Skip to content

Add OpenSea NFT automint partner skill - #120

Open
penumbraaasol wants to merge 6 commits into
zeriontech:mainfrom
penumbraaasol:add-opensea-automint-skill
Open

penumbraaasol wants to merge 6 commits into
zeriontech:mainfrom
penumbraaasol:add-opensea-automint-skill

Conversation

@penumbraaasol

Copy link
Copy Markdown

Unattended minting of OpenSea SeaDrop drops, with Zerion CLI handling funding and verification.

What it enables: discover open SeaDrop drops, judge them on live market data, fund the minting wallet on the right chain, wait for the mint window, and execute with safety rails — unsupervised.

Zerion CLI commands it composes with:
zerion positions find spendable balances per chain
zerion swap same-chain top-up
zerion bridge fund the mint chain from another
zerion portfolio confirm funds landed on the right chain
zerion history confirm the mint transaction
zerion pnl post-mint accounting

Why the combination is needed: Zerion cannot submit the mint itself — none of its chain-touching commands accept arbitrary to/data/value, and a SeaDrop mintPublic() call is not a swap, bridge, or send. Equally, a mint bot with no funding layer cannot get the right asset onto the right chain before a window opens. Each half is unusable alone for this flow.

Also documents two OpenSea data hazards that mislead any integration: the advertised floor is a listing rather than a trade, and a sold-out drop still reports MINTING.

Reference implementation: https://github.com/penumbraaasol/automint

Unattended minting of OpenSea SeaDrop drops, with Zerion CLI handling funding
and verification.

What it enables: discover open SeaDrop drops, judge them on live market data,
fund the minting wallet on the right chain, wait for the mint window, and
execute with safety rails — unsupervised.

Zerion CLI commands it composes with:
  zerion positions   find spendable balances per chain
  zerion swap        same-chain top-up
  zerion bridge      fund the mint chain from another
  zerion portfolio   confirm funds landed on the right chain
  zerion history     confirm the mint transaction
  zerion pnl         post-mint accounting

Why the combination is needed: Zerion cannot submit the mint itself — none of
its chain-touching commands accept arbitrary to/data/value, and a SeaDrop
mintPublic() call is not a swap, bridge, or send. Equally, a mint bot with no
funding layer cannot get the right asset onto the right chain before a window
opens. Each half is unusable alone for this flow.

Also documents two OpenSea data hazards that mislead any integration: the
advertised floor is a listing rather than a trade, and a sold-out drop still
reports MINTING.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

@bashalex bashalex left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I would request changes before merging. The funding/minting split makes sense, but the instructions overstate the external bot’s safeguards.

Reviewed PR commit 048315b and the referenced automint implementation at 55fdffe.

  1. [P1] Gas limits are checked but never enforced on the signed transaction. The advertised gas ceiling checks an estimate, but sendTransaction receives only to, data, and value. Fees can be recalculated above the ceiling. Fee-estimation failure also lets execution proceed, counting gas as zero. Pass validated fee/gas bounds into signing and fail closed when estimates fail.

  2. [P1] Continuous mode silently ignores the documented lifetime cap. run does not forward flags.cap. I reproduced that run --live --cap 0.05 leaves both cap and budget unset. The separate --budget check excludes gas and uses the earlier discovery price. The PR should not advertise bounded unattended spending until the executor enforces a total budget immediately before signing.

  3. [P1] The package invocation is unverified and currently broken. Line 17 recommends npx automint, but npm currently returns “Not Found”; the linked repository declares package opensea-mint-bot and binary mint. If somebody publishes automint, that command could execute unrelated code. Remove it, pin a reviewed source revision, and apply the repository’s required 15-day dependency cooldown to installation.

  4. [P1] Successful simulation does not validate the transaction’s intent. The bot’s gated-stage fallback accepts API-provided to/data/value without checking the destination, selector, collection, recipient, or quantity. The price ceiling checks the public-stage price instead of the returned transaction’s unit cost. An unintended transfer can simulate successfully. Restrict this integration to locally constructed public mints, or validate the fallback transaction before signing.

  5. [P2] The funding examples fund the treasury, not the separate mint wallet. Both examples use --wallet treasury. Swap output returns there, and bridging defaults to the same wallet. Add --to-address <mint-address> for bridging and an explicit transfer after swapping. Include mint-wallet creation/address discovery so the isolation advice is executable.

  6. [P2] The main example cannot mint unattended. The live command omits --yes. After waiting for the window, the bot prompts; without a TTY it cancels. Keystore unlocking also needs unattended configuration. Document both prerequisites, with spending limits established before enabling unattended execution.

  7. [P2] “A bid is escrowed” is false for this EVM flow. That claim gives misleading confidence in exit liquidity. OpenSea says collection offers preauthorize wallet funds; funds move only upon acceptance. Offers can become unfunded or be canceled. Treat them as a market signal, not a guaranteed exit. OpenSea documentation

Minor fixes: missing required YAML frontmatter, missing README registration, and nonexistent capabilities/agent.md reference.

I verified the execution issues with isolated mocks; no live transactions were made. This was a targeted review, not a full audit of the external bot or its dependencies.

penumbraaasol and others added 5 commits September 9, 2026 17:43
…isites

Instructions no longer overstate the external bot's safeguards, and the
upstream defects the review identified are fixed in the implementation
(automint b0affc0): gas bounds are now bound to the signed transaction and
fail closed when fees cannot be estimated; `run` forwards --cap and the total
is enforced against onchain price plus real gas immediately before signing;
and API-provided transactions are validated for destination, selector,
collection, recipient and quantity before signing, priced off the returned
transaction rather than the public-stage price.

Skill changes here:

- Removed `npx automint`. The package is unpublished and that name resolves to
  nothing today, so the command was both broken and a supply-chain hazard.
  Replaced with a pinned source checkout and a note to apply the dependency
  cooldown.
- Funding examples now fund the mint wallet rather than the treasury. Added
  wallet creation and address discovery, `--to-address` for bridging, and an
  explicit transfer after swapping, so the isolation advice is executable.
- Documented the two prerequisites for unattended execution that otherwise fail
  silently: `--yes`, since the confirmation prompt resolves to "no" without a
  TTY, and MINT_KEYSTORE_PASSWORD for unlocking, with spending limits set
  before enabling it.
- Corrected "a bid is escrowed". Collection offers are pre-authorised; funds
  move only on acceptance and an offer can become unfunded or be cancelled.
  Described as the best available exit signal, not a guaranteed exit.
- Added the required YAML frontmatter, registered the skill in README.md, and
  fixed the reference to capabilities/agent-management.md.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Also validates the fee recipient on API-provided transactions, closing the last
gap in the intent check.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The previous pin referenced a zerion-ai commit rather than an automint one.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Reframes the skill around the split proposed in review: Zerion owns a native
mint primitive for execution and fund safety, and automint is reduced to
discovery and scheduling.

automint no longer signs anything. All key material has been removed from it —
keystore deleted, wallet client removed, wallet commands dropped, and the
private-key environment variables no longer read. The minting address is
resolved from `zerion wallet list`, so simulation and balance checks run
against the wallet Zerion would actually sign with, and its policies are
surfaced before arming.

Execution delegates to `zerion mint <chain> <contract>`, passing the drop
rather than prebuilt calldata. Forwarding bytes Zerion did not construct would
leave its policies applying to an opaque blob instead of real intent, which is
the concern the split exists to address.

Until that primitive ships, a live run validates the mint and reports the
intent rather than executing, and the skill says so. Discovery, scoring and
scheduling work today.

Protocol notes for the primitive — verified selectors, the shared four-argument
layout across mint entrypoints, decodable custom errors, the
409-while-inactive and sold-out-still-reports-MINTING hazards, and the
requirements a scheduling caller needs — are in the reference repository at
docs/mint-primitive-spec.md.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The previous pin referenced a zerion-ai commit rather than an automint one.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants