skills/defi-risk-assessment/SKILL.md
Framework for evaluating DeFi protocol risk — smart contract audits, TVL analysis, governance structure, oracle dependencies, and token economics. Use when helping users assess protocol safety, compare DeFi options, or identify red flags before depositing funds.
npx skillsauth add aaaaqwq/agi-super-skills defi-risk-assessmentInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
A structured approach for AI agents to evaluate DeFi protocol risk and help users make informed decisions.
The code itself could have vulnerabilities.
Assessment Checklist:
Risk Levels: | Level | Criteria | |-------|---------| | Low | 2+ audits, 1+ year live, open source, large bug bounty | | Medium | 1 audit, 6+ months live, open source | | High | Unaudited or <6 months live | | Critical | Closed source, no audits, anonymous team |
The protocol design could fail under stress.
Key Questions:
Common Failure Modes:
How much control do insiders have?
| Factor | Low Risk | High Risk | |--------|----------|-----------| | Admin keys | Timelock + multisig | Single EOA | | Upgradability | Immutable or governance-gated | Instant proxy upgrade | | Token distribution | Wide distribution | Team holds >40% | | Oracle | Chainlink + fallback | Custom oracle, single source |
Can you exit your position when you need to?
Could regulatory action affect the protocol?
Rate each category 1–5, then calculate:
Overall Risk Score = (SmartContract × 3 + Economic × 2.5 + Centralization × 2 + Liquidity × 1.5 + Regulatory × 1) / 10
| Score | Rating | Recommendation | |-------|--------|---------------| | 1.0–2.0 | Very Low Risk | Suitable for conservative allocations | | 2.0–3.0 | Low Risk | Suitable for most users | | 3.0–3.5 | Medium Risk | Only with risk understanding | | 3.5–4.0 | High Risk | Small allocations only | | 4.0–5.0 | Very High Risk | Avoid for most users |
Aave V3: 10+ audits, 3+ years live, $10B+ TVL, Chainlink oracles, governance timelock, large bug bounty
Sperax USDs: Multiple audits, 100% stablecoin collateral (no volatile assets), Chainlink oracles, 2+ years live, collateral ratio safety checks, bug bounty ($100–$15K)
Newer L2 protocols: 1–2 audits, less than a year live, growing TVL, reasonable governance
Unaudited yield farms: No audits, anonymous team, high APYs from emissions only, proxy contracts, no timelock
Instant disqualifiers:
For agents evaluating a protocol:
testing
AI驱动的智能浏览器自动化工具。使用LLM理解页面并自动执行任务,比传统Playwright更智能、更省token。适用于复杂交互、动态页面、需要智能决策的浏览器操作。Chrome浏览器优先。
tools
网页登录态管理。使用 fast-browser-use (fbu) 管理各平台登录状态,定期检查可用性,新平台授权时自动保存 profile。
development
Monitor and report on API provider quotas, balances, and usage. Query official providers (Moonshot, DeepSeek, xAI, Google AI Studio) and relay/proxy providers (Xingjiabiapi, Aixn, WoW) via their billing APIs. Also checks subscription services (Brave Search, OpenRouter). Generates quota reports. Triggers on "查额度", "API余额", "quota check", "billing report", "api balance", "供应商额度", "中转站余额", "费用报告", "check balance", "how much credit".
development
# A股基金监控 Skill A股基金净值监控,支持实时估值和盘后净值,自动判断交易日/节假日。 ## 用法 ### 快速监控(命令行) ```bash # 默认配置,输出到控制台 bash ~/clawd/skills/a-fund-monitor/scripts/monitor.sh # 推送到群(使用--push参数) bash ~/clawd/skills/a-fund-monitor/scripts/monitor.sh --push # 监控指定基金 bash ~/clawd/skills/a-fund-monitor/scripts/monitor.sh --codes "000979 002943" ``` ### Agent调用 ``` 执行A股基金监控任务。 1. 读取配置文件: ~/clawd/skills/a-fund-monitor/config.json 2. 获取实时净值数据 3. 非交易日自动切换为简短报告 配置文件格式: { "funds": [ {"code": "000979", "name": "景顺长城沪港深精选股票