Skip to content

SYSTEM.00agentic trading control planerobinhood

Build agents that trade on Robinhood—with limits you can verify.

HISS turns trading intent into bounded, explainable and verifiable agent behavior across Robinhood brokerage and Robinhood Chain. You set the limits. Your surfaces execute. Every run leaves a receipt.

Install the HISS skill
SKILL.md ↗

HISS-hosted services do not hold Robinhood credentials, Lighter private keys, or unrestricted user signing authority. Execution happens on surfaces you control.

Control plane · Chain 4663

ONCHAIN READ · 03:16:36Z
MCP tools served
39 hosted
Autonomy fuses enforced per pack
5 base · 9 agentic
Receipts verifiable
30Verify one ↗
Robinhood Trading MCP
Built for the Robinhood Trading MCP

Agentic Stack — per-rail state

  • Robinhood Trading MCPREADY TO CONNECT
  • HISS MCPLIVE
  • Robinhood ChainLIVE
  • Bankr rails (deposits · stock tokens)USER EXECUTIONYour Bankr session executes — HISS validates + receipts.
  • Stock Premium LPREADPREPAREUser-signed execution BLOCKED: owner-gated off, no canary executed.
  • Vault V2 (24/7 mesh)ACTIVE 24 7
  • Lighter (Robinhood instance)PREPARE
  • Coil compilerLIVE
  • Risk fusesLIVERuntime enforcement BLOCKED — companion architecture-gated.
  • ReceiptsLIVERuntime receipt classes are shipped types with zero production instances.
Evidence — what backs each state
  • Robinhood Trading MCP: Committed capability matrix rev 2, verified 2026-07-22 (docs/mcp/capability-matrix.json). Tool schemas are UNKNOWN and fail closed.
  • HISS MCP: Live in-process /version read — toolset sha256:d4ca4e50b438ec079658bb65490679424018f2f944ec888d5f00cf6a8bb42496.
  • Robinhood Chain: GET /api/status (canonical StatusTruth: RPC probe + committed artifacts, degraded-capable).
  • Bankr rails (deposits · stock tokens): GET /api/agents/schema + SKILL.md Part IV (artifact-derived rail boundaries; rh-wallet is source-pending, BLOCKED, never a dependency).
  • Stock Premium LP: Hosted MCP toolset (SPL tools) + the SPL scanner reads; UNKNOWN halts prepares.
  • Vault V2 (24/7 mesh): GET /api/vaults/v2/status — the typed activation enum, rendered verbatim.
  • Lighter (Robinhood instance): LIGHTER_CURRENT_RUNG in @hiss/core (typed rung ladder) + public reads at /api/lighter/markets · orderbook · depth.
  • Coil compiler: Typed @hiss/core version literals; local MCP toolset pinned by tests; liveOrderSent: false hard-typed.
  • Risk fuses: Static @hiss/core fuse constants (no network, no failure mode).
  • Receipts: @hiss/core/receipts + /app/verify; the on-chain VaultReceiptRegistry read is degraded-capable via /api/status.
  • A failed read renders UNKNOWN — never “live”, never “not deployed”. Degraded reads show the last verified state, labeled.

Every claim on this page is backed by an on-chain read, a committed artifact, or a deterministic receipt — and a failed read says so.

SYSTEM.01from intent to receiptfive stages

Whisper → Coil → Fuses → Execute → Receipt

One pipeline governs every agent action on HISS, from a brokerage rebalance to an onchain ladder.

Deterministic example · fixed inputs · no live data, no balances, no orders

01 · The intent, as stated

"Hold a three-name mega-cap basket. Never let one name exceed 40%. Readiness check only — no orders."

HISS compiles, constrains, prepares, monitors, reconciles, and receipts. Your surfaces sign, submit, place orders, and manage positions.

SYSTEM.02one policy layertwo domains

Two places agents trade. One control plane.

Robinhood brokerage

Built for the Robinhood Trading MCP. Works with your Robinhood Agentic account.

Robinhood’s Agentic account is a dedicated, self-directed account you own — your agent can only place trades there, and you are responsible for them. HISS supplies what the account does not: compiled instructions, enforced bounds, and post-run audits. Readiness check is the default, and every compile artifact carries a hard-typed liveOrderSent: false.

Robinhood currently supports long equities and options orders for agents. Robinhood’s product, limits, and eligibility are Robinhood’s alone.

Robinhood Chain

USDG settlement. Stock Tokens trade 24/7. Your keys sign.

Onchain execution runs through wallets and contracts you control — an EOA, a Safe, or an eligible Bankr session. HISS applies the same Coil, fuse, and receipt discipline to ladders, pools, and vault operations on chain 4663.

HISS-hosted services do not hold Robinhood credentials, Lighter private keys, or unrestricted user signing authority.

SYSTEM.03railsstate-chipped, never assumed

The rails, as they actually are

Each rail renders its live state. Nothing on this board is a promise.

SYSTEM.04flagshiplive agentic liquidity

Stock Premium LP

The flagship agentic-liquidity product: scan Stock-Token premium against synchronized reads, compile a typed, bounded USDG ladder, and execute it from your own keys.

  • Premium, measured

    Synchronized reads across venues surface where Stock-Token prices sit against reference. No projections — measurements.

  • Ladders, bounded

    The compiler emits a typed USDG ladder with integer basis points, hard caps, and an explicit universe. One artifact, one hash.

  • Your keys, your fills

    You review, sign, and submit from a surface you control — Uniswap v3 pools on Robinhood Chain, settled in USDG. The honest net is always shown beside the fees.

Open Stock Premium LPScan the universe →Read-only by default. Not a performance claim.

SYSTEM.05pooledstate-driven

USDG vaults on Robinhood Chain

The flagship pooled product: the 24/7 Vault V2 settles USDG deposits on chain 4663, with every state rendered from live reads — never from copy.

ACTIVE 24/7MODE · IN_KIND_ONLY

HISS Vault V224/7 execution vault

0x432e90…230E69Robinhood Chain · 4663

Execution-coupled USDG deposits into tokenized-asset holdings, bounded by onchain price evidence — liveness, TWAP validity, depth, peg — never a trading calendar. Queued requests settle in keeper epochs; in-kind redemption stays available whenever shares exist.

Current holdings (live read)

1.57010777603903417 AAPL · 0.9 USDG cash

Reporting NAV (mid)

497.884601 USDG

Share price

≈ 0.956265 USDG/share

Shares outstanding

520.655374841481296331 shares

Public deposits

Open · queued lane active

Every required activation stage is onchain-active. Queued requests settle in keeper epochs; immediate capacity is evidence-bounded.

Open Vault V2Deposit USDG · Vault V2

Not a performance claim. Internally verified · not externally audited. Execution: In-kind only.

LEGACY · EMPTY

HISS Vault hVAULT · V1

Closed to new deposits. The original flagship V1 vault holds no depositor balances; its address, on-chain history, and receipts remain permanently verifiable.

Vault contracts are deployed and verified on Robinhood Chain; public deposits open only when the audit, disclosure, oracle, liquidity, and deployment readiness checks pass.

24/7 execution mesh (Vault V2):ACTIVE 24 7The 24/7 execution mesh reports active from live reads.

Depositor risks ↗

HISS is compilation and verification software. HISS-hosted services do not hold Robinhood credentials, Lighter private keys, or unrestricted user signing authority.

SYSTEM.06for builders and their agentsone file

One file teaches an agent the whole system

Skill file, llms.txt, MCP endpoints, and a documented API — everything an agent needs to use HISS correctly, including the limits.

Install the HISS skill
SKILL.md ↗
llms.txt / llms-full.txt
machine-readable site truth · llms.txt ↗
MCP
local stdio server + hosted endpoint — 39 hosted tools served · setup

PROOF.07evidencedeterministic

Claims compile into proofs

Three mechanical steps, each one click from the real surface: compile a Coil, verify a receipt, audit a run. Same inputs, same outputs, same hashes — or the check fails loudly.

  1. Compile

    A whisper becomes a Coil: a versioned manifest with integer basis-point weights and an explicit execution mode.

    Open the compiler
  2. Verify

    Recompute any receipt from its inputs. Verification is a function, not a promise.

    Verify a receipt
  3. Audit

    Every artifact carries its provenance: what was produced, what was read, and a hard-typed liveOrderSent: false on compile-only surfaces.

    Browse receipts

Receipts are deterministic — recompute them from the Coil JSON.how receipts work

SYSTEM.08protocol utility$HISS

Stake $HISS, receive xHISS

Under the current V2 reward method, verified HISS trading fees are allocated across xHISS stakers, vault providers, vault contributors, the HISS Treasury Safe, and an economic burn. Its retroactive catch-up is executed on-chain; monthly epochs are pending, so nothing is vesting or claimable yet.

stake · xhiss

State unknown

Stake $HISS, receive xHISS

Stake HISS, receive xHISS. Fee-funded HISS injections increase the HISS-per-xHISS share value over time.

Starting rate
1 : 1
HISS per xHISS at launch — injections raise it
Exit cooldown
72h
before the redeem window opens
Redeem window
2d
to redeem after cooldown
Injection drip
24h
each injection drips linearly

Checking live staking state…

Not a performance claim. Historical fee distributions are not forecasts. No known unresolved Critical or High findings after internal launch review.

V2 reward split · verified HISS trading fees

Full diagram on Rewards →
  • 50%xHISS stakersRecipient deployed
  • 15%Vault providersReserve at Safe
  • 15%Vault contributorsReserve at Safe
  • 10%Treasury SafePolicy
  • 10%Economic burnBurn executed

planned ≠ funded ≠ claimable. The burn leg is a dead-address transfer — HISS totalSupply is not reduced.

Not a performance claim. Historical fee distributions are not forecasts. No known unresolved Critical or High findings after internal launch review.

SYSTEM.09reported livenever fabricated

Reported live, never fabricated

Each row is a live check against on-chain reads, deploy artifacts, and status APIs. A failed fetch reads unknown — never a claim in either direction.

  • xHISS contractchecking…
  • Stakingchecking…
  • Flagship HISS VaultPendingchecking…

Checking live readiness…

Agentic rails — per-rail state

  • Robinhood Trading MCPREADY TO CONNECT
  • HISS MCPLIVE
  • Robinhood ChainLIVE
  • Bankr rails (deposits · stock tokens)USER EXECUTIONYour Bankr session executes — HISS validates + receipts.
  • Stock Premium LPREADPREPAREUser-signed execution BLOCKED: owner-gated off, no canary executed.
  • Vault V2 (24/7 mesh)ACTIVE 24 7
  • Lighter (Robinhood instance)PREPARE
  • Coil compilerLIVE
  • Risk fusesLIVERuntime enforcement BLOCKED — companion architecture-gated.
  • ReceiptsLIVERuntime receipt classes are shipped types with zero production instances.

SYSTEM.09boundaryread this

What HISS is — and is not

HISS is the control, policy, and proof layer for agentic trading — compilation and verification software, not advice. HISS compiles, constrains, prepares, monitors, reconciles, and receipts. Surfaces you control — a Robinhood Agentic MCP session, a Robinhood Chain wallet or Safe, an eligible Bankr session, a user-controlled Lighter runtime, or another bounded runtime — sign, submit, place orders, and manage positions. HISS-hosted services do not hold Robinhood credentials, Lighter private keys, or unrestricted user signing authority. HISS is not a vault platform, a staking app, a token dashboard, a portfolio viewer, or an AI trading bot.

  • · HISS is not a broker-dealer, investment adviser, custodian, or order router.
  • · Compile artifacts carry a hard-typed liveOrderSent: false.
  • · Not affiliated with Robinhood, Bankr, or Chainlink.
  • · Autonomous trading involves substantial risk, including loss of principal.