Skip to content
Terramike edited this page Oct 1, 2026 · 12 revisions

xrpl-muse-skill v0.14.1

Trade the XRP Ledger from the terminal — any token pair — with a hard safety boundary between proposing a trade and signing it.

  • xrpl-trade builds the transaction, autofills it against the live network, shows you everything (account, network, assets + issuers, amounts, limit price, max spend, fee, expiry), seals it in a hash-bound proposal envelope, and stops. It never sees your seed. It cannot submit.
  • xrpl-sign is the only program that touches the seed. It re-verifies the envelope, enforces the policy (spend caps, allowlisted pairs and destinations, fee cap), and signs only with explicit human approval of that exact proposal hash.

Current release: v0.14.1 (security release)

A third-party audit of v0.14.0 raised seven findings; all seven are fixed with focused regression tests:

  • Spend-state recovery — corrupt state fails closed; xrpl-sign recover-state rebuilds from the audit log
  • Approval-display sanitization — ANSI/OSC, control chars, bidi overrides rendered as visible escapes
  • Strict policy validation — unknown keys, wrong types, truthy strings, bad addresses rejected
  • Exact proposal hashes — --approve requires the full 64-hex hash; prefixes are inspection-only
  • Forensic ledger ranges — history scans pin one validated ledger
  • Pinned NFT verification — seller vs issuer shown separately
  • Delivered-value flows — only tesSUCCESS delivered_amount counted

Also in v0.14.1: the Farm Helper (xrpl-trade farm — read-only Farmers Union add-in), nft-new crash fix + scan trim, trusted-links updates, and an nft-trail holder fix (reported holder verified against the validated ledger).

Safety first: read-only by default

Fresh installs start read-only: every market read, balance check, token safety screen, and proposal build works keyless — signing is refused until you deliberately leave read-only mode with the typed xrpl-trade live ceremony.

Start here

Install

git clone https://github.com/terramike/xrpl-muse-skill
cd xrpl-muse-skill
pip install -r requirements-locked.txt
export PATH="$PWD/bin:$PATH"

xrpl-trade setup            # address + network (never the seed)

Wiki


Propose → approve → sign. Nothing moves without your hash.

Clone this wiki locally