOTH the deposited token's\nbalance and the obligation's health -- the response carries a real\n``verification`` block ({confirmed, slot, post_state, expected_vs_actual}).\nGate follow-on borrowing on ``verification.confirmed``, never on\ntx_signature alone. verify=false skips only the confirmation wait. When\nthe build leg auto-routed (protocol=\"auto\"), pass back the SAME resolved\n``protocol`` the build response reported -- re-resolving from \"auto\"/\nvenue_hint again on the completion leg could pick a different venue if\nhealth changed between calls.","detail":"Description of `lend_deposit` changed (2% word delta).","severity":"safe","descriptionDelta":0.02450980392156865},{"kind":"description_changed","tool":"lend_repay","after":"Repay borrowed amount (non-custodial). Returns an UNSIGNED base64 tx +\ncurrent health factor. amount in base units of token. Past the daily free\ntier an x402 payment_header is required.\n\n``idempotency_key`` (optional): a client-generated UUID.\nRetrying with the same key + same args replays the original result instead\nof re-repaying.\n\n``signed_transaction`` / ``verify`` (two-phase execution):\nsee lend_deposit -- re-call with the signed tx and Crank broadcasts it,\nconfirms it on-chain, and re-reads the repaid balance + obligation health.","before":"Repay borrowed amount (non-custodial). Returns an UNSIGNED base64 tx +\ncurrent health factor. amount in base units of token. Past the daily free\ntier an x402 payment_header is required.\n\n``idempotency_key`` (ENG-7ded4fb8, optional): a client-generated UUID.\nRetrying with the same key + same args replays the original result instead\nof re-repaying.\n\n``signed_transaction`` / ``verify`` (ENG-dc70e40b, two-phase execution):\nsee lend_deposit -- re-call with the signed tx and Crank broadcasts it,\nconfirms it on-chain, and re-reads the repaid balance + obligation health.","detail":"Description of `lend_repay` changed (4% word delta).","severity":"safe","descriptionDelta":0.04477611940298509},{"kind":"description_changed","tool":"leverage_close","after":"Unwind a tracked leveraged position: sell -> repay stable -> withdraw.\n\nReturns an ORDERED STEP PLAN. position_id from leverage_long. Past the daily\nfree tier an x402 payment_header is required.\n\n``jurisdiction``: closes are geo-gated too --\nsee short_open.\n\n``idempotency_key`` (optional): a client-generated UUID.\nRetrying with the same key + same args replays the original result instead\nof re-unwinding the position.","before":"Unwind a tracked leveraged position: sell -> repay stable -> withdraw.\n\nReturns an ORDERED STEP PLAN. position_id from leverage_long. Past the daily\nfree tier an x402 payment_header is required.\n\n``jurisdiction`` (ENG-27ae391a, gap RAILS-4): closes are geo-gated too --\nsee short_open.\n\n``idempotency_key`` (ENG-7ded4fb8, optional): a client-generated UUID.\nRetrying with the same key + same args replays the original result instead\nof re-unwinding the position.","detail":"Description of `leverage_close` changed (11% word delta).","severity":"safe","descriptionDelta":0.10526315789473684},{"kind":"description_changed","tool":"leverage_long","after":"Open a lending-based leveraged long by looping deposit -> borrow stable\n-> buy more -> redeposit.\n\nReturns an ORDERED STEP PLAN of UNSIGNED base64 txs, effective leverage, loop\ncount, health factor, and a position_id. amount in base units. The levered\ntoken is authenticity-verified first; set allow_unverified=true to lever an\nunverified mint at your own risk. Past the daily free tier an x402\npayment_header is required.\n\n``jurisdiction``: leverage is geo-gated too --\nsee short_open.\n\n``idempotency_key`` (optional): a client-generated UUID.\nRetrying with the same key + same args replays the original result instead\nof re-opening the leveraged position.","before":"Open a lending-based leveraged long by looping deposit -> borrow stable\n-> buy more -> redeposit.\n\nReturns an ORDERED STEP PLAN of UNSIGNED base64 txs, effective leverage, loop\ncount, health factor, and a position_id. amount in base units. The levered\ntoken is authenticity-verified first; set allow_unverified=true to lever an\nunverified mint at your own risk. Past the daily free tier an x402\npayment_header is required.\n\n``jurisdiction`` (ENG-27ae391a, gap RAILS-4): leverage is geo-gated too --\nsee short_open.\n\n``idempotency_key`` (ENG-7ded4fb8, optional): a client-generated UUID.\nRetrying with the same key + same args replays the original result instead\nof re-opening the leveraged position.","detail":"Description of `leverage_long` changed (7% word delta).","severity":"safe","descriptionDelta":0.0674157303370787},{"kind":"description_changed","tool":"liquid_stake","after":"Stake SOL for a liquid-staking token (non-custodial).\n\namount in lamports. protocol: marinade | jito | blaze. Returns an UNSIGNED\nbase64 tx + the LST received + current APY. The technology service fee is\ncharged on the staked-SOL notional past the daily free tier (x402\npayment_header; set pay_in_crank for the $CRANK discount).\n\nWorkflow: EXECUTE step (yield leg) -- stake the idle slice after comparing\nget_lst_yields. Non-custodial. Monitor via portfolio_snapshot. See\nget_trading_workflow.\n\n``idempotency_key`` (optional): a client-generated UUID.\nRetrying with the same key + same args replays the original result instead\nof re-staking.\n\n``signed_transaction`` / ``verify`` (two-phase execution):\nre-call this tool with the SIGNED base64 tx and Crank broadcasts it, then\nawaits on-chain confirmation and re-reads the LST + SOL balances -- the\nresponse carries a real ``verification`` block ({confirmed, slot,\npost_state, expected_vs_actual}). Gate follow-on decisions on\n``verification.confirmed``, never on tx_signature alone. verify=false skips\nonly the confirmation wait.","before":"Stake SOL for a liquid-staking token (non-custodial).\n\namount in lamports. protocol: marinade | jito | blaze. Returns an UNSIGNED\nbase64 tx + the LST received + current APY. The technology service fee is\ncharged on the staked-SOL notional past the daily free tier (x402\npayment_header; set pay_in_crank for the $CRANK discount).\n\nWorkflow: EXECUTE step (yield leg) -- stake the idle slice after comparing\nget_lst_yields. Non-custodial. Monitor via portfolio_snapshot. See\nget_trading_workflow.\n\n``idempotency_key`` (ENG-7ded4fb8, optional): a client-generated UUID.\nRetrying with the same key + same args replays the original result instead\nof re-staking.\n\n``signed_transaction`` / ``verify`` (ENG-dc70e40b, two-phase execution):\nre-call this tool with the SIGNED base64 tx and Crank broadcasts it, then\nawaits on-chain confirmation and re-reads the LST + SOL balances -- the\nresponse carries a real ``verification`` block ({confirmed, slot,\npost_state, expected_vs_actual}). Gate follow-on decisions on\n``verification.confirmed``, never on tx_signature alone. verify=false skips\nonly the confirmation wait.","detail":"Description of `liquid_stake` changed (3% word delta).","severity":"safe","descriptionDelta":0.02608695652173909},{"kind":"description_changed","tool":"list_signal_catalog","after":"Catalog of every available signal stream (free read).\n\nOne entry per signal source across all tiers -- on-chain collectors, free\nAPI sources, derived analyzers and external provider adapters -- with tier,\ncost-gate state (paid Tier-D gates are fail-closed and disabled by\ndefault), coverage window (earliest/latest persisted signal -- the honest\nbacktest window), effectiveness stats (graded evaluation count + correct\nrate) and a gameability class (social streams rank high -- they carry\nanti-gaming caps). Descriptive historical data only. Not financial advice.\n\nWorkflow: COMPOSE step -- enumerate streams before authoring a composite\nstrategy definition; pair with get_signals to inspect a stream's feed.","before":"Catalog of every available signal stream (free read; ENG-5029a312).\n\nOne entry per signal source across all tiers -- on-chain collectors, free\nAPI sources, derived analyzers and external provider adapters -- with tier,\ncost-gate state (paid Tier-D gates are fail-closed and disabled by\ndefault), coverage window (earliest/latest persisted signal -- the honest\nbacktest window), effectiveness stats (graded evaluation count + correct\nrate) and a gameability class (social streams rank high -- they carry\nanti-gaming caps). Descriptive historical data only. Not financial advice.\n\nWorkflow: COMPOSE step -- enumerate streams before authoring a composite\nstrategy definition; pair with get_signals to inspect a stream's feed.","detail":"Description of `list_signal_catalog` changed (2% word delta).","severity":"safe","descriptionDelta":0.02197802197802201},{"kind":"description_changed","tool":"lst_swap","after":"Swap between two LSTs via the Sanctum router (non-custodial).\n\nfrom_lst/to_lst are mints; amount in base units. Returns an UNSIGNED base64\ntx + output amount. The technology service fee is charged on the input-LST\nnotional past the daily free tier (x402 payment_header). The acquired LST\n(to_lst) is authenticity-verified first; set allow_unverified=true to swap\ninto an unverified LST at your own risk.\n\n``idempotency_key`` (optional): a client-generated UUID.\nRetrying with the same key + same args replays the original result instead\nof re-swapping.\n\n``signed_transaction`` / ``verify`` (two-phase execution):\nsee liquid_stake -- re-call with the signed tx and Crank broadcasts it,\nconfirms it on-chain, and re-reads both LST balances.","before":"Swap between two LSTs via the Sanctum router (non-custodial).\n\nfrom_lst/to_lst are mints; amount in base units. Returns an UNSIGNED base64\ntx + output amount. The technology service fee is charged on the input-LST\nnotional past the daily free tier (x402 payment_header). The acquired LST\n(to_lst) is authenticity-verified first; set allow_unverified=true to swap\ninto an unverified LST at your own risk.\n\n``idempotency_key`` (ENG-7ded4fb8, optional): a client-generated UUID.\nRetrying with the same key + same args replays the original result instead\nof re-swapping.\n\n``signed_transaction`` / ``verify`` (ENG-dc70e40b, two-phase execution):\nsee liquid_stake -- re-call with the signed tx and Crank broadcasts it,\nconfirms it on-chain, and re-reads both LST balances.","detail":"Description of `lst_swap` changed (3% word delta).","severity":"safe","descriptionDelta":0.03296703296703296},{"kind":"description_changed","tool":"offramp_to_fiat","after":"Cash out crypto to fiat via MoonPay (non-custodial).\n\ntoken is the crypto to sell; amount is its quantity; destination is a\nMoonPay bank_account_id the fiat is paid to. Returns offramp_id,\nestimated_fiat, and status. Past the daily free tier an x402 payment_header\nis required.\n\n``idempotency_key`` (optional): a client-generated UUID.\nRetrying with the same key + same args replays the original result (same\nofframp_id) instead of creating a second MoonPay sell order.","before":"Cash out crypto to fiat via MoonPay (non-custodial).\n\ntoken is the crypto to sell; amount is its quantity; destination is a\nMoonPay bank_account_id the fiat is paid to. Returns offramp_id,\nestimated_fiat, and status. Past the daily free tier an x402 payment_header\nis required.\n\n``idempotency_key`` (ENG-ac7961aa, optional): a client-generated UUID.\nRetrying with the same key + same args replays the original result (same\nofframp_id) instead of creating a second MoonPay sell order.","detail":"Description of `offramp_to_fiat` changed (4% word delta).","severity":"safe","descriptionDelta":0.037735849056603765},{"kind":"description_changed","tool":"perp_close","after":"Close a perp position, full or partial (non-custodial).\n\nclose_pct in (0, 100]. Returns an UNSIGNED base64 tx to sign + broadcast,\nplus exit price + realized P&L estimate (incl funding). Past the daily free\ntier an x402 payment_header is required.\n\n``jurisdiction``: closes are geo-gated too --\nsee perp_open_long.\n\n``idempotency_key`` (optional): a client-generated UUID.\nRetrying with the same key + same args replays the original result instead\nof re-closing the position.\n\n``signed_transaction`` / ``verify`` (two-phase execution):\nsee perp_open_long -- re-call with the signed tx and Crank broadcasts it,\nconfirms it on-chain, and re-reads the position.","before":"Close a perp position, full or partial (non-custodial).\n\nclose_pct in (0, 100]. Returns an UNSIGNED base64 tx to sign + broadcast,\nplus exit price + realized P&L estimate (incl funding). Past the daily free\ntier an x402 payment_header is required.\n\n``jurisdiction`` (ENG-27ae391a, gap RAILS-4): closes are geo-gated too --\nsee perp_open_long.\n\n``idempotency_key`` (ENG-7ded4fb8, optional): a client-generated UUID.\nRetrying with the same key + same args replays the original result instead\nof re-closing the position.\n\n``signed_transaction`` / ``verify`` (ENG-dc70e40b, two-phase execution):\nsee perp_open_long -- re-call with the signed tx and Crank broadcasts it,\nconfirms it on-chain, and re-reads the position.","detail":"Description of `perp_close` changed (8% word delta).","severity":"safe","descriptionDelta":0.08139534883720934},{"kind":"description_changed","tool":"perp_modify","after":"Modify an existing open Drift ORDER by order_id (non-custodial).\n\nAdjusts trigger price (TP/SL). new_leverage / add_collateral require a\nseparate collateral deposit/withdraw and are recorded for tracking. Returns\nan UNSIGNED base64 tx to sign + broadcast. Past the daily free tier an x402\npayment_header is required.\n\n``jurisdiction``: modify (changes leverage/\nexposure) is geo-gated too -- see perp_open_long.\n\n``idempotency_key`` (optional): a client-generated UUID.\nRetrying with the same key + same args replays the original result instead\nof re-modifying the order.","before":"Modify an existing open Drift ORDER by order_id (non-custodial).\n\nAdjusts trigger price (TP/SL). new_leverage / add_collateral require a\nseparate collateral deposit/withdraw and are recorded for tracking. Returns\nan UNSIGNED base64 tx to sign + broadcast. Past the daily free tier an x402\npayment_header is required.\n\n``jurisdiction`` (ENG-27ae391a, gap RAILS-4): modify (changes leverage/\nexposure) is geo-gated too -- see perp_open_long.\n\n``idempotency_key`` (ENG-ac7961aa, optional): a client-generated UUID.\nRetrying with the same key + same args replays the original result instead\nof re-modifying the order.","detail":"Description of `perp_modify` changed (8% word delta).","severity":"safe","descriptionDelta":0.07894736842105265},{"kind":"description_changed","tool":"perp_open_long","after":"Open a leveraged LONG perp position on Drift (non-custodial).\n\nReturns an UNSIGNED base64 transaction for your wallet to sign + broadcast,\nplus entry/liquidation/margin estimates. market e.g. SOL-PERP. size_usd is\nnotional USD; leverage up to the market max. TP/SL are informational in the\nbuild — place them as trigger orders after the position opens. The fee is\ncharged on size_usd notional past the daily free tier (x402 payment_header).\n\n``jurisdiction``: your ISO-3166-1 alpha-2\ncountry code, self-declared -- perps are geo-gated (CFTC posture: no US\npersons, unknown jurisdiction DENIED). Pass it once here (or via\n``declare_jurisdiction``/``trade_equity``) and it is remembered for 90\ndays; every perps/short/leverage call is denied until declared.\n\n``idempotency_key`` (optional): a client-generated UUID.\nRetrying with the same key + same args replays the original result instead\nof re-opening the position.\n\n``signed_transaction`` / ``verify`` (two-phase execution):\nre-call this tool with the SIGNED base64 tx and Crank broadcasts it, then\nawaits on-chain confirmation and re-reads the perp position -- the response\ncarries a real ``verification`` block ({confirmed, slot, post_state,\nexpected_vs_actual}). Gate follow-on decisions on ``verification.confirmed``,\nnever on tx_signature alone. verify=false skips only the confirmation wait.","before":"Open a leveraged LONG perp position on Drift (non-custodial).\n\nReturns an UNSIGNED base64 transaction for your wallet to sign + broadcast,\nplus entry/liquidation/margin estimates. market e.g. SOL-PERP. size_usd is\nnotional USD; leverage up to the market max. TP/SL are informational in the\nbuild — place them as trigger orders after the position opens. The fee is\ncharged on size_usd notional past the daily free tier (x402 payment_header).\n\n``jurisdiction`` (ENG-27ae391a, gap RAILS-4): your ISO-3166-1 alpha-2\ncountry code, self-declared -- perps are geo-gated (CFTC posture: no US\npersons, unknown jurisdiction DENIED). Pass it once here (or via\n``declare_jurisdiction``/``trade_equity``) and it is remembered for 90\ndays; every perps/short/leverage call is denied until declared.\n\n``idempotency_key`` (ENG-7ded4fb8, optional): a client-generated UUID.\nRetrying with the same key + same args replays the original result instead\nof re-opening the position.\n\n``signed_transaction`` / ``verify`` (ENG-dc70e40b, two-phase execution):\nre-call this tool with the SIGNED base64 tx and Crank broadcasts it, then\nawaits on-chain confirmation and re-reads the perp position -- the response\ncarries a real ``verification`` block ({confirmed, slot, post_state,\nexpected_vs_actual}). Gate follow-on decisions on ``verification.confirmed``,\nnever on tx_signature alone. verify=false skips only the confirmation wait.","detail":"Description of `perp_open_long` changed (5% word delta).","severity":"safe","descriptionDelta":0.045454545454545414},{"kind":"description_changed","tool":"perp_open_short","after":"Open a leveraged SHORT perp position on Drift (non-custodial).\n\nSame envelope as perp_open_long, opposite direction. ``jurisdiction``, ``idempotency_key`` (optional)\nand ``signed_transaction``/``verify`` (two-phase execution):\nsee perp_open_long.","before":"Open a leveraged SHORT perp position on Drift (non-custodial).\n\nSame envelope as perp_open_long, opposite direction. ``jurisdiction``\n(ENG-27ae391a, gap RAILS-4), ``idempotency_key`` (ENG-7ded4fb8, optional)\nand ``signed_transaction``/``verify`` (ENG-dc70e40b, two-phase execution):\nsee perp_open_long.","detail":"Description of `perp_open_short` changed (21% word delta).","severity":"safe","descriptionDelta":0.21212121212121215},{"kind":"description_changed","tool":"place_perp_order","after":"Open a leveraged perp position on the best/selected venue (non-custodial).\n\nside is \"long\" | \"short\". market e.g. SOL-PERP; size_usd is notional USD.\nvenue optional -- defaults to the configured primary (Jupiter Perps), with\nhealth failover to the fallback for new orders. Returns an UNSIGNED tx\n(Tier A) or a signing payload (Tier B) for your wallet to sign + broadcast,\nplus venue_name / custody_tier / settlement_token. Tier B (venue-custodied)\nvenues require acknowledge_tier_b=true after reviewing custody_disclosure.\nFee charged on size_usd notional past the daily free tier (x402).\n\n``jurisdiction``: your ISO-3166-1 alpha-2\ncountry code, self-declared -- perps are geo-gated (no US persons, unknown\njurisdiction DENIED). Declare once here (or via\n``declare_jurisdiction``/``trade_equity``) and it is remembered 90 days.\n\nWorkflow: EXECUTE step (leveraged directional leg) -- after get_venue_health /\nget_venue_risk_score clear the venue and get_risk_assessment caps the size.\nMonitor via perp_positions. See get_trading_workflow.\n\n``idempotency_key`` (optional): a client-generated UUID.\nRetrying with the same key + same args replays the original result instead\nof re-opening the order.\n\n``signed_transaction`` / ``verify`` (two-phase execution):\nre-call this tool with the SIGNED payload and Crank relays it by custody\ntier -- Tier A to Solana RPC, then awaits on-chain confirmation and\nre-reads the position on the executing venue; Tier B to the venue's own\nsubmit endpoint, which returns a venue order id (reported as\nvenue-acknowledged, since it is not an on-chain signature). Gate follow-on\ndecisions on ``verification.confirmed``, never on tx_signature alone.","before":"Open a leveraged perp position on the best/selected venue (non-custodial).\n\nside is \"long\" | \"short\". market e.g. SOL-PERP; size_usd is notional USD.\nvenue optional -- defaults to the configured primary (Jupiter Perps), with\nhealth failover to the fallback for new orders. Returns an UNSIGNED tx\n(Tier A) or a signing payload (Tier B) for your wallet to sign + broadcast,\nplus venue_name / custody_tier / settlement_token. Tier B (venue-custodied)\nvenues require acknowledge_tier_b=true after reviewing custody_disclosure.\nFee charged on size_usd notional past the daily free tier (x402).\n\n``jurisdiction`` (ENG-27ae391a, gap RAILS-4): your ISO-3166-1 alpha-2\ncountry code, self-declared -- perps are geo-gated (no US persons, unknown\njurisdiction DENIED). Declare once here (or via\n``declare_jurisdiction``/``trade_equity``) and it is remembered 90 days.\n\nWorkflow: EXECUTE step (leveraged directional leg) -- after get_venue_health /\nget_venue_risk_score clear the venue and get_risk_assessment caps the size.\nMonitor via perp_positions. See get_trading_workflow.\n\n``idempotency_key`` (ENG-7ded4fb8, optional): a client-generated UUID.\nRetrying with the same key + same args replays the original result instead\nof re-opening the order.\n\n``signed_transaction`` / ``verify`` (ENG-dc70e40b, two-phase execution):\nre-call this tool with the SIGNED payload and Crank relays it by custody\ntier -- Tier A to Solana RPC, then awaits on-chain confirmation and\nre-reads the position on the executing venue; Tier B to the venue's own\nsubmit endpoint, which returns a venue order id (reported as\nvenue-acknowledged, since it is not an on-chain signature). Gate follow-on\ndecisions on ``verification.confirmed``, never on tx_signature alone.","detail":"Description of `place_perp_order` changed (4% word delta).","severity":"safe","descriptionDelta":0.03977272727272729},{"kind":"description_changed","tool":"publish_strategy","after":"Publish a cloneable strategy config to the marketplace (the flywheel).\n\nconfig_template is the parameter set others clone. anonymous=true omits the\nauthor. performance_summary is a factual metrics blob -- no return promises\nare stored or surfaced (hard rule 8). backtest_run_id attaches a verified\nbacktest (on-chain attestation hash + leaderboard ranking). Equity\n(tokenized-security) strategies are excluded. Read/control-plane,\nfree.","before":"Publish a cloneable strategy config to the marketplace (the flywheel).\n\nconfig_template is the parameter set others clone. anonymous=true omits the\nauthor. performance_summary is a factual metrics blob -- no return promises\nare stored or surfaced (hard rule 8). backtest_run_id attaches a verified\nbacktest (on-chain attestation hash + leaderboard ranking). Equity\n(tokenized-security) strategies are excluded (MB#13761). Read/control-plane,\nfree.","detail":"Description of `publish_strategy` changed (4% word delta).","severity":"safe","descriptionDelta":0.03703703703703709},{"kind":"description_changed","tool":"register_counterparty_set","after":"Register/replace/clear the AGNTA counterparty allow-set for the\ncaller's opted-in DelegationGrant (non-custodial control plane).\n\nPersists to Django so the set survives an MCP process restart and is\nvisible to every process -- the follow-up to 's process-local\n``InMemoryCounterpartySetResolver``. ``wallet_address`` must belong to an\n``AgentWallet`` with a non-blank ``agnta_grant_pda`` already configured\n(opting in is a separate step, out of scope here); the target grant_pda\nis always resolved from that wallet, never caller-supplied. ``members``\nis a list of base58 32-byte destination pubkeys the grant's\n``counterparty_root`` should allow -- pass an EMPTY list to CLEAR the\nregistered set, after which every transfer-class call naming an on-chain\ndestination for this grant fails closed.\n\n``expected_root`` (hex, optional but STRONGLY recommended): compare\nagainst the grant's live on-chain ``counterparty_root`` (hex-encoded)\nbefore calling this -- when given, a set that does not commit to it is\nrefused (INVALID_PARAMS) rather than silently registered, which would\notherwise surface later as a confusing AGNTA_GRANT_COUNTERPARTY_DENIED on\nan unrelated transfer.","before":"Register/replace/clear the AGNTA counterparty allow-set for the\ncaller's opted-in DelegationGrant (non-custodial control plane,\nENG-5d2e7048).\n\nPersists to Django so the set survives an MCP process restart and is\nvisible to every process -- the follow-up to ENG-5a93618d's process-local\n``InMemoryCounterpartySetResolver``. ``wallet_address`` must belong to an\n``AgentWallet`` with a non-blank ``agnta_grant_pda`` already configured\n(opting in is a separate step, out of scope here); the target grant_pda\nis always resolved from that wallet, never caller-supplied. ``members``\nis a list of base58 32-byte destination pubkeys the grant's\n``counterparty_root`` should allow -- pass an EMPTY list to CLEAR the\nregistered set, after which every transfer-class call naming an on-chain\ndestination for this grant fails closed.\n\n``expected_root`` (hex, optional but STRONGLY recommended): compare\nagainst the grant's live on-chain ``counterparty_root`` (hex-encoded)\nbefore calling this -- when given, a set that does not commit to it is\nrefused (INVALID_PARAMS) rather than silently registered, which would\notherwise surface later as a confusing AGNTA_GRANT_COUNTERPARTY_DENIED on\nan unrelated transfer.","detail":"Description of `register_counterparty_set` changed (3% word delta).","severity":"safe","descriptionDelta":0.025210084033613467},{"kind":"description_changed","tool":"request_session_signer_authorization","after":"Open the browser-confirmation handshake to authorize a session signer.\n\nCall this when authorize_session_signer refuses with\nBROWSER_CONFIRMATION_REQUIRED (Lane 2 wallet -- ). Does NOT\nauthorize the signer -- returns a confirmation URL like\nenable_agent_wallet; the wallet's OWNER must approve in their own browser\n(wallet-signature gated, never in-chat). Poll with\npoll_session_signer_authorization(device_code) once approved.","before":"Open the browser-confirmation handshake to authorize a session signer.\n\nCall this when authorize_session_signer refuses with\nBROWSER_CONFIRMATION_REQUIRED (Lane 2 wallet -- ENG-b35851ed). Does NOT\nauthorize the signer -- returns a confirmation URL like\nenable_agent_wallet; the wallet's OWNER must approve in their own browser\n(wallet-signature gated, never in-chat). Poll with\npoll_session_signer_authorization(device_code) once approved.","detail":"Description of `request_session_signer_authorization` changed (5% word delta).","severity":"safe","descriptionDelta":0.045454545454545414},{"kind":"description_changed","tool":"revoke_session_signer","after":"Instantly revoke a delegated session signer (non-custodial control plane).\n\nSingle atomic DB UPDATE -- the gate resolves the row fresh on every call\nwith no cache, so this is enforced on the very next call using\nsigner_pubkey. No TTL/cache window.","before":"Instantly revoke a delegated session signer (non-custodial control plane).\n\nSingle atomic DB UPDATE -- the gate resolves the row fresh on every call\nwith no cache, so this is enforced on the very next call using\nsigner_pubkey. No TTL/cache window (ENG-39ec13bf).","detail":"Description of `revoke_session_signer` changed (5% word delta).","severity":"safe","descriptionDelta":0.05405405405405406},{"kind":"description_changed","tool":"send_token_social","after":"Send tokens to an X handle via a claimable crank.ing link (non-custodial).\n\nLocks ``amount`` (base units) of ``token`` (mint) from ``sender_wallet`` into\nthe on-chain claim escrow against a fresh claim code, and returns an UNSIGNED\nbase64 transaction for the sender to sign + broadcast, plus the\ncrank.ing/{code} claim link and the claim_code (the bearer secret to embed in\nthe announcement tweet). Whoever presents the code claims the tokens and\nbinds ``referral`` on their first claim. ``expiry_days`` (optional, default 7,\nrange 1-90) sets the claim window; unclaimed tokens are returned to the sender\nafter expiry. Anti-abuse gated: sender account age, verified wallet,\nper-sender daily limit. platform: x.\n\n``idempotency_key`` (optional): a client-generated UUID.\nRetrying with the same key + same args replays the original result (same\nclaim_code/link) instead of locking a second escrow.","before":"Send tokens to an X handle via a claimable crank.ing link (non-custodial).\n\nLocks ``amount`` (base units) of ``token`` (mint) from ``sender_wallet`` into\nthe on-chain claim escrow against a fresh claim code, and returns an UNSIGNED\nbase64 transaction for the sender to sign + broadcast, plus the\ncrank.ing/{code} claim link and the claim_code (the bearer secret to embed in\nthe announcement tweet). Whoever presents the code claims the tokens and\nbinds ``referral`` on their first claim. ``expiry_days`` (optional, default 7,\nrange 1-90) sets the claim window; unclaimed tokens are returned to the sender\nafter expiry. Anti-abuse gated: sender account age, verified wallet,\nper-sender daily limit. platform: x.\n\n``idempotency_key`` (ENG-7ded4fb8, optional): a client-generated UUID.\nRetrying with the same key + same args replays the original result (same\nclaim_code/link) instead of locking a second escrow.","detail":"Description of `send_token_social` changed (2% word delta).","severity":"safe","descriptionDelta":0.020408163265306145},{"kind":"description_changed","tool":"set_agnta_grant","after":"Opt a wallet into an AGNTA DelegationGrant spend/scope cap\n(non-custodial control plane).\n\nValidates grant_pda decodes as a base58 32-byte address, the on-chain\naccount exists and decodes as a DelegationGrant, it is not revoked and\nnot expired, and its delegate matches wallet_address -- every failure\nraises INVALID_PARAMS with a distinct message. Adds an ADDITIONAL cap\nenforced alongside (never replacing) WalletPolicy on every subsequent\nvalue-bearing call for this wallet -- always TIGHTENS enforcement, so it\napplies directly for every wallet, Lane 2 included.","before":"Opt a wallet into an AGNTA DelegationGrant spend/scope cap\n(non-custodial control plane, ENG-a515480a).\n\nValidates grant_pda decodes as a base58 32-byte address, the on-chain\naccount exists and decodes as a DelegationGrant, it is not revoked and\nnot expired, and its delegate matches wallet_address -- every failure\nraises INVALID_PARAMS with a distinct message. Adds an ADDITIONAL cap\nenforced alongside (never replacing) WalletPolicy on every subsequent\nvalue-bearing call for this wallet -- always TIGHTENS enforcement, so it\napplies directly for every wallet, Lane 2 included.","detail":"Description of `set_agnta_grant` changed (3% word delta).","severity":"safe","descriptionDelta":0.02941176470588236},{"kind":"description_changed","tool":"set_alert","after":"Create a price/position alert checked every 60s by Celery beat.\n\nalert_type: price_above | price_below | position_change. token is a mint\naddress. Optional webhook_url is POSTed when the alert fires.\n\nFree (no technology service fee) -- a control-plane write, moves no funds\nand has no transaction notional.\n\nWorkflow: MONITOR step -- arm after executing so a tripped level loops you back\nto the risk/execute phase. See get_trading_workflow.","before":"Create a price/position alert checked every 60s by Celery beat.\n\nalert_type: price_above | price_below | position_change. token is a mint\naddress. Optional webhook_url is POSTed when the alert fires.\n\nFree (no technology service fee) -- a control-plane write, moves no funds\nand has no transaction notional (ENG-4a5e0443).\n\nWorkflow: MONITOR step -- arm after executing so a tripped level loops you back\nto the risk/execute phase. See get_trading_workflow.","detail":"Description of `set_alert` changed (3% word delta).","severity":"safe","descriptionDelta":0.03389830508474578},{"kind":"description_changed","tool":"set_ooda_consent","after":"Opt in/out of the wake-on-condition worker.\n\nDefault OFF. When opted in, a triggered alert may run a metered\nbackground check (Haiku triage, escalating to Sonnet only if worth a\ncloser look) and propose one action. daily_wake_budget (default 10, 1-500)\nhard-caps metered wakes per day. The worker never executes -- every\nproposal is approved in your own wallet. See get_ooda_status for wake\nhistory including skipped wakes.\n\nUsage-vs-fee-revenue kill threshold: wakes\nauto-suspend if inference spend over kill_window_days (default 30 days)\nexceeds kill_threshold_ratio (default \"0.5\") of attributed fee revenue.\nkill_threshold_enabled lets you disable the check for this wallet;\nkill_threshold_ratio is a decimal string. All three are optional -- omit\nto leave the existing/default value untouched. See get_ooda_status for\nwhether/why a wallet was auto-killed (kill_switched_at, kill_reason).\n\nWorkflow: consent step -- run once (or to change budget/kill config)\nbefore wakes can fire; check get_ooda_status afterward to confirm state.","before":"Opt in/out of the wake-on-condition worker (ENG-8c57afc3).\n\nDefault OFF. When opted in, a triggered alert may run a metered\nbackground check (Haiku triage, escalating to Sonnet only if worth a\ncloser look) and propose one action. daily_wake_budget (default 10, 1-500)\nhard-caps metered wakes per day. The worker never executes -- every\nproposal is approved in your own wallet. See get_ooda_status for wake\nhistory including skipped wakes.\n\nUsage-vs-fee-revenue kill threshold (ENG-574a0e66/ENG-d7bc9d28): wakes\nauto-suspend if inference spend over kill_window_days (default 30 days)\nexceeds kill_threshold_ratio (default \"0.5\") of attributed fee revenue.\nkill_threshold_enabled lets you disable the check for this wallet;\nkill_threshold_ratio is a decimal string. All three are optional -- omit\nto leave the existing/default value untouched. See get_ooda_status for\nwhether/why a wallet was auto-killed (kill_switched_at, kill_reason).\n\nWorkflow: consent step -- run once (or to change budget/kill config)\nbefore wakes can fire; check get_ooda_status afterward to confirm state.","detail":"Description of `set_ooda_consent` changed (3% word delta).","severity":"safe","descriptionDelta":0.03389830508474578},{"kind":"description_changed","tool":"set_wallet_policy","after":"Configure the caller's own trading limits and rules on an agent wallet.\n\npolicies: a list of {policy_type, value, enabled?} objects. policy_type is\none of max_trade_size {\"usd\"} | daily_limit {\"usd\"} | approved_tokens\n{\"tokens\"} | banned_tokens {\"tokens\"} | position_limit {\"usd\"} | kill_switch\n{\"active\"} | drawdown_limit {\"max_pct\"} | max_daily_loss {\"usd\"} |\ntrade_velocity {\"max_per_hour\", \"max_per_day\"} | venue_allowlist\n{\"venues\"}. Upserts by policy_type; returns the full updated policy set.\n(Perp leverage cap is a separate follow-up,  -- not a\npolicy_type here.) On a Lane 2 wallet, a change that would LOOSEN a\nserver-enforced default raises BROWSER_CONFIRMATION_REQUIRED -- call\nrequest_wallet_policy_loosening instead.","before":"Configure the caller's own trading limits and rules on an agent wallet.\n\npolicies: a list of {policy_type, value, enabled?} objects. policy_type is\none of max_trade_size {\"usd\"} | daily_limit {\"usd\"} | approved_tokens\n{\"tokens\"} | banned_tokens {\"tokens\"} | position_limit {\"usd\"} | kill_switch\n{\"active\"} | drawdown_limit {\"max_pct\"} | max_daily_loss {\"usd\"} |\ntrade_velocity {\"max_per_hour\", \"max_per_day\"} | venue_allowlist\n{\"venues\"}. Upserts by policy_type; returns the full updated policy set.\n(Perp leverage cap is a separate follow-up, ENG-f3aacdf1 -- not a\npolicy_type here.) On a Lane 2 wallet, a change that would LOOSEN a\nserver-enforced default raises BROWSER_CONFIRMATION_REQUIRED -- call\nrequest_wallet_policy_loosening instead (ENG-45e5ea07).","detail":"Description of `set_wallet_policy` changed (4% word delta).","severity":"safe","descriptionDelta":0.04166666666666663},{"kind":"description_changed","tool":"short_close","after":"Close a tracked short: buy token -> repay loan -> withdraw collateral.\n\nReturns an ORDERED STEP PLAN + exit price. short_id from short_open. Past\nthe daily free tier an x402 payment_header is required.\n\n``jurisdiction``: closes are geo-gated too --\nsee short_open.\n\n``idempotency_key`` (optional): a client-generated UUID.\nRetrying with the same key + same args replays the original result instead\nof re-closing the short.","before":"Close a tracked short: buy token -> repay loan -> withdraw collateral.\n\nReturns an ORDERED STEP PLAN + exit price. short_id from short_open. Past\nthe daily free tier an x402 payment_header is required.\n\n``jurisdiction`` (ENG-27ae391a, gap RAILS-4): closes are geo-gated too --\nsee short_open.\n\n``idempotency_key`` (ENG-7ded4fb8, optional): a client-generated UUID.\nRetrying with the same key + same args replays the original result instead\nof re-closing the short.","detail":"Description of `short_close` changed (10% word delta).","severity":"safe","descriptionDelta":0.10169491525423724},{"kind":"description_changed","tool":"short_open","after":"Open a lending-based short: deposit collateral -> borrow token -> sell.\n\nReturns an ORDERED STEP PLAN of UNSIGNED base64 txs to sign + broadcast in\nsequence, plus entry price + health factor + a short_id for tracking. All\namounts in base units. The shorted token is authenticity-verified first; set\nallow_unverified=true to short an unverified mint at your own risk. Past the\ndaily free tier an x402 payment_header is required.\n\n``jurisdiction``: your ISO-3166-1 alpha-2\ncountry code, self-declared -- synthetic shorting is geo-gated (no US\npersons, unknown jurisdiction DENIED). Declare once here (or via\n``declare_jurisdiction``/``trade_equity``/perps tools) and it is\nremembered 90 days.\n\n``idempotency_key`` (optional): a client-generated UUID.\nRetrying with the same key + same args replays the original result instead\nof re-opening the short.","before":"Open a lending-based short: deposit collateral -> borrow token -> sell.\n\nReturns an ORDERED STEP PLAN of UNSIGNED base64 txs to sign + broadcast in\nsequence, plus entry price + health factor + a short_id for tracking. All\namounts in base units. The shorted token is authenticity-verified first; set\nallow_unverified=true to short an unverified mint at your own risk. Past the\ndaily free tier an x402 payment_header is required.\n\n``jurisdiction`` (ENG-27ae391a, gap RAILS-4): your ISO-3166-1 alpha-2\ncountry code, self-declared -- synthetic shorting is geo-gated (no US\npersons, unknown jurisdiction DENIED). Declare once here (or via\n``declare_jurisdiction``/``trade_equity``/perps tools) and it is\nremembered 90 days.\n\n``idempotency_key`` (ENG-7ded4fb8, optional): a client-generated UUID.\nRetrying with the same key + same args replays the original result instead\nof re-opening the short.","detail":"Description of `short_open` changed (5% word delta).","severity":"safe","descriptionDelta":0.053097345132743334},{"kind":"description_changed","tool":"sidecar_health","after":"Live reachability probe against the deployed execution sidecar.\n\nThin wrapper around ``sidecar_service.is_configured``/``healthcheck`` -- THE tool that replaces a tester's local\n``curl $SIDECAR_URL/health`` (docs/LANE2_DEVNET_VERIFY_RUNBOOK.md Gate C):\nthat curl only proves the TESTER's own shell can reach a sidecar, never\nwhether the DEPLOYED mcp.crank.ing server can -- the exact gap that let\nthe checklist read fully green on 13 Aug 2026 while\n``poll_agent_wallet_enable`` was still failing with \"managed signing\nunavailable (sidecar unreachable)\". This tool runs the probe\nfrom the server's own network path instead.\n\nUnconfigured (``SIDECAR_URL`` unset) raises a structured CONFIG_ERROR with\nNO network attempt -- feature-detected first via ``is_configured``, the\nsame presence-only check ``go_live_status.posture.sidecar.configured``\nreads (crank_mcp/services/go_live.py); the two must never disagree.\nConfigured but unreachable returns an OK envelope with\n``reachable: False`` -- distinct from \"not configured\" -- so a caller (or\nthe runbook's Gate C) can tell \"we never tried\" apart from \"we tried and\nit's down\".\n\nFREE read, never gated (never in x402 PAID_TOOLS): booleans/counts/hosts\nonly, no secret ever leaves this tool (mirrors go_live.posture's\npresence-only pattern -- never ``config.SIDECAR_AUTH_TOKEN`` itself).","before":"Live reachability probe against the deployed execution sidecar (ENG-5ad7ea6e).\n\nThin wrapper around ``sidecar_service.is_configured()``/``healthcheck()``\n(ENG-b3372aa9) -- THE tool that replaces a tester's local\n``curl $SIDECAR_URL/health`` (docs/LANE2_DEVNET_VERIFY_RUNBOOK.md Gate C):\nthat curl only proves the TESTER's own shell can reach a sidecar, never\nwhether the DEPLOYED mcp.crank.ing server can -- the exact gap that let\nthe checklist read fully green on 13 Aug 2026 while\n``poll_agent_wallet_enable`` was still failing with \"managed signing\nunavailable (sidecar unreachable)\" (MB#25893). This tool runs the probe\nfrom the server's own network path instead.\n\nUnconfigured (``SIDECAR_URL`` unset) raises a structured CONFIG_ERROR with\nNO network attempt -- feature-detected first via ``is_configured()``, the\nsame presence-only check ``go_live_status().posture.sidecar.configured``\nreads (crank_mcp/services/go_live.py); the two must never disagree.\nConfigured but unreachable returns an OK envelope with\n``reachable: False`` -- distinct from \"not configured\" -- so a caller (or\nthe runbook's Gate C) can tell \"we never tried\" apart from \"we tried and\nit's down\".\n\nFREE read, never gated (never in x402 PAID_TOOLS): booleans/counts/hosts\nonly, no secret ever leaves this tool (mirrors go_live.posture()'s\npresence-only pattern -- never ``config.SIDECAR_AUTH_TOKEN`` itself).","detail":"Description of `sidecar_health` changed (4% word delta).","severity":"safe","descriptionDelta":0.03731343283582089},{"kind":"description_changed","tool":"strategy_dca_create","after":"Create a dollar-cost-average strategy buying ``usd_per_buy`` of target each interval.\n\n``risk`` (optional) overrides the safe-default risk limits:\n``max_position_pct`` / ``max_portfolio_exposure_pct`` / ``max_single_loss_pct``\n/ ``max_drawdown_pct`` / ``max_daily_loss_pct`` (percent; <=0 disables a guard).\n\nDirection (optional, all deterministic signals -- DYOR): ``direction_mode``\n(auto | long_only | short_only | manual; default auto = follow the market\nregime, reducing exposure in a bear instead of accumulating), ``allow_short``\n(enable real shorts via the Drift perps venue), ``regime_override`` (force\nbull | bear | range | volatile instead of trusting detection).\n\nWorkflow: EXECUTE step -- stand up a recurring strategy after backtest_strategy\nvalidates it and get_risk_assessment sets the guards; track via strategy_status.\nAn agent wallet without a Turnkey signer = paper-trade (unsigned tx per tick).\nSee get_trading_workflow.","before":"Create a dollar-cost-average strategy buying ``usd_per_buy`` of target each interval.\n\n``risk`` (optional) overrides the safe-default risk limits (ENG-b2c60329):\n``max_position_pct`` / ``max_portfolio_exposure_pct`` / ``max_single_loss_pct``\n/ ``max_drawdown_pct`` / ``max_daily_loss_pct`` (percent; <=0 disables a guard).\n\nDirection (ENG-bd44b1b7, optional, all deterministic signals -- DYOR): ``direction_mode``\n(auto | long_only | short_only | manual; default auto = follow the market\nregime, reducing exposure in a bear instead of accumulating), ``allow_short``\n(enable real shorts via the Drift perps venue), ``regime_override`` (force\nbull | bear | range | volatile instead of trusting detection).\n\nWorkflow: EXECUTE step -- stand up a recurring strategy after backtest_strategy\nvalidates it and get_risk_assessment sets the guards; track via strategy_status.\nAn agent wallet without a Turnkey signer = paper-trade (unsigned tx per tick).\nSee get_trading_workflow.","detail":"Description of `strategy_dca_create` changed (3% word delta).","severity":"safe","descriptionDelta":0.03157894736842104},{"kind":"description_changed","tool":"strategy_equity_dca_create","after":"Create an equity dollar-cost-average strategy (tokenized equities / xStocks).\n\nShares the DCA executor -- identical mechanics/config to\n``strategy_dca_create`` -- tagged ``equity_dca`` because ``target_token`` is\nexpected to be a tokenized-equity mint. SEC posture: DCA is a\nMECHANICAL, user-configured strategy (not discretionary), so it stays\nautonomous even on a security target -- the per-execution confirmation gate\nonly applies to the discretionary types (momentum / sentiment). Equity\nclassification still drives geo-gating + disclaimers at execution; call\nasset_classification / get_disclaimers first.\n\n``risk`` / direction params: see ``strategy_dca_create``.","before":"Create an equity dollar-cost-average strategy (tokenized equities / xStocks).\n\nShares the DCA executor -- identical mechanics/config to\n``strategy_dca_create`` -- tagged ``equity_dca`` because ``target_token`` is\nexpected to be a tokenized-equity mint. SEC posture (ENG-6f4d3513): DCA is a\nMECHANICAL, user-configured strategy (not discretionary), so it stays\nautonomous even on a security target -- the per-execution confirmation gate\nonly applies to the discretionary types (momentum / sentiment). Equity\nclassification still drives geo-gating + disclaimers at execution; call\nasset_classification / get_disclaimers first.\n\n``risk`` / direction params: see ``strategy_dca_create``.","detail":"Description of `strategy_equity_dca_create` changed (3% word delta).","severity":"safe","descriptionDelta":0.02898550724637683},{"kind":"description_changed","tool":"strategy_momentum_create","after":"Create a momentum strategy -- fast/slow SMA crossover entry/exit.\n\nBuys on a bullish cross (fast SMA > slow SMA), sells on a bearish cross.\nDISCRETIONARY (SEC framework): the model interprets a signal\nand converts it to a trade, so targeting a tokenized SECURITY forces\nper-execution user confirmation before the scheduled dispatcher will run a\ntick (``strategies.tasks.execute_strategy`` requires ``user_confirmed=True``;\ncrypto targets stay fully autonomous). Call asset_classification first.\n\n``risk`` / direction params: see ``strategy_dca_create``.","before":"Create a momentum strategy -- fast/slow SMA crossover entry/exit.\n\nBuys on a bullish cross (fast SMA > slow SMA), sells on a bearish cross.\nDISCRETIONARY (SEC framework, ENG-6f4d3513): the model interprets a signal\nand converts it to a trade, so targeting a tokenized SECURITY forces\nper-execution user confirmation before the scheduled dispatcher will run a\ntick (``strategies.tasks.execute_strategy`` requires ``user_confirmed=True``;\ncrypto targets stay fully autonomous). Call asset_classification first.\n\n``risk`` / direction params: see ``strategy_dca_create``.","detail":"Description of `strategy_momentum_create` changed (3% word delta).","severity":"safe","descriptionDelta":0.03125},{"kind":"description_changed","tool":"strategy_rebalance_create","after":"Create a portfolio-rebalance strategy toward ``target_allocation`` (mint->weight).\n\nDirection (optional, deterministic signal): ``direction_mode`` /\n``allow_short`` / ``regime_override`` -- see ``strategy_dca_create``.","before":"Create a portfolio-rebalance strategy toward ``target_allocation`` (mint->weight).\n\nDirection (ENG-bd44b1b7, optional, deterministic signal): ``direction_mode`` /\n``allow_short`` / ``regime_override`` -- see ``strategy_dca_create``.","detail":"Description of `strategy_rebalance_create` changed (10% word delta).","severity":"safe","descriptionDelta":0.09999999999999998},{"kind":"description_changed","tool":"strategy_resume","after":"Re-enable a paused strategy (manual re-enable after a drawdown pause).\n\nThe drawdown kill switch latches a strategy to\n``paused_drawdown`` and requires this explicit owner action to resume; the\nequity high-water mark is reset so it does not immediately re-trip.","before":"Re-enable a paused strategy (manual re-enable after a drawdown pause).\n\nThe drawdown kill switch (ENG-b2c60329) latches a strategy to\n``paused_drawdown`` and requires this explicit owner action to resume; the\nequity high-water mark is reset so it does not immediately re-trip.","detail":"Description of `strategy_resume` changed (6% word delta).","severity":"safe","descriptionDelta":0.05555555555555558},{"kind":"description_changed","tool":"strategy_sentiment_create","after":"Create a sentiment strategy -- trades an aggregate sentiment score.\n\nBuys when the score is >= ``bull_threshold`` (flat), sells when it is\n<= ``bear_threshold`` (holding); the neutral band holds. The score is\nsourced live from market intelligence each tick, or pinned via\n``sentiment_score``. DISCRETIONARY (SEC framework): targeting\na tokenized SECURITY forces per-execution ``user_confirmed`` at execution\n(crypto stays fully autonomous). Call asset_classification first.\n\n``risk`` / direction params: see ``strategy_dca_create``.","before":"Create a sentiment strategy -- trades an aggregate sentiment score.\n\nBuys when the score is >= ``bull_threshold`` (flat), sells when it is\n<= ``bear_threshold`` (holding); the neutral band holds. The score is\nsourced live from market intelligence each tick, or pinned via\n``sentiment_score``. DISCRETIONARY (SEC framework, ENG-6f4d3513): targeting\na tokenized SECURITY forces per-execution ``user_confirmed`` at execution\n(crypto stays fully autonomous). Call asset_classification first.\n\n``risk`` / direction params: see ``strategy_dca_create``.","detail":"Description of `strategy_sentiment_create` changed (4% word delta).","severity":"safe","descriptionDelta":0.03508771929824561},{"kind":"description_changed","tool":"strategy_stoploss_create","after":"Create a stop-loss / take-profit / trailing-stop monitor on a held position.\n\n``position_amount`` is base units of ``target_token`` to liquidate on\ntrigger. At least one of ``stop_loss_pct`` / ``take_profit_pct`` / a trailing\nconfig should be set (fractions, e.g. 0.15 == 15%).\n\nDirection (optional, deterministic signal): ``direction_mode`` /\n``allow_short`` / ``regime_override`` -- see ``strategy_dca_create``.","before":"Create a stop-loss / take-profit / trailing-stop monitor on a held position.\n\n``position_amount`` is base units of ``target_token`` to liquidate on\ntrigger. At least one of ``stop_loss_pct`` / ``take_profit_pct`` / a trailing\nconfig should be set (fractions, e.g. 0.15 == 15%).\n\nDirection (ENG-bd44b1b7, optional, deterministic signal): ``direction_mode`` /\n``allow_short`` / ``regime_override`` -- see ``strategy_dca_create``.","detail":"Description of `strategy_stoploss_create` changed (4% word delta).","severity":"safe","descriptionDelta":0.0444444444444444},{"kind":"description_changed","tool":"strategy_vault_create","after":"Create a vault strategy -- a target-allocation basket held via rebalancing.\n\nShares the rebalance executor -- identical config/mechanics to\n``strategy_rebalance_create`` (``target_allocation`` mint->weight,\n``drift_threshold_pct``) -- framed as a passive basket rather than an active\nrebalance loop. No external vault/LP deposit (hard rule 1): the\nnon-custodial swap pipeline only rotates spot holdings toward the target\nweights.\n\nDirection (optional, deterministic signal): ``direction_mode`` /\n``allow_short`` / ``regime_override`` -- see ``strategy_dca_create``.","before":"Create a vault strategy -- a target-allocation basket held via rebalancing.\n\nShares the rebalance executor -- identical config/mechanics to\n``strategy_rebalance_create`` (``target_allocation`` mint->weight,\n``drift_threshold_pct``) -- framed as a passive basket rather than an active\nrebalance loop. No external vault/LP deposit (hard rule 1): the\nnon-custodial swap pipeline only rotates spot holdings toward the target\nweights.\n\nDirection (ENG-bd44b1b7, optional, deterministic signal): ``direction_mode`` /\n``allow_short`` / ``regime_override`` -- see ``strategy_dca_create``.","detail":"Description of `strategy_vault_create` changed (3% word delta).","severity":"safe","descriptionDelta":0.03389830508474578},{"kind":"description_changed","tool":"strategy_yield_farm_create","after":"Create a yield-farm strategy -- maintains a target basket allocation.\n\nShares the rebalance executor (config identical to\n``strategy_rebalance_create``): depositing into an external yield protocol\n/ LP position has no faithful swap-pipeline analogue, so this models a\nyield farm as keeping a target allocation across the basket via converging\nrebalance swaps (hard rule 1: the non-custodial pipeline only rotates spot\nholdings, never deposits externally).\n\nDirection (optional, deterministic signal): ``direction_mode`` /\n``allow_short`` / ``regime_override`` -- see ``strategy_dca_create``.","before":"Create a yield-farm strategy -- maintains a target basket allocation.\n\nShares the rebalance executor (config identical to\n``strategy_rebalance_create``): depositing into an external yield protocol\n/ LP position has no faithful swap-pipeline analogue, so this models a\nyield farm as keeping a target allocation across the basket via converging\nrebalance swaps (hard rule 1: the non-custodial pipeline only rotates spot\nholdings, never deposits externally).\n\nDirection (ENG-bd44b1b7, optional, deterministic signal): ``direction_mode`` /\n``allow_short`` / ``regime_override`` -- see ``strategy_dca_create``.","detail":"Description of `strategy_yield_farm_create` changed (3% word delta).","severity":"safe","descriptionDelta":0.032258064516129004},{"kind":"description_changed","tool":"token_info","after":"Token metadata, price, liquidity, volume, holder count.\n\nProvide token_address (mint) or a known symbol. Merges Helius (metadata)\nwith Birdeye (market data).\n\nFree (no technology service fee) -- a read with no transaction notional.","before":"Token metadata, price, liquidity, volume, holder count.\n\nProvide token_address (mint) or a known symbol. Merges Helius (metadata)\nwith Birdeye (market data).\n\nFree (no technology service fee) -- a read with no transaction notional\n(ENG-4a5e0443).","detail":"Description of `token_info` changed (7% word delta).","severity":"safe","descriptionDelta":0.06666666666666665},{"kind":"description_changed","tool":"trade_equity","after":"Spot-trade a tokenized equity (xStocks / Ondo) via Jupiter, non-custodial.\n\nside: buy | sell. amount is in base units of the INPUT token (USDC 6dp for a\nbuy, the equity token for a sell). These are tokenized SECURITIES: the call\nis geo-gated (Reg S = no US persons; declare jurisdiction once via the\njurisdiction arg) and OFAC-screened, and requires per-execution confirmation\n-- WITHOUT confirm=true it returns a quote + disclaimer and does NOT execute\n(no autonomous equity execution). With confirm=true it returns an UNSIGNED\nbase64 tx to sign + broadcast; pass signed_transaction to broadcast a\ncaller-signed tx. Value-bearing: past the daily free tier an x402\npayment_header is required. ip = caller origin IP for the Reg S geo gate\n(US IP -> refused even with an attestation; an agent's Railway Singapore\negress resolves to SG and passes). ``venue_hint`` is ADVISORY, never required -- equity routes via the issuer\nregistry (one surface today); an unknown hint raises.\n\n``idempotency_key`` (optional): see jupiter_swap -- same\nreplay-on-retry semantics, same key reused across build + broadcast.\n\n``verify`` (extending default True): when\nbroadcasting (signed_transaction supplied), await on-chain confirmation\nand re-read the equity mint balance -- the response gains a\n``verification`` block ({confirmed, slot, post_state,\nexpected_vs_actual}). Gate follow-on decisions on\n``verification.confirmed``, never on tx_signature alone. Set False to\nskip for latency-sensitive callers. Verify any prior signature later\nwith the standalone ``verify_transaction`` tool.","before":"Spot-trade a tokenized equity (xStocks / Ondo) via Jupiter, non-custodial.\n\nside: buy | sell. amount is in base units of the INPUT token (USDC 6dp for a\nbuy, the equity token for a sell). These are tokenized SECURITIES: the call\nis geo-gated (Reg S = no US persons; declare jurisdiction once via the\njurisdiction arg) and OFAC-screened, and requires per-execution confirmation\n-- WITHOUT confirm=true it returns a quote + disclaimer and does NOT execute\n(no autonomous equity execution). With confirm=true it returns an UNSIGNED\nbase64 tx to sign + broadcast; pass signed_transaction to broadcast a\ncaller-signed tx. Value-bearing: past the daily free tier an x402\npayment_header is required. ip = caller origin IP for the Reg S geo gate\n(US IP -> refused even with an attestation; an agent's Railway Singapore\negress resolves to SG and passes). ``venue_hint`` (ENG-fc290438/ENG-00ebde90,\nMB#18215) is ADVISORY, never required -- equity routes via the issuer\nregistry (one surface today); an unknown hint raises.\n\n``idempotency_key`` (ENG-7ded4fb8, optional): see jupiter_swap -- same\nreplay-on-retry semantics, same key reused across build + broadcast.\n\n``verify`` (ENG-e932b287, extending ENG-df8afe93, default True): when\nbroadcasting (signed_transaction supplied), await on-chain confirmation\nand re-read the equity mint balance -- the response gains a\n``verification`` block ({confirmed, slot, post_state,\nexpected_vs_actual}). Gate follow-on decisions on\n``verification.confirmed``, never on tx_signature alone. Set False to\nskip for latency-sensitive callers. Verify any prior signature later\nwith the standalone ``verify_transaction`` tool.","detail":"Description of `trade_equity` changed (5% word delta).","severity":"safe","descriptionDelta":0.049079754601227044},{"kind":"description_changed","tool":"unstake_lst","after":"Unstake an LST back to SOL (non-custodial).\n\nlst_token is a mint (mSOL/jitoSOL/bSOL); amount in base units. mSOL routes\nvia Marinade, others via the Sanctum router. Returns an UNSIGNED base64 tx.\nThe technology service fee is charged on the unstaked-LST notional past the\ndaily free tier (x402 payment_header).\n\n``idempotency_key`` (optional): a client-generated UUID.\nRetrying with the same key + same args replays the original result instead\nof re-unstaking.\n\n``signed_transaction`` / ``verify`` (two-phase execution):\nsee liquid_stake -- re-call with the signed tx and Crank broadcasts it,\nconfirms it on-chain, and re-reads the LST + SOL balances.","before":"Unstake an LST back to SOL (non-custodial).\n\nlst_token is a mint (mSOL/jitoSOL/bSOL); amount in base units. mSOL routes\nvia Marinade, others via the Sanctum router. Returns an UNSIGNED base64 tx.\nThe technology service fee is charged on the unstaked-LST notional past the\ndaily free tier (x402 payment_header).\n\n``idempotency_key`` (ENG-7ded4fb8, optional): a client-generated UUID.\nRetrying with the same key + same args replays the original result instead\nof re-unstaking.\n\n``signed_transaction`` / ``verify`` (ENG-dc70e40b, two-phase execution):\nsee liquid_stake -- re-call with the signed tx and Crank broadcasts it,\nconfirms it on-chain, and re-reads the LST + SOL balances.","detail":"Description of `unstake_lst` changed (4% word delta).","severity":"safe","descriptionDelta":0.03749999999999998},{"kind":"description_changed","tool":"verify_token","after":"Multi-layer authenticity check for a token mint (read-only, no execution).\n\nRuns the same five-layer verification the swap/trade tools enforce before\nbuilding a transaction: registry allow-list, Jupiter verified list, Metaplex\nmetadata authority, minimum liquidity, and token age + holder count. Returns\nverification_status (verified | unverified | suspicious | blocked), the\nreasons, non-blocking warnings, and the per-layer findings. Call this before\nswapping into an unfamiliar token.","before":"Multi-layer authenticity check for a token mint (read-only, no execution).\n\nRuns the same five-layer verification the swap/trade tools enforce before\nbuilding a transaction: registry allow-list, Jupiter verified list, Metaplex\nmetadata authority, minimum liquidity, and token age + holder count. Returns\nverification_status (verified | unverified | suspicious | blocked), the\nreasons, non-blocking warnings, and the per-layer findings. Call this before\nswapping into an unfamiliar token (ENG-a39caa6d).","detail":"Description of `verify_token` changed (4% word delta).","severity":"safe","descriptionDelta":0.03508771929824561},{"kind":"description_changed","tool":"verify_transaction","after":"Verify any prior transaction signature on demand (FREE read).\n\nPost-trade verification (harness spec  R13): awaits\non-chain confirmation of ``tx_signature`` at ``commitment`` level (up to\n``timeout_s``) and, when a state hint is supplied, re-reads the relevant\nstate to compare against what was expected:\n\n  - ``mint`` (+ ``wallet_address``): re-reads that SPL/SOL token balance.\n  - ``market`` (+ ``wallet_address``): re-reads the Drift perp position.\n  - ``protocol`` (+ ``wallet_address``, optional ``market`` /\n    ``marginfi_account``): re-reads the lending obligation health.\n\nReturns ``{confirmed, slot, commitment, post_state, expected_vs_actual,\nretry_guidance}``. ``confirmed`` is False (never True) on a timeout --\nNEVER treat an unconfirmed/timed-out result as success; ``retry_guidance``\nnames the next step. Use this after signing + broadcasting a transaction\nyourself (place_perp_order, lend_deposit/borrow/repay, and every other\nunsigned-tx tool never broadcast server-side) to confirm it actually\nlanded before treating the position/balance as changed.","before":"Verify any prior transaction signature on demand (FREE read).\n\nPost-trade verification (ENG-df8afe93, harness spec MB#18289 R13): awaits\non-chain confirmation of ``tx_signature`` at ``commitment`` level (up to\n``timeout_s``) and, when a state hint is supplied, re-reads the relevant\nstate to compare against what was expected:\n\n  - ``mint`` (+ ``wallet_address``): re-reads that SPL/SOL token balance.\n  - ``market`` (+ ``wallet_address``): re-reads the Drift perp position.\n  - ``protocol`` (+ ``wallet_address``, optional ``market`` /\n    ``marginfi_account``): re-reads the lending obligation health.\n\nReturns ``{confirmed, slot, commitment, post_state, expected_vs_actual,\nretry_guidance}``. ``confirmed`` is False (never True) on a timeout --\nNEVER treat an unconfirmed/timed-out result as success; ``retry_guidance``\nnames the next step. Use this after signing + broadcasting a transaction\nyourself (place_perp_order, lend_deposit/borrow/repay, and every other\nunsigned-tx tool never broadcast server-side) to confirm it actually\nlanded before treating the position/balance as changed.","detail":"Description of `verify_transaction` changed (4% word delta).","severity":"safe","descriptionDelta":0.03669724770642202},{"kind":"description_changed","tool":"verify_treasury_settlement_status","after":"On-chain proof the treasury actually received settled x402 USDC.\n\nWires ``services.x402_settlement.verify_treasury_settlement`` (\nreal on-chain proof: treasury USDC ATA balance read as the primary signal,\nplus settle-tx signature confirmation) up to an MCP tool -- the follow-up\nto which intentionally split the on-chain proof\nlogic from this wiring to avoid file collisions across parallel sessions.\n\n``signatures`` is optional: when omitted, this tool pulls recent settled\n``X402PaymentRecord.tx_signature`` values itself (via\n``django_bridge.recent_x402_signatures``, same window shape as\n``reconcile_x402_settlement``) over the last ``since_iso`` window (or all\ntime), capped at ``signature_limit`` to bound RPC round trips -- so a\ncaller does not have to hand-assemble signatures to get a real proof.\nPass an explicit ``signatures`` list to check specific settle-tx hashes\ninstead (bypasses the DB lookup entirely).\n\n``verified`` is True only when every checked signature confirms on-chain\nAND (if ``expected_usd`` is given) the treasury balance covers it -- see\nthe service docstring for the full non-falsely-asserting contract. Raises\nCONFIG_ERROR if no treasury wallet is configured, UPSTREAM_ERROR\n(retryable) on an RPC failure -- never a silent ``verified=False``.\n\nFREE read (never gated, never in x402 PAID_TOOLS): public addresses/\nsignatures/balances only, never a key (hard rule 1).","before":"On-chain proof the treasury actually received settled x402 USDC (ENG-fb2a9462).\n\nWires ``services.x402_settlement.verify_treasury_settlement`` (ENG-1be912ac\nreal on-chain proof: treasury USDC ATA balance read as the primary signal,\nplus settle-tx signature confirmation) up to an MCP tool -- the follow-up\nto ENG-b936ca31/MB#20378, which intentionally split the on-chain proof\nlogic from this wiring to avoid file collisions across parallel sessions.\n\n``signatures`` is optional: when omitted, this tool pulls recent settled\n``X402PaymentRecord.tx_signature`` values itself (via\n``django_bridge.recent_x402_signatures``, same window shape as\n``reconcile_x402_settlement``) over the last ``since_iso`` window (or all\ntime), capped at ``signature_limit`` to bound RPC round trips -- so a\ncaller does not have to hand-assemble signatures to get a real proof.\nPass an explicit ``signatures`` list to check specific settle-tx hashes\ninstead (bypasses the DB lookup entirely).\n\n``verified`` is True only when every checked signature confirms on-chain\nAND (if ``expected_usd`` is given) the treasury balance covers it -- see\nthe service docstring for the full non-falsely-asserting contract. Raises\nCONFIG_ERROR if no treasury wallet is configured, UPSTREAM_ERROR\n(retryable) on an RPC failure -- never a silent ``verified=False``.\n\nFREE read (never gated, never in x402 PAID_TOOLS): public addresses/\nsignatures/balances only, never a key (hard rule 1).","detail":"Description of `verify_treasury_settlement_status` changed (4% word delta).","severity":"safe","descriptionDelta":0.04137931034482756}],"published_at":"2026-08-22T17:23:12.000Z"}]