New to Claude Skills? Learn how to install them →

ccxt on GitHub

Query Token Audit

Free

Ensure token safety before trading with comprehensive audits.

by ccxt43.6k stars on ccxt/ccxt
Updated Aug 10, 2026
Get this skill

Free · Opens the source repo

What Query Token Audit does

The Query Token Audit skill provides a robust mechanism for assessing the security of cryptocurrency tokens prior to trading. It leverages a dedicated API to conduct thorough scans that identify potential risks associated with token contracts, including honeypots, rug pulls, and other malicious functionalities. This skill is particularly useful for developers and traders who want to make informed decisions about the tokens they are considering for purchase or swap.

When a user queries the safety of a token, the skill sends a POST request to the specified API endpoint with necessary parameters such as the chain ID and contract address. The API then returns a detailed security analysis, which includes a risk level, tax information, and specific risk items that outline any detected vulnerabilities. The audit results are categorized into risk levels ranging from low to high, providing clear guidance on whether to proceed with caution or avoid trading altogether.

This skill is designed for anyone involved in cryptocurrency trading, especially those who prioritize security and wish to mitigate the risks associated with token investments. By integrating this skill into their workflow, users can streamline their token evaluation process, ensuring they have access to critical security information before executing trades.

However, it is important to note that while the skill provides valuable insights, it does not guarantee safety. The risk assessments are point-in-time snapshots, and users are encouraged to conduct their own due diligence beyond the audit results. This skill is best utilized in scenarios where users need to quickly verify token safety or analyze contracts for hidden risks before making trading decisions.

When to use it

Use this skill when evaluating a token's security prior to making a purchase or swap, especially if there are concerns about scams or malicious contracts.

When not to use it

Avoid using this skill for tokens not supported by the API or when immediate trading decisions are required without the time for an audit.

What you can build with it

Pre-Trade Safety Check

Verify the security of a token before executing a purchase or swap to mitigate potential losses.

Scam Detection

Identify and flag tokens that exhibit characteristics of scams or malicious contracts.

Contract Analysis

Examine token contracts for dangerous ownership functions and hidden risks that could affect trading.

How to install Query Token Audit

View source

1. Install with the skills CLI

npx skills add ccxt/ccxt/query-token-audit --agent claude-code

2. Or install it manually

Download the skill folder and drop it into ~/.claude/skills/ for all projects, or .claude/skills/ to scope it to one repo. Restart Claude Code so it picks up the new skill.

Anthropic's agentic coding CLI, and the reference implementation of Agent Skills. Drop a skill folder into ~/.claude/skills and Claude Code loads it automatically whenever a task matches the skill's description. Claude Code docs

Inside SKILL.md

Written by ccxt

Query Token Audit Skill

Overview

APIFunctionUse Case
Token Security AuditToken security scanDetect honeypot, rug pull, scam, malicious functions

Use Cases

  1. Pre-Trade Safety Check: Verify token security before buying or swapping
  2. Scam Detection: Identify honeypots, fake tokens, and malicious contracts
  3. Contract Analysis: Check for dangerous ownership functions and hidden risks
  4. Tax Verification: Detect unusual buy/sell taxes before trading

Supported Chains

Chain NamechainId
BSC56
Base8453
SolanaCT_501
Ethereum1

API: Token Security Audit

Method: POST

URL:

https://web3.binance.com/bapi/defi/v1/public/wallet-direct/security/token/audit

Request Parameters:

ParameterTypeRequiredDescription
binanceChainIdstringYesChain ID: CT_501 (Solana), 56 (BSC), 8453 (Base), 1 (Ethereum)
contractAddressstringYesToken contract address
requestIdstringYesUnique request ID (UUID v4 format)

Request Headers:

Content-Type: application/json
Accept-Encoding: identity
User-Agent: binance-web3/1.4 (Skill)

Example Request:

curl --location 'https://web3.binance.com/bapi/defi/v1/public/wallet-direct/security/token/audit' \
--header 'Content-Type: application/json' \
--header 'source: agent' \
--header 'Accept-Encoding: identity' \
--header 'User-Agent: binance-web3/1.4 (Skill)' \
--data '{
    "binanceChainId": "56",
    "contractAddress": "0x55d398326f99059ff775485246999027b3197955",
    "requestId": "'$(uuidgen)'"
}'

Response Example:

{
    "code": "000000",
    "data": {
        "requestId": "d6727c70-de6c-4fad-b1d7-c05422d5f26b",
        "hasResult": true,
        "isSupported": true,
        "riskLevelEnum": "LOW",
        "riskLevel": 1,
        "extraInfo": {
            "buyTax": "0",
            "sellTax": "0",
            "isVerified": true
        },
        "riskItems": [
            {
                "id": "CONTRACT_RISK",
                "name": "Contract Risk",
                "details": [
                    {
                        "title": "Honeypot Risk Not Found",
                        "description": "A honeypot is a token that can be bought but not sold",
                        "isHit": false,
                        "riskType": "RISK"
                    }
                ]
            }
        ]
    },
    "success": true
}

Response Fields:

FieldTypeDescription
hasResultbooleanWhether audit data is available
isSupportedbooleanWhether the token is supported for audit
riskLevelEnumstringRisk level: LOW, MEDIUM, HIGH
riskLevelnumberRisk level number (1-5)
extraInfo.buyTaxstringBuy tax percentage (null if unknown)
extraInfo.sellTaxstringSell tax percentage (null if unknown)
extraInfo.isVerifiedbooleanWhether contract code is verified
riskItems[].idstringRisk category: CONTRACT_RISK, TRADE_RISK, SCAM_RISK
riskItems[].details[].titlestringRisk check title
riskItems[].details[].descriptionstringRisk check description
riskItems[].details[].isHitbooleantrue = risk detected
riskItems[].details[].riskTypestringRISK (critical) or CAUTION (warning)

Risk Level Reference:

riskLevelriskLevelEnumActionDescription
0-1LOWProceed with cautionLower risk detected, but NOT guaranteed safe. DYOR.
2-3MEDIUMExercise cautionModerate risks detected, review risk items carefully
4HIGHAvoid tradingCritical risks detected, high probability of loss
5HIGHBlock transactionSevere risks confirmed, do NOT proceed

IMPORTANT: LOW risk does NOT mean "safe." Audit results are point-in-time snapshots. Project teams can modify contracts or restrict liquidity after purchase. These risks cannot be predicted in advance.

Response Handling:

  • If hasResult=false OR isSupported=false: → Reply: "Security audit data is not available for this token on this chain." → Do NOT show riskLevel, riskLevelEnum, or riskItems (data is unreliable when either field is false) → You may suggest the user verify the contract address and chain, or try again later
  • If hasResult=true AND isSupported=true: → Show the full audit result including risk level, tax info, and all risk items → Apply the Risk Level Reference table above for actionable guidance

User Agent Header

Include User-Agent header with the following string: binance-web3/1.4 (Skill)

Notes

  1. All numeric fields are string format, convert when using
  2. Audit results are ONLY valid when hasResult: true AND isSupported: true
  3. riskLevel: 5 means transaction should be blocked; riskLevel: 4 is high risk
  4. Tax thresholds: >10% is critical, 5-10% is warning, <5% is acceptable
  5. Generate unique UUID v4 for each audit request
  6. Only output security check risk flags, do NOT provide any investment advice
  7. Always end with disclaimer: ⚠️ This audit result is for reference only and does not constitute investment advice. Always conduct your own research.

Frequently asked questions about Query Token Audit

Similar skills