verify_ledger_firmware
Verify a connected Ledger device's firmware against a known-good manifest, returning a structured verdict on authenticity and update status.
Instructions
READ-ONLY firmware-pinning check (issue #325 P3). Reads the connected Ledger's Secure Element firmware version + MCU bootloader version + device target_id via the dashboard-level getDeviceInfo APDU (CLA=0xE0 INS=0x01), asserts them against a hardcoded canonical manifest covering Nano S Plus / Nano X / Stax / Flex. REQUIRES the device to be in DASHBOARD MODE — no app open. Ask the user to close every Ledger app (return to the dashboard / home menu) before calling. Returns one of: verified (firmware in known-good list), warn (at or above floor but not in known-good — likely a fresh Ledger release we haven't manifest-bumped; surface to user but proceed), below-floor (firmware below the supported floor — refuse signing until upgraded via Ledger Live Manager), unknown-device (target_id doesn't match any known model — too-new MCP / discontinued / counterfeit), wrong-mode (an app is open — close apps and retry), no-device (no Ledger over USB), error (unexpected failure). One USB round-trip; never throws — surfaces every failure as a structured verdict for the agent to relay.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||