The open SDK, contract interfaces, agent skills, and MCP tooling for creator-run USDG vaults on Robinhood Chain — prepare and verify, keep signing control.
Website · Docs · Skills · MCP · Contracts · Security · X
$HISS 0x47162135cc8fb253f939Bd70e3D2B83075eaeBa3 · Robinhood Chain 4663
HISS is a toolkit for building transparent, creator-run investment vaults and agent-native financial tooling on Robinhood Chain.
A HISS vault is an on-chain ERC-4626 basket denominated in USDG (a 6-decimal stablecoin). A creator declares a target-weight strategy over tokenized equities, ETFs, and cash — as a signed, hashed vault manifest — and publishes it to an on-chain registry. Depositors share the vault's profits and losses pro-rata by share. Every strategy change, rebalance, and fee event is disclosed and, where it touches the chain, produces a verifiable receipt.
HISS is compilation and verification software. It prepares, simulates, scores, and records — it does not take custody of assets, does not hold your keys, and does not place brokerage orders. You keep signing control of everything you do. Protocol-level actions are governed by a 2-of-3 Treasury Safe.
This repository is the open SDK, contract interfaces, and documentation — not the production application source. The hosted product lives at hiss.finance. This repo lets you build against the same primitives, read the same on-chain state, and integrate agents.
- Create and publish vaults — compose a target-weight basket, validate its risk fuses, and publish the manifest to the on-chain registry. See Create a vault.
- Prepare deposits and withdrawals — build the transactions a depositor signs from their own wallet, with full fee and slippage disclosure. See Deposit / Withdraw.
- Stake $HISS — enter the xHISS single-asset staking vault, manage cooldown and redeem windows.
- Read live protocol state — deployments, fees, vault readiness, staking and reward status, straight from chain reads.
- Ship agent tooling — an MCP server exposing 22 read/prepare tools, plus agent skills, x402 paid endpoints, and Bankr command rails, so agents can prepare (never execute) financial actions.
- Score and audit — run the CoilOps compile-and-verify workbench over rebalance policies and produce post-run audits.
| I want to… | Start here | Docs |
|---|---|---|
| Build & publish a vault | Create a vault manifest | Create a vault |
| Integrate HISS into an app | Prepare a deposit with the SDK + React | SDK · React |
| Equip an AI agent | Install HISS Agent Skills | Agent skills |
| Run the MCP server | Agent / MCP integration | MCP |
| Use the CLI | Quickstart → hiss status |
CLI |
| Verify contracts & receipts | Contracts & addresses | Contracts · Receipts |
The packages are not yet published to npm — build them from source with
pnpm. Node.js 20+ and pnpm 10+ are required (the repo pinspnpm@10.28.1). The TypeScript packages run directly from source viatsx; the Solidity contracts use Foundry. No private credentials are required — reads use a public RPC you supply.
# 1. Clone
git clone https://github.com/HissFinance/hiss.git
cd hiss
# 2. Install workspace dependencies
pnpm install --frozen-lockfile
# 3. Build every package
pnpm build
# 4. (optional) Run the test suites
pnpm testOnce installed, import the workspace packages into your own app, or run the CLI:
# Read live protocol status from Robinhood Chain (supply a public RPC)
pnpm --filter @hiss-finance/cli start status \
--rpc-url https://rpc.mainnet.chain.robinhood.comWhen the packages are published, this section will switch to a single
pnpm add @hiss-finance/sdk. Until then, consume them via the workspace or a
local file: / link: reference.
HISS ships 10 agent skills — self-contained SKILL.md instruction packs that
teach a compatible coding agent how to work with HISS vaults, staking, rewards,
receipts, Bankr rails, Stock Tokens, the MCP server, and the HISS security
boundaries. They are installed with the open-source skills
CLI (npx skills), which supports Claude Code, Codex, Cursor, and other clients.
Skills are instructions for an agent — review a
SKILL.mdbefore installing it. HISS skills only prepare and verify: they never ask for a private key, never sign for you, and never claim a transaction happened without an on-chain receipt. See the safety note below.
npx skills add HissFinance/hiss --listnpx skills add HissFinance/hiss --skill hiss-vault-agent-kit# --all == --skill '*' --agent '*' -y (all skills, every detected agent)
npx skills add HissFinance/hiss --all# Claude Code
npx skills add HissFinance/hiss --skill hiss-vault-agent-kit -a claude-code
# Codex
npx skills add HissFinance/hiss --skill hiss-vault-agent-kit -a codex
# every HISS skill, Claude Code only
npx skills add HissFinance/hiss --skill '*' -a claude-codeAdd -g to install at the user level (global) instead of project-local, and
-y to skip prompts (for CI). Installs are project-local by default when run
inside a project.
Manual / project-local installation (no installer)
Every skill is a plain directory under skills/. To install one by
hand, copy it into your agent's skills directory:
# Claude Code (project-local)
mkdir -p .claude/skills
cp -R skills/hiss-vault-agent-kit .claude/skills/
# Codex (project-local)
mkdir -p .agents/skills
cp -R skills/hiss-vault-agent-kit .agents/skills/For an agent with no native skill support, open the raw SKILL.md and paste it in
as project instructions/context:
https://github.com/HissFinance/hiss/blob/main/skills/hiss-vault-agent-kit/SKILL.md
# Print a one-shot prompt for a single skill without installing it
npx skills use HissFinance/hiss@hiss-vault-agent-kit
# Update installed skills to the latest version
npx skills update
# Remove a skill
npx skills remove hiss-vault-agent-kitEach skill preserves the prepare-never-execute boundary: the agent reads, scores, and prepares; your wallet or Safe signs; only an on-chain receipt proves completion.
| Skill | Use it when you want an agent to… | It produces |
|---|---|---|
| hiss-vault-agent-kit | Discover vaults, read manifests/fees, create a vault candidate, prepare deposits/withdrawals, preview rebalances under fuses, verify receipts | Manifests + manifestHash, deposit/withdraw intents + ack hashes, readiness/risk reports |
| hiss-coilops | Turn a market thesis into a bounded, versioned trading Coil — generate, validate, score, compile | CoilManifest, Coil Health score, runbook, share card, receipts |
| hiss-staking | Guide xHISS staking — read state, prepare stake, start the 72h cooldown, redeem in the window | Prepared stake/cooldown/redeem intents; status & injection reads |
| hiss-rewards | Explain & verify the 50/15/15/10/10 split (incl. economic burn); distinguish planned ≠ funded ≠ claimable | Deterministic split plans with a planHash; state explanations |
| hiss-receipts | Write and verify canonical-JSON SHA-256 receipts; reject any forged execution claim | Receipts and {ok, mismatches[]} verification verdicts |
| hiss-risk-fuses | Audit the binding risk fuses on a Coil and explain why a capsule will/won't compile | Per-fuse descriptions, bound-check issues, a risk_fuse receipt |
| hiss-stock-tokens | Prepare, validate, and reconcile Bankr trades of the 15 canonical Robinhood Chain stock tokens | Order plan + exact Bankr command; a settlement receipt from an on-chain tx |
| hiss-bankrbot-robinhood | Compile a Coil for the Bankrbot → Robinhood MCP path — paper-first, live-readiness gated | Bankrbot command pack, Robinhood MCP capsule, paper runbook, audit |
| hiss-mcp | Drive the HISS tools over the local MCP server rather than raw HTTP | Prepared artifacts and verified state reads via MCP tools |
| hiss-security-boundaries | Enforce the trust boundaries — no custody, no credentials, no execution claims, autonomy consent gates | The guardrail reference the other skills are checked against |
flowchart LR
A[Skill instructions] --> B[HISS MCP / SDK / public APIs]
B --> C[Typed plan or artifact]
C --> D[User reviews]
D --> E[User wallet or Safe signs]
E --> F[Verified receipt]
Agents prepare and verify. They do not receive private keys, sign for you, or prove execution without an on-chain receipt. Never paste seed phrases, private keys, session cookies, or API secrets into an agent — HISS skills never need them, and every HISS tool rejects credential-shaped input. Agent output is not proof of execution: only a verified receipt proves a transaction happened.
| Package | What it does |
|---|---|
@hiss-finance/core |
The shared truth layer: typed constants, fee and reward math, manifest schemas, chain config, address book, and pure resolvers. No I/O — deterministic and testable. |
@hiss-finance/sdk |
High-level client: read vault/staking/reward state and prepare (build, never sign) deposit, withdraw, stake, and manifest-publish transactions. |
@hiss-finance/vault-kit |
Vault authoring helpers: compose allocations, validate risk fuses, compute fee previews, and hash a manifest. |
@hiss-finance/react |
React hooks and headless components for vault, staking, and reward surfaces. Bring your own wallet connector. |
@hiss-finance/cli |
A terminal client for status reads, manifest validation, and transaction preparation. |
@hiss-finance/mcp-server |
A local Model Context Protocol server exposing 22 read/prepare tools to any MCP-compatible agent. Read and prepare only — never executes. |
Smart-contract interfaces and ABIs live under contracts/;
JSON schemas under schemas/; runnable examples under
examples/; agent skill packs under
skills/.
Everything in this repo sits on the prepare side of the signing boundary. It reads public state and builds unsigned artifacts; you (or a Safe) sign, and the chain is the source of truth.
flowchart TD
A[Your app / AI agent] --> B[SDK · CLI · MCP · React · Skills]
B --> C[Public HISS APIs & contract interfaces]
C --> D[User wallet or 2-of-3 Treasury Safe]
D -->|signs| E[Robinhood Chain 4663]
E --> F[On-chain receipt]
F -->|verify| B
- Product: www.hiss.finance
- Robinhood Chain docs: docs.robinhood.com/chain/connecting
- Block explorer (mainnet): robinhoodchain.blockscout.com
| Field | Mainnet | Testnet |
|---|---|---|
| Chain ID | 4663 |
46630 |
| Network name | Robinhood Chain | Robinhood Chain Testnet |
| RPC URL | https://rpc.mainnet.chain.robinhood.com |
https://rpc.testnet.chain.robinhood.com |
| Native currency | ETH (18 decimals) | ETH (18 decimals) |
| Block explorer | https://robinhoodchain.blockscout.com |
https://explorer.testnet.chain.robinhood.com |
| Base vault asset | USDG (6 decimals) | — |
Full details in Robinhood Chain. Always verify chain config against the official Robinhood docs.
Addresses are load-bearing — never abbreviate them. On-chain state is always the
source of truth; see docs/generated/current-deployments.md
for the stamped snapshot.
| Contract / account | Address |
|---|---|
| USDG (base asset, 6dp) | 0x5fc5360D0400a0Fd4f2af552ADD042D716F1d168 |
| $HISS token (18dp) | 0x47162135cc8fb253f939Bd70e3D2B83075eaeBa3 |
| VaultFactory | 0x278d237c6890a5f7101296a9021ed9D26c821810 |
| HISS Vault (flagship) | 0x6d962604df1c6c5ef4b59d88863600fe71bb63e6 |
| xHISS staking vault | 0x699861D2C546ab86a7f2AE97ffc7aF89f3FF67Be |
| HISS Treasury Safe (2-of-3) | 0xF100Fc28dd1721C698046Dbd60408c523b69e36c |
The full address book (registries, distributors, adapters) is in
docs/contracts.md.
The SDK prepares artifacts and transactions. Nothing is signed for you.
import { composeVaultManifest, validateVaultFeeConfig, defaultVaultFeeConfig } from "@hiss-finance/vault-kit";
const feeConfig = defaultVaultFeeConfig("0xYourCreatorFeeRecipient");
// -> 10% performance fee, 10% HISS protocol share, routing fee 0 (routing disabled)
const issues = validateVaultFeeConfig(feeConfig);
if (issues.length) throw new Error(JSON.stringify(issues));
const { manifest, manifestHash } = composeVaultManifest({
name: "Mega-cap Tech Basket",
baseAsset: "USDG",
chainId: 4663,
targetWeightsBps: { AAPL: 1500, MSFT: 1500, NVDA: 1500, SPY: 3500, USDG: 2000 },
feeConfig,
strategyNoticePeriodSeconds: 604_800, // 7-day change notice
});
// Saving a candidate is free. Publishing a public vault costs a one-time
// creation fee and requires >= 5% creator skin before public deposits open.See Create a vault and Vault manifest.
import { HissClient } from "@hiss-finance/sdk";
const hiss = new HissClient({ chainId: 4663, rpcUrl: "https://rpc.mainnet.chain.robinhood.com" });
// A read: current share price and readiness (always a live chain read).
const vault = await hiss.vaults.read("0x6d962604df1c6c5ef4b59d88863600fe71bb63e6");
// A prepare: returns the approve + deposit transactions for the USER to sign.
const txs = await hiss.vaults.prepareDeposit({
vault: vault.address,
depositor: "0xDepositor",
amountUsdg: 1_000_000_000n, // 1,000 USDG (6 decimals)
});
// You sign and send `txs` with your own wallet. The deposit is complete only
// on the on-chain receipt — never before.See Deposit.
import { HissClient } from "@hiss-finance/sdk";
const hiss = new HissClient({ chainId: 4663 });
// Prepare a stake into the xHISS vault (single-asset staking over $HISS).
const stakeTxs = await hiss.staking.prepareStake({ staker: "0xStaker", amountHiss: 500n * 10n ** 18n });
// Exiting is a two-step, non-pausable flow: start a 72h cooldown, then redeem
// within the 2-day window.
const cooldownTx = await hiss.staking.prepareStartCooldown({
staker: "0xStaker",
xShares: 250n * 10n ** 18n,
});See xHISS staking and Cooldown and redeem.
Staking is a mechanical position, not a yield promise. Not a performance claim. Historical fee distributions are not forecasts.
Run the local MCP server and connect any MCP-compatible agent. Every tool is read, prepare, or score — agents never execute trades or move funds.
pnpm --filter @hiss-finance/mcp-server startThe server registers 22 tools (12 read, 10 prepare). Representative tools:
hiss_get_protocol_status, hiss_get_fee_schedule, hiss_get_staking_status,
hiss_create_vault_candidate, hiss_prepare_vault_deposit,
hiss_prepare_hiss_stake, hiss_verify_receipt. Full list in
MCP tools. Agents can also call x402 paid endpoints
and prepare Bankr commands.
The HISS website and first-party app tools are free — no subscriptions, no credits, no paywalls — and the packages here are open-source (Apache-2.0). You keep signing control; HISS only prepares and verifies. What you may still pay are normal network gas and contract-enforced protocol fees (shown below) — these are on-chain costs, not HISS charges. x402 services are separate, opt-in machine-to-machine (agent) rails where configured.
Every fee is disclosed; there are no hidden spreads. Current launch values:
| Fee | Value | Notes |
|---|---|---|
| Vault candidate save | 0 USDG | Always free. |
| Public vault creation | 50 USDG (launch) | Paid once, by the creator, when publishing on-chain. Candidate figure; the deployed factory is the source of truth. |
| Creator performance fee | 10% default | Of new profit above the high-water mark only. No fee on losses. Cap 10% (unverified) / 20% (verified). |
| HISS protocol share | 10% of the creator fee | A share of the creator's performance fee — never an extra charge on depositor principal. |
| Deposit / withdrawal fee | 0 / 0 | Chain gas, liquidity unwind, and slippage are disclosed separately. |
| Routing fee | 0 while routing disabled | 0.5–2 bps of rebalance notional only once HISS live routing is enabled. |
The full, worked-through fee guide — including $HISS token trading fees — is in
docs/fees/.
Verified $HISS token trading fees (from the Bankr/Doppler launch pool) are, on the HISS side, split 50 / 15 / 15 / 10 / 10 (HISS Reward Method V2):
- 50% → xHISS stakers (an ERC-4626 reward injection)
- 15% → eligible vault providers (facts-only scoring, 90-day vesting)
- 15% → eligible vault contributors (by share-seconds, 30-day vesting)
- 10% → the Treasury Safe (absorbs rounding dust; legs sum exactly)
- 10% → economic burn to the canonical dead address
0x000000000000000000000000000000000000dEaD
Vault contributors is the current name for the former depositor reward
cohort (methodology unchanged); V1 (50/30/10/10, no burn) is historical. The
burn leg is an economic burn — $HISS is transferred to the dead address and
leaves circulation, but the transfer does not reduce HISS.totalSupply (the
burn metric is the dead-address balance). The retroactive V2 migration executed a
cumulative economic burn of ~219.16M HISS to the dead address, with
totalSupply unchanged.
Claimed WETH fees are 100% to the Treasury Safe — never split. State is always chained: planned ≠ funded ≠ vesting ≠ claimable. Read the full mechanism in Reward flywheel.
- User wallet signs user actions. Deposits, withdrawals, staking, and manifest publishes are transactions you sign from your wallet. HISS never holds your keys.
- Treasury Safe (2-of-3) signs protocol actions. Ownership changes, reward funding, and injector authorization require the multisig.
- The SDK/CLI prepare only. They build transactions and artifacts; they do not broadcast on your behalf.
- No custody, no brokerage execution. HISS never holds pooled assets outside the audited contracts and never places brokerage orders.
See Security, Trust boundaries, and SECURITY.md.
Live, stamped snapshots (deployments, fees, status) are regenerated from chain
reads and committed under docs/generated/.
Because on-chain state changes, treat those files as snapshots with a freshness
limit — re-read the chain for anything transactional.
- Tokenized Stock Tokens and ETF tokens are economic exposure only. They confer no legal or beneficial ownership in the underlying issuer, no voting rights, and no direct dividend entitlement.
- Availability is region- and provider-dependent. Some surfaces (including Bankr rails and Robinhood's own agentic trading) have limited, jurisdiction-gated rollout. See Stock Tokens.
- HISS is not a fund, broker, or investment adviser, is not affiliated with Robinhood, and nothing here is investment advice. No guaranteed yield, no APY promise, no passive income. Vaults share profits and losses.
Runnable, self-contained examples live in examples/:
reading status, composing and validating a manifest, previewing fees, preparing a
deposit, and driving the MCP server.
| Area | Start here |
|---|---|
| Orientation | Getting started · Architecture · Glossary · FAQ |
| Chain & contracts | Robinhood Chain · Contracts |
| Packages | SDK · CLI · React · MCP |
| Vaults | Overview · Create · Manifest · Risk fuses |
| Fees | Overview · Vault fees · $HISS token fees · Reward flywheel |
| Staking | Overview · xHISS · Cooldown & redeem |
| Rewards | Overview · Vault contributors · Vault providers · Epochs & vesting |
| Agents | Agent skills · Bankrbot · x402 · CoilOps |
| Safety | Security · Trust boundaries · Receipts · Data freshness |
Contributions are welcome. Please read CONTRIBUTING.md and the Code of Conduct first. Maintainers are listed in MAINTAINERS.md; the release history is in CHANGELOG.md and the plan ahead in ROADMAP.md.
Please do not open public issues for security vulnerabilities. Use GitHub's private vulnerability reporting on this repository, or the process described in SECURITY.md.
Licensed under the Apache License 2.0. See NOTICE and THIRD_PARTY_LICENSES.md.
HISS Finance is compilation and verification software provided "as is", without warranty of any kind. It is not a fund, broker, exchange, or investment adviser, and it is not affiliated with Robinhood, Bankr, Doppler, or Chainlink. Nothing in this repository is investment, legal, or tax advice. Digital assets and tokenized instruments carry risk, including total loss. Vaults share profits and losses; there is no guaranteed yield and no APY promise. Tokenized Stock Tokens are economic exposure only and are restricted in some jurisdictions. You are solely responsible for your own transactions and for complying with the laws that apply to you.