Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Waiaas

ASecurity

Self-hosted crypto wallet daemon for AI agents. Manage wallets, send transactions, interact with DeFi protocols — without exposing private keys. EVM + Solana unified API via MCP. Use when: user asks to send crypto, check wallet balance, swap tokens, interact with DeFi, or manage on-chain assets. NOT for: fiat payments, bank transfers, or centralized exchange trading.

2 stars
0 votes
0 copies
0 views
Added 9/29/2026
blockchainrustgobashnodegitapisecurity

Works with

cliapimcp

Security Analysis

A96/100
mediumInstalls packages at runtime which could introduce malicious dependencies

Pro shows the line behind each finding and how to fix it

Scanned 9/29/2026

$npx -y skills add Arry8/openclaw-edge --skill waiaas --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Waiaas?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Waiaas
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/arry8-waiaas/badge)](https://www.skillsdirectory.com/skills/arry8-waiaas)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: waiaas
description: "Self-hosted crypto wallet daemon for AI agents. Manage wallets, send transactions, interact with DeFi protocols — without exposing private keys. EVM + Solana unified API via MCP. Use when: user asks to send crypto, check wallet balance, swap tokens, interact with DeFi, or manage on-chain assets. NOT for: fiat payments, bank transfers, or centralized exchange trading."
homepage: https://waiaas.ai
metadata: { "openclaw": { "emoji": "🔐", "homepage": "https://waiaas.ai", "requires": { "bins": ["waiaas"], "env": ["WAIAAS_SESSION_TOKEN"] }, "install": [{ "id": "waiaas-cli", "kind": "node", "package": "@waiaas/cli", "bins": ["waiaas"], "label": "Install WAIaaS CLI (source: https://github.com/minhoyoo-iotrust/WAIaaS)" }] } }
---

# WAIaaS — Self-Hosted Crypto Wallet for AI Agents

> **Your private keys should never live inside your agent process.** WAIaaS is a local daemon that holds keys in an isolated process, enforces spending policies, and requires human approval for high-value transactions. If your agent is compromised, the attacker cannot drain the wallet.

## When to Use

**USE this skill when:**

- "What's my wallet balance?"
- "Send 100 USDC to 0xAlice"
- "Swap 500 USDC for ETH on Base"
- "Supply 1 ETH to Aave on Arbitrum"
- "Show my DeFi positions"
- "What NFTs do I own?"

**NOT for:**

- Fiat payments or bank transfers
- Centralized exchange trading (Binance, Coinbase, etc.)
- Creating or deploying smart contracts from scratch

## Setup

The **daemon operator** (human) must set up WAIaaS before agents can use it:

```bash
npm install -g @waiaas/cli
waiaas init
waiaas start
waiaas quickset --mode testnet     # Start with testnet (Solana Devnet + EVM Sepolia)
```

`quickset` creates wallets, issues MCP session tokens, and prints a ready-to-use MCP config. Start with `--mode testnet` to verify the setup safely. Switch to `--mode mainnet` only after configuring spending policies.

**Configure spending policies** via Admin UI at `http://localhost:3100/admin` before connecting agents. WAIaaS uses default-deny — agents cannot transact until policies are configured.

> **Warning:** Do not use `--mode mainnet` until you have configured spending limits, token whitelists, and owner approval policies. Mainnet wallets handle real funds.

Connect the MCP server (pass token via environment variable):

```bash
export WAIAAS_SESSION_TOKEN="<session-token-from-quickset>"
openclaw config set mcpServers.waiaas.command "npx"
openclaw config set mcpServers.waiaas.args '["-y", "@waiaas/mcp"]'
openclaw config set mcpServers.waiaas.env.WAIAAS_SESSION_TOKEN "\${WAIAAS_SESSION_TOKEN}"
```

Or auto-register all wallets: `waiaas mcp setup --all`

> **Security:** Store session tokens in environment variables or a secrets manager, not in plaintext config files. Tokens are time-limited JWTs and can be revoked from Admin UI.

## How to Use

**Always call `connect_info` first.** It returns your accessible wallets, active policies, capabilities, and available DeFi actions.

### Core operations

- Check balance: `get_balance` or `get_assets` (includes tokens)
- Send crypto: `send_token` with `to`, `amount`, optionally `token` and `network`
- Simulate first: `simulate_transaction` to preview fees, policy tier, and balance changes before executing
- Sign messages: `sign_message` for personal_sign or EIP-712 typed data
- Transaction history: `list_transactions`, `list_incoming_transactions`

### DeFi

DeFi tools are registered as action providers. Call `connect_info` to see which are available.

- **Swap**: Jupiter (Solana), 0x (EVM), DCent Aggregator
- **Bridge**: LI.FI cross-chain, Across Protocol
- **Lending**: Aave V3 (EVM), Kamino (Solana) — supply, borrow, repay, withdraw
- **Staking**: Lido (ETH), Jito (SOL)
- **Yield**: Pendle yield trading
- **Perp**: Drift (Solana), Hyperliquid (positions, orders, markets, funding rates)
- **Prediction**: Polymarket (markets, orders, positions, P&L)

### NFT

- `list_nfts` — ERC-721, ERC-1155, Metaplex
- `get_nft_metadata` — Name, image, attributes
- `transfer_nft` — Requires APPROVAL tier by default

### Advanced

- `x402_fetch` — Auto-pay HTTP 402 responses with crypto
- `wc_connect` — WalletConnect pairing for owner approval via mobile wallet
- `build_userop` / `sign_userop` — ERC-4337 Account Abstraction
- `get_rpc_proxy_url` — RPC proxy URL for Forge/Hardhat (all tx go through policy engine)
- `encode_calldata` — Encode EVM function calls to hex for `call_contract`

## Security Model

- **Session tokens**: Agents use time-limited JWTs. Never the master password.
- **Default-deny policy**: Token whitelist, contract whitelist, spending limits, rate limits.
- **4 transaction tiers**: AUTO_SIGN → TIME_DELAY → APPROVAL → BLOCKED.
- **Kill switch**: Instantly freeze any wallet from Admin UI (`http://localhost:3100/admin`).

## Links

- Website: https://waiaas.ai
- GitHub: https://github.com/minhoyoo-iotrust/WAIaaS
- npm: `@waiaas/cli` · `@waiaas/sdk` · `@waiaas/mcp`
- ClawHub: https://clawhub.ai/minhoyoo-iotrust/waiaas-wallet

Attribution

Arry8Arry8
View sourceSee grades on GitHubMore from Arry8 →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Nft Standards

Implement NFT standards (ERC-721, ERC-1155) with proper metadata handling, minting strategies, and marketplace integration. Use when creating NFT contracts, building NFT marketplaces, or implementing digital asset systems.

458250 votes

Nft Standards

Implement NFT standards (ERC-721, ERC-1155) with proper metadata handling, minting strategies, and marketplace integration. Use when creating NFT contracts, building NFT marketplaces, or implementing digital asset systems.

401990 votes

vyper-compiler

Vyper smart contract compiler internals. Use when working on the Vyper compiler codebase — compilation pipeline, Venom IR, semantic analysis, code generation, testing, or contributing. Triggers on vyper compiler development, Venom passes, AST/semantics changes, codegen work, or test writing.

51840 votes

Flash Loan Simulator

Simulate flash loan arbitrage strategies and profitability across DeFi protocols. Use when performing crypto analysis. Trigger with phrases like "analyze crypto", "check blockchain", or "monitor market".

27190 votes

On Chain Analytics

Perform on-chain analysis including whale tracking, token flows, and network activity. Use when performing crypto analysis. Trigger with phrases like "analyze crypto", "check blockchain", or "monitor market".

27190 votes
View all in blockchain →