Configuring Horizon
coollabsio/coolify
A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.
Migrate an existing nansen-cli wallet from insecure password storage (env files, .credentials) to the new secure keychain-backed flow.
$ npx skills add nansen-ai/nansen-cli --skill nansen-wallet-keychain-migration -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install nansen-ai/nansen-cli nansen-wallet-keychain-migration --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/nansen-ai/nansen-cli.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/nansen-wallet-keychain-migration .claude/skills/nansen-wallet-keychain-migration && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "nansen-wallet-keychain-migration" agent skill from https://github.com/nansen-ai/nansen-cli/tree/main/skills/nansen-wallet-keychain-migration into .claude/skills/nansen-wallet-keychain-migration/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nansen-wallet-keychain-migration", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/nansen-ai/nansen-cli/tree/main/skills/nansen-wallet-keychain-migrationType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add nansen-ai/nansen-cli --skill nansen-wallet-keychain-migration -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install nansen-ai/nansen-cli nansen-wallet-keychain-migration --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nansen-ai/nansen-cli.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/nansen-wallet-keychain-migration .agents/skills/nansen-wallet-keychain-migration && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "nansen-wallet-keychain-migration" agent skill from https://github.com/nansen-ai/nansen-cli/tree/main/skills/nansen-wallet-keychain-migration into .agents/skills/nansen-wallet-keychain-migration/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nansen-wallet-keychain-migration", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add nansen-ai/nansen-cli --skill nansen-wallet-keychain-migration -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install nansen-ai/nansen-cli nansen-wallet-keychain-migration --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nansen-ai/nansen-cli.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/nansen-wallet-keychain-migration .cursor/skills/nansen-wallet-keychain-migration && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "nansen-wallet-keychain-migration" agent skill from https://github.com/nansen-ai/nansen-cli/tree/main/skills/nansen-wallet-keychain-migration into .cursor/skills/nansen-wallet-keychain-migration/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nansen-wallet-keychain-migration", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/nansen-ai/nansen-cli.git --path skills/nansen-wallet-keychain-migration--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add nansen-ai/nansen-cli --skill nansen-wallet-keychain-migration -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install nansen-ai/nansen-cli nansen-wallet-keychain-migration --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nansen-ai/nansen-cli.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/nansen-wallet-keychain-migration .gemini/skills/nansen-wallet-keychain-migration && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "nansen-wallet-keychain-migration" agent skill from https://github.com/nansen-ai/nansen-cli/tree/main/skills/nansen-wallet-keychain-migration into .gemini/skills/nansen-wallet-keychain-migration/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nansen-wallet-keychain-migration", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install nansen-ai/nansen-cli nansen-wallet-keychain-migrationInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add nansen-ai/nansen-cli --skill nansen-wallet-keychain-migration -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/nansen-ai/nansen-cli.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/nansen-wallet-keychain-migration .github/skills/nansen-wallet-keychain-migration && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "nansen-wallet-keychain-migration" agent skill from https://github.com/nansen-ai/nansen-cli/tree/main/skills/nansen-wallet-keychain-migration into .github/skills/nansen-wallet-keychain-migration/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nansen-wallet-keychain-migration", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add nansen-ai/nansen-cli --skill nansen-wallet-keychain-migration -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install nansen-ai/nansen-cli nansen-wallet-keychain-migration --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nansen-ai/nansen-cli.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/nansen-wallet-keychain-migration .opencode/skills/nansen-wallet-keychain-migration && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "nansen-wallet-keychain-migration" agent skill from https://github.com/nansen-ai/nansen-cli/tree/main/skills/nansen-wallet-keychain-migration into .opencode/skills/nansen-wallet-keychain-migration/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nansen-wallet-keychain-migration", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
nansen-wallet-keychain-migrationMigrate an existing nansen-cli wallet from insecure password storage (env files, .credentials) to the new secure keychain-backed flow.
Nansen Wallet Keychain Migration is an agent skill from nansen-ai/nansen-cli. Migrate an existing nansen-cli wallet from insecure password storage (env files, .credentials) to the new secure keychain-backed flow.
Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Backend & APIs. The licence is MIT.
Read from SKILL.md and the folder at commit d097942. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
Bash(nansen:*)From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
NANSEN_WALLET_PASSWORDNANSEN_API_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Nansen Wallet Keychain Migration loads about 1.9k tokens when it runs. Until then it costs about 42 tokens; SKILL.md has 756 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
they stored their password in `~/.nansen/.env`, a `.env` file, or `memory.md`not cover: password written to ~/.nansen/.envls -la ~/.nansen/.env 2>/dev/null && echo "FOUND: ~/.nansen/.env (insecure)"heck where it is being exported from (a `.env` file → Path A)### Path A: Password in `~/.nansen/.env` (old skill pattern)ents to write the password to `~/.nansen/.env`.assword is currently stored in ~/.nansen/.env, which is insecure.wallet, or I can read it from ~/.nansen/.env if you authorize it."source ~/.nansen/.env 2>/dev/null && nansen wallet securerm -f ~/.nansen/.envAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from nansen-ai/nansen-cli at commit d097942, republished under its MIT licence (© nansen-ai). 756 words, ~1,911 tokens.
.claude/skills/nansen-wallet-keychain-migration/SKILL.md (or your agent's skills folder).Nansen account API calls accept a selected nansen:api browser session or conventional API key with the same permissions. NANSEN_API_KEY takes precedence; optional primaryEnv preserves configured-key injection. Run nansen auth status for offline selection. Cached access expiry alone permits automatic renewal during an authorized task. Stop on anonymous selection, invalid state, blocked/uncertain renewal or actual auth failure; never drop a credential or fall back to anonymous x402 payment. Browser login does not grant wallet signing, privileged service identity or a persistent MCP integration key. Preserve all confirmation, signing, sanctions and geographic checks below. Browser login is available in CLI 2.0.0 within the macOS arm64 preview scope.
Use this skill when a user already has a nansen-cli wallet set up with the old password storage method and wants to migrate to the new secure flow.
~/.nansen/.env, a .env file, or memory.md⚠ Password loaded from insecure .credentials filewallet show only displays addresses and does NOT load or check the password.
To detect the actual password situation, check the stored password source directly:
# 1. Where is the password stored? Offline, decrypts nothing, prints no secrets
nansen auth status --pretty # → x402.password.source: "env" | "keychain" | "file" | null
# 2. Full setup check — flags the insecure .credentials file with a fix
nansen doctor --offline
# 3. Legacy pattern doctor does not cover: password written to ~/.nansen/.env
ls -la ~/.nansen/.env 2>/dev/null && echo "FOUND: ~/.nansen/.env (insecure)"Interpret x402.password.source:
"file" → password in .credentials file, needs migration (Path B)"keychain" → already secure, no migration needednull → password not persisted anywhere (Path C or D)"env" → NANSEN_WALLET_PASSWORD is set; check where it is being exported from (a .env file → Path A)Do NOT use nansen wallet export to probe the password state — the default is redacted and never loads the password, so it proves nothing (and --reveal prints private keys).
~/.nansen/.env (old skill pattern)The previous wallet skill told agents to write the password to ~/.nansen/.env.
Step 1 — Ask the human for their password:
"Your wallet password is currently stored in ~/.nansen/.env, which is insecure. I can migrate it to your OS keychain. Please confirm the password you used when creating the wallet, or I can read it from ~/.nansen/.env if you authorize it."
Step 2 — Migrate:
The source and nansen wallet secure MUST run in the same shell so the env
var is available to the node process:
source ~/.nansen/.env 2>/dev/null && nansen wallet secureStep 3 — Verify the password actually decrypts the wallet:
# Unset env var to prove keychain works, then run a decrypting export with
# all output discarded — the exit code alone is the signal, so no key
# material can land in a transcript or log
unset NANSEN_WALLET_PASSWORD
if nansen wallet export default --reveal > /dev/null 2>&1; then echo "decryption OK"; else echo "decryption FAILED"; fiIf the export exits 0 (decryption OK), the migration worked. If it fails,
the wrong password was migrated — run nansen wallet forget-password and retry with the correct password.
Step 4 — Clean up the insecure file:
rm -f ~/.nansen/.env.credentials file (auto-saved fallback)This happens when wallet create couldn't access the OS keychain (containers, CI).
nansen wallet secureIf the keychain is still unavailable (e.g. containerized Linux without D-Bus),
nansen wallet secure will explain the situation and suggest alternatives.
After migrating, verify decryption works (output discarded on purpose — branch on the exit code):
if nansen wallet export default --reveal > /dev/null 2>&1; then echo "decryption OK"; else echo "decryption FAILED"; fiNANSEN_WALLET_PASSWORD env var# Persist the env var password to keychain
nansen wallet secureThen verify without the env var (exit code is the signal; output is discarded so no keys are disclosed):
unset NANSEN_WALLET_PASSWORD
if nansen wallet export default --reveal > /dev/null 2>&1; then echo "decryption OK"; else echo "decryption FAILED"; fiThe password cannot be recovered. The wallet's private keys are encrypted with AES-256-GCM and the password is not stored anywhere recoverable.
Tell the human:
"Your wallet password cannot be recovered. If you have funds in this wallet, they may be inaccessible. You can create a new wallet and transfer any remaining accessible funds."
# Create a fresh wallet (human must provide a new password)
NANSEN_WALLET_PASSWORD="<new_password_from_user>" nansen wallet create --name new-walletAfter any migration, confirm the password was migrated correctly by proving the keychain password can actually decrypt the wallet:
# Unset env var to prove keychain works
unset NANSEN_WALLET_PASSWORD
# This MUST exit 0 — it proves the keychain password decrypts the wallet.
# Output is discarded on purpose: the exit code alone is the signal.
if nansen wallet export default --reveal > /dev/null 2>&1; then echo "decryption OK"; else echo "decryption FAILED"; fiIf the export fails, the wrong password was saved to the keychain. Fix with:
nansen wallet forget-password
NANSEN_WALLET_PASSWORD="<correct_password>" nansen wallet secureIf stderr still shows the .credentials warning, the keychain migration did
not succeed — check if the OS keychain service is running (secret-tool on Linux,
security on macOS).
If the user wants to remove their persisted password entirely:
nansen wallet forget-passwordThis clears the password from both OS keychain and .credentials file. Future
wallet operations will require NANSEN_WALLET_PASSWORD env var or re-running
nansen wallet secure.
--human flag — interactive prompts break agents~/.nansen/.env, read it in the same command
(source ~/.nansen/.env && nansen wallet secure) — do not echo or log the valuenansen wallet export default --reveal > /dev/null 2>&1 (branch on the exit code; never let the output print) — wallet show does NOT prove the password works (it never loads the password)© nansen-ai, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/nansen-wallet-keychain-migration of nansen-ai/nansen-cli.
Open the folder on GitHubat commit d097942
Nansen Wallet Keychain Migration next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Nansen Wallet Keychain Migration this skillnansen-ai/nansen-cli | 139 | — | ~1.9k | Automated safety check: Notes | MIT | |
| Configuring Horizoncoollabsio/coolify | 63k | 4 repos | ~898 | Automated safety check: Pass | MIT | |
| Nestjs Best Practicesrolling-scopes/rsschool-app | 10k | 6 repos | ~1.2k | Automated safety check: Pass | MIT | |
| Sub2API AdminWei-Shaw/sub2api | 44k | 1 repos | ~717 | Automated safety check: Pass | LGPL-3.0 | |
| Firecrawl Build Onboardingfirecrawl/firecrawl | 190k | 1 repos | ~1.4k | Automated safety check: Notes | ISC | |
| Obsidian BasesAtmosphere/atmosphere | 3.8k | 22 repos | ~3.2k | Automated safety check: Pass | Apache-2.0 |
coollabsio/coolify
A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.
rolling-scopes/rsschool-app
NestJS best practices and architecture patterns for building production-ready applications.
Wei-Shaw/sub2api
Manages a Sub2API deployment from the command line: accounts, redeem and invitation codes, groups, proxies, imports, exports and raw admin API calls.
firecrawl/firecrawl
Gets Firecrawl working in a project: signs you in through the browser, saves FIRECRAWL_API_KEY to .env and picks the first SDK or REST path.
Atmosphere/atmosphere
Create and edit Obsidian Bases (.base files) with views, filters, formulas, and summaries.
coollabsio/coolify
ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.
nansen-ai/nansen-cli
Smart money tracking — netflow, trades, holdings, perp trades.
nansen-ai/nansen-cli
Token deep dive — info, OHLCV, holders, flows, flow intelligence, who bought/sold, DEX trades, PnL, perp trades, perp positions, perp PnL leaderboard.
nansen-ai/nansen-cli
Wallet profiler — balance, PnL, labels, transactions, counterparties, related wallets, batch, trace, compare.
nansen-ai/nansen-cli
Routing guide -- when to use nansen agent (AI research) vs direct CLI data commands.
nansen-ai/nansen-cli
Guide users through native limit orders on Solana via nansen trade limit-order create|list|cancel|update, and the alert-based settlement-signal fallback for chains without native support.
nansen-ai/nansen-cli
Manage smart alerts — list, create, update, toggle, delete. An agent skill from nansen-ai/nansen-cli.
Categories
Migrate an existing nansen-cli wallet from insecure password storage (env files, .credentials) to the new secure keychain-backed flow. Nansen Wallet Keychain Migration is an agent skill from nansen-ai/nansen-cli.credentials) to the new secure keychain-backed flow.
Nansen Wallet Keychain Migration fits situations like: backend & APIs work in your project.
Run `npx skills add nansen-ai/nansen-cli --skill nansen-wallet-keychain-migration -a claude-code`. Or copy the skill folder (skills/nansen-wallet-keychain-migration in nansen-ai/nansen-cli) into .claude/skills/nansen-wallet-keychain-migration in your project. Claude Code loads it when a task matches its description.
Run `npx skills add nansen-ai/nansen-cli --skill nansen-wallet-keychain-migration -a codex`. Or copy the skill folder (skills/nansen-wallet-keychain-migration in nansen-ai/nansen-cli) into .agents/skills/nansen-wallet-keychain-migration in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add nansen-ai/nansen-cli --skill nansen-wallet-keychain-migration -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nansen-wallet-keychain-migration, .gemini/skills/nansen-wallet-keychain-migration, .github/skills/nansen-wallet-keychain-migration and .opencode/skills/nansen-wallet-keychain-migration in your project.
Going by SKILL.md and its folder, Nansen Wallet Keychain Migration needs credentials named NANSEN_WALLET_PASSWORD and NANSEN_API_KEY. Our summary lists: A credential in NANSEN_API_KEY. Its frontmatter pre-approves these tools: Bash(nansen:*).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Nansen Wallet Keychain Migration is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.9k tokens (SKILL.md is roughly 7.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Nansen Wallet Keychain Migration: Configuring Horizon (coollabsio/coolify, 63k stars), Nestjs Best Practices (rolling-scopes/rsschool-app, 10k stars), Sub2API Admin (Wei-Shaw/sub2api, 44k stars) and Firecrawl Build Onboarding (firecrawl/firecrawl, 190k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
nansen-ai (a GitHub organization) maintains it in nansen-ai/nansen-cli, which has 139 GitHub stars. The repository holds 32 skills in this directory. The repository was last updated on October 9, 2026.
Source: nansen-ai/nansen-cli on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.