
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
@hypelens/hypelens-agent-rail
Advanced tools
Mainnet place rail. REQUIRED: hypelens-setup/setup.mjs before start-mcp (start refused without .setup-ok). Refuse place until maxBuilderFee>=10 AND equity>0; hl_place_order polls orderStatus and auto-cancels RESTING sizeUsd→IOC until FILLED; builder 1bp.
Outside-agent Hyperliquid place rail. Builder fees → 0x9548B8E9554a1968843B3C380431b10996247c88 at 1bp (f=10) on fills. Never trade/farm that wallet.
hl_place_order / close always attaches builder: { b: 0x9548…, f: 10 }.hl_approve_payloads:
HYPERLIQUID_PRIVATE_KEY or HYPELENS_MASTER_PK is set → auto sign+POST ApproveBuilderFee (and approveAgent when agent ≠ master).HYPELENS_AGENT_PK) → return clear unsigned approve payloads + maxBuilderFee status; refuse place-with-builder until maxBuilderFee >= 10 (no silent $0).hl_place_order requires confirmTrade: true or intent: "trade"|"place"|"execute".cd skills/hyperliquid-place/scripts && npm install && node setup.mjs
# or: npx -y @hypelens/hypelens-agent-rail@0.1.28 hypelens-setup
setup.mjs / hypelens-setup:
ApproveBuilderFee when HYPERLIQUID_PRIVATE_KEY / HYPELENS_MASTER_PK presentmaxBuilderFee — place stays refused until approved (no silent $0)# npx setup then MCP:
npx -y @hypelens/hypelens-agent-rail@0.1.28 hypelens-setup
npx -y @hypelens/hypelens-agent-rail@0.1.28
# sticky ClawHub (REQUIRED order — skip setup = $0 / start refused):
clawhub install hyperliquid-place
cd skills/hyperliquid-place/scripts && npm install && node setup.mjs
# then restart MCP host / node start-mcp.mjs (writes .setup-ok)
Paying path: setup → maxBuilderFee>=10 → equity>0 → hl_place_order(..., confirmTrade:true) → fillStatus=FILLED (RESTING≠paid; rail auto-cancels RESTING sizeUsd→IOC once).
Env:
| Var | Role |
|---|---|
HYPELENS_AGENT_PK | Agent key for places |
HYPERLIQUID_PRIVATE_KEY / HYPELENS_MASTER_PK | Master — auto ApproveBuilderFee |
HYPERLIQUID_ACCOUNT_ADDRESS | Master address when using API wallet |
HYPELENS_NET | mainnet (default) or testnet |
hl_quickstart / hl_new_agent_wallethl_approve_payloads(agentAddress) — auto if master key; else MASTER signs ApproveBuilderFee 0.01%hl_balances (+ fundHow if equity=0)hl_place_order({coin:"BTC", isBuy:true, sizeUsd:12, leverage:2, confirmTrade:true})fillStatus=FILLED — RESTING≠paid (rail auto-cancel RESTING→IOC same turn once)Skipping ApproveBuilderFee / setup / fund / FILLED = $0 fees. Place is hard-refused until on-chain maxBuilderFee covers 1bp. start-mcp REFUSED until setup.mjs wrote .setup-ok.
FAQs
Mainnet place rail. REQUIRED: hypelens-setup/setup.mjs before start-mcp (start refused without .setup-ok). Refuse place until maxBuilderFee>=10 AND equity>0; hl_place_order polls orderStatus and auto-cancels RESTING sizeUsd→IOC until FILLED; builder 1bp.
The npm package @hypelens/hypelens-agent-rail receives a total of 79 weekly downloads. As such, @hypelens/hypelens-agent-rail popularity was classified as not popular.
We found that @hypelens/hypelens-agent-rail demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.