--- name: ledger-wallet-cli description: Official Ledger wallet-cli - USB-based CLI for Ledger hardware wallet flows (account discover, receive, balances, operations, send, swap quote/execute/status, genuine-check, assets token / token-by-id), the Ledger Key Ring (ring init/encrypt/decrypt/keys/destroy — LKRP-backed encryption of files and text), and Agent Intent (agent-intent enroll/recover/list/show/sync/send — enroll or recover a remote agent's software identity, import the Ledger Sync accounts it was granted and propose EVM payments for human review, no device required, never broadcasts, a separate trust model from `ring`). Use for any wallet-cli command execution and for mapping informal requests to the right command. --- # wallet-cli USB-based CLI for Ledger wallet flows. Networks: **bitcoin**, **ethereum**, **solana** (mainnet + testnets). Run from repo root: `pnpm --silent wallet-cli start [flags]` > **Concepts & rationale:** for _why_ a command behaves the way it does, or to surface a safety rule that this skill states tersely (genuine check, receive-address verification, sessions, sandbox, device contention), read [`references/business-logic.md`](references/business-logic.md). > **Session first:** When invoked without a specific task, **immediately run `session view`** — do not ask the user what to do first. Show the result, then ask what to do next. If labels exist, skip `account discover`. > **Sandbox:** `account discover`, `receive` (without `--no-verify`), `send` (without `--dry-run`), `genuine-check`, `swap execute`, `earn deposit` (without `--dry-run`), `earn withdraw` (without `--dry-run`), `ring init` **must** use `dangerouslyDisableSandbox: true` — these open the device over USB (via the node-webusb DMK transport) and are blocked by USB restrictions. `ring encrypt`, `ring decrypt`, `ring destroy`, `agent-intent enroll`, `agent-intent recover`, `agent-intent sync`, `agent-intent send` (without `--dry-run`) never open the device but **also** need the bypass — they're blocked by OS keychain access restrictions instead (`agent-intent enroll`/`recover` also hold a WebSocket to the Trustchain relay). `ring keys` needs neither, and neither does `agent-intent list`/`show`: they only read the local session file, so they run without the bypass. > **Device contention:** Never run two device commands in parallel — they fail with `[object Object]` or garbled APDU. Run sequentially. > **Device readiness:** Before running a device command, briefly describe what you're about to do. The CLI prompts for device interaction itself — **don't time out or kill the command**. _Exception: `genuine-check` exits immediately (`[✖] Wrong app. Open Ledger dashboard.`, exit code 4) if any currency app is open — unlike the other device commands, it targets the dashboard and has no auto-launch path. Ensure the device is on the dashboard before running; if it exits, ask the user to back out to the dashboard and re-run._ > **Ambiguous requests — ask, don't guess.** If a required parameter is missing or unclear (no recipient for `send`, no network for `account discover`, an amount with no ticker), stop and ask. A wrong guess on a hardware wallet flow can mean irreversible fund loss. --- ## Intent map Map informal phrasings to commands. Account references use a session label (e.g. `ethereum-1`). | User says | Command | | ----------------------------------------------------------------------------------- | ------------------------------------------------------------ | | "show me my wallet", "what do I have", "let's get started", no specific task | `session view` (run _immediately_, before asking anything) | | "find my accounts", "scan my wallet", "import my wallet", "set up Ethereum/Bitcoin" | `account discover ` | | "where do I send funds to", "give me my address", "deposit address" | `receive ` | | "how much do I have", "balance", "what's my ETH balance" | `balances ` | | "what did I send", "transaction history", "recent activity" | `operations ` | | "send X to Y", "transfer", "pay", "withdraw to an exchange" | `send --to
--amount ' '` | | "swap A to B", "convert", "trade ETH for BTC", "exchange" | `swap quote` -> `swap execute` -> `swap status` | | "where can I earn", "staking rates", "yield/APY", "best return on my ETH/SOL" | `earn yields [-n ]` | | "what am I staking", "my staking positions", "earn balance" | `earn positions ` | | "stake my SOL", "deposit into a vault", "earn yield on my USDC", "delegate" | `earn deposit --product --amount ''` | | "unstake", "withdraw my stake", "redeem from vault", "stop earning" | `earn withdraw …` | | "is this Ledger real", "verify authenticity", "I bought this off eBay" | `genuine-check` | | "encrypt this file / these env vars / publish tokens", "GPG alternative", "secret manager", "decrypt anywhere with my Ledger" | `ring init` -> `ring encrypt --key ` / `ring decrypt --key ` | | "what keys do I have on my ring", "list domains/projects I've encrypted under" | `ring keys` | | "wipe my key ring", "destroy the ring", "tear down LKRP membership" | `ring destroy` | | "enroll this agent", "let an agent propose intents", "set up Agent Intent for a bot" | `agent-intent enroll --profile --name --source ` (no device; blocks until approved) | | "recover this agent", "re-enroll an agent into its trustchain" | `agent-intent recover --profile ` (no device; blocks until approved) | | "what agents are enrolled", "list agent profiles" | `agent-intent list` | | "show me that agent profile", "what's the fingerprint for this agent" | `agent-intent show --profile ` | | "pull my synced accounts", "import from Ledger Sync", "sync the agent's accounts" | `agent-intent sync --profile ` (no device) | | "have the agent request a payment", "propose sending X to Y for approval" | `agent-intent send --profile --account