Torch Market
Torch Vault is a full-custody on-chain escrow for AI agents on Solana. The vault holds all assets -- SOL and tokens. The agent wallet is a disposable control... Skill: Torch Market Owner: mrsirg97-rgb Summary: Torch Vault is a full-custody on-chain escrow for AI agents on Solana. The vault holds all assets -- SOL and tokens. The agent wallet is a disposable control... Tags: latest:4.7.14 Version history: v4.7.14 | 2026-02-28T15:00:25.398Z | user - Updated Torch SDK dependency from version ^3.7.17 to ^3.7.23 for improved functionality and compatibility. - Incremented skill ve
Rank
62
Safety
84
Downloads
3.7k
Updated
Apr 15, 2026
Version
4.7.14
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 3.7K downloads reported by the source. Last updated 4/15/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Apr 15, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Apr 15, 2026
- Adoption signal
- 3.7K downloadsadoption · observed Apr 15, 2026
- Latest release
- 4.7.14release · observed Feb 28, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install kn7a0ff82yxwmqsge7kh9kdgqn80hpbf:torchmarket- Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
- Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-mrsirg97-rgb-torchmarket/snapshot"
Documentation
CLAWHUB
160,000 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
---
name: torch-market
version: "4.7.14"
description: Torch Vault is a full-custody on-chain escrow for AI agents on Solana. The vault holds all assets -- SOL and tokens. The agent wallet is a disposable controller that signs transactions but holds nothing of value. No private key with funds required. The vault can be created and funded entirely by the human principal -- the agent only needs an RPC endpoint to read state and build unsigned transactions. Authority separation means instant revocation, permissionless deposits, and authority-only withdrawals. Built on Torch Market -- a programmable economic substrate where every token is its own self-sustaining economy with bonding curves, community treasuries, lending markets, and governance.
license: MIT
disable-model-invocation: true
requires:
env:
- name: SOLANA_RPC_URL
required: true
- name: SOLANA_PRIVATE_KEY
required: false
- name: TORCH_NETWORK
required: false
metadata:
clawdbot:
requires:
env:
- name: SOLANA_RPC_URL
required: true
- name: SOLANA_PRIVATE_KEY
required: false
- name: TORCH_NETWORK
required: false
primaryEnv: SOLANA_RPC_URL
openclaw:
requires:
env:
- name: SOLANA_RPC_URL
required: true
- name: SOLANA_PRIVATE_KEY
required: false
- name: TORCH_NETWORK
required: false
primaryEnv: SOLANA_RPC_URL
install:
- id: npm-torchsdk
kind: npm
package: torchsdk@^3.7.23
flags: []
label: "Install Torch SDK (npm, optional -- SDK is bundled in lib/torchsdk/ on clawhub)"
author: torch-market
version: "4.7.14"
clawhub: https://clawhub.ai/mrsirg97-rgb/torchmarket
sdk-source: https://github.com/mrsirg97-rgb/torchsdk
examples-source: https://github.com/mrsirg97-rgb/torchsdk-examples
website: https://torch.market
program-id: 8hbUkonssSEEtkqzwM7ZcZrD9evacM92TcWSooVF4BeT
keywords:
- solana
- defi
- token-launchpad
- bonding-curve
- fair-launch
- vault-custody
- ai-agents
- agent-wallet
- agent-safety
- meme-coins
- protocol-rewards
- treasury-management
- treasury-yield
- liquidation
- collateral-lending
- token-2022
- raydium
- dex-trading
- community-treasury
- governance
- on-chain-messaging
- social-trading
- dao-launchpad
- pump-fun-alternative
- solana-agent-kit
- escrow
- anchor
- identity-verification
- said-protocol
categories:
- solana-protocols
- defi-primitives
- token-launchers
- agent-infrastructure
- lending-markets
- dex-integrations
- governance-tools
- custody-solutions
compatibility: >-
REQUIRED: SOLANA_RPC_URL (HTTPS Solana RPC endpoint).
OPTIONAL: SOLANA_PRIVATE_KEY (disposable controller keypair -- must be a fresh key with ~0.01 SOL for gas, NEVER a vault authority key or funded wallet).
OPTIONAL: TORCH_N_meta.json
{
"ownerId": "kn7a0ff82yxwmqsge7kh9kdgqn80hpbf",
"slug": "torchmarket",
"version": "4.7.14",
"publishedAt": 1772290825398
}audit_program.md
# Torch Market Security Audit Summary **Date:** February 27, 2026 | **Auditor:** Claude Opus 4.6 (Anthropic) | **Version:** V3.7.8 Production --- ## Scope Four audits covering the full stack: | Layer | Files | Lines | Report | |-------|-------|-------|--------| | On-chain program (V3.7.8) | 21 source files | ~6,800 | `audit.md` | | Frontend & API | 37 files (17 API routes, 12 libs, 8 components) | -- | `SECURITY_AUDIT_FE_V2.4.1_PROD.md` | | Agent Kit plugin (V4.0) | 4 files | ~1,900 | `SECURITY_AUDIT_AGENTKIT_V4.0.md` | | Torch SDK (V2.0) | 9 files | ~2,800 | Included in Agent Kit V4.0 audit | Program ID: `8hbUkonssSEEtkqzwM7ZcZrD9evacM92TcWSooVF4BeT` --- ## Findings Summary ### On-Chain Program (V3.7.8) | Severity | Count | Details | |----------|-------|---------| | Critical | 0 | -- | | High | 0 | -- | | Medium | 3 | Lending enabled by default (accepted); Token-2022 transfer fee on collateral (inherent, 0.04% new / 0.03% legacy); Epoch rewards race condition (accepted) | | Low | 7 | fund_vault_wsol decoupled accounting; Stranded WSOL lamports; Vault sol_balance drift; Sell no position check; Slot-based interest; Revival no virtual reserve update; Treasury lock ATA not Anchor-constrained (CPI validated, see V31 notes) | | Informational | 24 | Various carried findings + 3 new V3.7.1 + 2 new V3.7.2 + 2 new V3.7.3 + 2 new V3.7.5 (I-20: zero-burn migration design; I-21: AccountInfo stack pressure mitigation) + 1 new V3.7.6 (I-22: reserve floor zeroed, fee split rebalanced) + 1 new V3.7.7 (I-23: buyback removed, lending cap increased) + 1 new V3.7.8 (I-24: creator revenue streams, transfer fee bump) | **Rating: EXCELLENT -- Ready for Mainnet** Key strengths: - 27 instructions, 12 account types, 43 Kani formal verification proofs passed - **V34 creator revenue**: Three new income streams for creators — bonding SOL share (0.2%→1% carved from treasury rate, linear growth), 15% of post-migration `swap_fees_to_sol` proceeds, and star payout (cost reduced 0.05→0.02 SOL). `creator` account added to `Buy` and `SwapFeesToSol` contexts, validated against `bonding_curve.creator`. Transfer fee bumped from 3 to 4 bps (new tokens only — old tokens immutable). 4 new Kani proofs verify creator rate bounds, monotonicity, subtraction safety, and fee share conservation - **V33 buyback removal**: `execute_auto_buyback` instruction removed (~330 lines of handler + context). Eliminates a complex Raydium CPI instruction that spent treasury SOL providing exit liquidity during dumps, had a fee-inflation bug in vault balance reads, and competed with lending for treasury SOL. One fewer attack surface. Binary size reduced ~6% (850 KB → 804 KB). Treasury simplified to: fee harvest → sell high → SOL → lending yield + epoch rewards - **V33 lending cap increase**: Utilization cap raised from 50% to 70%. More SOL available for community lending while maintaining 30% visible reserve. Conservative LTV/liquidation thresholds unchanged - **V32 protocol treasury rebalance**:
audit_sdk.md
# Torch SDK Security Audit **Audit Date:** February 21, 2026 **Auditor:** Claude Opus 4.6 (Anthropic) **SDK Version:** 3.7.23 **On-Chain Program:** `8hbUkonssSEEtkqzwM7ZcZrD9evacM92TcWSooVF4BeT` (V3.7.8) **Language:** TypeScript **Test Result:** 32 passed, 0 failed (Surfpool mainnet fork + devnet E2E + tiers E2E) --- ## Table of Contents 1. [Executive Summary](#executive-summary) 2. [Scope](#scope) 3. [Methodology](#methodology) 4. [PDA Derivation Correctness](#pda-derivation-correctness) 5. [Quote Math Verification](#quote-math-verification) 6. [Vault Integration Review](#vault-integration-review) 7. [Input Validation](#input-validation) 8. [External API Surface](#external-api-surface) 9. [Dependency Analysis](#dependency-analysis) 10. [Transaction Builder Review](#transaction-builder-review) 11. [Findings](#findings) 12. [Conclusion](#conclusion) --- ## Executive Summary This audit covers the Torch SDK v3.7.17, a TypeScript library that reads on-chain state from Solana and builds unsigned transactions for the Torch Market protocol. The SDK was cross-referenced against the live on-chain program (V3.7.17) to verify PDA derivation, quote math, vault integration, migration flow, lending accounting, and account handling. v3.7.17 includes V25 pump-style reserves, V26 permissionless migration, V27 treasury lock and PDA-based pool validation, removal of `update_authority` (V28), V20 swap fees to SOL, V29 on-chain Token-2022 metadata (Metaplex removal, 0.1% transfer fee), a critical lending accounting fix, and dynamic network detection. The SDK is **stateless** (no global state, no connection pools), **non-custodial** (never touches private keys — all transactions are returned unsigned), and **RPC-first** (all data from Solana, no proprietary API for core operations). ### Overall Assessment | Category | Rating | Notes | |----------|--------|-------| | PDA Derivation | **PASS** | All 12 seeds match on-chain `constants.rs` exactly | | Quote Math | **PASS** | Exact match with on-chain buy handler (BigInt, fees, dynamic rate, token split) | | Vault Integration | **PASS** | Correct null/Some handling, wallet link derived from buyer (not vault creator) | | Key Safety | **PASS** | No key custody — unsigned transaction pattern throughout | | Input Validation | **PASS** | Slippage validated with explicit error, lengths checked, PublicKey constructor validates base58 | | External APIs | **PASS** | SAID + CoinGecko + metadata URI — all degrade gracefully, metadata fetch has 10s timeout | | Dependencies | **MINIMAL** | 4 runtime deps, all standard Solana ecosystem | ### Finding Summary | Severity | Count | |----------|-------| | Critical | 0 | | High | 0 | | Medium | 0 | | Low | 0 (3 resolved in v3.2.4) | | Informational | 7 | --- ## Scope ### Files Reviewed | File | Lines | Role | |------|-------|------| | `src/index.ts` | 114 | Public API surface (29 functions, ~37 types, 4 constants) | | `src/types.ts` | 457 | All TypeScript interfaces | | `src/c
design.md
# Torch SDK — Design Document
> TypeScript SDK for the Torch Market protocol on Solana. Version 3.7.23.
## Overview
The Torch SDK is a stateless, RPC-first TypeScript library for interacting with the Torch Market protocol. It reads on-chain state directly from Solana, builds unsigned transactions locally, and returns them for the caller to sign and submit. There is no API server, no websocket dependency, and no custody of keys.
The SDK is designed for AI agent integration. The core safety primitive is the **Torch Vault** — a full-custody on-chain escrow that holds all SOL and tokens. The vault is integrated into all operations (buy, sell, star, borrow, repay, DEX swap) so that agents trade with vault funds and all value stays in the vault. The agent wallet is a disposable controller that holds nothing of value.
## Architecture
```
┌──────────────────────────────────────────────────────────┐
│ CONSUMER (Agent / App) │
│ │
│ 1. Call SDK function (e.g. buildBuyTransaction) │
│ 2. Receive unsigned Transaction │
│ 3. Sign locally with wallet/keypair │
│ 4. Submit to Solana RPC │
└──────────────┬───────────────────────────┬───────────────┘
│ read │ build
▼ ▼
┌──────────────────────────┐ ┌────────────────────────────┐
│ Token Queries │ │ Transaction Builders │
│ │ │ │
│ getTokens() │ │ buildBuyTransaction() │
│ getToken() │ │ buildSellTransaction() │
│ getTokenMetadata() │ │ buildVaultSwapTx() │
│ getHolders() │ │ buildCreateTokenTx() │
│ getMessages() │ │ buildStarTransaction() │
│ getLendingInfo() │ │ buildMigrateTransaction() │
│ getLoanPosition() │ │ buildBorrowTransaction() │
│ getAllLoanPositions() │ │ buildRepayTransaction() │
│ getVault() │ │ buildLiquidateTransaction │
│ getVaultForWallet() │ │ buildClaimProtocolRewardsTx│
│ getVaultWalletLink() │ │ buildHarvestFeesTx() │
│ │ │ buildSwapFeesToSolTx() │
│ │ │ buildCreateVaultTx() │
│ │ │ buildDepositVaultTx() │
│ │ │ buildWithdrawVaultTx() │
│ │ │ buildWithdrawTokensTx() │
│ │ │ buildLinkWalletTx() │
│ │ │ buildUnlinkWalletTx() │
│ │ │ buildTransferAuthorityTx()│
└──────────┬───────────────┘ └──────────┬─────────────────┘
│ │
▼ ▼
┌──────────────────────────────────────────────────────────┐
│ AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/mrsirg97-rgb/torchmarket",
"sourceUrl": "https://clawhub.ai/mrsirg97-rgb/torchmarket",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-04-15T00:45:39.800Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-mrsirg97-rgb-torchmarket/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-mrsirg97-rgb-torchmarket/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-04-15T00:45:39.800Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "3.7K downloads",
"href": "https://clawhub.ai/mrsirg97-rgb/torchmarket",
"sourceUrl": "https://clawhub.ai/mrsirg97-rgb/torchmarket",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-04-15T00:45:39.800Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "4.7.14",
"href": "https://clawhub.ai/mrsirg97-rgb/torchmarket",
"sourceUrl": "https://clawhub.ai/mrsirg97-rgb/torchmarket",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-02-28T15:00:25.398Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-mrsirg97-rgb-torchmarket/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-mrsirg97-rgb-torchmarket/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 4.7.14",
"description": "- Updated Torch SDK dependency from version ^3.7.17 to ^3.7.23 for improved functionality and compatibility. - Incremented skill version to 4.7.14.",
"href": "https://clawhub.ai/mrsirg97-rgb/torchmarket",
"sourceUrl": "https://clawhub.ai/mrsirg97-rgb/torchmarket",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-02-28T15:00:25.398Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
