This is a real AI wallet skill, but it gives an agent broad authority over funds while fetching its highest-risk runtime code after install.
Install only after reviewing the upstream GitHub runtime you will actually provision, not just this package. Use test funds first, pin the wallet address, keep keys out of shell history/logs/source control, verify the native binary provenance and factory approval independently, and avoid enabling cron, auto-swap, arbitrary contract calls, token approvals, NFT transfers, or DeFi borrowing until you have clear spend limits and a way to pause execution.