VeilSAFE
Bankr Skills equip builders with plug-and-play tools to build more powerful agents.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Wraps the @veil-cash/sdk CLI and optionally uses Bankr Agent API to sign & submit unsigned deposit/register transactions. Supports ETH and USDC privacy pools on Base.
Assumptions
- Veil SDK is installed via one of these methods:
Option A: Global npm install (recommended)
npm install -g @veil-cash/sdk
This makes the veil CLI available globally.
Option B: Clone from GitHub
mkdir -p ~/.openclaw/workspace/repos cd ~/.openclaw/workspace/repos git clone https://github.com/veildotcash/veildotcash-sdk.git cd veildotcash-sdk npm ci && npm run build
- Bankr skill is configured:
~/.clawdbot/skills/bankr/config.json
- Veil secrets are stored outside git:
~/.clawdbot/skills/veil/.env.veil(chmod 600)~/.clawdbot/skills/veil/.envforRPC_URL(recommended — Veil queries a lot of blockchain data, so public RPCs will likely hit rate limits)
Usage
cd veil # Generate keypair scripts/veil-init.sh # Print keypair JSON scripts/veil-keypair.sh # Ask Bankr for address scripts/veil-bankr-prompt.sh "What is my Base wallet address? Respond with just the address." # Check balances (ETH pool — default) scripts/veil-balance.sh --address 0x... # Check balances (USDC pool) scripts/veil-balance.sh --address 0x... --pool usdc # Deposit via Bankr — ETH (build unsigned tx + submit) scripts/veil-deposit-via-bankr.sh ETH 0.011 --address 0x... # Deposit via Bankr — USDC (auto-handles approve + deposit) scripts/veil-deposit-via-bankr.sh USDC 100 --address 0x... # Withdraw / transfer / merge (local VEIL_KEY required) scripts/veil-withdraw.sh ETH 0.007 0x... scripts/veil-withdraw.sh USDC 50 0x... scripts/veil-transfer.sh ETH 0.001 0x... scripts/veil-transfer.sh USDC 25 0x... scripts/veil-merge.sh ETH 0.001 scripts/veil-merge.sh USDC 100
Notes
veil-bankr-prompt.shimplements the same submit/poll loop as the Bankr ski
4029e336cef5OBSERVED · 2026-10-09Install
Commands as the repository documents them. They are shown, not run.
npm install -g @veil-cash/sdk
git clone https://github.com/veildotcash/veildotcash-sdk.git
npm install -g @veil-cash/sdk
git clone https://github.com/veildotcash/veildotcash-sdk.git
npm install -g @veil-cash/sdk
Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| openclaw | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
---
name: veil
description: Privacy and shielded transactions on Base via Veil Cash (veil.cash). Deposit ETH or USDC into private pools, withdraw/transfer privately using ZK proofs. Manage Veil keypairs, check private/queue balances across all pools, and submit deposits via Bankr. Use when the user wants anonymous or private transactions, shielded transfers, or ZK-based privacy on Base.
metadata: {"clawdbot": {"emoji": "🌪️", "homepage": "https://veil.cash", "requires": {"bins": ["node", "curl", "jq"]}}}
---
# Veil
This skill wraps the `@veil-cash/sdk` CLI to make Veil operations agent-friendly.
## Supported Assets
| Asset | Decimals | Description |
|-------|----------|-------------|
| ETH | 18 | Native ETH (via WETH) |
| USDC | 6 | USDC on Base |
## What it does
- **Key management**: generate and store a Veil keypair locally
- **Status check**: verify configuration, registration, and relay health
- **Balances**: `veil balance` (queue + private) — supports `--pool eth|usdc`
- **Deposits via Bankr**: build **Bankr-compatible unsigned transactions** and ask Bankr to sign & submit (handles ERC20 approve + deposit for USDC)
- **Private actions**: `withdraw`, `transfer`, `merge` for ETH or USDC — executed locally using `VEIL_KEY` (ZK/proof flow)
## File locations (recommended)
- Veil keys: `~/.clawdbot/skills/veil/.env.veil` *(chmod 600)*
- Bankr API key: `~/.clawdbot/skills/bankr/config.json`
## Quick start
### 1) Install the Veil SDK
**Option A: Global npm install (recommended)**
```bash
npm install -g @veil-cash/sdk
```
**Option B: Clone from GitHub**
```bash
mkdir -p ~/.openclaw/workspace/repos
cd ~/.openclaw/workspace/repos
git clone https://github.com/veildotcash/veildotcash-sdk.git
cd veildotcash-sdk
npm ci && npm run build
```
### 2) Configure Base RPC (recommended)
Veil queries a lot of blockchain data (UTXOs, merkle proofs, etc.), so public RPCs will likely hit rate limits. A dedicated RPC from [Alchemy](https://www.alchemy.com/), [Infura](https://www.infura.io/), or similar is recommended.
Put `RPC_URL=...` in **one** of these:
- `~/.clawdbot/skills/veil/.env` *(preferred)*
- or the SDK repo `.env` (less ideal)
Example:
```bash
mkdir -p ~/.clawdbot/skills/veil
cat > ~/.clawdbot/skills/veil/.env << 'EOF'
RPC_URL=https://base-mainnet.g.alchemy.com/v2/YOUR_KEY
EOF
chmod 600 ~/.clawdbot/skills/veil/.env
```
### 3) Make scripts executable
```bash
chmod +x scripts/*.sh
```
### 4) Generate your Veil keypair
```bash
scripts/veil-init.sh
scripts/veil-keypair.sh
```
### 5) Check your setup
```bash
scripts/veil-status.sh
```
### 6) Find your Bankr Base address
```bash
scripts/veil-bankr-prompt.sh "What is my Base wallet address? Respond with just the address."
```
### 7) Check balances
```bash
# ETH pool (default)
scripts/veil-balance.sh --address 0xYOUR_BANKR_ADDRESS
# USDC pool
scripts/veil-balance.sh --address 0xYOUR_BANKR_ADDRESS --pool usdc
```
### 8) Deposit via Bankr (sign & submit)
```bash
# Deposit ETH
scripts/veil-deposit-via-bankr.sh ETH 0.011 --address 0xYOUR_BANKR_ADDRESS
# Deposit USDC (auto-handles approve + deposit)
scripts/veil-deposit-via-bankr.sh USDC 100 --address 0xYOUR_BANKR_ADDRESS
```
### 9) Withdraw (private to public)
```bash
scripts/veil-withdraw.sh ETH 0.007 0xYOUR_BANKR_ADDRESS
scripts/veil-withdraw.sh USDC 50 0xRECIPIENT
```
### 10) Transfer privately
```bash
scripts/veil-transfer.sh ETH 0.01 0xRECIPIENT
scripts/veil-transfer.sh USDC 25 0xRECIPIENT
```
### 11) Merge UTXOs
```bash
scripts/veil-merge.sh ETH 0.1
scripts/veil-merge.sh USDC 100
```
## References
- [SDK Reference](references/sdk-reference.md) — CLI commands, environment variables, error codes
- [Troubleshooting](references/troubleshooting.md) — Common issues and debugging tips
## Notes
- For **Bankr signing**, this skill uses Bankr's Agent API via your local `~/.clawdbot/skills/bankr/config.json`.
- For **USDC deposits** via Bankr, the skill automatically submits the ERC20 approval transaction first, then the deposit transaction.
- For privacy safety: never commit `.env.veil` or `.env` files to git.Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (3 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
4029e336cef5full audit observations/trust-audit/skill/bankrbot__veil.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 4029e336cef5 | SAFE | B | 89 | first audit |
Questions
What does the Veil skill do?
Bankr Skills equip builders with plug-and-play tools to build more powerful agents.
Is Veil safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Veil access on my machine?
The audit observed that it reaches the network. Each of those is consistent with what it says it does. Secrets in the source: none found.
Which assistants does Veil work with?
Its documentation mentions openclaw. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (4029e336cef5), read on 2026-10-09. The repository is watched, and a new audit runs when it changes — this is the first audit.