{"blocked_action_receipts":[{"decision":"blocked_before_mcp_call","mcp_write_tool_called":false,"reason":"Current grant is account-read only; no exact trade scope, symbol, side, notional cap, or fresh human approval for a state-changing Binance action.","request_id":"binance-block-trade-btcusdt-market-v1","requested_action":"create spot market order BTCUSDT","state_change":"none","tool_family":"spot trade/order placement"},{"decision":"blocked_after_classification","mcp_write_tool_called":false,"reason":"Raw balances and full asset lists are account-sensitive; public receipt may include only nonzero row count and hashes.","request_id":"binance-block-raw-balance-dump-v1","requested_action":"publish raw Binance balance payload","state_change":"none","tool_family":"account-sensitive read"},{"decision":"blocked_before_mcp_call","mcp_write_tool_called":false,"reason":"Internal transfer is state-changing and current API permission readout shows internal transfer disabled; requires fresh exact scope and explicit human approval.","request_id":"binance-block-internal-transfer-v1","requested_action":"move funds between Binance wallets/internal wallets","state_change":"none","tool_family":"internal transfer"},{"decision":"hard_block","mcp_write_tool_called":false,"reason":"Binance Agentic MCP docs state there is no withdrawal scope; this public proof never attempts withdrawal tooling.","request_id":"binance-block-withdrawal-v1","requested_action":"withdraw or externally transfer funds from Binance","state_change":"none","tool_family":"external withdrawal"}],"blocked_trade_attempt_receipt":{"claim":"Funded Binance MCP context reached; a concrete BTCUSDT trade intent was classified and blocked before any Binance MCP write/order tool call.","created_at_utc":"2026-08-31T10:56:00Z","gate_result":{"classification":{"decision":"block_before_mcp_call","reason":"State-changing Binance actions require exact symbol/side/notional scope plus fresh explicit human approval; this proof has neither.","tool_class":"state_changing_trade_or_transfer"},"mcp_tool_called":false,"mcp_write_tool_called":false,"request":{"arguments_redacted_or_absent":true,"fresh_human_trade_approval":false,"intent":"buy BTC with the funded Binance MCP context","notional_scope":"not_granted","order_type":"MARKET","request_id":"binance-blocked-trade-attempt-btcusdt-buy-market-v1","side":"BUY","state_change":true,"symbol":"BTCUSDT","tool":"spot.order"},"state_change":"none","tool_result_redacted":false},"ok":true,"proof_strength":"blocked_before_execution_no_mcp_write_tool_called","public_boundary":"This is an executable local policy-gate proof, not a Binance trade execution. It proves the dangerous request was refused before MCP write-call dispatch.","receipt_hash_sha256":"f4b30f9b1eab0d604800ab2b3543ce9f88cb4c736ae834ba2383d2d553234485","schema":"gregers.binance-blocked-trade-attempt.v1","side_effects":"no Binance trade, no order, no convert, no transfer, no withdrawal; classifier returned before calling any Binance write tool"},"boundaries":["Gregers-built proof only; not a Binance partnership claim and not official Concordium/Foundation output.","No trade, transfer, withdrawal, order, conversion, leverage, account configuration, API-key creation, or custody action was performed.","No raw balances, asset list, account id, API keys, OAuth tokens, recovery material, KYC data, bank/card data, signer secrets, or production funds are published.","The Binance deposit address is not directly printed in the page/API; the public Base tx hash may let chain observers infer the ERC-20 transfer recipient.","Observed Binance permission flags are classification evidence only; they are not approval to execute state-changing actions."],"classification":{"spot_depth":"safe_market_data_read","spot_getAccount":"account_sensitive_read_redact_balances","spot_tickerPrice":"safe_market_data_read","tools_list":"safe_capability_discovery","trade_or_convert_tools":"state_changing_requires_fresh_explicit_human_approval","wallet_transfer_tools":"state_changing_requires_fresh_explicit_human_approval","withdrawal_or_api_key_creation":"hard_block_for_public_demo"},"created_for_hook":"Binance Agent OS MCP real exchange access needs permission classification before execution","funded_agentic_gate_receipt":{"binance_mcp_arrival":{"account_read_context":"post-funding spot.getAccount read with omitZeroBalances=true; raw balances discarded after deriving nonzero row count","account_type":"SPOT","deposit_history_tx_seen":true,"deposit_status_code_seen":"6","nonzero_balance_rows_observed":1,"oauth_scopes":["mcp:account:read"],"raw_asset_list_published":false,"raw_balances_published":false},"blocked_actions":["trade/order placement","convert execution","internal transfer","withdrawal/external transfer","margin/futures/leverage","API-key creation","raw balance publication"],"boundary":"Agent executed external funding and then only a read-only gated Binance MCP market-data action. No Binance trade/order/transfer/withdrawal/convert/margin/futures action was executed. No raw Binance balance, asset list, OAuth token, private key or API credential is published. The Binance deposit address is not directly printed; the public funding tx hash may allow chain observers to infer the ERC-20 transfer recipient.","created_at_utc":"2026-08-31T10:14:55Z","external_funding":{"amount_usdc":"0.50","asset":"USDC","binance_deposit_address_directly_printed":false,"binance_deposit_address_redacted":true,"chain_status":"success","network":"Base","privacy_note":"The Binance deposit address is not directly printed in the page/API; because the tx hash is public chain evidence, the ERC-20 recipient may be inferred from Base logs.","recipient_address_inferable_from_public_tx_logs":true,"source":"MoonPay local wallet","source_address":"0x5325B4baAe421b68C502103D3915071484c98623","source_wallet_label_redacted":true,"token_contract":"0x833589fcd6edb6e08f4c7c32d4f71b54bda02913","tx_hash":"0xdf587c0fc1a30b3679f0c93eaad016542d7bb8b5b812b0b7d7635aca99115869"},"gated_action_after_funding":{"decision":"allowed","requested_action":"spot.tickerPrice BTCUSDT after Binance MCP deposit arrival/account-read state was observed","result_price_observed":"78519.99000000","result_symbol":"BTCUSDT","state_change":"none","tool_class":"safe_market_data_read"},"ok":true,"permission_flags":{"canDeposit":true,"canTrade":true,"canWithdraw":true},"permission_flags_boundary":"Observed Binance account permission flags are classification evidence only; they are not Gregers approval, MCP authorization for a state-changing action, or authority to trade/transfer/withdraw.","public_identifiers_published":{"amount_usdc":"0.50","chain":"Base","recipient_or_deposit_address":"not directly printed; inferable from public ERC-20 transfer logs because tx hash is published","source_address":"0x5325B4baAe421b68C502103D3915071484c98623","token_contract":"0x833589fcd6edb6e08f4c7c32d4f71b54bda02913","tx_hash":"0xdf587c0fc1a30b3679f0c93eaad016542d7bb8b5b812b0b7d7635aca99115869"},"receipt_hash_sha256":"0828d7a40729b19c6ee6186acf9d0667d654884e363866c3f236885c16b643f8","schema":"gregers.binance-funded-mcp-gate.v2"},"mode":"funded_deposit_arrival_account_sensitive_read_and_gated_market_action_no_binance_state_change","ok":true,"permission_flags_boundary":"Observed Binance account permission flags are classification evidence only; they are not Gregers approval, MCP authorization for a state-changing action, or authority to trade/transfer/withdraw.","permission_gate":{"before_account_sensitive_read":["verify operator authorization","classify tool","redact balances and asset list","record receipt hash"],"before_state_change":["new exact scope","exact amount/symbol/network/destination","fresh human approval","Binance confirmation","post-action receipt"],"concordium_role":"Gregers uses Concordium accountable-agent identity evidence to bind the agent/operator/policy receipt; Concordium is not the exchange, custodian, broker, payment rail, or official sponsor."},"public_identifiers_and_inference":{"not_directly_printed":["Binance deposit address","raw balances","raw asset list","Binance account id","OAuth/API credentials","private keys"],"onchain_inference":"Because the funding tx hash is public chain evidence, independent Base observers can infer the ERC-20 transfer recipient; the page/API do not directly print the Binance deposit address.","published":["funding tx hash","source address","USDC token contract","Base network","0.50 USDC amount","timestamps/hashes"]},"receipt_hash_sha256":"c6d3492c7b6135affdc53aa290b82740c5e9f3d084364886447686db6110f87f","redacted_binance_mcp_summary":{"account_fields_observed":["accountType","brokered","buyerCommission","canDeposit","canTrade","canWithdraw","commissionRates","makerCommission","permissions","preventSor","requireSelfTradePrevention","sellerCommission","takerCommission","uid","updateTime"],"balance_asset_count":1,"balances_redacted":true,"binance_permissions_observed":["TRD_GRP_035"],"created_at_utc":"2026-08-31T10:48:19Z","nonzero_asset_count":1,"nonzero_asset_symbols_hash_sha256":"8591ee9090c0c02ca1f103cb637131d8f358870aba145245ff083e138fdd705b","oauth_client_id":"codex","oauth_scopes":["mcp:account:read"],"ok":true,"permission_flags_boundary":"Observed Binance account permission flags are classification evidence only; they are not Gregers approval, MCP authorization for a state-changing action, or authority to trade/transfer/withdraw.","permission_flags_observed":{"accountType":"SPOT","canDeposit":true,"canTrade":true,"canWithdraw":true},"proof_boundary":"Account-sensitive read only. No balance amounts, raw asset list, orders, transfers, withdrawals, API keys, tokens, credentials, or directly printed Binance deposit address are published. Public funding tx hash may allow chain observers to infer the ERC-20 transfer recipient.","raw_account_data_persisted":false,"read_context":"fresh post-funding spot.getAccount read with omitZeroBalances=true; raw balances discarded immediately after deriving counts and hashes","summary_hash_sha256":"8b5ed711fcc911c55101492ec9391c7759f25652c0221fdd9d3b19bd62ec7f58","tool_call":"spot.getAccount","tool_class":"account_sensitive_read"},"schema":"gregers.binance-mcp-account-gate.v3","side_effects":"one authenticated account-sensitive read via Binance MCP; redacted local summary and public receipt generated; no state-changing Binance action, no balance publication, no Concordium transaction"}
