agentic-wallet
Crypto wallet operations via the awal CLI — sign in, check balances, send USDC/ETH/POL/SOL, trade tokens, fund the wallet, and use the x402 payment …
它会碰到什么
逐条看命中(1 条严重或高危)
- 严重
SKILL.md:5perm-wildcardallowed-tools: ["Bash(npx awal@2.12.1 *)", "Bash(npm *)", "Bash(node *)", "Bash(curl *)", "Bash(mkdir *)"]
这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。
技能内容
Agentic Wallet
Operate a crypto wallet through the awal CLI. This skill is a router: read the relevant reference file in references/ for the task at hand.
Preflight: Confirm wallet state
Before any wallet operation that requires authentication (everything except x402 search/details), check status:
npx awal@2.12.1 status
If the wallet is not authenticated, read references/auth.md and complete sign-in first.
Routing
Pick the reference that matches the task and Read it before acting:
| Task | Reference |
| --- | --- |
| Sign in, log in, connect wallet, OTP verification, "not signed in" errors | references/auth.md |
| Check balances, "how much USDC/ETH/POL/SOL do I have", balance per chain, JSON balance output | references/balance.md |
| Send USDC / ETH / POL / SOL to an address or ENS name (Base, Polygon, Solana) | references/send-usdc.md |
| Swap / trade / convert tokens on Base or Polygon | references/trade.md |
| Add funds, top up, onramp, buy USDC | references/fund.md |
| Find / browse / search paid services on the x402 bazaar | references/x402-search.md |
| Call a paid x402 API endpoint with automatic USDC payment | references/x402-pay.md |
| Build or deploy a paid API server that other agents can pay to use | references/x402-monetize.md |
| Query onchain data on Base (events, transactions, blocks) via the CDP SQL API | references/query-onchain.md |
If no clear match and the user wants an external capability, search the x402 bazaar (references/x402-search.md) — a paid service may exist.
Shared rules
- Input validation: every reference lists the regexes / allowlists that user-provided values must match before being placed in a shell command. Validate strictly; reject inputs containing spaces, semicolons, pipes, backticks, or other shell metacharacters. Do not pass unvalidated user input into commands.
- Single-quote
$amounts: any amount written as'$1.00'must be single-quoted to prevent bash variable expansion. - JSON output: every
awalcommand supports--jsonfor machine-readable output. - Auth errors mean re-auth: if any command fails with "Not authenticated" or similar, read
references/auth.mdand run the sign-in flow. - Insufficient balance: read
references/fund.mdto top up.
Quick command index
| Command | Purpose |
| --- | --- |
| npx awal@2.12.1 status | Server health + auth status |
| npx awal@2.12.1 address | Get wallet address |
| npx awal@2.12.1 balance | Get balances across Base, Polygon, Solana (use --chain for one chain) |
| npx awal@2.12.1 show | Open the wallet companion window (used for funding) |
| npx awal@2.12.1 auth login <email> | Send OTP code |
| npx awal@2.12.1 auth verify <otp> | Complete sign-in |
| npx awal@2.12.1 auth logout | Sign out and clear the session |
| npx awal@2.12.1 send <amount> <recipient> | Send tokens |
| npx awal@2.12.1 trade <amount> <from> <to> | Swap tokens |
| npx awal@2.12.1 x402 bazaar search <query> | Search paid services |
| npx awal@2.12.1 x402 bazaar list | List bazaar resources |
| npx awal@2.12.1 x402 details <url> | Inspect payment requirements |
| npx awal@2.12.1 x402 pay <url> | Pay and call an x402 endpoint |
想直接用这个技能?
本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。
它属于哪个仓库
vendored/coinbase/agentic-wallet/SKILL.md