nunchuk-coldcard-hsm
Pass
Audited by Gen Agent Trust Hub on May 10, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions to install the
ckcc-protocolpackage from the official Python package index. This is the legitimate and expected tool for interacting with Coldcard hardware devices. - [COMMAND_EXECUTION]: The skill makes use of standard command-line utilities including
ckcc(Coldcard CLI),nunchuk(the author's CLI tool), andjqfor processing transaction data and configuring wallet settings. These operations are essential for the skill's stated purpose. - [DATA_EXPOSURE]: The instructions involve processing Bitcoin wallet descriptors, PSBT (Partially Signed Bitcoin Transaction) files, and JSON policy files locally. These are standard artifacts in hardware wallet workflows and are handled without unauthorized external transmission.
Audit Metadata