What a bot must never be able to do
A bot needs to place, change and cancel orders. It does not need to withdraw, to send funds elsewhere or to raise its own limits, and the safest bot is one that cannot.
- Withdraw or send. Hyperliquid refuses the agent key every withdrawal and every send.
- Raise its limits. A wider local policy waits for your password, and only your phone signs the mandate.
- Open for real on its own. A real opening by the pilot or a copy needs a mandate that allows it.
- Hide what it did. Every order, its quote and the limits that judged it go to a journal on your computer.
Three ways to automate it
A script
Every command answers in JSON with --json, and every refusal carries a stable code and what to do next. A script adds --yes to an order once you agreed to what it does.
lpa perps quote --symbol BTC --side long --size 0.001 --leverage 2 --jsonAn AI assistant
Through the MCP server, Claude Code, Cursor or Codex read markets, quote and place orders under the same limits. A real order needs a quote you saw.
The daily pilot
Once a day it gathers a dossier, asks a model for one decision and lets the code judge it, on paper by default.
Copy a trader
lpa copy start mirrors a trader's orders on paper, or on the real account under a mandate that names that trader, with its own copy budget. Your own account is never copied, and a reduction the guardian could not place is kept and tried again.
Limits that hold
The local policy bounds each order: the largest order, the leverage, the markets. The mandate adds the orders and the notional per day and a daily loss stop. A refusal names the limit that stopped the order, with its figures.
What it cannot protect you from
A bot can still lose money: a bad strategy, a thin market, a model that misreads a day. Positions by steps carry no stop by default. Start on paper, and keep an account for the bot alone.