{"id":50612407,"url":"https://github.com/tetsuo-ai/agenc-ledger-flex-app","last_synced_at":"2026-06-06T05:02:04.344Z","repository":{"id":362256082,"uuid":"1248550569","full_name":"tetsuo-ai/agenc-ledger-flex-app","owner":"tetsuo-ai","description":"AgenC-aware Ledger Flex app fork based on Ledger app-solana","archived":false,"fork":false,"pushed_at":"2026-06-03T09:27:24.000Z","size":25934,"stargazers_count":0,"open_issues_count":0,"forks_count":0,"subscribers_count":0,"default_branch":"main","last_synced_at":"2026-06-03T11:10:49.237Z","etag":null,"topics":["agentic-ai","ledger-cli","marketplace"],"latest_commit_sha":null,"homepage":"https://marketplace.agenc.tech/","language":"C","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/tetsuo-ai.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":".github/CODEOWNERS","security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":"AGENTS.md","dco":null,"cla":null}},"created_at":"2026-05-24T19:40:30.000Z","updated_at":"2026-06-03T09:27:28.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/tetsuo-ai/agenc-ledger-flex-app","commit_stats":null,"previous_names":["tetsuo-ai/agenc-ledger-flex-app"],"tags_count":2,"template":false,"template_full_name":null,"purl":"pkg:github/tetsuo-ai/agenc-ledger-flex-app","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/tetsuo-ai%2Fagenc-ledger-flex-app","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/tetsuo-ai%2Fagenc-ledger-flex-app/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/tetsuo-ai%2Fagenc-ledger-flex-app/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/tetsuo-ai%2Fagenc-ledger-flex-app/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/tetsuo-ai","download_url":"https://codeload.github.com/tetsuo-ai/agenc-ledger-flex-app/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/tetsuo-ai%2Fagenc-ledger-flex-app/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":33969883,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-26T15:22:16.424Z","status":"online","status_checked_at":"2026-06-06T02:00:07.033Z","response_time":107,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["agentic-ai","ledger-cli","marketplace"],"created_at":"2026-06-06T05:02:03.812Z","updated_at":"2026-06-06T05:02:04.339Z","avatar_url":"https://github.com/tetsuo-ai.png","language":"C","funding_links":[],"categories":[],"sub_categories":[],"readme":"\u003ch1 align=\"center\"\u003eAgenC Ledger Flex App\u003c/h1\u003e\n\n\n\n\u003cp align=\"center\"\u003e\u003cem\u003eClear-signing for AgenC marketplace transactions on Ledger devices.\u003c/em\u003e\u003c/p\u003e\n\n\u003cp align=\"center\"\u003e\n  \u003cimg src=\"doc/agenc-ledger-stack.svg\" alt=\"AgenC clear-signing stack: marketplace kit → DMK → transport → AgenC Solana app → Ledger device\" width=\"720\"\u003e\n\u003c/p\u003e\n\n\nPrivate firmware workspace for an AgenC-aware Ledger Flex signing app.\n\nThis repository is based on Ledger's upstream\n[`app-solana`](https://github.com/LedgerHQ/app-solana) codebase. It keeps the\nSolana transaction parsing, signing, derivation, and APDU foundations, then adds\nnative AgenC instruction parsing so supported AgenC actions can be reviewed on\nthe Ledger secure screen.\n\n## Status\n\nCurrent milestone:\n\n- AgenC instruction parser + on-device display implemented in `libsol`, covering\n  the full marketplace lifecycle (see [Clear-Signing Scope](#clear-signing-scope))\n- `create_task` clear-signing covers SOL and SPL-token rewards, multi-worker and\n  non-default task types, and standalone (non-paired) creates\n- a side-by-side app named `AgenC Solana` has been built and installed on a real\n  Ledger Flex, alongside the official Ledger `Solana` app\n- clear-signing has been driven end-to-end over **Bluetooth via the Device\n  Management Kit** from the AgenC kit on a real Flex (see\n  [Clear-Signing over BLE + DMK](#clear-signing-over-ble--device-management-kit-dmk))\n- host unit tests cover the parser/display; Ragger golden-image tests cover the\n  on-device secure screens\n\nCurrent reproducible build hashes (`bin/app.sha256`), source-built for all four\nsupported devices with `APPNAME=\"AgenC Solana\"`:\n\n| Device | app.sha256 |\n|--------|------------|\n| Flex | `f9fc21c5ef1f59cf43dbc7e37770fef10c2a2624781bb1f91cbe7e814e75e10b` |\n| Stax | `bc476702c87304bcb615e4ecedcc0b34e8feaaab47aaf50d7d56ae79f60c6be5` |\n| Nano X | `997627d488971ffa564804c53798f8b87e8b3e80ef62781c711074298b176aff` |\n| Nano S+ | `90dac181bfb1d87fc5492272c3408fe62db93ea66271fe7d59146d638d341ecc` |\n\nThese supersede the earlier Flex-only `f3da723b…` build, which predates the\nexpanded create-task clear-signing coverage and needs a fresh hardware load.\n\nThis is an engineering fork, not a production Ledger Live release.\n\n## Safety Rule\n\nDo not replace the official installed Ledger `Solana` app.\n\nFor hardware testing, this fork is packaged as a separate Ledger app:\n\n```text\nAgenC Solana\n```\n\nDo not use upstream `make load` for this fork. The upstream default targets app\nname `Solana` with `--delete`. Use the guarded scripts under `tools/agenc/`\ninstead.\n\n## Clear-Signing Scope\n\nThe v1 parser focuses on the AgenC marketplace actions that matter for a first\nsecure-screen workflow:\n\n- register agent\n- create task — standalone, or as the `create_task` + `configure_task_validation`\n  review pair (which also shows the review window)\n- attach job spec\n- claim task\n- submit result\n- accept result\n- reject result\n- cancel task\n- expire claim\n\n`create_task` renders the full reviewable shape:\n\n- reward — SOL amount, **or**, for SPL-token rewards, the raw token base-unit\n  amount plus the token mint (the device cannot resolve mint decimals offline, so\n  it shows both explicitly rather than a misleading SOL-formatted value)\n- task and creator accounts\n- the 32-byte content-commitment hash (the on-chain `description` under the\n  moderation gate)\n- deadline, max workers, task type (shown when non-default), min reputation\n- program id\n\nThe device derives display fields from signed Solana transaction bytes:\n\n- program id\n- Anchor discriminator\n- instruction data\n- account indexes and account keys\n\nThe device does not trust host-provided display strings for security-critical\nreview text.\n\nSome fields are intentionally shown as incomplete when they cannot be derived\nfrom the transaction bytes alone. For example, the app does not infer settlement\nreward or cancellation refund amounts from account state.\n\n## Repository Layout\n\n- `libsol/agenc_instruction.*`\n  Native AgenC instruction parser and display model.\n- `libsol/agenc_instruction_test.c`\n  Direct parser tests and serialized Solana message fixtures.\n- `tests/application_client/agenc_cmd_builder.py`\n  Python fixture builder for AgenC transactions.\n- `tests/python/test_agenc_clear_signing.py`\n  Ragger/Speculos coverage for Flex secure-screen flows.\n- `tests/python/snapshots/flex/test_agenc_*`\n  Golden Flex screenshots for supported AgenC actions.\n- `icons/icon_agenc_*` and `glyphs/home_agenc_*`\n  Ledger icon and NBGL home glyph assets generated from the AgenC logo.\n- `tools/agenc/`\n  Safe build, load, APDU, and icon helper scripts for the side-by-side app.\n- `doc/agenc-ledger-flex.md`\n  Hardware loading notes and real-device result log.\n\n## Build\n\nBuild the side-by-side Flex app:\n\n```sh\ntools/agenc/build-flex.sh\n```\n\nThis uses Ledger's dev-tools container and builds with:\n\n```text\nAPPNAME=\"AgenC Solana\"\n```\n\nThe output is written to:\n\n- `bin/app.elf`\n- `bin/app.hex`\n- `bin/app.apdu`\n- `bin/app.sha256`\n\n## Test\n\nRun the C parser/message tests:\n\n```sh\ndocker run --rm -v \"$PWD:/app\" -w /app \\\n  ghcr.io/ledgerhq/ledger-app-builder/ledger-app-builder-lite:latest \\\n  make -C libsol clean\n\ndocker run --rm -v \"$PWD:/app\" -w /app \\\n  ghcr.io/ledgerhq/ledger-app-builder/ledger-app-builder-lite:latest \\\n  make -C libsol\n```\n\nRun focused Flex Ragger/Speculos tests:\n\n```sh\ndocker run --rm -v \"$PWD:/app\" -w /app \\\n  ghcr.io/ledgerhq/ledger-app-builder/ledger-app-dev-tools:latest \\\n  sh -lc 'rm -rf .tmp-ragger \u0026\u0026 trap \"rm -rf .tmp-ragger\" EXIT \u0026\u0026\n  mkdir -p .tmp-ragger/tmp .tmp-ragger/cache \u0026\u0026\n  TMPDIR=/app/.tmp-ragger/tmp python3 -m venv --system-site-packages .tmp-ragger/venv \u0026\u0026\n  . .tmp-ragger/venv/bin/activate \u0026\u0026\n  TMPDIR=/app/.tmp-ragger/tmp PIP_CACHE_DIR=/app/.tmp-ragger/cache \\\n    python -m pip install --no-cache-dir base58 ecdsa solders solana \"ragger[tests]\" \u0026\u0026\n  pytest tests/python/test_agenc_clear_signing.py --tb=short -v --device flex'\n```\n\n## Hardware Loading\n\nConfirm the Flex is visible:\n\n```sh\ntools/agenc/list-flex-apps.sh\n```\n\nGenerate a side-by-side offline APDU:\n\n```sh\ntools/agenc/generate-load-apdu.sh\n```\n\nLoad the app only after confirming the target is `AgenC Solana`:\n\n```sh\nAGENC_CONFIRM_SIDE_BY_SIDE_LOAD=1 tools/agenc/load-flex.sh\n```\n\nThe load script refuses to run without `AGENC_CONFIRM_SIDE_BY_SIDE_LOAD=1`.\nIt calculates `dataSize` and `installparamsSize` from `debug/app.map`, matching\nLedger SDK behavior.\n\nSuccessful hardware load parameters from the prior `f3da723b…` Flex load (recorded\non a real device; predates the expanded create-task coverage above, so a fresh load\nof the current build is needed):\n\n```text\nappName=AgenC Solana\ndataSize=512\ninstallparamsSize=345\napp.sha256=f3da723b7b8ad700598e072a7a30cd6526efab78d4b4cb32e4c3d81617d739c1\n```\n\nPost-load `listApps` confirmed both `Solana` and `AgenC Solana` installed on\nthe same Ledger Flex.\n\nThe latest loaded side-by-side build includes default clear-signing recognition\nfor the kit mainnet program id\n`HJsZ53Zb27b8QMRbQpuDngE44AdwCGxvEZr61Zmxw1xK`.\n\n## Program ID Policy\n\nThe current code recognizes the verified AgenC mainnet program id by default:\n\n```text\nHJsZ53Zb27b8QMRbQpuDngE44AdwCGxvEZr61Zmxw1xK\n```\n\nThat id now matches the kit mainnet preset and the generated kit Ledger\nfixtures. If the deployed program id changes, regenerate the kit Ledger\nfixtures and update this parser constant in the same release.\n\nIf a mainnet AgenC transaction does not show the `AgenC action` screens on the\ndevice, reject it.\n\n## Current Signed-Data Limits\n\nThe app only displays values that are present in the signed transaction bytes.\n\n- `submit_task_result` decodes AgenC artifact result data and displays the\n  artifact SHA-256 when the kit uses `artifact:sha256:*` result data.\n- `claim_task_with_job_spec` can display the task/job-spec account addresses,\n  but cannot display the job-spec hash or URI because the current protocol\n  instruction does not carry those fields in the claim instruction data.\n- `accept_task_result` and `cancel_task` cannot display reward/refund amounts\n  because those values come from on-chain task/escrow state, not the current\n  instruction data.\n\nShowing those claim and settlement commitments on-device requires a protocol\ninstruction upgrade or another commitment that is included in the bytes the\nLedger signs.\n\n## Relationship To The Kit\n\nThis repository owns firmware parsing, display, and Ledger device tests.\n\nThe AgenC Marketplace Agent Kit owns transaction construction, policy checks,\nCLI UX, and Ledger transport integration.\n\nThe intended boundary is:\n\n- kit builds and policy-checks the Solana transaction\n- Ledger app parses the signed bytes and displays trusted review fields\n- private keys remain on the Ledger device\n\n## Clear-Signing over BLE + Device Management Kit (DMK)\n\nThe AgenC Marketplace Agent Kit can drive this app over Bluetooth through Ledger's\n[Device Management Kit](https://github.com/LedgerHQ/device-sdk-ts) so AgenC mainnet\ntransactions are clear-signed on the device secure screen.\n\nThe relevant detail: DMK's Solana signer opens the app named `Solana` (the stock\napp) by default, which blind-signs AgenC instructions. To clear-sign, the kit must\nopen **this** app instead. It does so with an app-name override:\n\n- `AGENC_LEDGER_APP_NAME=\"AgenC Solana\"` (or the equivalent signer option) makes the\n  kit run `OpenAppDeviceAction({ appName: \"AgenC Solana\" })` on the DMK session and\n  pass `skipOpenApp: true` to every signer call, so the signer does not switch back\n  to the stock `Solana` app.\n- `AGENC_LEDGER_DMK_BLE=1` enables the kit's DMK Node-BLE transport.\n\n```sh\nAGENC_LEDGER_DMK_BLE=1 AGENC_LEDGER_APP_NAME=\"AgenC Solana\" \\\n  agenc-marketplace --network mainnet \\\n  --signer ledger --ledger-backend dmk --ledger-transport ble --ledger-key 0/0 \\\n  \u003ccommand\u003e\n```\n\nThe full build → install → drive-over-BLE+DMK workflow, including the kit wiring,\nis documented for agents and engineers in [`AGENTS.md`](./AGENTS.md). If a mainnet\nAgenC transaction shows a generic \"Blind signing / Unrecognized format\" screen, the\nstock `Solana` app is open instead of `AgenC Solana` — reject on the device and fix\nthe setup rather than approving blind.\n\n## Upstream\n\nUpstream base:\n\n```text\nhttps://github.com/LedgerHQ/app-solana\n```\n\nLocal remote convention:\n\n- `origin`: Ledger upstream\n- `agenc`: private AgenC app repo\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ftetsuo-ai%2Fagenc-ledger-flex-app","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Ftetsuo-ai%2Fagenc-ledger-flex-app","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ftetsuo-ai%2Fagenc-ledger-flex-app/lists"}