Skip to Main Content

ligis

Built at The Agent Arena Hackathon · Sep 26, 2026 · San Francisco, CA

ligis — Demo video

Autonomous agents are being handed wallets, and every tool call that fetches external content is a prompt-injection surface — the most damaging thing an injected instruction can do is redirect a payment. Ligis puts a containment layer between the agent and the money that is independent of the agent's own reasoning. The /arena demo shows a procurement agent ("Atlas") told to renew a $1,200 vendor contract. It pays correctly when asked legitimately — the gate returns GO. Then it fetches a poisoned invoice page containing a hidden instruction to redirect $60,000 to an attacker's wallet. Atlas tries to comply. Before the payment signs, Ligis's gate judges the intent using two independent checks — its own Jev intent layer (scope, amount, and payee consistency) and Vultr Serverless Inference as a second, independent LLM judge reasoning over the contract facts and fetched content (treated as untrusted). If either judge says STOP, the payment stops — a fail-closed design where an unavailable judge is reported as skipped, never as a silent pass. The verdict comes back STOP with plain-English reasons and a sha256 audit ID. Underneath, every agent has a portable, revocable on-chain identity (Casper Testnet / Pharos EVM) and the same CredentialRegistry gate answers "is this counterparty allowed to be paid for this capability?" in one read — powering the rest of the product beyond the arena scenario (/field, /gate, /steward, and an x402 Trust Gate for HTTP 402 payments that only settle after a GO).

Team