agentCLAWHUBUnverified

Torch Liquidation Bot

Autonomous vault-based liquidation keeper for Torch Market lending on Solana. Scans all migrated tokens for underwater loan positions (LTV > 65%) using the S...

OpenClaw

Rank

62

Safety

84

Downloads

2.0k

Updated

Apr 15, 2026

Version

4.0.4

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 2K downloads reported by the source. Last updated 4/15/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Apr 15, 2026
Protocol compatibility
OpenClawcompatibility · observed Apr 15, 2026
Adoption signal
2K downloadsadoption · observed Apr 15, 2026
Latest release
4.0.4release · observed Feb 28, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install kn7a0ff82yxwmqsge7kh9kdgqn80hpbf:torchliquidationbot
  1. Install using `clawhub skill install kn7a0ff82yxwmqsge7kh9kdgqn80hpbf:torchliquidationbot` in an isolated environment before connecting it to live workloads.
  2. No published capability contract is available yet, so validate auth and request/response behavior manually.
  3. Review the upstream CLAWHUB listing at https://clawhub.ai/mrsirg97-rgb/torchliquidationbot before using production credentials.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-mrsirg97-rgb-torchliquidationbot/snapshot"

Documentation

CLAWHUB

155,026 characters of source documentation, loaded on request.

Extracted files

5 files captured from the source.

SKILL.md

---
name: torch-liquidation-bot
version: "4.0.4"
description: Autonomous vault-based liquidation keeper for Torch Market lending on Solana. Scans all migrated tokens for underwater loan positions (LTV > 65%) using the SDK's built-in bulk loan scanner (getAllLoanPositions), builds and executes liquidation transactions through a Torch Vault, and collects a 10% collateral bonus. The agent keypair is generated in-process -- disposable, holds nothing of value. All SOL and collateral tokens route through the vault. The human principal creates the vault, funds it, links the agent, and retains full control. Built on torchsdk v3.7.22 and the Torch Market protocol.
license: MIT
disable-model-invocation: true
requires:
  env:
    - name: SOLANA_RPC_URL
      required: true
    - name: VAULT_CREATOR
      required: true
    - name: SOLANA_PRIVATE_KEY
      required: false
metadata:
  clawdbot:
    requires:
      env:
        - name: SOLANA_RPC_URL
          required: true
        - name: VAULT_CREATOR
          required: true
        - name: SOLANA_PRIVATE_KEY
          required: false
  openclaw:
    requires:
      env:
        - name: SOLANA_RPC_URL
          required: true
        - name: VAULT_CREATOR
          required: true
        - name: SOLANA_PRIVATE_KEY
          required: false
    install:
      - id: npm-torch-liquidation-bot
        kind: npm
        package: torch-liquidation-bot@^4.0.2
        flags: []
        label: "Install Torch Liquidation Bot (npm, optional -- SDK is bundled in lib/torchsdk/ and bot source is bundled under lib/kit on clawhub)"
  author: torch-market
  version: "4.0.4"
  clawhub: https://clawhub.ai/mrsirg97-rgb/torch-liquidation-bot
  kit-source: https://github.com/mrsirg97-rgb/torch-liquidation-kit
  website: https://torch.market
  program-id: 8hbUkonssSEEtkqzwM7ZcZrD9evacM92TcWSooVF4BeT
  keywords:
    - solana
    - defi
    - liquidation
    - liquidation-bot
    - liquidation-keeper
    - collateral-lending
    - vault-custody
    - ai-agents
    - agent-wallet
    - agent-safety
    - treasury-lending
    - bonding-curve
    - fair-launch
    - token-2022
    - raydium
    - community-treasury
    - protocol-rewards
    - solana-agent-kit
    - escrow
    - anchor
    - pda
    - on-chain
    - autonomous-agent
    - keeper-bot
    - torch-market
  categories:
    - solana-protocols
    - defi-primitives
    - lending-markets
    - agent-infrastructure
    - custody-solutions
    - liquidation-keepers
compatibility: >-
  REQUIRED: SOLANA_RPC_URL (HTTPS Solana RPC endpoint)
  REQUIRED: VAULT_CREATOR (vault creator pubkey).
  OPTIONAL: SOLANA_PRIVATE_KEY -- the bot generates a fresh disposable keypair in-process if not provided. The agent wallet holds nothing of value (~0.01 SOL for gas). All liquidation proceeds (collateral tokens) route to the vault. The vault can be created and funded entirely by the human principal. 
  This skill sets disable-model-invocation: true -- it must not be invoked autonomously withou

_meta.json

{
  "ownerId": "kn7a0ff82yxwmqsge7kh9kdgqn80hpbf",
  "slug": "torchliquidationbot",
  "version": "4.0.4",
  "publishedAt": 1772291810792
}

audit.md

# Torch Liquidation Bot — Security Audit

**Audit Date:** February 27, 2026
**Auditor:** Claude Opus 4.6 (Anthropic)
**Bot Version:** 4.0.2
**Kit Version:** 2.0.0
**SDK Version:** torchsdk 3.7.22
**On-Chain Program:** `8hbUkonssSEEtkqzwM7ZcZrD9evacM92TcWSooVF4BeT` (V3.7.7, 27 instructions)
**Language:** TypeScript
**Test Result:** 9 passed, 0 failed (Surfpool mainnet fork)

---

## Table of Contents

1. [Executive Summary](#executive-summary)
2. [Scope](#scope)
3. [Methodology](#methodology)
4. [What Changed (v3.0.2 → v4.0.0)](#what-changed-v302--v400)
5. [Keypair Safety Review](#keypair-safety-review)
6. [Vault Integration Review](#vault-integration-review)
7. [Scan Loop Security](#scan-loop-security)
8. [Configuration Validation](#configuration-validation)
9. [Dependency Analysis](#dependency-analysis)
10. [Threat Model](#threat-model)
11. [Findings](#findings)
12. [Resolved Findings from v3.0.2](#resolved-findings-from-v302)
13. [Conclusion](#conclusion)

---

## Executive Summary

This audit covers the Torch Liquidation Bot v4.0.0, an autonomous keeper that scans Torch Market lending positions and liquidates underwater loans through a Torch Vault. The bot was reviewed for key safety, vault integration correctness, error handling, and dependency surface.

The major change in v4.0.0 is the replacement of the N+1 scan pattern (`getLendingInfo` → `getHolders` → per-holder `getLoanPosition`) with a single `getAllLoanPositions()` call per token. This reduces RPC calls from 2 + N per token to 1 per token, eliminates the 20-holder discovery ceiling from the previous version, and leverages the SDK's pre-sorted output to break early once all liquidatable positions are processed.

The bot remains **vault-first** (all value routes through the vault PDA), **disposable-key** (agent keypair generated in-process, holds nothing), and **single-purpose** (scan and liquidate only — no trading, borrowing, or token creation).

### Overall Assessment

| Category | Rating | Notes |
|----------|--------|-------|
| Key Safety | **PASS** | In-process `Keypair.generate()`, no key files, no key logging |
| Vault Integration | **PASS** | `vault` param correctly passed to `buildLiquidateTransaction` |
| Error Handling | **PASS** | Cycle-level catch, per-token try/catch, per-liquidation try/catch, 30s RPC timeout |
| Config Validation | **PASS** | Required env vars checked, scan interval floored at 5000ms |
| Dependencies | **MINIMAL** | 2 runtime deps, both pinned exact |
| Supply Chain | **LOW RISK** | No post-install hooks, no remote code fetching |

### Finding Summary

| Severity | Count |
|----------|-------|
| Critical | 0 |
| High | 0 |
| Medium | 0 |
| Low | 0 (1 resolved) |
| Informational | 2 |

---

## Scope

### Files Reviewed

| File | Lines | Role |
|------|-------|------|
| `packages/bot/src/index.ts` | 192 | Entry point: keypair load/generate, vault check, scan loop |
| `packages/bot/src/config.ts` | 36 | Environment variable validation |
| `packages/bot/sr

design.md

# Torch Liquidation Bot — Design Document

> Autonomous vault-based liquidation keeper for Torch Market lending on Solana. Version 4.0.2.

## Overview

The Torch Liquidation Bot is a single-purpose keeper that scans Torch Market lending positions and liquidates underwater loans through a Torch Vault. It generates a disposable agent keypair in-process, verifies vault linkage, and runs a continuous scan-liquidate loop. All SOL and collateral tokens route through the vault — the agent wallet holds nothing of value.

The bot is built on `[email protected]` and targets the Torch Market on-chain program (`8hbUkonssSEEtkqzwM7ZcZrD9evacM92TcWSooVF4BeT`). It uses the SDK's bulk loan scanner (`getAllLoanPositions`) to discover liquidatable positions and the vault-routed `buildLiquidateTransaction` to execute them.

## Architecture

```
┌──────────────────────────────────────────────────────────┐
│                    LIQUIDATION BOT                         │
│                                                           │
│  main()                                                   │
│    ├── loadConfig()         → validate env vars            │
│    ├── Keypair.generate()   → disposable agent keypair     │
│    ├── getVault()           → verify vault exists           │
│    ├── getVaultForWallet()  → verify agent linked to vault  │
│    └── while (true)                                        │
│         └── scanAndLiquidate()                             │
│              ├── getTokens({ status: 'migrated' })         │
│              ├── getAllLoanPositions(mint)                  │
│              │    → returns positions sorted by health      │
│              │    → break at first non-liquidatable         │
│              ├── buildLiquidateTransaction(vault=creator)   │
│              ├── transaction.sign(agentKeypair)             │
│              ├── connection.sendRawTransaction()            │
│              └── confirmTransaction()                      │
└──────────────────────────┬───────────────────────────────┘
                           │
                           ▼
┌──────────────────────────────────────────────────────────┐
│                    torchsdk v3.7.22                        │
│                                                           │
│  Read-only queries:                                       │
│    getTokens, getAllLoanPositions                          │
│    getVault, getVaultForWallet                             │
│                                                           │
│  Transaction builder:                                     │
│    buildLiquidateTransaction (vault-routed)                │
│                                                           │
│  Confirmation:                                            │
│    confirmTransaction (on-chain via RPC)                   │
└──────────────────────────┬───────────────────────────────┘
                           │
                           ▼
┌───────────────────────────────────────

verification.md

# Formal Verification Report

## TL;DR

We used [Kani](https://model-checking.github.io/kani/), a formal verification tool from AWS, to mathematically prove that torch.market's core math is correct -- not just tested, but **proven for every possible input**. This covers all fee calculations, bonding curve pricing, lending formulas, and reward distribution. No SOL can be created from nothing, no tokens can be minted from thin air, and no fees can exceed their stated rates.

This is **not** a security audit. It proves the arithmetic is correct, but does not cover access control, account validation, or economic attacks. See [What Is NOT Verified](#what-is-not-verified) for full scope limitations.

**43 proof harnesses. All passing. Zero failures.**

---

## Overview

torch_market's core arithmetic has been formally verified using [Kani](https://model-checking.github.io/kani/), a Rust model checker backed by the CBMC bounded model checker. Kani exhaustively proves properties hold for **all** valid inputs within constrained ranges -- not just sampled test cases.

**Tool:** Kani Rust Verifier 0.67.0 / CBMC 6.8.0
**Target:** `torch_market` v3.7.8
**Harnesses:** 43 proof harnesses, all passing
**Source:** `programs/torch_market/src/kani_proofs.rs`

## What Is Formally Verified

The proofs cover the **pure arithmetic layer** -- every fee calculation, bonding curve formula, lending math function, and reward distribution used by the on-chain program. Each proof harness uses symbolic (unconstrained) inputs bounded to realistic protocol ranges, and Kani exhaustively checks all possible values within those bounds.

### Buy Flow (Harnesses 1-8)

| Harness | Property | Input Range |
|---------|----------|-------------|
| `verify_buy_fee_conservation` | `protocol_fee + treasury_fee + after_fees == sol_amount` | 0.001-200 SOL |
| `verify_protocol_fee_split` | `dev_share + protocol_portion == protocol_fee_total` | 0.001-200 SOL |
| `verify_treasury_rate_bounds` | `rate in [500, 2000]` (5-20%) flat across all tiers | 0-target SOL reserves |
| `verify_treasury_rate_monotonic` | More reserves -> lower treasury rate | 0-target SOL (two symbolic) |
| `verify_sol_distribution_conservation` | `curve + treasury + creator + dev + protocol == sol_amount` (zero SOL created or lost, V34 5-way sum) | 0.001-10 SOL per trade, 0-target SOL reserves |
| `verify_curve_tokens_bounded_legacy` | `tokens_out < virtual_token_reserves` (can't mint from thin air) | Legacy pool state space (IVT=107.3T) |
| `verify_curve_tokens_bounded_v25` | Same property for V27 per-tier reserves | V27 pool state space (IVT=756.25M tokens) |
| `verify_token_split_conservation` | `tokens_to_buyer + tokens_to_treasury == tokens_out` | 0 to TOTAL_SUPPLY |

### Sell Flow (Harnesses 9-10)

| Harness | Property | Input Range |
|---------|----------|-------------|
| `verify_sell_sol_bounded_legacy` | `sol_out < virtual_sol_reserves` (can't drain more SOL than exists) | Legacy pool state, max wallet cap |
| `verif
Github ReposUpdated 2h agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/mrsirg97-rgb/torchliquidationbot",
      "sourceUrl": "https://clawhub.ai/mrsirg97-rgb/torchliquidationbot",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-04-15T00:45:39.800Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-mrsirg97-rgb-torchliquidationbot/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-mrsirg97-rgb-torchliquidationbot/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-04-15T00:45:39.800Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "2K downloads",
      "href": "https://clawhub.ai/mrsirg97-rgb/torchliquidationbot",
      "sourceUrl": "https://clawhub.ai/mrsirg97-rgb/torchliquidationbot",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-04-15T00:45:39.800Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "4.0.4",
      "href": "https://clawhub.ai/mrsirg97-rgb/torchliquidationbot",
      "sourceUrl": "https://clawhub.ai/mrsirg97-rgb/torchliquidationbot",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-02-28T15:16:50.792Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-mrsirg97-rgb-torchliquidationbot/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-mrsirg97-rgb-torchliquidationbot/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 4.0.4",
      "description": "No user-facing changes detected in this release. Version bump only. - Version number updated to 4.0.4. - No changes to files, functionality, or documentation content. - latest sdk v3.7.23 bundled",
      "href": "https://clawhub.ai/mrsirg97-rgb/torchliquidationbot",
      "sourceUrl": "https://clawhub.ai/mrsirg97-rgb/torchliquidationbot",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-02-28T15:16:50.792Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 9, 2026.

Sponsored

Ads related to Torch Liquidation Bot and adjacent AI workflows.