CLI
user intent: "trade perp"
User LLM (local)
plans call sequence
Call Batch
sequence of CLI calls
Execute Sequence
CLI LLM, one call at a time
Mobile Notification
user reviews batch,
approves in principle
✦ Temp Approval Object
SHIELD
deterministic policy
known · malicious · unknown
Server LLM
adjudicates unknowns
vs. approval object
MFA Prompt
hard gate
real-time confirm
LATENCY
SKILLS REGISTRY
2FA ALWAYS TRIGGERED
SLOW ON 2FA
①
②
③
④
unknown
⑤
malicious → hard MFA
diverges
⑥
✓ known-good → silent pass
✓ within approval → pass