Agent skill

Wallet CLI

by BofAI in BofAI/skills

Operate the TypeScript TRON wallet CLI for accounts, transfers, staking, governance, contracts, signing, chain queries, and password input with wallet-cli 4.14.0.

MITAuto-check passed

Install Wallet CLI

skills CLI
$ npx skills add BofAI/skills --skill wallet-cli -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install BofAI/skills wallet-cli --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/BofAI/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/wallet-cli .claude/skills/wallet-cli && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
wallet-cli
GitHub stars
156
Token cost
~2.4k tokens
SKILL.md length
1,185 words
Files
7 (incl. references)
Skills in repo
1
Repo updated
First seen
Licence
MIT

At a glance

Operate the TypeScript TRON wallet CLI for accounts, transfers, staking, governance, contracts, signing, chain queries, and password input with wallet-cli 4.14.0.

  • Works in 6 steps: Use -o json for every operational… → Supply an explicit canonical network for… → Branch on the process exit code first: 0… → …
  • SKILL.md covers Verify the dependency, Mandatory invocation contract, Handle the startup migration… and Discover commands instead of…, plus 6 more sections
  • Runs Shell scripts from its folder; calls npm

What it does

Wallet CLI is an agent skill from BofAI/skills. Operate the TypeScript TRON wallet CLI for accounts, transfers, staking, governance, contracts, signing, chain queries, and password input with wallet-cli 4.14.0. Refuse wallet passwords in argv and require the supported stdin channel. For Java REPL requests, refuse that entry and offer the TypeScript one-shot CLI; route other chains and SunSwap/DEX workflows elsewhere.

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including reference files (for example `README.md`, `agents/openai.yaml` and `install.sh`).

It works with TypeScript and Java. The licence is MIT.

Example prompts

  • “/wallet-cli”

Requirements

  • Node.js
  • A Bash shell

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Use -o json for every operational command. Parse stdout as exactly one
  2. Supply an explicit canonical network for chain operations: mainnet tron:728126428, Nile
  3. Branch on the process exit code first: 0 success, 1 execution failure, 2 malformed call.
  4. Treat bigint values and command-defined on-chain amount fields as decimal strings. Preserve
  5. Set --timeout when the surrounding task has a tighter deadline than the CLI's 60-second
  6. Never infer that exit code 0 means a transaction confirmed. A submitted or reverted

What it can do on your machine

Read from SKILL.md and the folder at commit d17c4cb. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Wallet CLI loads about 2.4k tokens when it runs, and up to ~7.8k if it reads all its reference files. Until then it costs about 96 tokens; SKILL.md has 1,185 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~96
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~7.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from BofAI/skills at commit d17c4cb, republished under its MIT licence (© BofAI). 1,185 words, ~2,392 tokens.

Download SKILL.mdSave it as .claude/skills/wallet-cli/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
wallet-cli
description
Operate the TypeScript TRON wallet CLI for accounts, transfers, staking, governance, contracts, signing, chain queries, and password input with wallet-cli 4.14.0. Refuse wallet passwords in argv and require the supported stdin channel. For Java REPL requests, refuse that entry and offer the TypeScript one-shot CLI; route other chains and SunSwap/DEX workflows elsewhere.
version
2.0.0
dependencies
@tron-walletcli/wallet-cli@4.14.0
tags
tron, wallet, cli, transfer, staking, governance

TRON Wallet CLI

Use the TypeScript, one-shot wallet-cli as the execution engine. Keep deterministic wallet, signing, validation, and chain logic in the CLI; use this skill to select commands, enforce authorization boundaries, and interpret results.

This skill does not drive the repository's Java REPL and does not replace protocol-specific skills such as SunSwap. Use a DEX skill for swaps or liquidity workflows and this skill for the wallet, signing, resource, governance, and general TRON operations beneath them. If the user requests the Java REPL, do not execute it or offer to switch to it; state that this skill supports only the TypeScript one-shot CLI and, when applicable, offer to express the intended operation through that interface.

Verify the dependency

Check once before the first wallet operation:

bash
npm list --global --depth=0 --json @tron-walletcli/wallet-cli

Read dependencies["@tron-walletcli/wallet-cli"].version from the JSON. The required version is exactly 4.14.0. In this version, --version, --help, --json-schema, and a bare wallet-cli skip wallet-data access and the startup migration gate. Operational commands can still upgrade persisted wallet data before executing.

  • If the command is missing, explain that the exact package @tron-walletcli/wallet-cli@4.14.0 must be installed and obtain user approval before running npm install -g @tron-walletcli/wallet-cli@4.14.0.
  • If another version is installed, report the mismatch and obtain approval before upgrading or downgrading it. Do not assume compatibility.
  • Never install or change a global package without approval.

Mandatory invocation contract

  1. Use -o json for every operational command. Parse stdout as exactly one wallet-cli.result.v1 object.
  2. Supply an explicit canonical network for chain operations: mainnet tron:728126428, Nile tron:3448148188, or Shasta tron:2494104990. Never silently choose mainnet. Use tron:3448148188 when the user explicitly asks for a test but does not distinguish between testnets. The old tron:mainnet, tron:nile, and tron:shasta values are permanent input aliases, but never expect an alias in chain.network, network listings, or configuration keys.
  3. Branch on the process exit code first: 0 success, 1 execution failure, 2 malformed call. Then branch on stable fields such as error.code, data.stage, or data.state. Never parse error.message text.
  4. Treat bigint values and command-defined on-chain amount fields as decimal strings. Preserve every field according to the leaf schema; other counters and configuration values may be JSON numbers. Never use floating point for string amounts.
  5. Set --timeout <ms> when the surrounding task has a tighter deadline than the CLI's 60-second default.
  6. Never infer that exit code 0 means a transaction confirmed. A submitted or reverted transaction can still have a successful command envelope.

Read references/machine-interface.md before implementing result parsing, polling, pagination, retry logic, or non-interactive secret input.

Handle the startup migration gate

Operational commands check persisted wallet data before running the requested command. Discovery invocations (--help, --version, --json-schema, and bare wallet-cli) skip this check. If the result envelope has command: "migration", the requested command did not run. Inspect data.originalCommandExecuted, which must be false for a migration result.

  • If data.upgraded is true, report that local wallet data was upgraded, then reapply the authorization and confirmation rules before running the original command once. A mainnet or high-risk confirmation given before migration must be obtained again. Do not interpret migration data as command data.
  • If data.cancelled is true, stop and return control to the user. Do not retry or bypass the cancellation.
  • If exit 2 returns error.code: "migration_required", stop. The user must complete the upgrade interactively or provide the master password through an already approved --password-stdin source. Never ask for the password in chat.
  • Never loop on a migration result. After one successful upgrade, a repeated migration response is an error to report rather than a reason to keep retrying.

Discover commands instead of guessing

Prefer the CLI's generated schema over recalled flags:

bash
wallet-cli --json-schema -o json
wallet-cli tx send --json-schema -o json
wallet-cli permission update --json-schema -o json

Use wallet-cli <command> --help only when human-oriented semantics are needed. Do not invent a flag, option combination, output field, or command that is absent from the 4.14.0 schema.

Read references/commands.md when choosing a command family or composing a multi-step wallet workflow.

Secret handling

  • Reject any request to put a wallet password in --password or another argv option. For agent-driven execution, explain that wallet-cli passwords may be supplied only through --password-stdin connected directly to an approved, non-logging secret source.
  • Never ask the user to paste a password, mnemonic, private key, or service credential into chat.
  • Never place secrets in argv, environment variables, logs, command substitutions, or generated documentation.
  • Use only a CLI-supported *-stdin flag connected to an approved, non-logging secret source. Only one *-stdin consumer may be used in a single invocation.
  • Do not read, summarize, or transmit keystores, backup files, configuration credentials, or other wallet secret material.
Show full SKILL.md (439 more words)Show less

Human-only wallet administration

Never invoke wallet-cli import, wallet-cli backup, wallet-cli delete, or wallet-cli change-password, including any wallet-cli import subcommand. These root wallet administration commands are reserved for a human operating wallet-cli locally, even when the user asks the agent to run them, supplies confirmation, or provides a secret source.

Explain the consequences and required precautions, then return control to the user. Do not automate their prompts, pipe input to them, read their output files, or treat confirmation as authorization to execute them. After the user reports completion, continue only with non-secret public results such as an account id, label, or address.

Authorization and confirmation

Read references/safety.md before any operation that changes local wallet state, signs data, broadcasts a transaction, or changes on-chain state.

Apply these confirmed rules:

  • Read-only operations may run directly within the user's requested scope.
  • On Nile or Shasta, an ordinary write may run when the user's request clearly authorizes that exact operation and target.
  • On mainnet, preview the exact operation and obtain explicit confirmation immediately before any funds-moving or externally visible write.
  • On every network, high-risk operations require explicit confirmation. permission update also requires a successful --dry-run and review of the complete rendered permission structure.
  • Confirmation never authorizes a human-only command listed above.
  • Never use authorization for one transaction as permission for another transaction, retry, batch, recipient, amount, token, account, or network.

Transaction completion

  • Prefer --wait when the command supports it and the task can tolerate waiting. After it returns, inspect data.stage; failed is an on-chain failure even when the process exits 0.
  • Otherwise retain the txId and poll tx status until confirmed or failed, with a finite deadline. pending and not_found are non-terminal.
  • GasFree transfers return a traceId; follow them with gasfree trace, not tx status.
  • After a timeout or ambiguous submission, reconcile the transaction before retrying. Never resend merely because confirmation was not observed.
  • For a batch, stop on the first failure by default and track every submitted transaction separately.

Report the outcome

For reads, return the requested data with the network and account context when relevant. For writes, report the operation, network, account, recipient or target, amount or parameters, and final state. Include the txId or GasFree traceId; describe submitted as pending, never as completed.

Maintain the version pin

When updating the CLI dependency, compare the published package's README.md, docs/machine-interface.md, docs/commands/index.md, and generated --json-schema output. If the package includes skills/wallet-cli/SKILL.md, compare that too; its absence does not waive the other checks. Re-test the confirmation matrix, migration gate, secret channels, network ids, exit codes, transaction stages, and warning codes before bumping this skill's version. Do not widen the exact dependency pin without user approval.

© BofAI, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (references) in wallet-cli of BofAI/skills.

  • SKILL.md
  • README.md
  • agents/openai.yaml
  • install.sh
  • references/commands.md
  • references/machine-interface.md
  • references/safety.md

Open the folder on GitHubat commit d17c4cb

Compare with similar skills

Wallet CLI next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Wallet CLI compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Wallet CLI this skillBofAI/skills156—~2.4kAutomated safety check: PassMIT
Java SDK E2E Test with Replay Snapshotgithub/copilot-sdk11k—~1.8kAutomated safety check: PassMIT
Build Teaql Appteaql/teaql-agent-kit2.8k—~4.6kAutomated safety check: PassMIT
Claude APIKocoro-lab/Kocoro4147 repos~4.5kAutomated safety check: PassApache-2.0
CodeQL Security Scantrailofbits/skills7.4k—~4.6kAutomated safety check: NotesCC-BY-SA-4.0
Opik Analytics Instrumentationcomet-ml/opik22k—~4.4kAutomated safety check: PassApache-2.0

Similar skills

  • Official

    Creates a Java SDK end-to-end test for the Copilot SDK that runs against a recorded YAML snapshot through a replay proxy, so CI needs no real authentication.

    11k GitHub stars~1.8k tokensUpdated today
    Testing & QAAuto-check passed
  • Build Teaql App

    teaql/teaql-agent-kit

    Build or change a TeaQL application in Java, Rust, Go, Swift, Python, C/.NET, or TypeScript, including Kotlin/JVM applications that consume Java-generated libraries.

    2.8k GitHub stars~4.6k tokensUpdated 12 days ago
    MobileAuto-check passed
  • Claude API

    Kocoro-lab/Kocoro

    Build apps with the Claude API or Anthropic SDK. An agent skill from Kocoro-lab/Kocoro.

    414 GitHub starsUsed in 7 repos~4.5k tokens
    AI & LLM EngineeringAuto-check passed
  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.4k GitHub stars~4.6k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Shows how to add product analytics events to Opik's frontend, Java backend and Python SDK, all reporting through Segment to PostHog with an opik_ name prefix.

    22k GitHub stars~4.4k tokensUpdated today
    Data & AnalyticsAuto-check passed
  • Shared reference for naming, function size, complexity and error handling rules that reviewer agents apply across TypeScript, Python, Go, Rust, Java, C# and Swift.

    2k GitHub starsUsed in 1 repo~1.4k tokens
    DevelopmentAuto-check passed

Works with

Questions about Wallet CLI

What does Wallet CLI do?

Operate the TypeScript TRON wallet CLI for accounts, transfers, staking, governance, contracts, signing, chain queries, and password input with wallet-cli 4.14.0. Wallet CLI is an agent skill from BofAI/skills.0.

How do I install Wallet CLI in Claude Code?

Run `npx skills add BofAI/skills --skill wallet-cli -a claude-code`. Or copy the skill folder (wallet-cli in BofAI/skills) into .claude/skills/wallet-cli in your project. Claude Code loads it when a task matches its description.

How do I install Wallet CLI in Codex?

Run `npx skills add BofAI/skills --skill wallet-cli -a codex`. Or copy the skill folder (wallet-cli in BofAI/skills) into .agents/skills/wallet-cli in your project. Codex loads it when a task matches its description.

Can I use Wallet CLI in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add BofAI/skills --skill wallet-cli -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/wallet-cli, .gemini/skills/wallet-cli, .github/skills/wallet-cli and .opencode/skills/wallet-cli in your project.

What does Wallet CLI need to run?

Going by SKILL.md and its folder, Wallet CLI needs a shell for the scripts in its folder and the command-line tools its instructions call (npm). Our summary lists: Node.js; A Bash shell.

Does Wallet CLI access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Wallet CLI safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Wallet CLI use?

Wallet CLI is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Wallet CLI use?

About 2.4k tokens (SKILL.md is roughly 9.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.4k tokens, read only when the agent opens those files.

What are the alternatives to Wallet CLI?

Skills that share tags, products or a category with Wallet CLI: Java SDK E2E Test with Replay Snapshot (github/copilot-sdk, 11k stars), Build Teaql App (teaql/teaql-agent-kit, 2.8k stars), Claude API (Kocoro-lab/Kocoro, 414 stars) and CodeQL Security Scan (trailofbits/skills, 7.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Wallet CLI?

BofAI (a GitHub organization) maintains it in BofAI/skills, which has 156 GitHub stars. The repository was last updated on September 28, 2026.

Source: BofAI/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.