Competitor News Monitor
NousResearch/hermes-agent
Watch named companies for material news; cited digests. An agent skill from NousResearch/hermes-agent.
A skill your agent uses when a contributor wants to add a Wallet Security News entry to the walletbeat site.
$ npx skills add walletbeat/walletbeat --skill wallet-security-news -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install walletbeat/walletbeat wallet-security-news --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/walletbeat/walletbeat.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/wallet-security-news .claude/skills/wallet-security-news && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "wallet-security-news" agent skill from https://github.com/walletbeat/walletbeat/tree/beta/.agents/skills/wallet-security-news into .claude/skills/wallet-security-news/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "wallet-security-news", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/walletbeat/walletbeat/tree/beta/.agents/skills/wallet-security-newsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add walletbeat/walletbeat --skill wallet-security-news -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install walletbeat/walletbeat wallet-security-news --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/walletbeat/walletbeat.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/wallet-security-news .agents/skills/wallet-security-news && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "wallet-security-news" agent skill from https://github.com/walletbeat/walletbeat/tree/beta/.agents/skills/wallet-security-news into .agents/skills/wallet-security-news/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "wallet-security-news", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add walletbeat/walletbeat --skill wallet-security-news -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install walletbeat/walletbeat wallet-security-news --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/walletbeat/walletbeat.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/wallet-security-news .cursor/skills/wallet-security-news && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "wallet-security-news" agent skill from https://github.com/walletbeat/walletbeat/tree/beta/.agents/skills/wallet-security-news into .cursor/skills/wallet-security-news/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "wallet-security-news", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/walletbeat/walletbeat.git --path .agents/skills/wallet-security-news--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add walletbeat/walletbeat --skill wallet-security-news -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install walletbeat/walletbeat wallet-security-news --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/walletbeat/walletbeat.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/wallet-security-news .gemini/skills/wallet-security-news && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "wallet-security-news" agent skill from https://github.com/walletbeat/walletbeat/tree/beta/.agents/skills/wallet-security-news into .gemini/skills/wallet-security-news/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "wallet-security-news", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install walletbeat/walletbeat wallet-security-newsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add walletbeat/walletbeat --skill wallet-security-news -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/walletbeat/walletbeat.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/wallet-security-news .github/skills/wallet-security-news && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "wallet-security-news" agent skill from https://github.com/walletbeat/walletbeat/tree/beta/.agents/skills/wallet-security-news into .github/skills/wallet-security-news/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "wallet-security-news", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add walletbeat/walletbeat --skill wallet-security-news -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install walletbeat/walletbeat wallet-security-news --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/walletbeat/walletbeat.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/wallet-security-news .opencode/skills/wallet-security-news && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "wallet-security-news" agent skill from https://github.com/walletbeat/walletbeat/tree/beta/.agents/skills/wallet-security-news into .opencode/skills/wallet-security-news/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "wallet-security-news", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
wallet-security-newsA skill your agent uses when a contributor wants to add a Wallet Security News entry to the walletbeat site.
Wallet Security News is an agent skill from walletbeat/walletbeat. Use when a contributor wants to add a Wallet Security News entry to the walletbeat site. Guides through reading the incident source, extracting the required data, classifying the incident (type, severity, impact, status), structuring the news file, registering it in the index, and verifying with the project checks. Works for hacks, data breaches, vulnerabilities, and general incidents, whether they affect a tracked wallet or not.
Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
The repository describes itself as: An open repository of EVM-compatible wallets 🌸. The licence is MIT.
3 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit c6104c7. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
pnpmFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
trezor.iox.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Wallet Security News loads about 2.1k tokens when it runs. Until then it costs about 114 tokens; SKILL.md has 1,038 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from walletbeat/walletbeat at commit c6104c7, republished under its MIT licence (© walletbeat). 1,038 words, ~2,138 tokens.
.claude/skills/wallet-security-news/SKILL.md (or your agent's skills folder).You are helping a contributor add a Wallet Security News entry to the Walletbeat project. The incident they want to record is: $ARGUMENTS (if blank, ask them for the incident URL or a description of the incident before proceeding).
You have explicit permission to create and edit files inside data/news/ and to edit data/news/index.ts and .cspell.json.
$ARGUMENTS is blank, ask: "Which incident would you like to add a security news entry for? Please share the announcement URL or a description."curl). Extract the facts below from the article itself — do not guess.src/types/content/news.ts — the WalletSecurityNews type and all enumsdata/news/index.ts — how entries are registered and sorteddata/news/ as style references (e.g. data/news/2026-01-06-global-e-breach.ts for a service-provider data breach, or data/news/2026-07-17-consensys-metamask-north-korean-hacker.ts for a wallet-company incident)After reading these, summarize the facts you extracted and confirm the classification with the contributor before creating the file.
From the source, extract as many of these as the article supports:
publishedAtupdatedAtwallets. Map to the exact wallet ID (the filename of the wallet in data/software-wallets/, data/hardware-wallets/, or data/embedded-wallets/, e.g. metamask, ledger).wallets: [] — the entry is then a general incident. Do not invent an ID.summary (2–3 sentences, objective, and factual)titleUse the enums in src/types/content/news.ts. When unsure, pick the most conservative matching value and confirm with the contributor.
type (NewsType) — how the event is categorized:HACK — exploit/attack that stole crypto or wallet fundsDATA_BREACH — unauthorized exposure of personal information (not funds)VULNERABILITY — discovered flaw, exploited or notINCIDENT — general security event not covered aboveseverity (Severity) — CRITICAL / HIGH / MEDIUM / LOW, based on impact (funds at risk is high; a non-fund privacy exposure of emails is typically MEDIUM).impact.category (ImpactCategory) — what kind of damage:SEED_PHRASE_LEAK, PRIVATE_KEY_LEAK, SIGNING_BUG, SUPPLY_CHAIN, PRIVACY_LEAK, PHISHING_RELATED, HARDWARE_VULNERABILITY, VENDOR_INFILTRATION, OTHERimpact.fundsImpacted — true if user funds were affected or at risk, else false.status (IncidentStatus) — RESOLVED / MITIGATED / ONGOING / DISPUTED. Use the value matching how much the article indicates the incident is addressed.Every entry needs a ref (WithRef<WalletSecurityNews>) pointing at the primary source(s):
Prefer the official announcement / incident report from the wallet developer or the affected party (e.g. a blog post, a security advisory).
The ref.label should be a human-readable description of the link (e.g. the article's title), and ref.url the direct URL.
Add secondary refs (news coverage, affected-company advisories) only if they add meaningful detail.
To cite more than one source, make ref an array of labeled ref objects (each with label + url). E.g. a blog post plus the vendor's announcement on X:
ref: [
{ label: 'Trezor blog: Recent customer data exposed in shipping provider incident', url: 'https://trezor.io/blog/news/...' },
{ label: 'Trezor on X: Customer data exposure incident', url: 'https://x.com/Trezor/status/...' },
],refTodo / refNotNecessary are not appropriate here — the news entry should always cite the incident source.
Create a single file in data/news/:
data/news/YYYY-MM-DD-<slug>.tsYYYY-MM-DD = the incident's publishedAt (when the incident occurred or was first disclosed).<slug> = a short, kebab-case slug of the incident, matching the entry's slug field.Example: data/news/2026-08-06-privy-metabase-security-incident.ts
The file exports a single default object as const satisfies WalletSecurityNews. Match the exact structure of existing entries — the object must include every WalletSecurityNews field (slug, type, ref, impact, publishedAt, severity, status, summary, title, updatedAt, wallets). Dates use YYYY-MM-DD strings.
In data/news/index.ts, add a dynamic import for the new file inside the allWalletSecurityNews array. Order in the array does not matter — the list is sorted by publishedAt at the end of the module.
If the source introduces proper nouns the project dictionary does not know (e.g. a vendor or tool name such as Metabase), add the word to the words array in .cspell.json, keeping it alphabetically sorted. Only add valid proper nouns — never add typos or arbitrary words.
Two gotchas when adding a word:
cSpell matches words case-insensitively, one entry (ShipMonk) also covers the lowercased slug in the filename / index import (shipmonk) — don't add both spellings. Enter the word in its correct capitalization (the proper-noun form), not lowercase. Harper (the grammar linter, see tests/utils/grammar.ts) builds its vocabulary from the words list in .cspell.json. A capitalized entry is recognized as a proper noun, and Harper automatically adds its possessive 's form — so you don't need to add ShipMonk's. A lowercase entry would not be recognized as a proper noun.imToken) trips Harper's Capitalization lint (it would force ImToken). Such words must also be added to PROPER_NOUNS_LOWERCASE_FIRST in tests/utils/grammar.ts — a code edit outside this skill's file permissions.cSpell test sorts by toLowerCase() (tests/cspell.test.ts), so ordering can differ from a naive case-sensitive sort — e.g. ShipMonk (ship...) sorts after shefi and before sidepanel, not right after Shamir. If the order is wrong, pnpm check:vitest fails with a message naming the two words that are out of order; move it accordingly.Run the project checks after creating the entry:
pnpm check:allThis must pass before the change is considered complete. Common failures specific to news entries:
check:spelling step flags unknown proper nouns. Fix by adding the term to .cspell.json.WalletSecurityNews. Missing fields, wrong enum values, or a slug mismatch between the filename and the slug field will fail to compile.wallets: [] is valid. An incident is still worth recording when it does not map to a tracked wallet — use an empty wallets array rather than an invented ID.YYYY-MM-DD strings. publishedAt is the incident/disclosure date; updatedAt is the last-known-update date.ref. The news entry must cite the incident source — no refTodo.pnpm check:all before opening a PR — it must pass.© walletbeat, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/wallet-security-news of walletbeat/walletbeat.
Open the folder on GitHubat commit c6104c7
Wallet Security News next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Wallet Security News this skillwalletbeat/walletbeat | 119 | — | ~2.1k | Automated safety check: Pass | MIT | |
| Competitor News MonitorNousResearch/hermes-agent | 252k | — | ~1.2k | Automated safety check: Pass | MIT | |
| Newsalsk1992/CloddsBot | 3k | — | ~462 | Automated safety check: Pass | MIT | |
| Changelog Entrysickn33/agentic-awesome-skills | 47k | 1 repos | ~1.1k | Automated safety check: Pass | MIT | |
| Contributor Screendifferent-ai/openwork | 24k | — | ~939 | Automated safety check: Warn | Custom licence | |
| Codewhale Contributor Onboardingcodewhale-hq/Codewhale | 41k | — | ~1.3k | Automated safety check: Pass | MIT |
NousResearch/hermes-agent
Watch named companies for material news; cited digests. An agent skill from NousResearch/hermes-agent.
alsk1992/CloddsBot
Monitor news and correlate with prediction market movements. An agent skill from alsk1992/CloddsBot.
sickn33/agentic-awesome-skills
Generate a properly formatted CHANGELOG.md entry in Keep a Changelog format from a commit range or PR.
different-ai/openwork
Screen a pull request from an outside contributor for hidden, obfuscated, or supply-chain-risky changes before any of its code runs.
codewhale-hq/Codewhale
Reports whether a fresh Codewhale checkout is current, builds and passes its tests, and what changed since the contributor was last here, without touching the working tree.
sickn33/agentic-awesome-skills
Crypto wallet management across 7 blockchains via EmblemAI Agent Hustle API.
walletbeat/walletbeat
A skill your agent uses when a contributor wants to add a brand-new wallet to the walletbeat project.
walletbeat/walletbeat
A skill your agent uses when a contributor wants to populate or update feature data for a wallet that already exists in the Walletbeat project.
walletbeat/walletbeat
A skill your agent uses when asked to deal with a wallet's network traffic data, for automated analysis and classification.
A skill your agent uses when a contributor wants to add a Wallet Security News entry to the walletbeat site. Wallet Security News is an agent skill from walletbeat/walletbeat. Use when a contributor wants to add a Wallet Security News entry to the walletbeat site.
Wallet Security News fits situations like: A contributor wants to add a Wallet Security News entry to the walletbeat site.
Run `npx skills add walletbeat/walletbeat --skill wallet-security-news -a claude-code`. Or copy the skill folder (.agents/skills/wallet-security-news in walletbeat/walletbeat) into .claude/skills/wallet-security-news in your project. Claude Code loads it when a task matches its description.
Run `npx skills add walletbeat/walletbeat --skill wallet-security-news -a codex`. Or copy the skill folder (.agents/skills/wallet-security-news in walletbeat/walletbeat) into .agents/skills/wallet-security-news in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add walletbeat/walletbeat --skill wallet-security-news -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/wallet-security-news, .gemini/skills/wallet-security-news, .github/skills/wallet-security-news and .opencode/skills/wallet-security-news in your project.
Going by SKILL.md and its folder, Wallet Security News needs the command-line tools its instructions call (pnpm).
SKILL.md names 2 domains. In commands or code: trezor.io and x.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Wallet Security News is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.1k tokens (SKILL.md is roughly 8.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Wallet Security News: Competitor News Monitor (NousResearch/hermes-agent, 252k stars), News (alsk1992/CloddsBot, 3k stars), Changelog Entry (sickn33/agentic-awesome-skills, 47k stars) and Contributor Screen (different-ai/openwork, 24k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
walletbeat (a GitHub organization) maintains it in walletbeat/walletbeat, which has 119 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on October 10, 2026.
Source: walletbeat/walletbeat on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.