Agent skill

External Call Safety

by quillai-network in quillai-network/quillshield_skills

Detects unsafe external call patterns and token integration vulnerabilities in smart contracts.

MITAuto-check passedBackend & APIs

Install External Call Safety

skills CLI
$ npx skills add quillai-network/quillshield_skills --skill external-call-safety -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install quillai-network/quillshield_skills external-call-safety --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/quillai-network/quillshield_skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/external-call-safety/skills/external-call-safety .claude/skills/external-call-safety && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
external-call-safety
GitHub stars
130
Token cost
~3.1k tokens
SKILL.md length
585 words
Files
3 (incl. references)
Skills in repo
11
Repo updated
First seen
Licence
MIT

At a glance

Detects unsafe external call patterns and token integration vulnerabilities in smart contracts.

  • Auditing contracts that interact with external contracts
  • SKILL.md covers When to Use, When NOT to Use, Part 1: External Call Safety and Part 2: Token Integration…, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Integrate arbitrary ERC20 tokens

What it does

External Call Safety is an agent skill from quillai-network/quillshield_skills. Detects unsafe external call patterns and token integration vulnerabilities in smart contracts. Covers unchecked call/delegatecall/staticcall return values, fee-on-transfer tokens, rebasing tokens, tokens with missing return values (USDT), ERC-777 callback risks, unsafe approve race conditions, return data bombs, gas stipend limitations, and push vs pull payment patterns. Use when auditing contracts that interact with external contracts, integrate arbitrary ERC20 tokens, distribute payments, or make low-level…

Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/call-safety-patterns.md` and `references/weird-erc20.md`).

It sits in Backend & APIs, covering Smart contracts, Async programming and Smart contract auditing. It works with Ethereum. The repository describes itself as: Structured skills for smart contract security audits. Infers state invariants, detects semantic guard gaps, models flash loan + oracle attack chains, simulates adversarial… The licence is MIT.

When your agent uses it

  • Auditing contracts that interact with external contracts
  • Integrate arbitrary ERC20 tokens
  • Distribute payments
  • Make low-level calls

Example prompts

  • “Use the external-call-safety skill to detect unsafe external call patterns and token integration vulnerabilities in smart contracts”
  • “/external-call-safety”

What it can do on your machine

Read from SKILL.md and the folder at commit 8bdd3c0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are solidity and markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

External Call Safety loads about 3.1k tokens when it runs, and up to ~6.5k if it reads all its reference files. Until then it costs about 136 tokens; SKILL.md has 585 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~136
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from quillai-network/quillshield_skills at commit 8bdd3c0, republished under its MIT licence (© quillai-network). 585 words, ~3,071 tokens.

Download SKILL.mdSave it as .claude/skills/external-call-safety/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
external-call-safety
description
Detects unsafe external call patterns and token integration vulnerabilities in smart contracts. Covers unchecked call/delegatecall/staticcall return values, fee-on-transfer tokens, rebasing tokens, tokens with missing return values (USDT), ERC-777 callback risks, unsafe approve race conditions, return data bombs, gas stipend limitations, and push vs pull payment patterns. Use when auditing contracts that interact with external contracts, integrate arbitrary ERC20 tokens, distribute payments, or make low-level calls.

External Call Safety

Detect vulnerabilities arising from unsafe interactions with external contracts and non-standard token behaviors that break protocol assumptions. Covers OWASP SC06 (Unchecked External Calls) plus the entire "weird ERC20" problem space.

When to Use

  • Auditing any contract that calls external contracts (token transfers, cross-contract interactions)
  • Reviewing protocols that support arbitrary/user-supplied ERC20 tokens
  • Analyzing ETH payment distribution logic (airdrops, reward distribution, refunds)
  • Verifying low-level call safety (call, delegatecall, staticcall)
  • When a protocol claims to support "any ERC20 token"

When NOT to Use

  • Reentrancy-specific analysis (use reentrancy-pattern-analysis — though there is overlap)
  • Oracle/price feed analysis (use oracle-flashloan-analysis)
  • Pure access control review (use semantic-guard-analysis)

Part 1: External Call Safety

Vulnerability Class 1: Unchecked Return Values

Low-level calls (call, delegatecall, staticcall) return a boolean indicating success. If unchecked, failed calls are silently ignored.

solidity
// VULNERABLE: Return value not checked
function withdraw(uint256 amount) external {
    balances[msg.sender] -= amount;
    payable(msg.sender).call{value: amount}(""); // Can fail silently!
    // User's balance decreased but ETH not sent
}

// SAFE: Check return value
function withdraw(uint256 amount) external {
    balances[msg.sender] -= amount;
    (bool success, ) = payable(msg.sender).call{value: amount}("");
    require(success, "Transfer failed");
}

Detection Algorithm:

For each low-level call expression:
  1. Is the return value captured? (bool success, bytes memory data) = ...
  2. Is the success boolean checked? require(success) or if(!success) revert
  3. If not captured or not checked → UNCHECKED RETURN VALUE

Severity:
  - ETH transfer unchecked → CRITICAL (funds lost)
  - Token operation unchecked → HIGH (state desync)
  - Non-financial call unchecked → MEDIUM
Vulnerability Class 2: Gas Stipend Limitations
solidity
// DANGEROUS: transfer() and send() forward only 2300 gas
payable(recipient).transfer(amount); // Reverts if recipient needs > 2300 gas
payable(recipient).send(amount);     // Returns false, often unchecked

// SAFE: Use call() with gas
(bool success, ) = payable(recipient).call{value: amount}("");
require(success, "Transfer failed");

Why 2300 gas is dangerous:

  • Contracts with receive() or fallback() that do more than emit an event will fail
  • EIP-1884 changed SLOAD gas cost, breaking some existing contracts
  • Multi-sig wallets and smart contract wallets often need more gas
Vulnerability Class 3: Return Data Bomb

A malicious contract can return extremely large data to consume the caller's gas.

solidity
// Vulnerable to return data bomb
(bool success, bytes memory data) = untrustedContract.call(calldata);
// If untrustedContract returns 1MB of data, copying it costs massive gas

// SAFE: Limit return data or ignore it
(bool success, ) = untrustedContract.call(calldata); // Ignore return data
// Or use assembly to limit return data size
Vulnerability Class 4: Delegatecall to Untrusted Contract
solidity
// CRITICAL: delegatecall executes untrusted code in OUR storage context
function execute(address target, bytes calldata data) external {
    target.delegatecall(data); // Untrusted code can overwrite ANY storage
}

// delegatecall should ONLY be used with trusted, immutable targets

Part 2: Token Integration Safety ("Weird ERC20" Tokens)

Issue 1: Fee-on-Transfer Tokens

Some tokens deduct a fee during transfer() and transferFrom(). The recipient receives less than the specified amount.

solidity
// VULNERABLE: Assumes received amount equals input amount
function deposit(uint256 amount) external {
    token.transferFrom(msg.sender, address(this), amount);
    balances[msg.sender] += amount; // Credits MORE than actually received!
}

// SAFE: Check actual balance change
function deposit(uint256 amount) external {
    uint256 balanceBefore = token.balanceOf(address(this));
    token.transferFrom(msg.sender, address(this), amount);
    uint256 balanceAfter = token.balanceOf(address(this));
    uint256 actualReceived = balanceAfter - balanceBefore;
    balances[msg.sender] += actualReceived; // Credits actual amount
}

Known fee-on-transfer tokens: STA, PAXG, USDT (fee currently 0 but can be activated), RFI/SAFEMOON forks.

Issue 2: Rebasing Tokens

Rebasing tokens change all balances proportionally without transfers. Protocol's accounting desynchronizes from actual balances.

solidity
// VULNERABLE: Stores absolute balance amounts
function deposit(uint256 amount) external {
    token.transferFrom(msg.sender, address(this), amount);
    userDeposit[msg.sender] = amount; // After rebase, actual balance differs!
}

// Mitigation options:
// 1. Store shares instead of amounts
// 2. Wrap rebasing token (wstETH pattern)
// 3. Explicitly state: "rebasing tokens not supported"

Known rebasing tokens: stETH, AMPL, OHM, YAM, BASED.

Issue 3: Missing Return Values

Some tokens don't return a boolean from transfer()/transferFrom()/approve(), breaking the ERC20 standard.

solidity
// VULNERABLE: Assumes return value exists
bool success = token.transfer(recipient, amount); // Reverts if token returns nothing

// SAFE: Use SafeERC20
using SafeERC20 for IERC20;
token.safeTransfer(recipient, amount); // Handles missing return values

Known tokens with missing returns: USDT, BNB, OMG, KNC (legacy versions).

Issue 4: Tokens with Callbacks (ERC-777)

ERC-777 tokens trigger tokensToSend() on the sender and tokensReceived() on the recipient during transfers, enabling reentrancy.

ERC-777 callback hooks:
  transfer() → calls tokensReceived() on recipient
  transferFrom() → calls tokensToSend() on sender, tokensReceived() on recipient
  send() → calls tokensToSend() on sender, tokensReceived() on recipient

ANY of these can re-enter the calling contract!

Cross-reference: See reentrancy-pattern-analysis for detailed ERC-777 reentrancy detection.

Issue 5: Unsafe Approve Pattern
solidity
// VULNERABLE: Approve race condition
token.approve(spender, newAmount);
// Between the approval TX and the spending TX, the spender can:
// 1. Spend the OLD allowance
// 2. Then spend the NEW allowance
// Total spent: oldAmount + newAmount (double spending)

// SAFE: Reset to zero first, or use increaseAllowance
token.approve(spender, 0); // Reset
token.approve(spender, newAmount); // Set new

// Or use SafeERC20
token.safeIncreaseAllowance(spender, amount);

// ALSO DANGEROUS: Some tokens (USDT) revert on non-zero to non-zero approve
token.approve(spender, newAmount); // REVERTS if current allowance != 0
// MUST reset to 0 first for USDT
Issue 6: Tokens with Blacklists

Some tokens can blacklist addresses, causing transfers to/from those addresses to revert.

solidity
// VULNERABLE: Assumes transfer always succeeds for valid amounts
function distribute(address[] calldata users, uint256[] calldata amounts) external {
    for (uint i = 0; i < users.length; i++) {
        token.transfer(users[i], amounts[i]); // Reverts if ANY user is blacklisted
        // Entire batch fails!
    }
}

// SAFE: Handle per-user failures
function distribute(address[] calldata users, uint256[] calldata amounts) external {
    for (uint i = 0; i < users.length; i++) {
        try IERC20(token).transfer(users[i], amounts[i]) {
            // Success
        } catch {
            // Log failure, skip this user, don't block others
        }
    }
}

Known blacklist tokens: USDC, USDT, TUSD.

Show full SKILL.md (227 more words)Show less
Issue 7: Tokens with Max Supply / Transfer Limits

Some tokens have maximum transfer amounts per transaction or maximum holding amounts per address.

solidity
// Protocol may assume any amount can be transferred
// But some tokens: require(amount <= maxTransferAmount)
// This can brick protocols that batch large transfers

Part 3: Payment Pattern Analysis

Push vs Pull Pattern
PUSH (Dangerous):
  Contract sends funds TO recipients
  - Can fail if recipient is a contract that reverts
  - Can be DoS'd by one malicious recipient
  - Gas costs unpredictable

PULL (Safe):
  Recipients claim funds FROM contract
  - Each claim is independent
  - One user's failure doesn't affect others
  - Gas costs predictable per claim

Detection:

For each function that sends ETH or tokens to external addresses:
  If sending to user-supplied addresses in a loop → PUSH pattern
  If sending to individual addresses via claim function → PULL pattern
  PUSH pattern with untrusted recipients → HIGH risk of DoS

Workflow

Task Progress:
- [ ] Step 1: Find all external calls (call, delegatecall, staticcall, transfer, send)
- [ ] Step 2: Verify return values are checked for all external calls
- [ ] Step 3: Identify all token interactions and classify token assumptions
- [ ] Step 4: Check for fee-on-transfer compatibility (balance before/after pattern)
- [ ] Step 5: Check for rebasing token compatibility
- [ ] Step 6: Verify SafeERC20 usage for tokens with missing return values
- [ ] Step 7: Check approve patterns for race conditions and USDT compatibility
- [ ] Step 8: Analyze payment distribution pattern (push vs pull)
- [ ] Step 9: Score findings and generate report

Output Format

markdown
## External Call Safety Report

### Finding: [Title]

**Function:** `functionName()` at `Contract.sol:L42`
**Category:** [Unchecked Return | Fee-on-Transfer | Rebasing | Missing Return | Callback | Approve Race | DoS]
**Severity:** [CRITICAL | HIGH | MEDIUM]

**Issue:**
[Description of the unsafe external call or token integration issue]

**Affected Tokens:**
[List of known tokens that trigger this issue, e.g., USDT, USDC, stETH]

**Vulnerable Code:**
[Code snippet]

**Attack Scenario:**
1. [Step-by-step exploitation]

**Recommendation:**
[Use SafeERC20, balance-before-after, pull pattern, etc.]

Quick Detection Checklist

  • Are ALL low-level call return values checked (require(success))?
  • Does the protocol use SafeERC20 for all token interactions?
  • Does the deposit function use balance-before-after pattern for fee-on-transfer tokens?
  • Does the protocol explicitly handle or reject rebasing tokens?
  • Does approve() reset to 0 before setting new allowance (USDT compatibility)?
  • Are batch payment operations using pull pattern (not push)?
  • Is delegatecall only used with trusted, immutable targets?
  • Are return data sizes from untrusted contracts limited?
  • Does the protocol handle token blacklisting gracefully?

For weird ERC20 catalog, see {baseDir}/references/weird-erc20.md. For call safety patterns, see {baseDir}/references/call-safety-patterns.md.

Rationalizations to Reject

  • "We only support standard ERC20 tokens" → USDT is the most used token and it's non-standard (no return value, fee capability)
  • "The call will always succeed" → Smart contract wallets, blacklisted addresses, and gas changes can cause failures
  • "We trust the token contract" → Token contracts can be upgraded (proxies) or have hidden features
  • "transfer() is safe enough" → 2300 gas stipend breaks with gas repricing EIPs; use call()
  • "We checked the token before listing" → Fee-on-transfer can be toggled on after listing (USDT has this capability)
  • "Rebasing tokens are rare" → stETH is one of the largest tokens by TVL

© quillai-network, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in plugins/external-call-safety/skills/external-call-safety of quillai-network/quillshield_skills.

  • SKILL.md
  • references/call-safety-patterns.md
  • references/weird-erc20.md

Open the folder on GitHubat commit 8bdd3c0

Compare with similar skills

External Call Safety next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

External Call Safety compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
External Call Safety this skillquillai-network/quillshield_skills130—~3.1kAutomated safety check: PassMIT
Stellar iOS Mac SDKSoneso/stellar-ios-mac-sdk132—~4.3kAutomated safety check: PassApache-2.0
Smart Contract Auditforefy/.context1521 repos~5.1kAutomated safety check: PassMIT
Fizz Convertpashov/skills1.2k2 repos~3.7kAutomated safety check: PassMIT
Smart Contract Auditgreatpie/smart-contract-audit-skill101—~1.1kAutomated safety check: PassNone
Solidity AuditorGabson0x/bountyforge442—~3.7kAutomated safety check: PassNone

Similar skills

  • Stellar iOS Mac SDK

    Soneso/stellar-ios-mac-sdk

    Guides Stellar blockchain development in Swift using stellar-ios-mac-sdk.

    132 GitHub stars~4.3k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Smart Contract Audit

    forefy/.context

    Comprehensive smart contract security audit framework with multi-expert analysis.

    152 GitHub starsUsed in 1 repo~5.1k tokens
    SecurityAuto-check passed
  • Fizz Convert

    pashov/skills

    Convert English-language properties in PROPERTIES.md (produced by the Fizz skill) into Solidity assertions inside the existing fuzz harness, then flip their checkboxes.

    1.2k GitHub starsUsed in 2 repos~3.7k tokens
    Backend & APIsAuto-check passed
  • Smart Contract Audit

    greatpie/smart-contract-audit-skill

    Script-backed, out-of-box auditing workflow for Solidity/EVM repositories based on EVMbench detect/patch/exploit methodology.

    101 GitHub stars~1.1k tokensUpdated 7 mo ago
    Backend & APIsAuto-check passed
  • Solidity Auditor

    Gabson0x/bountyforge

    Security audit of Solidity code while you develop. An agent skill from Gabson0x/bountyforge.

    442 GitHub stars~3.7k tokensUpdated 24 days ago
    Backend & APIsAuto-check passed
  • Explorer Contract Verification

    sablier-labs/evm-monorepo

    Verify smart contracts on Etherscan, Routescan, and Blockscout block explorers.

    353 GitHub stars~1.9k tokensUpdated yesterday
    Backend & APIsAuto-check passed

More from quillai-network/quillshield_skills

All 11 skills in this repo
  • Behavioral State Analysis

    quillai-network/quillshield_skills

    Token-efficient smart contract security auditing via Behavioral State Analysis (BSA).

    130 GitHub stars~1.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dos Griefing Analysis

    quillai-network/quillshield_skills

    Detects Denial of Service and griefing vulnerabilities in smart contracts.

    130 GitHub stars~3.3k tokensUpdated 6 mo ago
    Auto-check passed
  • Input Arithmetic Safety

    quillai-network/quillshield_skills

    Detects input validation failures and arithmetic vulnerabilities in smart contracts.

    130 GitHub stars~3.1k tokensUpdated 6 mo ago
    Auto-check passed
  • Oracle Flashloan Analysis

    quillai-network/quillshield_skills

    Detects price oracle manipulation and flash loan attack vectors in DeFi smart contracts.

    130 GitHub stars~2.8k tokensUpdated 6 mo ago
    Auto-check passed
  • Proxy Upgrade Safety

    quillai-network/quillshield_skills

    Detects vulnerabilities in upgradeable proxy smart contracts including storage layout collisions, uninitialized implementations, function selector clashing, delegatecall context issues, and upgrade…

    130 GitHub stars~3.2k tokensUpdated 6 mo ago
    Auto-check passed
  • Reentrancy Pattern Analysis

    quillai-network/quillshield_skills

    Systematically detects all reentrancy vulnerability variants in smart contracts — classic, cross-function, cross-contract, and read-only reentrancy.

    130 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed

Works with

Categories

Questions about External Call Safety

What does External Call Safety do?

Detects unsafe external call patterns and token integration vulnerabilities in smart contracts. External Call Safety is an agent skill from quillai-network/quillshield_skills. Detects unsafe external call patterns and token integration vulnerabilities in smart contracts.

When should I use External Call Safety?

External Call Safety fits situations like: auditing contracts that interact with external contracts; integrate arbitrary ERC20 tokens; distribute payments; make low-level calls.

How do I install External Call Safety in Claude Code?

Run `npx skills add quillai-network/quillshield_skills --skill external-call-safety -a claude-code`. Or copy the skill folder (plugins/external-call-safety/skills/external-call-safety in quillai-network/quillshield_skills) into .claude/skills/external-call-safety in your project. Claude Code loads it when a task matches its description.

How do I install External Call Safety in Codex?

Run `npx skills add quillai-network/quillshield_skills --skill external-call-safety -a codex`. Or copy the skill folder (plugins/external-call-safety/skills/external-call-safety in quillai-network/quillshield_skills) into .agents/skills/external-call-safety in your project. Codex loads it when a task matches its description.

Can I use External Call Safety in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add quillai-network/quillshield_skills --skill external-call-safety -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/external-call-safety, .gemini/skills/external-call-safety, .github/skills/external-call-safety and .opencode/skills/external-call-safety in your project.

What does External Call Safety need to run?

SKILL.md names no scripts, command-line tools or credentials: External Call Safety is instructions for the agent only.

Does External Call Safety access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is External Call Safety safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does External Call Safety use?

External Call Safety is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does External Call Safety use?

About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.4k tokens, read only when the agent opens those files.

What are the alternatives to External Call Safety?

Skills that share tags, products or a category with External Call Safety: Stellar iOS Mac SDK (Soneso/stellar-ios-mac-sdk, 132 stars), Smart Contract Audit (forefy/.context, 152 stars), Fizz Convert (pashov/skills, 1.2k stars) and Smart Contract Audit (greatpie/smart-contract-audit-skill, 101 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains External Call Safety?

quillai-network (a GitHub organization) maintains it in quillai-network/quillshield_skills, which has 130 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on March 30, 2026.

Source: quillai-network/quillshield_skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.