Rendu depuis le dépôt source en conservant titres, exemples, code, tableaux, liens et images.
xrpl
Each rule under rules/ is self-contained: an incorrect example, a correct example, and links to upstream xrpl.js source, xrpl.org docs, and (where available) an XRPL Developer Portal code sample. Use the index below to jump to the rule that fits the task.
This skill is not an API reference. For exhaustive type signatures, see js.xrpl.org. For XLS protocol specs, use the companion `xrpl-standards` skill — when work touches AMM, MPT, NFToken, Credentials, Batch, etc., load both skills.
Read first: Security
These four rules are non-negotiable. Funds have been lost over every one of them.
- `security-partial-payment` — always credit `delivered_amount`, never `Amount` on incoming payments. Partial-payment inflation is the canonical XRPL exchange exploit.
- `security-validate-meta` — a preliminary
tesSUCCESSdoes not mean the tx was applied. Only validated-ledger meta is authoritative. - `security-lastledgersequence` — never submit without
LastLedgerSequence. Without it a transaction can replay weeks later. - `security-validate-destination-tag` — honor
requireDestTag; a missing tag on a custodial destination loses funds.
What to read when
Map the user's task to the rules to consult before writing code.
| User's task or phrase | Read these rules |
|---|---|
| "Credit an incoming payment", "deposit handler", "watch for payments" | security-partial-payment, security-validate-meta, read-pagination-marker |
| "Sign and submit", "send a transaction", "send XRP" | tx-autofill-before-sign, tx-submitandwait, security-lastledgersequence, tx-handle-tec-codes |
| "Set up an exchange deposit address", "custodial account" | security-validate-destination-tag, wallet-regular-key-for-hot-wallets |
| "Generate a wallet", "key management" | wallet-secure-entropy, wallet-prefer-ed25519, wallet-regular-key-for-hot-wallets |
| "Connect to rippled", "websocket", "reconnect" | client |
| "Balance math", "convert XRP / drops", "IOU value" | amounts |
| "Retry a failed tx", "tec error" | tx-handle-tec-codes, tx-idempotent-retry, tx-submitandwait |
| "List trust lines / NFTs / offers", "accountlines", "accountobjects" | read-pagination-marker |
| "Audit our XRPL integration" | Read all security-* rules first, then amounts and wallet-*. |
Full rule index
Impact tags below match each rule file's frontmatter (CRITICAL, HIGH, MEDIUM).
Security
- `security-partial-payment` —
CRITICAL— Readdelivered_amount, notAmount - `security-validate-meta` —
CRITICAL— Wait forvalidated: truebefore crediting - `security-lastledgersequence` —
CRITICAL— Always setLastLedgerSequence - `security-validate-destination-tag` —
CRITICAL— HonorrequireDestTagon destination
Amounts & numbers
- `amounts` —
CRITICAL— Drops +BigIntfor XRP,bignumber.jsfor IOUs, never JSnumber; respect the 15-digit IOU mantissa
Client & connection
- `client` —
HIGH— One sharedClientper app,wss://overhttps://, trust the built-in reconnect, always disconnect on shutdown
Wallet & signing
- `wallet-secure-entropy` —
CRITICAL—Wallet.generate()only; never hand-rolled entropy - `wallet-prefer-ed25519` —
MEDIUM— Default to ed25519 - `wallet-regular-key-for-hot-wallets` —
HIGH— UseSetRegularKeyso the master key can be disabled
Transactions & submission
- `tx-autofill-before-sign` —
HIGH—client.autofill(tx)before signing - `tx-submitandwait` —
HIGH— PrefersubmitAndWaitoversubmit - `tx-handle-tec-codes` —
HIGH— Distinguishtec*(applied, failed) fromtem*/tef*/ter*(not applied) - `tx-idempotent-retry` —
HIGH— ReuseSequenceorTicketon retry - `read-pagination-marker` —
MEDIUM— Loop onmarkerfor paginated requests
Code samples
The rules in this skill explain what to do and why. When you need a runnable, end-to-end example — how to actually construct, sign, and submit a transaction — go to the XRPL Developer Portal code samples. They are maintained by XRPLF and stay current with xrpl.js. Prefer them over inventing example code.
When the user asks "how do I send a payment / mint an NFT / set up an escrow" and the answer requires runnable code, fetch the matching sample and adapt it — do not paraphrase the structure from memory.
How to Use
Once you have picked a rule from the table above, read its file:
Read <skill-dir>/rules/<rule-name>.md<skill-dir> resolves to wherever the skill is installed — ~/.claude/skills/xrpl/ for a user-level Claude Code install, .claude/skills/xrpl/ for a project-level install, /mnt/skills/user/xrpl/ on claude.ai, or a plugin-managed path. Don't hard-code the directory; rely on the path the host resolves.
Each rule file contains:
- Frontmatter —
title,impact(CRITICAL / HIGH / MEDIUM),tags, and where applicablexrpl_js_source,upstream_docs,code_sample. Fields with no good link are omitted; treat any of these as optional metadata. - Why it matters — one or two sentences explaining the failure mode.
- Incorrect example — what the broken code typically looks like.
- Correct example — the idiomatic fix.
- Notes — edge cases, related amendments, version caveats.
- See also — explicit links back to upstream xrpl.js source files, xrpl.org protocol docs, and (where it exists) a dev-portal code sample.
Companion skill: xrpl-standards
If the task touches a specific XLS amendment (AMM, MPT, NFToken, Credentials, Batch, DID, Clawback, Permissioned DEX, etc.), load the `xrpl-standards` skill alongside this one. That skill holds the raw spec text — field definitions, transaction formats, ledger objects, failure conditions — that this skill deliberately does not duplicate.
Authoritative external resources
- xrpl.js API reference: https://js.xrpl.org
- xrpl.js source: https://github.com/XRPLF/xrpl.js
- Protocol docs: https://xrpl.org/docs
- Code samples: https://github.com/XRPLF/xrpl-dev-portal/tree/master/_code-samples
- Standards (XLS): load the `xrpl-standards` skill
