Skip to main content

defi-risk-analysis

Evaluates DeFi protocols' risk profiles by analyzing smart contracts, governance, and historical performance to identify vulnerabilities.

Install this skill

or
0/100

Security score

The defi-risk-analysis skill was audited on May 26, 2026 and we found 42 security issues across 3 threat categories, including 3 high-severity. Review the findings below before installing.

Categories Tested

Security Issues

medium line 734

Template literal with variable interpolation in command context

SourceSKILL.md
734```
medium line 39

Curl to non-GitHub URL

SourceSKILL.md
39curl -s 'https://api.llama.fi/protocols' | jq -r '.[] | select(.name | test("{protocol}"; "i")) | "\(.slug) -- \(.name) -- TVL: \(.tvl)"'
high line 42

Curl to non-GitHub URL

SourceSKILL.md
42Then fetch full data with the resolved slug: `curl -s 'https://api.llama.fi/protocol/{slug}'` to get:
medium line 48

Curl to non-GitHub URL

SourceSKILL.md
48curl -s "https://api.gopluslabs.io/api/v1/token_security/<chain_id>?contract_addresses=<address>"
high line 69

Curl to non-GitHub URL

SourceSKILL.md
69- **RugCheck**: `curl -s 'https://api.rugcheck.xyz/v1/tokens/{mint_address}/report'` -- returns risk score, mutable metadata, freeze authority, mint authority, top holders, LP lock status
high line 70

Curl to non-GitHub URL

SourceSKILL.md
70- **Birdeye**: `curl -s -H 'X-API-KEY: public' 'https://public-api.birdeye.so/public/token_security?address={mint_address}'` -- holder concentration, LP info
medium line 81

Curl to non-GitHub URL

SourceSKILL.md
81curl -s "https://api.gopluslabs.io/api/v1/address_security/<address>?chain_id=<chain_id>"
medium line 206

Curl to non-GitHub URL

SourceSKILL.md
206curl -s 'https://api.llama.fi/protocol/{slug}' | jq '{audits, audit_note, audit_links}'
medium line 416

Curl to non-GitHub URL

SourceSKILL.md
416curl -s "https://api.etherscan.io/api?module=contract&action=getsourcecode&address=<address>&apikey=<key>"
medium line 418

Curl to non-GitHub URL

SourceSKILL.md
418curl -s "https://api.arbiscan.io/api?module=contract&action=getsourcecode&address=<address>&apikey=<key>"
medium line 580

Curl to non-GitHub URL

SourceSKILL.md
580curl -s "https://api.etherscan.io/api?module=logs&action=getLogs&address={proxy}&topic0=0xbc7cd75a20ee27fd9adebab32041f755214dbc6bffa90cc0225b39da2e5c2d3b&apikey={key}"
low line 39

External URL reference

SourceSKILL.md
39curl -s 'https://api.llama.fi/protocols' | jq -r '.[] | select(.name | test("{protocol}"; "i")) | "\(.slug) -- \(.name) -- TVL: \(.tvl)"'
low line 42

External URL reference

SourceSKILL.md
42Then fetch full data with the resolved slug: `curl -s 'https://api.llama.fi/protocol/{slug}'` to get:
low line 48

External URL reference

SourceSKILL.md
48curl -s "https://api.gopluslabs.io/api/v1/token_security/<chain_id>?contract_addresses=<address>"
low line 69

External URL reference

SourceSKILL.md
69- **RugCheck**: `curl -s 'https://api.rugcheck.xyz/v1/tokens/{mint_address}/report'` -- returns risk score, mutable metadata, freeze authority, mint authority, top holders, LP lock status
low line 70

External URL reference

SourceSKILL.md
70- **Birdeye**: `curl -s -H 'X-API-KEY: public' 'https://public-api.birdeye.so/public/token_security?address={mint_address}'` -- holder concentration, LP info
low line 81

External URL reference

SourceSKILL.md
81curl -s "https://api.gopluslabs.io/api/v1/address_security/<address>?chain_id=<chain_id>"
low line 206

External URL reference

SourceSKILL.md
206curl -s 'https://api.llama.fi/protocol/{slug}' | jq '{audits, audit_note, audit_links}'
low line 218

External URL reference

SourceSKILL.md
218https://{domain}/audits
low line 219

External URL reference

SourceSKILL.md
219https://{domain}/security
low line 416

External URL reference

SourceSKILL.md
416curl -s "https://api.etherscan.io/api?module=contract&action=getsourcecode&address=<address>&apikey=<key>"
low line 418

External URL reference

SourceSKILL.md
418curl -s "https://api.arbiscan.io/api?module=contract&action=getsourcecode&address=<address>&apikey=<key>"
low line 580

External URL reference

SourceSKILL.md
580curl -s "https://api.etherscan.io/api?module=logs&action=getLogs&address={proxy}&topic0=0xbc7cd75a20ee27fd9adebab32041f755214dbc6bffa90cc0225b39da2e5c2d3b&apikey={key}"
low line 721

External URL reference

SourceSKILL.md
721- Squads v3/v4 multisig: follow up at https://v4.squads.so/ for threshold/members
low line 1015

External URL reference

SourceSKILL.md
1015- Protocol info: `https://api.llama.fi/protocol/{slug}`
low line 1016

External URL reference

SourceSKILL.md
1016- All protocols: `https://api.llama.fi/protocols`
low line 1018

External URL reference

SourceSKILL.md
1018- Yields: `https://yields.llama.fi/pools`
low line 1022

External URL reference

SourceSKILL.md
1022Base URL: `https://api.gopluslabs.io/api/v1`
low line 1048

External URL reference

SourceSKILL.md
1048| Ethereum | `https://safe-transaction-mainnet.safe.global/api/v1` |
low line 1049

External URL reference

SourceSKILL.md
1049| Arbitrum | `https://safe-transaction-arbitrum.safe.global/api/v1` |
low line 1050

External URL reference

SourceSKILL.md
1050| Polygon | `https://safe-transaction-polygon.safe.global/api/v1` |
low line 1051

External URL reference

SourceSKILL.md
1051| Optimism | `https://safe-transaction-optimism.safe.global/api/v1` |
low line 1052

External URL reference

SourceSKILL.md
1052| Base | `https://safe-transaction-base.safe.global/api/v1` |
low line 1053

External URL reference

SourceSKILL.md
1053| BSC | `https://safe-transaction-bsc.safe.global/api/v1` |
low line 1063

External URL reference

SourceSKILL.md
1063| 1 (Ethereum) | `https://api.etherscan.io/api` |
low line 1064

External URL reference

SourceSKILL.md
1064| 56 (BSC) | `https://api.bscscan.com/api` |
low line 1065

External URL reference

SourceSKILL.md
1065| 137 (Polygon) | `https://api.polygonscan.com/api` |
low line 1066

External URL reference

SourceSKILL.md
1066| 42161 (Arbitrum) | `https://api.arbiscan.io/api` |
low line 1067

External URL reference

SourceSKILL.md
1067| 10 (Optimism) | `https://api-optimistic.etherscan.io/api` |
low line 1068

External URL reference

SourceSKILL.md
1068| 8453 (Base) | `https://api.basescan.org/api` |
low line 1076

External URL reference

SourceSKILL.md
1076- **URL**: `https://api.mainnet-beta.solana.com` (or set `SOLANA_RPC_URL` env var)
low line 1084

External URL reference

SourceSKILL.md
1084| `https://api.solana.fm/v0/accounts/{address}` | Account label, owner program, type detection |
Scanned on May 26, 2026
View Security Dashboard
Installation guide →