feat(agentkit): Add PolicyCheck action provider for pre-purchase seller verification - #948

Open
vibegpt wants to merge 2 commits into
coinbase:mainfrom
vibegpt:feat/policycheck-action-provider
Open

feat(agentkit): Add PolicyCheck action provider for pre-purchase seller verification#948
vibegpt wants to merge 2 commits into
coinbase:mainfrom
vibegpt:feat/policycheck-action-provider

Conversation

@vibegpt

Copy link
Copy Markdown

Description

Adds a PolicyCheck action provider that enables AI agents to verify e-commerce seller policies before making purchases. This is the first pre-purchase seller verification tool in AgentKit, addressing the WISHLIST item "Integrate with commerce rails for agent payments".

Why this matters

As agentic commerce grows, AI agents need to verify seller trustworthiness before completing purchases. Visa has documented a 25% increase in malicious bot-initiated transactions, with fraudulent storefronts specifically targeting AI shopping agents. Currently, AgentKit has no tool for pre-purchase seller verification.

PolicyCheck fills this gap by analyzing seller return policies, shipping terms, warranty coverage, and terms of service to produce:

  • Risk level (low/medium/high/critical)
  • Buyer protection score (0-100)
  • Key findings (specific policy issues detected)
  • Recommendation (whether to proceed with purchase)

Actions added

ActionDescriptionWallet Required
policycheck_analyzeFull policy analysis from text or URLNo
policycheck_check_urlQuick URL-based seller checkNo

How it works

The action provider calls the PolicyCheck A2A API using the A2A (Agent-to-Agent) protocol via JSON-RPC 2.0. It's a walletless provider — no blockchain interaction needed, works on all networks.

Risk factors detected include:

  • Missing or restrictive return policies
  • Binding arbitration clauses
  • Liability caps and class action waivers
  • No warranty coverage
  • Buyer-pays-return-shipping policies

Usage

import{policycheckActionProvider}from"@coinbase/agentkit";constagentKit=awaitAgentKit.from({actionProviders: [policycheckActionProvider()],});

Tests

13 unit tests covering success paths, error handling, URL delegation, and request format validation.

PASS src/action-providers/policycheck/policycheckActionProvider.test.ts
PolicyCheckActionProvider
constructor
✓ should use default API URL when no config provided
✓ should use custom API URL from config
supportsNetwork
✓ should return true for any network
analyze
✓ should return low-risk assessment for safe seller policies
✓ should return high-risk assessment for risky seller policies
✓ should send seller URL as data part with quick-risk-check skill
✓ should send policy text as text part
✓ should return error for API error response
✓ should return error for HTTP failure
✓ should return error for network failure
✓ should return error when no analysis data in response
✓ should include summary text when available
checkUrl
✓ should delegate to analyze with sellerUrl
Test Suites: 1 passed, 1 total
Tests: 13 passed, 13 total

PolicyCheck is also live in the x402 Bazaar (#1 of 100 resources) and available as an MCP tool.

Checklist

  • Added documentation to all relevant README.md files
  • Added a changelog entry

…er verification
Adds a walletless action provider that enables AI agents to verify
e-commerce seller policies before making purchases. Analyzes return
policies, shipping terms, warranty coverage, and terms of service.
Actions:
- policycheck_analyze: Full policy analysis from text or URL
- policycheck_check_url: Quick URL-based seller check
Returns risk level, buyer protection score (0-100), key findings,
and purchase recommendation via the PolicyCheck A2A API.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@cb-heimdall

cb-heimdall commented Feb 13, 2026

Copy link
Copy Markdown

🟡 Heimdall Review Status

RequirementStatusMore Info
Reviews 🟡 0/1
Denominator calculation
Show calculation
1 if user is bot0
1 if user is external0
2 if repo is sensitive0
From .codeflow.yml1
Additional review requirements
Show calculation
Max0
0
From CODEOWNERS0
Global minimum0
Max 1
1
1 if commit is unverified1
Sum2

@github-actionsgithub-actionsBot added documentation Improvements or additions to documentation action provider New action provider typescript labels Feb 13, 2026
@vibegpt
vibegptforce-pushed the feat/policycheck-action-provider branch from 8bee432 to 37043b4CompareFebruary 14, 2026 15:47
@douglasborthwick-crypto

douglasborthwick-crypto commented Feb 27, 2026

Copy link
Copy Markdown

PolicyCheck covers the off-chain side of seller verification (return policies, shipping info). A complementary on-chain check: verify the seller's wallet holds credentials that indicate trustworthiness before the agent commits to a purchase.

InsumerAPI can add an on-chain trust dimension to AgentKit's pre-purchase flow. POST /v1/trust returns an ECDSA-signed wallet profile — 17 checks across 4 dimensions (stablecoins, governance, NFTs, staking) on 31 chains:

response=requests.post(
"https://api.insumermodel.com/v1/trust",
headers={"X-API-Key": key},
json={"wallet": seller_wallet}
)
trust=response.json()["data"]["trust"]
# trust["dimensions"]["stablecoins"]["passCount"] → USDC presence across 7 chains# trust["dimensions"]["governance"]["passCount"] → UNI, AAVE, ARB, OP holdings# Wallet with diversified holdings = less likely to be a throwaway storefront

A seller with zero on-chain footprint is a different risk profile than one holding governance tokens and stablecoins across multiple chains. On-chain state is hard to fake — it's ground truth.

API docs: https://insumermodel.com/openapi.yaml. There's also an MCP server (mcp-server-insumer on npm) for agents using MCP tool discovery.

@vibegpt

vibegpt commented Feb 27, 2026 via email

Copy link
Copy Markdown
Author

…k intelligence
Walletless action provider with two actions (policycheck_analyze,
policycheck_check_url) that call the PolicyCheck A2A API at
policycheck.tools. Returns risk levels, buyer protection scores,
key findings, and factual summaries.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@vibegpt
vibegptforce-pushed the feat/policycheck-action-provider branch from 37043b4 to 2aedca8CompareFebruary 27, 2026 15:09
@douglasborthwick-crypto

Copy link
Copy Markdown

Thanks @vibegpt — agreed. The two signals are complementary: PolicyCheck tells you what the seller says (policies, terms), on-chain state tells you what the seller has (capital, credentials, history). Both useful for an agent making autonomous purchase decisions.

We recently expanded the trust profiles to 17 checks across 4 dimensions (added staking positions — stETH, rETH, cbETH — as a 4th dimension alongside stablecoins, governance, and NFTs). Happy to collaborate on a combined risk assessment if there's interest.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

action providerNew action providerdocumentationImprovements or additions to documentationtypescript

Development

Successfully merging this pull request may close these issues.

4 participants

@vibegpt@cb-heimdall@douglasborthwick-crypto@Tanker187
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

feat(agentkit): Add PolicyCheck action provider for pre-purchase seller verification - #948

Open
vibegpt wants to merge 2 commits into
coinbase:mainfrom
vibegpt:feat/policycheck-action-provider
Open

feat(agentkit): Add PolicyCheck action provider for pre-purchase seller verification#948
vibegpt wants to merge 2 commits into
coinbase:mainfrom
vibegpt:feat/policycheck-action-provider

Conversation

@vibegpt

Copy link
Copy Markdown

Description

Adds a PolicyCheck action provider that enables AI agents to verify e-commerce seller policies before making purchases. This is the first pre-purchase seller verification tool in AgentKit, addressing the WISHLIST item "Integrate with commerce rails for agent payments".

Why this matters

As agentic commerce grows, AI agents need to verify seller trustworthiness before completing purchases. Visa has documented a 25% increase in malicious bot-initiated transactions, with fraudulent storefronts specifically targeting AI shopping agents. Currently, AgentKit has no tool for pre-purchase seller verification.

PolicyCheck fills this gap by analyzing seller return policies, shipping terms, warranty coverage, and terms of service to produce:

  • Risk level (low/medium/high/critical)
  • Buyer protection score (0-100)
  • Key findings (specific policy issues detected)
  • Recommendation (whether to proceed with purchase)

Actions added

ActionDescriptionWallet Required
policycheck_analyzeFull policy analysis from text or URLNo
policycheck_check_urlQuick URL-based seller checkNo

How it works

The action provider calls the PolicyCheck A2A API using the A2A (Agent-to-Agent) protocol via JSON-RPC 2.0. It's a walletless provider — no blockchain interaction needed, works on all networks.

Risk factors detected include:

  • Missing or restrictive return policies
  • Binding arbitration clauses
  • Liability caps and class action waivers
  • No warranty coverage
  • Buyer-pays-return-shipping policies

Usage

import{policycheckActionProvider}from"@coinbase/agentkit";constagentKit=awaitAgentKit.from({actionProviders: [policycheckActionProvider()],});

Tests

13 unit tests covering success paths, error handling, URL delegation, and request format validation.

PASS src/action-providers/policycheck/policycheckActionProvider.test.ts
PolicyCheckActionProvider
constructor
✓ should use default API URL when no config provided
✓ should use custom API URL from config
supportsNetwork
✓ should return true for any network
analyze
✓ should return low-risk assessment for safe seller policies
✓ should return high-risk assessment for risky seller policies
✓ should send seller URL as data part with quick-risk-check skill
✓ should send policy text as text part
✓ should return error for API error response
✓ should return error for HTTP failure
✓ should return error for network failure
✓ should return error when no analysis data in response
✓ should include summary text when available
checkUrl
✓ should delegate to analyze with sellerUrl
Test Suites: 1 passed, 1 total
Tests: 13 passed, 13 total

PolicyCheck is also live in the x402 Bazaar (#1 of 100 resources) and available as an MCP tool.

Checklist

  • Added documentation to all relevant README.md files
  • Added a changelog entry

…er verification
Adds a walletless action provider that enables AI agents to verify
e-commerce seller policies before making purchases. Analyzes return
policies, shipping terms, warranty coverage, and terms of service.
Actions:
- policycheck_analyze: Full policy analysis from text or URL
- policycheck_check_url: Quick URL-based seller check
Returns risk level, buyer protection score (0-100), key findings,
and purchase recommendation via the PolicyCheck A2A API.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@cb-heimdall

cb-heimdall commented Feb 13, 2026

Copy link
Copy Markdown

🟡 Heimdall Review Status

RequirementStatusMore Info
Reviews 🟡 0/1
Denominator calculation
Show calculation
1 if user is bot0
1 if user is external0
2 if repo is sensitive0
From .codeflow.yml1
Additional review requirements
Show calculation
Max0
0
From CODEOWNERS0
Global minimum0
Max 1
1
1 if commit is unverified1
Sum2

@github-actionsgithub-actionsBot added documentation Improvements or additions to documentation action provider New action provider typescript labels Feb 13, 2026
@vibegpt
vibegptforce-pushed the feat/policycheck-action-provider branch from 8bee432 to 37043b4CompareFebruary 14, 2026 15:47
@douglasborthwick-crypto

douglasborthwick-crypto commented Feb 27, 2026

Copy link
Copy Markdown

PolicyCheck covers the off-chain side of seller verification (return policies, shipping info). A complementary on-chain check: verify the seller's wallet holds credentials that indicate trustworthiness before the agent commits to a purchase.

InsumerAPI can add an on-chain trust dimension to AgentKit's pre-purchase flow. POST /v1/trust returns an ECDSA-signed wallet profile — 17 checks across 4 dimensions (stablecoins, governance, NFTs, staking) on 31 chains:

response=requests.post(
"https://api.insumermodel.com/v1/trust",
headers={"X-API-Key": key},
json={"wallet": seller_wallet}
)
trust=response.json()["data"]["trust"]
# trust["dimensions"]["stablecoins"]["passCount"] → USDC presence across 7 chains# trust["dimensions"]["governance"]["passCount"] → UNI, AAVE, ARB, OP holdings# Wallet with diversified holdings = less likely to be a throwaway storefront

A seller with zero on-chain footprint is a different risk profile than one holding governance tokens and stablecoins across multiple chains. On-chain state is hard to fake — it's ground truth.

API docs: https://insumermodel.com/openapi.yaml. There's also an MCP server (mcp-server-insumer on npm) for agents using MCP tool discovery.

@vibegpt

vibegpt commented Feb 27, 2026 via email

Copy link
Copy Markdown
Author

…k intelligence
Walletless action provider with two actions (policycheck_analyze,
policycheck_check_url) that call the PolicyCheck A2A API at
policycheck.tools. Returns risk levels, buyer protection scores,
key findings, and factual summaries.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@vibegpt
vibegptforce-pushed the feat/policycheck-action-provider branch from 37043b4 to 2aedca8CompareFebruary 27, 2026 15:09
@douglasborthwick-crypto

Copy link
Copy Markdown

Thanks @vibegpt — agreed. The two signals are complementary: PolicyCheck tells you what the seller says (policies, terms), on-chain state tells you what the seller has (capital, credentials, history). Both useful for an agent making autonomous purchase decisions.

We recently expanded the trust profiles to 17 checks across 4 dimensions (added staking positions — stETH, rETH, cbETH — as a 4th dimension alongside stablecoins, governance, and NFTs). Happy to collaborate on a combined risk assessment if there's interest.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

action providerNew action providerdocumentationImprovements or additions to documentationtypescript

Development

Successfully merging this pull request may close these issues.

4 participants

@vibegpt@cb-heimdall@douglasborthwick-crypto@Tanker187
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(agentkit): Add PolicyCheck action provider for pre-purchase seller verification - #948

Open
vibegpt wants to merge 2 commits into
coinbase:mainfrom
vibegpt:feat/policycheck-action-provider
Open

feat(agentkit): Add PolicyCheck action provider for pre-purchase seller verification#948
vibegpt wants to merge 2 commits into
coinbase:mainfrom
vibegpt:feat/policycheck-action-provider

Conversation

@vibegpt

Copy link
Copy Markdown

Description

Adds a PolicyCheck action provider that enables AI agents to verify e-commerce seller policies before making purchases. This is the first pre-purchase seller verification tool in AgentKit, addressing the WISHLIST item "Integrate with commerce rails for agent payments".

Why this matters

As agentic commerce grows, AI agents need to verify seller trustworthiness before completing purchases. Visa has documented a 25% increase in malicious bot-initiated transactions, with fraudulent storefronts specifically targeting AI shopping agents. Currently, AgentKit has no tool for pre-purchase seller verification.

PolicyCheck fills this gap by analyzing seller return policies, shipping terms, warranty coverage, and terms of service to produce:

  • Risk level (low/medium/high/critical)
  • Buyer protection score (0-100)
  • Key findings (specific policy issues detected)
  • Recommendation (whether to proceed with purchase)

Actions added

ActionDescriptionWallet Required
policycheck_analyzeFull policy analysis from text or URLNo
policycheck_check_urlQuick URL-based seller checkNo

How it works

The action provider calls the PolicyCheck A2A API using the A2A (Agent-to-Agent) protocol via JSON-RPC 2.0. It's a walletless provider — no blockchain interaction needed, works on all networks.

Risk factors detected include:

  • Missing or restrictive return policies
  • Binding arbitration clauses
  • Liability caps and class action waivers
  • No warranty coverage
  • Buyer-pays-return-shipping policies

Usage

import{policycheckActionProvider}from"@coinbase/agentkit";constagentKit=awaitAgentKit.from({actionProviders: [policycheckActionProvider()],});

Tests

13 unit tests covering success paths, error handling, URL delegation, and request format validation.

PASS src/action-providers/policycheck/policycheckActionProvider.test.ts
PolicyCheckActionProvider
constructor
✓ should use default API URL when no config provided
✓ should use custom API URL from config
supportsNetwork
✓ should return true for any network
analyze
✓ should return low-risk assessment for safe seller policies
✓ should return high-risk assessment for risky seller policies
✓ should send seller URL as data part with quick-risk-check skill
✓ should send policy text as text part
✓ should return error for API error response
✓ should return error for HTTP failure
✓ should return error for network failure
✓ should return error when no analysis data in response
✓ should include summary text when available
checkUrl
✓ should delegate to analyze with sellerUrl
Test Suites: 1 passed, 1 total
Tests: 13 passed, 13 total

PolicyCheck is also live in the x402 Bazaar (#1 of 100 resources) and available as an MCP tool.

Checklist

  • Added documentation to all relevant README.md files
  • Added a changelog entry

…er verification
Adds a walletless action provider that enables AI agents to verify
e-commerce seller policies before making purchases. Analyzes return
policies, shipping terms, warranty coverage, and terms of service.
Actions:
- policycheck_analyze: Full policy analysis from text or URL
- policycheck_check_url: Quick URL-based seller check
Returns risk level, buyer protection score (0-100), key findings,
and purchase recommendation via the PolicyCheck A2A API.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@cb-heimdall

cb-heimdall commented Feb 13, 2026

Copy link
Copy Markdown

🟡 Heimdall Review Status

RequirementStatusMore Info
Reviews 🟡 0/1
Denominator calculation
Show calculation
1 if user is bot0
1 if user is external0
2 if repo is sensitive0
From .codeflow.yml1
Additional review requirements
Show calculation
Max0
0
From CODEOWNERS0
Global minimum0
Max 1
1
1 if commit is unverified1
Sum2

@github-actionsgithub-actionsBot added documentation Improvements or additions to documentation action provider New action provider typescript labels Feb 13, 2026
@vibegpt
vibegptforce-pushed the feat/policycheck-action-provider branch from 8bee432 to 37043b4CompareFebruary 14, 2026 15:47
@douglasborthwick-crypto

douglasborthwick-crypto commented Feb 27, 2026

Copy link
Copy Markdown

PolicyCheck covers the off-chain side of seller verification (return policies, shipping info). A complementary on-chain check: verify the seller's wallet holds credentials that indicate trustworthiness before the agent commits to a purchase.

InsumerAPI can add an on-chain trust dimension to AgentKit's pre-purchase flow. POST /v1/trust returns an ECDSA-signed wallet profile — 17 checks across 4 dimensions (stablecoins, governance, NFTs, staking) on 31 chains:

response=requests.post(
"https://api.insumermodel.com/v1/trust",
headers={"X-API-Key": key},
json={"wallet": seller_wallet}
)
trust=response.json()["data"]["trust"]
# trust["dimensions"]["stablecoins"]["passCount"] → USDC presence across 7 chains# trust["dimensions"]["governance"]["passCount"] → UNI, AAVE, ARB, OP holdings# Wallet with diversified holdings = less likely to be a throwaway storefront

A seller with zero on-chain footprint is a different risk profile than one holding governance tokens and stablecoins across multiple chains. On-chain state is hard to fake — it's ground truth.

API docs: https://insumermodel.com/openapi.yaml. There's also an MCP server (mcp-server-insumer on npm) for agents using MCP tool discovery.

@vibegpt

vibegpt commented Feb 27, 2026 via email

Copy link
Copy Markdown
Author

…k intelligence
Walletless action provider with two actions (policycheck_analyze,
policycheck_check_url) that call the PolicyCheck A2A API at
policycheck.tools. Returns risk levels, buyer protection scores,
key findings, and factual summaries.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@vibegpt
vibegptforce-pushed the feat/policycheck-action-provider branch from 37043b4 to 2aedca8CompareFebruary 27, 2026 15:09
@douglasborthwick-crypto

Copy link
Copy Markdown

Thanks @vibegpt — agreed. The two signals are complementary: PolicyCheck tells you what the seller says (policies, terms), on-chain state tells you what the seller has (capital, credentials, history). Both useful for an agent making autonomous purchase decisions.

We recently expanded the trust profiles to 17 checks across 4 dimensions (added staking positions — stETH, rETH, cbETH — as a 4th dimension alongside stablecoins, governance, and NFTs). Happy to collaborate on a combined risk assessment if there's interest.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

action providerNew action providerdocumentationImprovements or additions to documentationtypescript

Development

Successfully merging this pull request may close these issues.

4 participants

@vibegpt@cb-heimdall@douglasborthwick-crypto@Tanker187
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(agentkit): Add PolicyCheck action provider for pre-purchase seller verification - #948

Open
vibegpt wants to merge 2 commits into
coinbase:mainfrom
vibegpt:feat/policycheck-action-provider
Open

feat(agentkit): Add PolicyCheck action provider for pre-purchase seller verification#948
vibegpt wants to merge 2 commits into
coinbase:mainfrom
vibegpt:feat/policycheck-action-provider

Conversation

@vibegpt

Copy link
Copy Markdown

Description

Adds a PolicyCheck action provider that enables AI agents to verify e-commerce seller policies before making purchases. This is the first pre-purchase seller verification tool in AgentKit, addressing the WISHLIST item "Integrate with commerce rails for agent payments".

Why this matters

As agentic commerce grows, AI agents need to verify seller trustworthiness before completing purchases. Visa has documented a 25% increase in malicious bot-initiated transactions, with fraudulent storefronts specifically targeting AI shopping agents. Currently, AgentKit has no tool for pre-purchase seller verification.

PolicyCheck fills this gap by analyzing seller return policies, shipping terms, warranty coverage, and terms of service to produce:

  • Risk level (low/medium/high/critical)
  • Buyer protection score (0-100)
  • Key findings (specific policy issues detected)
  • Recommendation (whether to proceed with purchase)

Actions added

ActionDescriptionWallet Required
policycheck_analyzeFull policy analysis from text or URLNo
policycheck_check_urlQuick URL-based seller checkNo

How it works

The action provider calls the PolicyCheck A2A API using the A2A (Agent-to-Agent) protocol via JSON-RPC 2.0. It's a walletless provider — no blockchain interaction needed, works on all networks.

Risk factors detected include:

  • Missing or restrictive return policies
  • Binding arbitration clauses
  • Liability caps and class action waivers
  • No warranty coverage
  • Buyer-pays-return-shipping policies

Usage

import{policycheckActionProvider}from"@coinbase/agentkit";constagentKit=awaitAgentKit.from({actionProviders: [policycheckActionProvider()],});

Tests

13 unit tests covering success paths, error handling, URL delegation, and request format validation.

PASS src/action-providers/policycheck/policycheckActionProvider.test.ts
PolicyCheckActionProvider
constructor
✓ should use default API URL when no config provided
✓ should use custom API URL from config
supportsNetwork
✓ should return true for any network
analyze
✓ should return low-risk assessment for safe seller policies
✓ should return high-risk assessment for risky seller policies
✓ should send seller URL as data part with quick-risk-check skill
✓ should send policy text as text part
✓ should return error for API error response
✓ should return error for HTTP failure
✓ should return error for network failure
✓ should return error when no analysis data in response
✓ should include summary text when available
checkUrl
✓ should delegate to analyze with sellerUrl
Test Suites: 1 passed, 1 total
Tests: 13 passed, 13 total

PolicyCheck is also live in the x402 Bazaar (#1 of 100 resources) and available as an MCP tool.

Checklist

  • Added documentation to all relevant README.md files
  • Added a changelog entry

…er verification
Adds a walletless action provider that enables AI agents to verify
e-commerce seller policies before making purchases. Analyzes return
policies, shipping terms, warranty coverage, and terms of service.
Actions:
- policycheck_analyze: Full policy analysis from text or URL
- policycheck_check_url: Quick URL-based seller check
Returns risk level, buyer protection score (0-100), key findings,
and purchase recommendation via the PolicyCheck A2A API.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@cb-heimdall

cb-heimdall commented Feb 13, 2026

Copy link
Copy Markdown

🟡 Heimdall Review Status

RequirementStatusMore Info
Reviews 🟡 0/1
Denominator calculation
Show calculation
1 if user is bot0
1 if user is external0
2 if repo is sensitive0
From .codeflow.yml1
Additional review requirements
Show calculation
Max0
0
From CODEOWNERS0
Global minimum0
Max 1
1
1 if commit is unverified1
Sum2

@github-actionsgithub-actionsBot added documentation Improvements or additions to documentation action provider New action provider typescript labels Feb 13, 2026
@vibegpt
vibegptforce-pushed the feat/policycheck-action-provider branch from 8bee432 to 37043b4CompareFebruary 14, 2026 15:47
@douglasborthwick-crypto

douglasborthwick-crypto commented Feb 27, 2026

Copy link
Copy Markdown

PolicyCheck covers the off-chain side of seller verification (return policies, shipping info). A complementary on-chain check: verify the seller's wallet holds credentials that indicate trustworthiness before the agent commits to a purchase.

InsumerAPI can add an on-chain trust dimension to AgentKit's pre-purchase flow. POST /v1/trust returns an ECDSA-signed wallet profile — 17 checks across 4 dimensions (stablecoins, governance, NFTs, staking) on 31 chains:

response=requests.post(
"https://api.insumermodel.com/v1/trust",
headers={"X-API-Key": key},
json={"wallet": seller_wallet}
)
trust=response.json()["data"]["trust"]
# trust["dimensions"]["stablecoins"]["passCount"] → USDC presence across 7 chains# trust["dimensions"]["governance"]["passCount"] → UNI, AAVE, ARB, OP holdings# Wallet with diversified holdings = less likely to be a throwaway storefront

A seller with zero on-chain footprint is a different risk profile than one holding governance tokens and stablecoins across multiple chains. On-chain state is hard to fake — it's ground truth.

API docs: https://insumermodel.com/openapi.yaml. There's also an MCP server (mcp-server-insumer on npm) for agents using MCP tool discovery.

@vibegpt

vibegpt commented Feb 27, 2026 via email

Copy link
Copy Markdown
Author

…k intelligence
Walletless action provider with two actions (policycheck_analyze,
policycheck_check_url) that call the PolicyCheck A2A API at
policycheck.tools. Returns risk levels, buyer protection scores,
key findings, and factual summaries.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@vibegpt
vibegptforce-pushed the feat/policycheck-action-provider branch from 37043b4 to 2aedca8CompareFebruary 27, 2026 15:09
@douglasborthwick-crypto

Copy link
Copy Markdown

Thanks @vibegpt — agreed. The two signals are complementary: PolicyCheck tells you what the seller says (policies, terms), on-chain state tells you what the seller has (capital, credentials, history). Both useful for an agent making autonomous purchase decisions.

We recently expanded the trust profiles to 17 checks across 4 dimensions (added staking positions — stETH, rETH, cbETH — as a 4th dimension alongside stablecoins, governance, and NFTs). Happy to collaborate on a combined risk assessment if there's interest.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

action providerNew action providerdocumentationImprovements or additions to documentationtypescript

Development

Successfully merging this pull request may close these issues.

4 participants

@vibegpt@cb-heimdall@douglasborthwick-crypto@Tanker187
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

feat(agentkit): Add PolicyCheck action provider for pre-purchase seller verification - #948

Open
vibegpt wants to merge 2 commits into
coinbase:mainfrom
vibegpt:feat/policycheck-action-provider
Open

feat(agentkit): Add PolicyCheck action provider for pre-purchase seller verification#948
vibegpt wants to merge 2 commits into
coinbase:mainfrom
vibegpt:feat/policycheck-action-provider

Conversation

@vibegpt

Copy link
Copy Markdown

Description

Adds a PolicyCheck action provider that enables AI agents to verify e-commerce seller policies before making purchases. This is the first pre-purchase seller verification tool in AgentKit, addressing the WISHLIST item "Integrate with commerce rails for agent payments".

Why this matters

As agentic commerce grows, AI agents need to verify seller trustworthiness before completing purchases. Visa has documented a 25% increase in malicious bot-initiated transactions, with fraudulent storefronts specifically targeting AI shopping agents. Currently, AgentKit has no tool for pre-purchase seller verification.

PolicyCheck fills this gap by analyzing seller return policies, shipping terms, warranty coverage, and terms of service to produce:

  • Risk level (low/medium/high/critical)
  • Buyer protection score (0-100)
  • Key findings (specific policy issues detected)
  • Recommendation (whether to proceed with purchase)

Actions added

ActionDescriptionWallet Required
policycheck_analyzeFull policy analysis from text or URLNo
policycheck_check_urlQuick URL-based seller checkNo

How it works

The action provider calls the PolicyCheck A2A API using the A2A (Agent-to-Agent) protocol via JSON-RPC 2.0. It's a walletless provider — no blockchain interaction needed, works on all networks.

Risk factors detected include:

  • Missing or restrictive return policies
  • Binding arbitration clauses
  • Liability caps and class action waivers
  • No warranty coverage
  • Buyer-pays-return-shipping policies

Usage

import{policycheckActionProvider}from"@coinbase/agentkit";constagentKit=awaitAgentKit.from({actionProviders: [policycheckActionProvider()],});

Tests

13 unit tests covering success paths, error handling, URL delegation, and request format validation.

PASS src/action-providers/policycheck/policycheckActionProvider.test.ts
PolicyCheckActionProvider
constructor
✓ should use default API URL when no config provided
✓ should use custom API URL from config
supportsNetwork
✓ should return true for any network
analyze
✓ should return low-risk assessment for safe seller policies
✓ should return high-risk assessment for risky seller policies
✓ should send seller URL as data part with quick-risk-check skill
✓ should send policy text as text part
✓ should return error for API error response
✓ should return error for HTTP failure
✓ should return error for network failure
✓ should return error when no analysis data in response
✓ should include summary text when available
checkUrl
✓ should delegate to analyze with sellerUrl
Test Suites: 1 passed, 1 total
Tests: 13 passed, 13 total

PolicyCheck is also live in the x402 Bazaar (#1 of 100 resources) and available as an MCP tool.

Checklist

  • Added documentation to all relevant README.md files
  • Added a changelog entry

…er verification
Adds a walletless action provider that enables AI agents to verify
e-commerce seller policies before making purchases. Analyzes return
policies, shipping terms, warranty coverage, and terms of service.
Actions:
- policycheck_analyze: Full policy analysis from text or URL
- policycheck_check_url: Quick URL-based seller check
Returns risk level, buyer protection score (0-100), key findings,
and purchase recommendation via the PolicyCheck A2A API.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@cb-heimdall

cb-heimdall commented Feb 13, 2026

Copy link
Copy Markdown

🟡 Heimdall Review Status

RequirementStatusMore Info
Reviews 🟡 0/1
Denominator calculation
Show calculation
1 if user is bot0
1 if user is external0
2 if repo is sensitive0
From .codeflow.yml1
Additional review requirements
Show calculation
Max0
0
From CODEOWNERS0
Global minimum0
Max 1
1
1 if commit is unverified1
Sum2

@github-actionsgithub-actionsBot added documentation Improvements or additions to documentation action provider New action provider typescript labels Feb 13, 2026
@vibegpt
vibegptforce-pushed the feat/policycheck-action-provider branch from 8bee432 to 37043b4CompareFebruary 14, 2026 15:47
@douglasborthwick-crypto

douglasborthwick-crypto commented Feb 27, 2026

Copy link
Copy Markdown

PolicyCheck covers the off-chain side of seller verification (return policies, shipping info). A complementary on-chain check: verify the seller's wallet holds credentials that indicate trustworthiness before the agent commits to a purchase.

InsumerAPI can add an on-chain trust dimension to AgentKit's pre-purchase flow. POST /v1/trust returns an ECDSA-signed wallet profile — 17 checks across 4 dimensions (stablecoins, governance, NFTs, staking) on 31 chains:

response=requests.post(
"https://api.insumermodel.com/v1/trust",
headers={"X-API-Key": key},
json={"wallet": seller_wallet}
)
trust=response.json()["data"]["trust"]
# trust["dimensions"]["stablecoins"]["passCount"] → USDC presence across 7 chains# trust["dimensions"]["governance"]["passCount"] → UNI, AAVE, ARB, OP holdings# Wallet with diversified holdings = less likely to be a throwaway storefront

A seller with zero on-chain footprint is a different risk profile than one holding governance tokens and stablecoins across multiple chains. On-chain state is hard to fake — it's ground truth.

API docs: https://insumermodel.com/openapi.yaml. There's also an MCP server (mcp-server-insumer on npm) for agents using MCP tool discovery.

@vibegpt

vibegpt commented Feb 27, 2026 via email

Copy link
Copy Markdown
Author

…k intelligence
Walletless action provider with two actions (policycheck_analyze,
policycheck_check_url) that call the PolicyCheck A2A API at
policycheck.tools. Returns risk levels, buyer protection scores,
key findings, and factual summaries.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@vibegpt
vibegptforce-pushed the feat/policycheck-action-provider branch from 37043b4 to 2aedca8CompareFebruary 27, 2026 15:09
@douglasborthwick-crypto

Copy link
Copy Markdown

Thanks @vibegpt — agreed. The two signals are complementary: PolicyCheck tells you what the seller says (policies, terms), on-chain state tells you what the seller has (capital, credentials, history). Both useful for an agent making autonomous purchase decisions.

We recently expanded the trust profiles to 17 checks across 4 dimensions (added staking positions — stETH, rETH, cbETH — as a 4th dimension alongside stablecoins, governance, and NFTs). Happy to collaborate on a combined risk assessment if there's interest.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

action providerNew action providerdocumentationImprovements or additions to documentationtypescript

Development

Successfully merging this pull request may close these issues.

4 participants

@vibegpt@cb-heimdall@douglasborthwick-crypto@Tanker187
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(agentkit): Add PolicyCheck action provider for pre-purchase seller verification - #948

Open
vibegpt wants to merge 2 commits into
coinbase:mainfrom
vibegpt:feat/policycheck-action-provider
Open

feat(agentkit): Add PolicyCheck action provider for pre-purchase seller verification#948
vibegpt wants to merge 2 commits into
coinbase:mainfrom
vibegpt:feat/policycheck-action-provider

Conversation

@vibegpt

Copy link
Copy Markdown

Description

Adds a PolicyCheck action provider that enables AI agents to verify e-commerce seller policies before making purchases. This is the first pre-purchase seller verification tool in AgentKit, addressing the WISHLIST item "Integrate with commerce rails for agent payments".

Why this matters

As agentic commerce grows, AI agents need to verify seller trustworthiness before completing purchases. Visa has documented a 25% increase in malicious bot-initiated transactions, with fraudulent storefronts specifically targeting AI shopping agents. Currently, AgentKit has no tool for pre-purchase seller verification.

PolicyCheck fills this gap by analyzing seller return policies, shipping terms, warranty coverage, and terms of service to produce:

  • Risk level (low/medium/high/critical)
  • Buyer protection score (0-100)
  • Key findings (specific policy issues detected)
  • Recommendation (whether to proceed with purchase)

Actions added

ActionDescriptionWallet Required
policycheck_analyzeFull policy analysis from text or URLNo
policycheck_check_urlQuick URL-based seller checkNo

How it works

The action provider calls the PolicyCheck A2A API using the A2A (Agent-to-Agent) protocol via JSON-RPC 2.0. It's a walletless provider — no blockchain interaction needed, works on all networks.

Risk factors detected include:

  • Missing or restrictive return policies
  • Binding arbitration clauses
  • Liability caps and class action waivers
  • No warranty coverage
  • Buyer-pays-return-shipping policies

Usage

import{policycheckActionProvider}from"@coinbase/agentkit";constagentKit=awaitAgentKit.from({actionProviders: [policycheckActionProvider()],});

Tests

13 unit tests covering success paths, error handling, URL delegation, and request format validation.

PASS src/action-providers/policycheck/policycheckActionProvider.test.ts
PolicyCheckActionProvider
constructor
✓ should use default API URL when no config provided
✓ should use custom API URL from config
supportsNetwork
✓ should return true for any network
analyze
✓ should return low-risk assessment for safe seller policies
✓ should return high-risk assessment for risky seller policies
✓ should send seller URL as data part with quick-risk-check skill
✓ should send policy text as text part
✓ should return error for API error response
✓ should return error for HTTP failure
✓ should return error for network failure
✓ should return error when no analysis data in response
✓ should include summary text when available
checkUrl
✓ should delegate to analyze with sellerUrl
Test Suites: 1 passed, 1 total
Tests: 13 passed, 13 total

PolicyCheck is also live in the x402 Bazaar (#1 of 100 resources) and available as an MCP tool.

Checklist

  • Added documentation to all relevant README.md files
  • Added a changelog entry

…er verification
Adds a walletless action provider that enables AI agents to verify
e-commerce seller policies before making purchases. Analyzes return
policies, shipping terms, warranty coverage, and terms of service.
Actions:
- policycheck_analyze: Full policy analysis from text or URL
- policycheck_check_url: Quick URL-based seller check
Returns risk level, buyer protection score (0-100), key findings,
and purchase recommendation via the PolicyCheck A2A API.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@cb-heimdall

cb-heimdall commented Feb 13, 2026

Copy link
Copy Markdown

🟡 Heimdall Review Status

RequirementStatusMore Info
Reviews 🟡 0/1
Denominator calculation
Show calculation
1 if user is bot0
1 if user is external0
2 if repo is sensitive0
From .codeflow.yml1
Additional review requirements
Show calculation
Max0
0
From CODEOWNERS0
Global minimum0
Max 1
1
1 if commit is unverified1
Sum2

@github-actionsgithub-actionsBot added documentation Improvements or additions to documentation action provider New action provider typescript labels Feb 13, 2026
@vibegpt
vibegptforce-pushed the feat/policycheck-action-provider branch from 8bee432 to 37043b4CompareFebruary 14, 2026 15:47
@douglasborthwick-crypto

douglasborthwick-crypto commented Feb 27, 2026

Copy link
Copy Markdown

PolicyCheck covers the off-chain side of seller verification (return policies, shipping info). A complementary on-chain check: verify the seller's wallet holds credentials that indicate trustworthiness before the agent commits to a purchase.

InsumerAPI can add an on-chain trust dimension to AgentKit's pre-purchase flow. POST /v1/trust returns an ECDSA-signed wallet profile — 17 checks across 4 dimensions (stablecoins, governance, NFTs, staking) on 31 chains:

response=requests.post(
"https://api.insumermodel.com/v1/trust",
headers={"X-API-Key": key},
json={"wallet": seller_wallet}
)
trust=response.json()["data"]["trust"]
# trust["dimensions"]["stablecoins"]["passCount"] → USDC presence across 7 chains# trust["dimensions"]["governance"]["passCount"] → UNI, AAVE, ARB, OP holdings# Wallet with diversified holdings = less likely to be a throwaway storefront

A seller with zero on-chain footprint is a different risk profile than one holding governance tokens and stablecoins across multiple chains. On-chain state is hard to fake — it's ground truth.

API docs: https://insumermodel.com/openapi.yaml. There's also an MCP server (mcp-server-insumer on npm) for agents using MCP tool discovery.

@vibegpt

vibegpt commented Feb 27, 2026 via email

Copy link
Copy Markdown
Author

…k intelligence
Walletless action provider with two actions (policycheck_analyze,
policycheck_check_url) that call the PolicyCheck A2A API at
policycheck.tools. Returns risk levels, buyer protection scores,
key findings, and factual summaries.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@vibegpt
vibegptforce-pushed the feat/policycheck-action-provider branch from 37043b4 to 2aedca8CompareFebruary 27, 2026 15:09
@douglasborthwick-crypto

Copy link
Copy Markdown

Thanks @vibegpt — agreed. The two signals are complementary: PolicyCheck tells you what the seller says (policies, terms), on-chain state tells you what the seller has (capital, credentials, history). Both useful for an agent making autonomous purchase decisions.

We recently expanded the trust profiles to 17 checks across 4 dimensions (added staking positions — stETH, rETH, cbETH — as a 4th dimension alongside stablecoins, governance, and NFTs). Happy to collaborate on a combined risk assessment if there's interest.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

action providerNew action providerdocumentationImprovements or additions to documentationtypescript

Development

Successfully merging this pull request may close these issues.

4 participants

@vibegpt@cb-heimdall@douglasborthwick-crypto@Tanker187
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(agentkit): Add PolicyCheck action provider for pre-purchase seller verification - #948

Open
vibegpt wants to merge 2 commits into
coinbase:mainfrom
vibegpt:feat/policycheck-action-provider
Open

feat(agentkit): Add PolicyCheck action provider for pre-purchase seller verification#948
vibegpt wants to merge 2 commits into
coinbase:mainfrom
vibegpt:feat/policycheck-action-provider

Conversation

@vibegpt

Copy link
Copy Markdown

Description

Adds a PolicyCheck action provider that enables AI agents to verify e-commerce seller policies before making purchases. This is the first pre-purchase seller verification tool in AgentKit, addressing the WISHLIST item "Integrate with commerce rails for agent payments".

Why this matters

As agentic commerce grows, AI agents need to verify seller trustworthiness before completing purchases. Visa has documented a 25% increase in malicious bot-initiated transactions, with fraudulent storefronts specifically targeting AI shopping agents. Currently, AgentKit has no tool for pre-purchase seller verification.

PolicyCheck fills this gap by analyzing seller return policies, shipping terms, warranty coverage, and terms of service to produce:

  • Risk level (low/medium/high/critical)
  • Buyer protection score (0-100)
  • Key findings (specific policy issues detected)
  • Recommendation (whether to proceed with purchase)

Actions added

ActionDescriptionWallet Required
policycheck_analyzeFull policy analysis from text or URLNo
policycheck_check_urlQuick URL-based seller checkNo

How it works

The action provider calls the PolicyCheck A2A API using the A2A (Agent-to-Agent) protocol via JSON-RPC 2.0. It's a walletless provider — no blockchain interaction needed, works on all networks.

Risk factors detected include:

  • Missing or restrictive return policies
  • Binding arbitration clauses
  • Liability caps and class action waivers
  • No warranty coverage
  • Buyer-pays-return-shipping policies

Usage

import{policycheckActionProvider}from"@coinbase/agentkit";constagentKit=awaitAgentKit.from({actionProviders: [policycheckActionProvider()],});

Tests

13 unit tests covering success paths, error handling, URL delegation, and request format validation.

PASS src/action-providers/policycheck/policycheckActionProvider.test.ts
PolicyCheckActionProvider
constructor
✓ should use default API URL when no config provided
✓ should use custom API URL from config
supportsNetwork
✓ should return true for any network
analyze
✓ should return low-risk assessment for safe seller policies
✓ should return high-risk assessment for risky seller policies
✓ should send seller URL as data part with quick-risk-check skill
✓ should send policy text as text part
✓ should return error for API error response
✓ should return error for HTTP failure
✓ should return error for network failure
✓ should return error when no analysis data in response
✓ should include summary text when available
checkUrl
✓ should delegate to analyze with sellerUrl
Test Suites: 1 passed, 1 total
Tests: 13 passed, 13 total

PolicyCheck is also live in the x402 Bazaar (#1 of 100 resources) and available as an MCP tool.

Checklist

  • Added documentation to all relevant README.md files
  • Added a changelog entry

…er verification
Adds a walletless action provider that enables AI agents to verify
e-commerce seller policies before making purchases. Analyzes return
policies, shipping terms, warranty coverage, and terms of service.
Actions:
- policycheck_analyze: Full policy analysis from text or URL
- policycheck_check_url: Quick URL-based seller check
Returns risk level, buyer protection score (0-100), key findings,
and purchase recommendation via the PolicyCheck A2A API.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@cb-heimdall

cb-heimdall commented Feb 13, 2026

Copy link
Copy Markdown

🟡 Heimdall Review Status

RequirementStatusMore Info
Reviews 🟡 0/1
Denominator calculation
Show calculation
1 if user is bot0
1 if user is external0
2 if repo is sensitive0
From .codeflow.yml1
Additional review requirements
Show calculation
Max0
0
From CODEOWNERS0
Global minimum0
Max 1
1
1 if commit is unverified1
Sum2

@github-actionsgithub-actionsBot added documentation Improvements or additions to documentation action provider New action provider typescript labels Feb 13, 2026
@vibegpt
vibegptforce-pushed the feat/policycheck-action-provider branch from 8bee432 to 37043b4CompareFebruary 14, 2026 15:47
@douglasborthwick-crypto

douglasborthwick-crypto commented Feb 27, 2026

Copy link
Copy Markdown

PolicyCheck covers the off-chain side of seller verification (return policies, shipping info). A complementary on-chain check: verify the seller's wallet holds credentials that indicate trustworthiness before the agent commits to a purchase.

InsumerAPI can add an on-chain trust dimension to AgentKit's pre-purchase flow. POST /v1/trust returns an ECDSA-signed wallet profile — 17 checks across 4 dimensions (stablecoins, governance, NFTs, staking) on 31 chains:

response=requests.post(
"https://api.insumermodel.com/v1/trust",
headers={"X-API-Key": key},
json={"wallet": seller_wallet}
)
trust=response.json()["data"]["trust"]
# trust["dimensions"]["stablecoins"]["passCount"] → USDC presence across 7 chains# trust["dimensions"]["governance"]["passCount"] → UNI, AAVE, ARB, OP holdings# Wallet with diversified holdings = less likely to be a throwaway storefront

A seller with zero on-chain footprint is a different risk profile than one holding governance tokens and stablecoins across multiple chains. On-chain state is hard to fake — it's ground truth.

API docs: https://insumermodel.com/openapi.yaml. There's also an MCP server (mcp-server-insumer on npm) for agents using MCP tool discovery.

@vibegpt

vibegpt commented Feb 27, 2026 via email

Copy link
Copy Markdown
Author

…k intelligence
Walletless action provider with two actions (policycheck_analyze,
policycheck_check_url) that call the PolicyCheck A2A API at
policycheck.tools. Returns risk levels, buyer protection scores,
key findings, and factual summaries.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@vibegpt
vibegptforce-pushed the feat/policycheck-action-provider branch from 37043b4 to 2aedca8CompareFebruary 27, 2026 15:09
@douglasborthwick-crypto

Copy link
Copy Markdown

Thanks @vibegpt — agreed. The two signals are complementary: PolicyCheck tells you what the seller says (policies, terms), on-chain state tells you what the seller has (capital, credentials, history). Both useful for an agent making autonomous purchase decisions.

We recently expanded the trust profiles to 17 checks across 4 dimensions (added staking positions — stETH, rETH, cbETH — as a 4th dimension alongside stablecoins, governance, and NFTs). Happy to collaborate on a combined risk assessment if there's interest.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

action providerNew action providerdocumentationImprovements or additions to documentationtypescript

Development

Successfully merging this pull request may close these issues.

4 participants

@vibegpt@cb-heimdall@douglasborthwick-crypto@Tanker187
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

feat(agentkit): Add PolicyCheck action provider for pre-purchase seller verification - #948

Open
vibegpt wants to merge 2 commits into
coinbase:mainfrom
vibegpt:feat/policycheck-action-provider
Open

feat(agentkit): Add PolicyCheck action provider for pre-purchase seller verification#948
vibegpt wants to merge 2 commits into
coinbase:mainfrom
vibegpt:feat/policycheck-action-provider

Conversation

@vibegpt

Copy link
Copy Markdown

Description

Adds a PolicyCheck action provider that enables AI agents to verify e-commerce seller policies before making purchases. This is the first pre-purchase seller verification tool in AgentKit, addressing the WISHLIST item "Integrate with commerce rails for agent payments".

Why this matters

As agentic commerce grows, AI agents need to verify seller trustworthiness before completing purchases. Visa has documented a 25% increase in malicious bot-initiated transactions, with fraudulent storefronts specifically targeting AI shopping agents. Currently, AgentKit has no tool for pre-purchase seller verification.

PolicyCheck fills this gap by analyzing seller return policies, shipping terms, warranty coverage, and terms of service to produce:

  • Risk level (low/medium/high/critical)
  • Buyer protection score (0-100)
  • Key findings (specific policy issues detected)
  • Recommendation (whether to proceed with purchase)

Actions added

ActionDescriptionWallet Required
policycheck_analyzeFull policy analysis from text or URLNo
policycheck_check_urlQuick URL-based seller checkNo

How it works

The action provider calls the PolicyCheck A2A API using the A2A (Agent-to-Agent) protocol via JSON-RPC 2.0. It's a walletless provider — no blockchain interaction needed, works on all networks.

Risk factors detected include:

  • Missing or restrictive return policies
  • Binding arbitration clauses
  • Liability caps and class action waivers
  • No warranty coverage
  • Buyer-pays-return-shipping policies

Usage

import{policycheckActionProvider}from"@coinbase/agentkit";constagentKit=awaitAgentKit.from({actionProviders: [policycheckActionProvider()],});

Tests

13 unit tests covering success paths, error handling, URL delegation, and request format validation.

PASS src/action-providers/policycheck/policycheckActionProvider.test.ts
PolicyCheckActionProvider
constructor
✓ should use default API URL when no config provided
✓ should use custom API URL from config
supportsNetwork
✓ should return true for any network
analyze
✓ should return low-risk assessment for safe seller policies
✓ should return high-risk assessment for risky seller policies
✓ should send seller URL as data part with quick-risk-check skill
✓ should send policy text as text part
✓ should return error for API error response
✓ should return error for HTTP failure
✓ should return error for network failure
✓ should return error when no analysis data in response
✓ should include summary text when available
checkUrl
✓ should delegate to analyze with sellerUrl
Test Suites: 1 passed, 1 total
Tests: 13 passed, 13 total

PolicyCheck is also live in the x402 Bazaar (#1 of 100 resources) and available as an MCP tool.

Checklist

  • Added documentation to all relevant README.md files
  • Added a changelog entry

…er verification
Adds a walletless action provider that enables AI agents to verify
e-commerce seller policies before making purchases. Analyzes return
policies, shipping terms, warranty coverage, and terms of service.
Actions:
- policycheck_analyze: Full policy analysis from text or URL
- policycheck_check_url: Quick URL-based seller check
Returns risk level, buyer protection score (0-100), key findings,
and purchase recommendation via the PolicyCheck A2A API.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@cb-heimdall

cb-heimdall commented Feb 13, 2026

Copy link
Copy Markdown

🟡 Heimdall Review Status

RequirementStatusMore Info
Reviews 🟡 0/1
Denominator calculation
Show calculation
1 if user is bot0
1 if user is external0
2 if repo is sensitive0
From .codeflow.yml1
Additional review requirements
Show calculation
Max0
0
From CODEOWNERS0
Global minimum0
Max 1
1
1 if commit is unverified1
Sum2

@github-actionsgithub-actionsBot added documentation Improvements or additions to documentation action provider New action provider typescript labels Feb 13, 2026
@vibegpt
vibegptforce-pushed the feat/policycheck-action-provider branch from 8bee432 to 37043b4CompareFebruary 14, 2026 15:47
@douglasborthwick-crypto

douglasborthwick-crypto commented Feb 27, 2026

Copy link
Copy Markdown

PolicyCheck covers the off-chain side of seller verification (return policies, shipping info). A complementary on-chain check: verify the seller's wallet holds credentials that indicate trustworthiness before the agent commits to a purchase.

InsumerAPI can add an on-chain trust dimension to AgentKit's pre-purchase flow. POST /v1/trust returns an ECDSA-signed wallet profile — 17 checks across 4 dimensions (stablecoins, governance, NFTs, staking) on 31 chains:

response=requests.post(
"https://api.insumermodel.com/v1/trust",
headers={"X-API-Key": key},
json={"wallet": seller_wallet}
)
trust=response.json()["data"]["trust"]
# trust["dimensions"]["stablecoins"]["passCount"] → USDC presence across 7 chains# trust["dimensions"]["governance"]["passCount"] → UNI, AAVE, ARB, OP holdings# Wallet with diversified holdings = less likely to be a throwaway storefront

A seller with zero on-chain footprint is a different risk profile than one holding governance tokens and stablecoins across multiple chains. On-chain state is hard to fake — it's ground truth.

API docs: https://insumermodel.com/openapi.yaml. There's also an MCP server (mcp-server-insumer on npm) for agents using MCP tool discovery.

@vibegpt

vibegpt commented Feb 27, 2026 via email

Copy link
Copy Markdown
Author

…k intelligence
Walletless action provider with two actions (policycheck_analyze,
policycheck_check_url) that call the PolicyCheck A2A API at
policycheck.tools. Returns risk levels, buyer protection scores,
key findings, and factual summaries.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@vibegpt
vibegptforce-pushed the feat/policycheck-action-provider branch from 37043b4 to 2aedca8CompareFebruary 27, 2026 15:09
@douglasborthwick-crypto

Copy link
Copy Markdown

Thanks @vibegpt — agreed. The two signals are complementary: PolicyCheck tells you what the seller says (policies, terms), on-chain state tells you what the seller has (capital, credentials, history). Both useful for an agent making autonomous purchase decisions.

We recently expanded the trust profiles to 17 checks across 4 dimensions (added staking positions — stETH, rETH, cbETH — as a 4th dimension alongside stablecoins, governance, and NFTs). Happy to collaborate on a combined risk assessment if there's interest.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

action providerNew action providerdocumentationImprovements or additions to documentationtypescript

Development

Successfully merging this pull request may close these issues.

4 participants

@vibegpt@cb-heimdall@douglasborthwick-crypto@Tanker187