New to Claude Skills? Learn how to install them →

jeremylongshore on GitHub

Wallet Security Auditor

Free

Analyze and enhance your cryptocurrency wallet security.

Get this skill

Free · Opens the source repo

What Wallet Security Auditor does

The Wallet Security Auditor is a specialized tool designed to perform in-depth security analyses of cryptocurrency wallets. It focuses on scanning ERC20 token approvals, evaluating transaction patterns, and calculating security risk scores to help users understand their wallet's exposure to potential threats. This tool is particularly useful for developers and cryptocurrency enthusiasts who want to ensure their wallets are secure and free from vulnerabilities.

Using the Wallet Security Auditor, users can conduct various assessments, including listing active token approvals, performing comprehensive security scans, and generating risk scores based on multiple criteria. The tool's functionality allows users to identify unlimited or risky approvals, analyze transaction history, and detect suspicious activities, providing a clear picture of the wallet's security posture. The output includes detailed reports that highlight vulnerabilities and offer actionable recommendations to improve wallet security.

This skill is ideal for anyone involved in cryptocurrency, from casual users to developers and security professionals. By leveraging the Wallet Security Auditor, users can proactively manage their wallet security, making informed decisions about which approvals to revoke and how to mitigate risks effectively. The tool's read-only nature ensures that it does not interfere with wallet operations or private keys, making it a safe choice for security audits.

Overall, the Wallet Security Auditor is an essential resource for anyone looking to enhance their cryptocurrency wallet security through thorough analysis and actionable insights.

When to use it

Use this tool when you need to audit a wallet's security, review token approvals, or assess risk exposure.

When not to use it

This skill is not suitable for executing transactions or managing private keys, as it is strictly a read-only analysis tool.

What you can build with it

Conducting a Security Audit

Use the Wallet Security Auditor to perform a comprehensive security audit of your wallet before making any significant transactions.

Reviewing Token Approvals

Quickly scan your wallet to list all active ERC20 token approvals and identify any that may pose a security risk.

Generating Risk Reports

Create detailed reports to share with team members or for personal records to track the security status of your cryptocurrency wallet.

How to install Wallet Security Auditor

View source

1. Install with the skills CLI

npx skills add jeremylongshore/claude-code-plugins-plus-skills/auditing-wallet-security --agent claude-code

2. Or install it manually

Download the skill folder and drop it into ~/.claude/skills/ for all projects, or .claude/skills/ to scope it to one repo. Restart Claude Code so it picks up the new skill.

Anthropic's agentic coding CLI, and the reference implementation of Agent Skills. Drop a skill folder into ~/.claude/skills and Claude Code loads it automatically whenever a task matches the skill's description. Claude Code docs

Inside SKILL.md

Written by jeremylongshore

Wallet Security Auditor

Overview

Security analysis tool for cryptocurrency wallets. Scans ERC20 token approvals, analyzes transaction patterns, calculates security risk scores, and provides actionable recommendations to improve wallet security.

Important: This is a read-only analysis tool. It does NOT execute transactions, manage private keys, or perform revocations.

Prerequisites

Before using this skill, ensure you have:

  • Python 3.8+ with requests library installed
  • Optional: ETHERSCAN_API_KEY environment variable for higher rate limits
  • Network access to blockchain RPC endpoints (public RPCs included)
  • Target wallet address (hex format, 0x...)

Instructions

1. List Token Approvals

Scan wallet for all active ERC20 token approvals:

cd ${CLAUDE_SKILL_DIR}/scripts
python wallet_auditor.py approvals <address> --chain <chain>

Options:

  1. --chain: ethereum, bsc, polygon, arbitrum, optimism, base (default: ethereum)
  2. --unlimited: Show only unlimited approvals
  3. --verbose: Detailed output

2. Full Security Scan

Comprehensive security analysis including approvals, transaction history, and patterns:

python wallet_auditor.py scan <address> --verbose

Analyzes: 4. Active token approvals (unlimited, risky) 5. Transaction history patterns 6. Contract interactions (verified vs unverified) 7. Suspicious activity detection

3. Calculate Security Score

Get weighted security risk score (0-100, higher = safer):

python wallet_auditor.py score <address>
python wallet_auditor.py score <address> --json  # JSON output

Score components: 8. Approvals (40%): Unlimited, risky, stale approvals 9. Interactions (30%): Contract verification, flagged addresses 10. Patterns (20%): Transaction frequency, diversity 11. Age (10%): Wallet maturity

Risk levels: 12. 90-100: SAFE 13. 70-89: LOW 14. 50-69: MEDIUM 15. 30-49: HIGH 16. 0-29: CRITICAL

4. Analyze Transaction History

Review recent contract interactions and patterns:

python wallet_auditor.py history <address> --days 30

Detects: 17. Rapid approval patterns 18. Interaction bursts (many contracts in short time) 19. High failure rates 20. Dust attacks

5. Generate Revoke List

Get prioritized list of approvals to revoke:

python wallet_auditor.py revoke-list <address>

Flags: 21. Unlimited approvals to unknown contracts 22. Risky/flagged spenders 23. Stale approvals (>6 months)

6. Generate Full Report

Create comprehensive security audit report:

python wallet_auditor.py report <address> --output report.txt
python wallet_auditor.py report <address> --json  # JSON format

7. List Supported Chains

python wallet_auditor.py chains

Output

Security Score Report

╔═══════════════════════════════════════════════════════════════════╗
║                    WALLET SECURITY SCORE                          ║
╠═══════════════════════════════════════════════════════════════════╣
║  Overall Score:  [████████████████····] 82/100                    ║
║  Risk Level:     🟢 LOW                                           ║
╠═══════════════════════════════════════════════════════════════════╣
║  Component Scores:                                                ║
║    Approvals:     [██████████████······] 70/100                   ║
║    Interactions:  [██████████████████··] 90/100                   ║
║    Patterns:      [████████████████████] 100/100                  ║
╚═══════════════════════════════════════════════════════════════════╝

Approval Summary

  • Total active approvals count
  • Unlimited approvals flagged
  • Risky approvals with severity
  • Unique spenders and tokens

Risk Factors

  • [CRITICAL] Unlimited approval to unknown contract
  • [HIGH] Approval to flagged contract
  • [MEDIUM] Many unlimited approvals (>5)
  • [LOW] Interaction with unverified contract

Recommendations

  • Priority 1: Revoke risky approvals immediately
  • Priority 2: Review unnecessary unlimited approvals
  • Priority 3: Audit all approvals periodically

Error Handling

See ${CLAUDE_SKILL_DIR}/references/errors.md for comprehensive error handling:

ErrorCauseSolution
Address validation failedInvalid formatUse 0x + 40 hex characters
RPC timeoutNode unresponsiveRetry or use different RPC
Rate limitedToo many requestsAdd ETHERSCAN_API_KEY
No approvals foundWallet cleanNormal - no action needed

Examples

See ${CLAUDE_SKILL_DIR}/references/examples.md for detailed examples.

Quick Security Check

# Check wallet approvals
python wallet_auditor.py approvals 0xd8dA6BF26964aF9D7eEd9e03E53415D37aA96045

# Full security scan
python wallet_auditor.py scan 0xd8dA6BF26964aF9D7eEd9e03E53415D37aA96045 --verbose

# Get security score
python wallet_auditor.py score 0xd8dA6BF26964aF9D7eEd9e03E53415D37aA96045

# Check other chains
python wallet_auditor.py approvals 0x... --chain polygon
python wallet_auditor.py approvals 0x... --chain arbitrum

Generate Audit Report

# Text report
python wallet_auditor.py report 0x... --output security_audit.txt

# JSON for integration
python wallet_auditor.py report 0x... --json --output audit.json

Resources

  • revoke.cash: Web UI for revoking approvals
  • Etherscan Token Approval Checker: View/revoke on block explorer
  • Etherscan API: https://docs.etherscan.io/api-endpoints
  • ERC20 Approval Event: Topic 0x8c5be1e5ebec7d5bd14f71427d1e84f3dd0314c0f7b2291e5b200ac8c7c3b925
  • GoPlus Security API: Additional contract risk data

Frequently asked questions about Wallet Security Auditor

Similar skills