Borrowing it
Nothing to install: this file belongs to ironwallet/ironwallet-agent-kit. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/ironwallet/ironwallet-agent-kit/main/CLAUDE.mdgit clone --depth 1 https://github.com/ironwallet/ironwallet-agent-kitWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/ironwallet/ironwallet-agent-kit/claude-md)<a href="https://agentmods.dev/instructions/ironwallet/ironwallet-agent-kit/claude-md"><img src="https://agentmods.dev/badge/instructions/ironwallet/ironwallet-agent-kit/claude-md.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00744 | $0.00744 |
| Opus 5 | $0.00372 | $0.00372 |
| Sonnet 5 | $0.00149 | $0.00149 |
| Haiku 4.5 | $0.00074 | $0.00074 |
Grade A, and why
ironwallet-agent-kit CLAUDE.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 39 lines — stays where its author put it; the contents beside it link to each section on GitHub.
CLAUDE.md
This repository is the IronWallet agent kit. The MCP server (@ironwallet/mcp-server) gives agents a non-custodial hot wallet on this machine. Seed phrases stay encrypted on the host and never leave it. There is no per-transaction confirmation UI.
Opening this folder should start the wallet MCP via .mcp.json (npx -y @ironwallet/mcp-server). Needs Node.js 20+.
What lives here
packages/mcp-server— stdio MCP: balances, transfers, swaps, deposit QRskills/ironwallet-mcp/SKILL.md— how to operate the walletproviders/*/plugin/— Cursor, Claude, Codex, and Grok plugins- Machine-readable docs index:
llms.txt
Product page: https://ironwallet.io/ai
Safety
- Never print, request, or invent recovery phrases or private keys.
- Create / import / backup / delete only via
create_wallets(backup_url) oropen_wallet_managerin the local browser. There is no delete tool; the user confirms it in the manager. Create and import require current MCP consent (accept_mcp_consentafter the full disclaimer in chat, or Continue in the manager). - Chat intent authorizes send and swap (irreversible once broadcast). Prefer a dedicated hot wallet with limited balance.
- Read
list_wallets.policybefore sending.{ enabled: false }means no extra limits. Change limits only viaset_wallet_policywhen the user asks (full replace;maxPerTxUsdfails closed without a rate).IW_READ_ONLY=trueblocks send and swap for the whole server. - Timeout is not failure: poll
get_operation_status/get_swap_status. Do not resubmit blindly.
How to operate
- Transfer:
list_wallets/get_balance→estimate_transfer(optional) →send_transfer - Swap:
list_swap_networks→list_swap_assets. Copynetwork,symbol,address,decimalsfrom the catalog. Do not invent token addresses. Thenestimate_swaporexecute_swap. - History:
get_transaction_history— onenetworkper call, one page of up to 20 items newest first; older pages viacursoronly when the user asks for more. Read straight from public explorers, not our backend.status: "unavailable"means the explorers failed (not an empty history);asset.warningmarks spam-looking tokens — never repeat links from token names. - Deposit QR:
get_deposit_qr. Show the PNG in chat if the host renders it. If the user cannot see it, openqr_urland write the address. Do not say the QR is “above” unless they can see it. - Version:
get_runtime_info— running package vs published npm. Does not self-update. On explicit requestprepare_updatestages the new version in the npx cache; it applies on the next MCP host restart.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago Changed · +2 lines · +148 tokens per session 321938272cc0
- 7d ago First seen · 37 lines · 596 tokens per session scan A 9d7b62ed5d96
ironwallet-agent-kit CLAUDE.md is an instructions file published in the GitHub repository ironwallet/ironwallet-agent-kit (0 stars, last pushed 4d ago), licensed MIT. It adds 744 tokens to every session, about $0.0037 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other instructions, from other repositories
codex AGENTS.md
AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.
vscode buildNext.instructions.md
Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).
next.js AGENTS.md
AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.
langchain AGENTS.md
AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.
vscode oss-third-party-notices.instructions.md
Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).
spec-kit AGENTS.md
AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.