Agent skill

Token Security

by alsk1992 in alsk1992/CloddsBot

“Token security audit via GoPlus API”

— description from SKILL.md by alsk1992
MITAuto-check passedSecurity

Install Token Security

skills CLI
$ npx skills add alsk1992/CloddsBot --skill token-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install alsk1992/CloddsBot token-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/alsk1992/CloddsBot.git skills-src && mkdir -p .claude/skills && cp -r skills-src/src/skills/bundled/token-security .claude/skills/token-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
token-security
GitHub stars
2.9k
Token cost
~113 tokens
SKILL.md length
19 words
Files
2
Skills in repo
118
Repo updated
First seen
Licence
MIT

At a glance

  • Runs TypeScript scripts from its folder

About this skill

Token Security is a skill in alsk1992/CloddsBot (2.9k stars). Its SKILL.md is about 113 tokens, with 1 other file in the folder. Licence: MIT.

What it can do on your machine

Read from SKILL.md and the folder at commit c930628. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (TypeScript), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Token Security loads about 113 tokens when it runs. Until then it costs about 13 tokens; SKILL.md has 19 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~13
When it runs · the whole SKILL.md, loaded when a task matches
~113

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from alsk1992/CloddsBot at commit c930628, republished under its MIT licence (© alsk1992). 19 words, ~113 tokens.

Download SKILL.mdSave it as .claude/skills/token-security/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
token-security
description
Token security audit via GoPlus API
command
audit
emoji
🔍

Token Security Audit

Comprehensive token security analysis powered by GoPlus API - honeypot detection, rug-pull analysis, and risk scoring.

Commands

/audit <address>                  Auto-detect chain and audit token
/audit <address> --chain <name>   Audit token on specific chain
/audit help                       Show help

© alsk1992, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in src/skills/bundled/token-security of alsk1992/CloddsBot.

  • SKILL.md
  • index.ts

Open the folder on GitHubat commit c930628

Compare with similar skills

Token Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Token Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Token Security this skillalsk1992/CloddsBot2.9k—~113Automated safety check: PassMIT
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Kubernetes Network Security Auditkubeshark/kubeshark12k—~7.3kAutomated safety check: NotesApache-2.0
Native Dependency Updatemono/SkiaSharp5.6k—~4.1kAutomated safety check: PassMIT
Semgrep Security Scantrailofbits/skills7.4k—~3.7kAutomated safety check: NotesCC-BY-SA-4.0
Skillward AuditFangcun-AI/SkillWard143—~2.9kAutomated safety check: PassCustom licence

Similar skills

  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 8 days ago
    SecurityAuto-check passed
  • Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.

    12k GitHub stars~7.3k tokensUpdated 7 days ago
    SecurityAuto-check: notes
  • Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.

    5.6k GitHub stars~4.1k tokensUpdated today
    SecurityAuto-check passed
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.4k GitHub stars~3.7k tokensUpdated 5 days ago
    SecurityAuto-check: notes
  • Skillward Audit

    Fangcun-AI/SkillWard

    Security-audit a third-party skill bundle (folder with SKILL.md, or .zip / .tar.gz archive) before installing it, using the SkillWard cloud scanner.

    143 GitHub stars~2.9k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Security Audit

    TheDecipherist/claude-code-mastery

    Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.

    550 GitHub stars~1.3k tokensUpdated 5 mo ago
    SecurityAuto-check: notes

More from alsk1992/CloddsBot

All 118 skills in this repo
  • Qmd

    alsk1992/CloddsBot

    Local hybrid search for markdown notes and docs. An agent skill from alsk1992/CloddsBot.

    2.9k GitHub starsUsed in 3 repos~1.2k tokens
    Auto-check passed
  • Drift SDK

    alsk1992/CloddsBot

    Drift Protocol perpetual futures trading on Solana (direct SDK)

    2.9k GitHub starsUsed in 1 repo~625 tokens
    Auto-check passed
  • Edge

    alsk1992/CloddsBot

    Find mispriced markets by comparing to external models and data sources

    2.9k GitHub starsUsed in 1 repo~472 tokens
    Auto-check passed
  • Embeddings

    alsk1992/CloddsBot

    Vector embeddings configuration and semantic search. An agent skill from alsk1992/CloddsBot.

    2.9k GitHub starsUsed in 1 repo~1.3k tokens
    Auto-check passed
  • News

    alsk1992/CloddsBot

    Monitor news and correlate with prediction market movements. An agent skill from alsk1992/CloddsBot.

    2.9k GitHub starsUsed in 1 repo~462 tokens
    Auto-check passed
  • Opportunity

    alsk1992/CloddsBot

    Find and execute cross-platform arbitrage opportunities across prediction markets

    2.9k GitHub starsUsed in 1 repo~2.2k tokens
    Auto-check passed

Categories

Questions about Token Security

How do I install Token Security in Claude Code?

Run `npx skills add alsk1992/CloddsBot --skill token-security -a claude-code`. Or copy the skill folder (src/skills/bundled/token-security in alsk1992/CloddsBot) into .claude/skills/token-security in your project. Claude Code loads it when a task matches its description.

How do I install Token Security in Codex?

Run `npx skills add alsk1992/CloddsBot --skill token-security -a codex`. Or copy the skill folder (src/skills/bundled/token-security in alsk1992/CloddsBot) into .agents/skills/token-security in your project. Codex loads it when a task matches its description.

Can I use Token Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add alsk1992/CloddsBot --skill token-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/token-security, .gemini/skills/token-security, .github/skills/token-security and .opencode/skills/token-security in your project.

What does Token Security need to run?

Going by SKILL.md and its folder, Token Security needs TypeScript for the scripts in its folder.

Does Token Security access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Token Security safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Token Security use?

Token Security is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Token Security use?

About 113 tokens (SKILL.md is roughly 452 characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Token Security?

Skills that share tags, products or a category with Token Security: Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Kubernetes Network Security Audit (kubeshark/kubeshark, 12k stars), Native Dependency Update (mono/SkiaSharp, 5.6k stars) and Semgrep Security Scan (trailofbits/skills, 7.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Token Security?

alsk1992 (a GitHub user) maintains it in alsk1992/CloddsBot, which has 2,901 GitHub stars. The repository holds 118 skills in this directory. The repository was last updated on October 2, 2026.

Source: alsk1992/CloddsBot on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.