Skip to main content

agenta-monero

Use when making or receiving Monero (XMR) payments. Generates addresses, sends payments, checks balances, verifies transactions, generates and verifies payment proofs, estimates fees, sweeps funds, and manages wallet operations via a self-hosted monero-wallet-rpc node. Keywords: monero, xmr, cryp...

Install this skill

or
70/100

Security score

The agenta-monero skill was audited on Jul 28, 2026 and we found 2 security issues across 1 threat category, including 2 high-severity. Review the findings below before installing.

Categories Tested

Security Issues

high line 36

Reading .env files

SourceSKILL.md
34> - `sweep_all.sh` transfers **all unlocked funds** from the wallet (or subaddress) to a single destination. A mistaken or maliciously triggered sweep can drain the entire balance.
35> - Always validate the recipient address (`validate_address.sh`) and confirm the amount before executing a send or sweep.
36> - The `.env` file contains `MONERO_WALLET_PASSWORD` and RPC credentials. It is created with `chmod 600`, but on multi-user systems, shared CI, or agent workspaces with broad read access, an attacker who reads `.env` can access the wallet and move funds. Secure the file and the system accordingly.
37
38**Use when:** generating receive addresses, sending/sweeping XMR, checking balance, verifying an incoming payment or a payment proof, estimating fees, or reconciling transactions by hash.
high line 84

Reading .env files

SourceSKILL.md
82- Start `monero-wallet-rpc` as a background process (PID stored in `$MONERO_LOCK_DIR/wallet-rpc.pid`).
83- Run `./setup.sh` and report readiness.
84- **Credentials are not emitted in stdout JSON.** They exist only in `.env` (chmod 600). If the user needs to see them, read from `.env` directly.
85
86## Quick reference
Scanned on Jul 28, 2026
View Security Dashboard
Installation guide →
GitHub Stars 2
Rate this skill
Categoryfinance
UpdatedSeptember 28, 2026
tibbar-etihw/agenta-monero