{
  "markdown": "# hyperevm-mcp\n\n**Ask your AI assistant about the Hyperliquid ecosystem in plain English.**\nIt reads. There is nowhere to put a private key, and that is the whole security model.\n\n```\n\"what's the best HYPE yield right now\"\n```\n\n```\nNetwork HYPE staking APR: 1.80%–2.25% across 27 active validators.\nAnything far above this is a reward or a risk premium.\n\n## Liquid staking (HYPE LSTs)\n| Protocol       | Token |   APY |  7d |     TVL |\n| -------------- | ----- | ----: | --: | ------: |\n| Kinetiq kHYPE  | KHYPE | 1.94% | n/a | $825.9M |\n| stHYPE         | —     |   n/a | n/a | $173.9M |\n| Kinetiq kmHYPE | —     |   n/a | n/a |  $36.1M |\n\n## Lending markets\n| Protocol         | Asset | Supply | Borrow |  Util | Max LTV |    TVL |\n| ---------------- | ----- | -----: | -----: | ----: | ------: | -----: |\n| HyperLend Pooled | USDC  |  5.84% |  7.36% | 88.2% |   62.0% | $12.1M |\n| HyperLend Pooled | USD₮0 |  5.15% |  7.94% | 72.2% |   62.0% |  $1.8M |\n| HyperLend Pooled | WHYPE |  0.61% |  0.98% | 78.0% |   60.0% | $42.1M |\n\n## Other HYPE yield (LP, looping, fixed-term)\n| Protocol     | Pool                  |    APY |  Base |       7d |   TVL | IL  |\n| ------------ | --------------------- | -----: | ----: | -------: | ----: | --- |\n| nest CL      | WHYPE-USDC (0.0638%)  | 38.80% |   n/a |  +0.33pp | $5.9M | yes |\n| nest CL      | WHYPE-UBTC (0.2%)     | 32.78% |   n/a |  -9.93pp | $1.7M | yes |\n| Ramses CL V2 | WHYPE-USDC (CL 0.11%) | 30.14% | 0.00% | -29.96pp | $1.8M | yes |\n\n## Protocol vaults\n| Vault                         |     TVL |     24h |      7d |     30d |\n| ----------------------------- | ------: | ------: | ------: | ------: |\n| Hyperliquidity Provider (HLP) | $225.7M | -0.003% | +0.010% | -0.024% |\n\nNote: 3 of the rows above are mostly token emissions rather than earned yield.\nCompare the APY and Base columns — emissions stop when the issuing team\ndecides they stop.\n```\n\nFour of those cells read `n/a`. That is the point: stHYPE publishes no yield pool, and kHYPE's weekly delta came back from the source implying the pool paid nothing seven days ago, which its own daily history contradicts. A number we cannot stand behind is not printed.\n\nThe vault row shows the same rule twice over. HLP has no pool on DefiLlama at all,\nso a table built from that source alone silently omits the largest single place\nto deposit on the chain — it is read from Hyperliquid instead. And Hyperliquid's\nown APR field for it is *not* shown, because the same value means one thing as\nan annual rate and something 365 times larger as a daily one, and the vault's\nhistory does not settle which. What is shown is realised profit and loss per\nwindow, divided here, where the arithmetic is ours to defend.\n\nThen ask whether to believe one of those rates:\n\n```\n\"has that Ramses WHYPE-USDC pool actually been paying 100%?\"\n```\n\n```\n## Pool history\nPool:                   WHYPE-USDC\nProject:                Ramses CL V2\nAPY now:                16.86%\nAPY 7d ago:             144.75%\nAPY 30d ago:            107.77%\nEarned vs emitted now:  0.00% earned · 16.86% emitted\nTVL change over window: -10.7%\n\n| Date (UTC) |     APY | Earned | Emitted |   TVL |\n| ---------- | ------: | -----: | ------: | ----: |\n| 2026-06-27 | 107.77% |  0.00% | 107.77% | $1.9M |\n| 2026-07-09 |  70.09% |  0.00% |  70.09% | $2.0M |\n| 2026-07-21 |  58.80% |  0.00% |  58.80% | $1.8M |\n| 2026-07-26 |  16.86% |  0.00% |  16.86% | $1.7M |\n```\n\nZero earned, every day, for a month.\n\n## Install\n\n**Claude Code**\n\n```bash\nclaude mcp add hyperevm -- npx -y @sand0vvv/hyperevm-mcp\n```\n\n**Cursor, Claude Desktop, or any MCP client** — add to the config file:\n\n```json\n{\n  \"mcpServers\": {\n    \"hyperevm\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@sand0vvv/hyperevm-mcp\"]\n    }\n  }\n}\n```\n\nThat is the whole setup. Nothing to fill in afterwards — there is no account to authenticate against.\n\n## Try asking\n\n- *what's the best HYPE yield right now*\n- *compare lending rates on HyperEVM*\n- *which HYPE pools are just token emissions and which actually earn*\n- *has that 40% APY held up, or is it decaying*\n- *is BTC funding actually stable, or was that one hour*\n- *who earns the most fees on this chain*\n- *could I actually get out of $500k of HYPE*\n- *which protocols grew this week*\n- *tell me about HyperLend*\n- *what's in this wallet: 0x…*\n- *where should I stake HYPE and what does the commission cost me*\n\n## Tools\n\nNine tools. Five report the present, three report how it got there, one reads an address.\n\n| Tool | What it answers |\n| --- | --- |\n| `hyperevm_yields` | Every yield on HYPE in one table: liquid staking, lending with supply/borrow/utilisation/max LTV, LP and looping, and the HLP vault — with earned yield separated from token emissions |\n| `hyperevm_protocols` | What is deployed on HyperEVM: chain TVL, per-protocol TVL, 1d/7d change, sortable by size or weekly growth; a detail card for any one protocol |\n| `hyperevm_fees` | Fees users actually paid, ranked over 24h/7d/30d. TVL says how much money sits somewhere; this says whether anyone is paying to use it |\n| `hl_market` | Perp mark price, funding hourly and annualised, open interest, 24h volume; spot pairs; predicted funding across Hyperliquid, Binance and Bybit |\n| `hl_staking` | HYPE validators ranked by predicted APR, with commission, uptime and stake share — what the network pays before any wrapper takes its cut |\n| `hyperevm_pool_history` | One pool's APY and TVL over weeks, split into earned versus emitted — so a headline rate can be checked against its own history |\n| `hl_funding` | How funding actually behaved over days: average, range, how much of the time it held its sign, and what the position would have paid |\n| `hl_orderbook` | Spread and resting depth, and whether a given trade size fills inside the visible book — or a plain statement that it does not |\n| `hyperevm_wallet` | Any public address: account value, open positions with entry, unrealised PnL and liquidation price, spot balances, HYPE staking |\n\nThe pairs are deliberate. `hyperevm_yields` and `hl_market` tell you what a number is now; `hyperevm_pool_history` and `hl_funding` tell you whether to believe it. A 47% pool that has been 100% emissions for a month and a 20% pool earning fees are not the same product, and only the second pair can tell them apart.\n\n## Slash commands\n\nThe server also ships MCP prompts, which appear as slash commands in Claude Code:\n\n| Prompt | What it does |\n| --- | --- |\n| `yield-report` | Staking, liquid staking, lending and LP in one pass, ranked with emissions called out |\n| `protocol-brief` | One protocol: size, mechanics, where its yield sits, how it compares |\n| `wallet-review` | A public address: exposure, funding cost per day, idle balances |\n| `funding-scan` | Where Hyperliquid funding diverges from Binance and Bybit |\n\n## What this server does not do\n\nIt has no write path. Not \"disabled by default\" — the code to sign or send anything does not exist.\n\n- **Nothing here can move money.** The code that would sign a transaction is not in this package.\n- Nothing to configure either: the server reads no environment variables, so there is nothing to leak.\n- The filesystem is never touched, no process is ever started, and no telemetry leaves the machine.\n- Talks to exactly four hosts, hardcoded in [`src/core/http.ts`](src/core/http.ts):\n  `api.hyperliquid.xyz`, `api.llama.fi`, `yields.llama.fi`, `rpc.hyperliquid.xyz`.\n  No tool takes a URL, host or chain as a parameter.\n\n**None of that is a promise — it is a test.** `npm run audit` checks every line above against the\nsource and exits non-zero if one stops being true; it runs in CI before publish. Adding a `fs` import\nor a second network host fails the build rather than reaching you:\n\n```\n$ npm run audit\ncapability\n  ok    does not read or write the filesystem\n  ok    does not spawn processes\n  ok    does not open raw sockets or listen\n  ok    does not evaluate code at runtime\n  ok    reads no environment variables — there is nothing to configure\n  ok    no crypto, signing or key handling anywhere\nnetwork surface\n  ok    contacts exactly 4 hosts, all hardcoded\n  ok    no tool accepts a URL, host or endpoint as a parameter\n  ok    every outbound call goes through the allowlisted fetch wrapper\ntype-level guarantee\n  ok    the Safe escape hatch exists in exactly one file\n  ok    renderers accept only Safe text, so unsanitised output cannot compile\n  ok    prompts are authored here, never assembled from network data\ndata handling\n  ok    never reads free-text descriptions from upstream\n  ok    stdout carries the MCP protocol only\n  ok    every tool answers through the envelope, including on failure\nsupply chain\n  ok    no install-time lifecycle scripts\n  ok    exactly 2 direct dependencies\n  ok    published tarball contains build output only\n\nevery claim in the README is enforced here\n```\n\nThe whole server is a few thousand lines of TypeScript. It is meant to be read before you install it.\n\n## Three details worth knowing\n\n**Lending rates are not where they look like they are.** DefiLlama's `/pools` reports `0.00%` for\ncollateral markets — truthfully, since their supply rate really is zero. The rate lives in a second\nendpoint, `/lendBorrow`, joined on the pool id. A naive integration prints a table of zeros over a\n$239M market. This one joins them and shows supply, borrow and utilisation separately.\n\n**Missing data is shown as missing.** stHYPE ($172M) and beHYPE publish no yield pool on DefiLlama,\nso their APY appears as `n/a` next to their real TVL, with the network staking APR printed above as a\nreference. A zero standing in for \"unknown\" would be the most expensive thing this tool could print.\n\n**Emissions are not yield.** The top pools by headline APY are often paying entirely in their own\ntoken. The table carries a `Base` column next to `APY`, so `48.86% / base 0.00%` reads as what it is,\nand a note names the rows where most of the number is emissions. The `7d` column shows the same\nthing over time: that pool's APY fell 30 percentage points in a week.\n\n## Third-party text and prompt injection\n\nThis server is read-only and cannot act. But it carries text written by strangers into your agent's\ncontext, next to whatever else that agent can do — a wallet, a shell. Validator names on Hyperliquid\nare free text set by whoever runs the validator; DefiLlama protocol names come from pull requests.\nSo the text is treated as hostile, in three layers.\n\n**1. Fields that are not needed are never read.** `description` — 445 characters of free text on a\nvalidator, 599 on a DefiLlama protocol — is not parsed anywhere in the code. The audit fails the build\nif that changes.\n\n**2. An allowlist, not a blocklist.** Everything printed passes a filter that keeps letters, digits,\ncurrency signs and a short list of punctuation, and drops everything else. Not a list of bad\nsequences to catch — a list of what may pass. So `<|im_start|>`, `[INST]`, `###`, `{{`, backticks and\ntable pipes cannot survive, because the characters that build them are not on the list. Input is\nNFKC-normalised first, so full-width lookalikes fold to ASCII before the filter rather than after.\n\n**3. The type system, not discipline.** Sanitised text has its own type. The renderers accept nothing\nelse, so printing a raw upstream field is a compile error rather than a code-review miss. There is\nexactly one place where that type can be created from a plain string, and the audit fails the build\nif a second appears.\n\nA test feeds a poisoned upstream response — chat-template markers, a `javascript:` URL, an injected\ninstruction, a fence in the slug — through a real tool and asserts that none of it reaches the output\nin a form that can do anything.\n\n**What this does not do:** it cannot stop plain English. A validator named \"ignore previous\ninstructions\" still reads as those words. The answers to that are the field whitelist, the 24-character\ncap, and the fact that this server exposes no action for such a sentence to trigger — not a cleverer\nfilter. Anyone claiming a filter solves prompt injection is selling something.\n\nDetails in [SECURITY.md](SECURITY.md).\n\n## Requirements\n\nNode 20 or newer. Two direct dependencies: `@modelcontextprotocol/sdk` and `zod`.\n(The SDK brings its own tree, as it does for every MCP server; nothing else is added on top.)\n\n## Development\n\n```bash\nnpm install\nnpm test          # build, unit tests, behaviour checks — runs offline\nnpm run verify    # the above plus the self-audit and a real MCP handshake\n```\n\nIndividually:\n\n```bash\nnpm run build\nnode scripts/test.mjs           # units: numbers, tables, the sanitiser, the cache\nnpm run check     # behaviour: injection end-to-end, allowlist, retry, stale fallback, outage\nnpm run audit     # enforces every claim in this README against the source\nnpm run preflight # fails if this repository contains anything that should not be public\nnpm run smoke     # every tool against the live public APIs\nnpm run stdio     # spawn the server and speak MCP to it\n```\n\nThe unit tests cover the parts that decide what a reader sees: that \"unknown\"\nrenders as `n/a` and never as `0`, that percentage points and percentages stay\ndifferent units, that a cell cannot forge a table column, that a failed refresh\nserves the previous answer and says so. The behaviour checks drive poisoned\nupstream responses through whole tools.\n\n## Disclaimer\n\nUnofficial and community-built. Not affiliated with Hyperliquid or with any protocol listed.\nData comes from public APIs and may be delayed or wrong; DefiLlama refreshes roughly every 30 minutes.\nWhen a refresh fails the previous answer is served with a visible \"REFRESH FAILED, this is N min old\"\nlabel rather than an error — old data is useful, old data pretending to be fresh is not.\nNot financial advice.\n\nMIT © sand0vvv\n",
  "bytes": 13822,
  "sha": "9fea4ca0cfbfb26ce3c2b7703e225bfeba38bfb81ee418c9f04f566f9d95066d",
  "repo_slug": "sand0vvv/hyperevm-mcp",
  "fonte": "repo",
  "truncated": false,
  "api": "https://agentalog.com/api/listings/mcp_io_github_sand0vvv_hyperevm_mcp_afe6319a/readme"
}