Atlas / Skills / bankrbot / Veil

VeilSAFE

skills/bankrbot/veil

Bankr Skills equip builders with plug-and-play tools to build more powerful agents.

Verdict
SAFE
Grade
B
Trust score
89 /100
Version
—
Hosts
1 documented
License
—
Stars
1,202
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Wraps the @veil-cash/sdk CLI and optionally uses Bankr Agent API to sign & submit unsigned deposit/register transactions. Supports ETH and USDC privacy pools on Base.

Assumptions

  • Veil SDK is installed via one of these methods:

Option A: Global npm install (recommended)

npm install -g @veil-cash/sdk

This makes the veil CLI available globally.

Option B: Clone from GitHub

mkdir -p ~/.openclaw/workspace/repos
cd ~/.openclaw/workspace/repos
git clone https://github.com/veildotcash/veildotcash-sdk.git
cd veildotcash-sdk
npm ci && npm run build
  • Bankr skill is configured:
  • ~/.clawdbot/skills/bankr/config.json
  • Veil secrets are stored outside git:
  • ~/.clawdbot/skills/veil/.env.veil (chmod 600)
  • ~/.clawdbot/skills/veil/.env for RPC_URL (recommended — Veil queries a lot of blockchain data, so public RPCs will likely hit rate limits)

Usage

cd veil

# Generate keypair
scripts/veil-init.sh

# Print keypair JSON
scripts/veil-keypair.sh

# Ask Bankr for address
scripts/veil-bankr-prompt.sh "What is my Base wallet address? Respond with just the address."

# Check balances (ETH pool — default)
scripts/veil-balance.sh --address 0x...

# Check balances (USDC pool)
scripts/veil-balance.sh --address 0x... --pool usdc

# Deposit via Bankr — ETH (build unsigned tx + submit)
scripts/veil-deposit-via-bankr.sh ETH 0.011 --address 0x...

# Deposit via Bankr — USDC (auto-handles approve + deposit)
scripts/veil-deposit-via-bankr.sh USDC 100 --address 0x...

# Withdraw / transfer / merge (local VEIL_KEY required)
scripts/veil-withdraw.sh ETH 0.007 0x...
scripts/veil-withdraw.sh USDC 50 0x...
scripts/veil-transfer.sh ETH 0.001 0x...
scripts/veil-transfer.sh USDC 25 0x...
scripts/veil-merge.sh ETH 0.001
scripts/veil-merge.sh USDC 100

Notes

  • veil-bankr-prompt.sh implements the same submit/poll loop as the Bankr ski
Read from source at commit 4029e336cef5OBSERVED · 2026-10-09
02

Install

Commands as the repository documents them. They are shown, not run.

npm install -g @veil-cash/sdk
git clone https://github.com/veildotcash/veildotcash-sdk.git
npm install -g @veil-cash/sdk
git clone https://github.com/veildotcash/veildotcash-sdk.git
npm install -g @veil-cash/sdk
03

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
openclawmentioned
04

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: veil
description: Privacy and shielded transactions on Base via Veil Cash (veil.cash). Deposit ETH or USDC into private pools, withdraw/transfer privately using ZK proofs. Manage Veil keypairs, check private/queue balances across all pools, and submit deposits via Bankr. Use when the user wants anonymous or private transactions, shielded transfers, or ZK-based privacy on Base.
metadata: {"clawdbot": {"emoji": "🌪️", "homepage": "https://veil.cash", "requires": {"bins": ["node", "curl", "jq"]}}}
---

# Veil

This skill wraps the `@veil-cash/sdk` CLI to make Veil operations agent-friendly.

## Supported Assets

| Asset | Decimals | Description |
|-------|----------|-------------|
| ETH   | 18       | Native ETH (via WETH) |
| USDC  | 6        | USDC on Base |

## What it does

- **Key management**: generate and store a Veil keypair locally
- **Status check**: verify configuration, registration, and relay health
- **Balances**: `veil balance` (queue + private) — supports `--pool eth|usdc`
- **Deposits via Bankr**: build **Bankr-compatible unsigned transactions** and ask Bankr to sign & submit (handles ERC20 approve + deposit for USDC)
- **Private actions**: `withdraw`, `transfer`, `merge` for ETH or USDC — executed locally using `VEIL_KEY` (ZK/proof flow)

## File locations (recommended)

- Veil keys: `~/.clawdbot/skills/veil/.env.veil` *(chmod 600)*
- Bankr API key: `~/.clawdbot/skills/bankr/config.json`

## Quick start

### 1) Install the Veil SDK

**Option A: Global npm install (recommended)**
```bash
npm install -g @veil-cash/sdk
```

**Option B: Clone from GitHub**
```bash
mkdir -p ~/.openclaw/workspace/repos
cd ~/.openclaw/workspace/repos
git clone https://github.com/veildotcash/veildotcash-sdk.git
cd veildotcash-sdk
npm ci && npm run build
```

### 2) Configure Base RPC (recommended)

Veil queries a lot of blockchain data (UTXOs, merkle proofs, etc.), so public RPCs will likely hit rate limits. A dedicated RPC from [Alchemy](https://www.alchemy.com/), [Infura](https://www.infura.io/), or similar is recommended.

Put `RPC_URL=...` in **one** of these:

- `~/.clawdbot/skills/veil/.env` *(preferred)*
- or the SDK repo `.env` (less ideal)

Example:
```bash
mkdir -p ~/.clawdbot/skills/veil
cat > ~/.clawdbot/skills/veil/.env << 'EOF'
RPC_URL=https://base-mainnet.g.alchemy.com/v2/YOUR_KEY
EOF
chmod 600 ~/.clawdbot/skills/veil/.env
```

### 3) Make scripts executable

```bash
chmod +x scripts/*.sh
```

### 4) Generate your Veil keypair

```bash
scripts/veil-init.sh
scripts/veil-keypair.sh
```

### 5) Check your setup

```bash
scripts/veil-status.sh
```

### 6) Find your Bankr Base address

```bash
scripts/veil-bankr-prompt.sh "What is my Base wallet address? Respond with just the address."
```

### 7) Check balances

```bash
# ETH pool (default)
scripts/veil-balance.sh --address 0xYOUR_BANKR_ADDRESS

# USDC pool
scripts/veil-balance.sh --address 0xYOUR_BANKR_ADDRESS --pool usdc
```

### 8) Deposit via Bankr (sign & submit)

```bash
# Deposit ETH
scripts/veil-deposit-via-bankr.sh ETH 0.011 --address 0xYOUR_BANKR_ADDRESS

# Deposit USDC (auto-handles approve + deposit)
scripts/veil-deposit-via-bankr.sh USDC 100 --address 0xYOUR_BANKR_ADDRESS
```

### 9) Withdraw (private to public)

```bash
scripts/veil-withdraw.sh ETH 0.007 0xYOUR_BANKR_ADDRESS
scripts/veil-withdraw.sh USDC 50 0xRECIPIENT
```

### 10) Transfer privately

```bash
scripts/veil-transfer.sh ETH 0.01 0xRECIPIENT
scripts/veil-transfer.sh USDC 25 0xRECIPIENT
```

### 11) Merge UTXOs

```bash
scripts/veil-merge.sh ETH 0.1
scripts/veil-merge.sh USDC 100
```

## References

- [SDK Reference](references/sdk-reference.md) — CLI commands, environment variables, error codes
- [Troubleshooting](references/troubleshooting.md) — Common issues and debugging tips

## Notes

- For **Bankr signing**, this skill uses Bankr's Agent API via your local `~/.clawdbot/skills/bankr/config.json`.
- For **USDC deposits** via Bankr, the skill automatically submits the ERC20 approval transaction first, then the deposit transaction.
- For privacy safety: never commit `.env.veil` or `.env` files to git.
05

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (3 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (0)

No findings outside the package's declared scope.

Gates applied: no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha 4029e336cef5full audit observations/trust-audit/skill/bankrbot__veil.json · Report an issue / request a re-scan
06

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-094029e336cef5SAFEB89first audit
07

Questions

What does the Veil skill do?

Bankr Skills equip builders with plug-and-play tools to build more powerful agents.

Is Veil safe to install?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.

What can Veil access on my machine?

The audit observed that it reaches the network. Each of those is consistent with what it says it does. Secrets in the source: none found.

Which assistants does Veil work with?

Its documentation mentions openclaw. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (4029e336cef5), read on 2026-10-09. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement