AuraCheck Test · Web3 Agent · BSC Testnet

Test what users see.
Prove what happens on-chain.

Point the agent at a dApp. It drives the real MetaMask, sends testnet transactions, and checks receipts, events, and balances in code. Every verdict is attested on-chain.

Real MetaMask Chain facts decided in code Attested on BNB Chain

Building for the Indonesia Web3 Hackathon 2026 · AI Agents and Finance & Commerce tracks · BNB Chain

AURACHECK WEB3 AGENT / ONE SESSION

Watch the agent
test a dApp.

Observe. Act through the wallet. Verify on-chain. Attest.
The owner watches every step live.

Read the dApp before touching the wallet.

With MetaMask locked, the agent maps what the dApp offers, then ranks the flows where money moves and something can go wrong.

  • Read-only exploration
  • Feature inventory from real UI labels
  • Risk-ranked scenario backlog
Scenario 2/6: DepositDAPP
S7 TabunganSave S7USD

Balance: 100 S7USD

Amount: 5Deposit

Why: “Connect passed. Deposit moves value and is the next risk.”

Agent steps
  1. Observe dApp, wallet locked
  2. Click “Deposit”, amount 5, confirm in MetaMask
  3. Wait for the finalized receipt, decode events
  4. Attest the report hash on-chain
On-chain

Waiting for a transaction

Verdict: running (2 of 6 scenarios)Attestation: pending
Illustrative layout of the live run viewValues shown are examples, not a recorded session.
01 / AUTONOMOUS BY DEFAULT

“Test this dApp.”
That’s the prompt.

Paste a URL and walk away. The agent picks the risky scenarios, runs them through the wallet, reflects on what it found, and decides when it has covered enough. Prefer control? Guided mode lets you pick one of three recommended flows.

See how verdicts work
autonomous-sessionNO FURTHER INPUT
  1. Observe the dApp with the wallet locked
  2. Rank risky flows into a backlog
  3. Plan a scenario, including negative paths
  4. Act through MetaMask, guarded
  5. Verify receipts, events, and balances
  6. Reflect: next scenario or stop
ONE REPORT · ONE ATTESTATION
01 /

Real wallet

Connect, sign, confirm, and reject in MetaMask.

02 /

Negative paths

Rejected txs, low balances, double clicks.

03 /

Facts in code

The model operates the UI, never judges the chain.

04 /

Proof at the end

A report hash anyone can verify on-chain.

Your dApp says success.
The chain has the final word.

Try a sample dApp
02 / UI VS CHAIN

Expected vs Actual. Decided in code.

Each scenario sets what the interface claimed beside what the chain recorded. The verdict follows fixed rules.

How a scenario is judged
The UI saysThe chain saysVerdictFinding
SuccessReverted, no tx, or wrong event or amountFAIL · HIGHUI–chain mismatch
AnyWrong contract, wrong chain, or duplicate submissionFAIL · HIGHWrong target or double send
Still loading after finalitySuccessFAIL · MEDIUMStale UI
ErrorSuccessFAIL · MEDIUMUI error on success
MatchesMatchesPASS—
—Receipt not final before timeoutINCONCLUSIVENever a PASS
RECEIPTSFinalized

Waits for the finalized block, up to 120 s

EVENTSDecoded

From the receipt logs, emitter checked

BALANCESBlock-pinned

Read before and after, never “latest”

03 / TRY THE SAMPLES

Three dApps. Bugs on purpose.

Savings, merchant payments, and loyalty, built for Indonesia and live on BSC Testnet. Each has a normal mode and hidden bug modes the agent must catch without being told.

04 / PROOF ON-CHAIN

The agent tests.
The chain remembers.

Every session that reaches a verdict ends in one public-safe report. Its SHA-256 hash and verdict are written to S7RunAttestor once. The result page’s Verify button hashes the report in your browser and compares it with the record on-chain.

View S7RunAttestor on BscScan
BSC Testnet · chain 97

› attest(runId, reportHash, verdict, uri)
RunAttested · one record per session
Verify: hash locally, compare on-chain

05 / GUARDRAILS

Safe to point at any dApp.

The public agent opens only after an adversarial security gate passes.

Testnet only

No mainnet signing, ever. Mainnet RPC hosts are blocked.

Guarded wallet

Every wallet request passes a deterministic check first.

One browser per session

A fresh, isolated container that restarts pristine.

Locked-down network

Public web only. Internal addresses are unreachable.

No double sends

Identical duplicate transactions are refused in-step.

Public-safe reports

Only hashes and fixed titles go on-chain.

Owner-only live view

Sharing starts after the session finishes.

Not an audit

Every result says so, plainly.

Where the agent is today.

About the hackathon
  1. ✓ Done

    Contracts

    5 contracts deployed and verified on BSC Testnet

  2. ✓ Done

    Sample dApps

    3 dApps live with bug modes; MetaMask connects

  3. ✓ Done

    Agent toolkit

    Tx and signature policy, RPC policy proxy, verifier and verdict matrix, attestation hashing. 458 unit tests.

  4. ✓ Done

    Feasibility

    The agent sees and clicks the real MetaMask popup; the vision model calls custom wallet and chain tools

  5. ◐ In progress

    Staging

    Deploying the full agent session runner

  6. → Next

    Public demo

    Live view of the agent and MetaMask, autonomous multi-scenario mode, and opBNB support

BUILT DURING THE HACKATHON

The Web3 agent layer (wallet and chain toolkit, RPC policy proxy, verifier, on-chain attestor, sample dApps, and contracts) was built during the hackathon period. It runs on top of AuraCheck’s existing AI QA engine for web apps, which we extended to drive MetaMask and verify on-chain results.

A FEW GOOD QUESTIONS

Clarity before
you commit.

Talk to the team
Is this a smart-contract audit?

No. Every result says “Automated test result, not an audit”. The agent tests how your dApp behaves for a user, through the UI and the wallet, and checks what reached the chain. It does not review contract source code for vulnerabilities.

Which networks does it use?

BSC Testnet (chain 97) only. The agent never signs on mainnet: its demo wallets hold zero mainnet value, and mainnet RPC hosts are blocked at the network edge.

Does the agent use my wallet?

No. Each test slot has its own demo wallet with testnet funds only. The agent operates the real MetaMask extension with that wallet, and every wallet request passes a deterministic guard before anything is clicked.

Who decides PASS or FAIL?

Code. The AI observes the dApp, picks risky scenarios, and operates the interface. Receipts, decoded events, and balance changes are compared with the UI’s claim in code, so the model never decides a chain fact.

What is published on-chain?

A hash of a public-safe result document, its verdict, and its address. The document holds the verdict, the dApp origin, finding types, and transaction hashes. Screenshots and the full Expected vs Actual stay behind the owner’s share link.

Can I test my own dApp today?

The three sample dApps and the contracts are live now, and the full session runner is being deployed to staging. The public demo, with a live view of the agent and MetaMask, opens after its security gate passes. Join the early list and we’ll invite you when your dApp can be tested.

READY WHEN YOU ARE

Your dApp says success. Does the chain agree?

Join the early list. We’ll invite you when the public agent can test your dApp.