--- name: overlay-market description: Trade leveraged perpetual futures on Overlay Protocol (BSC). Scan markets, analyze prices with technical indicators, check wallet balance, encode build/unwind transactions, and monitor positions with PnL. Use when the user wants to trade on Overlay, analyze Overlay markets, or manage Overlay positions. compatibility: Requires Node.js 18+. Run `npm install` in the skill directory. Requires network access to BSC RPC and Overlay APIs. metadata: author: overlay-market version: "0.1.6" chain: bsc chain-id: "56" env: OVERLAY_PRIVATE_KEY: required: false description: Private key for signing transactions (needed for send.js and --dry-run) BSC_RPC_URL: required: false description: BSC RPC endpoint (defaults to bsc-dataseed.binance.org) ONEINCH_API_KEY: required: false description: 1inch API key — bypasses the Overlay proxy and calls api.1inch.dev directly (used by unwind.js) --- # Overlay Market Trade leveraged perpetual futures on 30+ markets (crypto, commodities, indices, social metrics) on BSC. Overlay markets are synthetic — you trade against a protocol-managed price feed, not an order book. Positions are opened with USDT collateral. ## Transaction Signing This skill produces **unsigned transaction objects** (JSON with `to`, `data`, `value`, `chainId`). Your agent needs a way to sign and broadcast on BSC (chainId 56). A bundled `send.js` script is provided for simple private-key signing, but any signer works. The recommended setup is a smart contract account with restricted permissions (e.g. Safe + Zodiac Roles), so the agent can only call approved functions. Do not use a raw private key with real funds — use an external signer or a dedicated low-value testing wallet. ## Configuration | Variable | Required | Description | |----------|----------|-------------| | `OVERLAY_PRIVATE_KEY` | No | Private key for `send.js` and `--dry-run`. Not needed if your agent signs externally — use `--owner
` with `unwind.js` instead. | | `BSC_RPC_URL` | No | BSC RPC endpoint. Defaults to `bsc-dataseed.binance.org`. | | `ONEINCH_API_KEY` | No | If set, `unwind.js` calls `api.1inch.dev` directly instead of the Overlay proxy. | ## External Services | Service | Host | Used by | |---------|------|---------| | Overlay market catalog | `api.overlay.market/data/api/markets` | `scan.js` | | Overlay OHLC candles | `api.overlay.market/bsc-charts/v1/charts` | `chart.js` | | Overlay prices | `api.overlay.market/bsc-charts/v1/charts/marketsPricesOverview` | `scan.js` | | Goldsky subgraph | `api.goldsky.com` | `positions.js`, `unwind.js` | | 1inch Swap API | `api.1inch.dev` or Overlay proxy (see below) | `unwind.js` | | BSC RPC | `bsc-dataseed.binance.org` or `BSC_RPC_URL` | all scripts | ### 1inch Swap API The Shiva contract's `unwindStable` hardcodes 1inch AggregationRouterV6 as its only swap path — it requires pre-built 1inch calldata and has no fallback, so calling the 1inch API is architecturally required. By default, requests go through an Overlay-operated Cloudflare Workers proxy (`1inch-proxy.overlay-market-account.workers.dev`) that injects the API key server-side. Set `ONEINCH_API_KEY` to call `api.1inch.dev` directly and bypass the proxy. The swap calldata is validated at two layers: - **Client-side** — `unwind.js` ABI-decodes the response and extracts `minReturnAmount` - **On-chain** — Shiva verifies `srcToken`, `dstToken`, `dstReceiver`, `minReturnAmount`, `spentAmount`, and post-swap token balance ### Static Analysis Notes Naive taint analysis may flag two patterns in `common.js` — both are false positives: - **`process.env.BSC_RPC_URL` + network call** (line 139) — The env var *is* the RPC endpoint. It becomes a destination URL by design, not exfiltrated data. - **`readFileSync` + network call** (line 10) — `readFileSync` is used only for the local `.cache/` directory (read/write market data cache). Cached data originates *from* network responses, not the other way around. No local file contents are sent to external services. `OVERLAY_PRIVATE_KEY` is read at line 147 but never transmitted — it is passed to viem's `privateKeyToAccount()` which derives the address and signs locally. ## Scripts --- ### approve.js Approve USDT spending for the LBSC contract. Required before the first `build.js` transaction. ``` node scripts/approve.js [amount] ``` Without `amount`, approves unlimited. Shows current allowance if `OVERLAY_PRIVATE_KEY` is set. --- ### balance.js Wallet USDT and BNB balance. ``` node scripts/balance.js [address] ``` --- ### scan.js All markets with prices and 1h/24h/7d changes. ``` node scripts/scan.js [--details