cloak shield
Shield
Move funds from the agent's wallet into the pool. This is the one public step, so the skill does it ahead of time and in round amounts.
ok shielded 1.5 SOL · note n_8f2c…Cloak is a zero-knowledge privacy route for AI agents on Solana. Your agent keeps its wallet and its keys. It just stops leaving a trail.
curl -fsSL https://usecloak.pro/skill.md -o .claude/skills/cloak/SKILL.md
Every observer, watching the same address.
An agent holds a wallet. It pays for an API call, swaps some tokens, mints something, pays a sub-agent for work. All of it lands on one address, permanently, for anyone to read.
That isn't only the agent's problem. It's a problem for whoever the agent works for. Their treasury, their strategy, their counterparties, the shape of their task graph — all of it reconstructable from a block explorer.
Cloak puts a route in between.
The agent deposits SOL or SPL tokens into the shielded pool and gets back a private note — a commitment that only its spending key can use. This deposit is the one public link to the agent's wallet.
To act, the agent generates a zk-SNARK on its own machine proving it owns an unspent note of at least the right amount, without saying which one. One to three seconds on ordinary hardware.
A relayer submits the transaction and covers network fees. The destination sees funds arriving from an address with no history. The pool sees a valid proof. Neither sees the agent.
Incoming payments land on one-time stealth addresses derived from the agent's viewing key. Each payer gets a different destination, so none of them can be tied together.
Each capability is one command. The agent calls it the same way it calls any other tool, and gets JSON back. Funds never leave the agent's control; relayers can submit transactions but can't spend notes.
cloak shield
Move funds from the agent's wallet into the pool. This is the one public step, so the skill does it ahead of time and in round amounts.
ok shielded 1.5 SOL · note n_8f2c…cloak pay
Settle invoices, API bills and bounties from the pool. The recipient gets the money and nothing else.
ok relayed · recipient sees a fresh addresscloak receive --stealth
Hand out a new one-time address to every payer. They each see a different destination; the agent sees one balance.
ok stealth address 3Ff…kP1 · one usecloak swap
Trade through Jupiter from inside the pool. No visible intent before the trade, so nothing to sandwich.
ok 2.5 SOL → 410.94 USDC · via jupitercloak call
Call any program from a throwaway session key funded by the pool. Mint, stake, vote. The program sees the session key, not the agent.
ok session key funded · executed · sweptcloak viewkey
Hand a read-only viewing key to an operator or auditor when you need to. Private from the world, not from the owner.
ok viewing key exported · read-onlyPeople install apps and extensions. Agents install skills. Cloak ships as one markdown file that tells an LLM agent exactly how to shield, prove, relay and receive — the commands, the JSON it gets back, the rules to follow, and what to do when something fails.
It works with the agent's existing keypair. Proofs are generated in the agent's own runtime and never leave the machine.
# add the skill to your project mkdir -p .claude/skills/cloak curl -fsSL https://usecloak.pro/skill.md \ -o .claude/skills/cloak/SKILL.md # then, in a session > /cloak pay 7xKX…9fQ 25 USDC ok note selected 0.9 SOL → 25 USDC ok proof generated 1.8s ok relayed 4Gw…Cua7 ok recipient sees fresh address, no history
# OpenClaw / ClawHub clawhub install cloak # or by hand curl -fsSL https://usecloak.pro/skill.md \ -o ~/.openclaw/skills/cloak/SKILL.md > "pay this invoice without exposing the treasury" ok cloak.pay via shielded route
# any framework: put the file in context curl -fsSL https://usecloak.pro/skill.md # the skill documents a plain CLI with --json output cloak shield 1.5 SOL cloak balance cloak pay <addr> 25 USDC cloak receive --stealth cloak swap SOL USDC 2.5
Routing a payment, a receive or a program call through Cloak costs nothing beyond the network fee the relayer pays on the agent's behalf. Private swaps carry a 0.3% protocol fee. Every unit of it is used to buy CLOAK on the open market, and the CLOAK it buys is burned.
There is no treasury cut, no team share and no discretionary spend. The fee vault is a program account anyone can read, and the buyback is a permissionless instruction anyone can trigger once the vault crosses its threshold.
Read the tokenomics →| Action | Fee | Where it goes |
|---|---|---|
| Shield / unshield | Network fee only | Relayer, as gas reimbursement |
| Pay | Network fee only | Relayer, as gas reimbursement |
| Receive | None | — |
| Interact | Network fee only | Relayer, as gas reimbursement |
| Swap | 0.3% of input | 100% CLOAK buyback, then burned |
No. A mixer pools funds and relies on obfuscation. Cloak is a shielded pool with zero-knowledge proofs: every spend is proven valid cryptographically, nothing is "mixed", and owners can disclose their own history to an auditor with a viewing key.
No. Notes can only be spent with the agent's spending key. Relayers submit transactions; they cannot move funds.
Locally, in the agent's runtime, with a small WASM prover bundled in the CLI. Typical proof time is one to three seconds.
Network fees, paid out of the shielded balance so the agent never needs a public gas wallet. Swaps add a 0.3% protocol fee, all of which buys and burns CLOAK. Nothing else is charged.
The deposit into the pool is public. Amounts are visible to whoever receives them. And privacy depends on the size of the anonymity set — the skill tells the agent to check it before making promises to the user.