skills/defi-risk-assessment/SKILL.md
Framework for evaluating DeFi protocol risk — smart contract audits, TVL analysis, governance structure, oracle dependencies, and token economics. Use when helping users assess protocol safety, compare DeFi options, or identify red flags before depositing funds.
npx skillsauth add aaaaqwq/claude-code-skills defi-risk-assessmentInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
A structured approach for AI agents to evaluate DeFi protocol risk and help users make informed decisions.
The code itself could have vulnerabilities.
Assessment Checklist:
Risk Levels: | Level | Criteria | |-------|---------| | Low | 2+ audits, 1+ year live, open source, large bug bounty | | Medium | 1 audit, 6+ months live, open source | | High | Unaudited or <6 months live | | Critical | Closed source, no audits, anonymous team |
The protocol design could fail under stress.
Key Questions:
Common Failure Modes:
How much control do insiders have?
| Factor | Low Risk | High Risk | |--------|----------|-----------| | Admin keys | Timelock + multisig | Single EOA | | Upgradability | Immutable or governance-gated | Instant proxy upgrade | | Token distribution | Wide distribution | Team holds >40% | | Oracle | Chainlink + fallback | Custom oracle, single source |
Can you exit your position when you need to?
Could regulatory action affect the protocol?
Rate each category 1–5, then calculate:
Overall Risk Score = (SmartContract × 3 + Economic × 2.5 + Centralization × 2 + Liquidity × 1.5 + Regulatory × 1) / 10
| Score | Rating | Recommendation | |-------|--------|---------------| | 1.0–2.0 | Very Low Risk | Suitable for conservative allocations | | 2.0–3.0 | Low Risk | Suitable for most users | | 3.0–3.5 | Medium Risk | Only with risk understanding | | 3.5–4.0 | High Risk | Small allocations only | | 4.0–5.0 | Very High Risk | Avoid for most users |
Aave V3: 10+ audits, 3+ years live, $10B+ TVL, Chainlink oracles, governance timelock, large bug bounty
Sperax USDs: Multiple audits, 100% stablecoin collateral (no volatile assets), Chainlink oracles, 2+ years live, collateral ratio safety checks, bug bounty ($100–$15K)
Newer L2 protocols: 1–2 audits, less than a year live, growing TVL, reasonable governance
Unaudited yield farms: No audits, anonymous team, high APYs from emissions only, proxy contracts, no timelock
Instant disqualifiers:
For agents evaluating a protocol:
testing
通用自媒体文章自动发布工具。支持百家号、搜狐号、知乎、微信公众号、小红书、抖音号六个平台的自动化发布流程。使用Playwright自动化实现平台导航和发布,支持通过storageState管理Cookie实现账号切换。
development
# SKILL.md - Model Configuration Status (mcstatus) ## 触发条件 - `/mcstatus` 命令 - 用户询问模型配备、模型配置、model status、模型列表等 ## 功能 实时生成 Agent + Cron 的模型配置报告,展示当前所有 agent 的主模型/fallback链和所有 cron 任务的模型分配。 ## 执行步骤 ### Step 1: 收集 Agent 模型配置 读取各 agent 的 models.json 获取主模型和 fallback 链: ```bash for agent in main ops code quant data research content market finance pm law product sales batch; do config=$(cat ~/.openclaw/agents/$agent/agent/models.json 2>/dev/null) if [ -n "$config" ]; then echo "=== $agent
tools
MCP 服务器智能管理助手。自动检测 MCP 可用性、智能开关、功能问答,提供人性化的 MCP 管理体验。
tools
从GitHub搜索并自动安装配置MCP(Model Context Protocol)服务器工具到Claude配置文件。当用户需要安装MCP工具时触发此技能。工作流程:搜索GitHub上的MCP项目 -> 提取npx配置 -> 添加到~/.claude.json -> 处理API密钥(如有)。