牛 NIULAI AGENT v0.2
BNB CHAIN / BINANCE AGENT OS / MCP
X / @NIULAIAGENTBSC AGENT OS LAYER
AUTONOMOUS COW AGENT / BNB CHAIN / AGENT OS READY

NiuLai Agent

An autonomous Cow Agent built around 牛来, with bounded execution, verifiable missions and an integration path into Binance Agent OS for standardized market, account and trading tools.

BINANCE AGENT OS MCP LAYER BNB CHAIN BOUND AUTONOMY ERC-8004 READY
//

The AI decides what work should be done. The protocol decides what the AI is allowed to do. The blockchain records what actually happened.

NiuLai cybernetic cow agent
ROLE COORDINATOR
RUNTIME AGENT OS READY
CHAIN BSC / 56
CONTROL POLICY GATED
01WORK
→
02EARN
→
03ACCUMULATE
→
04DEPLOY
↻
02 / DESIGN PRINCIPLES

Autonomy without blind trust.

NiuLai is not an LLM with a private key. The intelligence layer can propose actions, but deterministic controls sit between model output and money.

01

Intent, not calldata

The model emits semantic missions such as ACCUMULATE_NIULAI. A deterministic compiler resolves routes, contracts, amounts and deadlines.

02

Bounded capital

Each Cow operates under explicit spend limits, asset allowlists, protocol permissions, reserve floors and time windows.

03

Verifiable output

Financial claims come from transaction receipts, contract events, indexed wallet state and reproducible accounting — not AI narration.

03 / SYSTEM ARCHITECTURE

Three layers. Three kinds of truth.

Reasoning remains flexible. Control stays deterministic. Settlement stays onchain.

L1
INTELLIGENCE LAYEROFFCHAIN
ObserverPlannerResearchCoordinatorCow Agents
AI TRUTH → what the agent wants to do and why.
↓ structured intent
L2
CONTROL LAYERDETERMINISTIC
Mission CompilerPolicy EngineRisk EngineSimulatorSigner
PROTOCOL TRUTH → what the agent is permitted to do.
↓ authorized execution
L3
SETTLEMENT LAYERBNB SMART CHAIN
CowRegistryTreasuryVaultPolicyExecutorRevenueRouterAdapters
BLOCKCHAIN TRUTH → what actually happened.
▾ protocol/ proposed monorepo
├── contracts/ onchain settlement + permissions
├── agent-runtime/ planner, tools, workers
├── mission-service/ compiler + state machine
├── risk-engine/ quotes, limits, simulation
├── agent-os-bridge/ MCP client + Binance capability adapter
├── indexer/ BSC events → normalized data
├── accounting/ revenue, cost basis, NAV
└── web/ protocol terminal + docs
04 / BINANCE AGENT OS

A financial tool layer for the Cow.

NiuLai keeps its reasoning and protocol policy independent, then connects approved capabilities through a dedicated Agent OS adapter. Binance Agent OS provides a standardized access layer for market data, account information, payments, wallet/onchain tooling and supported trading workflows.

BINANCE AGENT OS ↗
NIULAIPlanner + Missionsdecides intent
→
LOCAL CONTROLPolicy + Riskapproves scope
→
MCP ADAPTERBinance Agent OSstandardized tools
→
FINANCIAL RAILSData / Account / Tradepermission bound
01

Market intelligence

Use Agent OS tools as a normalized source for market data instead of letting the model scrape or invent state.

02

Account context

Read balances, portfolio state and transaction history from an authorized account context when the configured permission allows it.

03

Supported execution

Approved missions may route supported trading activity through the Agent OS MCP layer. NiuLai policy remains the first gate.

04

Permission isolation

Use user-controlled permissions and a dedicated subaccount boundary so an agent does not inherit unrestricted main-account authority.

● agent-os.config

transportMCP / Streamable HTTP

endpointagent.binance.com/mcp/agentic

componentsBinance APIs · Wallet Agentic Hub · x402 · Skill Hub · MCP

credential modelauthorized connection / revocable permissions

niulai modeADAPTER TARGET — credentials not embedded in static build

Architecture rule: Agent OS extends the Cow's tool surface; it does not replace NiuLai's Mission Engine, risk limits or treasury controls. The model still proposes intent. The local protocol still decides whether that intent is allowed.
05 / MISSION ENGINE

Every action starts as a Mission.

The LLM never sends arbitrary calldata. It produces a typed intent. The protocol turns that intent into an immutable execution plan.

mission-intent.json
{
  "missionType": "ACCUMULATE_NIULAI",
  "agentId": 17,
  "requestedAmountUsd": 250,
  "priority": "NORMAL",
  "reasonCodes": [
    "SURPLUS_AVAILABLE",
    "SCHEDULED_ACCUMULATION"
  ]
}
execution-plan.json
{
  "missionId": "0x91...c4",
  "policyVersion": 8,
  "adapter": "PANCAKE_V3",
  "maxSpend": 250000000,
  "minExpectedOutput": "...",
  "validUntil": 1786964400,
  "planHash": "0xa8...12"
}
PROPOSED
→
COMPILED
→
POLICY CHECKED
→
SIMULATED
→
AUTHORIZED
→
SUBMITTED
→
CONFIRMED
Any stage can terminate as REJECTED, SIMULATION_FAILED, REVERTED or EXPIRED.
06 / POLICY ENGINE

The AI cannot negotiate with the rules.

Policy lives outside the prompt. A compromised model still faces deterministic restrictions.

COW_EXECUTOR_V1 ACTIVE POLICY
ALLOWED ASSETSBNB / USDT / 牛来
ALLOWED ACTIONSSWAP / RETURN / CLAIM
MAX TX VALUE$250
24H SPEND CAP$1,000
MAX PRICE IMPACT0.75%
RESERVE FLOOR$20,000
EXTERNAL TRANSFERDENIED
LEVERAGE / BORROWDENIED
AI INTENT→SCHEMA→ALLOWLIST→BUDGET→RISK→SIMULATION→SIGN
07 / TREASURY

Protocol capital is not Cow pocket money.

The main treasury remains isolated. Cow Agents receive limited working capital and scoped authority.

▣
TREASURY VAULTProtocol-owned capital
RESERVERunway + safety floor
OPERATIONSInfrastructure + execution
牛来 HOLDINGSAccumulated protocol position
↓ bounded allocations
COW #001$250 CAP
COW #002$500 CAP
COW #003$100 CAP
Failure domain: compromise of one Cow should expose only that Cow's permitted working capital — never unrestricted protocol treasury access.
08 / ACCUMULATION ENGINE

Accumulate with bounded market impact.

The protocol does not buy because an AI says “bullish.” It allocates a defined portion of realized surplus under reserve, liquidity and execution constraints.

EXECUTION BUDGET
min( surplus × allocationRatio, dailyCap, liquidityCap )
INPUTEXAMPLEROLE
Realized agent revenue$4,000External value earned
Operating expenses$1,000Compute, execution, services
Reserve requirement$500Keep runway intact
Available surplus$2,500Revenue − costs − reserve
Allocation ratio40%Policy parameter
Liquidity cap$350Market impact constraint
Execution budget$350Not $1,000
T+00$125quote → execute
···
T+15$125re-quote → execute
···
T+30$100re-quote → complete

Illustrative execution only. Real sizing is derived from configured policy and live liquidity data.

09 / THE HERD

Specialized agents, shared economic objective.

NiuLai is the coordinator. Child Cows receive distinct capability profiles, wallets, budgets and mission histories.

000

COORDINATOR

Schedules work, creates missions and allocates tasks. No unrestricted execution power.

NIULAI-000
SCT

SCOUT

Reads chain state, liquidity, jobs and protocol data. Primarily read-only.

NIULAI-SCOUT-01
EXE

EXECUTOR

Executes approved financial actions through typed protocol adapters.

NIULAI-EXECUTOR-01
WRK

WORKER

Completes external jobs and routes verified earnings back to the protocol.

NIULAI-WORKER-01
DEPLOY_COW mission gate
MAX HERD SIZE 25 CURRENT COWS 8 TREASURY RUNWAY 180d REQUIRED RUNWAY 90d DEPLOY BUDGET $500 RESULT APPROVED
10 / AGENT RUNTIME

Structured reasoning in. Deterministic execution out.

OBSERVERchain + jobs + treasury
↓
PLANNERstructured decision
↓
MISSION COMPILERtyped executable plan
↓
RISK ENGINEquotes + limits
↓
SIMULATORstate + execution checks
↓
ADAPTER ROUTERonchain / Agent OS MCP
↓
EXECUTION RAILBSC or Binance Agent OS
demo.trace

COORDINATOR created mission #1842

POLICY profile COW_EXECUTOR_V1 loaded

RISK price impact 0.42% / max 0.75%

SIM execution simulation PASS

SIGNER plan hash authorized

CHAIN mission confirmed 0x91…c4

DEMO TRACE · NOT LIVE CHAIN DATA
11 / SECURITY MODEL

Assume the model can be wrong.

The security model does not depend on perfect AI behavior. It is designed so model failure does not automatically become treasury failure.

01No raw treasury key in model runtime

Signing is isolated from LLM and mission processes.

02No arbitrary target execution

Typed actions and adapter allowlists replace generic call().

03Replay protection

Mission ID, nonce, chain ID, time window, policy version and plan hash bind authorization.

04Policy versioning

Changing risk limits invalidates stale outstanding permits.

05Emergency pause

Guardian can stop new risk without gaining unrestricted withdrawal authority.

06Simulation before signing

Every value-moving mission is checked against expected onchain behavior.

12 / DATA + ACCOUNTING

Charts must mean exactly what they say.

No fabricated TVL. No deposit-as-revenue accounting. No “AI performance” percentage without a formula.

TREASURY HOLDINGSbalanceOf(protocol-owned accounts)
SCHEMA PREVIEW
At block N: treasury balance + approved protocol-owned Cow balances. Historical purchases alone are not holdings.
CAPITAL CONTRIBUTION

Funds injected into treasury. Not revenue.

AGENT REVENUE

External consideration earned from verified work.

REALIZED P&L

Closed gains or losses recognized by accounting rules.

UNREALIZED P&L

Mark-to-market movement. Not realized revenue.

13 / CONTRACT SURFACE

Small core. Replaceable adapters.

MODULERESPONSIBILITYUPGRADE STRATEGY
CowRegistryAgent records, parent relationship, policy IDs, stateimmutable V1
TreasuryVaultProtocol assets + bounded capital allocationimmutable V1
PolicyExecutorTyped execution + onchain authorization checksimmutable V1
RevenueRouterVerified revenue routing + accounting eventsimmutable V1
DEX AdaptersVenue-specific execution logicreplaceable
AgentOSAdapterMCP capability bridge for Binance Agent OSreplaceable
Job AdaptersExternal agent commerce / settlement interfacesreplaceable
GET/v1/agents

Herd registry + operational state

GET/v1/missions

Mission state + chain references

GET/v1/treasury

Balances, NAV and reserve state

GET/v1/accounting/revenue

Verified revenue classifications

GET/v1/accumulations

Confirmed 牛来 acquisition events

14 / IMPLEMENTATION ROADMAP

Ship the smallest credible system first.

PHASE 0Protocol specification

Architecture, accounting semantics, mission types, permissions.

PHASE 1NiuLai Runtime + Agent OS Bridge

Coordinator, Mission Engine, Policy Engine, treasury, MCP client and permission-scoped Binance Agent OS adapter.

PHASE 2The Herd

Cow Registry, scoped wallets, deployment gates and specialized workers.

PHASE 3Agent commerce

External work adapters, settlement and verifiable revenue provenance.

PHASE 4Protocol terminal

Live mission log, Agent OS activity, holdings, cost basis, revenue and herd analytics.

NiuLai Agent
THE HERD WORKS FOR 牛来.

Work → Earn → Accumulate → Deploy.

Not a chatbot with a token. An onchain economic actor with explicit permissions, measurable work and verifiable settlement.