Methodology
Where the numbers come from
Every figure on this site is one of four kinds, and each page says which. When a read fails, the page says so instead of showing a stale or guessed value.
Last updated 2 October 2026
Read from the chain at request time: blocks, gas, balances, v4 pools, hook bytecode.
Bounds and shares enforced by the Rule Craft contracts (unaudited): module bounds, royalty cap, protocol share. Gas figures are estimates.
Blueprints the team wrote to illustrate rule sets. No pools, no authors on chain.
Anything that needs the Rule Craft contracts before the owner deploys them: launches, swaps on Rule Craft pools, royalties, the token supply.
Chain reads
The server reads Robinhood Chain (chain 4663) over JSON-RPC: a private endpoint when the operator configures one, otherwise the public RPC, then a second public endpoint. An endpoint that fails sits out for a minute. The browser never talks to the RPC directly; it goes through a read-only relay on this site that only accepts read methods.
The pool list
Pools come from Initialize events of the Uniswap v4 PoolManager at 0x8366a39CC670B4001A1121B8F6A443A643e40951, over roughly the last 300,000 blocks. Each event gives the two currencies, the fee, the tick spacing and the hook address. Token symbols are read with symbol(); a token that does not answer is shown by its address. Successful reads are kept for two minutes; failed reads are never cached.
Hook permissions
A v4 hook's permissions are the lowest 14 bits of its address. The scanner reads those bits; it does not need the source and cannot be fooled by a name. What the bits cannot tell you is how the callbacks behave, whether parameters can change, or who controls upgrades. The scanner says so on every report.
The risk grade
The grade measures how far a rule set can move a trade or an LP away from a plain v4 pool. It is not a judgement of intent and not an audit. For a composed rule set it adds up six factors (the code lives in src/lib/compose.ts):
| Factor | Max | How |
|---|---|---|
| Hook permissions | 35 | Sum of callback weights the rule set enables, against the sum of all 14. Delta and remove-liquidity callbacks weigh most. |
| Steady take per buy | 25 | Worst-case share of a buy taken by fees and rules after any opening window, above the plain fee, scaled to 10%. |
| Opening window | 15 | Guard tax during the Snipe Guard window, scaled to 50%. |
| Fee movement | 10 | Distance between the dynamic fee floor and ceiling, scaled to 3 points. |
| LP exits | 10 | Whether any liquidity is time-locked. |
| Unreleased code | 5 | Whether a planned module is part of the set. |
Scores map to grades: 0–20 A (light), 21–40 B, 41–60 C, 61–80 D, above 80 E (extreme). For a hook we did not compose, only its bits and the pool fee are known, so the scanner weighs permissions, delta rights, withdrawal access, dynamic fees and the fact that the code is unknown.
Fail-closed displays
- A failed chain read shows “Read failed” or “--”, never zero dressed as data.
- APIs return HTTP 503 rather than an empty list when the chain cannot be reached.
- Buttons that would write to contracts that are not deployed are disabled and say “Not deployed yet”.
Questions about a number? Read the docs or ask on X.