Local keystore + MCP server. Claude can sign EVM transactions but never sees the private key.
Claude can sign, but never see. is a local signing tool and Claude Code integration that lets agentic coding tools use private keys without ever putting key material in the model's context window. Status: pre-alpha. The MCP server, CLI, unlock flow, ward hooks, and policy engine (static checks) all work end-to-end. Out-of-band confirmation, rolling-window value caps, and EIP-712 domain allowlists…
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts — it cannot prove the absence of malicious code.
Claude can sign, but never see. is a local signing tool and Claude Code integration that lets agentic coding tools use private keys without ever putting key material in the model's context window. Status: pre-alpha. The MCP server, CLI, unlock flow, ward hooks, and policy engine (static checks) all work end-to-end. Out-of-band confirmation, rolling-window value caps, and EIP-712 domain allowlists are not yet implemented. Until they land — and until the supply-chain attestations promised for…