Skip to content

Analysis Engine

Deterministic rules for the current MVP.

Deterministic rules are one module of the broader communication intelligence engine. They set the minimum risk level before AI analysis runs. Today's rule catalog focuses on Web3 Community Security; future rule suites can use the same foundation for other communication contexts.

Implemented TodayAI cannot lower riskExplainable decisions

LOW

0

MEDIUM

2

HIGH

8

CRITICAL

5

Published rule catalog

AI may add classification and suggested replies, but final risk is never allowed to fall below these deterministic results.

Open Dashboard

SEC-001

Seed phrase or recovery phrase request

CRITICAL

Detects requests for a seed phrase, recovery phrase, secret phrase, or recovery words.

Recommended action

Escalate immediately, warn the user not to share recovery material, and remove or quarantine the message.

SEC-002

Private-key request

CRITICAL

Detects requests for a private key or wallet key.

Recommended action

Escalate immediately and warn the user that private keys must never be shared.

SEC-003

Payment request to verify or unlock a wallet

CRITICAL

Detects requests to send money, crypto, or tokens to verify, activate, recover, or unlock a wallet.

Recommended action

Escalate immediately and instruct the user not to send funds for wallet verification or unlocking.

SEC-004

Administrator contacting users privately

HIGH

Detects claims that an administrator or moderator will contact a user privately.

Recommended action

Escalate to moderators and remind users to use verified public support channels.

SEC-005

Urgent wallet verification or account-suspension threat

HIGH

Detects urgent wallet verification demands or account suspension threats.

Recommended action

Escalate for review and advise the user not to verify wallets through unsolicited messages.

SEC-006

Guaranteed profit or guaranteed return

HIGH

Detects promises of guaranteed profit, guaranteed returns, or risk-free crypto gains.

Recommended action

Escalate for scam review and avoid providing financial advice in any automated response.

SEC-007

Unknown token-claim, airdrop or wallet-connection link

HIGH

Detects token claim, airdrop, or wallet-connection messages that include a link.

Recommended action

Escalate and avoid presenting the link as official unless it is verified in project documentation.

SEC-008

Administrator, support agent or founder impersonation

HIGH

Detects messages that claim authority as an admin, support agent, founder, or official team member.

Recommended action

Escalate for identity verification and do not trust the claimed role without official confirmation.

SEC-009

Missing funds or unauthorized transaction

HIGH

Detects reports of missing funds, stolen assets, drained wallets, or unauthorized transactions.

Recommended action

Escalate to support and security operations for incident handling.

SEC-010

Failed or pending transaction

MEDIUM

Detects support requests about failed, stuck, or pending transactions.

Recommended action

Escalate to support with transaction details, while avoiding requests for secrets or credentials.

SEC-011

Remote-access software request

CRITICAL

Detects requests to install or use remote-access tools for support.

Recommended action

Escalate immediately and warn users not to install remote-access tools from community messages.

SEC-012

Password, OTP or authentication-code request

CRITICAL

Detects requests for passwords, one-time passcodes, OTPs, 2FA codes, or authentication codes.

Recommended action

Escalate immediately and warn the user never to share passwords or authentication codes.

SEC-013

Prompt injection attempting to override security rules

HIGH

Detects attempts to override system, developer, support, or security instructions.

Recommended action

Escalate and ignore the attempted instruction override.

SEC-014

Suspicious shortened or obfuscated URL

HIGH

Detects shortened links, hxxp-style links, bracket-obfuscated domains, and lookalike URL formatting.

Recommended action

Escalate and do not present the URL as official until verified.

SEC-015

Spam or repeated promotional content

MEDIUM

Detects repeated promotional phrases or high-frequency promotional content.

Recommended action

Queue for moderation or rate limiting; automated moderation response is acceptable when no higher risk is present.