# @three-ws/onchain-agent-wallets

Give an AI agent a Solana spending allowance instead of your key. Chain-enforced cap, x402.

- **Type:** MCP server
- **Trust:** 40/100 (C), scored on the package rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 0.1.0
- **Author:** io.github.nirholas
- **License:** Unknown
- **npm:** @three-ws/onchain-agent-wallets
- **Source:** https://github.com/nirholas/onchain-agent-wallets
- **Compatible clients:** claude-code, cursor, copilot, gemini (basis: transport)

## Trust

40/100 (C), scored on the package rubric
- Publisher verified: no
- Install scripts: suspicious script found
- Prompt-injection scan: not run
- Obfuscation scan: not run
- Evidence age: 0 days

## Security scan

- **Status:** warnings
- **Scanned:** 2026-09-10T18:24:22.817Z
- **Version scanned:** 0.1.0
- **CVEs:** none found by OSV at scan time
**Findings**
- injection-shaped content (warning) in the `agent_pay` tool: Exfiltration-shaped instruction

## Tools

15 declared. Statically extracted from the shipped source — a floor on the surface, not a census.
- `agent_pay` — Send tokens from the agent vault to a recipient, signed by the agent as the on-chain delegate. Every
- `agent_wallet_status` — Show an agent wallet as it actually stands on-chain: vault balance, how much of the delegated allowance is
- `approve_agent_allowance` — Set how much the agent may spend from the vault, enforced by the SPL Token program. This REPLACES the
- `create_agent_wallet` — Create an agent wallet on Solana. Generates a fresh keypair for the agent, creates a vault token account
- `deploy_agent_onchain` — Mint the agent an on-chain identity in the Metaplex Agent Registry on Solana, carrying its EIP-8004
- `export_agent_runtime` — Produce the config that puts this agent wallet in front of a model: an mcp.json block, the equivalent
- `fund_agent_wallet` — Move tokens from your wallet into the agent vault, and optionally send the agent a little SOL for its own
- `onchain-agent-wallets`
- `list_agent_wallets` — List the agent wallets configured here, each with its live vault balance, remaining on-chain allowance, and
- `pay_x402` — Call an HTTP endpoint that charges with x402, paying from the agent allowance on Solana. The price is read
- `revoke_agent_wallet` — Cancel the agent's delegation on-chain. After this the SPL Token program refuses every transfer the agent
- `send_signed_transaction` — Broadcast a base64 transaction that Phantom, Solflare, Backpack, or a Ledger already signed, and wait for
- `set_guardrails` — Set the rules this server enforces before it signs a spend: per-transaction cap, rolling 24h cap, allowed
- `spend_log` — The audit trail for one agent: every spend that went through and every one the guardrails refused, with the
- `withdraw_from_vault` — Withdraw tokens from an agent vault back to your own wallet. The vault is yours, so this always works,

## Install

**Verdict: do-not-install** — Do not install: 1 injection-shaped pattern found in this entry's own text — it may try to steer the model that loads it.
**Blocking**
- 1 injection-shaped pattern found in this entry's own text — it may try to steer the model that loads it. — tool:agent_pay: Exfiltration-shaped instruction
**Cautions** (coverage gaps and advisories — never blocking)
- No publisher has proved control of this listing; it is indexed, not vouched for.
**Client configuration withheld.** Client configs are withheld because this entry has a blocking finding. Show the warnings below to the person installing it.
If they have seen the findings and still want to proceed, request the plan again with acknowledge_warnings=true.

## Blast radius

Contained to moderate — no credential declaration found, from the publisher, the upstream registry, or the README. Known so far: runs on your machine; read-only tool surface.
- Floor 13, ceiling 31 (tier: unknown)
- `unknown` means the floor and ceiling land in different bands — not measured enough to name one. It does not mean low.
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/%40three-ws%2Fonchain-agent-wallets
- Install plan: https://forgeregistry.com/api/v1/packages/%40three-ws%2Fonchain-agent-wallets/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/%40three-ws%2Fonchain-agent-wallets
- HTML page: https://forgeregistry.com/registry/%40three-ws%2Fonchain-agent-wallets
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
