Agent skill

Nansen Wallet Keychain Migration

by nansen-ai in nansen-ai/nansen-cli

Migrate an existing nansen-cli wallet from insecure password storage (env files, .credentials) to the new secure keychain-backed flow.

MITAuto-check: notesBackend & APIs

Install Nansen Wallet Keychain Migration

skills CLI
$ npx skills add nansen-ai/nansen-cli --skill nansen-wallet-keychain-migration -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install nansen-ai/nansen-cli nansen-wallet-keychain-migration --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/nansen-ai/nansen-cli.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/nansen-wallet-keychain-migration .claude/skills/nansen-wallet-keychain-migration && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
nansen-wallet-keychain-migration
GitHub stars
139
Token cost
~1.9k tokens
SKILL.md length
756 words
Files
1
Skills in repo
32
Repo updated
First seen
Licence
MIT

At a glance

Migrate an existing nansen-cli wallet from insecure password storage (env files, .credentials) to the new secure keychain-backed flow.

  • Backend & APIs work in your project
  • SKILL.md covers Authentication, When to use, Detect current state and Migration paths, plus 3 more sections
  • Needs NANSEN_WALLET_PASSWORD and NANSEN_API_KEY

What it does

Nansen Wallet Keychain Migration is an agent skill from nansen-ai/nansen-cli. Migrate an existing nansen-cli wallet from insecure password storage (env files, .credentials) to the new secure keychain-backed flow.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs. The licence is MIT.

When your agent uses it

  • Backend & APIs work in your project

Example prompts

  • “/nansen-wallet-keychain-migration”

Requirements

  • A credential in NANSEN_API_KEY
  • Pre-approved tools (allowed-tools): Bash(nansen:*)

What it can do on your machine

Read from SKILL.md and the folder at commit d097942. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash(nansen:*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • NANSEN_WALLET_PASSWORD
    • NANSEN_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Nansen Wallet Keychain Migration loads about 1.9k tokens when it runs. Until then it costs about 42 tokens; SKILL.md has 756 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~42
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:29
    they stored their password in `~/.nansen/.env`, a `.env` file, or `memory.md`
  • NoteMentions a .env fileSKILL.md:46
    not cover: password written to ~/.nansen/.env
  • NoteMentions a .env fileSKILL.md:47
    ls -la ~/.nansen/.env 2>/dev/null && echo "FOUND: ~/.nansen/.env (insecure)"
  • NoteMentions a .env fileSKILL.md:54
    heck where it is being exported from (a `.env` file → Path A)
  • NoteMentions a .env fileSKILL.md:60
    ### Path A: Password in `~/.nansen/.env` (old skill pattern)
  • NoteMentions a .env fileSKILL.md:62
    ents to write the password to `~/.nansen/.env`.
  • NoteMentions a .env fileSKILL.md:66
    assword is currently stored in ~/.nansen/.env, which is insecure.
  • NoteMentions a .env fileSKILL.md:68
    wallet, or I can read it from ~/.nansen/.env if you authorize it."
  • NoteMentions a .env fileSKILL.md:76
    source ~/.nansen/.env 2>/dev/null && nansen wallet secure
  • NoteMentions a .env fileSKILL.md:96
    rm -f ~/.nansen/.env

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from nansen-ai/nansen-cli at commit d097942, republished under its MIT licence (© nansen-ai). 756 words, ~1,911 tokens.

Download SKILL.mdSave it as .claude/skills/nansen-wallet-keychain-migration/SKILL.md (or your agent's skills folder).
name
nansen-wallet-keychain-migration
description
Migrate an existing nansen-cli wallet from insecure password storage (env files, .credentials) to the new secure keychain-backed flow.
allowed-tools
Bash(nansen:*)

Authentication

Nansen account API calls accept a selected nansen:api browser session or conventional API key with the same permissions. NANSEN_API_KEY takes precedence; optional primaryEnv preserves configured-key injection. Run nansen auth status for offline selection. Cached access expiry alone permits automatic renewal during an authorized task. Stop on anonymous selection, invalid state, blocked/uncertain renewal or actual auth failure; never drop a credential or fall back to anonymous x402 payment. Browser login does not grant wallet signing, privileged service identity or a persistent MCP integration key. Preserve all confirmation, signing, sanctions and geographic checks below. Browser login is available in CLI 2.0.0 within the macOS arm64 preview scope.

Wallet Migration — Old Flow to Secure Keychain

Use this skill when a user already has a nansen-cli wallet set up with the old password storage method and wants to migrate to the new secure flow.

When to use

  • User mentions they stored their password in ~/.nansen/.env, a .env file, or memory.md
  • User gets the stderr warning: ⚠ Password loaded from insecure .credentials file
  • User asks to "secure my wallet" or "migrate to keychain"
  • User created a wallet before the keychain update was released

Detect current state

wallet show only displays addresses and does NOT load or check the password. To detect the actual password situation, check the stored password source directly:

bash
# 1. Where is the password stored? Offline, decrypts nothing, prints no secrets
nansen auth status --pretty     # → x402.password.source: "env" | "keychain" | "file" | null

# 2. Full setup check — flags the insecure .credentials file with a fix
nansen doctor --offline

# 3. Legacy pattern doctor does not cover: password written to ~/.nansen/.env
ls -la ~/.nansen/.env 2>/dev/null && echo "FOUND: ~/.nansen/.env (insecure)"

Interpret x402.password.source:

  • "file" → password in .credentials file, needs migration (Path B)
  • "keychain" → already secure, no migration needed
  • null → password not persisted anywhere (Path C or D)
  • "env" → NANSEN_WALLET_PASSWORD is set; check where it is being exported from (a .env file → Path A)

Do NOT use nansen wallet export to probe the password state — the default is redacted and never loads the password, so it proves nothing (and --reveal prints private keys).

Migration paths

Path A: Password in ~/.nansen/.env (old skill pattern)

The previous wallet skill told agents to write the password to ~/.nansen/.env.

Step 1 — Ask the human for their password:

"Your wallet password is currently stored in ~/.nansen/.env, which is insecure. I can migrate it to your OS keychain. Please confirm the password you used when creating the wallet, or I can read it from ~/.nansen/.env if you authorize it."

Step 2 — Migrate:

The source and nansen wallet secure MUST run in the same shell so the env var is available to the node process:

bash
source ~/.nansen/.env 2>/dev/null && nansen wallet secure

Step 3 — Verify the password actually decrypts the wallet:

bash
# Unset env var to prove keychain works, then run a decrypting export with
# all output discarded — the exit code alone is the signal, so no key
# material can land in a transcript or log
unset NANSEN_WALLET_PASSWORD
if nansen wallet export default --reveal > /dev/null 2>&1; then echo "decryption OK"; else echo "decryption FAILED"; fi

If the export exits 0 (decryption OK), the migration worked. If it fails, the wrong password was migrated — run nansen wallet forget-password and retry with the correct password.

Step 4 — Clean up the insecure file:

bash
rm -f ~/.nansen/.env
Path B: Password in .credentials file (auto-saved fallback)

This happens when wallet create couldn't access the OS keychain (containers, CI).

bash
nansen wallet secure

If the keychain is still unavailable (e.g. containerized Linux without D-Bus), nansen wallet secure will explain the situation and suggest alternatives.

After migrating, verify decryption works (output discarded on purpose — branch on the exit code):

bash
if nansen wallet export default --reveal > /dev/null 2>&1; then echo "decryption OK"; else echo "decryption FAILED"; fi
Show full SKILL.md (275 more words)Show less
Path C: Password only in NANSEN_WALLET_PASSWORD env var
bash
# Persist the env var password to keychain
nansen wallet secure

Then verify without the env var (exit code is the signal; output is discarded so no keys are disclosed):

bash
unset NANSEN_WALLET_PASSWORD
if nansen wallet export default --reveal > /dev/null 2>&1; then echo "decryption OK"; else echo "decryption FAILED"; fi
Path D: Password lost entirely

The password cannot be recovered. The wallet's private keys are encrypted with AES-256-GCM and the password is not stored anywhere recoverable.

Tell the human:

"Your wallet password cannot be recovered. If you have funds in this wallet, they may be inaccessible. You can create a new wallet and transfer any remaining accessible funds."

bash
# Create a fresh wallet (human must provide a new password)
NANSEN_WALLET_PASSWORD="<new_password_from_user>" nansen wallet create --name new-wallet

Post-migration verification

After any migration, confirm the password was migrated correctly by proving the keychain password can actually decrypt the wallet:

bash
# Unset env var to prove keychain works
unset NANSEN_WALLET_PASSWORD

# This MUST exit 0 — it proves the keychain password decrypts the wallet.
# Output is discarded on purpose: the exit code alone is the signal.
if nansen wallet export default --reveal > /dev/null 2>&1; then echo "decryption OK"; else echo "decryption FAILED"; fi

If the export fails, the wrong password was saved to the keychain. Fix with:

bash
nansen wallet forget-password
NANSEN_WALLET_PASSWORD="<correct_password>" nansen wallet secure

If stderr still shows the .credentials warning, the keychain migration did not succeed — check if the OS keychain service is running (secret-tool on Linux, security on macOS).

Forget password (all stores)

If the user wants to remove their persisted password entirely:

bash
nansen wallet forget-password

This clears the password from both OS keychain and .credentials file. Future wallet operations will require NANSEN_WALLET_PASSWORD env var or re-running nansen wallet secure.

Critical rules for agents

  • NEVER generate a password — always ask the human
  • NEVER store the password in files, memory, logs, or conversation history
  • NEVER use --human flag — interactive prompts break agents
  • If the human authorizes reading ~/.nansen/.env, read it in the same command (source ~/.nansen/.env && nansen wallet secure) — do not echo or log the value
  • ALWAYS verify after migration with nansen wallet export default --reveal > /dev/null 2>&1 (branch on the exit code; never let the output print) — wallet show does NOT prove the password works (it never loads the password)

© nansen-ai, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/nansen-wallet-keychain-migration of nansen-ai/nansen-cli.

Open the folder on GitHubat commit d097942

Compare with similar skills

Nansen Wallet Keychain Migration next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Nansen Wallet Keychain Migration compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Nansen Wallet Keychain Migration this skillnansen-ai/nansen-cli139—~1.9kAutomated safety check: NotesMIT
Configuring Horizoncoollabsio/coolify63k4 repos~898Automated safety check: PassMIT
Nestjs Best Practicesrolling-scopes/rsschool-app10k6 repos~1.2kAutomated safety check: PassMIT
Sub2API AdminWei-Shaw/sub2api44k1 repos~717Automated safety check: PassLGPL-3.0
Firecrawl Build Onboardingfirecrawl/firecrawl190k1 repos~1.4kAutomated safety check: NotesISC
Obsidian BasesAtmosphere/atmosphere3.8k22 repos~3.2kAutomated safety check: PassApache-2.0

Similar skills

  • Configuring Horizon

    coollabsio/coolify

    A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.

    63k GitHub starsUsed in 4 repos~898 tokens
    Backend & APIsAuto-check passed
  • Nestjs Best Practices

    rolling-scopes/rsschool-app

    NestJS best practices and architecture patterns for building production-ready applications.

    10k GitHub starsUsed in 6 repos~1.2k tokens
    Backend & APIsAuto-check passed
  • Sub2API Admin

    Wei-Shaw/sub2api

    Manages a Sub2API deployment from the command line: accounts, redeem and invitation codes, groups, proxies, imports, exports and raw admin API calls.

    44k GitHub starsUsed in 1 repo~717 tokens
    Backend & APIsAuto-check passed
  • Firecrawl Build Onboarding

    firecrawl/firecrawl

    Gets Firecrawl working in a project: signs you in through the browser, saves FIRECRAWL_API_KEY to .env and picks the first SDK or REST path.

    190k GitHub starsUsed in 1 repo~1.4k tokens
    Backend & APIsAuto-check: notes
  • Obsidian Bases

    Atmosphere/atmosphere

    Create and edit Obsidian Bases (.base files) with views, filters, formulas, and summaries.

    3.8k GitHub starsUsed in 22 repos~3.2k tokens
    Backend & APIsAuto-check passed
  • Fortify Development

    coollabsio/coolify

    ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 4 repos~1.9k tokens
    Backend & APIsAuto-check passed

More from nansen-ai/nansen-cli

All 32 skills in this repo
  • Nansen Smart Money Tracker

    nansen-ai/nansen-cli

    Smart money tracking — netflow, trades, holdings, perp trades.

    139 GitHub starsUsed in 2 repos~1.1k tokens
    Auto-check passed
  • Nansen Token Research

    nansen-ai/nansen-cli

    Token deep dive — info, OHLCV, holders, flows, flow intelligence, who bought/sold, DEX trades, PnL, perp trades, perp positions, perp PnL leaderboard.

    139 GitHub starsUsed in 2 repos~1.2k tokens
    Auto-check passed
  • Nansen Wallet Profiler

    nansen-ai/nansen-cli

    Wallet profiler — balance, PnL, labels, transactions, counterparties, related wallets, batch, trace, compare.

    139 GitHub starsUsed in 2 repos~1.5k tokens
    Auto-check passed
  • Nansen Agent Guide

    nansen-ai/nansen-cli

    Routing guide -- when to use nansen agent (AI research) vs direct CLI data commands.

    139 GitHub stars~948 tokensUpdated 2 days ago
    Auto-check passed
  • Nansen Limit Orders

    nansen-ai/nansen-cli

    Guide users through native limit orders on Solana via nansen trade limit-order create|list|cancel|update, and the alert-based settlement-signal fallback for chains without native support.

    139 GitHub stars~2.5k tokensUpdated 2 days ago
    Auto-check passed
  • Nansen Smart Alerts

    nansen-ai/nansen-cli

    Manage smart alerts — list, create, update, toggle, delete. An agent skill from nansen-ai/nansen-cli.

    139 GitHub stars~1.6k tokensUpdated 2 days ago
    Auto-check passed

Categories

Questions about Nansen Wallet Keychain Migration

What does Nansen Wallet Keychain Migration do?

Migrate an existing nansen-cli wallet from insecure password storage (env files, .credentials) to the new secure keychain-backed flow. Nansen Wallet Keychain Migration is an agent skill from nansen-ai/nansen-cli.credentials) to the new secure keychain-backed flow.

When should I use Nansen Wallet Keychain Migration?

Nansen Wallet Keychain Migration fits situations like: backend & APIs work in your project.

How do I install Nansen Wallet Keychain Migration in Claude Code?

Run `npx skills add nansen-ai/nansen-cli --skill nansen-wallet-keychain-migration -a claude-code`. Or copy the skill folder (skills/nansen-wallet-keychain-migration in nansen-ai/nansen-cli) into .claude/skills/nansen-wallet-keychain-migration in your project. Claude Code loads it when a task matches its description.

How do I install Nansen Wallet Keychain Migration in Codex?

Run `npx skills add nansen-ai/nansen-cli --skill nansen-wallet-keychain-migration -a codex`. Or copy the skill folder (skills/nansen-wallet-keychain-migration in nansen-ai/nansen-cli) into .agents/skills/nansen-wallet-keychain-migration in your project. Codex loads it when a task matches its description.

Can I use Nansen Wallet Keychain Migration in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add nansen-ai/nansen-cli --skill nansen-wallet-keychain-migration -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nansen-wallet-keychain-migration, .gemini/skills/nansen-wallet-keychain-migration, .github/skills/nansen-wallet-keychain-migration and .opencode/skills/nansen-wallet-keychain-migration in your project.

What does Nansen Wallet Keychain Migration need to run?

Going by SKILL.md and its folder, Nansen Wallet Keychain Migration needs credentials named NANSEN_WALLET_PASSWORD and NANSEN_API_KEY. Our summary lists: A credential in NANSEN_API_KEY. Its frontmatter pre-approves these tools: Bash(nansen:*).

Does Nansen Wallet Keychain Migration access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Nansen Wallet Keychain Migration safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Nansen Wallet Keychain Migration use?

Nansen Wallet Keychain Migration is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Nansen Wallet Keychain Migration use?

About 1.9k tokens (SKILL.md is roughly 7.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Nansen Wallet Keychain Migration?

Skills that share tags, products or a category with Nansen Wallet Keychain Migration: Configuring Horizon (coollabsio/coolify, 63k stars), Nestjs Best Practices (rolling-scopes/rsschool-app, 10k stars), Sub2API Admin (Wei-Shaw/sub2api, 44k stars) and Firecrawl Build Onboarding (firecrawl/firecrawl, 190k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Nansen Wallet Keychain Migration?

nansen-ai (a GitHub organization) maintains it in nansen-ai/nansen-cli, which has 139 GitHub stars. The repository holds 32 skills in this directory. The repository was last updated on October 9, 2026.

Source: nansen-ai/nansen-cli on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.