Rustok Agentic Wallet
Self-custody Ethereum agent wallet - one container image, keys never leave your machine. Reads balances and DeFi positions. Sending is gated in a separate console, never the agent chat: approve each payment, or confirm autonomous mode once and it pays alone. No spending limits, you assume all risk.
Rank
62
Safety
84
Downloads
1.9k
Updated
Oct 9, 2026
Version
0.11.0
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.9K downloads reported by the source. Last updated 10/9/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 9, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 9, 2026
- Adoption signal
- 1.9K downloadsadoption · observed Oct 9, 2026
- Latest release
- 0.11.0release · observed Aug 20, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s173q029wxh3tq4t0exr2f1fzn8accy0:wallet- Install using `clawhub skill install s173q029wxh3tq4t0exr2f1fzn8accy0:wallet` in an isolated environment before connecting it to live workloads.
- No published capability contract is available yet, so validate auth and request/response behavior manually.
- Review the upstream CLAWHUB listing at https://clawhub.ai/rustok/wallet before using production credentials.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-rustok-wallet/snapshot"
Documentation
CLAWHUB
149,518 characters of source documentation, loaded on request.
Extracted files
4 files captured from the source.
SKILL.md
---
name: rustok-wallet-tui
description: Self-custody Ethereum agent wallet. Installs with one command and runs entirely on your machine as a single container image (MCP over stdio); private keys never leave it. Read wallet context, balances and DeFi positions (Aave v3, ERC-4626); preview transactions. Sending funds on-chain is gated in a separate terminal console, never inside the agent chat: you approve each payment, or confirm autonomous mode once and the wallet sends on its own after that; message signing is refused outright, in every mode. You assume all risk for funds on the agent wallet — there are no hard-coded spending limits.
version: 0.11.0
metadata:
openclaw:
emoji: "🦀"
homepage: https://github.com/rustok-org/mcp
---
# rustok-wallet-tui
> **License note:** this OpenClaw skill package (`skills/rustok-wallet-tui/`) is MIT-0
> per ClawHub requirements. The Rustok wallet core itself is proprietary; only the
> compiled binary image is distributed.
You are connected to a **self-custody** Ethereum agent wallet that runs entirely
on the user's machine as a single Docker image (`ghcr.io/rustok-org/rustok-wallet-tui`).
The container runs the wallet core + gateway and speaks MCP over **stdio**; the
private keys live only in the user's local Docker volume and never leave it.
> ⚠️ **Self-custody, real funds, your risk.** This wallet has **no hard-coded
> spending limits or budgets** — the user consciously accepts that funds sent to
> the agent wallet are at risk. txguard still flags risky transactions, but it
> does not block them. All supported chains the user enables are live (incl.
> Ethereum mainnet). Always preview before executing and show the user the details.
## What's protected — and what isn't (be honest with the user)
The wallet's guarantee is narrow and specific. State it plainly; do not oversell it.
The full list of boundaries — password delivery, updates, what we do not verify at
all — lives in [docs/CAVEATS.md](https://github.com/rustok-org/mcp/blob/main/docs/CAVEATS.md).
| | |
|---|---|
| **Protected** | Private keys stay in the user's **local Docker volume** and never leave the machine. **Sending funds on-chain** (`execute_transaction`) is gated in a **separate console window** (`rustok console`, opened by the user — see below): parked for the user's approval, with a PIN for high-risk items — unless the user has confirmed **autonomous mode** there, a confirmation only they can give, once per wallet. |
| **Refused, not gated** | `sign_message` (EIP-191) is **refused outright** — in every mode, autonomous included. The console never sees a signature request, because signing does not happen at all: parking a signature for approval (`kind:sign`) is planned and not built. A tool that is listed and always refuses is neither a capability to rely on nor a hole to fear. Tell the user that rather than letting them plan around a signature. |
| **Outside the model** | An agent with **shell / `docker exec` access to the cont_meta.json
{
"ownerId": "kn783xqj8cgxz5m78mszfj7x9d81x8f3",
"slug": "wallet",
"version": "0.11.0",
"publishedAt": 1787202059882
}skill-card.md
## Description: Rustok Agentic Wallet gives an agent access to a local self-custody Ethereum wallet for reading balances and DeFi positions, previewing transactions, and submitting transactions through supervised or user-confirmed autonomous wallet modes. This skill is ready for commercial/non-commercial use. ## Publisher: [rustok](https://clawhub.ai/user/rustok) ### License/Terms of Use: MIT-0 ## Use Case: External users and developers use this skill to let an agent inspect Ethereum wallet state, review DeFi positions, preview on-chain transactions, and coordinate transaction execution from a local self-custody wallet. It is intended for users who accept live-funds risk and understand the separate approval console and autonomous mode behavior. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: The skill handles a real self-custody wallet with live-funds transaction authority and no hard-coded spending limits. Mitigation: Use read-only capabilities unless transaction execution is specifically needed, keep only limited funds in the wallet, preview every transaction, and rely on the separate approval console unless the user intentionally confirms autonomous mode. Risk: The installer can be run through a remote shell pipeline, which makes it easy to execute installer code without review. Mitigation: Fetch the installer to a file, inspect it before running it, and verify installer or container provenance where possible. Risk: Broad default execution capabilities increase the blast radius if an agent session is misconfigured or over-trusted. Mitigation: Configure the narrowest required wallet capability set, such as read-only access for balance and position inspection. Risk: Local wallet secrets and wallet volumes require lifecycle management by the user. Mitigation: Understand how to remove or rotate the local secret and wallet volume before using the skill with meaningful funds. ## Reference(s): - [ClawHub skill page](https://clawhub.ai/rustok/skills/wallet) - [Rustok MCP homepage](https://github.com/rustok-org/mcp) - [Install guide](https://github.com/rustok-org/mcp/blob/main/docs/INSTALL.md) - [Caveats](https://github.com/rustok-org/mcp/blob/main/docs/CAVEATS.md) ## Skill Output: **Output Type(s):** [text, markdown, shell commands, configuration, guidance] **Output Format:** [Markdown guidance with inline shell commands and JSON configuration snippets] **Output Parameters:** [1D] **Other Properties Related to Output:** [May include wallet-state summaries, transaction-preview guidance, approval-console instructions, and status-polling guidance.] ## Skill Version(s): 0.11.0 (source: server release metadata, SKILL.md frontmatter, claw.json) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before depl
claw.json
{
"name": "rustok-wallet-tui",
"version": "0.11.0",
"description": "Self-custody Ethereum agent wallet. Installs with one command and runs entirely on your machine as a single container image (MCP over stdio); private keys never leave it. Read wallet context, balances and DeFi positions (Aave v3, ERC-4626); preview transactions. Sending funds on-chain is gated in a separate terminal console, never inside the agent chat: you approve each payment, or confirm autonomous mode once and the wallet sends on its own after that; message signing is refused outright, in every mode. You assume all risk for funds on the agent wallet — there are no hard-coded spending limits.",
"author": "rustok-org",
"license": "MIT-0",
"permissions": [
"network"
],
"entry": "SKILL.md",
"tags": [
"crypto",
"ethereum",
"wallet",
"defi",
"agent-wallet",
"mcp",
"self-custody"
],
"minOpenClawVersion": "0.8.0",
"homepage": "https://github.com/rustok-org/mcp"
}AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/rustok/skills/wallet",
"sourceUrl": "https://clawhub.ai/rustok/skills/wallet",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T23:52:08.372Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-rustok-wallet/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-rustok-wallet/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-09T23:52:08.372Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.9K downloads",
"href": "https://clawhub.ai/rustok/wallet",
"sourceUrl": "https://clawhub.ai/rustok/wallet",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T23:52:08.372Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "0.11.0",
"href": "https://clawhub.ai/rustok/wallet",
"sourceUrl": "https://clawhub.ai/rustok/wallet",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-08-20T05:00:59.882Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-rustok-wallet/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-rustok-wallet/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 0.11.0",
"description": "## rustok-wallet-tui 0.11.0 - Updated onboarding instructions to use the correct versioned install script for 0.11.0. - Expanded documentation: clarified how mode switching works and what happens to parked transactions. - Added details explaining that both enabling and disabling autonomous mode require explicit user action in the console, and what to expect when the mode changes mid-session. - Removed the `skill-card.md` file.",
"href": "https://clawhub.ai/rustok/wallet",
"sourceUrl": "https://clawhub.ai/rustok/wallet",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-08-20T05:00:59.882Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
