Defi Amm Security
affaan-m/ECC
Security checklist for Solidity AMM contracts, liquidity pools, and swap flows.
Framework for evaluating DeFi protocol risk — smart contract audits, TVL analysis, governance structure, oracle dependencies, and token economics.
$ npx skills add aAAaqwq/AGI-Super-Team --skill defi-risk-assessment -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install aAAaqwq/AGI-Super-Team defi-risk-assessment --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/aAAaqwq/AGI-Super-Team.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/defi-risk-assessment .claude/skills/defi-risk-assessment && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "defi-risk-assessment" agent skill from https://github.com/aAAaqwq/AGI-Super-Team/tree/main/skills/defi-risk-assessment into .claude/skills/defi-risk-assessment/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "defi-risk-assessment", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/aAAaqwq/AGI-Super-Team/tree/main/skills/defi-risk-assessmentType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add aAAaqwq/AGI-Super-Team --skill defi-risk-assessment -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install aAAaqwq/AGI-Super-Team defi-risk-assessment --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aAAaqwq/AGI-Super-Team.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/defi-risk-assessment .agents/skills/defi-risk-assessment && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "defi-risk-assessment" agent skill from https://github.com/aAAaqwq/AGI-Super-Team/tree/main/skills/defi-risk-assessment into .agents/skills/defi-risk-assessment/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "defi-risk-assessment", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aAAaqwq/AGI-Super-Team --skill defi-risk-assessment -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install aAAaqwq/AGI-Super-Team defi-risk-assessment --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aAAaqwq/AGI-Super-Team.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/defi-risk-assessment .cursor/skills/defi-risk-assessment && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "defi-risk-assessment" agent skill from https://github.com/aAAaqwq/AGI-Super-Team/tree/main/skills/defi-risk-assessment into .cursor/skills/defi-risk-assessment/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "defi-risk-assessment", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/aAAaqwq/AGI-Super-Team.git --path skills/defi-risk-assessment--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add aAAaqwq/AGI-Super-Team --skill defi-risk-assessment -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install aAAaqwq/AGI-Super-Team defi-risk-assessment --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aAAaqwq/AGI-Super-Team.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/defi-risk-assessment .gemini/skills/defi-risk-assessment && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "defi-risk-assessment" agent skill from https://github.com/aAAaqwq/AGI-Super-Team/tree/main/skills/defi-risk-assessment into .gemini/skills/defi-risk-assessment/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "defi-risk-assessment", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install aAAaqwq/AGI-Super-Team defi-risk-assessmentInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add aAAaqwq/AGI-Super-Team --skill defi-risk-assessment -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/aAAaqwq/AGI-Super-Team.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/defi-risk-assessment .github/skills/defi-risk-assessment && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "defi-risk-assessment" agent skill from https://github.com/aAAaqwq/AGI-Super-Team/tree/main/skills/defi-risk-assessment into .github/skills/defi-risk-assessment/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "defi-risk-assessment", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aAAaqwq/AGI-Super-Team --skill defi-risk-assessment -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install aAAaqwq/AGI-Super-Team defi-risk-assessment --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aAAaqwq/AGI-Super-Team.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/defi-risk-assessment .opencode/skills/defi-risk-assessment && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "defi-risk-assessment" agent skill from https://github.com/aAAaqwq/AGI-Super-Team/tree/main/skills/defi-risk-assessment into .opencode/skills/defi-risk-assessment/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "defi-risk-assessment", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
defi-risk-assessmentFramework for evaluating DeFi protocol risk — smart contract audits, TVL analysis, governance structure, oracle dependencies, and token economics.
Defi Risk Assessment is an agent skill from aAAaqwq/AGI-Super-Team. Framework for evaluating DeFi protocol risk — smart contract audits, TVL analysis, governance structure, oracle dependencies, and token economics. Use when helping users assess protocol safety, compare DeFi options, or identify red flags before depositing funds.
Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Business, Finance & HR, covering Crypto and DeFi analysis and Smart contract auditing. The repository describes itself as: An installable, cross-framework AI organization: C-suite agents, expert subagents, curated skills, independent review, and one-command setup across 18 AI client/runtime adapters. The licence is MIT.
10 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 7cefd81. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
defillama.comdefisafety.comrekt.newsFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Defi Risk Assessment loads about 1.4k tokens when it runs. Until then it costs about 71 tokens; SKILL.md has 644 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from aAAaqwq/AGI-Super-Team at commit 7cefd81, republished under its MIT licence (© aAAaqwq). 644 words, ~1,358 tokens.
.claude/skills/defi-risk-assessment/SKILL.md (or your agent's skills folder).A structured approach for AI agents to evaluate DeFi protocol risk and help users make informed decisions.
The code itself could have vulnerabilities.
Assessment Checklist:
Risk Levels:
| Level | Criteria |
|---|---|
| Low | 2+ audits, 1+ year live, open source, large bug bounty |
| Medium | 1 audit, 6+ months live, open source |
| High | Unaudited or <6 months live |
| Critical | Closed source, no audits, anonymous team |
The protocol design could fail under stress.
Key Questions:
Common Failure Modes:
How much control do insiders have?
| Factor | Low Risk | High Risk |
|---|---|---|
| Admin keys | Timelock + multisig | Single EOA |
| Upgradability | Immutable or governance-gated | Instant proxy upgrade |
| Token distribution | Wide distribution | Team holds >40% |
| Oracle | Chainlink + fallback | Custom oracle, single source |
Can you exit your position when you need to?
Could regulatory action affect the protocol?
Rate each category 1–5, then calculate:
Overall Risk Score = (SmartContract × 3 + Economic × 2.5 + Centralization × 2 + Liquidity × 1.5 + Regulatory × 1) / 10| Score | Rating | Recommendation |
|---|---|---|
| 1.0–2.0 | Very Low Risk | Suitable for conservative allocations |
| 2.0–3.0 | Low Risk | Suitable for most users |
| 3.0–3.5 | Medium Risk | Only with risk understanding |
| 3.5–4.0 | High Risk | Small allocations only |
| 4.0–5.0 | Very High Risk | Avoid for most users |
Aave V3: 10+ audits, 3+ years live, $10B+ TVL, Chainlink oracles, governance timelock, large bug bounty
Sperax USDs: Multiple audits, 100% stablecoin collateral (no volatile assets), Chainlink oracles, 2+ years live, collateral ratio safety checks, bug bounty ($100–$15K)
Newer L2 protocols: 1–2 audits, less than a year live, growing TVL, reasonable governance
Unaudited yield farms: No audits, anonymous team, high APYs from emissions only, proxy contracts, no timelock
Instant disqualifiers:
For agents evaluating a protocol:
© aAAaqwq, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/defi-risk-assessment of aAAaqwq/AGI-Super-Team.
Open the folder on GitHubat commit 7cefd81
We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in aAAaqwq/AGI-Super-Team, which our catalogue first saw on October 7, 2026.
Defi Risk Assessment next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Defi Risk Assessment this skillaAAaqwq/AGI-Super-Team | 105 | 1 repos | ~1.4k | Automated safety check: Pass | MIT | |
| Defi Amm Securityaffaan-m/ECC | 277k | 1 repos | ~1.3k | Automated safety check: Pass | MIT | |
| Soroban Oracle Data Feed Auditsickn33/agentic-awesome-skills | 47k | 1 repos | ~1.3k | Automated safety check: Pass | MIT | |
| Technical Analysttradermonty/claude-trading-skills | 3k | 4 repos | ~4.6k | Automated safety check: Pass | MIT | |
| Polyclawchainstacklabs/polyclaw | 359 | 1 repos | ~2k | Automated safety check: Pass | Apache-2.0 | |
| Longbridge Researchhelsome/folio | 271 | 3 repos | ~2.1k | Automated safety check: Pass | MIT |
affaan-m/ECC
Security checklist for Solidity AMM contracts, liquidity pools, and swap flows.
sickn33/agentic-awesome-skills
DeFi price oracle integration and safety audit register: heartbeat bounds, stale price threshold reversion, and TWAP medianizer validation.
tradermonty/claude-trading-skills
This skill should be used when analyzing weekly price charts for stocks, stock indices, cryptocurrencies, or forex pairs.
chainstacklabs/polyclaw
Trade on Polymarket via split + CLOB execution. An agent skill from chainstacklabs/polyclaw.
helsome/folio
Institution ratings, consensus price targets, EPS/revenue forecasts, finance calendar, shareholder data, fund holders, insider trades (SEC Form 4), short interest, industry rankings, peer group…
24mlight/StockClaw
Analyze stocks and cryptocurrencies using Yahoo Finance data.
aAAaqwq/AGI-Super-Team
Create SEO-optimized marketing content with consistent brand voice.
aAAaqwq/AGI-Super-Team
Advanced financial calculator with future value tables, present value, discount calculations, markup pricing, and compound interest.
aAAaqwq/AGI-Super-Team
Transaction-verified trading signals on Base blockchain. An agent skill from aAAaqwq/AGI-Super-Team.
aAAaqwq/AGI-Super-Team
Register AI agents on Ethereum mainnet using ERC-8004 (Trustless Agents).
aAAaqwq/AGI-Super-Team
Create distinctive, production-grade static sites with React, Tailwind CSS, and shadcn/ui — no mockups needed.
aAAaqwq/AGI-Super-Team
Publish and manage content on 知识星球 (zsxq.com). An agent skill from aAAaqwq/AGI-Super-Team.
Categories
Framework for evaluating DeFi protocol risk — smart contract audits, TVL analysis, governance structure, oracle dependencies, and token economics. Defi Risk Assessment is an agent skill from aAAaqwq/AGI-Super-Team. Framework for evaluating DeFi protocol risk — smart contract audits, TVL analysis, governance structure, oracle dependencies, and token economics.
Defi Risk Assessment fits situations like: helping users assess protocol safety; compare DeFi options; identify red flags before depositing funds.
Run `npx skills add aAAaqwq/AGI-Super-Team --skill defi-risk-assessment -a claude-code`. Or copy the skill folder (skills/defi-risk-assessment in aAAaqwq/AGI-Super-Team) into .claude/skills/defi-risk-assessment in your project. Claude Code loads it when a task matches its description.
Run `npx skills add aAAaqwq/AGI-Super-Team --skill defi-risk-assessment -a codex`. Or copy the skill folder (skills/defi-risk-assessment in aAAaqwq/AGI-Super-Team) into .agents/skills/defi-risk-assessment in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aAAaqwq/AGI-Super-Team --skill defi-risk-assessment -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/defi-risk-assessment, .gemini/skills/defi-risk-assessment, .github/skills/defi-risk-assessment and .opencode/skills/defi-risk-assessment in your project.
SKILL.md names no scripts, command-line tools or credentials: Defi Risk Assessment is instructions for the agent only.
SKILL.md names 3 domains. As links in the text: defillama.com, defisafety.com and rekt.news. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Defi Risk Assessment is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.4k tokens (SKILL.md is roughly 5.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Defi Risk Assessment: Defi Amm Security (affaan-m/ECC, 277k stars), Soroban Oracle Data Feed Audit (sickn33/agentic-awesome-skills, 47k stars), Technical Analyst (tradermonty/claude-trading-skills, 3k stars) and Polyclaw (chainstacklabs/polyclaw, 359 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
aAAaqwq (a GitHub user) maintains it in aAAaqwq/AGI-Super-Team, which has 105 GitHub stars. The repository holds 167 skills in this directory. The repository was last updated on October 8, 2026.
Source: aAAaqwq/AGI-Super-Team on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.