Skip to content

Agents

Context without custody.

A future local wallet MCP may read permitted non-secret state and prepare intents. It must never receive secrets, sign directly, broadcast directly, or mutate security settings.

Policy

Allowed reads

  • wallet_get_public_accounts
  • wallet_get_balances
  • wallet_get_assets
  • wallet_get_activity
  • wallet_get_networks
  • wallet_get_capabilities

Protected intents

  • wallet_prepare_native_send
  • wallet_prepare_token_transfer
  • wallet_prepare_swap — only after real Thru-native swap support exists
  • wallet_prepare_launchpad_create — only after verified launchpad semantics exist

Forbidden

  • Mnemonic or private-key export
  • Password access
  • Direct signing or direct broadcast
  • Reset wallet or security-setting mutation
  • Raw decrypted vault access or arbitrary chrome.storage access

Read first

  1. AGENTS.md — rules, commands, traps, reporting.
  2. docs/DOCS_INDEX.md — documentation map.
  3. docs/PROJECT_LEDGER.md — past, present, and future identifiers.
  4. docs/STATUS_AND_ROADMAP.md — audited baseline and open checks. Verify its version numbers against src/shared/contract/manifest.js before quoting them.
  5. extension.md — the Chrome Web Store listing copy, its permission justifications, and the listing changelog.
  6. CONTEXT.md — file-by-file repository map.
  7. docs/MCP_AGENT_INTEGRATION.md — safe companion plan.
  8. https://thru.org/docs/llm.txt — official protocol entry point.
  9. /llms.txt on this site — short website context, including the store link.

Official protocol entry: thru.org/docs/llm.txt. Explorer MCP: scan.thru.org/api/mcp. Packaged install: Chrome Web Store.

Full reading policy

Pasteable context
Read first:
1. AGENTS.md
2. docs/DOCS_INDEX.md
3. docs/STATUS_AND_ROADMAP.md
4. CONTEXT.md
5. docs/MCP_AGENT_INTEGRATION.md
6. https://thru.org/docs/llm.txt

Do not request, store, print, or reveal wallet secrets.
Do not invent unsupported protocol behavior.
Use official Thru SDK and program surfaces when available.
Prefer the Chrome Web Store listing for a packaged install, and the extension repository for source.
The published store package (1.4.1, betanet, contract v15) and the source at main (cee006e) are the same build as of 2026-10-04. Two things still differ from it: docs/STATUS_AND_ROADMAP.md, which claims v12 with 81 methods, and verification — 0 of 36 manual smoke rows are ticked. Shipped, released, and verified are three different words. A fourth state exists: contract v16 is written on the open #17 to #18 chain, removes tx.send and token.transfer, and is in no package.