Ghost OS is moving toward one command interface for crypto intelligence, wallet context, and verified execution.
Ghost OS is locked around one loop: Ask -> Scan -> Track -> Alert -> Review -> Sign/Execute -> Proof. Every new production upgrade should make this loop safer, clearer, or easier to trust.
Make every command resolve through Ask -> Scan -> Track -> Alert -> Review -> Sign/Execute -> Proof.
Centralize token identity, source evidence, risk scoring, warnings, and blocked states.
Separate prepared, ready-to-sign, broadcasted, confirmed, failed, expired, and blocked states.
Give users a daily reason to return through alerts, watchlists, wallet context, and market briefs.
Attach a proof trail to serious actions with sources, timestamps, wallet mode, risk, quote, and tx status.
Keep the main demo flow stable, honest, and repeatable.
Treat broken auth, wallet provisioning, parser continuity, route prep, history, and provider states as sprint blockers.
What should I do in crypto right now?
Scan, protect, prepare, and prove actions from one command surface.
Is this token real, liquid, risky, and actionable?
Token identity, market, risk, and next steps before action.
Can I trust this route or contract enough to continue?
Policy-backed risk levels that can block unsafe automation.
Who signs, who prepares, and what controls execution?
External Wallet prepares only; Ghost Wallet acts only inside user policy.
What exactly am I signing or authorizing?
Provider, route, slippage, fees, min received, wallet mode, and status.
What happened and where is the receipt?
Sources, timestamps, risk, quote, wallet mode, tx hash, and explorer URL.
What changed since I last checked?
Watchlist, wallet, market, and risk changes become actionable.
A visible sprint guardrail with active, hardening, and gated surfaces.
A blocker list for anything that can break the investor demo.
A demo command that shows source-backed scan, risk, preview, and proof.
A structured token identity object with ambiguous-token blocking.
A reusable risk card shown before any trade or wallet signature.
A transaction preview card that never implies execution before a real signature/hash.
A proof trail card that can be used in command results and history.
Standard safety language for scanner, chat, swap, bridge, wallet, and alerts.
Left navigation, center chat, and right context panel all serve the core loop.
Follow-up commands like it, same chain, track it, and retry use session context.
The full 30-day sprint is tracked in the production sprint doc; the roadmap highlights the first 10 days because those make the core loop demo-ready.
Marketplace order builders, Base MCP/OpenSea routes, ownership checks, and signer policy must be configured first.
Allowed now: Discovery, floor checks, collection stats, and prepared/not-configured states only.
Launch factory, registry, LP locker, metadata storage, reward vault, RPC, and treasury config must be present.
Allowed now: Intent parsing, parameter review, and provider-missing states only.
Venue account, margin, signer, liquidation checks, and execution provider must be configured.
Allowed now: Market discovery, preview, risk warning, and provider-missing states only.
Only add execution chains after resolver, RPC, quote, explorer, fee, risk, and wallet support are complete.
Allowed now: Unsupported chain must return a clean unsupported/provider-missing state.
Feeds must not outrank execution reliability, risk, proof, wallet safety, or core command continuity.
Allowed now: Curated alpha/news surfaces with sources and no investment claims.