BankrBLOCK
Bankr Skills equip builders with plug-and-play tools to build more powerful agents.
Overview
Bankr Skills equip builders with plug-and-play tools to build more powerful agents.
4029e336cef5OBSERVED · 2026-10-09Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned | |
| cursor | mentioned | |
| openclaw | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
---
name: bankr
description: Bankr is an AI crypto agent with its own wallets, a direct Wallet API and a pay-as-you-go LLM gateway, driven by the `bankr` CLI or the REST API. Use it when the user wants to trade or swap crypto or tokenized stocks, check balances or PnL, send tokens, trade perps (Hyperliquid, Avantis) or prediction markets (Polymarket), buy, sell or mint NFTs, look up prices, market data or token research, claim Merkl rewards, browse the web through the agent, launch a token or claim its fees, automate orders, sign or submit transactions, call or deploy x402 paid endpoints, store files on their wallet, or use and pay for LLMs through Bankr. Chains: Base, Ethereum, Polygon, Solana, Unichain, World Chain, Arbitrum, BNB Chain, Robinhood Chain and Arc.
metadata:
{
"clawdbot":
{
"emoji": "📺",
"homepage": "https://bankr.bot",
"requires": { "bins": ["bankr"] },
},
}
---
# Bankr
Bankr is an AI crypto agent that holds its own wallets. Two ways in, both using the same `bk_...` API key:
- **Bankr CLI** (`@bankr/cli`, recommended). It handles login, job polling and confirmations for you.
- **REST API** at `https://api.bankr.bot`. Use `/agent/*` for natural-language prompts (async jobs) and `/wallet/*` for direct, synchronous wallet operations.
**Installing this skill means downloading the whole `bankr/` folder: this `SKILL.md` plus every file in [references/](references/).** A copy of `SKILL.md` alone leaves every reference link below dead.
This file is the entry point. Topic detail lives in [references/](references/) (read the one for your task before acting), in the docs at [docs.bankr.bot](https://docs.bankr.bot), and in the OpenAPI spec at `https://docs.bankr.bot/openapi/api.yaml`. **Fetch the spec instead of guessing a route or payload.** It is the authoritative request/response schema and can be newer than this skill.
## Get an API key
**Check whether you're already authenticated.** The host may supply the key, either as `BANKR_API_KEY` or through an egress proxy that attaches it to requests. Try `bankr whoami`, or make a request, before logging in, and never ask the user to paste a key just because the variable is empty. See [host-managed credentials](references/safety.md#host-managed-credentials-no-key-on-disk).
Signing up provisions an EVM wallet (one address on every EVM chain) and a Solana wallet, so there is nothing to set up by hand.
### Headless email login (recommended for agents)
Run `bankr update` first. The flow below works on @bankr/cli 0.3.38 and later. Pass `--accept-terms` and `--key-name` explicitly: from 0.3.43 a headless login accepts the Terms by itself and picks a unique key name, but on 0.3.38 a headless login without `--accept-terms` fails after the one-time code has been used, and an omitted key name defaults to `CLI-<date>`, which collides with a key created earlier that day.
1. `bankr login email <email>` sends a one-time code.
2. Ask the user for everything in **one** message:
- the **code** from their email;
- their go-ahead on the **[Terms of Service](https://bankr.bot/terms)**. Share the link and say plainly that step 3 accepts the Terms on their behalf. **If they decline, stop.**
- any changes to the key defaults below, and a **key name** (an active key can't reuse a name).
3. Run `bankr login email <email> --code <otp> --accept-terms --key-name "<name>" [flags]`.
| New-key default | Flag to change it |
| --- | --- |
| Wallet API on | `--no-wallet-api` |
| Agent API on | `--no-agent-api` |
| Token Launch API on | `--no-token-launch` |
| Read-write | `--read-only` (for research or monitoring keys that must never transact) |
| LLM gateway off | `--llm` |
Optional hardening flags: `--allowed-ips <ips>` (IP/CIDR allowlist) and `--allowed-recipients <addresses>` (EVM/Solana send allowlist). After login, the `Features:` line shows what the key actually got.
- **The code is single-use.** From 0.3.43 the CLI retries dropped connections during login by itself. If step 3 fails, restart from step 1 for a fresh code; never re-run it with the same code.
- **Accounts with MFA on:** step 3 prints a `https://bankr.bot/mfa/confirm/...` link and waits up to five minutes for the user to approve in a browser with their passkey or authenticator app. Show the user the link, keep the command running and don't retry. If the link expires, fall back to an existing key (below). A headless login never asks for the authenticator code in the terminal; only an interactive `bankr login email` does (0.3.45+).
### Other ways in
- **Existing key:** `bankr login --api-key bk_...`. Add `--llm-key <key>` if the user has a separate gateway key. To mint a key in the browser, `bankr login --url` prints the [bankr.bot/api-keys](https://bankr.bot/api-keys) link.
- **Sign-In with Ethereum:** `bankr login siwe --private-key 0x...`. These keys start **read-only**; pass `--read-write` to allow transactions.
- Confirm the login with `bankr whoami`.
## Bankr CLI
Install with `bun install -g @bankr/cli` (or `npm install -g @bankr/cli`), and update with `bankr update`.
**`bankr --help` and `bankr <command> --help` are the command reference**, [docs.bankr.bot/cli](https://docs.bankr.bot/cli) has the full guide, and the [changelog](https://docs.bankr.bot/cli-changelog) lists what changed in each published version. Command groups: `wallet` (portfolio, transfer, swap, sign, submit), `agent` (prompt, status, cancel, skills), `tokens`, `launch`, `fees`, `project` (0.3.43+), `files`, `club`, `llm`, `x402`, `webhooks`, `config`, plus `login`, `logout` and `whoami`.
Behavior that `--help` doesn't spell out:
- **Anything that isn't a command is a prompt.** `bankr what is the price of ETH?` is the same as `bankr agent "what is the price of ETH?"`. Named commands take precedence, so a prompt that starts with a command word (`claude`, `launch`, ...) has to go through `bankr agent "..."`.
- **The shell expands `$`.** In `"Buy $50 of ETH"`,Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (10)
**`bankr --help` and `bankr <command> --help` are the command reference**, [docs.bankr.bot/cli](https://docs.bankr.bot/cli) has the full guide, and the [changelog](https://docs.bankr.bot/cli-changelog
For details, see [docs.bankr.bot/wallet-api/overview](https://docs.bankr.bot/wallet-api/overview) and [references/sign-submit-api.md](references/sign-submit-api.md). Swaps are covered in [references/t
| Scheduled commands | Bankr Club: 20 active (paused ones count). Without Club: one per Telegram or Farcaster direct-cast conversation. Creating one from the API, the terminal or a public post require
Minting a key from the dashboard or `bankr login email` can fail with `400 Name already exists` when an active key already has that name (choose another `--key-name`; from 0.3.43 an omitted name defau
Report the job ID, the exact error text, a timestamp, and the chain and tokens involved, but never the API key (`bankr config get` masks it). Support is at [help.bankr.bot](https://help.bankr.bot) and
The CLI's `Not authenticated` means it found no key in `BANKR_API_KEY` or `~/.bankr/config.json`. To log in, follow [Get an API key](../SKILL.md#get-an-api-key) in SKILL.md. In a sandbox where the hos
| 403 | `Read-only API key` | A write on a read-only key | Use a read-write key |
- **A Python 3 script** (standard library, up to 20 KB) for multi-step calculations. It needs a signed-in session or a read-write API key; read-only keys get pipelines only.
Both endpoints need `walletApiEnabled` on a read-write key, and answer `403 Wallet API access not enabled` or `403 Read-only API key` otherwise. They also enforce the key's IP allowlist and share the
| `Read-only API key` | The key can't submit transactions |
Gates applied: critical_finding, no_behavioural_pass, undeclared_transfer.
4029e336cef5full audit observations/trust-audit/skill/bankrbot__bankr.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 4029e336cef5 | BLOCK | D | 69 | first audit |
Questions
What does the Bankr skill do?
Bankr Skills equip builders with plug-and-play tools to build more powerful agents.
Is Bankr safe to install?
No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What can Bankr access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Bankr work with?
Its documentation mentions claude-code, cursor and openclaw. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (4029e336cef5), read on 2026-10-09. The repository is watched, and a new audit runs when it changes — this is the first audit.