Give the AI agent its own EVM wallet with admin-controlled policies the agent CANNOT bypass even under prompt injection.

MITAuto-check passedSecurity

Install Agent Wallet

skills CLI
$ npx skills add internet-court/internet-court-skill --skill agent-wallet -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install internet-court/internet-court-skill agent-wallet --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/internet-court/internet-court-skill.git skills-src && mkdir -p .claude/skills && cp -r skills-src/vendored/chaingpt/agent-wallet .claude/skills/agent-wallet && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
agent-wallet
GitHub stars
6.6k
Used in
1 other repo
Token cost
~4.1k tokens
SKILL.md length
1,843 words
Files
2
Skills in repo
80
Repo updated
First seen
Licence
MIT

At a glance

Give the AI agent its own EVM wallet with admin-controlled policies the agent CANNOT bypass even under prompt injection.

  • Works in 3 steps: Loads the policy file fresh from disk… → Runs checkPolicy(intent) — pure… → Refuses if any rule fails, with a clear…
  • Tasks that involve Smart contracts
  • SKILL.md covers Threat model, Setup (admin steps — done once), Tools and Policy file format, plus 8 more sections
  • Calls claude

What it does

Agent Wallet is an agent skill from internet-court/internet-court-skill. Give the AI agent its own EVM wallet with admin-controlled policies the agent CANNOT bypass even under prompt injection. Encrypted keystore (AES-256-GCM, scrypt KDF), policy file the agent has no tool to write, deterministic policy gate on every signing operation, optional local HTTP dashboard. Triggers: agent wallet, give the agent a wallet, agent address, fund the agent, agent autonomy, policy gate, kill switch, agent permissions, bounded autonomy, ERC-4337 alternative, session-key alternative.

Its SKILL.md is about 4.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file.

It sits in Security, covering Smart contracts and Prompt injection and agent security. The repository describes itself as: The trust layer for agent-to-agent commerce — natural-language mandates, ERC-7710 delegated permissions, x402 payments, escrow, and dispute resolution as one open, catch-all… The licence is MIT.

When your agent uses it

  • Tasks that involve Smart contracts
  • Tasks that involve Prompt injection and agent security

Example prompts

  • “/agent-wallet”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Loads the policy file fresh from disk (no caching — admin can update mid-session).
  2. Runs checkPolicy(intent) — pure deterministic code that doesn't see the LLM's context.
  3. Refuses if any rule fails, with a clear reason the agent surfaces back to the user.

What it can do on your machine

Read from SKILL.md and the folder at commit fa89195. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • claude

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Agent Wallet loads about 4.1k tokens when it runs. Until then it costs about 129 tokens; SKILL.md has 1,843 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~129
When it runs · the whole SKILL.md, loaded when a task matches
~4.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from internet-court/internet-court-skill at commit fa89195, republished under its MIT licence (© internet-court). 1,843 words, ~4,088 tokens.

Download SKILL.mdSave it as .claude/skills/agent-wallet/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
agent-wallet
description
Give the AI agent its own EVM wallet with admin-controlled policies the agent CANNOT bypass even under prompt injection. Encrypted keystore (AES-256-GCM, scrypt KDF), policy file the agent has no tool to write, deterministic policy gate on every signing operation, optional local HTTP dashboard. Triggers: agent wallet, give the agent a wallet, agent address, fund the agent, agent autonomy, policy gate, kill switch, agent permissions, bounded autonomy, ERC-4337 alternative, session-key alternative.

ChainGPT Agent Wallet Skill

The agent has its own EOA wallet on every EVM chain it supports. The admin (you, in your shell) sets policies that the agent cannot violate or revoke — even if a malicious prompt convinces the LLM to try.

Threat model

The attacker's goal: prompt-inject the agent to drain its wallet to an attacker address.

The plugin's defense: the policy check is in code, not in the LLM's prompt. Every chaingpt_agent_wallet_sign_and_send call:

  1. Loads the policy file fresh from disk (no caching — admin can update mid-session).
  2. Runs checkPolicy(intent) — pure deterministic code that doesn't see the LLM's context.
  3. Refuses if any rule fails, with a clear reason the agent surfaces back to the user.

The attacker can convince the LLM to call sign_and_send(to=attacker, value=ALL) — but the tool layer refuses because attacker isn't in allowedToAddresses or value exceeds maxTxValueWei or killSwitch=true. The trust boundary is the tool code, not the LLM.

There is no MCP tool that writes the policy file. The admin edits it directly with a text editor. There is no MCP tool that reads or sets the passphrase. The passphrase lives only in the shell env var or the OS keychain — never in the keystore file, never in the LLM's context.

Setup (admin steps — done once)

The keystore passphrase resolves in this priority order:

  1. CHAINGPT_AGENT_WALLET_PASSPHRASE env var — explicit override. Best for CI / headless / power users who want zero process-list and zero keychain exposure.
  2. OS keychain — auto-managed. On macOS (Keychain via security) or Linux (libsecret via secret-tool), if no env var is set, chaingpt_agent_wallet_init generates a strong 256-bit passphrase and stores it in the keychain. You never type or remember it; the MCP server reads it back on each load.
bash
# Just init — a strong passphrase is generated + stored in your OS keychain.
claude
> initialize the agent wallet

The init output tells you it used the keychain and how to export the passphrase for backup.

Option B — explicit env var (CI / headless / max control)
bash
# Set a strong passphrase BEFORE starting the MCP server (>= 16 chars)
export CHAINGPT_AGENT_WALLET_PASSPHRASE="your-strong-passphrase-here-min-16-chars"
claude
> initialize the agent wallet

Back up the passphrase either way. Keychain entry: service=chaingpt-mcp-agent-wallet account=keystore-passphrase. Export on macOS with security find-generic-password -s chaingpt-mcp-agent-wallet -a keystore-passphrase -w. Lose it (and any backup) → the keystore is unrecoverable. There is no recovery path.

Security tradeoff of the keychain option: the secret stays out of plaintext-on-disk and out of the LLM context, but the keychain is unlocked while you're logged in — a local attacker on an unlocked session could read it. That's a much higher bar than a plaintext file and appropriate for a low-value bounded hot wallet. For zero local exposure, use Option B.

This creates two files:

FileContentsWho edits it
~/.chaingpt-mcp/agent-wallet/keystore.jsonAES-256-GCM encrypted private keyGenerated once by the init tool. Never edit by hand. Back it up.
~/.chaingpt-mcp/agent-wallet/policy.jsonPlain JSON rulesYou, the admin, with a text editor. The agent has NO tool that writes this file.

Both default to ~/.chaingpt-mcp/agent-wallet/ but can be overridden via CHAINGPT_KEYSTORE_FILE and CHAINGPT_AGENT_POLICY_FILE.

Tools

ToolMutates state?Notes
chaingpt_agent_wallet_initCreates keystoreOne-shot. Refuses if file exists.
chaingpt_agent_wallet_addressNoReturns the agent's EOA address. Use this to receive funds.
chaingpt_agent_wallet_statusNoAddress + policy digest + kill-switch state. Run this before any signing.
chaingpt_agent_wallet_balancesNoNative-coin balances across requested chains.
chaingpt_agent_wallet_policyNo (read-only)Shows the current policy JSON. Cannot modify it.
chaingpt_agent_wallet_sign_and_sendSigns + broadcasts a txThe only tool that can move funds. Gated by policy.
chaingpt_agent_wallet_serve_uiStarts a local HTTP serverDashboard on http://127.0.0.1:8787. Read-only view.

Policy file format

Default policy.json (lazily created on first read) is the Balanced DeFi policy: killSwitch: false, major DEX/lending routers allow-listed, 0.1 native per-tx cap, 0.3 native + 20 txs per rolling 24h (maxDailySpendWei / maxDailyTxCount), memo required. A corrupt or partially-missing policy file always falls back to fail-closed (killSwitch: true) — tampering can never open the gates. Apply the "Locked down" template (or set killSwitch: true) for a refuse-everything posture.

Example production policy (allow DEX rebalancing on Base, capped at 0.1 ETH/tx, audit memo required):

json
{
  "version": 1,
  "killSwitch": false,
  "allowedChains": [8453],
  "allowedToAddresses": [
    "0x6352a56caadc4f1e25cd6c75970fa768a3304e64",
    "0x111111125421ca6dc452d289314280a0f8842a65"
  ],
  "blockedToAddresses": [
    "0x0000000000000000000000000000000000000000"
  ],
  "maxTxValueWei": "100000000000000000",
  "maxTxGas": "500000",
  "blockedSelectors": [],
  "requireMemo": true,
  "notes": "Base only, OpenOcean + 1inch routers only, 0.1 ETH cap, memo required for audit",
  "updatedAt": "2026-05-18T20:00:00Z"
}
Field reference
FieldTypeBehavior when unsetBehavior when set
killSwitchboolrefuses everything (fail-closed)true refuses everything; false proceeds to other checks
allowedChainsint[]any chain allowedrefuses if chainId not in list
allowedToAddressesstring[]any address allowedrefuses if to not in list (case-insensitive)
blockedToAddressesstring[]nothing blockedrefuses if to matches (case-insensitive)
maxTxValueWeistringno caprefuses if native value > max
maxTxGasstringno caprefuses if gasLimit > max; an explicit gasLimit becomes REQUIRED (auto-estimation would bypass the cap)
maxDailySpendWeistringno velocity caprefuses if 24h ledger spend + this tx value would exceed the cap (fail-closed if the ledger is unreadable)
maxDailyTxCountintno velocity caprefuses once the rolling-24h signed-tx count reaches the cap
blockedSelectorsstring[]nothing blockedrefuses if first 4 bytes of data match (e.g. 0xa9059cbb blocks ERC-20 transfer)
requireMemoboolno memo requiredrefuses if the memo arg is missing

Precedence: kill switch > blockedToAddresses > allowedToAddresses > value caps > gas cap > daily velocity caps > blockedSelectors > memo. Any single failure refuses the tx.

Solana wallet (v1.19+)

The same bounded-autonomy model on Solana. Separate Ed25519 keystore (solana-keystore.json, same cipher + same admin passphrase), gated by the solana policy sub-object that — like everything else here — no MCP tool can write.

text
chaingpt_agent_wallet_solana_init           # one-time keystore
chaingpt_agent_wallet_solana_address        # fund this (the balance is the outermost cap)
<any builder: jupiter swap / marginfi / kamino / transfer>  → unsigned VersionedTransaction (base64)
chaingpt_agent_wallet_solana_sign_and_send txBase64=<…> memo=<…>

Policy block (admin-only, dashboard or text editor):

json
"solana": {
  "enabled": true,
  "allowedPrograms": ["11111111111111111111111111111111", "JUP6LkbZbjS1jKKwapdHNy74zcZ3tLUZoi5QNyVTaV4"],
  "maxTxLamports": "100000000",
  "maxDailySpendLamports": "300000000",
  "maxDailyTxCount": 20,
  "requireMemo": true
}

Hard facts to relay accurately:

  • Fail-closed migration: a policy file without solana.enabled: true refuses every Solana signing op. unrestricted does not bypass it.
  • Spend is simulation-priced: the tool simulates first and meters the fee-payer lamport delta against maxTxLamports + the 24h window. Simulation unavailable or failing ⇒ refusal, never a blind broadcast.
  • The program allowlist fences which protocols the agent may ENTER (top-level instructions). Inner CPIs are invisible to it — the lamport caps + tx count are the actual spend fence. SPL-token outflows don't move fee-payer lamports, so they are fenced by the allowlist and tx count, not the lamport cap.
  • The agent must be the sole signer and fee payer — co-signing or fee-sponsoring someone else's tx is refused structurally.

On-chain caps — ERC-4337 session keys (v1.21+)

The endgame: the user's ERC-7579 smart account grants the agent's EOA a SCOPED on-chain session (Smart Sessions module). The caps live in audited contracts and are validated by the EntryPoint. Status: BETA — the module addresses are verified deployed on Base Sepolia and the encoders are unit-tested, but the end-to-end live proof is not yet published. Treat the on-chain column below as the DESIGNED guarantee, not yet an independently-demonstrated one; the local gate is your tested fence today.

ThreatLocal policy gate (tested)On-chain session caps (designed, beta)
Prompt injection✅ blocks✅ designed to block
Policy file tampered/rewritten❌ falls✅ designed to block
Full host compromise (keystore stolen)❌ falls✅ designed to block, bounded by remaining allowance + expiry (live proof pending)
text
chaingpt_aa_session_build_grant chain=base account=<user SCW> tokenCaps=[{token: USDC, cap: "100000000"}] validUntil=<unix>
  → OWNER signs the userOpHash externally → chaingpt_aa_submit_userop
chaingpt_aa_session_status                    # chain-authoritative: enabled? remaining?
chaingpt_agent_wallet_4337_sign_and_send …    # the agent acts; local gates AND chain caps both apply
chaingpt_aa_session_build_revoke …            # incident response: chain-level kill

Hard facts: erc4337.enabled policy opt-in is fail-closed and OFF by default everywhere (this surface acts on a third-party account). Unbounded grants are refused at build time. A bundler rejection of an over-cap op is the product working — never retry around it. v1 supports Biconomy Nexus 1.x accounts.

Show full SKILL.md (704 more words)Show less

Pre-flight checklist

text
1. chaingpt_agent_wallet_status   # see address + policy digest + kill switch state
2. chaingpt_agent_wallet_balances # confirm funded on the target chain
3. chaingpt_agent_wallet_policy   # read the active rules in full
4. chaingpt_agent_wallet_sign_and_send chain=… to=… valueWei=… data=… memo="…"

If the call gets refused with a policy reason: do not try to work around it from the agent side. Surface the reason to the admin and let them edit the policy file (or override) themselves.

Local admin dashboard

text
> Use chaingpt_agent_wallet_serve_ui

Returns a http://127.0.0.1:8787 URL and a one-time admin token printed in the tool output (also saved to ~/.chaingpt-mcp/agent-wallet/.admin-token, 0600). The token rotates on every restart.

Open the URL in your browser. Paste the admin token at the login screen. The dashboard then shows:

  • Deposit address with QR code
  • Multi-chain native-coin balances (refresh page to update)
  • One-click kill switch — engage or disable, single button
  • Policy JSON editor — full inline editor, validated server-side, atomic write with .bak backup
  • Keystore + policy file paths for reference
Why this is safe even though the dashboard CAN edit the policy

Recall the threat model: the attacker controls the LLM via prompt injection. The defenses, in layers:

  1. No MCP tool exposes a write to the policy file. The LLM literally cannot reach the savePolicy function — it's only imported by the localhost HTTP server.
  2. The localhost HTTP server has no client inside the agent. The plugin has no MCP tool that does arbitrary HTTP POSTs to localhost. The LLM cannot trigger the dashboard's POST endpoints even by trying.
  3. Admin auth required. Even if a future tool somehow gained HTTP access, every POST endpoint requires a valid session cookie that's only set after the admin pastes the token. The token rotates every restart and lives only in admin-controlled state (env / file with 0600 perms).
  4. Origin + Referer check. Cross-origin POSTs (CSRF) are rejected. Browsers always set Origin on form submits.
  5. Strict schema validation. Even with a valid session, the policy editor rejects unknown fields, bad chain IDs, malformed addresses, non-integer wei values, etc. Garbage cannot make it onto disk.
  6. Atomic write + .bak. A botched save can't corrupt the policy file mid-write, and the previous version is recoverable.
  7. Bound to 127.0.0.1 only. Never on 0.0.0.0 — the dashboard is not reachable from other machines on the network.

The single failure mode that would bypass all of this: malware running on the admin's machine that can read the admin token file AND make HTTP requests to localhost. At that point the attacker has shell access and can read the keystore directly; the policy file is no longer the weakest link.

Dashboard endpoints
MethodPathBehavior
GET /login form (if unauthed) or redirect to /dashboard—
POST /logincheck admin token, set session cookie, redirect to /dashboardrequires Origin
GET /dashboardfull admin UI (auth required)—
GET /api/policycurrent policy JSONrequires session
POST /api/policysave new policy after validationrequires session + Origin
POST /api/killswitchtoggle the kill switch (set=on/off)requires session + Origin
GET /api/statusJSON with address + balances + policy digestrequires session
GET /logoutclear session cookie, redirect to login—

What this skill does NOT do

  • Solana / non-EVM signing. The agent wallet is EVM-only. Solana program-instruction signing is a separate path not yet wired.
  • Multi-sig. This is a single EOA. For larger sums use a Safe / Gnosis multi-sig and have the agent's EOA be one signer; the policy still applies to the agent's signing.
  • Session keys / ERC-4337. Bounded smart-account autonomy is a different model (smart account holds funds, agent gets a revocable session key). This skill is the simpler EOA + policy-file approach; ERC-4337 is a future feature.
  • Recover lost passphrases. Lose CHAINGPT_AGENT_WALLET_PASSPHRASE → the keystore is unrecoverable. There is no recovery path. Back up the passphrase out-of-band (1Password, hardware safe, etc.).
  • Read or change the policy from the agent's tools. Deliberately. Edit the file with your text editor.

Funding the agent

  1. Get the address: chaingpt_agent_wallet_address
  2. Send funds from any wallet (CEX withdrawal, MetaMask, hardware wallet, etc.) to that address on any chain the policy allows.
  3. Confirm: chaingpt_agent_wallet_balances chains=[base,arbitrum]

The agent is now ready to operate within its policy bounds.

Credit accounting

All agent-wallet tools cost 0 ChainGPT credits. The wallet is custody-on-the-user's-machine (not custody-via-ChainGPT). The credit funnel comes from upstream tools the user/agent calls (chaingpt_research_token, chaingpt_risk_token, chaingpt_intel_token) before deciding to deploy.

Reference

  • Keystore format: AES-256-GCM with scrypt (N=2^14) KDF. File version 1.
  • Default paths: ~/.chaingpt-mcp/agent-wallet/{keystore.json,policy.json} (override via env).
  • File perms: 0600 for keystore, 0700 for parent dir (POSIX).

© internet-court, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in vendored/chaingpt/agent-wallet of internet-court/internet-court-skill.

  • SKILL.md
  • LICENSE

Open the folder on GitHubat commit fa89195

Used in 1 other repository

We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in internet-court/internet-court-skill, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Agent Wallet next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Agent Wallet compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Agent Wallet this skillinternet-court/internet-court-skill6.6k1 repos~4.1kAutomated safety check: PassMIT
Binance Token AuditTermiX-official/cryptoclaw100—~695Automated safety check: PassMIT
Slowmist Agent Securityslowmist/slowmist-agent-security508—~1.4kAutomated safety check: PassMIT
Agent Security Hardeningaffaan-m/ECC276k—~2.7kAutomated safety check: PassMIT
Safety Scanruvnet/ruflo74k—~409Automated safety check: NotesMIT
Fork AncestryPlamenTSV/plamen303—~2.4kAutomated safety check: PassMIT

Similar skills

  • Binance Token Audit

    TermiX-official/cryptoclaw

    Binance Web3 official skill — security audit for token contracts, detecting honeypots, rug pulls, and malicious functions across BSC, Base, Solana, and Ethereum.

    100 GitHub stars~695 tokensUpdated 4 mo ago
    SecurityAuto-check passed
  • Slowmist Agent Security

    slowmist/slowmist-agent-security

    Comprehensive security review framework for AI agents. An agent skill from slowmist/slowmist-agent-security.

    508 GitHub stars~1.4k tokensUpdated 5 mo ago
    SecurityAuto-check passed
  • Security hardening guidance for AI agent frameworks that process untrusted content, invoke tools, write workspace files, manage runtime identifiers, or handle credentials.

    276k GitHub stars~2.7k tokensUpdated yesterday
    SecurityAuto-check passed
  • Safety Scan

    ruvnet/ruflo

    Scan inputs for prompt injection, unsafe content, and adversarial attacks using AIDefence.

    74k GitHub stars~409 tokensUpdated yesterday
    SecurityAuto-check: notes
  • Fork Ancestry

    PlamenTSV/plamen

    Trigger Pattern Always (run during recon TASK 0, not breadth) - Inject Into Recon agent only (metabuffer.md enrichment)

    303 GitHub stars~2.4k tokensUpdated 14 days ago
    SecurityAuto-check passed
  • Skill Scanner

    getsentry/skills

    Official

    Scan agent skills for security issues. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.5k tokens
    SecurityAuto-check: warnings

More from internet-court/internet-court-skill

All 80 skills in this repo
  • Kleros IPFS Upload

    internet-court/internet-court-skill

    Uploads one Kleros-related file per paid request to IPFS through the Kleros x402 gateway for 0.01 USDC on Base, returning a CID that Kleros contracts can reference.

    6.6k GitHub stars~4.9k tokensUpdated 1 mo ago
    Auto-check: notes
  • 0G Compute Network Guide

    internet-court/internet-court-skill

    Guides building on the 0G Compute Network, a decentralized GPU marketplace for AI inference and fine-tuning, with SDK patterns and CLI commands.

    6.6k GitHub starsUsed in 1 repo~1.9k tokens
    Auto-check passed
  • PNP Prediction Markets on Solana

    internet-court/internet-court-skill

    Creates, trades and settles permissionless prediction markets on Solana with any SPL token as collateral, including social-media and custom-oracle markets.

    6.6k GitHub stars~7.5k tokensUpdated 1 mo ago
    Auto-check: notes
  • BNB Chain MCP Server

    internet-court/internet-court-skill

    Connects an agent to the BNB Chain MCP server to read blocks and contracts, move tokens and NFTs, register ERC-8004 agents and use Greenfield storage.

    6.6k GitHub starsUsed in 1 repo~1.7k tokens
    Auto-check passed
  • GenLayer ERC-7710 Connector

    internet-court/internet-court-skill

    Specifies how a GenLayer Intelligent Contract decision about an agent's performance becomes an ERC-7710 revocation or policy change, through a relayer or bridge and an EVM controller.

    6.6k GitHub starsUsed in 1 repo~2.2k tokens
    Auto-check passed
  • GenLayer Agent Supervision Adapter

    internet-court/internet-court-skill

    Specifies how a GenLayer Intelligent Contract should supervise an AI agent, with review rubrics, evidence schemas and continue, warn, constrain or revoke decisions.

    6.6k GitHub starsUsed in 1 repo~1.8k tokens
    Auto-check passed

Questions about Agent Wallet

What does Agent Wallet do?

Give the AI agent its own EVM wallet with admin-controlled policies the agent CANNOT bypass even under prompt injection. Agent Wallet is an agent skill from internet-court/internet-court-skill. Give the AI agent its own EVM wallet with admin-controlled policies the agent CANNOT bypass even under prompt injection.

When should I use Agent Wallet?

Agent Wallet fits situations like: tasks that involve Smart contracts; tasks that involve Prompt injection and agent security.

How do I install Agent Wallet in Claude Code?

Run `npx skills add internet-court/internet-court-skill --skill agent-wallet -a claude-code`. Or copy the skill folder (vendored/chaingpt/agent-wallet in internet-court/internet-court-skill) into .claude/skills/agent-wallet in your project. Claude Code loads it when a task matches its description.

How do I install Agent Wallet in Codex?

Run `npx skills add internet-court/internet-court-skill --skill agent-wallet -a codex`. Or copy the skill folder (vendored/chaingpt/agent-wallet in internet-court/internet-court-skill) into .agents/skills/agent-wallet in your project. Codex loads it when a task matches its description.

Can I use Agent Wallet in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add internet-court/internet-court-skill --skill agent-wallet -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/agent-wallet, .gemini/skills/agent-wallet, .github/skills/agent-wallet and .opencode/skills/agent-wallet in your project.

What does Agent Wallet need to run?

Going by SKILL.md and its folder, Agent Wallet needs the command-line tools its instructions call (claude).

Does Agent Wallet access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Agent Wallet safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Agent Wallet use?

Agent Wallet is published under the MIT licence (from the LICENSE file in the skill folder). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Agent Wallet use?

About 4.1k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Agent Wallet?

Skills that share tags, products or a category with Agent Wallet: Binance Token Audit (TermiX-official/cryptoclaw, 100 stars), Slowmist Agent Security (slowmist/slowmist-agent-security, 508 stars), Agent Security Hardening (affaan-m/ECC, 276k stars) and Safety Scan (ruvnet/ruflo, 74k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Agent Wallet?

internet-court (a GitHub organization) maintains it in internet-court/internet-court-skill, which has 6,551 GitHub stars. The repository holds 80 skills in this directory. The repository was last updated on August 19, 2026.

Source: internet-court/internet-court-skill on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.