Solana Dev
solana-foundation/solana-dev-skill
A skill your agent uses when user asks to "build a Solana dapp", "write an Anchor program", "create a token", "debug Solana errors", "set up wallet connection", "test my Solana program", "fuzz my…
Run on-chain safety diligence on a Solana token before anyone buys it - mint and freeze authority, liquidity lock or burn, holder concentration, sell simulation - and give a plain verdict with the…
$ npx skills add nirholas/three.ws --skill token-safety-check -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install nirholas/three.ws token-safety-check --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/nirholas/three.ws.git skills-src && mkdir -p .claude/skills && cp -r skills-src/community-skills/skills/token-safety-check .claude/skills/token-safety-check && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "token-safety-check" agent skill from https://github.com/nirholas/three.ws/tree/main/community-skills/skills/token-safety-check into .claude/skills/token-safety-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "token-safety-check", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/nirholas/three.ws/tree/main/community-skills/skills/token-safety-checkType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add nirholas/three.ws --skill token-safety-check -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install nirholas/three.ws token-safety-check --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nirholas/three.ws.git skills-src && mkdir -p .agents/skills && cp -r skills-src/community-skills/skills/token-safety-check .agents/skills/token-safety-check && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "token-safety-check" agent skill from https://github.com/nirholas/three.ws/tree/main/community-skills/skills/token-safety-check into .agents/skills/token-safety-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "token-safety-check", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add nirholas/three.ws --skill token-safety-check -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install nirholas/three.ws token-safety-check --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nirholas/three.ws.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/community-skills/skills/token-safety-check .cursor/skills/token-safety-check && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "token-safety-check" agent skill from https://github.com/nirholas/three.ws/tree/main/community-skills/skills/token-safety-check into .cursor/skills/token-safety-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "token-safety-check", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/nirholas/three.ws.git --path community-skills/skills/token-safety-check--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add nirholas/three.ws --skill token-safety-check -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install nirholas/three.ws token-safety-check --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nirholas/three.ws.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/community-skills/skills/token-safety-check .gemini/skills/token-safety-check && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "token-safety-check" agent skill from https://github.com/nirholas/three.ws/tree/main/community-skills/skills/token-safety-check into .gemini/skills/token-safety-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "token-safety-check", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install nirholas/three.ws token-safety-checkInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add nirholas/three.ws --skill token-safety-check -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/nirholas/three.ws.git skills-src && mkdir -p .github/skills && cp -r skills-src/community-skills/skills/token-safety-check .github/skills/token-safety-check && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "token-safety-check" agent skill from https://github.com/nirholas/three.ws/tree/main/community-skills/skills/token-safety-check into .github/skills/token-safety-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "token-safety-check", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add nirholas/three.ws --skill token-safety-check -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install nirholas/three.ws token-safety-check --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nirholas/three.ws.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/community-skills/skills/token-safety-check .opencode/skills/token-safety-check && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "token-safety-check" agent skill from https://github.com/nirholas/three.ws/tree/main/community-skills/skills/token-safety-check into .opencode/skills/token-safety-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "token-safety-check", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
token-safety-checkRun on-chain safety diligence on a Solana token before anyone buys it - mint and freeze authority, liquidity lock or burn, holder concentration, sell simulation - and give a plain verdict with the…
Token Safety Check is an agent skill from nirholas/three.ws. Run on-chain safety diligence on a Solana token before anyone buys it - mint and freeze authority, liquidity lock or burn, holder concentration, sell simulation - and give a plain verdict with the evidence. Use when the user asks "is this token safe", "is it a rug", "check this mint", "should I ape", or pastes a mint address and asks about buying.
Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including scripts (for example `metadata.json`).
It sits in Backend & APIs, covering Smart contracts. It works with Solana. The repository describes itself as: Open-source platform for 3D AI agents. Turn text or a photo into a rigged, animated GLB avatar, give it an LLM brain, memory and a wallet, and embed it anywhere with one web… The licence is Apache-2.0.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit ddf6e49. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (JavaScript), which the agent can run.
Shell commands in SKILL.md call:
nodeFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
three.wsFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Token Safety Check loads about 1.3k tokens when it runs. Until then it costs about 92 tokens; SKILL.md has 743 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from nirholas/three.ws at commit ddf6e49, republished under its Apache-2.0 licence (© nirholas). 743 words, ~1,317 tokens.
.claude/skills/token-safety-check/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.You are doing pre-buy diligence on one Solana token. Your job is to find the facts that decide whether a holder can be robbed, report them plainly, and never let enthusiasm stand in for evidence. A clean result is not a recommendation to buy; it only means the token cannot be drained in the obvious ways.
When you can, also run a sell simulation: a token that lets you buy but not sell is a honeypot, and only a simulated round trip proves otherwise.
With three.ws tools or HTTP access, use these; all are free and need no key:
GET https://three.ws/api/crypto/security?address=<mint> returns checks.mintAuthorityRevoked, freezeAuthorityRevoked, metadataMutable, lpBurnedOrLocked, liquidityUsd, topHolderPctFlag, a riskLevel and reasons.GET https://three.ws/api/pump/safety?mint=<mint>&amount=<sol> checks authorities and simulates a buy then a sell. It returns verdict (allow, warn, block), score, checks and reasons. It is the same firewall the three.ws trade endpoints enforce, so a block here means the platform will refuse the trade too.GET https://three.ws/api/crypto/holders?address=<mint> returns the top holders with percentages and a concentration label.GET https://three.ws/api/pump/token-stats?mint=<mint> adds dev share, early-buyer share and 5m to 24h volume for tokens that launched on the bonding-curve launchpad./api/pump-fun-mcp): get_token_holders for concentration and get_coin_intel for bundle and organic-activity scores.Without platform access, the bundled script reads the chain directly:
node scripts/check-mint.mjs <mint> # human-readable report
node scripts/check-mint.mjs <mint> --json # machine-readableIt reports authorities, the token program and its extensions, supply, and top 1, 10 and 20 concentration, and falls back across RPC endpoints when one is throttled. It cannot see liquidity locks or simulate a sell; say so when it is your only source.
Lead with a one-line verdict, then the evidence as a short list, then what is unknown.
Example shape:
CAUTION. Authorities are revoked and liquidity is locked, but the top 10 non-pool wallets hold 41% of supply.
- Mint authority: revoked. Freeze authority: revoked.
- Liquidity: locked, about $38k deep.
- Concentration: top holder is the pool (13%); the next 9 wallets hold 28%.
- Sell simulation: passed at 0.5 SOL.
- Unknown: team wallets are not labeled on-chain.
© nirholas, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (scripts) in community-skills/skills/token-safety-check of nirholas/three.ws.
Open the folder on GitHubat commit ddf6e49
Token Safety Check next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Token Safety Check this skillnirholas/three.ws | 227 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | |
| Solana Devsolana-foundation/solana-dev-skill | 574 | — | ~3.8k | Automated safety check: Pass | MIT | |
| RadarAuditware/radar | 154 | — | ~2.1k | Automated safety check: Pass | GPL-3.0 | |
| Safe Solana BuilderFrankcastleauditor/safe-solana-builder | 145 | — | ~3.6k | Automated safety check: Pass | None | |
| Wiremock TestOpenZeppelin/openzeppelin-relayer | 153 | — | ~1.6k | Automated safety check: Notes | AGPL-3.0 | |
| Solana Token Extensionssolanabr/ai-kit | 108 | — | ~3.5k | Automated safety check: Pass | MIT |
solana-foundation/solana-dev-skill
A skill your agent uses when user asks to "build a Solana dapp", "write an Anchor program", "create a token", "debug Solana errors", "set up wallet connection", "test my Solana program", "fuzz my…
Auditware/radar
Use radar for smart contract security analysis, AST generation, and detection template development.
Frankcastleauditor/safe-solana-builder
A skill your agent uses whenever the user wants to write, scaffold, or build a Solana smart contract or program from scratch.
OpenZeppelin/openzeppelin-relayer
Manage WireMock proxy for RPC testing. An agent skill from OpenZeppelin/openzeppelin-relayer.
solanabr/ai-kit
Helps choose, combine and create Token-2022 mint and account extensions on Solana with the spl-token CLI, @solana/kit or Anchor, and integrate the resulting mints.
moonpay/skills
A skill your agent uses when accessing Alchemy APIs for RPC calls, token balances, NFT metadata, asset transfers, transaction simulation, or Alchemy-specific features.
nirholas/three.ws
Add the Shaders WebGPU mouse effect used for the Tidal Commons hero: a white twinkling halftone cursor trail driven by ChromaFlow, masked through a DotGrid, finished with chromatic ripples and film…
nirholas/three.ws
Package a finished local project into an intentional GitHub repository, create a strong README and visual preview, push it safely, configure a public GitHub Pages URL when the project is compatible…
nirholas/three.ws
Audit a website or digital experience against its supplied source references for originality and plagiarism risk.
nirholas/three.ws
Turn a completed daily UI inspiration capture into exactly five original landing-page builds, one per separate Codex task, using Sites.
nirholas/three.ws
Write, rewrite, review, or continuously refine X/Twitter posts in Meng To's current voice using his deduplicated authored-post corpus, personal and product context, shared resources, and Content…
nirholas/three.ws
Create polished 60 fps 4:3 4K browser screen-recording style videos from Codex in-app browser captures, with browser-only crop, natural macOS cursor styling, deliberate click choreography…
Works with
Categories
Run on-chain safety diligence on a Solana token before anyone buys it - mint and freeze authority, liquidity lock or burn, holder concentration, sell simulation - and give a plain verdict with the…. ws. Run on-chain safety diligence on a Solana token before anyone buys it - mint and freeze authority, liquidity lock or burn, holder concentration, sell simulation - and give a plain verdict with the evidence.
Token Safety Check fits situations like: the user asks is this token safe; check this mint; pastes a mint address and asks about buying.
Run `npx skills add nirholas/three.ws --skill token-safety-check -a claude-code`. Or copy the skill folder (community-skills/skills/token-safety-check in nirholas/three.ws) into .claude/skills/token-safety-check in your project. Claude Code loads it when a task matches its description.
Run `npx skills add nirholas/three.ws --skill token-safety-check -a codex`. Or copy the skill folder (community-skills/skills/token-safety-check in nirholas/three.ws) into .agents/skills/token-safety-check in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add nirholas/three.ws --skill token-safety-check -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/token-safety-check, .gemini/skills/token-safety-check, .github/skills/token-safety-check and .opencode/skills/token-safety-check in your project.
Going by SKILL.md and its folder, Token Safety Check needs JavaScript for the scripts in its folder and the command-line tools its instructions call (node). Our summary lists: Node.js.
SKILL.md names 1 domain. In commands or code: three.ws; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Token Safety Check is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.3k tokens (SKILL.md is roughly 5.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Token Safety Check: Solana Dev (solana-foundation/solana-dev-skill, 574 stars), Radar (Auditware/radar, 154 stars), Safe Solana Builder (Frankcastleauditor/safe-solana-builder, 145 stars) and Wiremock Test (OpenZeppelin/openzeppelin-relayer, 153 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
nirholas (a GitHub user) maintains it in nirholas/three.ws, which has 227 GitHub stars. The repository holds 92 skills in this directory. The repository was last updated on October 8, 2026.
Source: nirholas/three.ws on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.