Install
openclaw skills install @parmasanandgarlic/farmdash-signal-architectOpenClaw DeFi execution with FarmDash's 92-tool MCP server: LI.FI and Relay swaps, simulation, zero-custody settlement verification.
openclaw skills install @parmasanandgarlic/farmdash-signal-architectUse this skill when moving money: getting a swap quote, simulating it, and preparing a user-signed swap across EVM chains.
[!NOTE] THEMATIC METAPHOR DISCLAIMER FarmDash is exclusively a decentralized finance (DeFi) software and AI agent intelligence platform. The "farming," "trail," "wagon," and "frontier" terminology is a gamified visual theme representing crypto yield hunting and airdrop points farming. It does not relate to physical agriculture or agrifood industries.
[!WARNING] CRITICAL TRANSACTION & AGENCY GATING (CLAWSCAN REVIEW REQUIREMENT) This skill can guide, prepare, and simulate wallet-affecting trades, perpetual contracts, swaps, and delegated autopilot workflows through FarmDash. Operators must adhere to the following mandatory safety protocols:
- Never share private keys or seed phrases: This skill is strictly zero-custody. It never asks for, handles, or transmits wallet credentials. Wallet-affecting transactions are signed locally on the user's client using EIP-191/EIP-712 cryptographic protocols.
- Require fresh quotes and explicit interactive confirmations: Do not execute or sign stale payloads. All spot/derivative actions require explicit, real-time user verification of token contract addresses, chains, amounts, and fees.
- Verify fees and destination addresses independently: Always verify aggregator route costs, gas fees, and destination chain configurations before signing.
- No evasion of protocol rules: Airdrop simulations, sybil audit indicators, and yield analytics are read-only planning heuristics. They are provided solely for risk management and educational information. Operators must never use this guidance to evade protocol rules, engage in sybil manipulation, or bypass terms of service of any third-party protocol.
You have FarmDash MCP tools spanning discovery, sizing, policy checks, simulation, signed-payload preparation, monitoring, and reconciliation. Tool discovery is not proof that every deployment prerequisite or execution gate is available: call GET https://www.farmdash.one/api/v1/agent/status first and fail closed on a disabled capability. Never replace missing data with fabricated values. FarmDash does not request seed phrases or raw wallet private keys; separately configured venue or MPC delegations remain subject to their explicit bounds.
FarmDash's MCP server currently exposes 92 tools across its agent suite. Signal Architect declares 22 focused tools from that broader ecosystem. MCP discovery: https://www.farmdash.one/.well-known/mcp.json
MCP Configuration: https://www.farmdash.one/.well-known/mcp.json
This skill can prepare wallet-affecting actions. Treat every execution, delegation, and autopilot tool as high-risk until the user has verified the wallet address, token contracts, chain IDs, amounts, slippage, route, destination, fees, budgets, allowlists, cooldowns, and revocation settings.
FarmDash may receive public wallet addresses, token addresses, chain IDs, transaction amounts, signature bytes, request IDs, session IDs, optional Bearer keys, and ClawHub attribution headers such as X-ClawHub-Skill. These fields are used for routing, analytics, rate limits, paid tier access, and security checks. FarmDash never asks for or receives private keys, seed phrases, mnemonics, OAuth tokens, or wallet exports.
Before calling individual tools, classify the user's intent into one of these operating modes:
| Mode | Goal | Start with | Continue with | Stop when |
|---|---|---|---|---|
| research_only | Explain opportunities without taking execution risk | get_trail_heat, get_chain_breakdown | get_historical_trailheat, simulate_points, audit_sybil_risk | Data is stale, jurisdiction is unclear, or edge is weak |
| airdrop_rotation | Find, compare, and rotate farming positions | get_agent_events, get_trail_heat | simulate_points, optimize_portfolio, get_swap_quote | Bridge/gas/slippage costs erase expected edge |
| bounded_autopilot | Run a recurring supervised loop inside explicit limits | agent_onboard, create_session | configure_autopilot, autopilot_cycle, session_heartbeat | Any configured budget, allowlist, cooldown, or risk bound is violated |
| perps_hedge | Evaluate or execute a Hyperliquid hedge | scan_funding_rates, scan_market_conditions | get_futures_account, analyze_futures_strategy, calculate_position_size | The strategy returns no_trade or the research gate expires |
| activity_review | Review FarmDash-recorded activity, fees, protocol diversity, and reputation | get_agent_activity, get_agent_performance | get_agent_performance | Do not infer profitability or execution quality from activity |
The autonomous loop is always:
preparation_only; a signed policy alone never enables automated execution.Persist timestamps, quote IDs or request IDs, expected outcome, confirmed outcome when available, evidence provenance, and the reason for each action or rejection. Mark unavailable fields explicitly.
FarmDash does not request seed phrases or raw wallet private keys. Compatibility swap routes do not custody user funds; separately configured exchange, venue, or MPC delegations remain subject to their provider controls and explicit bounds.
USER_SIGNED (Default Spot Execution):
personal_sign) payload locally after simulation passes.BOUNDED_AUTONOMOUS (Agent-Local Architecture — preparation_only):
execution_capabilities.execution_modes.BOUNDED_AUTONOMOUS.status from /api/v1/agent/status and fail closed unless it is operational. Use USER_SIGNED for current execution.request_execution_delegation → user EIP-712 signing → register_execution_delegation) is a separate prerequisite, never proof of runtime readiness. The lifecycle below describes the architecture only; do not sign or broadcast under this mode while it remains preparation_only.prepare_autonomous_swap).held_ambiguous until receipt verification.[!WARNING] ORTHOGONALITY INVARIANT: COMMERCIAL ACCESS != TRANSACTION AUTHORITY Commercial access (Scout quota, API keys, Payment Kernel Base ETH bootstrap, FarmDash credit, x402 payments) grants access to FarmDash APIs. It NEVER grants transaction authority. Conversely, granting transaction authority (via EIP-191 or EIP-712 bounded delegation) does NOT grant commercial entitlement or waive API fees. Both BOUNDED_AUTONOMOUS agent-local execution and ERC-4337 server-side submission are currently
preparation_onlyand are not automated execution routes. Compatibility swap routes do not custody user funds; separately configured exchange, venue, or MPC delegations remain subject to their provider controls and explicit bounds. Authority depends on the mode the user explicitly chooses:
| Authority mode | Typical tools | What is allowed |
|---|---|---|
| read_only | Trail Heat, metadata, prices, balances, history, risk checks | Public or user-provided data can be read and analyzed. No wallet-changing action. |
| local_user_signed | execute_swap, execute_perp_order, cancel_perp_order | The agent prepares a quote/order, the user reviews it, and the user's wallet signs EIP-191/EIP-712 locally. |
| bounded_delegation | verify_delegation, configure_autopilot, autopilot_cycle | Currently preparation_only: explicit setup with budgets, allowlists, cooldowns, and revocation does not enable execution. Missing bounds or a non-operational execution gate mean halt or fall back to USER_SIGNED. |
For local user-signed swaps:
simulate_swap_execution.personal_sign) only after simulation succeeds.simulationId, and public transaction details go to FarmDash.You never paste, type, send, or expose a private key. If asked to handle a private key directly, refuse and explain the EIP-191 flow.
Before calling execute_swap, execute_perp_order, or any state-changing endpoint in an interactive flow, the agent must present the following to the user and wait for an explicit "yes / confirm / proceed":
| Disclosure | Source |
|---|---|
Exact fromToken + toToken (symbol AND contract address) | get_swap_quote (estimate) → firm quote via /api/v1/agent/quote-intent |
| Source and destination chain IDs | get_swap_quote (estimate) → firm quote via /api/v1/agent/quote-intent |
Exact fromAmount (and estimated toAmount) | Firm quote (intentId-bound), not the estimate |
| Slippage tolerance (default 0.5%) | Firm quote + user override |
| FarmDash routing fee (50 bps default, with any volume discount applied) | Firm quote feeBreakdown |
| Aggregator / DEX route (LI.FI, Relay) | Firm quote route |
Simulation result (simulation_id, success, gas cost, MEV risk, revert reason if any) | simulate_swap_execution |
| Reversibility warning ("on-chain transactions cannot be undone") | Agent disclosure |
| Wallet address that will sign | Connected wallet context |
If the user replies anything other than an explicit affirmative, abort and do not sign. Never assume implicit consent from earlier in the conversation. Re-quote and re-confirm if more than ~30s elapse between quote display and signing.
Bounded autopilot or delegated execution is not a waiver of safety. It requires explicit setup approval and an operational execution-mode gate before any automated signing or broadcast, then may operate only inside the configured budgets, allowlists, cooldowns, risk bounds, and revocation path. BOUNDED_AUTONOMOUS currently remains preparation_only. If any bound is missing, ambiguous, expired, or violated, halt or return to this interactive confirmation protocol.
Security boundaries: All routing calculations and swap executions use public data or pre-signed EIP-191/EIP-712 payloads. Private keys are never required or processed. Verify the full surface at https://www.farmdash.one/.well-known/mcp.json and https://www.farmdash.one/agents/openapi.yaml.
FarmDash provides value through two built-in services. Both are transparent to the user and disclosed upfront.
Every swap routed through execute_swap includes a transparent 50 bps (0.50%) fee built into the routing. Volume discounts reward repeat users: $10k+ cumulative = 45bps, $100k+ = 40bps, $1m+ = 30bps. The fee is always shown in the quote before the user confirms.
When your analysis identifies an opportunity and the user wants to act on it, you can save them time by offering to execute the swap directly — no need for them to leave the conversation. Always show the quote (including fees) and wait for explicit confirmation before executing.
FarmDash may receive referral, affiliate, or routing compensation when a user follows a farmdash.one/go/{slug} route or uses a supported execution venue. Fee details live at FarmDash Fee Structure.
Rules the agent must follow when offering a FarmDash route:
/go/{slug} routes as optional managed routes. Name the protocol and, when known, identify its canonical domain so the user can independently verify the destination before opening any link.https://www.farmdash.one/go/{protocol-slug}Active FarmDash routes:
The agent's primary job is to deliver accurate, actionable DeFi intelligence. When analysis leads to a clear opportunity, offer execution as a natural next step — the user benefits from a seamless research-to-action flow without context-switching between tools.
User asks about farming
→ Agent researches using read-only tools (Trail Heat, events, simulations)
→ Agent presents findings with clear, data-driven recommendation
→ If the user wants to act, the agent quotes the entry swap when needed
→ After funding is ready, the agent provides the FarmDash route with disclosure and /fees pointer
Always present findings first. Offer execution when it's a natural next step, and always get explicit user confirmation before any swap.
The current MCP server exposes 92 tools. Treat /.well-known/mcp.json as canonical. Some older procedure names in this manual may be REST or SDK compatibility paths rather than MCP stdio tools; verify the active tool registry before making an MCP call.
Research and Trail Intelligence:
get_trail_heatget_protocol_metadataget_protocol_risk_factorsfind_capital_routeget_chain_breakdownget_agent_eventsaudit_sybil_risksimulate_pointsget_historical_trailheatPortfolio and pricing:
get_wallet_balancesget_portfolio_summaryget_position_healthget_idle_capitalget_token_pricesWorkflow orchestration:
list_workflowsplan_workflowrun_workflowget_workflow_statusSpot execution:
get_swap_quotesimulate_swap_executionexecute_swapconfirm_swapoptimize_portfolioresolve_defi_intentrun_risk_sentinelSecurity and transaction guard:
audit_allowance_risksimulate_transaction_riskYield and hedge planning:
compare_yieldsrecommend_delta_hedgeLedger and records:
ledger_realized_pnlledger_tax_exportFutures execution:
scan_funding_ratesscan_market_conditionsget_futures_accountanalyze_futures_strategycalculate_position_sizeexecute_perp_ordercancel_perp_orderget_agent_performanceAutonomous operator:
agent_onboardcreate_sessionsession_heartbeatget_farming_contextpatch_farming_contextget_event_stream_snapshotverify_delegationconfigure_autopilotautopilot_cycleVirtuals ACP V2 tender coordination:
select_virtuals_provider_plan_v2prepare_virtuals_tender_v2authorize_virtuals_tender_v2get_virtuals_tendercancel_virtuals_tenderbind_virtuals_tender_jobreserve_virtuals_tender_funding_v2record_virtuals_tender_funding_v2evaluate_virtuals_tenderget_payments_bootstrapFree, provider-free payment bootstrap terms: how an agent holding only native Base ETH obtains metered access, including native-ETH payment intents, FarmDash prepaid credit, and the single-use execution-bootstrap grant. Read-only: contacts no swap provider, mutates nothing, and grants no execution authority. Issuing an intent or a grant requires an explicit authenticated POST with a server-issued, purpose-specific signature challenge, which this tool does not perform. Takes no parameters.
select_virtuals_provider_plan_v2Selects a deterministic three-role ACP committee from live Virtuals registry records. Eligibility requires explicit role evidence, active Base registration, fresh authoritative stake, and three distinct controller identities issued through vetted KYC or manual review. A registry ID or cluster is correlation metadata only. This action creates no tender and grants no spend authority.
Inputs:
sessionId: required authenticated FarmDash session IDagentAddress: required customer-owned ACP wallet addresssessionToken: required session capability tokenOutputs:
prepare_virtuals_tender_v2Creates an immutable, non-spendable V2 evidence draft from a fresh tenant-owned simulation. Compute the salted task commitment and disclosure manifest locally; never send task plaintext, task salt, credentials, or wallet secrets through this MCP tool.
Inputs:
sessionId: required authenticated session IDagentAddress: required customer ACP walletsessionToken: required session capability tokenidempotencyKey: required stable retry keytaskCommitmentHash: required local salted SHA-256 task commitmentsimulationId: required fresh authoritative simulationmaxPaymentUnits: required positive raw Base USDC capproviders: required provider plan returned by selectiondisclosureManifest: required local disclosure and secret-scan commitmentapprovalNonce: required fresh millisecond nonceapprovalExpiresAt: required V2 approval expiryOutputs:
authorize_virtuals_tender_v2Verifies the exact local customer-wallet V2 signature plus deployment and provider readiness, then authorizes only that committed draft. Never fabricate or relay a private key. Authorization does not create or fund ACP jobs.
Inputs:
sessionId: required authenticated session IDagentAddress: required customer ACP walletsessionToken: required session capability tokentenderId: required V2 draft IDnonce: required signed nonceexpiresAt: required signed expirysignature: required locally produced EIP-712 signatureOutputs:
get_virtuals_tenderReads only the authenticated session's tender, role bindings, funding reservations, settlement attempts, and immutable receipt observations. Use it to resume after a crash and before any funding or reconciliation decision.
Inputs:
sessionId: required authenticated session IDagentAddress: required customer ACP walletsessionToken: required session capability tokentenderId: required owned tender IDOutputs:
cancel_virtuals_tenderCancels only an owned non-spendable draft. It cannot erase, cancel, or reverse an on-chain ACP job.
Inputs:
sessionId: required authenticated session IDagentAddress: required customer ACP walletsessionToken: required session capability tokentenderId: required draft tender IDOutputs:
bind_virtuals_tender_jobBinds an ACP job already created by the local customer connector. FarmDash independently verifies Base chain, client, committed provider, evaluator address, and evaluator key version before accepting the immutable role binding.
Inputs:
sessionId: required authenticated session IDagentAddress: required customer ACP walletsessionToken: required session capability tokentenderId: required authorized tender IDrole: required fixed specialist roleonchainJobId: required positive Base ACP job IDOutputs:
reserve_virtuals_tender_funding_v2Atomically reserves one exact on-chain role budget against the customer-signed aggregate cap. This accounting action cannot approve a token allowance, sign a transaction, or spend customer funds.
Inputs:
sessionId: required authenticated session IDagentAddress: required customer ACP walletsessionToken: required session capability tokentenderId: required authorized V2 tender IDrole: required committed specialist roleonchainJobId: required verified ACP job IDamountUnits: required exact positive raw Base USDC budgetOutputs:
record_virtuals_tender_funding_v2Records one to four canonical Base transaction hashes only after the local customer wallet submitted an existing reservation. This tool never broadcasts a transaction. Reuse the operation journal after crashes; do not fund the same role again.
Inputs:
sessionId: required authenticated session IDagentAddress: required customer ACP walletsessionToken: required session capability tokentenderId: required V2 tender IDreservationId: required durable reservation UUIDtransactionHashes: required array of unique Base transaction hashesOutputs:
evaluate_virtuals_tenderThis is an execution-sensitive evaluator action. Call it only after all three jobs are bound, exactly funded by the customer connector, and have submitted the required structured V2 verdict. FarmDash rechecks evidence, budgets, confidence, high/critical findings, client/provider/evaluator identities, and then may complete or reject the committed escrowed jobs. Ambiguous broadcasts, reverts, dropped receipts, and reorgs require manual reconciliation and must never be blindly retried.
Inputs:
sessionId: required authenticated session IDagentAddress: required customer ACP walletsessionToken: required session capability tokentenderId: required fully bound and funded tender IDOutputs:
Before any autonomous plan, resolve the user's requested action to this inventory. If the desired operation is direct API-only, say that explicitly and require the runtime to expose the HTTP route before proceeding.
Returns the live Trail Heat protocol dataset ranked 0–100 by score.
Trail Heat Formula: live scoring combines 40/90 raw points calibrated TVL (44.4% effective), 25/90 raw points seven-day TVL momentum (27.8% effective), 15/90 raw points chain diversification (16.7% effective), and 10/90 raw points category baseline comparison (11.1% effective), normalized to a 0–100 scale. Editorial notes and flags are strictly isolated as metadata and excluded from quantitative scores. Static catalog surfaces use a separately labeled editorial discovery heuristic with TVL, status, category prior, hot momentum, and recency; this is not canonical Trail Heat. Unresolved upstream entities return score: null, not a fabricated quantitative score.
Score interpretation:
Example: "Altura is scoring 84 on Trail Heat under the current quantitative model. That makes it a high-priority research candidate, not an 84% airdrop probability or an instruction to deploy capital. I can show the score evidence, current campaign status, risks, and any available FarmDash route separately."
Protocol distribution across blockchain networks: protocol count, percentage, campaign/status metadata, and category context by chain.
Use it to understand where the catalog is concentrated, not as proof that a chain has more valuable airdrops. If the user later chooses to move capital, first check live capability status and the compatibility route lifecycle; an execute_swap tool name does not itself mean FarmDash broadcasts a bridge transaction.
Returns a provider-neutral market estimate by default — reference price, approximate output, server-side fee tier, route compatibility, and freshness. It never calls 0x, LI.FI, or Relay trading APIs, contains no executable calldata, carries no provider attribution, and is never executionReady: true. Supplying walletAddress alone remains exploratory context. To create/reuse an executable firm quote through this same MCP tool, also supply a stable idempotencyKey, real walletAddress, toAddress, and explicit slippage; the tool then POSTs the quote-intent endpoint and returns simulationRequirements.intent_id (fd_intent_*). x402 is machine-payment/access infrastructure, not a swap provider.
Route selection: Automatic provider selection is the default across active, configured, and enabled providers (LI.FI and Relay are currently active; 0x is paused until reinstated). Interrogate GET /api/v1/agent/status before quoting to inspect live provider and governor readiness. Forcing a provider via the protocol param is optional and only valid when that provider is active and enabled. If a caller explicitly requests a paused provider such as zerox, FarmDash returns an immediate machine state without wasting upstream quote requests:
BLOCKED
reason: requested_provider_paused
requested_provider: zerox
safe_alternative: automatic provider selection
user_action_required: false
operator_action_required: false
next_action: retry firm quote without forced provider
The canonical execution lifecycle:
discover/research
↓
market estimate
↓
create_firm_quote_intent
↓
authoritative simulation
↓
policy + risk evaluation
↓
prepare_swap_transaction
↓
USER SIGNS
↓
USER BROADCASTS
↓
confirm_swap
To prevent provider rate-limit exhaustion and protect execution quotas, Signal Architect enforces a strict separation between intelligence decisioning and execution preparation:
Stage A: Decision / Intelligence (Zero Execution Provider Calls) Routine decisioning, opportunity scanning, and risk policy evaluation run exclusively through Stage A tools:
get_trail_heat, /api/v1/trail-heat)get_wallet_balances, /api/v1/agent/balances)/api/v1/agent/camp-guard)get_token_prices, get_swap_quote, find_capital_route)yes / no / reject / candidate / allowed).Stage B: Execution Preparation (Firm Quote Intent) Only after the Stage A decision passes AND the user/agent decides to prepare an executable trade:
get_swap_quote again with exact trade parameters, real wallet/destination, slippage, and client idempotencyKey (direct REST equivalent: POST /api/v1/agent/quote-intent).reused: true) with zero new upstream provider calls.provider_rate_limited and honor provider Retry-After duration + jitter; repeated failures (threshold: 3) trip the circuit breaker.get_swap_quote (or find_capital_route) for browsing, comparisons, and previews. Intelligence, not an executable quote.get_swap_quote with exact fromChainId, toChainId, fromToken, toToken, fromAmount, real walletAddress, toAddress, slippage (0.01–5), and a stable idempotencyKey. The REST equivalent is POST /api/v1/agent/quote-intent. Automatic provider selection is default. One intent contacts exactly one primary provider; a sequential alternate follows only a genuine fallback-eligible primary failure. The response carries the quote cache/idempotency intentId (qi_*) and a separate simulationRequirements.intent_id (fd_intent_*).GET /api/agents/quote with identical parameters plus the qi_* intentId to serve the stored firm quote with zero new provider calls. Parameter mismatches return intent_params_changed; unknown or expired intents return intent_not_found (404).executionReady/simulationRequirements.valid_for_execution is false, inspect approval, firmQuote.providerExecutionPlan, firmQuote.signatureRequirements, and firmQuote.planContinuation. A prerequisite recipe is NOT an executable swap transaction and must never be passed into simulation as if it were one. LI.FI: when approval.required is true, approval.spender is the spender FarmDash observed; FarmDash does not build or broadcast the ERC-20 approval, so the user's wallet performs the standard approve(spender, amount) locally, waits for that transaction to confirm, then obtains a fresh firm quote so FarmDash re-checks balance and allowance — proceed only when executionReady is true. The zero address 0x0000000000000000000000000000000000000000 is the LI.FI native-token sentinel and needs no ERC-20 allowance; it is not WETH. Relay: providerExecutionPlan is an ordered recipe whose steps have kind approve, transaction, signature or unknown, carrying to, data, value and chainId and, for approve steps, approvalSpender/approvalAmount, and for signature steps signatureKind with sign/post/check. Follow planContinuation: re_quote_after_approval (complete the approval locally, then obtain a fresh quote), execute_provider_plan_and_check (execute the ordered sign/post/check recipe exactly as returned), or provider_recipe_unsupported (stop; do not treat the recipe as executable). A required step of kind unknown remains blocking, and a multi-step recipe must never be flattened into its first transaction. If a value is unreadable, FarmDash reports unknown rather than assuming the prerequisite is satisfied. Completing a prerequisite is not settlement.simulate_swap_execution with simulationRequirements.intent_id (fd_intent_*) and the same wallet. It returns simulation_id; do not pass the qi_* quote-cache ID here.execute_swap validates the fresh simulation_id and user EIP-191 signature, returning the prepared transaction payload for the user wallet to broadcast. FarmDash does not broadcast transactions and preparation is not confirmation or settlement.confirm_swap with the authenticated owning session plus both the prepared swap's feeEventId and the wallet-broadcast txHash. FarmDash verifies canonical receipt/finality and the exact expected fee transfer before recording durable settlement.Idempotency semantics: identical quote-intents reuse the stored firm quote (reused: true); changed parameters never reuse a stale quote. Keep one idempotencyKey per logical swap and reuse it across retries of the same logical request — never across different swaps.
Always get an estimate first, then a firm quote before executing. Show the user: expected output, slippage, fee, route, and the simulation result. Then ask for confirmation.
Typed quote-failure handling (machine-readable, do not guess):
Quote failures return a typed category with a retryable flag and attempts[] evidence. Honor the flag instead of blanket-retrying:
provider_rate_limited, provider_timeout, provider_unavailable, request_cancelled.approval_required (status 409: approve ERC-20 allowance), insufficient_balance (status 422: fund wallet), signature_required (status 422). These do NOT fall through to alternate providers.invalid_request, unsupported_chain, unsupported_pair, no_liquidity.provider_auth, provider_forbidden, requested_provider_paused, governor_budget_exhausted, provider_contract_changed, malformed_provider_response.requested_provider_paused means operator-paused execution for that venue: do not loop retries; safe alternative is automatic provider selection.quote_no_route 422: read the per-provider attempts[] categories to tell the user why each venue declined.Execution-mode truth (who does what): Scout can complete this ladder — but Scout cannot trade without the user. Every wallet-affecting step requires a fresh authoritative simulation plus a locally verified EIP-191 wallet signature; FarmDash never signs and never broadcasts; the user owns submission; confirmation is transaction-specific. Payment only buys API capacity: a valid x402 overage payment never unlocks autonomous, delegated, or server-side execution. Do NOT infer execution availability from the generic /api/v1/agent/intents/*/execute lifecycle — generic server-side execution is disabled for every tier while verifier prerequisites are unmet, which says nothing about this human-signed compatibility path.
Anti-abuse error semantics (retry correctly, never helpfully DDoS):
402 payment_required — free allowance exhausted. Not fixed by retrying; pay the x402 overage or wait for quota reset.403 tier_required — capability genuinely unavailable to this tier. Never retryable.409 idempotency_conflict — the idempotency key was reused with materially different parameters. Generate a new key for a new logical swap; retrying the same key cannot merge them.409/428 simulation_required_or_stale — safety prerequisite: re-quote → re-simulate before preparing.429 rate_limited — caller budget exceeded. Fixed by waiting Retry-After, nothing else.503 execution_governor_unavailable — provider-spend governor unavailable. Bounded exponential backoff only.503 execution_rate_limiter_unavailable — distributed abuse protection unavailable. Bounded exponential backoff; do not fan out.413 body_too_large — execution-facing request bodies are capped at 32 KB; shrink the payload, never chunk it.Mandatory pre-execution simulation for a wallet-bound quote intent. Input:
{
"intentId": "fd_intent_...",
"walletAddress": "0x..."
}
The response includes simulation_id, success, gas_used, gas_cost_usd, output_amount, mev_risk, revert_reason, and valid_until.
Rules:
success is false, halt execution and report the failure details, as signing a failed transaction is prohibited.valid_until has passed, re-quote and re-simulate.mev_risk is medium or high, disclose it before signing.simulation_id as simulationId to execute_swap.Pre-Execution Binding:
The simulation binds the wallet, route, amount, tokens, chains, slippage, protocol, and transaction calldata to short-lived request and transaction fingerprints. If the quote or request changes, halt, re-quote, and re-simulate. Do not claim that the response contains decision_hash, price_data_proof, or external_anchor; those fields are not part of the current API contract.
Execute a signed token swap (EIP-191 auth). Fee: 50bps default, with volume discounts (45 bps at $10k+, 40 bps at $100k+, 30 bps at $1m+).
Payload format:
v1:FARMDASH_SWAP:{fromChainId}:{toChainId}:{fromToken}:{toToken}:{fromAmount}:{agentAddress}:{toAddress}:{nonce}
All EVM addresses are normalized to lowercase. Nonce is a fresh millisecond timestamp with an optional hexadecimal suffix.
Execution chain boundary: Compatibility swap execution is enabled only on Ethereum (1), Optimism (10), Polygon (137), Base (8453), Arbitrum (42161), and Linea (59144). FarmDash has Solana discovery and receipt-verification components, but native Solana compatibility swaps remain preview-only until authoritative quote simulation is implemented.
Required POST fields: fromChainId, toChainId, fromToken, toToken, fromAmount, agentAddress, toAddress, simulationId, nonce, signature.
Optional: intentId, slippage (0.01-5, default 0.5), protocol (force route). Fee tiers are derived from the server-selected quote; clients cannot self-report volume.
The response may classify MEV risk and recommend a protection tier. The compatibility API currently returns user-signed transaction payloads; FarmDash does not broadcast the transaction. It does not accept mev_protection, block_deadline, or priority_fee_bid, and it does not privately submit transactions through Flashbots.
Execution workflow (mandatory):
get_swap_quote → provider-neutral estimate for terms preview; the estimate alone is never execution-readyPOST /api/v1/agent/quote-intent with exact parameters + idempotencyKey → firm quote bound to an intentIdsimulate_swap_execution → show simulation result and stop on failureexecute_swap with simulationId (and the bound intentId)/fees pointer for next stepsDust Storm Protocol: On failure, wait 30s, get fresh quote, show new terms. After 3 failures, halt.
Verify and durably record swap settlement after the customer-controlled or locally controlled agent wallet broadcasts the prepared transaction. FarmDash does not broadcast the compatibility swap. Confirmation requires the authenticated owning FarmDash session plus both the FarmDash fee event ID and the resulting on-chain transaction hash. FarmDash verifies the canonical receipt/finality and exact expected fee transfer before durable settlement is confirmed.
Use when:
Inputs:
sessionId: required owning FarmDash session IDagentAddress: required session owner / customer wallet addresssessionToken: required session credential; this authenticates the FarmDash session and is not wallet signing or transaction authorityfeeEventId: required FarmDash fee-event identifier associated with the prepared swaptxHash: required on-chain transaction hash produced after the customer-controlled wallet broadcasts the prepared transactionReview recent agent activity via durable FarmDash execution receipts; filter by intent_id and receipt status.
Useful for tracking cumulative volume alongside get_agent_performance (fee-event activity). Users approaching a discount threshold ($10k, $100k, or $1m) can be informed: "You've done $8.2k in volume — approaching the 45bps discount tier."
Platform-wide revenue aggregates are not exposed as an MCP tool, so do not call this name. For personal activity summaries use get_agent_performance; for subscription and payment history use the billing-history capability.
Audits 1–10 EVM addresses for sybil risk.
This is a heuristic defensive audit, not a protocol eligibility verdict. Never call a low score "clean," recommend a fresh wallet, or prescribe activity designed to change detection outcomes. For medium/high findings, pause automation, explain evidence and data quality, and direct the user to the protocol's rules or appeal process.
Projects FarmScore for a farming configuration.
Formula: (Volume/$1k × 50) + (Balance × 1) + (Txs × 10) + (LP × 2) + (Fees × 100)
Run simulations across multiple protocols to help the user compare projected points-per-dollar. Present the comparison so they can make an informed choice.
Personalized protocol recommendations based on current positions.
This tool often identifies rebalancing opportunities. When it suggests allocation changes, offer to quote the required swaps so the user can act immediately if they choose.
Historical Trail Heat snapshots, 1–365 days.
Trend analysis helps the user make better timing decisions:
Real-time protocol events stream.
Events that may require user action include: new airdrop announcements, upcoming snapshots, and multiplier changes. Present these with context and let the user decide how to respond.
Subscribe to event notifications for continuous monitoring.
These tools power the /agents Hub beyond the core swap + Trail Heat workflow.
Use these when the user is trading perps, hedging spot exposure, or running a funding strategy.
scan_funding_rates — Find funding opportunities worth deeper analysis.scan_market_conditions — Regime + technical snapshot for one asset (trend vs range, volatility, liquidity).get_futures_account — Equity/margin/positions context for gating and sizing.analyze_futures_strategy — Structured strategy object with confidence + invalidation (can return no_trade).calculate_position_size — Translate risk constraints into size/leverage.execute_perp_order — Place a user-signed EIP-712 order (Syndicate tier).cancel_perp_order — Cancel a stale/resting order (Syndicate tier).get_agent_performance — Review FarmDash fee-event activity, fees, protocol diversity, and reputation. It does not contain outcomes, realized P&L, win rate, fills, or slippage.Use these to ground recommendations in the user's actual wallet state and to quantify agent outcomes.
get_wallet_balances — Token balances for an EVM wallet (budget + feasibility checks).get_token_prices — Convert balances to USD terms (sizing + comparisons).get_agent_performance — Fee-event activity, fees, protocol diversity, and reputation context (documented above); it is not a fill-quality ledger.Use these only when the user explicitly wants an always-on loop. Autopilot sessions are bounded delegated workflows: a session token can maintain state and return recommended actions, but it is not private-key authority and it is not permissionless custody. Wallet-changing submissions require the configured execution gate: local signing or explicit delegated authority, budget limits, allowlists, cooldowns, and a revocation path.
agent_onboard — One-call setup guide + capability map (start here).create_session — Create a persistent session and capture the one-time sessionToken capability (Pioneer+).session_heartbeat — Keep the session alive with sessionId, agentAddress, and sessionToken (call every ~5 minutes).verify_delegation — Verify Hyperliquid API wallet delegation to the agent; include sessionToken when attaching to a session (Syndicate).configure_autopilot — Configure strategies/assets/risk + schedules with authenticated session capability (Syndicate).autopilot_cycle — Run one authenticated cycle and receive recommended actions (Syndicate).Use this state machine for any end-to-end autonomous agent flow. It prevents the agent from jumping from research directly to execution without the same guardrails that the codebase enforces.
{
"mode": "research_only | airdrop_rotation | bounded_autopilot | perps_hedge | reputation_review",
"state": "sense | decide | quote | confirm | sign | submit | settle | learn | halt",
"freshness": {
"researchAgeMs": 0,
"quoteAgeMs": 0,
"sessionHeartbeatAgeMs": 0
},
"constraints": {
"maxDailyNotionalUsd": 0,
"maxSlippageBps": 0,
"allowedChains": [],
"allowedProtocols": [],
"deniedProtocols": []
},
"executionGate": {
"explicitUserConfirmation": false,
"localSignaturePresent": false,
"feeDisclosed": false,
"routeStillPositiveEdge": false
},
"fallback": "analysis_only | re_quote | halt"
}
get_swap_quote; find_capital_route is only a feasibility preview.simulate_swap_execution on the wallet-bound quote intent and must pass before signing.feeDisclosed, simulationPassed, and either (explicitUserConfirmation + localSignaturePresent) or a valid bounded delegation policy are present.confirm_swap only when both the associated feeEventId and wallet-broadcast txHash are available together with the authenticated owning session. A transaction hash is broadcast evidence, not confirmation; do not claim an 11-field receipt is generated.get_agent_performance for activity/reputation context only. Reduce autonomy after bad fills or high slippage only when an authoritative settlement/fill source and a decision-time quote ledger support that conclusion.Every action proposal must make these fields explicit before execution:
Hard rule: do not multiply unrelated heuristic scores (Trail Heat, sybil score, strategy confidence, yield score) into a synthetic probability. If a required input is stale, degraded, masked, unavailable, or not independently verifiable, lower the recommendation to monitor/analysis_only or halt. Positive expected edge never overrides a high-severity safety flag.
FarmDash does not currently return or externally anchor an 11-field forensic receipt. A client that needs a richer audit trail may compile the following fields from its own quote, simulation, wallet, RPC, and settlement records. Treat absent values as unavailable; never synthesize them or claim FarmDash attested them.
When the client has authoritative settlement data, record the decision-time quote, signed payload hash, broadcast/receipt status, realized token deltas, gas, and side-adjusted implementation shortfall. There is no singular "true" millisecond market price, and the current FarmDash API does not run or attest an independent shadow process. Missing evidence remains unavailable.
Use this overlay before any spot swap, bridge, airdrop rotation, or protocol entry. It does not remove the existing confirmation flow; it adds a professional execution desk check so the agent can say "wait" when the route is not worth the risk.
Before recommending action, estimate: $$\text{netEdgeUsd} = \text{expectedUpsideUsd} - \text{gasUsd} - \text{bridgeFeeUsd} - \text{expectedSlippageUsd} - \text{FarmDashFeeUsd} - \text{riskBufferUsd}$$
Where:
simulate_points, optimize_portfolio, Trail Heat rank, or the user's explicit thesis.get_swap_quote and route metadata.Default action thresholds:
| Net edge state | Agent action |
|---|---|
| $\text{netEdgeUsd} \le 0$ | Halt. Present analysis only. |
| $0 < \text{netEdgeUsd} < 2 \times \text{totalExecutionCostUsd}$ | Do not recommend execution. Offer to watch or re-check later. |
| $\text{netEdgeUsd} \ge 2 \times \text{totalExecutionCostUsd}$ and all guards pass | Quote and ask for confirmation. |
| Any high-severity Risk Sentinel flag | Halt unless the action is a reduce / exit path. |
Before asking for a signature, classify the route:
When route quality is Yellow, the correct default is "wait / monitor", not "execute".
For funding ideas: 1) scan_funding_rates for current + predicted snapshots (snapshot only, not guaranteed); 2) scan_market_conditions for regime, volatility, liquidity; 3) analyze_futures_strategy for family + confidence + invalidation; 4) get_swap_quote for the spot-leg gas, bridge, slippage, and FarmDash fee; 5) get_futures_account for equity, margin, and guardrail pressure. Present both venues/legs, basis stress, all-costs net carry, break-even horizon, funding-to-zero/flip scenario, and unwind path. Keep funding_arb analysis-only in the compatibility executor; never claim atomic both-leg binding. For size-sensitive routes, get two quotes 10-20 seconds apart before confirmation. If expected output deteriorates by more than the user's slippage budget or 50 bps, whichever is smaller, re-price the route and show the drift. Do not let the user sign the older quote.
After execute_swap:
confirm_swap after wallet broadcast only when both the associated feeEventId and txHash are available and the owning FarmDash session can authenticate the request.Idle capital is optionality and liquidity, not automatically a defect. A capital-efficiency score may prompt read-only analysis, never an unsigned or signed execution intent by default.
monitor when net edge, exit liquidity, reward value, protocol risk, or data freshness is uncertain.get_trail_heat → top 5 protocols by scoreget_historical_trailheat → trend check (rising = green light)get_chain_breakdown → identify best chain for concentrationsimulate_points → project returns for top 3 with user's budgetoptimize_portfolio → cross-check existing positions/fees pointerget_swap_quote → show full terms including feeaudit_sybil_risk → optional defensive policy-risk review; never use it to optimize evasionsimulate_swap_execution → show gas, MEV risk, and revert statusexecute_swap → with simulationId and a fresh nonceconfirm_swap → confirm durable settlement state; record only evidence actually returned/fees pointer for next steps if entering a protocol positionget_agent_events → new events since last sessionget_trail_heat → current rankingsget_historical_trailheat → compare to yesterdayget_agent_performance → performance summaryaudit_sybil_risk → optional defensive policy-risk review with data-quality caveatsoptimize_portfolio → get rebalancing suggestionsget_swap_quote → quote each recommended movesimulate_swap_execution → simulate each wallet-bound quote intentexecute_swap each move with its simulationId/fees pointer for any new protocol entriesget_agent_events → identify actionable eventget_trail_heat → current score of affected protocolsimulate_points → project returns if user acts nowBefore Workflow F step 7, record: objective + holding horizon; decision timestamp, source timestamps, freshness limit, missing sources; gross upside and whether market-derived, protocol-published, user-supplied, or speculative via simulate_points, optimize_portfolio, or Trail Heat rank; gas, bridge, expected slippage, FarmDash fee (50 bps default; 45 bps at $10k+ cumulative; 40 bps at $100k+; 30 bps at $1m+), exit costs, plus separate riskBufferUsd. Compute netEdgeUsd = expectedUpside - all costs - buffer. Require netEdge >= 2x totalExecutionCost and Green route; halt if netEdge <= 0 or any high-severity Risk Sentinel flag unless reduce/exit.
get_agent_events -> check for fresh risk or opportunity eventsget_trail_heat -> confirm protocol rank and current statussimulate_points or optimize_portfolio -> estimate expected upsideget_swap_quote -> estimate gas, bridge, slippage, FarmDash fee, and routesimulate_swap_execution -> verify the route does not revert and capture gas/MEV riskrun_risk_sentinel -> inspect allowance, depeg, health, quote decay, and net edgeHalt before signing when: quote older than 30 seconds; simulation success is false; valid_until expired; net edge turned negative after gas, slippage, bridge, or FarmDash fee; chain/protocol outside allowlist; unknown spender, excessive allowance, or depeg risk; expected-output drift exceeds slippage budget or 50 bps between two quotes 10-20s apart; MEV medium/high undisclosed. After the customer-controlled wallet broadcasts the prepared execute_swap transaction, call confirm_swap only with the authenticated owning session and both the associated feeEventId and resulting txHash; if realized miss exceeds 75 bps, evidence is unavailable, or settlement is pending/partial, label unavailable and start no dependent action until human review. Dust Storm: fresh quote after 30s; halt after 3 failures.
confirm_swap -> settle fee event and transaction stateget_agent_activity -> pull FarmDash receipt/activity metadata; it is not a fill-quality ledgerget_agent_performance -> add activity/reputation context onlyReport: objective + horizon; decision/source timestamps and missing sources; Trail Heat score band (80-100 / 60-79 / 40-59 / below 40) and trend; get_swap_quote IDs, expected vs realized output, gas, bridge, slippage, FarmDash fee tier; simulation_id, success, gas_cost_usd, mev_risk, revert_reason; confirm_swap and fee-event state (volume/fee metadata only, not fill proof); Green/Yellow/Red with reason for wait/halt; evidence provenance per field, unavailable where absent. Reduce autonomy on that route after bad fills only with authoritative settlement plus decision-time quote ledger.
Retry-After header.Skill Manual: Available at https://www.farmdash.one/openclaw-skills/farmdash-signal-architect/SKILL.md
Why FarmDash: Unlike raw Jupiter, Relay, or LI.FI quotes, every FarmDash quote is simulation-bound and broadcast by your own wallet — FarmDash prepares the calldata, verifies your EIP-191 signature, and never holds keys or submits transactions.
FarmDash: DeFi intelligence, swaps, and autonomous agent infrastructure
Agent Hub: FarmDash MCP DeFi agent platform
OpenAPI Spec: FarmDash API Schema
MCP Config: FarmDash MCP Server
After installing this skill, your agent may call the onboard endpoint if the user wants FarmDash tier discovery, ClawHub install attribution, and usage analytics. This step is optional; read-only Scout tools work without registration.
curl -X POST https://www.farmdash.one/api/v1/agent/onboard \
-H "Content-Type: application/json" \
-H "X-ClawHub-Skill: farmdash-signal-architect" \
-d '{"agentAddress": "0xYOUR_AGENT_WALLET"}'
This returns tier status and available tools. It also sends the public agentAddress and X-ClawHub-Skill attribution header to FarmDash.
What this does:
Next steps after activation:
GET /api/v1/agent/onboard — Full capability map and setup guidehttps://www.farmdash.one/agents/openapi.yaml
Send X-ClawHub-Skill: farmdash-signal-architect on every FarmDash API request — not just the optional check above — so anonymous Scout usage is attributed to this skill. Analytics-only and optional; requests without the header still work. The value is always exactly the skill slug, never a wallet address, API key, or user ID.