runningoffcode

Agent Wormhole — AI skill for Claude Code

AI community

Stop self-replicating prompt payloads from writing themselves into your AI agent's config files.

How to install Agent Wormhole

This entry records only its repository, not the path inside it, so there is no exact command to give. Open runningoffcode/agent-wormhole and copy the folder into ~/.claude/skills/, or the file into ~/.claude/agents/.

What Agent Wormhole does

Stop self-replicating prompt payloads from writing themselves into your AI agent's config files.

Alternatives in AI

  • Model Config — /model-config — Choose the model you follow 705 ★
  • Memory Forge Rs — Stop resetting satisfying AI chats — edit the memory instead 474 ★
  • UltraCode Shim — Give Claude Code's ultracode mode to ANY model you already pay for 422 ★

README

Agent Wormhole

[Integration guide: payment safety, policy, confirmed top-ups and launch attestations](docs/integration.md).

[![ci](https://github.com/runningoffcode/agent-wormhole/actions/workflows/ci.yml/badge.svg)](https://github.com/runningoffcode/agent-wormhole/actions/workflows/ci.yml) [![PyPI](https://img.shields.io/pypi/v/wormhole-guard?label=pypi%20wormhole-guard)](https://pypi.org/project/wormhole-guard/) [![npm](https://img.shields.io/npm/v/wormhole-x402?label=npm%20wormhole-x402)](https://www.npmjs.com/package/wormhole-x402) [![Python](https://img.shields.io/pypi/pyversions/wormhole-guard)](https://pypi.org/project/wormhole-guard/) [![License](https://img.shields.io/badge/license-Apache%202.0-blue)](LICENSE) [![Telemetry](https://img.shields.io/badge/telemetry-none-brightgreen)](docs/limits.md#no-telemetry)

**The security layer for agentic commerce.**

**[agentwormhole.com](https://agentwormhole.com)** · [docs](https://docs.agentwormhole.com) · [dashboard](https://dashboard.agentwormhole.com) · [research](https://agentwormhole.com/research)

AI agents now read instructions they did not write, sign payments a merchant priced, and buy tokens whose metadata an attacker typed. All three are the same problem — **untrusted text reaching a model that acts** — and this is one stack that covers all three:

Surface What reaches the agent The guard
Instructions CLAUDE.md, .cursor/rules, hooks, fetched pages wormhole-guard (Python, offline, free)
Payments x402 quotes, EIP-3009 authorizations, Solana transactions wormhole-x402 (TypeScript, offline core)
Token launches names, symbols, descriptions, links the launch layer (hosted, $0.01/token)

Everything verifiable is free forever — badges, attestations, signatures, verdicts. The metered work is what costs, in USDC over x402, and an agent can pay for itself with no human in the loop.

![Launch badges — every state](docs/assets/badge-states.png)