Back to Browse

Defi Garden MCP Server

FinanceModerate6.2MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

Underwritten DeFi yield discovery & goal planning for AI agents on Base & EVM.

About

Underwritten DeFi yield discovery & goal planning for AI agents on Base & EVM.

Remote endpoints: streamable-http: https://www.defi.garden/api/mcp

Security Report

6.2
Moderate6.2Moderate Risk

DeFi Garden is a client-side web application with an MCP server component for AI integration. The codebase demonstrates reasonable security practices for a static frontend application, but several moderate concerns exist: the MCP server implementation lacks documented authentication mechanisms, there is extensive use of external APIs without visible rate-limiting or validation safeguards, and the keeper modules execute autonomous transactions on Hyperliquid with minimal documented access controls. The live-browser.js script injection mechanism, while functional, presents attack surface if the local development server is misconfigured. Supply chain analysis found 1 known vulnerability in dependencies (0 critical, 1 high severity).

3 files analyzed ยท 11 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

env_vars

Check that this permission is expected for this type of plugin.

HTTP Network Access

Connects to external APIs or services over the internet.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

File System Write

Writes or modifies files on your machine. Check that this is expected for the tool.

localStorage

Check that this permission is expected for this type of plugin.

process_spawn

Check that this permission is expected for this type of plugin.

system_info

Check that this permission is expected for this type of plugin.

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

๐ŸŒฑ DeFi Garden

Calm, honest DeFi yield discovery and goal-based savings planning.

DeFi Garden is a static, zero-backend, zero-build-step web application built on the DefiLlama yields API, designed for cautious savers and DeFi operators who value trust, realistic projections, and mathematical transparency over speculative hype.

Live Demo MIT License React 18 UMD


๐ŸŒŸ The Two Core Faces of DeFi Garden

DeFi Garden serves two distinct workflows through an inline, zero-flash IA router (window.__APP_MODE in home.html):

1. ๐Ÿชด Garden Planner (Default Experience โ€” / and plan.html)

  • Goal-First Conversational Savings: Plan savings around real-life goals (subscriptions, gadgets, life milestones) rather than chasing abstract APY numbers.
  • Yield-Funded Paradigm: "Buy it outright and the money's gone. Garden it and you keep the money AND get the thing."
  • Blended Yield Rates: Calculates honest "forever numbers" โ€” the capital required so ongoing live yield pays recurring bills automatically.
  • Degen Honesty: Applies a mandatory โ…“ decay haircut to variable farm/reward emissions, ensuring users plan around realistic long-term carry.

2. ๐Ÿ“Š Analytics & Yield Discovery (/?token=, /?chain=, /?pool=, /?app=1)

  • Multi-Chain Pool Explorer: Real-time yield monitoring across 50+ blockchains (Ethereum, Arbitrum, Base, Hyperliquid, Solana, etc.) and all major protocol types (Lending, Staking, LP/DEX, Yield Farming).
  • Deep Pool Breakdown (PoolDetail.js): In-depth pool analytics, 30-day mean APY tracking, base vs. reward emission separation, and impermanent loss risk indicators.
  • Funding Harvest Module (/hype-harvest.html / /?module=hype-harvest): Delta-neutral cash-and-carry funding harvest calculator for Hyperliquid perps with live basis spread tracking and dual-oracle divergence tripwires.

๐Ÿ›ก๏ธ Trust Rails (The Core Moat)

Every metric rendered across DeFi Garden derives from live on-chain and API data through strict, non-negotiable trust rails:

  1. APY_SANITY_LIMIT = 1000%: Anomalous, short-lived spikes can never enter a plan. In analytics, anomalous pools are demoted, flagged with โš , and forced to high-risk classification.
  2. DEFAULT_MIN_TVL = $100K: Low-liquidity pools below the safety floor are filtered out to protect savers from illiquid exits and sudden deprecations.
  3. Dual-Oracle Divergence Guard: Modules verify mark vs. oracle price divergence ($<15\text{ bps}$ tripwire) to alert on basis dislocation and squeeze risk.
  4. Deterministic Math Layer: LLMs may narrate or explain mechanisms, but numbers, projections, and compounded yields are calculated deterministically.

๐ŸŽจ Design System โ€” "Quiet"

DeFi Garden uses the "Quiet" design system โ€” a restrained, clean-minimal, table-first interface designed for clarity and focus:

  • Surface Tokens (--ui-*):
    • Backgrounds: --ui-bg (#F7F8FA light / #161A20 dark), --ui-surface (#FFFFFF / #1E242C), --ui-surface-muted, --ui-surface-sunken.
    • Separation: Single-pixel hairline borders (--ui-border: #E4E7EE, --ui-border-strong: #CBD2DF).
    • Text: High-contrast hierarchy (--ui-text: #10151F, --ui-text-secondary: #5A6478, --ui-text-muted: #8A93A6).
    • Accents: Fixed trust-blue palette (--ui-accent: #3B82F6, --ui-accent-hover: #2563EB, --ui-accent-soft: #EFF5FF).
    • Radii: Clean geometric squircles (--ui-radius-sm: 8px, --ui-radius-md: 12px, --ui-radius-lg: 16px, --ui-radius-pill: 999px).
  • No Heavy Shadows or Skeuomorphic Skeins: Depth is created through crisp hairline borders and subtle surface tone steps, not artificial dual-direction shadows or background gradients.
  • Physical Press Physics: Interactive controls sink 1px on :active (transform: translateY(1px)), respecting prefers-reduced-motion.
  • First-Class Bilingual Support (translations.js): Complete English (en) and Korean (ko) localization synchronized across all user-facing strings.

๐Ÿ› ๏ธ Architecture & Technology Stack

  • Zero Build Step: Runs natively on vanilla web standards. React 18 UMD loaded via script tag; components written in pure React.createElement (no JSX compilation step required).
  • Data Ingestion: Client-side integration with https://yields.llama.fi/pools and Hyperliquid Info API (https://api.hyperliquid.xyz/info).
  • State Management:
    • Theme: localStorage.getItem('theme') with data-theme="light|dark" attribute on <html>.
    • Language: URL param ?lang= + localStorage.getItem('defi-garden-lang').
    • Saved Plan: localStorage.getItem('garden-plan').
  • SEO & Machine Readability:
    • Automated dynamic sitemaps (generate-sitemap.js).
    • AI Context endpoints: llms.txt and llms-full.txt (generate-llms.js).
    • Model Context Protocol (MCP) server integration (mcp_server.js).

๐Ÿ“ Repository Structure

defi_garden/
โ”œโ”€โ”€ home.html                   # Master router & analytics app shell
โ”œโ”€โ”€ plan.html                   # Standalone Garden Planner entry
โ”œโ”€โ”€ hype-harvest.html           # HYPE Funding Harvest module
โ”œโ”€โ”€ planner.js                  # Conversational Garden Planner engine
โ”œโ”€โ”€ app.js                      # Core analytics grid & pool filtering
โ”œโ”€โ”€ PoolDetail.js               # In-depth pool analytics & calculator
โ”œโ”€โ”€ hype-harvest.js             # HYPE funding harvest React UMD module
โ”œโ”€โ”€ translations.js             # Bilingual dictionary (EN + KO)
โ”œโ”€โ”€ translations.min.js         # Production-minified translation dictionary
โ”œโ”€โ”€ style.css                   # "Quiet" design system tokens & base styles
โ”œโ”€โ”€ planner-styles.css          # Planner-specific layout styles
โ”œโ”€โ”€ pool-detail-styles.css      # Pool detail drawer styles
โ”œโ”€โ”€ hype-harvest.css            # Funding harvest layout styles
โ”œโ”€โ”€ trust-rails.js              # Shared trust-rail constants
โ”œโ”€โ”€ canonical.js                # URL canonicalization logic
โ”œโ”€โ”€ keeper/                     # Autonomous execution & risk keeper scripts
โ”‚   โ”œโ”€โ”€ keeper_engine.py        # Core risk keeper engine
โ”‚   โ””โ”€โ”€ hype_funding_harvest.py # Hyperliquid HYPE funding rate worker
โ”œโ”€โ”€ tests/                      # Python unit & integration test suite
โ”‚   โ”œโ”€โ”€ test_keeper_engine.py
โ”‚   โ””โ”€โ”€ test_keeper_hype_harvest.py
โ””โ”€โ”€ test_*.js                   # JavaScript offline test suite (71+ test files)

๐Ÿงช Development & Testing

DeFi Garden requires no build pipeline. Serve locally with any static HTTP server:

# Start local server
python3 -m http.server 8000
# Open in browser: http://localhost:8000

Running Tests

# Run all unit tests in fast plain mode
npm run test:fast

# Run the complete test suite (plain + browser)
npm test

# Minify production assets
npm run minify

๐Ÿ“œ License

MIT License. See LICENSE for details.

Reviews

No reviews yet

Be the first to review this server!