npx skills add ...
npx skills add okx/onchainos-skills --skill okx-agentic-wallet
Operate OKX Onchain OS wallets and execute or inspect on-chain transactions. Use for wallet login/status/accounts/addresses/balances/holdings; receive/send/transfer; swaps, bridges, limit orders, contract calls, gas estimation, simulation, broadcast, and tracking; Bitcoin UTXO/BRC-20/inscriptions; signing, approvals, wallet policy/export, public-address portfolios, security checks, and audit logs.
npx skills add okx/onchainos-skills --skill okx-agentic-wallet
Wallet and on-chain execution skill using the onchainos CLI. It covers wallet lifecycle, Gas Station, DEX swaps, cross-chain bridges, limit-order strategies, transaction gateway operations, public-address portfolios, security checks, and audit logs.
Match the user intent to a row, then read that row's linked file first — it holds the flow. Read only the matched file; do not load other rows' files. Each file links its own deeper files (cli-reference, troubleshooting) at the bottom via explicit links — open those when the flow needs them; never construct a file path yourself.
| User Intent | Reference |
|---|---|
| Sign in / connect / social login (Google / Apple / Email) / logout; add / switch account; login status | wallet |
| Deposit / top up / receive a token; my receive address or QR code | funding |
| Check my (logged-in) balance / holdings, including BTC or a BRC-20 ticker | wallet |
| Bitcoin UTXO-specific queries, management, or FAQ / definitions | utxo-cli-reference |
| Send / transfer native, ERC-20, SPL, BTC, BRC-20, or SUI tokens | wallet |
| Call a contract (approve / deposit / withdraw / custom function), including a SUI PTB | wallet |
| Transaction history / tx detail / order status; sign a message (personalSign / EIP-712) | wallet |
| Policy / spending limit / whitelist; export wallet / mnemonic; MEV protection for a contract-call; third-party Solana plugin write pre-flight | wallet |
| Apple-login wallet differs from the OKX Wallet App / "missing" balance; rename a wallet or account; how transaction signing works (TEE) | account-faq |
Pay gas with a stablecoin on Solana; enable / disable / change default gas token / status; a send / contract-call returns gasStationUsed or a Gas Station Confirming; Gas Station FAQ / "check order" | gas-station |
| Swap / trade / buy / sell / convert tokens; quote; best route; calldata-only swap; liquidity sources; ERC-20 approval for a DEX | swap |
| Bridge / cross-chain swap / move tokens between chains; bridge quote / fee comparison; supported bridges; track cross-chain arrival | bridge |
| Limit order: buy dip / take profit / stop loss / buy above; cancel / list / resume limit (strategy) orders | strategy |
| Broadcast a signed / raw tx; estimate gas price / gas-limit; simulate a tx; track a broadcast order | gateway |
A given public address's balance / holdings / total value (0xAbc… / a Solana address) | portfolio |
| Token / honeypot safety; DApp / URL phishing; tx or signature pre-check; check / list / revoke token approvals (ERC-20 / Permit2) | security |
| Export / locate audit log, view command history | audit-log |
Preflight checks: At the start of each thread, complete the checks in _shared/preflight.md.
--help only when the matched reference does not provide the required syntax, the installed CLI rejects the documented command or flag, or version drift is suspected. Do not run --help routinely before a command whose syntax is already explicit and verified in the current thread. Load the matched domain's -cli-reference.md only when its return-field schema or examples are needed.--chain accepts numeric chain IDs and human-readable names. Resolution rules and the supported-chain matrix live in _shared/chain-support.md. If <100% confident of a chain name, run onchainos wallet chains.
Some state-changing commands return confirming (exit code 2) when the backend needs user confirmation. The response carries message (prompt to show) and next (what to do after they confirm).
message and ask for confirmation.next (usually: re-run the same command with --force appended). For wallet send, do not query wallet balance between confirmation and the re-run; the server validates balances and gas.Never pass --force on the FIRST invocation of a state-changing command. Add --force only after all of: (1) you ran the command once without it, (2) the CLI returned a Confirming response (exit code 2, "confirming": true), (3) you displayed message and the user explicitly confirmed.
1.5 ETH), never base units.< 0.01, show full precision.$1.2M, $340K); sort holdings by USD value descending.0x1234...abcd); native tokens with empty tokenAddress → (native).wETH, stETH, wBTC, xOKB…) and its price differs >50% from the base token, add an inline price unverified flag and suggest onchainos token price-info to cross-check.clientId, API keys, private keys, seed phrases, or passwords. Never expose: accessToken, refreshToken, apiKey, secretKey, passphrase, sessionKey, sessionCert, teeId, saTeeId, encryptedSessionSk, signingKey, raw tx data. Show raw accountName (never raw accountId to the user).Credentials corrupted / "please login again" error the local credential store is unreadable — don't retry the same command, re-authenticate the user with wallet login. See wallet-troubleshooting.md.txHash, signature, contract address) MUST be echoed verbatim, character-for-character from the most recent CLI stdout. Never reproduce an identifier from memory, expand an abbreviated form, or re-type it across messages — re-invoke the command that produced it; for a wallet address, use wallet addresses. Never paraphrase, normalize case, insert spaces, or line-break inside an identifier. Always display the full txHash.0x-prefixed, 42 chars; Solana Base58, 32–44 chars. Validate before sending.executeResult is false → show executeErrorMsg, do NOT broadcast.block > warn > empty. Top-level action = highest priority from riskItemDetail. An empty action means only that no risk was detected within the checks performed; it is not proof that the asset, DApp, signature, or transaction is safe.riskLevel / isHoneyPot / taxRate client-side, since the CLI owns the matrix and hand-derived rules drift from it. security token-scan --trade-direction → per-token action (block / pause / warn / safe) plus top-level combinedAction (severity block > pause > warn > safe). swap quote / swap swap → per-route action (ok / warn / block) plus reason. The CLI only classifies; you decide the interaction: halt on block, require explicit yes/no on pause, and surface the reason and ask on warn. For safe, ok, or an empty action.unsignedInfo) response marks a transaction as gas-free, the native-token balance pre-check is skipped, so the transaction can succeed even when the user holds zero native token. This is server-authoritative — the client never sets, requests, or overrides it; the backend chooses eligible transactions (e.g. X Layer AA mode, Solana TEE-sponsored), while all other transactions still require native token for gas. NEVER: preemptively tell the user they must top up native token before a send / swap — a sponsored transaction may still go through; let it attempt and surface a backend insufficient-balance error only if one actually occurs.