Agent skill

Quickintel Scan

by LeoYeAI in LeoYeAI/openclaw-master-skills

Scan any token for security risks, honeypots, and scams using Quick Intel's contract analysis API.

MITAuto-check passedLegal & Compliance

Install Quickintel Scan

skills CLI
$ npx skills add LeoYeAI/openclaw-master-skills --skill quickintel-scan -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install LeoYeAI/openclaw-master-skills quickintel-scan --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/quickintel-scan .claude/skills/quickintel-scan && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
quickintel-scan
GitHub stars
2.2k
Token cost
~4k tokens
SKILL.md length
1,141 words
Files
3
Skills in repo
1,215
Repo updated
First seen
Licence
MIT

At a glance

Scan any token for security risks, honeypots, and scams using Quick Intel's contract analysis API.

  • : checking if a token is safe to buy
  • SKILL.md covers Quick Reference, How to Scan, Supported Chains (63) and Reading Scan Results, plus 8 more sections
  • Calls curl; reaches x402.quickintel.io and frames.ag; needs SPONGE_API_KEY and AGENTWALLET_API_TOKEN
  • Detecting honeypots

What it does

Quickintel Scan is an agent skill from LeoYeAI/openclaw-master-skills. Scan any token for security risks, honeypots, and scams using Quick Intel's contract analysis API. Use when: checking if a token is safe to buy, detecting honeypots, analyzing contract ownership and permissions, finding hidden mint/blacklist functions, or evaluating token risk before trading. Triggers: 'is this token safe', 'scan token', 'check for honeypot', 'audit contract', 'rug pull check', 'token security', 'safe to buy', 'scam check'. Supports 63 chains including Base, Ethereum, Solana, Sui, Tron. Costs…

Its SKILL.md is about 4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `Reference.md` and `_meta.json`).

It sits in Legal & Compliance, covering Contract review and Trading and backtesting. It works with x402, Circle USDC, Ethereum and Solana. The repository describes itself as: 🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai. The licence is MIT.

When your agent uses it

  • : checking if a token is safe to buy
  • Detecting honeypots
  • Analyzing contract ownership and permissions
  • Finding hidden mint/blacklist functions

Example prompts

  • “is this token safe”
  • “scan token”
  • “check for honeypot”
  • “/quickintel-scan”

Requirements

  • A credential in SPONGE_API_KEY
  • A credential in AGENTWALLET_API_TOKEN

What it can do on your machine

Read from SKILL.md and the folder at commit e5199b5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • x402.quickintel.io
    • frames.ag
    • api.wallet.paysponge.com

    Also links to:

    • paysponge.com
    • quickintel.io
    • docs.quickintel.io
    • x402.org
    • t.me

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • SPONGE_API_KEY
    • AGENTWALLET_API_TOKEN
    • X402_PAYMENT_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Quickintel Scan loads about 4k tokens when it runs. Until then it costs about 207 tokens; SKILL.md has 1,141 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~207
When it runs · the whole SKILL.md, loaded when a task matches
~4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from LeoYeAI/openclaw-master-skills at commit e5199b5, republished under its MIT licence (© LeoYeAI). 1,141 words, ~3,973 tokens.

Download SKILL.mdSave it as .claude/skills/quickintel-scan/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
quickintel-scan
description
Scan any token for security risks, honeypots, and scams using Quick Intel's contract analysis API. Use when: checking if a token is safe to buy, detecting honeypots, analyzing contract ownership and permissions, finding hidden mint/blacklist functions, or evaluating token risk before trading. Triggers: 'is this token safe', 'scan token', 'check for honeypot', 'audit contract', 'rug pull check', 'token security', 'safe to buy', 'scam check'. Supports 63 chains including Base, Ethereum, Solana, Sui, Tron. Costs $0.03 USDC per scan via x402 payment protocol. Requires an x402-compatible wallet — recommended: managed wallet service (Sponge, AgentWallet) with no raw key exposure. Programmatic signing with dedicated hot wallet also supported. This skill is read-only and never accesses your tokens or assets.

Quick Intel Token Security Scanner

Scan any token on 63 chains for honeypots, scams, and security risks. Returns a detailed audit in seconds. Costs $0.03 USDC per scan via x402 — read-only, never touches your wallet or tokens.

Quick Reference

SituationAction
User asks "is this token safe?"Scan the token, interpret results
User wants to buy/trade a tokenScan BEFORE trading, warn on red flags
Scan shows is_Honeypot: trueSTOP — tell user they cannot sell this token
Scan shows isScam: trueSTOP — known scam contract
Scan shows can_Mint: trueWarn: owner can inflate supply
Scan shows high buy/sell tax (>10%)Warn: excessive fees reduce profits
Scan shows contract_Renounced: falseCaution: owner retains control
liquidity: false in resultsMay use non-standard pair — verify on DEX aggregator
User gives chain + addressYou have everything needed to scan
User gives only address, no chainAsk which chain, or try to infer from address format

How to Scan

Endpoint: POST https://x402.quickintel.io/v1/scan/full

Request body:

json
{
  "chain": "base",
  "tokenAddress": "0x..."
}

That's it. The x402 payment ($0.03 USDC/USDM) is handled automatically by your wallet integration. If you have @x402/fetch, Sponge Wallet, AgentWallet, Vincent, or Lobster.cash — the payment flow is transparent. Pay on any of 14 networks: Base (recommended, lowest fees), Ethereum, Arbitrum, Optimism, Polygon, Avalanche, Unichain, Linea, Sonic, HyperEVM, Ink, Monad, MegaETH (USDM), or Solana.

Which integration do I use?

⚠️ Wallet Security: This skill does NOT require your private key. The x402 payment is handled by YOUR agent's wallet — whichever wallet your agent already uses. If your agent doesn't have a wallet yet, use a managed wallet service (Sponge, AgentWallet, Vincent, Lobster.cash) instead of raw private keys. If you must use programmatic signing, use a dedicated hot wallet with minimal funds ($1-5 USDC), never your main wallet.

Your setupUse thisKey exposure
Using Sponge WalletPattern A below (recommended)✅ No raw keys — API key only
Using AgentWallet (frames.ag)Pattern B below✅ No raw keys — API token only
Using Lobster.cash / CrossmintSee REFERENCE.md✅ No raw keys — managed wallet
Using Vincent WalletSee REFERENCE.md✅ No raw keys — managed signing
Have @x402/fetch installedPattern C below⚠️ Requires private key in env
Have viem or ethers.js, no x402 libraryPattern D below (manual signing)⚠️ Requires private key in env
Using Solana walletSee REFERENCE.md⚠️ Requires private key in env
Not sure / no wallet configuredStart with Pattern A (Sponge)✅ No raw keys
bash
curl -sS -X POST "https://api.wallet.paysponge.com/api/x402/fetch" \
  -H "Authorization: Bearer $SPONGE_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "url": "https://x402.quickintel.io/v1/scan/full",
    "method": "POST",
    "body": {
      "chain": "base",
      "tokenAddress": "0xa4a2e2ca3fbfe21aed83471d28b6f65a233c6e00"
    },
    "preferred_chain": "base"
  }'

Requires: SPONGE_API_KEY env var. Sign up at paysponge.com. Sponge manages the wallet and signing — your agent never touches a private key.

Pattern B: AgentWallet (No Raw Keys)
javascript
const response = await fetch('https://frames.ag/api/wallets/{username}/actions/x402/fetch', {
  method: 'POST',
  headers: {
    'Authorization': `Bearer ${process.env.AGENTWALLET_API_TOKEN}`,
    'Content-Type': 'application/json'
  },
  body: JSON.stringify({
    url: 'https://x402.quickintel.io/v1/scan/full',
    method: 'POST',
    body: { chain: 'base', tokenAddress: '0x...' }
  })
});
const scan = await response.json();

Requires: AGENTWALLET_API_TOKEN env var. Get one at frames.ag.

Pattern C: @x402/fetch (Programmatic Signing)

⚠️ Uses a private key. Use a dedicated hot wallet with minimal funds, not your main wallet.

javascript
import { x402Fetch } from '@x402/fetch';
import { createWallet } from '@x402/evm';

// Use a DEDICATED wallet with only payment funds ($1-5 USDC)
// NEVER use your main wallet or trading wallet private key here
const wallet = createWallet(process.env.X402_PAYMENT_KEY);

const response = await x402Fetch('https://x402.quickintel.io/v1/scan/full', {
  method: 'POST',
  headers: { 'Content-Type': 'application/json' },
  body: JSON.stringify({ chain: 'base', tokenAddress: '0x...' }),
  wallet,
  preferredNetwork: 'eip155:8453'
});

const scan = await response.json();
Pattern D: Manual EVM Signing (viem)

⚠️ Uses a private key. Use a dedicated hot wallet with minimal funds, not your main wallet.

If you don't have @x402/fetch, handle the payment flow manually:

javascript
import { keccak256, toHex } from 'viem';
import { privateKeyToAccount } from 'viem/accounts';

// Use a DEDICATED wallet with only payment funds ($1-5 USDC)
const account = privateKeyToAccount(process.env.X402_PAYMENT_KEY);
const SCAN_URL = 'https://x402.quickintel.io/v1/scan/full';

// Step 1: Hit endpoint, get 402 with payment requirements
const scanBody = JSON.stringify({ chain: 'base', tokenAddress: '0x...' });
const initialRes = await fetch(SCAN_URL, {
  method: 'POST',
  headers: { 'Content-Type': 'application/json' },
  body: scanBody,
});

if (initialRes.status !== 402) throw new Error(`Expected 402, got ${initialRes.status}`);
const paymentRequired = await initialRes.json();

// Step 2: Find preferred network in accepts array
const networkInfo = paymentRequired.accepts.find(a => a.network === 'eip155:8453');
if (!networkInfo) throw new Error('Base network not available');

// Step 3: Sign EIP-712 TransferWithAuthorization
const nonce = keccak256(toHex(`${Date.now()}-${Math.random()}`));
const validBefore = BigInt(Math.floor(Date.now() / 1000) + 3600);

const signature = await account.signTypedData({
  domain: {
    name: networkInfo.extra.name,
    version: networkInfo.extra.version,
    chainId: 8453,
    verifyingContract: networkInfo.asset,
  },
  types: {
    TransferWithAuthorization: [
      { name: 'from', type: 'address' },
      { name: 'to', type: 'address' },
      { name: 'value', type: 'uint256' },
      { name: 'validAfter', type: 'uint256' },
      { name: 'validBefore', type: 'uint256' },
      { name: 'nonce', type: 'bytes32' },
    ],
  },
  primaryType: 'TransferWithAuthorization',
  message: {
    from: account.address,
    to: networkInfo.payTo,
    value: BigInt(networkInfo.amount),
    validAfter: 0n,
    validBefore,
    nonce,
  },
});

// Step 4: Build PAYMENT-SIGNATURE header
// CRITICAL: signature is a SIBLING of authorization, NOT nested inside it
// CRITICAL: value/validAfter/validBefore must be DECIMAL STRINGS
const paymentPayload = {
  x402Version: 2,
  scheme: 'exact',
  network: 'eip155:8453',
  payload: {
    signature,                         // ← Direct child of payload
    authorization: {
      from: account.address,
      to: networkInfo.payTo,
      value: networkInfo.amount,                  // Decimal string: "30000"
      validAfter: '0',                            // Decimal string
      validBefore: validBefore.toString(),         // Decimal string
      nonce,
    },
  },
};

const paymentHeader = Buffer.from(JSON.stringify(paymentPayload)).toString('base64');

// Step 5: Retry with payment
const paidRes = await fetch(SCAN_URL, {
  method: 'POST',
  headers: {
    'Content-Type': 'application/json',
    'PAYMENT-SIGNATURE': paymentHeader,
  },
  body: scanBody,
});

const scan = await paidRes.json();

Common mistakes that cause payment failures:

  • signature nested inside authorization instead of as a sibling → "Cannot read properties of undefined"
  • Missing x402Version: 2 at top level
  • Using hex ("0x7530") or raw numbers instead of decimal strings ("30000") for value/validAfter/validBefore
  • Wrong endpoint path (/v1/scan/auditfull instead of /v1/scan/full)

For ethers.js, Solana, Vincent, Lobster.cash, and other wallet patterns, see REFERENCE.md.

Supported Chains (63)

EVM: eth, base, arbitrum, optimism, polygon, bsc, avalanche, fantom, linea, scroll, zksync, blast, mantle, mode, zora, manta, sonic, berachain, unichain, abstract, monad, megaeth, hyperevm, shibarium, pulse, core, opbnb, polygonzkevm, metis, kava, klaytn, astar, oasis, iotex, conflux, canto, velas, grove, lightlink, bitrock, loop, besc, energi, maxx, degen, inevm, viction, nahmii, real, xlayer, worldchain, apechain, morph, ink, soneium, plasma

Non-EVM: solana, sui, radix, tron, injective

Use exact chain names as shown (e.g., "eth" not "ethereum", "bsc" not "binance").

Reading Scan Results

Red Flags — DO NOT BUY
FieldValueMeaning
tokenDynamicDetails.is_HoneypottrueCannot sell — funds are trapped
isScamtrueKnown scam contract
isAirdropPhishingScamtruePhishing attempt
quickiAudit.has_ScamstrueContains scam patterns
quickiAudit.can_Potentially_Steal_FundstrueHas theft mechanisms

If ANY of these are true, tell the user not to buy and explain why.

Show full SKILL.md (470 more words)Show less
Warnings — Proceed With Caution
FieldValueRisk
buy_Tax or sell_Tax> 10High fees eat profits
quickiAudit.can_MinttrueOwner can create more tokens, diluting value
quickiAudit.can_BlacklisttrueOwner can block wallets from selling
quickiAudit.can_Pause_TradingtrueOwner can freeze all trading
quickiAudit.can_Update_FeestrueTaxes could increase after you buy
quickiAudit.hidden_OwnertrueReal owner is obscured
quickiAudit.contract_RenouncedfalseOwner retains control over contract
quickiAudit.is_ProxytrueContract code can be changed
Positive Signs
FieldValueMeaning
quickiAudit.contract_RenouncedtrueNo owner control
contractVerifiedtrueSource code is public
quickiAudit.can_MintfalseFixed supply
quickiAudit.can_BlacklistfalseNo blocking capability
buy_Tax and sell_Tax0 or lowMinimal fees
Liquidity Check

tokenDynamicDetails.liquidity indicates whether a liquidity pool was detected.

  • liquidity: false does NOT always mean illiquid — Quick Intel checks major pairs (WETH, USDC, USDT) but may miss non-standard pairings. Verify independently on a DEX aggregator.
  • liquidity: true — still check lp_Locks for lock status. Unlocked liquidity = rug pull risk.

Example: Interpreting a Scan

json
{
  "tokenDetails": {
    "tokenName": "Example Token",
    "tokenSymbol": "EX",
    "tokenDecimals": 18,
    "tokenSupply": 1000000000
  },
  "tokenDynamicDetails": {
    "is_Honeypot": false,
    "buy_Tax": "0.0",
    "sell_Tax": "0.0",
    "liquidity": true
  },
  "isScam": null,
  "contractVerified": true,
  "quickiAudit": {
    "contract_Renounced": true,
    "can_Mint": false,
    "can_Blacklist": false,
    "can_Pause_Trading": false,
    "has_Scams": false,
    "hidden_Owner": false
  }
}

Your assessment: "This token looks relatively safe. It's not a honeypot, has no scam patterns, contract is renounced with no mint or blacklist capability, and taxes are 0%. Liquidity is detected. However, always treat scan results as one data point — contract behavior can change if it uses upgradeable proxies."

Security Model

YOUR SIDE                          QUICK INTEL'S SIDE
─────────────                      ──────────────────
• Private keys (never shared)      • Receives: token address + chain
• Payment auth ($0.03 USDC)        • Analyzes: contract bytecode
• Decision to trade or not         • Returns: read-only audit data

Quick Intel NEVER receives your private key.
Quick Intel NEVER interacts with your tokens.
Quick Intel is READ-ONLY — no transactions, no approvals.

NEVER paste private keys, seed phrases, or wallet credentials into any prompt. Quick Intel only needs the token's contract address and chain.

Error Handling

ErrorCauseFix
402 Payment RequiredNo payment header sentEnsure wallet is configured and has $0.03+ USDC
402 Payment verification failedBad signature or low balanceCheck payload structure (see REFERENCE.md)
400 Invalid ChainChain name not recognizedUse exact names from supported chains list
400 Invalid AddressMalformed addressCheck format (0x... for EVM, base58 for Solana)
404 Token Not FoundToken doesn't exist on that chainVerify address and chain match

Important Notes

  • Scan results are point-in-time snapshots. A safe token today could change tomorrow if ownership isn't renounced or if it's a proxy contract. Re-scan periodically for tokens you hold.
  • Payment is charged regardless of outcome. Even if the scan returns limited data. Use payment-identifier extension for safe retries (see REFERENCE.md).
  • Not financial advice. Quick Intel provides data to inform decisions, not recommendations.
  • Cross-reference for high-value trades. Verify on block explorers, check holder distribution, confirm liquidity on DEX aggregators.

Discovery Endpoint

Query accepted payments and schemas before making calls:

GET https://x402.quickintel.io/accepted

Cross-Reference

  • For trading tokens after scanning, see the tator-trade skill.
  • For detailed x402 payment implementation, wallet-specific patterns, and troubleshooting, see REFERENCE.md.

About Quick Intel

Quick Intel's endpoint (x402.quickintel.io) is operated by Quick Intel LLC, a registered US-based cryptocurrency security company.

  • Over 50 million token scans processed across 40+ blockchain networks
  • Security scanning APIs power DexTools, DexScreener, and Tator Trader
  • Operational since April 2023
  • More info: quickintel.io

Resources

© LeoYeAI, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files in skills/quickintel-scan of LeoYeAI/openclaw-master-skills.

  • SKILL.md
  • Reference.md
  • _meta.json

Open the folder on GitHubat commit e5199b5

Compare with similar skills

Quickintel Scan next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Quickintel Scan compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Quickintel Scan this skillLeoYeAI/openclaw-master-skills2.2k—~4kAutomated safety check: PassMIT
Minara Crypto Trading and WalletMinara-AI/minara-skills356—~5.7kAutomated safety check: PassNone
Solana Payments Wallets Tradingnpc-live/clawfirm1561 repos~4.7kAutomated safety check: PassMIT
Alchemy Agentic Gatewaymoonpay/skills113—~2.1kAutomated safety check: NotesMIT
AlchemyBankrBot/skills1.2k—~3.5kAutomated safety check: PassMIT
Quicknodemajiayu000/claude-skill-registry6661 repos~1.5kAutomated safety check: PassMIT

Similar skills

  • Minara Crypto Trading and Wallet

    Minara-AI/minara-skills

    Drives the Minara CLI for crypto swaps, perps, limit orders, wallet transfers, deposits and withdrawals, plus AI market analysis.

    356 GitHub stars~5.7k tokensUpdated 20 days ago
    Business, Finance & HRAuto-check passed
  • Pay people in SOL or USDC, buy and sell tokens, check prices, discover trending and new tokens, create and manage Solana wallets, stake SOL, earn yield through lending and managed vaults, borrow…

    156 GitHub starsUsed in 1 repo~4.7k tokens
    Business, Finance & HRAuto-check passed
  • A skill your agent uses when accessing Alchemy APIs for RPC calls, token balances, NFT metadata, asset transfers, transaction simulation, or Alchemy-specific features.

    113 GitHub stars~2.1k tokensUpdated 27 days ago
    Backend & APIsAuto-check: notes
  • Alchemy

    BankrBot/skills

    Blockchain API access via Alchemy. An agent skill from BankrBot/skills.

    1.2k GitHub stars~3.5k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Quicknode

    majiayu000/claude-skill-registry

    Blockchain RPC and data access via Quicknode. An agent skill from majiayu000/claude-skill-registry.

    666 GitHub starsUsed in 1 repo~1.5k tokens
    Backend & APIsAuto-check passed
  • Agentic Wallet

    coinbase/agentic-wallet-skills

    Crypto wallet operations via the awal CLI — sign in, check balances, send USDC/ETH/POL/SOL, trade tokens, fund the wallet, and use the x402 payment protocol to discover paid services, pay for API…

    127 GitHub starsUsed in 2 repos~1k tokens
    Backend & APIsAuto-check passed

More from LeoYeAI/openclaw-master-skills

All 1,215 skills in this repo
  • DevOps Pipeline Management

    LeoYeAI/openclaw-master-skills

    Manages pipelines on a DevOps quality and efficiency platform through its OpenAPI: list workspaces and templates, create, update, run and cancel pipelines, and read run records.

    2.2k GitHub stars~4.2k tokensUpdated 2 mo ago
    Auto-check: notes
  • Feishu Document Collaboration

    LeoYeAI/openclaw-master-skills

    Patches OpenClaw's Feishu extension so an edited document triggers an isolated agent session that reads the doc and replies inline, turning it into a live chat space.

    2.2k GitHub stars~2k tokensUpdated 2 mo ago
    Auto-check passed
  • Files Memory System

    LeoYeAI/openclaw-master-skills

    Multi-context memory management system for OpenClaw agents with group-isolated storage, global shared memory, workspace organization, and group-specific skills isolation.

    2.2k GitHub stars~3.8k tokensUpdated 2 mo ago
    Auto-check passed
  • GEO-Claw AI Visibility Agent

    LeoYeAI/openclaw-master-skills

    Runs a brand's AI-search visibility work end to end: diagnosing how AI platforms represent it, repositioning it, producing AI-optimized content and monitoring ongoing mentions.

    2.2k GitHub stars~4.7k tokensUpdated 2 mo ago
    Auto-check passed
  • Google Workspace CLI

    LeoYeAI/openclaw-master-skills

    Installs and authenticates the gws CLI, then automates Gmail, Drive, Sheets, Calendar, Docs, Chat and Tasks with ready-made recipes, persona bundles and security audits.

    2.2k GitHub stars~2.6k tokensUpdated 2 mo ago
    Auto-check: notes
  • HealthFit Health Advisors

    LeoYeAI/openclaw-master-skills

    Runs four advisor roles, a fitness coach, nutritionist, data analyst and TCM practitioner, to build a health profile and track workouts, diet and wellness over time.

    2.2k GitHub stars~4.4k tokensUpdated 2 mo ago
    Auto-check passed

Questions about Quickintel Scan

What does Quickintel Scan do?

Scan any token for security risks, honeypots, and scams using Quick Intel's contract analysis API. Quickintel Scan is an agent skill from LeoYeAI/openclaw-master-skills. Scan any token for security risks, honeypots, and scams using Quick Intel's contract analysis API.

When should I use Quickintel Scan?

Quickintel Scan fits situations like: : checking if a token is safe to buy; detecting honeypots; analyzing contract ownership and permissions; finding hidden mint/blacklist functions.

How do I install Quickintel Scan in Claude Code?

Run `npx skills add LeoYeAI/openclaw-master-skills --skill quickintel-scan -a claude-code`. Or copy the skill folder (skills/quickintel-scan in LeoYeAI/openclaw-master-skills) into .claude/skills/quickintel-scan in your project. Claude Code loads it when a task matches its description.

How do I install Quickintel Scan in Codex?

Run `npx skills add LeoYeAI/openclaw-master-skills --skill quickintel-scan -a codex`. Or copy the skill folder (skills/quickintel-scan in LeoYeAI/openclaw-master-skills) into .agents/skills/quickintel-scan in your project. Codex loads it when a task matches its description.

Can I use Quickintel Scan in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LeoYeAI/openclaw-master-skills --skill quickintel-scan -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/quickintel-scan, .gemini/skills/quickintel-scan, .github/skills/quickintel-scan and .opencode/skills/quickintel-scan in your project.

What does Quickintel Scan need to run?

Going by SKILL.md and its folder, Quickintel Scan needs the command-line tools its instructions call (curl) and credentials named SPONGE_API_KEY, AGENTWALLET_API_TOKEN and X402_PAYMENT_KEY. Our summary lists: A credential in SPONGE_API_KEY; A credential in AGENTWALLET_API_TOKEN.

Does Quickintel Scan access the network?

SKILL.md names 8 domains. In commands or code: x402.quickintel.io, frames.ag and api.wallet.paysponge.com; the agent is likely to contact these when it follows the instructions. As links in the text: paysponge.com, quickintel.io, docs.quickintel.io, x402.org and t.me. This is read from the text; nothing was executed.

Is Quickintel Scan safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Quickintel Scan use?

Quickintel Scan is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Quickintel Scan use?

About 4k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Quickintel Scan?

Skills that share tags, products or a category with Quickintel Scan: Minara Crypto Trading and Wallet (Minara-AI/minara-skills, 356 stars), Solana Payments Wallets Trading (npc-live/clawfirm, 156 stars), Alchemy Agentic Gateway (moonpay/skills, 113 stars) and Alchemy (BankrBot/skills, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Quickintel Scan?

LeoYeAI (a GitHub user) maintains it in LeoYeAI/openclaw-master-skills, which has 2,158 GitHub stars. The repository holds 1,215 skills in this directory. The repository was last updated on July 20, 2026.

Source: LeoYeAI/openclaw-master-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.