tychi-mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited tychi-mcp (Plugin) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
@tychilabs/tyi-mcp)Give your AI agent a wallet — onboard, hold funds, send, and pay under policy.
Agent-native MCP server (stdio) for Cursor and other hosts. Nine tools: routing (tyi_route), readiness (tyi_status), onboarding, fast wallet lifecycle (create / import / switch), and tyi_chat for balances, sends, and policy-gated payments on Arbitrum One. Private keys encrypted in ~/.tyi on the operator machine; signing never leaves the device. Hosted Tychi brain parses intent and runs the LLM — configure TYCHI_BRAIN_URL (HTTPS recommended; see SECURITY.md).
Agents → @tychilabs/[email protected] · Humans → @tychilabs/tyi

tyi_route maps intent → correct tool (avoids slow misuse of tyi_chat)tyi_status checks mode before any wallet actiontyi_onboard + tyi_onboard_schema for first-time setup (password, LLM provider, API key)tyi_create_wallet, tyi_import_wallet, tyi_switch_wallet (fast, no brain loop)tyi_chat for balances, sends, transfers, payments, policy, limits, history~/.tyityi_reset wipes local data when operator confirmsBeta ships on Arbitrum One (chain id 42161) — EVM balances, sends, and UGF gasless payments. More chains in registry; Solana/Sui import supported.
Onchain agent wallet on Arbitrum One — self-custody, local signing, UGF gas routing today:
| Roadmap | What it unlocks |
|---|---|
| Automation | Policy-gated agents — recurring sends, triggers, scheduled flows |
| Trading | Spot swaps across Arbitrum liquidity — agent quotes, operator confirms |
| Lending | Supply on Arbitrum money markets — yield without leaving keystore |
| Borrowing | Collateralized borrow — cap-enforced, fully self-custodial |
tyi_route → tyi_status
→ direct tool (onboard / create / import / switch / reset) ← FAST
→ tyi_chat (balance / send / pay / policy only) ← SLOWNever call tyi_chat when tyi_status.ready is false.
Import seed or private key → tyi_import_wallet only (never via tyi_chat).
| Tool | Use when |
|---|---|
tyi_route | First — intent → tool map |
tyi_status | Session start — ready? what's missing? |
tyi_onboard_schema | Field schema before onboard |
tyi_onboard | First setup or LLM-only setup |
tyi_create_wallet | New wallet by name |
tyi_import_wallet | Import mnemonic or privkey (EVM / Solana / Sui) |
tyi_switch_wallet | Change active wallet |
tyi_reset | Wipe ~/.tyi (confirm: true) |
tyi_chat | Balance, send, pay, transfer, policy, limits |
Pin the release (do not use floating @beta in production):
npx @tychilabs/[email protected]
npx @tychilabs/[email protected] --toolsSee [SECURITY.md](./SECURITY.md) — trust model, brain transport (HTTP beta endpoint), sensitive tools, supply-chain pinning. No install scripts.
Repo includes .mcp.json (Open Plugins) for Cursor Directory. Set `TYI_PASSWORD` and `TYCHI_BRAIN_URL` in host env (HTTPS brain recommended).
{
"mcpServers": {
"tychi": {
"command": "npx",
"args": ["@tychilabs/[email protected]"],
"env": {
"TYI_PASSWORD": "<from tyi_onboard>",
"TYCHI_BRAIN_URL": "<https brain URL — required>"
}
}
}
}Beta default if unset in code: http://hosted_brain.tychilabs.com — use HTTPS self-host or trusted network only.
OpenClaw:
openclaw mcp set tychi '{"command":"npx","args":["@tychilabs/[email protected]"],"env":{"TYI_PASSWORD":"<password>","TYCHI_BRAIN_URL":"<https brain URL>"}}'
openclaw mcp reload| Mode | Meaning |
|---|---|
fresh | No wallet — run tyi_onboard |
llm_only | Wallet exists, no LLM key — onboard LLM fields only |
ready | OK for tyi_chat |
Operator provides (never invent): keystore password, LLM provider + API key, optional mnemonic for import.
Prefer MCP env for TYI_PASSWORD over chat after onboard.
| Field | Prompt | |||
|---|---|---|---|---|
password | Keystore password for ~/.tyi → later TYI_PASSWORD in MCP env | |||
agent_name | Agent name (default Tychi) | |||
llm_provider | anthropic \ | gemini \ | openai \ | groq |
llm_api_key | Provider API key (validated, stored encrypted on brain) | |||
mnemonic | Optional import (fresh only) |
tyi_reset with { "confirm": true } — wipes ~/.tyiTYI_PASSWORD from MCP envopenclaw mcp unset tychi then openclaw mcp reload| Symptom | Action |
|---|---|
not_ready on chat | Run onboard flow |
TYI_PASSWORD env required | Set env after onboard; reload host |
no_llm_key / missing llm_key | tyi_onboard llm_only |
partial install | tyi_reset then fresh onboard |
fetch failed on brain | Set TYCHI_BRAIN_URL explicitly; use HTTPS self-host or beta http://hosted_brain.tychilabs.com |
| Variable | Required | Default |
|---|---|---|
TYI_PASSWORD | After onboard | — |
TYCHI_BRAIN_URL | Recommended | http://hosted_brain.tychilabs.com (beta; prefer HTTPS override) |
TYI_DATA_DIR | No | ~/.tyi |
KEYSTORE_PASSWORD | Alias | same as TYI_PASSWORD |
Apache License 2.0 — see LICENSE. Runtime dependency: @tychilabs/tyi.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.