Agent skill

Security Check

by TermiX-official in TermiX-official/cryptoclaw

Assess token and address security via the GoPlus Security API.

MITAuto-check passedBusiness, Finance & HR

Install Security Check

skills CLI
$ npx skills add TermiX-official/cryptoclaw --skill security-check -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install TermiX-official/cryptoclaw security-check --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/TermiX-official/cryptoclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security-check .claude/skills/security-check && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-check
GitHub stars
100
Token cost
~945 tokens
SKILL.md length
342 words
Files
1
Skills in repo
33
Repo updated
First seen
Licence
MIT

At a glance

Assess token and address security via the GoPlus Security API.

  • Works in 5 steps: Token Security → Address Security → Approval Security → …
  • Business, Finance & HR work in your project
  • SKILL.md covers Quick Access, Base URL, Security Checks and Risk Scoring Workflow, plus 3 more sections
  • Reaches api.gopluslabs.io

What it does

Security Check is an agent skill from TermiX-official/cryptoclaw. Assess token and address security via the GoPlus Security API.

Its SKILL.md is about 950 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Business, Finance & HR. The licence is MIT.

When your agent uses it

  • Business, Finance & HR work in your project

Example prompts

  • “/security-check”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Token Security
  2. Address Security
  3. Approval Security
  4. NFT Security
  5. Phishing Site Detection

What it can do on your machine

Read from SKILL.md and the folder at commit 9e1c91b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • api.gopluslabs.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Check loads about 945 tokens when it runs. Until then it costs about 19 tokens; SKILL.md has 342 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~19
When it runs · the whole SKILL.md, loaded when a task matches
~945

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from TermiX-official/cryptoclaw at commit 9e1c91b, republished under its MIT licence (© TermiX-official). 342 words, ~945 tokens.

Download SKILL.mdSave it as .claude/skills/security-check/SKILL.md (or your agent's skills folder).
name
security-check
description
Assess token and address security via the GoPlus Security API.

GoPlus Security API

Quick Access

The check_address_security tool provides instant address risk assessment. All transfers are also auto-checked before execution.

Assess token contracts, wallet addresses, and approvals for security risks using the free GoPlus API.

Base URL

https://api.gopluslabs.io/api/v1

No API key required. Free tier is sufficient for normal usage.

Security Checks

1. Token Security
GET /token_security/{chain_id}?contract_addresses={address}

Chain IDs: 1 (Ethereum), 56 (BSC), 137 (Polygon), 42161 (Arbitrum), 10 (Optimism), 8453 (Base)

Key response fields:

  • is_honeypot — token cannot be sold (CRITICAL)
  • buy_tax / sell_tax — percentage tax on trades (HIGH if > 10%)
  • is_mintable — owner can mint unlimited tokens
  • hidden_owner — ownership is concealed
  • can_take_back_ownership — owner can reclaim after renouncing
  • selfdestruct — contract can self-destruct
  • is_proxy — upgradeable proxy contract
  • is_open_source — source code is verified
  • holder_count — number of holders
  • lp_holder_count — number of LP holders
  • is_anti_whale — anti-whale mechanism present
  • owner_percent — percentage held by owner
  • creator_percent — percentage held by creator
2. Address Security
GET /address_security/{address}?chain_id={chain_id}

Checks if an address is associated with: phishing, stealing, malicious contracts, or blacklists.

3. Approval Security
GET /approval_security/{chain_id}?contract_addresses={address}

Checks token approval risks: whether the approved contract is malicious or has known exploits.

4. NFT Security
GET /nft_security/{chain_id}?contract_addresses={address}

Checks NFT contract for: privileged operations, restricted transfer, self-destruct, and trading risks.

5. Phishing Site Detection
GET /phishing_site?url={url}

Checks if a URL is a known phishing site. Use this before directing users to any DeFi frontend.

Risk Scoring Workflow

Evaluate the response fields and classify risk:

CRITICAL (do not proceed):

  • is_honeypot: 1
  • selfdestruct: 1
  • hidden_owner: 1 AND is_mintable: 1

HIGH (strong warning):

  • buy_tax > 10% or sell_tax > 10%
  • can_take_back_ownership: 1
  • is_open_source: 0 (unverified source)
  • owner_percent > 50%

MEDIUM (note to user):

  • is_proxy: 1 (upgradeable)
  • is_mintable: 1 (alone)
  • holder_count < 100

LOW (informational):

  • is_anti_whale: 1
  • Minor tax (< 5%)

Risk Report Template

🛡️ Security Report: {token_name} ({symbol})
Chain: {chain_name} | Contract: {address}

Risk Level: {CRITICAL|HIGH|MEDIUM|LOW}

✅ Passed:
- Open source: Yes
- Not a honeypot
- No self-destruct

⚠️ Warnings:
- Sell tax: 5%
- Mintable: Yes
- Holder count: 87

❌ Critical:
- (none)

Recommendation: {proceed with caution / avoid / safe to interact}

Cross-references

Other skills should invoke security checks:

  • token-swap: Check token before executing swaps
  • nft-manager: Check NFT contract before purchases
  • etherscan: Complement ABI analysis with security data

Example Interactions

User: "Is this token safe? 0x..." → Call /token_security/56?contract_addresses=0x..., generate risk report

User: "Check this address for me: 0x..." → Call /address_security/0x...?chain_id=56, report any flags

User: "Are my token approvals safe?" → Call /approval_security/56?contract_addresses=0x... for each approved contract

User: "Is this DeFi site legit? https://..." → Call /phishing_site?url=https://..., report result

© TermiX-official, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/security-check of TermiX-official/cryptoclaw.

Open the folder on GitHubat commit 9e1c91b

Compare with similar skills

Security Check next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Check compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Check this skillTermiX-official/cryptoclaw100—~945Automated safety check: PassMIT
Technical Analysttradermonty/claude-trading-skills3k5 repos~4.6kAutomated safety check: PassMIT
Creating Financial ModelsChen-zexi/open-ptc-agent7294 repos~1.3kAutomated safety check: PassMIT
Stock APIzhangxiangliang/stock-api2k—~507Automated safety check: PassMIT
Theme Detectortradermonty/claude-trading-skills3k2 repos~4.9kAutomated safety check: PassMIT
Itr Walakaranb192/itr-wala871—~3.6kAutomated safety check: PassMIT

Similar skills

  • Technical Analyst

    tradermonty/claude-trading-skills

    This skill should be used when analyzing weekly price charts for stocks, stock indices, cryptocurrencies, or forex pairs.

    3k GitHub starsUsed in 5 repos~4.6k tokens
    Business, Finance & HRAuto-check passed
  • Creating Financial Models

    Chen-zexi/open-ptc-agent

    This skill provides an advanced financial modeling suite with DCF analysis, sensitivity testing, Monte Carlo simulations, and scenario planning for investment decisions

    729 GitHub starsUsed in 4 repos~1.3k tokens
    Business, Finance & HRAuto-check passed
  • Stock API

    zhangxiangliang/stock-api

    Fetch real-time stock quotes, K-line (candlestick) history, and search symbols for China A-shares, Hong Kong, and US markets.

    2k GitHub stars~507 tokensUpdated today
    Business, Finance & HRAuto-check passed
  • Theme Detector

    tradermonty/claude-trading-skills

    Detect and analyze trending market themes across sectors. An agent skill from tradermonty/claude-trading-skills.

    3k GitHub starsUsed in 2 repos~4.9k tokens
    Business, Finance & HRAuto-check passed
  • Itr Wala

    karanb192/itr-wala

    File Indian income tax returns (ITR) for FY 2025-26 / AY 2026-27.

    871 GitHub stars~3.6k tokensUpdated 4 days ago
    Business, Finance & HRAuto-check passed
  • Tushare Data

    zillionare/zillionare

    面向中文自然语言的 Tushare 数据研究技能。用于把“看看这只股票最近怎么样”“帮我查财报趋势”“最近哪个板块最强”“北向资金在买什么”“给我导出一份行情数据”这类请求,转成可执行的数据获取、清洗、对比、筛选、导出与简要分析流程。适用于 A 股、指数、ETF/基金、财务、估值、资金流、公告新闻、板块概念与宏观数据等研究场景。

    319 GitHub starsUsed in 2 repos~2.3k tokens
    Business, Finance & HRAuto-check passed

More from TermiX-official/cryptoclaw

All 33 skills in this repo
  • Coding Agent

    TermiX-official/cryptoclaw

    Delegate coding tasks to Codex, Claude Code, or Pi agents via background process.

    100 GitHub starsUsed in 8 repos~2.7k tokens
    Auto-check passed
  • Prose

    TermiX-official/cryptoclaw

    OpenProse VM skill pack. An agent skill from TermiX-official/cryptoclaw.

    100 GitHub starsUsed in 3 repos~3.8k tokens
    Auto-check: notes
  • Merge PR

    TermiX-official/cryptoclaw

    Merge a GitHub PR via squash after /preparepr. An agent skill from TermiX-official/cryptoclaw.

    100 GitHub stars~1.2k tokensUpdated 4 mo ago
    Auto-check passed
  • Acp Router

    TermiX-official/cryptoclaw

    Route plain-language requests for Pi, Claude Code, Codex, OpenCode, Gemini CLI, or ACP harness work into either OpenClaw ACP runtime sessions or direct acpx-driven sessions ("telephone game" flow).

    100 GitHub starsUsed in 2 repos~1.9k tokens
    Auto-check passed
  • Review PR

    TermiX-official/cryptoclaw

    Review-only GitHub pull request analysis with the gh CLI. An agent skill from TermiX-official/cryptoclaw.

    100 GitHub stars~1.7k tokensUpdated 4 mo ago
    Auto-check passed
  • Coingecko

    TermiX-official/cryptoclaw

    Query CoinGecko API for prices, market data, trending tokens, and historical charts.

    100 GitHub starsUsed in 1 repo~755 tokens
    Auto-check passed

Questions about Security Check

What does Security Check do?

Assess token and address security via the GoPlus Security API. Security Check is an agent skill from TermiX-official/cryptoclaw. Assess token and address security via the GoPlus Security API.

When should I use Security Check?

Security Check fits situations like: business, Finance & HR work in your project.

How do I install Security Check in Claude Code?

Run `npx skills add TermiX-official/cryptoclaw --skill security-check -a claude-code`. Or copy the skill folder (skills/security-check in TermiX-official/cryptoclaw) into .claude/skills/security-check in your project. Claude Code loads it when a task matches its description.

How do I install Security Check in Codex?

Run `npx skills add TermiX-official/cryptoclaw --skill security-check -a codex`. Or copy the skill folder (skills/security-check in TermiX-official/cryptoclaw) into .agents/skills/security-check in your project. Codex loads it when a task matches its description.

Can I use Security Check in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add TermiX-official/cryptoclaw --skill security-check -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-check, .gemini/skills/security-check, .github/skills/security-check and .opencode/skills/security-check in your project.

What does Security Check need to run?

SKILL.md names no scripts, command-line tools or credentials: Security Check is instructions for the agent only.

Does Security Check access the network?

SKILL.md names 1 domain. In commands or code: api.gopluslabs.io; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Security Check safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Security Check use?

Security Check is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Check use?

About 945 tokens (SKILL.md is roughly 3.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Check?

Skills that share tags, products or a category with Security Check: Technical Analyst (tradermonty/claude-trading-skills, 3k stars), Creating Financial Models (Chen-zexi/open-ptc-agent, 729 stars), Stock API (zhangxiangliang/stock-api, 2k stars) and Theme Detector (tradermonty/claude-trading-skills, 3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Check?

TermiX-official (a GitHub organization) maintains it in TermiX-official/cryptoclaw, which has 100 GitHub stars. The repository holds 33 skills in this directory. The repository was last updated on May 25, 2026.

Source: TermiX-official/cryptoclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.