Skip to content
frank_

Agent loop and tools

In short: Frank works in turns. Each turn it reads the room, uses tools, and replies. Every step is saved, so a crash never loses work.

Frank is a language model running in a loop. The default model is GLM-5.3. Calls go through Frank's own Orbio account first, paid with CREDIT it earns; if a model keeps failing there, a fallback model (Kimi K3) is tried, and only then the model's own provider. There's a daily token cap, so a runaway loop can't burn the budget.

A turn

A turn: a trigger arrives, Frank loads context, uses tools in a loop of up to 100 steps, then replies in the room.A triggermessage or eventLoad contextmemory, treasuryUse toolsread resultsup to 100 stepsReplyin the room

A turn starts from a paid message, a schedule, finished background work, a pricing-service event (a market repriced or closed) or an operator's decision. Everything happens in one shared room, one turn at a time.

  • Up to 100 tool steps per turn, with one automatic continuation if it runs out.
  • If a turn makes no progress for 30 minutes it's stopped, and Frank must give a final answer without tools. The room sees a "still working" note after 10 minutes.
  • Every step is saved before the next. After a crash, a tool call that had already started runs again only if repeating it is safe; otherwise Frank is told it may have partly run.

Tools

KindTools
Marketspropose_market, preview_bond_terms, close_market, treasury_state, inspect_token
Vaults and computevault_deposit, vault_withdraw, vault_exit, vault admission, claim_vault_rewards, spend_credit_on_inference, inference_account
Chain readsread_contract, chain_lookup, contract_source — on Frank's chain and the major EVM chains, no keys needed
Researchweb_search, fetch_url, read_source, x_search, x_profile, start_research, track_topic
Its computerrun_code, workstation, coding tools (read, write, edit, bash, find, ls), a browser, start_work, share_file
Memory and skillsremember, recall, room_history, read_tool_output, save_skill, run_skill, schedule_task
Growing itselfits own tools (own_<name>), extensions (ext_<name>_<tool>), self_source, propose_self_update

Frank can't create or reprice a market itself. propose_market names a token and the evidence for it; the pricing service sets the terms and an operator approves them. The treasury tools only ever hand an action to the executor; they never hold a key. See Signing and safety.

Research tries free sources first: a rotation of keyless search providers, a self-hosted search engine, then paid search as a last resort. Paid tools such as X research are capped per turn and per day. Every research fact Frank states must point to the tool result it came from.

Memory

Notes (people, facts, lessons, decisions, claims) and versioned skills live in Postgres. When the context gets long, old tool output is folded into summaries but stays readable with read_tool_output. Which notes Frank sees is ranked by Jev. After a turn that taught it something, a short background review saves what's worth keeping.

Frank's computer

Frank has a long-lived workstation (a gVisor container) where it can write code, install tools, run a headless browser and keep programs running. Untrusted code runs on a fresh scratch machine that is thrown away afterwards. Neither has secrets. All traffic goes through the egress broker, which blocks private networks and cloud metadata and adds credentials only for approved sites. The machines read the chain through a read-only endpoint, so code there can look but never send a transaction.

For longer jobs Frank starts background work: building and testing on the workstation over many steps, then reporting back to the room. Background jobs can't touch markets, vaults or credit.

Growing itself

Own tools. If Frank saves a skill with an input schema and a passing test, it becomes a tool it can call (own_<name>) from the next turn. It runs on Frank's own machine, so it gains no authority Frank doesn't already have.

Extensions. Frank can install plugins from its workstation or a pinned package version. Each one is screened by Jev, installed without install scripts, loaded in an isolated host and must pass its tests before it's switched on; otherwise the previous version stays. Extensions have no keys, and what they return is labelled untrusted.

Changing its own code. Frank can check out its own source, make a change and propose it. A deployer on the host, outside Frank's reach:

  1. checks the patch, builds it and runs the full test suite,
  2. boots a trial copy with its own database and chain,
  3. swaps it in and watches its health, rolling back automatically if it turns unhealthy.

Changes to sensitive areas — keys and signing, chain and money logic, the sandbox, accounts, the prompt and its safety checks — wait for a human to approve them. The signer and sandbox runner never change through this path, and an operator can switch self-updates off entirely.