Install
$ agentstack add skill-flux-point-studios-cardano-agent-skills-cardano-cli-plutus-scripts-operator ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
cardano-cli-plutus-scripts-operator
> OPERATOR SKILL: Executes Plutus script transactions. Requires explicit human invocation due to collateral risk.
When to use
- When ready to spend from a script address
- After reviewing guidance from
cardano-cli-plutus-scripts
Operating rules (must follow)
- ALWAYS verify collateral UTxO is ADA-only
- Confirm script hash matches expected
- Validate datum/redeemer JSON before use
- REQUIRE explicit confirmation before submit
- Test on preprod/preview before mainnet
Pre-flight checklist
[ ] Network: ___________
[ ] Script file (.plutus) verified
[ ] Script hash matches on-chain
[ ] Datum JSON validated
[ ] Redeemer JSON validated
[ ] Collateral UTxO selected (ADA-only!)
[ ] Protocol parameters fresh
Execution workflow
Step 1: Verify script
# Get script hash
cardano-cli conway transaction policyid \
--script-file script.plutus
# Derive script address
cardano-cli conway address build \
--payment-script-file script.plutus \
--testnet-magic 1 \
--out-file script.addr
Step 2: Query script UTxO
cardano-cli conway query utxo \
--address $(cat script.addr) \
--testnet-magic 1
Step 3: Prepare collateral
# Must be ADA-only UTxO at your payment address
cardano-cli conway query utxo \
--address \
--testnet-magic 1
# Select one with only ADA (no tokens)
Step 4: Build script spend
cardano-cli conway transaction build \
--testnet-magic 1 \
--tx-in # \
--tx-in-script-file script.plutus \
--tx-in-inline-datum-present \
--tx-in-redeemer-file redeemer.json \
--tx-in-collateral # \
--tx-out + \
--change-address \
--out-file tx.unsigned
Step 5: Sign and submit
# Sign (collateral signer required)
cardano-cli conway transaction sign \
--tx-file tx.unsigned \
--signing-key-file payment.skey \
--testnet-magic 1 \
--out-file tx.signed
# ⚠️ CONFIRM before submit
echo "=== SCRIPT SPEND CONFIRMATION ==="
echo "Script: $(cat script.addr | head -c 20)..."
echo "Spending UTxO: "
echo "Collateral: "
echo "Output to: "
cardano-cli conway transaction submit \
--testnet-magic 1 \
--tx-file tx.signed
Debugging failed scripts
# If script fails, check execution units
cardano-cli conway transaction build \
... \
--calculate-plutus-script-cost cost.json
# Review cost.json for budget issues
cat cost.json | jq .
Safety / key handling
- Collateral is at risk if script fails unexpectedly
- Use minimal collateral (1-5 ADA typically sufficient)
- Keep datum/redeemer free of secrets
- Verify script logic on testnet first
References
cardano-cli-plutus-scripts(guidance skill)shared/PRINCIPLES.md
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: Flux-Point-Studios
- Source: Flux-Point-Studios/cardano-agent-skills
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.