Binance Token Audit
TermiX-official/cryptoclaw
Binance Web3 official skill — security audit for token contracts, detecting honeypots, rug pulls, and malicious functions across BSC, Base, Solana, and Ethereum.
Give the AI agent its own EVM wallet with admin-controlled policies the agent CANNOT bypass even under prompt injection.
$ npx skills add internet-court/internet-court-skill --skill agent-wallet -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install internet-court/internet-court-skill agent-wallet --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/internet-court/internet-court-skill.git skills-src && mkdir -p .claude/skills && cp -r skills-src/vendored/chaingpt/agent-wallet .claude/skills/agent-wallet && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "agent-wallet" agent skill from https://github.com/internet-court/internet-court-skill/tree/main/vendored/chaingpt/agent-wallet into .claude/skills/agent-wallet/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "agent-wallet", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/internet-court/internet-court-skill/tree/main/vendored/chaingpt/agent-walletType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add internet-court/internet-court-skill --skill agent-wallet -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install internet-court/internet-court-skill agent-wallet --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/internet-court/internet-court-skill.git skills-src && mkdir -p .agents/skills && cp -r skills-src/vendored/chaingpt/agent-wallet .agents/skills/agent-wallet && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "agent-wallet" agent skill from https://github.com/internet-court/internet-court-skill/tree/main/vendored/chaingpt/agent-wallet into .agents/skills/agent-wallet/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "agent-wallet", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add internet-court/internet-court-skill --skill agent-wallet -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install internet-court/internet-court-skill agent-wallet --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/internet-court/internet-court-skill.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/vendored/chaingpt/agent-wallet .cursor/skills/agent-wallet && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "agent-wallet" agent skill from https://github.com/internet-court/internet-court-skill/tree/main/vendored/chaingpt/agent-wallet into .cursor/skills/agent-wallet/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "agent-wallet", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/internet-court/internet-court-skill.git --path vendored/chaingpt/agent-wallet--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add internet-court/internet-court-skill --skill agent-wallet -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install internet-court/internet-court-skill agent-wallet --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/internet-court/internet-court-skill.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/vendored/chaingpt/agent-wallet .gemini/skills/agent-wallet && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "agent-wallet" agent skill from https://github.com/internet-court/internet-court-skill/tree/main/vendored/chaingpt/agent-wallet into .gemini/skills/agent-wallet/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "agent-wallet", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install internet-court/internet-court-skill agent-walletInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add internet-court/internet-court-skill --skill agent-wallet -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/internet-court/internet-court-skill.git skills-src && mkdir -p .github/skills && cp -r skills-src/vendored/chaingpt/agent-wallet .github/skills/agent-wallet && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "agent-wallet" agent skill from https://github.com/internet-court/internet-court-skill/tree/main/vendored/chaingpt/agent-wallet into .github/skills/agent-wallet/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "agent-wallet", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add internet-court/internet-court-skill --skill agent-wallet -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install internet-court/internet-court-skill agent-wallet --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/internet-court/internet-court-skill.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/vendored/chaingpt/agent-wallet .opencode/skills/agent-wallet && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "agent-wallet" agent skill from https://github.com/internet-court/internet-court-skill/tree/main/vendored/chaingpt/agent-wallet into .opencode/skills/agent-wallet/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "agent-wallet", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
agent-walletGive the AI agent its own EVM wallet with admin-controlled policies the agent CANNOT bypass even under prompt injection.
Agent Wallet is an agent skill from internet-court/internet-court-skill. Give the AI agent its own EVM wallet with admin-controlled policies the agent CANNOT bypass even under prompt injection. Encrypted keystore (AES-256-GCM, scrypt KDF), policy file the agent has no tool to write, deterministic policy gate on every signing operation, optional local HTTP dashboard. Triggers: agent wallet, give the agent a wallet, agent address, fund the agent, agent autonomy, policy gate, kill switch, agent permissions, bounded autonomy, ERC-4337 alternative, session-key alternative.
Its SKILL.md is about 4.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file.
It sits in Security, covering Smart contracts and Prompt injection and agent security. The repository describes itself as: The trust layer for agent-to-agent commerce — natural-language mandates, ERC-7710 delegated permissions, x402 payments, escrow, and dispute resolution as one open, catch-all… The licence is MIT.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit fa89195. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
claudeFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Agent Wallet loads about 4.1k tokens when it runs. Until then it costs about 129 tokens; SKILL.md has 1,843 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from internet-court/internet-court-skill at commit fa89195, republished under its MIT licence (© internet-court). 1,843 words, ~4,088 tokens.
.claude/skills/agent-wallet/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.The agent has its own EOA wallet on every EVM chain it supports. The admin (you, in your shell) sets policies that the agent cannot violate or revoke — even if a malicious prompt convinces the LLM to try.
The attacker's goal: prompt-inject the agent to drain its wallet to an attacker address.
The plugin's defense: the policy check is in code, not in the LLM's prompt. Every chaingpt_agent_wallet_sign_and_send call:
checkPolicy(intent) — pure deterministic code that doesn't see the LLM's context.The attacker can convince the LLM to call sign_and_send(to=attacker, value=ALL) — but the tool layer refuses because attacker isn't in allowedToAddresses or value exceeds maxTxValueWei or killSwitch=true. The trust boundary is the tool code, not the LLM.
There is no MCP tool that writes the policy file. The admin edits it directly with a text editor. There is no MCP tool that reads or sets the passphrase. The passphrase lives only in the shell env var or the OS keychain — never in the keystore file, never in the LLM's context.
The keystore passphrase resolves in this priority order:
CHAINGPT_AGENT_WALLET_PASSPHRASE env var — explicit override. Best for CI / headless / power users who want zero process-list and zero keychain exposure.security) or Linux (libsecret via secret-tool), if no env var is set, chaingpt_agent_wallet_init generates a strong 256-bit passphrase and stores it in the keychain. You never type or remember it; the MCP server reads it back on each load.# Just init — a strong passphrase is generated + stored in your OS keychain.
claude
> initialize the agent walletThe init output tells you it used the keychain and how to export the passphrase for backup.
# Set a strong passphrase BEFORE starting the MCP server (>= 16 chars)
export CHAINGPT_AGENT_WALLET_PASSPHRASE="your-strong-passphrase-here-min-16-chars"
claude
> initialize the agent walletBack up the passphrase either way. Keychain entry:
service=chaingpt-mcp-agent-wallet account=keystore-passphrase. Export on macOS withsecurity find-generic-password -s chaingpt-mcp-agent-wallet -a keystore-passphrase -w. Lose it (and any backup) → the keystore is unrecoverable. There is no recovery path.
Security tradeoff of the keychain option: the secret stays out of plaintext-on-disk and out of the LLM context, but the keychain is unlocked while you're logged in — a local attacker on an unlocked session could read it. That's a much higher bar than a plaintext file and appropriate for a low-value bounded hot wallet. For zero local exposure, use Option B.
This creates two files:
| File | Contents | Who edits it |
|---|---|---|
~/.chaingpt-mcp/agent-wallet/keystore.json | AES-256-GCM encrypted private key | Generated once by the init tool. Never edit by hand. Back it up. |
~/.chaingpt-mcp/agent-wallet/policy.json | Plain JSON rules | You, the admin, with a text editor. The agent has NO tool that writes this file. |
Both default to ~/.chaingpt-mcp/agent-wallet/ but can be overridden via CHAINGPT_KEYSTORE_FILE and CHAINGPT_AGENT_POLICY_FILE.
| Tool | Mutates state? | Notes |
|---|---|---|
chaingpt_agent_wallet_init | Creates keystore | One-shot. Refuses if file exists. |
chaingpt_agent_wallet_address | No | Returns the agent's EOA address. Use this to receive funds. |
chaingpt_agent_wallet_status | No | Address + policy digest + kill-switch state. Run this before any signing. |
chaingpt_agent_wallet_balances | No | Native-coin balances across requested chains. |
chaingpt_agent_wallet_policy | No (read-only) | Shows the current policy JSON. Cannot modify it. |
chaingpt_agent_wallet_sign_and_send | Signs + broadcasts a tx | The only tool that can move funds. Gated by policy. |
chaingpt_agent_wallet_serve_ui | Starts a local HTTP server | Dashboard on http://127.0.0.1:8787. Read-only view. |
Default policy.json (lazily created on first read) is the Balanced DeFi policy: killSwitch: false, major DEX/lending routers allow-listed, 0.1 native per-tx cap, 0.3 native + 20 txs per rolling 24h (maxDailySpendWei / maxDailyTxCount), memo required. A corrupt or partially-missing policy file always falls back to fail-closed (killSwitch: true) — tampering can never open the gates. Apply the "Locked down" template (or set killSwitch: true) for a refuse-everything posture.
Example production policy (allow DEX rebalancing on Base, capped at 0.1 ETH/tx, audit memo required):
{
"version": 1,
"killSwitch": false,
"allowedChains": [8453],
"allowedToAddresses": [
"0x6352a56caadc4f1e25cd6c75970fa768a3304e64",
"0x111111125421ca6dc452d289314280a0f8842a65"
],
"blockedToAddresses": [
"0x0000000000000000000000000000000000000000"
],
"maxTxValueWei": "100000000000000000",
"maxTxGas": "500000",
"blockedSelectors": [],
"requireMemo": true,
"notes": "Base only, OpenOcean + 1inch routers only, 0.1 ETH cap, memo required for audit",
"updatedAt": "2026-05-18T20:00:00Z"
}| Field | Type | Behavior when unset | Behavior when set |
|---|---|---|---|
killSwitch | bool | refuses everything (fail-closed) | true refuses everything; false proceeds to other checks |
allowedChains | int[] | any chain allowed | refuses if chainId not in list |
allowedToAddresses | string[] | any address allowed | refuses if to not in list (case-insensitive) |
blockedToAddresses | string[] | nothing blocked | refuses if to matches (case-insensitive) |
maxTxValueWei | string | no cap | refuses if native value > max |
maxTxGas | string | no cap | refuses if gasLimit > max; an explicit gasLimit becomes REQUIRED (auto-estimation would bypass the cap) |
maxDailySpendWei | string | no velocity cap | refuses if 24h ledger spend + this tx value would exceed the cap (fail-closed if the ledger is unreadable) |
maxDailyTxCount | int | no velocity cap | refuses once the rolling-24h signed-tx count reaches the cap |
blockedSelectors | string[] | nothing blocked | refuses if first 4 bytes of data match (e.g. 0xa9059cbb blocks ERC-20 transfer) |
requireMemo | bool | no memo required | refuses if the memo arg is missing |
Precedence: kill switch > blockedToAddresses > allowedToAddresses > value caps > gas cap > daily velocity caps > blockedSelectors > memo. Any single failure refuses the tx.
The same bounded-autonomy model on Solana. Separate Ed25519 keystore (solana-keystore.json, same cipher + same admin passphrase), gated by the solana policy sub-object that — like everything else here — no MCP tool can write.
chaingpt_agent_wallet_solana_init # one-time keystore
chaingpt_agent_wallet_solana_address # fund this (the balance is the outermost cap)
<any builder: jupiter swap / marginfi / kamino / transfer> → unsigned VersionedTransaction (base64)
chaingpt_agent_wallet_solana_sign_and_send txBase64=<…> memo=<…>Policy block (admin-only, dashboard or text editor):
"solana": {
"enabled": true,
"allowedPrograms": ["11111111111111111111111111111111", "JUP6LkbZbjS1jKKwapdHNy74zcZ3tLUZoi5QNyVTaV4"],
"maxTxLamports": "100000000",
"maxDailySpendLamports": "300000000",
"maxDailyTxCount": 20,
"requireMemo": true
}Hard facts to relay accurately:
solana.enabled: true refuses every Solana signing op. unrestricted does not bypass it.maxTxLamports + the 24h window. Simulation unavailable or failing ⇒ refusal, never a blind broadcast.The endgame: the user's ERC-7579 smart account grants the agent's EOA a SCOPED on-chain session (Smart Sessions module). The caps live in audited contracts and are validated by the EntryPoint. Status: BETA — the module addresses are verified deployed on Base Sepolia and the encoders are unit-tested, but the end-to-end live proof is not yet published. Treat the on-chain column below as the DESIGNED guarantee, not yet an independently-demonstrated one; the local gate is your tested fence today.
| Threat | Local policy gate (tested) | On-chain session caps (designed, beta) |
|---|---|---|
| Prompt injection | ✅ blocks | ✅ designed to block |
| Policy file tampered/rewritten | ❌ falls | ✅ designed to block |
| Full host compromise (keystore stolen) | ❌ falls | ✅ designed to block, bounded by remaining allowance + expiry (live proof pending) |
chaingpt_aa_session_build_grant chain=base account=<user SCW> tokenCaps=[{token: USDC, cap: "100000000"}] validUntil=<unix>
→ OWNER signs the userOpHash externally → chaingpt_aa_submit_userop
chaingpt_aa_session_status # chain-authoritative: enabled? remaining?
chaingpt_agent_wallet_4337_sign_and_send … # the agent acts; local gates AND chain caps both apply
chaingpt_aa_session_build_revoke … # incident response: chain-level killHard facts: erc4337.enabled policy opt-in is fail-closed and OFF by default everywhere (this surface acts on a third-party account). Unbounded grants are refused at build time. A bundler rejection of an over-cap op is the product working — never retry around it. v1 supports Biconomy Nexus 1.x accounts.
1. chaingpt_agent_wallet_status # see address + policy digest + kill switch state
2. chaingpt_agent_wallet_balances # confirm funded on the target chain
3. chaingpt_agent_wallet_policy # read the active rules in full
4. chaingpt_agent_wallet_sign_and_send chain=… to=… valueWei=… data=… memo="…"If the call gets refused with a policy reason: do not try to work around it from the agent side. Surface the reason to the admin and let them edit the policy file (or override) themselves.
> Use chaingpt_agent_wallet_serve_uiReturns a http://127.0.0.1:8787 URL and a one-time admin token printed in the tool output (also saved to ~/.chaingpt-mcp/agent-wallet/.admin-token, 0600). The token rotates on every restart.
Open the URL in your browser. Paste the admin token at the login screen. The dashboard then shows:
.bak backupRecall the threat model: the attacker controls the LLM via prompt injection. The defenses, in layers:
savePolicy function — it's only imported by the localhost HTTP server.Origin on form submits..bak. A botched save can't corrupt the policy file mid-write, and the previous version is recoverable.127.0.0.1 only. Never on 0.0.0.0 — the dashboard is not reachable from other machines on the network.The single failure mode that would bypass all of this: malware running on the admin's machine that can read the admin token file AND make HTTP requests to localhost. At that point the attacker has shell access and can read the keystore directly; the policy file is no longer the weakest link.
| Method | Path | Behavior |
|---|---|---|
GET / | login form (if unauthed) or redirect to /dashboard | — |
POST /login | check admin token, set session cookie, redirect to /dashboard | requires Origin |
GET /dashboard | full admin UI (auth required) | — |
GET /api/policy | current policy JSON | requires session |
POST /api/policy | save new policy after validation | requires session + Origin |
POST /api/killswitch | toggle the kill switch (set=on/off) | requires session + Origin |
GET /api/status | JSON with address + balances + policy digest | requires session |
GET /logout | clear session cookie, redirect to login | — |
CHAINGPT_AGENT_WALLET_PASSPHRASE → the keystore is unrecoverable. There is no recovery path. Back up the passphrase out-of-band (1Password, hardware safe, etc.).chaingpt_agent_wallet_addresschaingpt_agent_wallet_balances chains=[base,arbitrum]The agent is now ready to operate within its policy bounds.
All agent-wallet tools cost 0 ChainGPT credits. The wallet is custody-on-the-user's-machine (not custody-via-ChainGPT). The credit funnel comes from upstream tools the user/agent calls (chaingpt_research_token, chaingpt_risk_token, chaingpt_intel_token) before deciding to deploy.
~/.chaingpt-mcp/agent-wallet/{keystore.json,policy.json} (override via env).© internet-court, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in vendored/chaingpt/agent-wallet of internet-court/internet-court-skill.
Open the folder on GitHubat commit fa89195
We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in internet-court/internet-court-skill, which our catalogue first saw on October 7, 2026.
Agent Wallet next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Agent Wallet this skillinternet-court/internet-court-skill | 6.6k | 1 repos | ~4.1k | Automated safety check: Pass | MIT | |
| Binance Token AuditTermiX-official/cryptoclaw | 100 | — | ~695 | Automated safety check: Pass | MIT | |
| Slowmist Agent Securityslowmist/slowmist-agent-security | 508 | — | ~1.4k | Automated safety check: Pass | MIT | |
| Agent Security Hardeningaffaan-m/ECC | 276k | — | ~2.7k | Automated safety check: Pass | MIT | |
| Safety Scanruvnet/ruflo | 74k | — | ~409 | Automated safety check: Notes | MIT | |
| Fork AncestryPlamenTSV/plamen | 303 | — | ~2.4k | Automated safety check: Pass | MIT |
TermiX-official/cryptoclaw
Binance Web3 official skill — security audit for token contracts, detecting honeypots, rug pulls, and malicious functions across BSC, Base, Solana, and Ethereum.
slowmist/slowmist-agent-security
Comprehensive security review framework for AI agents. An agent skill from slowmist/slowmist-agent-security.
affaan-m/ECC
Security hardening guidance for AI agent frameworks that process untrusted content, invoke tools, write workspace files, manage runtime identifiers, or handle credentials.
ruvnet/ruflo
Scan inputs for prompt injection, unsafe content, and adversarial attacks using AIDefence.
PlamenTSV/plamen
Trigger Pattern Always (run during recon TASK 0, not breadth) - Inject Into Recon agent only (metabuffer.md enrichment)
getsentry/skills
Scan agent skills for security issues. An agent skill from getsentry/skills.
internet-court/internet-court-skill
Uploads one Kleros-related file per paid request to IPFS through the Kleros x402 gateway for 0.01 USDC on Base, returning a CID that Kleros contracts can reference.
internet-court/internet-court-skill
Guides building on the 0G Compute Network, a decentralized GPU marketplace for AI inference and fine-tuning, with SDK patterns and CLI commands.
internet-court/internet-court-skill
Creates, trades and settles permissionless prediction markets on Solana with any SPL token as collateral, including social-media and custom-oracle markets.
internet-court/internet-court-skill
Connects an agent to the BNB Chain MCP server to read blocks and contracts, move tokens and NFTs, register ERC-8004 agents and use Greenfield storage.
internet-court/internet-court-skill
Specifies how a GenLayer Intelligent Contract decision about an agent's performance becomes an ERC-7710 revocation or policy change, through a relayer or bridge and an EVM controller.
internet-court/internet-court-skill
Specifies how a GenLayer Intelligent Contract should supervise an AI agent, with review rubrics, evidence schemas and continue, warn, constrain or revoke decisions.
Categories
Give the AI agent its own EVM wallet with admin-controlled policies the agent CANNOT bypass even under prompt injection. Agent Wallet is an agent skill from internet-court/internet-court-skill. Give the AI agent its own EVM wallet with admin-controlled policies the agent CANNOT bypass even under prompt injection.
Agent Wallet fits situations like: tasks that involve Smart contracts; tasks that involve Prompt injection and agent security.
Run `npx skills add internet-court/internet-court-skill --skill agent-wallet -a claude-code`. Or copy the skill folder (vendored/chaingpt/agent-wallet in internet-court/internet-court-skill) into .claude/skills/agent-wallet in your project. Claude Code loads it when a task matches its description.
Run `npx skills add internet-court/internet-court-skill --skill agent-wallet -a codex`. Or copy the skill folder (vendored/chaingpt/agent-wallet in internet-court/internet-court-skill) into .agents/skills/agent-wallet in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add internet-court/internet-court-skill --skill agent-wallet -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/agent-wallet, .gemini/skills/agent-wallet, .github/skills/agent-wallet and .opencode/skills/agent-wallet in your project.
Going by SKILL.md and its folder, Agent Wallet needs the command-line tools its instructions call (claude).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Agent Wallet is published under the MIT licence (from the LICENSE file in the skill folder). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.1k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Agent Wallet: Binance Token Audit (TermiX-official/cryptoclaw, 100 stars), Slowmist Agent Security (slowmist/slowmist-agent-security, 508 stars), Agent Security Hardening (affaan-m/ECC, 276k stars) and Safety Scan (ruvnet/ruflo, 74k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
internet-court (a GitHub organization) maintains it in internet-court/internet-court-skill, which has 6,551 GitHub stars. The repository holds 80 skills in this directory. The repository was last updated on August 19, 2026.
Source: internet-court/internet-court-skill on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.