Clawhub
Pre-trade risk API for crypto trading agents. Returns exposure limits, allowed actions, and policy constraints for BTC/USD and ETH/USD from 30+ real-time signals. Spot, perpetual futures (perps), and DeFi borrowing aware.
Rank
62
Safety
84
Downloads
1.3k
Updated
Oct 10, 2026
Version
1.4.1
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.3K downloads reported by the source. Last updated 10/10/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 10, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 10, 2026
- Adoption signal
- 1.3K downloadsadoption · observed Oct 10, 2026
- Latest release
- 1.4.1release · observed Sep 10, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17avrjxb7vs8sb2xqm1097rwx8e5hs6:riskstate- Install using `clawhub skill install s17avrjxb7vs8sb2xqm1097rwx8e5hs6:riskstate` in an isolated environment before connecting it to live workloads.
- No published capability contract is available yet, so validate auth and request/response behavior manually.
- Review the upstream CLAWHUB listing at https://clawhub.ai/riskstate/riskstate before using production credentials.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-riskstate-riskstate/snapshot"
Documentation
CLAWHUB
144,590 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
--- name: riskstate version: 1.4.1 description: Pre-trade risk API for crypto trading agents. Returns exposure limits, allowed actions, and policy constraints for BTC/USD and ETH/USD from 30+ real-time signals. Spot, perpetual futures (perps), and DeFi borrowing aware. category: risk-management auth: bearer-token env: RISKSTATE_API_KEY endpoint: POST https://api.riskstate.ai/v1/risk-state assets: [BTC, ETH] refresh: 60s cache, recommend 5min polling homepage: https://riskstate.ai docs: https://riskstate.ai/docs/api repository: https://github.com/Riskstate/risk-engine tags: [crypto, ai, bitcoin, trading, ethereum, trading-bot, agents, policy-engine, ai-agents, defi, decentralized-finance, ai-trading, agent-skills, defi-risk-management, risk-governance, skills-sh, perpetual-futures, perps, spot-trading, btc-usd, eth-usd] pricing: free-beta author: RiskState license: proprietary --- # RiskState — Pre-Trade Risk Layer for Crypto ## What it does Returns **dynamic risk permissions** for BTC/USD and ETH/USD before capital is deployed. A deterministic policy engine computes how much exposure is allowed based on 30+ real-time signals across macro, on-chain, derivatives, and DeFi health. Applicable to **spot**, **perpetual futures (perps)**, and **DeFi borrowing**. The response tells you: - **max_size_fraction**: Maximum exposure as fraction of portfolio (0.0–1.0). For spot: amount to deploy. For perps: max notional exposure (divide by your leverage for margin). - **allowed_actions / blocked_actions**: What MAY and MUST NOT be done (enum tokens) - **risk_flags**: Structural blockers (hard stop) vs contextual risks (reduce conviction) - **binding_constraint**: Which cap is limiting and why - **policy_level**: 1–5 summary label (informational — use `exposure_policy` for enforcement) ## What it does NOT do - No trade signals, no entry/exit prices, no predictions - No portfolio allocation advice - No order execution or routing - No historical data or backtesting This is a **risk governor**, not a trading oracle. The assessment is USD-denominated. ## When to call - **Before opening or sizing positions** — check permissions first - **Periodically during holds** — every 5 min for active trading, every 4h for holding - **After significant market moves** — cache invalidates after 60s (`ttl_seconds` in response) ## Authentication Request a free API key at [https://riskstate.ai](https://riskstate.ai) (email only). You will receive a key with the `rs_live_` prefix. Set it as the `RISKSTATE_API_KEY` environment variable and pass it as a Bearer token: ``` Authorization: Bearer $RISKSTATE_API_KEY ``` ## Binding precedence When consuming the response, agents MUST evaluate fields in this order: 1. `risk_flags.structural_blockers` — if non-empty, ABORT new entries 2. `exposure_policy.blocked_actions` — actions the agent MUST NOT take 3. `exposure_policy.reduce_recommended` — reduce exposure if true 4. `exposure_policy.max_size_fraction` — maximum position siz
README.md
<p align="center">
<img src="https://riskstate.ai/logo-r-grey.svg" width="48" alt="RiskState" />
</p>
<h1 align="center">RiskState</h1>
<p align="center">
<strong>Pre-trade risk API for crypto — BTC/USD and ETH/USD exposure governance</strong><br />
<sub>For trading agents, open-source systems, and capital desks. Spot and perpetual futures (perps). DeFi borrowing aware.</sub>
</p>
<p align="center">
<a href="https://api.riskstate.ai/v1/risk-state"><img src="https://img.shields.io/badge/API-v1.4.0-blue?style=flat-square" alt="API Version" /></a>
<a href="https://riskstate.ai"><img src="https://img.shields.io/badge/status-beta-green?style=flat-square" alt="Status" /></a>
<a href="#supported-assets"><img src="https://img.shields.io/badge/assets-BTC%2FUSD%20%7C%20ETH%2FUSD-orange?style=flat-square" alt="Assets" /></a>
<a href="#markets"><img src="https://img.shields.io/badge/markets-spot%20%7C%20perps%20%7C%20DeFi-purple?style=flat-square" alt="Markets" /></a>
<a href="#pricing"><img src="https://img.shields.io/badge/pricing-free%20beta-brightgreen?style=flat-square" alt="Pricing" /></a>
</p>
<p align="center">
<a href="https://riskstate.ai">Website</a> · <a href="docs/api-v1.md">API Reference</a> · <a href="SKILL.md">SKILL.md</a> · <a href="https://x.com/riskstate_ai">X/Twitter</a>
</p>
---
## What is RiskState?
A deterministic engine that converts live market state into **dynamic risk permissions** — exposure limits, leverage caps, and allowed actions — before capital is deployed.
One API call returns position limits, allowed actions, and policy constraints computed from **30+ real-time signals** across macro, on-chain, derivatives, and DeFi health. The assessment is **USD-denominated**: all scoring is based on BTC/USD and ETH/USD price action, derivatives, and macro conditions.
```bash
curl -X POST https://api.riskstate.ai/v1/risk-state \
-H "Authorization: Bearer $RISKSTATE_API_KEY" \
-H "Content-Type: application/json" \
-d '{"asset": "BTC"}'
```
```json
{
"exposure_policy": {
"max_size_fraction": 0.42,
"leverage_allowed": true,
"allowed_actions": ["DCA", "LONG_SHORT_CONFIRMED"],
"blocked_actions": ["ALL_IN", "LEVERAGE_GT_2X"]
},
"policy_level": 4,
"risk_flags": {
"structural_blockers": [],
"context_risks": ["HIGH_COUPLING"]
},
"binding_constraint": {
"source": "MACRO",
"reason_codes": ["MACRO_NEUTRAL", "COUPLING_NORMAL"]
}
}
```
Read `max_size_fraction`, check `structural_blockers`, and act. No parsing. No interpretation.
## Why?
Whether you run an AI trading agent, a systematic trading system, or a manual desk — crypto markets have regime shifts that require adaptive risk governance. Static rules fail. RiskState provides a **pre-trade risk check** that adapts every 60 seconds.
| Without governance | With RiskState |
|---|---|
| Position size based on signal confidence alone | Capped at `max_size_fraction` (max notional exposure) |
| No awareness of macro regime_meta.json
{
"ownerId": "kn7djkxqyactdmda78e52x792h83c54v",
"slug": "riskstate",
"version": "1.4.1",
"publishedAt": 1789038662413
}CHANGELOG.md
# Changelog
All notable changes to the RiskState API will be documented in this file.
## [1.4.0] - 2026-04-22
### Added
- **Policy combiner refinements (PR3)** — Five additive refinements to `policy_permissions`, all surfaced in the response and the audit `policy_hash`:
- **TREND / RANGE weight split** — `TREND` blends 0.65 structural / 0.35 tactical (continuation-led); `RANGE` 0.55 / 0.45 (tactical has more voice). PANIC, EUPHORIA, and SQUEEZE weights unchanged.
- **DQ-gated structural veto** — structural veto is skipped when `structural_score.data_quality < 60`, emitting `STRUCTURAL_VETO_SKIPPED_LOW_DQ`. Prevents low-confidence structural reads from overriding clean tactical signals.
- **PANIC SHORT override** — PANIC regime exempts SHORT positions from the strong-structural veto (`STRUCTURAL_VETO_SKIPPED_PANIC`), so dead-cat-bounce / fake-breakout setups are not blocked.
- **Bucket codes in `reason_codes`** — typed tokens (e.g. `TACTICAL_STRONG_BULL_72`, `STRUCTURAL_WEAK_22`) replace raw scores for downstream classification.
- **`shadow_max_size_fraction`** — read-only preview of a candidate combiner-driven sizing rule. Does not bind today; surfaced for offline comparison.
### Changed
- Policy hash inputs widened to cover the new bucket codes and shadow size — cached hashes from v1.3.0 will not match (one-time invalidation).
## [1.3.0] - 2026-04-21
### Added
- **Decoupled Structural + Tactical scores + policy combiner (PR2)** — Splits the single composite into two layers that each drive the appropriate decision:
- `structural_score` — slow horizon (weeks-months): cycle, supply, demand, macro. `{overall, label, subfamilies, data_quality, source}`.
- `tactical_score` — fast horizon (24-72h): positioning pressure, momentum, volume/CVD, derivatives extremity, L/S velocity, whale pressure. `{overall, label, components, signals}`.
- `policy_permissions` — context-aware combiner producing `risk_permission_score`, regime-dependent weights, `direction_bias`, `direction_layer` (audit), and `reason_codes`.
### Changed
- **`exposure_policy.direction_bias` now comes from the combiner** (was composite-tilt). Breaking semantics.
- `exposure_policy.direction_layer` added — audit field showing which layer drove direction.
- Existing `composite` retained for backwards compatibility; `max_size_fraction` still driven by the legacy 4-cap engine.
## [1.2.1] - 2026-04-21
### Added
- **Positioning Pressure Score (PR1)** — continuous 0-100 tactical signal derived from the squeeze scorer (50 = neutral, >50 short-squeeze setup). Wired into BTC and ETH composite as a 9% subscore. Response gains `positioning.positioning_pressure_score` and `positioning.positioning_pressure_net`.
### Changed
- **ETH issuance recalibration** — asymmetric bands + 7d/30d blend. Mild post-Merge inflation (+0.82%/yr) now scores ~53 (was ~30); hard-downgrade threshold raised to >+2.0%/yr.
## [1.2.0] - 2026-03-19
### Added
- **Usage tracking** — Monthly and total API cdocs/api-v1.md
# RiskState API v1 Documentation
Pre-trade risk permissions for BTC/USD and ETH/USD. Spot, perpetual futures (perps), and DeFi borrowing aware.
> **USD-denominated:** All scoring is based on BTC/USD and ETH/USD price action, derivatives, and macro conditions. If you trade non-USD pairs (e.g., BTC/EUR, ETH/BTC), additional cross-rate risk is not covered by this API.
## Endpoint
```
POST /v1/risk-state
```
## Authentication
All requests require a Bearer token in the `Authorization` header.
```
Authorization: Bearer <your_api_key>
```
### Key types
| Type | Format | Rate limit | Access |
|------|--------|------------|--------|
| **Owner** | `RISKSTATE_API_KEY` env var | Unlimited | All endpoints |
| **External** | `rs_live_` + 64 hex chars | 60 req/min | `/v1/risk-state` + read-only endpoints |
### Getting an API key
Request API access at [https://riskstate.ai](https://riskstate.ai) — only an email is required. You'll receive an `rs_live_` key via email within minutes.
Keys are managed through the `/api/api-keys` admin endpoint (owner-only).
The endpoint **fails closed**: if the server secret is not configured, all requests are denied (401). Rate-limited requests return 429 with `retry_after_seconds: 60`.
## Request
### Headers
| Header | Required | Value |
|--------|----------|-------|
| `Authorization` | Yes | `Bearer <token>` |
| `Content-Type` | Yes | `application/json` |
### Body (JSON)
| Field | Type | Default | Description |
|-------|------|---------|-------------|
| `asset` | string | `"BTC"` | Asset to evaluate. `"BTC"` or `"ETH"`. |
| `wallet` | string | `null` | Ethereum wallet address (0x...) for DeFi position data. Optional. |
| `protocol` | string | `"spark"` | DeFi lending protocol. `"spark"` or `"aave"`. Only used when `wallet` is provided. |
| `include_details` | boolean | `false` | Include expanded scoring details in response. |
| `reference_time` | number | `now` | Unix seconds. Pins `daysSinceHalving` and the policy hash to a single timestamp, enabling bit-exact reproducibility. Must be in `[halving, now+1d]`. |
| `allow_degraded` | boolean | `false` | If `false` (default), the endpoint returns **503 Core data unavailable** when any of `price`, `rsi`, `funding` are missing upstream. Set to `true` to receive a degraded policy (with `data_integrity` capped). |
### Example requests
**Minimal (BTC):**
```bash
curl -X POST https://api.riskstate.ai/v1/risk-state \
-H "Authorization: Bearer $RISKSTATE_API_KEY" \
-H "Content-Type: application/json" \
-d '{"asset": "BTC"}'
```
**Detailed (with scoring breakdown):**
```bash
curl -X POST https://api.riskstate.ai/v1/risk-state \
-H "Authorization: Bearer $RISKSTATE_API_KEY" \
-H "Content-Type: application/json" \
-d '{"asset": "BTC", "include_details": true}'
```
**DeFi monitoring (with wallet + Aave):**
```bash
curl -X POST https://api.riskstate.ai/v1/risk-state \
-H "Authorization: Bearer $RISKSTATE_API_KEY" \
-H "Content-Type: application/json" \
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/riskstate/skills/riskstate",
"sourceUrl": "https://clawhub.ai/riskstate/skills/riskstate",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T18:49:59.527Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-riskstate-riskstate/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-riskstate-riskstate/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-10T18:49:59.527Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.3K downloads",
"href": "https://clawhub.ai/riskstate/riskstate",
"sourceUrl": "https://clawhub.ai/riskstate/riskstate",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T18:49:59.527Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "1.4.1",
"href": "https://clawhub.ai/riskstate/riskstate",
"sourceUrl": "https://clawhub.ai/riskstate/riskstate",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-10T11:11:02.413Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-riskstate-riskstate/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-riskstate-riskstate/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 1.4.1",
"description": "Canonical URLs moved to the Riskstate GitHub org; skill migrated to the riskstate publisher.",
"href": "https://clawhub.ai/riskstate/riskstate",
"sourceUrl": "https://clawhub.ai/riskstate/riskstate",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-10T11:11:02.413Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
