Skip to content

Phylax

$PHYLAX

AI Agents · Uncategorised

Verified Builder

Phylax is a pre-install security layer for AI agent skills. Before a skill can touch a wallet, Phylax scans it and returns a deterministic verdict — ALLOW, WARN, or DENY — with a rule ID and human-readable proof for every finding. It turns "install and hope" into "audit, then install."

QuietLast ship 2mo ago

Latest ship

Active development: 76 commits across 2 contributors

Code ActivitySource linked

13 active day(s) in usephylax/phylax-skill-audit.

Builder activity

Meaningful, source-backed updates per week. Commits are aggregated, not counted individually.

Build timeline

  1. v0.1.0 — Phylax public launch

    Github ReleaseSource verified

    First public release of Phylax — a pre-install security audit for agent skills on Base (chain 8453). Phylax scans a skill before you install it and returns a deterministic ALLOW / WARN / DENY verdict with line-level evidence. What it does - Static scan — prompt-injection, secret-exfiltration, and obfuscation in SKILL.md + manifest - Onchain scan — referenced Base contracts: bytecode selectors, proxy/upgradeability, honeypot/owner powers - Endpoint scan — x402 endpoints: HTTPS enforcement, 402 schema, price sanity - Deterministic scoring — `score = 100 − Σ(sev

    View evidence

Research notes

Written by Dawnscan researchers and reviewed before publishing. Commentary with sources — not the project's own claims, and not evidence of shipping.

No published notes on Phylax yet.

    Know something about Phylax? Sign in with wallet to submit a research note. Notes are reviewed before they appear here.

    Sources

    Contract
    0xff36…9f0d