nunchuk-coldcard-hsm

Pass

Audited by Gen Agent Trust Hub on May 10, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to install the ckcc-protocol package from the official Python package index. This is the legitimate and expected tool for interacting with Coldcard hardware devices.
  • [COMMAND_EXECUTION]: The skill makes use of standard command-line utilities including ckcc (Coldcard CLI), nunchuk (the author's CLI tool), and jq for processing transaction data and configuring wallet settings. These operations are essential for the skill's stated purpose.
  • [DATA_EXPOSURE]: The instructions involve processing Bitcoin wallet descriptors, PSBT (Partially Signed Bitcoin Transaction) files, and JSON policy files locally. These are standard artifacts in hardware wallet workflows and are handled without unauthorized external transmission.
Audit Metadata
Risk Level
SAFE
Analyzed
May 10, 2026, 02:53 AM