AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Xrpl

skill-peersyst-xrplskills-xrpl · by Peersyst

Apply opinionated rules and security patterns to JavaScript and TypeScript code that uses the xrpl.js client library to interact with the XRP Ledger. Use when users want to write a new XRPL integration with xrpl.js, review or refactor existing xrpl.js code, sign or submit a transaction, construct or credit a payment, work with issued currencies, AMM, NFToken, escrow, or payment channels, query ac…

No reviews yet
0 installs
11 views
0.0% view→install

Install

$ agentstack add skill-peersyst-xrplskills-xrpl

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access Used
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-peersyst-xrplskills-xrpl)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
2mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Xrpl? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

xrpl

Each rule under rules/ is self-contained: an incorrect example, a correct example, and links to upstream xrpl.js source, xrpl.org docs, and (where available) an XRPL Developer Portal code sample. Use the index below to jump to the rule that fits the task.

This skill is not an API reference. For exhaustive type signatures, see js.xrpl.org. For XLS protocol specs, use the companion [xrpl-standards](../xrpl-standards) skill — when work touches AMM, MPT, NFToken, Credentials, Batch, etc., load both skills.

Read first: Security

These four rules are non-negotiable. Funds have been lost over every one of them.

  • [security-partial-payment](rules/security-partial-payment.md) — always credit delivered_amount, never Amount on incoming payments. Partial-payment inflation is the canonical XRPL exchange exploit.
  • [security-validate-meta](rules/security-validate-meta.md) — a preliminary tesSUCCESS does not mean the tx was applied. Only validated-ledger meta is authoritative.
  • [security-lastledgersequence](rules/security-lastledgersequence.md) — never submit without LastLedgerSequence. Without it a transaction can replay weeks later.
  • [security-validate-destination-tag](rules/security-validate-destination-tag.md) — honor requireDestTag; a missing tag on a custodial destination loses funds.

What to read when

Map the user's task to the rules to consult before writing code.

| User's task or phrase | Read these rules | |---|---| | "Credit an incoming payment", "deposit handler", "watch for payments" | security-partial-payment, security-validate-meta, read-pagination-marker | | "Sign and submit", "send a transaction", "send XRP" | tx-autofill-before-sign, tx-submitandwait, security-lastledgersequence, tx-handle-tec-codes | | "Set up an exchange deposit address", "custodial account" | security-validate-destination-tag, wallet-regular-key-for-hot-wallets | | "Generate a wallet", "key management" | wallet-secure-entropy, wallet-prefer-ed25519, wallet-regular-key-for-hot-wallets | | "Connect to rippled", "websocket", "reconnect" | client | | "Balance math", "convert XRP / drops", "IOU value" | amounts | | "Retry a failed tx", "tec error" | tx-handle-tec-codes, tx-idempotent-retry, tx-submitandwait | | "List trust lines / NFTs / offers", "accountlines", "accountobjects" | read-pagination-marker | | "Audit our XRPL integration" | Read all security-* rules first, then amounts and wallet-*. |

Full rule index

Impact tags below match each rule file's frontmatter (CRITICAL, HIGH, MEDIUM).

Security

  • [security-partial-payment](rules/security-partial-payment.md) — CRITICAL — Read delivered_amount, not Amount
  • [security-validate-meta](rules/security-validate-meta.md) — CRITICAL — Wait for validated: true before crediting
  • [security-lastledgersequence](rules/security-lastledgersequence.md) — CRITICAL — Always set LastLedgerSequence
  • [security-validate-destination-tag](rules/security-validate-destination-tag.md) — CRITICAL — Honor requireDestTag on destination

Amounts & numbers

  • [amounts](rules/amounts.md) — CRITICAL — Drops + BigInt for XRP, bignumber.js for IOUs, never JS number; respect the 15-digit IOU mantissa

Client & connection

  • [client](rules/client.md) — HIGH — One shared Client per app, wss:// over https://, trust the built-in reconnect, always disconnect on shutdown

Wallet & signing

  • [wallet-secure-entropy](rules/wallet-secure-entropy.md) — CRITICALWallet.generate() only; never hand-rolled entropy
  • [wallet-prefer-ed25519](rules/wallet-prefer-ed25519.md) — MEDIUM — Default to ed25519
  • [wallet-regular-key-for-hot-wallets](rules/wallet-regular-key-for-hot-wallets.md) — HIGH — Use SetRegularKey so the master key can be disabled

Transactions & submission

  • [tx-autofill-before-sign](rules/tx-autofill-before-sign.md) — HIGHclient.autofill(tx) before signing
  • [tx-submitandwait](rules/tx-submitandwait.md) — HIGH — Prefer submitAndWait over submit
  • [tx-handle-tec-codes](rules/tx-handle-tec-codes.md) — HIGH — Distinguish tec* (applied, failed) from tem* / tef* / ter* (not applied)
  • [tx-idempotent-retry](rules/tx-idempotent-retry.md) — HIGH — Reuse Sequence or Ticket on retry
  • [read-pagination-marker](rules/read-pagination-marker.md) — MEDIUM — Loop on marker for paginated requests

Code samples

The rules in this skill explain what to do and why. When you need a runnable, end-to-end example — how to actually construct, sign, and submit a transaction — go to the XRPL Developer Portal code samples. They are maintained by XRPLF and stay current with xrpl.js. Prefer them over inventing example code.

| Task | Sample | |---|---| | Construct and send an XRP payment | send-xrp | | Add a memo to a payment | send-a-memo | | Handle a partial payment safely | partial-payment | | Watch an account for incoming payments | monitor-payments-websocket | | Submit a transaction with finality and retries | reliable-tx-submission, submit-and-verify | | Pre-flight a destination's requireDestTag | require-destination-tags | | Walk paginated account_* responses | markers-and-pagination, walk-owner-directory | | Configure regular keys / disable master | assign-regular-key, disable-master-key | | Sign offline / multisign | secure-signing, multisigning | | Use Tickets for parallel submission | use-tickets | | Issued currencies / IOUs | issue-a-token, freeze, clawback | | AMM | create-amm, amm-clob | | NFToken | non-fungible-token, nft-modular-tutorials | | MPT (Multi-Purpose Tokens) | mpt-generator, mpt-sender, issue-mpt-with-metadata | | Escrow, Checks, Payment Channels | escrow, checks, claim-payment-channel | | Credentials, DID | credential, issue-credentials, verify-credential, did | | Getting started from zero | get-started, quickstart |

When the user asks "how do I send a payment / mint an NFT / set up an escrow" and the answer requires runnable code, fetch the matching sample and adapt it — do not paraphrase the structure from memory.

How to Use

Once you have picked a rule from the table above, read its file:

Read /rules/.md

` resolves to wherever the skill is installed — ~/.claude/skills/xrpl/ for a user-level Claude Code install, .claude/skills/xrpl/ for a project-level install, /mnt/skills/user/xrpl/` on claude.ai, or a plugin-managed path. Don't hard-code the directory; rely on the path the host resolves.

Each rule file contains:

  • Frontmattertitle, impact (CRITICAL / HIGH / MEDIUM), tags, and where applicable xrpl_js_source, upstream_docs, code_sample. Fields with no good link are omitted; treat any of these as optional metadata.
  • Why it matters — one or two sentences explaining the failure mode.
  • Incorrect example — what the broken code typically looks like.
  • Correct example — the idiomatic fix.
  • Notes — edge cases, related amendments, version caveats.
  • See also — explicit links back to upstream xrpl.js source files, xrpl.org protocol docs, and (where it exists) a dev-portal code sample.

Companion skill: xrpl-standards

If the task touches a specific XLS amendment (AMM, MPT, NFToken, Credentials, Batch, DID, Clawback, Permissioned DEX, etc.), load the [xrpl-standards](../xrpl-standards) skill alongside this one. That skill holds the raw spec text — field definitions, transaction formats, ledger objects, failure conditions — that this skill deliberately does not duplicate.

Authoritative external resources

  • xrpl.js API reference: https://js.xrpl.org
  • xrpl.js source: https://github.com/XRPLF/xrpl.js
  • Protocol docs: https://xrpl.org/docs
  • Code samples: https://github.com/XRPLF/xrpl-dev-portal/tree/master/_code-samples
  • Standards (XLS): load the [xrpl-standards](../xrpl-standards) skill

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.