Repository navigation
User Guide
Current release: v0.14.1. New users start read-only by default — every market read, balance check, and proposal build works keyless; signing stays refused until the typed xrpl-trade live ceremony. See Security for the full safety model.
git clone https://github.com/terramike/xrpl-muse-skill.git
cd xrpl-muse-skill
pip install -r requirements-locked.txt
export PATH="$PWD/bin:$PATH"
xrpl-trade setup
xrpl-sign init-policy
xrpl-trade faucet --network testnetxrpl-trade setup asks whether to generate a new wallet (default no) and which network to use. Local generation is testnet/devnet only; selecting an existing address stores only public address/network settings. A generated testnet credential is stored separately in a typed, owner-only file bound to the network and account; it is never printed by setup or wallet creation. Do not copy it to mainnet.
xrpl-trade wallet backup --network testnet displays the testnet seed once for an offline backup. Run that command in your own terminal, not through a chat assistant, so the seed does not enter the conversation transcript. Mainnet seed creation and backup are refused by this CLI.
-
Propose: run an
xrpl-tradecommand. It builds an unsigned transaction, prints the account, network, assets and issuers, amount, price, fee, and expiry, then saves a hash-bound proposal. It does not submit. - Review: check all proposal terms and verify the full 64-character digest. For NFT buys, independently check the issuer/minter as well as the current seller. For NFT uploads, review the staged file and full digest.
- Approve and sign: Muse must bind genuine user confirmation to the exact reviewed operation before the vault supplies credentials. Mainnet signing requires a named profile and the full digest:
xrpl-sign --profile <name> --hash <full-64-character-hash> --approveThe CLI --approve flag is only an assertion. A typed command in a transcript is not proof of consent. Without the actual Muse approval and vault boundary, do not sign mainnet transactions.
Read-only policy review can use a hash prefix, but a prefix can never authorize signing.
Mainnet proposals and signing require a named entry in ~/.xrpl/profiles.json, which binds account, network, credential reference, policy file/digest, and accounting state. Create a profile file from existing supported configuration with xrpl-sign init-profiles; review the generated profile carefully. After a deliberate policy edit, review it and run:
xrpl-sign sync-profile --profile <name>The profile and policy schemas reject unknown or invalid settings. The v4 policy is testnet-locked by default. Missing per-asset spend limits block that asset; destination payments require an allowlisted address/tag. Do not weaken the policy just to silence a rejection.
The CLI refuses mainnet wallet creation and backup. Provision and store mainnet credentials in the secure vault. Mainnet giveaway credentials are also vault-only. Legacy local seeds must be removed or migrated out before mainnet signing.
Mainnet remains blocked until an operator verifies in the real Muse environment that genuine confirmation gates one-time credential injection and the proposing agent cannot modify the signer, dependencies, profiles, policy, or state. xrpl-trade doctor can inspect local files but cannot certify those runtime protections.
Other bots may use read-only and proposal commands, but do not inherit Muse's secure credential boundary. Do not use another bot for mainnet unless its own vault and approval implementation is independently verified.
Stage artwork locally, review the file and full SHA-256 digest, then supply that independently reviewed digest:
xrpl-trade nft-stage --file ~/.xrpl/media/art.png --name "Neon Drift"
xrpl-trade nft-pin-and-propose --stage <stage-id> \
--approve-stage <full-reviewed-stage-sha256>The stage digest is checked before Pinata credentials are accessed. Muse must bind the reviewed stage ID and digest into its actual approved operation; the CLI flag alone is not approval. Pinning writes externally and can leave content pinned even if a later proposal step fails. The signer separately requires the exact proposal hash approval before an NFT mint is submitted.
xrpl-trade doctor reports local profile, signer/helper, protected-file, and accounting checks plus unresolved reservations. Treat its Muse deployment status as unverified.
Never delete or truncate damaged accounting state. Recover only from a reviewed reconstruction after recording the source SHA-256; the signer preserves the damaged file and refuses to discard known liabilities. To migrate legacy accounting, use xrpl-sign migrate-state with the profile, legacy state kind, full source digest, and full reviewed migration digest. See Technical Reference for the safe recovery flow.
- Commands and flags: Command Reference
- Security model and release gate: Security
- Proposal binding, accounting, migration: Technical Reference
- Example prompts: Prompt Library
- Troubleshooting: FAQ
Propose → approve → sign. Nothing moves without your hash.