Check what an install can do with your keys and funds
onchain_agent_check_installBefore installing a crypto package, MCP server or skill, check what it can do with your keys and funds. USE WHEN you are about to run npm/pnpm/yarn/bun add, npx -y, pip install, uvx or claude mcp add, or paste an {"mcpServers": …} config. Pass the command or the config text; every target in it gets a Sato Check custody summary answering four questions: does it take your key, does your key leave, can it move funds on its own, what changed.
Each answer rests on evidence of one class — declared (the project says so), traced (our static read of the published artifact) or observed (a sandbox run with planted test keys). A stored profile answers first; an unstored target is read live within a bounded budget. Targets that could not be profiled are listed in unresolved with the reason. has_observed_key_egress is true only when a planted test key was seen leaving — the one fact to stop on.
RULE ENFORCED: a profile describes what was read and run, with dates. It is not a safety rating, an audit or an endorsement; "unknown" means we could not look, and "none found" is not "not there". Local signing is what a wallet does.
Returns (json): { schema: "sato.custody/v1", subjects: [{ subject, summary: { key_access, key_egress, fund_action_count, notable, version, as_of, check_url }, answers: { key_access, key_egress, fund_actions, changes }, solana_receipt }], unresolved: [{ input, reason }], has_observed_key_egress }. solana_receipt is where that version's reading is recorded on Solana ({ attestation_address, explorer_url, cluster, as_of, digest_hex }), or null when none is. Read-only.
Example: { command: "npm i viem @goat-sdk/core" } · { config: "{"mcpServers":{"wallet":{"command":"npx","args":["-y","some-wallet-mcp"]}}}" }
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| config | No | An MCP config block as text, e.g. {"mcpServers": {...}}. | |
| command | No | An install command, e.g. "npm i @solana/web3.js viem" or "claude mcp add wallet -- npx -y some-wallet-mcp". |