wallet
Health Warn
- License — License: NOASSERTION
- Description — Repository has a description
- Active repo — Last push 0 days ago
- Low visibility — Only 6 GitHub stars
Code Fail
- exec() — Shell command execution in .agents/skills/brand/scripts/extract-colors.cjs
- fs module — File system access in .agents/skills/brand/scripts/extract-colors.cjs
- fs module — File system access in .agents/skills/brand/scripts/inject-brand-context.cjs
- child_process — Shell command execution capability in .agents/skills/brand/scripts/sync-brand-to-tokens.cjs
- fs module — File system access in .agents/skills/brand/scripts/sync-brand-to-tokens.cjs
- fs module — File system access in .agents/skills/brand/scripts/validate-asset.cjs
- fs module — File system access in .agents/skills/design-system/scripts/embed-tokens.cjs
- fs module — File system access in .agents/skills/design-system/scripts/generate-tokens.cjs
Permissions Pass
- Permissions — No dangerous permissions requested
No AI report is available for this listing yet.
Desktop EVM Wallet for agentic DeFi
Ekubo Wallet
Ekubo Wallet is a native GPUI desktop wallet for EVM accounts used by people,
local AI agents, and WalletConnect dapps. One tray-first process owns encrypted
state and private keys. The separately bundled ekubo-wallet-mcp-bridge speaks
stdio for local agent harnesses; the wallet application itself has no
command-line, terminal, or webview mode.
[!WARNING]
Windows and Linux key-storage limitation: the current builds store raw
account keys and the SQLCipher database key in a per-user credential service
that does not isolate them to Ekubo Wallet. Same-user malware, including a
prompt-injected local agent that can execute programs as the user, can extract
those keys outside the wallet and bypass policy and native review. Read the
platform threat-model section
before using either build with valuable accounts.
User-facing installation and usage documentation lives at
docs.ekubo.org/wallet. This repository retains
the source, build instructions, and implementation-specific security
documentation.
Development
The workspace requires Rust 1.94.1 or newer.
cargo fmt --all --check
cargo clippy --locked --workspace --all-targets --all-features -- -D warnings
cargo test --locked --workspace --all-features
GPUI is pinned to Zed revision52b2927a1bac46be5d50ad341ac00b665e13764b; gpui-component is pinned to26cc9366abb27ccedce386ac99a615a8fa7018da. The application consumes only the
Apache-2.0 GPUI infrastructure, not Zed's GPL workspace/UI crates.
See architecture, the system-wide
threat model, the code-oriented
security boundary, and the
release process. The enforced policy vocabulary—including
flat prepared-envelope matchers and the review effect—is documented in
policy authoring.
License
See LICENSE.
Reviews (0)
Sign in to leave a review.
Leave a reviewNo results found