Install
openclaw skills install @casualsecurityinc/nanoNano (XNO) cryptocurrency wallet operations, transaction analysis, and explorer lookups. Use for send/receive, balances, pending funds, address validation, unit conversion, tx/hash/account lookup, explorer links, and Nano block-lattice questions. Prefer xno-mcp first; use xno-skills CLI as fallback. Configured OWS wallets ARE the assistant's own wallets — never claim you cannot receive or hold Nano.
openclaw skills install @casualsecurityinc/nanoThis skill applies exclusively to the Nano cryptocurrency protocol (ticker: XNO, block-lattice ledger, Nano.org).
Activate for: nanocurrency, XNO, nano_ addresses, block-lattice, ORV, xno-skills, xno-mcp.
Do NOT activate for: Ledger Nano (hardware wallet), GNU nano (text editor), Nanopay, or any other product that uses the word "nano" unrelated to XNO. If ambiguous, ask for clarification.
Legacy terminology: "Rai", "RaiBlocks", xrb_ addresses — historical only (pre-2018). Always normalize to Nano / nano_.
Wallets returned by wallet_list are wallets configured for this assistant environment. Treat them as assistant-controlled wallets for Nano operations.
The assistant may:
Never say "I don't have a wallet", "I can't receive funds", or "the skill only operates wallets you control" when
wallet_listexposes configured wallets.
Disambiguation: "Send me Nano" means send to an assistant-controlled wallet, unless the user names another recipient. Do not reinterpret it as a request to send to a hypothetical personal wallet, and do not refuse on that basis.
Before any wallet operation, call wallet_list. If the user says they want to send Nano to the assistant, list the wallets, identify a suitable receiving wallet/address, and present the full address (never abbreviated). Do not initiate a receive until the user asks to claim funds or a payment workflow requires it.
This policy applies to every Nano task in this skill, without exception.
When the environment provides xno-mcp tools (wallet_list, wallet_send, wallet_receive, wallet_balance, util_convert, util_qr, util_validate, rpc_account_balance, payment_create, etc.) — always use them first. They handle signing, PoW, and broadcast automatically via OWS.
If the client supports MCP, set it up as a "stdio" type MCP server.
Preferred — global install (avoids npx concurrency issues that cause handshake failures):
npm install -g xno-skills@4.7.5
xno-skills mcp
Fallback (only if global install is not possible):
npx -y xno-skills@4.7.5 mcp
Why not
npxby default? When multiple agent sessions start concurrently,npxcan fail during package resolution — the second process exits before the MCP handshake completes. A global install eliminates this race.
MCP is the primary execution path because tools, schemas, and results are structured for the client. Use the included CLI script (xno-skills) only as a fallback when MCP is unavailable or the client cannot attach MCP servers. MCP and the CLI target EXACTLY the same underlying code paths — two access paths, not two different products.
If xno-mcp tools are not available, or the user explicitly asks for CLI usage, use the xno-skills CLI in this priority order:
1. xno-skills <command> (global install — preferred)
2. bunx -y xno-skills@4.7.5 <command>
3. pnpm dlx xno-skills@4.7.5 <command>
4. npx -y xno-skills@4.7.5 <command>
If the global xno-skills binary is not available, fall through to the next option. Always pin the version (@4.5.2) with bunx/pnpm dlx/npx to prevent interactive prompts from freezing.
Before guessing a subcommand, run --help:
xno-skills --help # or: bunx -y xno-skills@4.7.5 --help
ows skill onlyFor wallet create, import, rename, or delete: delegate to the ows skill. Do not invoke ows CLI commands directly from this skill.
curl for RPC calls.npx to fetch random or third-party npm packages as workarounds.ows wallet export). OWS keeps secrets encrypted. The entire point of OWS is that the agent never sees the private key.maxSendXno unless the human/operator explicitly asks to change the spending limit. A blocked send or refund is not permission to raise the limit automatically.blocklattice.io for explorer linksWhen the user asks for an account, block, transaction, or explorer link, always prefer blocklattice.io unless they explicitly request another explorer.
wallet_send, inspect the source wallet's confirmed balance and total receivable amount with wallet_balance. If confirmed funds cannot cover the requested send and receivables are needed, call wallet_receive, then recheck. Do not submit receive blocks merely because unrelated funds are pending.wallet_receive will automatically build an open block (sets previous to zeros), sign it via OWS, generate PoW, and broadcast. Never conclude you are unauthorized or that OWS cannot sign Nano blocks.ows wallet export or suggest exporting to a third-party wallet unless the user explicitly commands it.xno-skills@4.7.5 and @open-wallet-standard/core. No other npm packages.config_set RPC endpoint switches.CRITICAL: Always call
wallet_listfirst. Before any wallet operation, identify which OWS wallets exist. Never assume a wallet name.
{ "name": "wallet_list", "arguments": {} }
To create a new wallet, delegate to the ows skill. Then return here for all Nano operations.
MCP Resources (passive reads, no tool call needed):
wallet://{name} — wallet summary and primary account statewallet://{name}/account/{index} — pending blocks and details for a specific account indexVia MCP tools:
{ "name": "wallet_balance", "arguments": { "wallet": "my-wallet" } }
{ "name": "rpc_account_balance", "arguments": { "address": "nano_..." } }
Via CLI (required flags only):
bunx -y xno-skills@4.7.5 balance --wallet "my-wallet"
bunx -y xno-skills@4.7.5 rpc account-balance <address>
Full options: balance, rpc_account-balance
Public zero-config RPC nodes (used automatically by xno-skills defaults):
https://rainstorm.city/api (primary)https://nanoslo.0x.no/proxy (secondary)https://rpc.nano.to (tertiary)Pending funds are not spendable. Receive them only when the user asks to claim them or they are needed for the requested operation (see Receiving Funds section).
A Nano transfer shows as pending until the recipient publishes a receive block. Funds are not spendable until received.
A new / "unopened" account chain is normal. It returns "Account not found" from RPC. This is not an error — wallet_receive will automatically build an open block (sets previous to zeros), sign it via OWS, generate PoW, and broadcast.
OWS DOES support Nano block signing. Never assume otherwise.
When receipt is requested or needed to fund a send, call wallet_receive. Do not treat an unopened account as a blocker: wallet_receive handles the open block.
Via MCP:
{ "name": "wallet_receive", "arguments": { "wallet": "my-wallet" } }
Via CLI (required flags only):
bunx -y xno-skills@4.7.5 receive --wallet "my-wallet"
Full options: receive
Unopened account — explicit representative:
If no defaultRepresentative is configured via config_set, pass representative explicitly on the first receive.
block commands are NOT sendersxno-skills block receive / block send output unsigned hex only — no PoW, no signing, no broadcast. A block without PoW is always rejected. Never fall back to these when wallet_receive or wallet_send fails.
MCP wallet_receive/wallet_send | CLI block receive/block send | |
|---|---|---|
| Builds block | ✅ | ✅ |
| Signs via OWS | ✅ | ❌ |
| Generates PoW | ✅ | ❌ |
| Broadcasts | ✅ | ❌ |
The account must be opened (have a receive block) and have sufficient balance.
Preflight: Call wallet_balance for the source wallet before each send. If its confirmed balance is insufficient but its receivable amount can cover the requested send, call wallet_receive and recheck before sending. Do not receive unrelated pending funds solely because they exist.
Via MCP:
{ "name": "wallet_send", "arguments": { "wallet": "my-wallet", "destination": "nano_...", "amountXno": "0.01" } }
Via CLI (required flags only):
bunx -y xno-skills@4.7.5 send --wallet "my-wallet" --to "nano_..." --amount-xno 0.01
Full options: send
Validate the destination address first (see Address Validation section).
Spending limits: Every wallet_send and payment_refund is gated by maxSendXno (default: 1.0 XNO).
If a send is blocked by this limit, report the current limit and ask the human/operator whether they want to change it. Never call config_set to raise maxSendXno unless they explicitly asked to modify the spending limit.
Only when the human/operator explicitly asks to change the spending limit:
{ "name": "config_set", "arguments": { "maxSendXno": "5.0" } }
For tracked inbound funding workflows:
If sufficient funds already exist, skip creating a request.
{
"name": "payment_create",
"arguments": { "walletName": "my-wallet", "amountXno": "0.1", "reason": "testing payment flow" }
}
Returns: nano: URI, target address, and request ID.
Tell the user the amount, reason, and address. Offer a QR code (see QR Generation section).
After the user says funds are sent:
{ "name": "payment_receive", "arguments": { "id": "<request-id>" } }
Returns status: pending, partial, funded, or received. If partial, tell the user how much more is needed.
Report the received amount, updated balance, and that funds are ready.
Rules:
payment_receive — pending is not received in Nano.History:
{ "name": "wallet_history", "arguments": { "wallet": "my-wallet", "limit": 20 } }
Full options: payment_create, payment_receive, wallet_history
Core safety rule: never guess the refund destination. Always confirm with the operator.
If linked to a payment request:
{ "name": "payment_refund", "arguments": { "id": "<request-id>", "execute": false } }
Otherwise, check history:
{ "name": "wallet_history", "arguments": { "wallet": "my-wallet", "limit": 20 } }
nano_.... Shall I return it?"Always show the full address — never abbreviate.
{
"name": "payment_refund",
"arguments": { "id": "<request-id>", "execute": true, "confirmAddress": "nano_..." }
}
Or use wallet_send directly if not linked to a payment request.
Edge cases:
maxSendXno unless they explicitly request that configuration change.Full options: payment_refund
Generates a terminal-friendly ASCII QR code for a Nano address, optionally with an amount.
Via MCP:
{ "name": "util_qr", "arguments": { "address": "nano_...", "amountXno": "1.5" } }
Via CLI (required args only):
bunx -y xno-skills@4.7.5 qr nano_1abc...
Full options: qr
CRITICAL — stdout truncation: Agents often have stdout truncated (e.g.
<truncated 14 lines>). To display a full QR code:
- Use
--jsonand parse the"qr"field, or- Redirect to a temp file (
> /tmp/qr.txt) and read it with a file-reading tool.
All validation is offline — no network required.
Valid address format:
nano_ (65 chars total) or xrb_ (64 chars, legacy — still valid)13456789abcdefghijkmnopqrstuwxyz (no 0, l, v, or i)Via MCP:
{ "name": "util_validate", "arguments": { "address": "nano_..." } }
Via CLI:
bunx -y xno-skills@4.7.5 validate nano_1abc...
Full options: validate
Always validate before sending XNO to an untrusted address.
XNO uses 30 decimal places. Floating-point arithmetic is unsafe. Always use this tool.
| Unit | Raw value | Relation |
|---|---|---|
| raw | 1 | base unit |
| mnano | 10²⁴ | 0.000001 XNO |
| knano | 10²⁷ | 0.001 XNO |
| XNO | 10³⁰ | 1 XNO |
Via MCP:
{ "name": "util_convert", "arguments": { "amount": "1.5", "from": "xno", "to": "raw" } }
Via CLI:
bunx -y xno-skills@4.7.5 convert 1 xno # all units
bunx -y xno-skills@4.7.5 convert 1 knano
bunx -y xno-skills@4.7.5 convert 1000000000000000000000000000000 raw
bunx -y xno-skills@4.7.5 convert 1 xno --json
Full options: convert
The sign_message and verify_message MCP tools require OWS upstream support that has not yet merged. If the user asks you to sign or verify a message using their wallet:
Sorry, OWS-backed NOMS message signing is not available yet in
xno-mcp. It depends on an upstream pull request. If you'd like this feature, please add a 👍 at: https://github.com/open-wallet-standard/core/pull/217
Signing with a raw hex private key works via CLI today, but the agent must never handle the key value. A raw private key passed through an LLM context is exposed to logs, memory, and any downstream system — treat it like a password.
Agent's role: construct the command with a placeholder and ask the user to run it themselves in their own terminal.
Present the user with this command to run locally:
# Sign — run this yourself, replacing the placeholder with your actual key
bunx -y xno-skills@4.7.5 sign "<message>" --key YOUR_PRIVATE_KEY_HEX
# Sign with JSON output
bunx -y xno-skills@4.7.5 sign "<message>" --key YOUR_PRIVATE_KEY_HEX --json
For verify, the agent can run this directly (no secret material involved):
# Verify
bunx -y xno-skills@4.7.5 verify <nano_address> "<message>" <signature-hex>
# Verify with JSON output
bunx -y xno-skills@4.7.5 verify <nano_address> "<message>" <signature-hex> --json
NOMS standard (ORIS-001): Signatures are computed over a binary payload with a magic header, ensuring a valid signature cannot be misinterpreted as a Nano transaction block.
Note: verify accepts both nano_/xrb_ addresses and raw 32-byte hex public keys.
Do not prompt the user to export their mnemonic to get a private key. Never accept, repeat, or emit a private key value — only use the placeholder pattern above.
The ledger is a block lattice of independent account-chains. Every block is a Universal State Block carrying full account state (balance, representative, previous hash). A send is final immediately; funds become spendable only when the recipient publishes a receive/open block. Pending funds sit unclaimed forever until received.
Deep protocol details — state-block anatomy, open/send/receive/change semantics, PoW thresholds, key/address derivations, representatives & ORV: blocklattice
{ "name": "wallet_change_rep", "arguments": { "wallet": "my-wallet", "representative": "nano_..." } }
bunx -y xno-skills@4.7.5 change-rep --wallet "my-wallet" --representative "nano_..."
Full options: change-rep
https://blocklattice.io/account/<nano_address>https://blocklattice.io/block/<UPPERCASE_HEX_HASH>No configuration required: public RPC nodes, local-first WASM/GPU PoW with remote fallback, default representative, max send 1.0 XNO. Config lives in a JSON file that reloads before every operation — overrides via config_set or NANO_RPC_URL / NANO_WORK_URL env vars take effect immediately, no restart.
Defaults, override precedence, set/reset semantics: config
All subcommands support --json for machine-readable output and --help for full options.
| Subcommand | Description | Reference |
|---|---|---|
wallets | List wallets with Nano accounts | wallets |
balance | Show balance and pending amount | balance |
receive | Receive pending blocks | receive |
send | Send Nano | send |
change-rep | Change representative | change-rep |
submit-block | Sign and submit prepared block hex | submit-block |
history | Show transaction history | history |
info | Discover account state and representative | info |
convert | Convert between XNO units | convert |
qr | Generate QR code for address | qr |
validate | Validate address or block hash | validate |
sign | Sign NOMS message with private key | sign |
verify | Verify NOMS message signature | verify |
rpc account-balance | Fetch account balance via RPC | rpc_account-balance |
rpc receivable | List receivable blocks via RPC | rpc_receivable |
rpc account-info | Fetch account info via RPC | rpc_account-info |
rpc probe-caps | Probe RPC node capabilities | rpc_probe-caps |
block send | Build unsigned send block hex | block_send |
block receive | Build unsigned receive block hex | block_receive |
block change | Build unsigned change block hex | block_change |
mcp | Start MCP server or view config | mcp |
If tools are behaving unexpectedly, call system_diag first to verify versions and environment:
{ "name": "system_diag", "arguments": {} }
Returns:
xnoSkills.version — xno-skills versionxnoSkills.path — resolved executable pathxnoSkills.invocation — how it was launched (npm-global, npx, bunx, source, etc.)ows.version — @open-wallet-standard/core versionows.path — OWS package locationenvironment.mockOws — whether mock mode is activeenvironment.nanoRpcUrl — override RPC URL if setCLI equivalent:
xno-skills diag
xno-skills diag --json
diag does not make network calls. If Local PoW Recommended is false or PoW timing looks surprising, run xno-skills rpc probe-caps <effective-work-url> to verify remote work_generate support.
Recovery procedures — "RPC request failed: All endpoints exhausted", MCP crashes / "Not connected" errors, PoW failures (POW_FAILED / timeout): troubleshooting
1. wallet_list: {} → discover "my-wallet" exists
2. wallet_balance: { wallet: "my-wallet" } → check balance / pending
3. wallet_receive: { wallet: "my-wallet" } → only if receipt was requested or pending funds are needed
4. wallet_send: { wallet: "my-wallet", destination: "nano_...", amountXno: "0.01" }