Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add mzf11125/midnight_agent_skills --skill midnight-walletgit clone --depth 1 https://github.com/mzf11125/midnight_agent_skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/mzf11125/midnight_agent_skills/midnight-wallet)<a href="https://agentmods.dev/skills/mzf11125/midnight_agent_skills/midnight-wallet"><img src="https://agentmods.dev/badge/skills/mzf11125/midnight_agent_skills/midnight-wallet/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/mzf11125/midnight_agent_skills/midnight-wallet"><img src="https://agentmods.dev/badge/skills/mzf11125/midnight_agent_skills/midnight-wallet.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00287 | $0.05800 |
| Opus 5 | $0.00143 | $0.02900 |
| Sonnet 5 | $0.00057 | $0.01160 |
| Haiku 4.5 | $0.00029 | $0.00580 |
Grade B, and why
midnight-wallet scanned grade B with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Sends data to an external URLmediumData exfiltration
A POST to an outside endpoint may be telemetry or may be exfiltration; either way the mod talks to somewhere, and you should know where.
const faucetResponse = await fetch('https://faucet.preprod.midnight.network/dust', { method: 'POST', How it starts
The opening of the file, as written. The whole thing — 738 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Midnight Wallet Operations
Wallet SDK Overview
The Midnight Wallet SDK provides a comprehensive set of tools for managing wallets on the Midnight Network. It includes support for shielded private transactions, unshielded public transactions, DUST token management, and hierarchical deterministic key derivation. The SDK is designed to work both in browser environments through wallet extensions and in Node.js environments through programmatic wallet creation.
The core entry point for wallet operations is the WalletFacade which unifies the various wallet types into a single interface. Underneath the facade the SDK implements several specialized wallet types each handling a different aspect of token management and transaction flow.
Wallets on Midnight manage three types of tokens and coins. Unshielded NIGHT tokens exist in public UTXOs visible on the ledger. Shielded coins exist in encrypted form known only to the wallet owner. DUST tokens are a special resource used to pay for transaction fees and must be generated before they can be spent.
The Wallet SDK integrates with the DApp Connector API for browser based DApps and provides standalone programmatic interfaces for server side and CLI applications.
Wallet Types
ShieldedWallet
The ShieldedWallet manages private transactions on the Midnight Network. It handles the creation and spending of shielded coins using zero knowledge proofs through the Zswap protocol. Shielded coins obscure the transaction amount and participants from public view.
Shielded operations include creating shielded coins from unshielded tokens through the shield operation. Spend operations consume existing shielded coins and produce new shielded coins or unshielded tokens as output. The wallet maintains a local state containing the user's shielded coin set that is synchronized with the Zswap protocol state.
class ShieldedWallet<S extends ShieldedCoinInfo> {
async createShieldedCoin(amount: bigint): Promise<ShieldedCoinInfo>
async spendShieldedCoin(coin: ShieldedCoinInfo): Promise<Transaction>
async getShieldedBalances(): Promise<ShieldedBalance[]>
async getShieldedCoins(): Promise<ShieldedCoinInfo[]>
}
What ships with it
4 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 738 lines · 287 tokens per session scan B 44bb1a096947
midnight-wallet is a skill published in the GitHub repository mzf11125/midnight_agent_skills (6 stars, last pushed 2mo ago), licensed MIT. It adds 287 tokens to every session and 5,800 once invoked, about $0.0014 per session on Opus 5. A static security scan graded it B with 1 finding (sends data to an external url). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
official-sui-skills
Pointer to the official Mysten Labs skills for building on Sui — language fundamentals, object model, PTBs, SDKs, publishing, upgrades, frontend integration, accessing on-chain data. Maintained upstream at github.com/MystenLabs/skills; pinned to the same ref the audit catalog derives from (see…
sui-and-move-tools
Use to get bytecode for a deployed Sui package and produce a disassembled working view. One GraphQL call fetches every module's raw bytecode bytes; sui move disassemble (already on the system, running sui prompt) produces .asm files for analysis. Trigger on "fetch this package's bytecode", "get me the .mv for package…
web3-audit
Smart contract security audit — 10 DeFi bug classes (accounting desync, access control, incomplete path, off-by-one, oracle, ERC4626, reentrancy, flash loan, signature replay, proxy), pre-dive kill signals (TVL < $500K etc), Foundry PoC template, grep patterns for each class, and real Immunefi paid examples. Use for…
sora-taira-testnet
Work against the SORA Taira testnet through its deployed Torii MCP endpoint for live account, asset, alias, contract, governance, Musubi package-registry, and transaction workflows. Use when Codex needs to inspect or mutate the Taira testnet, verify or add https://taira.sora.org/v1/mcp, prefer the curated iroha. tool…
mochi-local-sandbox
Bring up and use a Mochi-managed local Iroha sandbox plus its local Torii MCP endpoint. Use when Codex needs a reliable local devnet, needs to print or verify the codex mcp add mochi-local --url ... command, or should consume the generated .env.local and .mochi/generated/ bootstrap files for local-only development.
token-discovery-guide
Guide to discovering and evaluating new tokens — on-chain screening, red flag detection, fundamental analysis, and due diligence workflow. Covers DEX screening tools, liquidity analysis, holder distribution, and scam identification. Use when helping users research new tokens safely.