Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, email [email protected] and we’ll put it right.

Quiver Risk Brain

REMOTE · QUIVER-PRODUCTION-C3A8.UP.RAILWAY.APP · SCANNED AUG 3

Verifiable, deterministic risk math for autonomous agents; re-runnable proof on every answer.

+7 this week 71 Trust /100
Trust breakdown (6 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →

Endpoint Security74
Transport & Reachability100
Schema Quality & AI Usability61
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 2340 tokens (~260/item across 9 items; 9 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management27
  • Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
  • Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Install

Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.

remote · quiver-production-c3a8.up.railway.app

# add to Claude Code
claude mcp add --transport http tristan-tech-ai-quiver-risk-brain https://quiver-production-c3a8.up.railway.app/mcp
# ~/.codex/config.toml
[mcp_servers.tristan-tech-ai-quiver-risk-brain]
url = "https://quiver-production-c3a8.up.railway.app/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "tristan-tech-ai-quiver-risk-brain": {
      "type": "remote",
      "url": "https://quiver-production-c3a8.up.railway.app/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add tristan-tech-ai-quiver-risk-brain --url https://quiver-production-c3a8.up.railway.app/mcp --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  tristan-tech-ai-quiver-risk-brain:
    url: "https://quiver-production-c3a8.up.railway.app/mcp"
// mcp.json
{
  "mcpServers": {
    "tristan-tech-ai-quiver-risk-brain": {
      "type": "http",
      "url": "https://quiver-production-c3a8.up.railway.app/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 3 Aug 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 23 to 27. That category is still filling its 30-day observation window: 7 days of observed history at the previous scan, 8 at this one. The score rises as the window fills, whether or not the server changes.

  • 1 Aug 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 17 to 20. That category is still filling its 30-day observation window: 5 days of observed history at the previous scan, 6 at this one. The score rises as the window fills, whether or not the server changes.

  • 31 Jul 26 +3
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 30 Jul 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 29 Jul 26 +1
    • “perp_gate” reworded the description of “side” cosmetic
    • “perp_gate” reworded the description of “venue” cosmetic

    2 cosmetic changes on this day. Switch on “Show cosmetic changes” to see them.

  • 28 Jul 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.

  • 27 Jul 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 26 Jul 26 64

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 3 Aug 2026 · Probed https://quiver-production-c3a8.up.railway.app/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=*.up.railway.app CN=YE1,O=Let's Encrypt,C=US 29 Jul 2026 27 Oct 2026 ECDSA 256 ECDSA-SHA384 6da79bb561da3efeb0e751ca21abd3999fe
SANs: *.up.railway.app, up.railway.app
CN=YE1,O=Let's Encrypt,C=US (CA) CN=Root YE,O=ISRG,C=US 3 Sept 2025 2 Sept 2028 ECDSA 384 ECDSA-SHA384 5ddd70dd31f801c85c186a7a04b80afe
CN=Root YE,O=ISRG,C=US (CA) CN=ISRG Root X2,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 ECDSA-SHA384 872165fc34b6e5fba8add5b3705fb53a
CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) CN=ISRG Root X1,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 SHA256-RSA 6c8f1dc727c7117f7baf853ac980f9cd
DNSSEC insecure

Validation of quiver-production-c3a8.up.railway.app. Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
app. present 23684 8 Verified
railway.app. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication No authorisation required

The endpoint answered without asking for a token. Anyone who knows the URL can reach it.

Result No authorisation required
HTTP status 200
Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://quiver-production-c3a8.up.railway.app/mcp Verified 200
http (plaintext) http://quiver-production-c3a8.up.railway.app/mcp HTTPS enforced 301 https://quiver-production-c3a8.up.railway.app/mcp
MCP tools — 9 exposed · ~2,340 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.

Tool Tokens
event_vol ~306

Options-implied expected move around a scheduled event (FOMC/CPI/earnings/etc.). Given spot, ATM implied vol, and days-to-event, returns the 1σ move, the straddle-implied expected ABSOLUTE move (risk-neutral E|ΔS|), and the probability of exceeding move thresholds. Given the vol term structure across the event (ATM IV of the expiry before vs after), it ISOLATES the event's own priced-in move (the Wright event-day technique). Self-checked: the straddle equals a numerical integral of |S_T−S₀|. This is the magnitude that macro calendars (which give only date + impact label) leave out.

NameTypeReqDescription
Tnumberyears (or daysToEvent)
atmIvnumberATM IV as a decimal (alternative to atmIvPct)
atmIvPctnumberATM IV in % (or atmIv decimal)
daysAfternumberdays to the after-event expiry
daysBeforenumberdays to the before-event expiry
daysToEventnumberdays until the event
ivAfterPctnumberATM IV (%) of the expiry just AFTER the event
ivBeforePctnumberATM IV (%) of the expiry just BEFORE the event
spotnumberyescurrent spot price
thresholdsPctarraymove thresholds (%) for probability-of-exceeding
NameTypeReqDescription
atmIvPctATM IV used (%)
checksarrayGround-truth self-checks; the result is untrustworthy if any fails.
eventIsolationthe event's own priced-in move, isolated from the term structure (when before/after IVs are given)
expectedMove1σ move + straddle-implied expected |ΔS| (risk-neutral)
horizonDayshorizon in days
methodtechnique + assumptions used
okbooleanfalse when the engine rejected the input
probabilityMoveBeyondprobability of exceeding each move threshold
proofobjectVerifiability envelope: echoed inputs, engine codeHash, contentHash of this exact result, self-checks, EIP-712 signature (EAS-ready). Re-run the open engine on `inputs` to reproduce the result byte-f…
spotspot the computation is anchored on

No examples provided.

exec_verify ~238

Deterministic execution-quality / fair-fill verification. Given a completed swap (amountIn, amountOutRealized) plus either the pre-trade pool reserves+fee (constant-product) or a fair reference price, returns how many basis points the fill lost to ADVERSE execution (sandwich/MEV/stale) beyond the unavoidable fee + own price impact. Proves that a fill "within slippage tolerance" can still have been robbed. Call after a swap to detect being sandwiched.

NameTypeReqDescription
amountInnumberyesinput amount actually sent
amountOutRealizednumberyesoutput amount actually received
fairPricenumberreference mode: fair out-per-in price at submit time
feeTiernumberpool fee as fraction, e.g. 0.003
reserveInnumberpool reserve of input token, pre-trade (constant-product mode)
reserveOutnumberpool reserve of output token, pre-trade
slippageTolerancePctnumberthe slippage setting used, to demonstrate within-tolerance-yet-robbed
NameTypeReqDescription
adverseExecutionBpsbps lost to ADVERSE execution beyond the honest cost
adverseValueOutvalue lost to adverse execution, in output-token units
checksarrayGround-truth self-checks; the result is untrustworthy if any fails.
honestFillPricethe fill price an honest execution would have produced
honestOutoutput an honest execution would have delivered
midPricepre-trade mid price
modeconstant-product or reference-price mode
noteinterpretation guidance
okbooleanfalse when the engine rejected the input
proofobjectVerifiability envelope: echoed inputs, engine codeHash, contentHash of this exact result, self-checks, EIP-712 signature (EAS-ready). Re-run the open engine on `inputs` to reproduce the result byte-f…
realizedFillPricethe fill price actually received
unavoidableCostBpsfee + own price impact — the honest, unavoidable cost (bps)
verdictplain-language verdict

No examples provided.

lp_risk ~229

Forward-looking liquidity-provision risk. Given a realized price ratio (for impermanent loss) and/or a volatility + horizon (for expected divergence / LVR), returns the closed-form IL, the expected −σ²T/8 divergence, and — with a fee APR — the net forecast and breakeven volatility (the vol above which fees no longer cover the bleed). Self-checked: the IL closed form is verified at the token level against explicit constant-product amounts. Call before providing liquidity to see whether the fee yield can plausibly beat the divergence loss.

NameTypeReqDescription
capitalUsdnumberposition capital in USD — losses are also reported in USD
concentrationFactornumberV3 amplifier ≥1 (default 1)
feeAprPctnumberannualized fee yield estimate
horizonPeriodsnumberperiods (default 1)
periodsPerYearnumberdefault 365
priceRationumberrealized P1/P0 for realized IL
volatilitynumberper-period vol (decimal) for expected divergence
NameTypeReqDescription
checksarrayGround-truth self-checks; the result is untrustworthy if any fails.
concentrationFactorV3 concentration amplifier applied
expectedDivergenceexpected divergence loss / LVR over the horizon (−σ²T/8 law)
feeVsDivergencenet forecast and breakeven volatility vs the fee APR
modelmodel assumptions used
okbooleanfalse when the engine rejected the input
proofobjectVerifiability envelope: echoed inputs, engine codeHash, contentHash of this exact result, self-checks, EIP-712 signature (EAS-ready). Re-run the open engine on `inputs` to reproduce the result byte-f…
realizedILclosed-form impermanent loss at the realized price ratio

No examples provided.

options_risk ~215

Portfolio greeks (delta/gamma/vega/theta/vanna/volga) + SPAN-style scenario margin for an options book on Black-76. Given a list of legs {type, strike, expiryDays, iv, quantity(signed)} and a forward, returns aggregate greeks, first-order P&L per underlying move, and the worst-case loss over a price×vol grid. Self-checked: analytic greeks are verified against finite-difference derivatives of the repriced book. Call to size an options book's true net risk and margin — not the sum of per-leg notionals.

NameTypeReqDescription
forwardnumbershared forward price (or set per position)
positionsarrayyesoption legs of the book
rnumberdiscount rate, default 0
scanRangePctnumberSPAN price scan range, default 0.15
volShiftVolPtsnumberSPAN vol shift in vol-points, default 10
NameTypeReqDescription
checksarrayGround-truth self-checks; the result is untrustworthy if any fails.
greeksaggregate delta/gamma/vega/theta/vanna/volga — each verified vs finite differences
modelBlack-76 assumptions used
okbooleanfalse when the engine rejected the input
pnlPerUnderlyingPctMovefirst-order P&L per % move of the underlying
portfolioValuemark-to-model value of the book
positionsper-leg pricing breakdown
positionsCountnumber of legs priced
proofobjectVerifiability envelope: echoed inputs, engine codeHash, contentHash of this exact result, self-checks, EIP-712 signature (EAS-ready). Re-run the open engine on `inputs` to reproduce the result byte-f…
spanMarginworst-case loss over the price×vol scenario grid (SPAN-style margin)

No examples provided.

perp_gate ~427

Deterministic perpetual-futures risk. Given a position (entry, size, margin/leverage, maint-margin/maxLeverage), returns the exact liquidation price, the % adverse move to liquidation, effective leverage, and (if a funding rate is given) the funding drag. Pass a Hyperliquid `symbol` (e.g. BTC) to auto-fill live mark price, funding, and max leverage. Includes a self-check proving the liquidation invariant. Call this BEFORE opening or sizing any leveraged perp position — an agent that knows its true liquidation distance does not get surprise-liquidated.

NameTypeReqDescription
entryPricenumberdefaults to live mark if a symbol is given
fundingRateHourlynumberhourly funding rate (Hyperliquid funds hourly)
horizonHoursnumberhorizon for the funding-drag estimate, in hours
leveragenumberposition leverage (alternative to margin)
maintMarginRatenumbere.g. 0.0125; or pass maxLeverage (mmr = 0.5/maxLeverage)
marginnumberisolated margin posted (or pass leverage)
markPricenumbercurrent mark; distance-to-liq measured from here
maxLeveragenumbervenue max leverage for the asset
notionalnumberposition notional in quote/USD
sidestringlong | short (buy | sell are accepted synonyms, as is -1 for short); default long
sizenumberposition size in base units (or pass notional)
symbolstringperp symbol (e.g. BTC) — auto-fills live markPrice, fundingRateHourly, and the margin source (Hyperliquid notional tiers or dYdX maintenance rate); also defaults entryPrice to the live mark
venuestringlive-data venue (default hyperliquid). The maths is venue-agnostic — for any other venue omit this and pass maxLeverage/markPrice/fundingRateHourly yourself.
NameTypeReqDescription
checksarrayGround-truth self-checks; the result is untrustworthy if any fails.
effectiveLeveragenotional / margin actually run
fundingfunding drag over the horizon (when a funding rate is given)
initialMarginRatePctinitial margin rate applied (%)
liquidationPriceexact price at which the position liquidates
maintenanceMarginRatePctmaintenance margin rate applied (%)
marginTiervenue margin tier the notional falls into
modelmodel assumptions used
moveToLiquidationPctadverse % move (from mark) that triggers liquidation
okbooleanfalse when the engine rejected the input
proofobjectVerifiability envelope: echoed inputs, engine codeHash, contentHash of this exact result, self-checks, EIP-712 signature (EAS-ready). Re-run the open engine on `inputs` to reproduce the result byte-f…

No examples provided.

portfolio_gate ~382

Cross-venue portfolio risk. Given positions across venues [{venue, asset|symbol, side, size, entryPrice, margin|leverage, maxLeverage|marginTiers}] — OR just account: a Hyperliquid 0x address, whose FULL live book (positions, margins, account equity, the venue's own liquidation prices) is pulled keylessly — returns TRUE net exposure per underlying, the leg that liquidates FIRST (the binding constraint), concentration (HHI / effective independent bets), and a correlated-crash stress counting how many legs liquidate SIMULTANEOUSLY when the market moves ±X% (correlation→1, the Oct-10-2025 crash regime). Pass Hyperliquid symbols to auto-fill live mark/leverage/margin-tiers. Self-checked (exposure reconciliation, per-leg liquidation invariant, nearest=min, monotone stress, venue-liquidation cross-check). Call to see whether independently-sized bets are secretly ONE bet that blows up together.

NameTypeReqDescription
accountstringOR: a Hyperliquid account address (0x…) — the full live book (positions, margins, equity, venue liquidation prices) is pulled keylessly; explicit positions take precedence.
betaTierstringbeta regime for the factor stress: mild | moderate | severe — cross-event validated tiers (pre-registered). Default = worst-case single-event table; explicit betas override.
positionsarraylegs: {venue, asset|symbol, side long|short, size, entryPrice, markPrice?, margin|leverage, maxLeverage|maintMarginRate|marginTiers}. A Hyperliquid symbol auto-fills live mark/leverage/tiers.
shockScenariosPctarraycorrelated market moves (%) to stress; default [5,10,20,30]
NameTypeReqDescription
checksarrayGround-truth self-checks; the result is untrustworthy if any fails.
concentrationHHI + effective number of independent bets
correlatedShockStressper-scenario: how many legs liquidate simultaneously at a correlated ±X% move
modelmodel assumptions used
nearestLiquidationthe leg that liquidates FIRST — the binding constraint
netExposureByAssetTRUE net exposure per underlying (longs netted against shorts)
okbooleanfalse when the engine rejected the input
positionsper-leg breakdown with each liquidation price
positionsCountnumber of legs analyzed
proofobjectVerifiability envelope: echoed inputs, engine codeHash, contentHash of this exact result, self-checks, EIP-712 signature (EAS-ready). Re-run the open engine on `inputs` to reproduce the result byte-f…
totalGrossNotionalsum of |notional| across legs
totalNetNotionalnet notional after long/short netting

No examples provided.

risk_attest ~132

Batch the content-hashes from many Quiver proof envelopes into ONE Merkle root plus per-item inclusion proofs, so a single on-chain anchor (your wallet's tx) attests all of them at once. Self-checked for completeness (every item verifies) and soundness (a non-member does not). Use to make a batch of risk computations cheaply and permanently attestable for audit/liability, without a chain write per computation.

NameTypeReqDescription
contentHashesarrayalternatively, raw content-hashes
itemsarrayproof envelopes (uses proof.contentHash) or raw content-hashes (hex)
NameTypeReqDescription
algorithmhash/tree construction used
anchorEIP-712 (EAS-ready) attestation payload for the single on-chain anchor
attestationsper-item inclusion proofs
checksarrayGround-truth self-checks; the result is untrustworthy if any fails.
duplicateLeavesduplicate content-hashes detected in the batch
leafCountnumber of items batched
merkleRootthe single root that attests every item
okbooleanfalse when the engine rejected the input
proofobjectVerifiability envelope: echoed inputs, engine codeHash, contentHash of this exact result, self-checks, EIP-712 signature (EAS-ready). Re-run the open engine on `inputs` to reproduce the result byte-f…
verifyhow to verify inclusion against the root

No examples provided.

size_gate ~211

Deterministic position sizing (fractional Kelly) + risk-of-ruin. Given an edge — discrete {winProb, winLossRatio} or continuous {expectedReturn, volatility} — and a bankroll, returns the fractional-Kelly size and the probability of ever drawing down to 50/75/90%. The direct antidote to over-betting: full Kelly rides thin edges to ruin; this defaults to quarter-Kelly. Call before sizing ANY position.

NameTypeReqDescription
bankrollnumberbankroll in account units — recommended sizes are returned in the same units
expectedReturnnumbercontinuous mode: excess return per period (mu)
kellyFractionnumberfraction of full Kelly to bet (default 0.25)
volatilitynumbercontinuous mode: volatility per period (sigma)
winLossRationumberdiscrete mode: net win/loss odds b
winProbnumberdiscrete mode: win probability in (0,1)
NameTypeReqDescription
checksarrayGround-truth self-checks; the result is untrustworthy if any fails.
expectedLogGrowthexpected log-growth rate at the recommended size
fullKellyFractionfull-Kelly fraction of bankroll (the ruinous ceiling, not the recommendation)
hasEdgefalse when the edge is non-positive (bet nothing)
impliedPortfolioVolPctportfolio volatility implied by the recommended size (%)
kellyFractionUsedfraction of full Kelly applied (default 0.25)
leverageimplied leverage of the recommended size
modediscrete or continuous
modelmodel assumptions used
noteplain-language guidance
okbooleanfalse when the engine rejected the input
proofobjectVerifiability envelope: echoed inputs, engine codeHash, contentHash of this exact result, self-checks, EIP-712 signature (EAS-ready). Re-run the open engine on `inputs` to reproduce the result byte-f…
recommendedBetFractionrecommended bet as a fraction of bankroll
recommendedSizerecommended bet size in bankroll units
riskOfRuinprobability of ever drawing down to 50/75/90% of bankroll

No examples provided.

treasury_risk ~200

Stablecoin / on-chain treasury risk. Given a book of positions [{asset, amountUsd, apyPct, venue, chain, pegTarget, depegProbAnnual}], returns concentration (Herfindahl by asset/venue/chain + breaches over a limit), depeg stress (explicit scenarios + a worst-single-depeg scan), weighted and risk-adjusted yield. Self-checked: HHI == Σw², weights sum to 1, depeg-loss identity. Call to size a treasury's real risk — issuer/venue/chain concentration and depeg exposure — not just its headline APY.

NameTypeReqDescription
concentrationLimitPctnumberflag any single exposure above this (default 25)
depegFloornumberworst-single-depeg stress floor (default 0.90)
depegScenariosarray[{asset, price}] explicit depeg stresses
positionsarrayyestreasury holdings
NameTypeReqDescription
checksarrayGround-truth self-checks; the result is untrustworthy if any fails.
concentrationHerfindahl (HHI) by asset/venue/chain + limit breaches
depegStressexplicit depeg scenarios + worst-single-depeg scan
expectedAnnualDepegLossUsdexpected annual loss from depeg probabilities (USD)
modelmodel assumptions used
okbooleanfalse when the engine rejected the input
proofobjectVerifiability envelope: echoed inputs, engine codeHash, contentHash of this exact result, self-checks, EIP-712 signature (EAS-ready). Re-run the open engine on `inputs` to reproduce the result byte-f…
riskAdjustedApyPctyield after expected depeg loss (%)
totalUsdtotal treasury size in USD
verdictplain-language verdict
weightedApyPctholdings-weighted headline APY (%)

No examples provided.