Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/stakekit/agentkit/yield-xyz-agentkit-moonpaynpx skills add stakekit/agentkit --skill yield-xyz-agentkit-moonpaygit clone --depth 1 https://github.com/stakekit/agentkitWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/stakekit/agentkit/yield-xyz-agentkit-moonpay)<a href="https://agentmods.dev/skills/stakekit/agentkit/yield-xyz-agentkit-moonpay"><img src="https://agentmods.dev/badge/skills/stakekit/agentkit/yield-xyz-agentkit-moonpay.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00101 | $0.01227 |
| Opus 5 | $0.00051 | $0.00613 |
| Sonnet 5 | $0.00020 | $0.00245 |
| Haiku 4.5 | $0.00010 | $0.00123 |
Grade A, and why
yield-xyz-agentkit-moonpay scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
- **Never call the Yield.xyz API directly** (curl/HTTP) — it requires an API key How it starts
The opening of the file, as written. The whole thing — 120 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Yield.xyz AgentKit × MoonPay
The MoonPay connector for the Yield.xyz AgentKit: MoonPay handles wallet auth and signs + broadcasts the transactions that yield-xyz-agentkit builds.
yield-xyz-agentkit (this skill's base) owns all yield logic — discovery, schemas, validator selection, balances, building unsignedTransaction (actions_enter / actions_exit / actions_manage), output formatting, and the MCP tool reference. Use it for all of that; this skill only signs and broadcasts.
MoonPay → confirm auth + wallet (provides the address)
yield-xyz-agentkit → discover yield + build unsignedTransaction
MoonPay → sign + broadcast
yield-xyz-agentkit → submit_hash + poll get_transaction
Two MCPs, One Flow
This skill requires both MCP servers connected:
| MCP | Role |
|---|---|
| Yield.xyz AgentKit | Yield discovery + transaction building (owned by the yield-xyz-agentkit skill) |
| MoonPay | Auth + wallet + sign + broadcast — wallet_list, transaction_sign, transaction_send, token_balance_list, and more |
If either MCP is missing, stop and tell the user. See references/setup.md for
connection instructions.
CRITICAL
- Never modify
unsignedTransactionbefore signing — not addresses, amounts, fees, or encoding, on any chain. If anything looks wrong, haveyield-xyz-agentkitbuild a NEW action. Modifying it will result in permanent loss of funds. - Never call the Yield.xyz API directly (curl/HTTP) — it requires an API key
and returns
401. All Yield.xyz access goes through the MCP (handled by theyield-xyz-agentkitskill).
Full Flow
Step 1 — Check MoonPay auth and wallet
Before anything else:
- Call MoonPay
wallet_listto confirm a wallet exists. - If no wallet or not authenticated, guide the user through login (they receive an email code; once verified they can proceed).
- Note the wallet address — this is the
addresstheyield-xyz-agentkitskill uses in all its calls.
What ships with it
4 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 120 lines · 101 tokens per session scan A eba83c8a85da
yield-xyz-agentkit-moonpay is a skill published in the GitHub repository stakekit/agentkit (3 stars, last pushed 1mo ago), licensed MIT. It adds 101 tokens to every session and 1,227 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
plan-experiment
Designs a structured ML experiment plan with hypothesis, model candidates, hyperparameter search space, compute budget, and experiment ordering. Invoke automatically whenever a user has a defined target and wants to start training — even if they just say "let's train a model", "I want to try a few models", or "what…
portfolio
Portfolio system knowledge base. Use when: position queries, routing strategy questions, provider integration. Not for: general code exploration (use code-explore), code review (use codex-code-review). Output: domain-specific analysis + recommendations.
prompt-proximity-architecture
Turn an approved measurement charter, ICPs, and buyer jobs into a budget-aware prompt coverage blueprint across proximity bands, aided status, information acts, journey states, roles, locales, evidence grades, partitions, and measurement lanes. Use before prompt wording to define required, optional, and prohibited…
invest
First-time fork users: run the invest-setup skill first to initialize. The main flow lives in this skill (the AI agent uses the CLI/MCP to view the portfolio / run the committee / replay decision history). The Web GUI has been retired (2026-07) — every capability is exposed via CLI subcommands / MCP tools. The backend…
invest-setup
First-time openInvest installation and onboarding. ONLY use when user explicitly says "set up invest" / "init invest" / "帮我初始化 invest", OR when invest skill's doctor returns status="needssetup". NOT for daily usage — once onboarding is done, the invest skill takes over (portfolio viewing, committee analysis, buy/sell…
invest-backup
Back up / restore openInvest's local state — memory/ (holdings, strategy, user profile, committee records, dream logs) + db/ (trade ledger, job run history, market-data cache) + .env (SMTP/API credentials) + userprofile.json. All of this data is .gitignore'd with no historical versions in git, so a single accidental…