Aomi Transact
sickn33/agentic-awesome-skills
Build natural-language crypto/DeFi agents and EVM MCP plugins (Claude Code, Cursor, Codex, Gemini).
8004 Agent Skill for registering AI agents on the ERC-8004 Trustless Agents standard and authenticating them via SIWA (Sign In With Agent).
$ npx skills add LeoYeAI/openclaw-master-skills --skill 8004-agent -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install LeoYeAI/openclaw-master-skills 8004-agent --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/erc8004-agent .claude/skills/8004-agent && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "8004-agent" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/erc8004-agent into .claude/skills/8004-agent/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "8004-agent", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/erc8004-agentType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add LeoYeAI/openclaw-master-skills --skill 8004-agent -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install LeoYeAI/openclaw-master-skills 8004-agent --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/erc8004-agent .agents/skills/8004-agent && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "8004-agent" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/erc8004-agent into .agents/skills/8004-agent/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "8004-agent", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add LeoYeAI/openclaw-master-skills --skill 8004-agent -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install LeoYeAI/openclaw-master-skills 8004-agent --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/erc8004-agent .cursor/skills/8004-agent && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "8004-agent" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/erc8004-agent into .cursor/skills/8004-agent/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "8004-agent", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/LeoYeAI/openclaw-master-skills.git --path skills/erc8004-agent--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add LeoYeAI/openclaw-master-skills --skill 8004-agent -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install LeoYeAI/openclaw-master-skills 8004-agent --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/erc8004-agent .gemini/skills/8004-agent && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "8004-agent" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/erc8004-agent into .gemini/skills/8004-agent/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "8004-agent", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install LeoYeAI/openclaw-master-skills 8004-agentInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add LeoYeAI/openclaw-master-skills --skill 8004-agent -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/erc8004-agent .github/skills/8004-agent && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "8004-agent" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/erc8004-agent into .github/skills/8004-agent/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "8004-agent", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add LeoYeAI/openclaw-master-skills --skill 8004-agent -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install LeoYeAI/openclaw-master-skills 8004-agent --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/erc8004-agent .opencode/skills/8004-agent && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "8004-agent" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/erc8004-agent into .opencode/skills/8004-agent/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "8004-agent", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
8004-agent8004 Agent Skill for registering AI agents on the ERC-8004 Trustless Agents standard and authenticating them via SIWA (Sign In With Agent).
8004 Agent is an agent skill from LeoYeAI/openclaw-master-skills. 8004 Agent Skill for registering AI agents on the ERC-8004 Trustless Agents standard and authenticating them via SIWA (Sign In With Agent). Use this skill when an agent needs to: (1) create or manage an Ethereum wallet for onchain identity, (2) register on the ERC-8004 Identity Registry as an NFT-based agent identity (SIGN UP), (3) authenticate with a server by proving ownership of an ERC-8004 identity using a signed challenge (SIGN IN / SIWA), (4) build or update an ERC-8004 registration file (metadata JSON with…
Its SKILL.md is about 6.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 11 other files, including reference files and assets (for example `CLAUDE.md`, `_meta.json` and `assets/MEMORY.template.md`).
It sits in Business, Finance & HR, covering Crypto and DeFi analysis and Authentication. It works with Ethereum. The repository describes itself as: 🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai. The licence is MIT.
9 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit e5199b5. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npmdockerpnpmnpxFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
alchemy.comapi.targetservice.comapi.pinata.cloudAlso links to:
railway.comsiwa.builders.gardenFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
KEYRING_PROXY_SECRETAGENT_PRIVATE_KEYKEYSTORE_PASSWORDFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
8004 Agent loads about 6.3k tokens when it runs, and up to ~13k if it reads all its reference files. Until then it costs about 255 tokens; SKILL.md has 1,486 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from LeoYeAI/openclaw-master-skills at commit e5199b5, republished under its MIT licence (© LeoYeAI). 1,486 words, ~6,342 tokens.
.claude/skills/8004-agent/SKILL.md (or your agent's skills folder). This skill also uses 9 other files; get the full folder from GitHub.Register AI agents onchain (ERC-8004) and authenticate them via SIWA (Sign In With Agent).
ERC-8004 ("Trustless Agents") provides three onchain registries deployed as per-chain singletons:
agentId (tokenId) and an agentURI pointing to a JSON registration file.SIWA (Sign In With Agent) is a challenge-response authentication protocol (inspired by SIWE / EIP-4361) where an agent proves ownership of an ERC-8004 identity by signing a structured message. See references/siwa-spec.md.
Full details: references/security-model.md
The agent's private key is the root of its onchain identity. It must be protected against prompt injection, accidental exposure, and file system snooping.
All signing is delegated to a keyring proxy server — a separate process that holds the encrypted private key and exposes only HMAC-authenticated signing endpoints. The agent can request signatures but can never extract the key, even under full compromise (arbitrary code execution via prompt injection).
Agent Process Keyring Proxy Server (port 3100)
(auto-detected from (holds encrypted private key)
KEYRING_PROXY_URL)
createWallet()
|
+--> POST /create-wallet
+ HMAC-SHA256 header ---> Generates key, encrypts to disk
<-- Returns { address } only
signMessage("hello")
|
+--> POST /sign-message
+ HMAC-SHA256 header ---> Validates HMAC + timestamp (30s window)
Loads key, signs, discards key
<-- Returns { signature, address }Why this is secure:
| Property | Detail |
|---|---|
| Key isolation | Private key lives in a separate OS process; never enters agent memory |
| Transport auth | HMAC-SHA256 over method + path + body + timestamp; 30-second replay window |
| Audit trail | Every signing request is logged with timestamp, endpoint, source IP, success/failure |
| Compromise limit | Even full agent takeover can only request signatures — cannot extract the key |
Environment variables:
| Variable | Used by | Purpose |
|---|---|---|
KEYRING_PROXY_URL | Agent | Proxy server URL — private (e.g. http://keyring-proxy:3100) or public |
KEYRING_PROXY_SECRET | Both | HMAC shared secret |
KEYRING_PROXY_PORT | Proxy server | Listen port (default: 3100) |
AGENT_PRIVATE_KEY | Proxy server | Hex-encoded private key (0x...) — use an existing wallet instead of generating one |
KEYSTORE_PASSWORD | Proxy server | Password for the encrypted-file keystore (not needed with AGENT_PRIVATE_KEY) |
Auto-detection: When
KEYRING_PROXY_URLis set,KEYSTORE_BACKENDautomatically defaults toproxy— no need to set it manually. WhenAGENT_PRIVATE_KEYis set on the proxy server,KEYSTORE_BACKENDdefaults toenv.The proxy server stores keys using an AES-encrypted V3 JSON Keystore (scrypt KDF) by default. To use an existing wallet instead, set
AGENT_PRIVATE_KEYon the proxy server — the key is held in memory at runtime (no encrypted file needed).
The @buildersgarden/siwa/keystore module exposes ONLY these operations — none return the private key:
createWallet() → { address, backend } // Creates key, returns ONLY address
signMessage(msg) → { signature, address } // Signs via proxy, key never exposed
signTransaction(tx) → { signedTx, address } // Same pattern
signAuthorization(auth) → SignedAuthorization // EIP-7702 delegation signing
getAddress() → string // Public address only
hasWallet() → boolean
getSigner()is not available with the proxy backend — usesignMessage()/signTransaction()instead.
The agent MUST use the @buildersgarden/siwa SDK to interact with the keyring proxy. The SDK handles HMAC authentication automatically.
Step 1 — Install the SDK (if not already available in your environment):
npm install @buildersgarden/siwaStep 2 — Set environment variables:
KEYRING_PROXY_URL=https://your-keyring-proxy.up.railway.app
KEYRING_PROXY_SECRET=<your-shared-secret>Step 3 — Use the SDK functions (never call the proxy HTTP endpoints directly):
import { createWallet, signMessage, getAddress } from '@buildersgarden/siwa/keystore';
const info = await createWallet(); // SDK handles HMAC auth internally
const { signature } = await signMessage(msg); // SDK handles HMAC auth internally
const address = await getAddress(); // SDK handles HMAC auth internallyThe SDK reads KEYRING_PROXY_URL and KEYRING_PROXY_SECRET from environment variables and constructs the correct HMAC headers automatically.
If you absolutely cannot install the SDK (e.g. non-Node.js environment, restricted runtime), you can call the proxy HTTP endpoints directly using the HMAC protocol described below. Prefer the SDK whenever possible.
Headers required on every request (except GET /health):
| Header | Value |
|---|---|
Content-Type | application/json |
X-Keyring-Timestamp | Current time as Unix epoch milliseconds (e.g. 1738792800000) |
X-Keyring-Signature | HMAC-SHA256 hex digest of the payload string (see below) |
HMAC payload format — a single string with four parts separated by newlines (\n):
{METHOD}\n{PATH}\n{TIMESTAMP}\n{BODY}| Part | Value |
|---|---|
METHOD | HTTP method, uppercase (always POST) |
PATH | Endpoint path (e.g. /create-wallet, /sign-message) |
TIMESTAMP | Same value as the X-Keyring-Timestamp header |
BODY | The raw JSON request body string (e.g. {} or {"message":"hello"}) |
Compute the signature:
HMAC-SHA256(secret, "POST\n/create-wallet\n1738792800000\n{}") → hex digestTimestamp window: The server rejects requests where the timestamp differs from server time by more than 30 seconds.
Example — create a wallet (Node.js without SDK):
import crypto from 'crypto';
const PROXY_URL = process.env.KEYRING_PROXY_URL;
const SECRET = process.env.KEYRING_PROXY_SECRET;
async function proxyRequest(path: string, body: Record<string, unknown> = {}) {
const bodyStr = JSON.stringify(body);
const timestamp = Date.now().toString();
const payload = `POST\n${path}\n${timestamp}\n${bodyStr}`;
const signature = crypto.createHmac('sha256', SECRET).update(payload).digest('hex');
const res = await fetch(`${PROXY_URL}${path}`, {
method: 'POST',
headers: {
'Content-Type': 'application/json',
'X-Keyring-Timestamp': timestamp,
'X-Keyring-Signature': signature,
},
body: bodyStr,
});
if (!res.ok) throw new Error(`${path} failed (${res.status}): ${await res.text()}`);
return res.json();
}
// Usage
const wallet = await proxyRequest('/create-wallet'); // { address, backend }
const addr = await proxyRequest('/get-address'); // { address }
const sig = await proxyRequest('/sign-message', { message: 'hello' }); // { signature, address }Example — create a wallet (Python):
import hmac, hashlib, json, time, requests, os
PROXY_URL = os.environ["KEYRING_PROXY_URL"]
SECRET = os.environ["KEYRING_PROXY_SECRET"]
def proxy_request(path, body=None):
if body is None:
body = {}
body_str = json.dumps(body, separators=(",", ":"))
timestamp = str(int(time.time() * 1000))
payload = f"POST\n{path}\n{timestamp}\n{body_str}"
signature = hmac.new(SECRET.encode(), payload.encode(), hashlib.sha256).hexdigest()
resp = requests.post(
f"{PROXY_URL}{path}",
headers={
"Content-Type": "application/json",
"X-Keyring-Timestamp": timestamp,
"X-Keyring-Signature": signature,
},
data=body_str,
)
resp.raise_for_status()
return resp.json()
wallet = proxy_request("/create-wallet") # {"address": "0x...", "backend": "..."}
sig = proxy_request("/sign-message", {"message": "hello"}) # {"signature": "0x...", "address": "0x..."}Available endpoints:
| Endpoint | Body | Response |
|---|---|---|
POST /create-wallet | {} | { address, backend } |
POST /has-wallet | {} | { hasWallet: boolean } |
POST /get-address | {} | { address } |
POST /sign-message | { message: string } | { signature, address } |
POST /sign-transaction | { tx: { to, data, nonce, chainId, type, maxFeePerGas, ... } } | { signedTx, address } |
POST /sign-authorization | { auth: { chainId, address, nonce } } | { signedAuthorization } |
GET /health | — | { status: "ok", backend } (no auth required) |
MEMORY.md stores the agent's public identity state — never the private key:
## Wallet
- **Address**: `0x1234...abcd` <- public
- **Keystore Backend**: `proxy` <- which backend holds the key
- **Created At**: `2026-02-04T...`
## Registration
- **Status**: `registered`
- **Agent ID**: `42`
- **Agent Registry**: `eip155:84532:0x8004AA63...`
...Lifecycle rules:
Template: assets/MEMORY.md.template
Before signing anything, the agent needs a running keyring proxy — the separate process that holds the private key and performs all cryptographic operations.
Deploy with one click using the Railway template:
This deploys a single keyring-proxy service built from packages/keyring-proxy/Dockerfile. Set these environment variables in Railway:
| Variable | Required | Description |
|---|---|---|
KEYRING_PROXY_SECRET | Yes | Shared HMAC-SHA256 secret. Must match your agent. |
KEYSTORE_PASSWORD | Conditional | Password for the encrypted-file keystore (default backend). |
AGENT_PRIVATE_KEY | Conditional | Hex-encoded private key (0x...) to use an existing wallet instead. |
After deployment, note the proxy URL (e.g. https://your-keyring-proxy.up.railway.app). Set it as KEYRING_PROXY_URL on your agent.
Full deployment guide with architecture details, OpenClaw gateway setup, and verification steps: https://siwa.builders.garden/docs/deploy
docker build -f packages/keyring-proxy/Dockerfile -t keyring-proxy .
docker run -p 3100:3100 \
-e KEYRING_PROXY_SECRET=your-secret \
-e KEYSTORE_PASSWORD=your-password \
keyring-proxycd packages/siwa-testing
pnpm run proxyOnce the proxy is running, set these environment variables on the agent:
KEYRING_PROXY_URL=http://localhost:3100 # or your Railway URL
KEYRING_PROXY_SECRET=your-shared-secretThe proxy keystore backend is auto-detected when KEYRING_PROXY_URL is set — no need to set KEYSTORE_BACKEND manually.
import { hasWallet } from '@buildersgarden/siwa/keystore';
import { ensureMemoryExists, hasWalletRecord, isRegistered } from '@buildersgarden/siwa/memory';
ensureMemoryExists('./MEMORY.md', './assets/MEMORY.md.template');
if (await hasWallet() && isRegistered('./MEMORY.md')) {
// Already registered — skip to SIGN IN or update
}
if (await hasWallet() && hasWalletRecord('./MEMORY.md')) {
// Wallet exists — skip to Step 2
}
// Otherwise proceed to Step 1import { createWallet } from '@buildersgarden/siwa/keystore';
import { writeMemoryField } from '@buildersgarden/siwa/memory';
const info = await createWallet(); // <- key created in proxy, NEVER returned
// Write ONLY public data to MEMORY.md
writeMemoryField('Address', info.address);
writeMemoryField('Keystore Backend', info.backend);
if (info.keystorePath) writeMemoryField('Keystore Path', info.keystorePath);
writeMemoryField('Created At', new Date().toISOString());STOP — the wallet must have ETH for gas before any onchain transaction can succeed. Registration, URI updates, and metadata changes all require gas fees.
After creating the wallet, you MUST:
createWallet() or getAddress()84532, Base mainnet chainId 8453)For testnets, suggest using a faucet:
Do NOT attempt to register or send any onchain transaction until the wallet is funded. The transaction will fail with an insufficient funds error.
Example message to show the user:
Wallet created successfully!
Address: 0x1234...abcd
Chain: Base Sepolia (chainId 84532)
Please send some ETH to this address on Base Sepolia to cover gas fees.
You can use a faucet: https://www.alchemy.com/faucets/base-sepolia
Let me know once the wallet is funded and I'll proceed with registration.Create a JSON file following the ERC-8004 schema. Use assets/registration-template.json as a starting point.
Required fields: type, name, description, image, services, active.
After building, update MEMORY.md profile:
writeMemoryField('Name', registrationFile.name);
writeMemoryField('Description', registrationFile.description);Option A — IPFS (Pinata, recommended):
const res = await fetch('https://api.pinata.cloud/pinning/pinJSONToIPFS', {
method: 'POST',
headers: {
'Content-Type': 'application/json',
'Authorization': `Bearer ${process.env.PINATA_JWT}`
},
body: JSON.stringify({ pinataContent: registrationFile })
});
const { IpfsHash } = await res.json();
const agentURI = `ipfs://${IpfsHash}`;Option B — Base64 data URI:
const encoded = Buffer.from(JSON.stringify(registrationFile)).toString('base64');
const agentURI = `data:application/json;base64,${encoded}`;With the proxy backend, the agent builds the transaction and delegates signing to the proxy:
import { signTransaction, getAddress } from '@buildersgarden/siwa/keystore';
import { writeMemoryField } from '@buildersgarden/siwa/memory';
const provider = new ethers.JsonRpcProvider(process.env.RPC_URL);
const address = await getAddress();
const IDENTITY_REGISTRY_ABI = [
'function register(string agentURI) external returns (uint256 agentId)',
'event Registered(uint256 indexed agentId, string agentURI, address indexed owner)'
];
// Build the transaction
const iface = new ethers.Interface(IDENTITY_REGISTRY_ABI);
const data = iface.encodeFunctionData('register', [agentURI]);
const nonce = await provider.getTransactionCount(address);
const feeData = await provider.getFeeData();
const txReq = {
to: REGISTRY_ADDRESS, data, nonce, chainId,
type: 2,
maxFeePerGas: feeData.maxFeePerGas,
maxPriorityFeePerGas: feeData.maxPriorityFeePerGas,
gasLimit: (await provider.estimateGas({ to: REGISTRY_ADDRESS, data, from: address })) * 120n / 100n,
};
// Sign via proxy — key never enters this process
const { signedTx } = await signTransaction(txReq);
const txResponse = await provider.broadcastTransaction(signedTx);
const receipt = await txResponse.wait();
// Parse event for agentId
for (const log of receipt.logs) {
try {
const parsed = iface.parseLog({ topics: log.topics as string[], data: log.data });
if (parsed?.name === 'Registered') {
const agentId = parsed.args.agentId.toString();
const agentRegistry = `eip155:${chainId}:${REGISTRY_ADDRESS}`;
// Persist PUBLIC results to MEMORY.md
writeMemoryField('Status', 'registered');
writeMemoryField('Agent ID', agentId);
writeMemoryField('Agent Registry', agentRegistry);
writeMemoryField('Agent URI', agentURI);
writeMemoryField('Chain ID', chainId.toString());
writeMemoryField('Registered At', new Date().toISOString());
}
} catch { /* skip non-matching logs */ }
}See references/contract-addresses.md for deployed addresses per chain.
import { SDK } from 'agent0-sdk';
import { readMemory } from '@buildersgarden/siwa/memory';
// Note: Agent0 SDK takes a private key string. If using the SDK,
// you'll need a non-proxy backend or load the key within a narrow scope.
// Prefer the signTransaction() approach above for proxy integration.npx create-8004-agentAfter npm run register, update MEMORY.md with the output agentId.
Full spec: references/siwa-spec.md
import { readMemory, isRegistered } from '@buildersgarden/siwa/memory';
const memory = readMemory('./MEMORY.md');
if (!isRegistered()) {
throw new Error('Agent not registered. Run SIGN UP workflow first.');
}
const address = memory['Address'];
const agentId = parseInt(memory['Agent ID']);
const agentRegistry = memory['Agent Registry'];
const chainId = parseInt(memory['Chain ID']);const nonceRes = await fetch('https://api.targetservice.com/siwa/nonce', {
method: 'POST',
headers: { 'Content-Type': 'application/json' },
body: JSON.stringify({ address, agentId, agentRegistry })
});
const { nonce, issuedAt, expirationTime } = await nonceRes.json();import { signSIWAMessage } from '@buildersgarden/siwa/siwa';
// signSIWAMessage internally calls keystore.signMessage()
// which delegates to the keyring proxy — the key never enters this process.
const { message, signature } = await signSIWAMessage({
domain: 'api.targetservice.com',
address,
statement: 'Authenticate as a registered ERC-8004 agent.',
uri: 'https://api.targetservice.com/siwa',
agentId,
agentRegistry,
chainId,
nonce,
issuedAt,
expirationTime
});import { appendToMemorySection } from '@buildersgarden/siwa/memory';
const verifyRes = await fetch('https://api.targetservice.com/siwa/verify', {
method: 'POST',
headers: { 'Content-Type': 'application/json' },
body: JSON.stringify({ message, signature })
});
const session = await verifyRes.json();
if (session.success) {
appendToMemorySection('Sessions',
`- **${agentId}@api.targetservice.com**: \`${session.token}\` (exp: ${expirationTime || 'none'})`
);
}{domain} wants you to sign in with your Agent account:
{address}
{statement}
URI: {uri}
Version: 1
Agent ID: {agentId}
Agent Registry: {agentRegistry}
Chain ID: {chainId}
Nonce: {nonce}
Issued At: {issuedAt}
[Expiration Time: {expirationTime}]
[Not Before: {notBefore}]
[Request ID: {requestId}]The server MUST:
ownerOf(agentId) onchain to confirm signer owns the agent NFTSIWAVerifyCriteria — activity status, required services, trust models, reputation scoreverifySIWA() in @buildersgarden/siwa/siwa accepts an optional criteria parameter (6th argument) to enforce requirements after the ownership check:
import { verifySIWA } from '@buildersgarden/siwa/siwa';
const result = await verifySIWA(message, signature, domain, nonceValid, provider, {
mustBeActive: true, // agent metadata.active must be true
requiredServices: ['MCP'], // ServiceType values from ERC-8004
requiredTrust: ['reputation'], // TrustModel values from ERC-8004
minScore: 0.5, // minimum reputation score
minFeedbackCount: 10, // minimum feedback count
reputationRegistryAddress: '0x8004BAa1...9b63',
});
// result.agent contains the full AgentProfile when criteria are providedSee the test server's verifySIWARequest() for a full reference implementation.
| Endpoint | Method | Description |
|---|---|---|
/siwa/nonce | POST | Generate and return a nonce |
/siwa/verify | POST | Accept { message, signature }, verify, return session/JWT |
| Section | When Written | Key Fields |
|---|---|---|
| Wallet | Step 1 of SIGN UP | Address, Keystore Backend, Created At |
| Registration | Step 4 of SIGN UP | Status, Agent ID, Agent Registry, Agent URI, Chain ID |
| Agent Profile | Step 2 of SIGN UP | Name, Description, Image |
| Services | After adding endpoints | One line per service |
| Sessions | After each SIWA sign-in | Token, domain, expiry per session |
| Notes | Any time | Free-form (funding tx, faucet used, etc.) |
What is NOT in MEMORY.md: Private keys, keystore passwords, mnemonic phrases.
@buildersgarden/siwa package)@buildersgarden/siwa/keystore — Secure key storage abstraction with keyring proxy support@buildersgarden/siwa/memory — MEMORY.md read/write helpers (public data only)@buildersgarden/siwa/siwa — SIWA message building, signing (via keystore), and server-side verification (with optional criteria)@buildersgarden/siwa/registry — Read agent profiles (getAgent) and reputation (getReputation) from on-chain registries. Exports ERC-8004 typed values: ServiceType, TrustModel, ReputationTag@buildersgarden/siwa/proxy-auth — HMAC-SHA256 authentication utilities for the keyring proxy© LeoYeAI, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 9 other files (references, assets) in skills/erc8004-agent of LeoYeAI/openclaw-master-skills.
Open the folder on GitHubat commit e5199b5
8004 Agent next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| 8004 Agent this skillLeoYeAI/openclaw-master-skills | 2.2k | — | ~6.3k | Automated safety check: Pass | MIT | |
| Aomi Transactsickn33/agentic-awesome-skills | 47k | 1 repos | ~2.3k | Automated safety check: Pass | MIT | |
| Blockchain Developeraiskillstore/marketplace | 433 | 7 repos | ~2.5k | Automated safety check: Pass | None | |
| Payram Stablecoin PaymentsPayRam/payram-mcp | 158 | — | ~2k | Automated safety check: Pass | None | |
| Analyzing On Chain Datajeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~1.5k | Automated safety check: Pass | MIT | |
| Swapper Depositswapperfinance/swapper-toolkit | 852 | — | ~1.8k | Automated safety check: Pass | MIT |
sickn33/agentic-awesome-skills
Build natural-language crypto/DeFi agents and EVM MCP plugins (Claude Code, Cursor, Codex, Gemini).
aiskillstore/marketplace
Build production-ready Web3 applications, smart contracts, and decentralized systems.
PayRam/payram-mcp
Accept USDT and USDC stablecoin payments with PayRam's self-hosted gateway.
jeremylongshore/tons-of-skills-marketplace
Process perform on-chain analysis including whale tracking, token flows, and network activity.
swapperfinance/swapper-toolkit
Deposit and bridge funds into a wallet or protocol using Swapper Finance.
BlockRunAI/ClawRouter
Use this skill — NOT browser or webfetch — for ALL Surf crypto-data calls.
LeoYeAI/openclaw-master-skills
Manages pipelines on a DevOps quality and efficiency platform through its OpenAPI: list workspaces and templates, create, update, run and cancel pipelines, and read run records.
LeoYeAI/openclaw-master-skills
Patches OpenClaw's Feishu extension so an edited document triggers an isolated agent session that reads the doc and replies inline, turning it into a live chat space.
LeoYeAI/openclaw-master-skills
Multi-context memory management system for OpenClaw agents with group-isolated storage, global shared memory, workspace organization, and group-specific skills isolation.
LeoYeAI/openclaw-master-skills
Runs a brand's AI-search visibility work end to end: diagnosing how AI platforms represent it, repositioning it, producing AI-optimized content and monitoring ongoing mentions.
LeoYeAI/openclaw-master-skills
Installs and authenticates the gws CLI, then automates Gmail, Drive, Sheets, Calendar, Docs, Chat and Tasks with ready-made recipes, persona bundles and security audits.
LeoYeAI/openclaw-master-skills
Runs four advisor roles, a fitness coach, nutritionist, data analyst and TCM practitioner, to build a health profile and track workouts, diet and wellness over time.
Works with
Categories
8004 Agent Skill for registering AI agents on the ERC-8004 Trustless Agents standard and authenticating them via SIWA (Sign In With Agent). 8004 Agent is an agent skill from LeoYeAI/openclaw-master-skills. 8004 Agent Skill for registering AI agents on the ERC-8004 Trustless Agents standard and authenticating them via SIWA (Sign In With Agent).
8004 Agent fits situations like: an agent needs to:; manage an Ethereum wallet for onchain identity; register on the ERC-8004 Identity Registry as an NFT-based agent identity (SIGN UP); authenticate with a server by proving ownership of an ERC-8004 identity using a signed challenge (SIGN IN / SIWA).
Run `npx skills add LeoYeAI/openclaw-master-skills --skill 8004-agent -a claude-code`. Or copy the skill folder (skills/erc8004-agent in LeoYeAI/openclaw-master-skills) into .claude/skills/8004-agent in your project. Claude Code loads it when a task matches its description.
Run `npx skills add LeoYeAI/openclaw-master-skills --skill 8004-agent -a codex`. Or copy the skill folder (skills/erc8004-agent in LeoYeAI/openclaw-master-skills) into .agents/skills/8004-agent in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LeoYeAI/openclaw-master-skills --skill 8004-agent -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/8004-agent, .gemini/skills/8004-agent, .github/skills/8004-agent and .opencode/skills/8004-agent in your project.
Going by SKILL.md and its folder, 8004 Agent needs the command-line tools its instructions call (npm, docker, pnpm and npx) and credentials named KEYRING_PROXY_SECRET, AGENT_PRIVATE_KEY and KEYSTORE_PASSWORD. Our summary lists: Python 3; Node.js; A credential in KEYRING_PROXY_SECRET; A credential in AGENT_PRIVATE_KEY.
SKILL.md names 5 domains. In commands or code: alchemy.com, api.targetservice.com and api.pinata.cloud; the agent is likely to contact these when it follows the instructions. As links in the text: railway.com and siwa.builders.garden. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
8004 Agent is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 6.3k tokens (SKILL.md is roughly 25k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 6.9k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with 8004 Agent: Aomi Transact (sickn33/agentic-awesome-skills, 47k stars), Blockchain Developer (aiskillstore/marketplace, 433 stars), Payram Stablecoin Payments (PayRam/payram-mcp, 158 stars) and Analyzing On Chain Data (jeremylongshore/tons-of-skills-marketplace, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
LeoYeAI (a GitHub user) maintains it in LeoYeAI/openclaw-master-skills, which has 2,161 GitHub stars. The repository holds 1,235 skills in this directory. The repository was last updated on July 20, 2026.
Source: LeoYeAI/openclaw-master-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.