SKILLEMALL.ai

BC poseidon-otc

Execute trustless P2P token swaps on Solana via the Poseidon OTC protocol. Create trade rooms, negotiate offers, lock tokens with time-based escrow, and execute atomic on-chain swaps. Supports agent-to-agent trading with real-time WebSocket updates.

ClawHub Agent Skills author: Romovow v1.0.0 6 files body ≈ 2 682 tokens Open the sourceclawhub.ai analyzed 3 d ago

As a process C 51/100 · Has gaps — weak spots: result and completion, when it triggers, inputs and preconditions

GeneratorAI and agentsInfrastructureSales and CRMtype and topics are labelled automatically from the skill text
JSON
Technical rating
B
86/100
safety, quality, tests
Safety 60%
88
Quality 40%
84
Run on models
none yet
Process rating
C
51/100
Has gaps
Result and completion w 14
0
Inputs and preconditions w 11
0
Failures and branches w 10
0
the three weakest of ten parameters · all ten

How to improve

    For the model run — optional
    • Your own cases (evals/evals.json, 4–6 real requests with expected answers): the full check would then run those instead of a model-drafted suite.
    • A spec.yaml with trigger phrases and assertions — a behaviour contract for CI; `skilltest init` writes a template.

    Guard findings · 12

    ✓ No critical or high findings

    Medium and low: 12
    • low Secrets in code secret-high-entropy-token README.md:55
      High-entropy token-like string (may be an id, hash or a credential) (quoted — discussed, not commanded)
      { mint: 'EPjF…t1v', amount: 100000000, decimals: 6 }
      quoted
    • low Secrets in code secret-high-entropy-token README.md:130
      High-entropy token-like string (may be an id, hash or a credential) (quoted — discussed, not commanded)
      **Mainnet:** `AfiR…KUN`
      quoted
    • low Secrets in code secret-high-entropy-token SKILL.md:43
      High-entropy token-like string (may be an id, hash or a credential) (quoted — discussed, not commanded)
      mint: 'EPjF…t1v',  // USDC mint
      quoted
    • low Secrets in code secret-high-entropy-token SKILL.md:205
      High-entropy token-like string (may be an id, hash or a credential) (quoted — discussed, not commanded)
      mint: 'EPjF…t1v',
      quoted
    • low Secrets in code secret-high-entropy-token SKILL.md:233
      High-entropy token-like string (may be an id, hash or a credential) (quoted — discussed, not commanded)
      mint: 'So11…112',  // wSOL
      quoted
    • low Secrets in code secret-high-entropy-token SKILL.md:257
      High-entropy token-like string (may be an id, hash or a credential) (documentation table row)
      | USDC | `EPjF…t1v` | 6 |
      table
    • low Secrets in code secret-high-entropy-token SKILL.md:258
      High-entropy token-like string (may be an id, hash or a credential) (documentation table row)
      | USDT | `Es9v…NYB` | 6 |
      table
    • low Secrets in code secret-high-entropy-token src/index.ts:35
      High-entropy token-like string (may be an id, hash or a credential) (quoted — discussed, not commanded)
      const OTC_PROGRAM_ID = new PublicKey('AfiR…KUN');
      quoted
    • low Secrets in code secret-high-entropy-token src/index.ts:517
      High-entropy token-like string (may be an id, hash or a credential) (quoted — discussed, not commanded)
      const RELAYER_PUBKEY = new PublicKey('8Ty6…nuv');
      quoted
    • low Secrets in code secret-high-entropy-token src/index.ts:518
      High-entropy token-like string (may be an id, hash or a credential) (quoted — discussed, not commanded)
      const TOKEN_PROGRAM_ID = new PublicKey('Toke…5DA');
      quoted
    • low Secrets in code secret-high-entropy-token src/index.ts:519
      High-entropy token-like string (may be an id, hash or a credential) (quoted — discussed, not commanded)
      const WSOL_MINT = new PublicKey('So11…112');
      quoted
    • low Secrets in code secret-high-entropy-token src/index.ts:561
      High-entropy token-like string (may be an id, hash or a credential) (quoted — discussed, not commanded)
      { pubkey: new PublicKey('Sysv…111'), isSigner: false, isWritable: false },
      quoted

    Files scanned: 6. Evidence is masked. Grey chips explain why severity was lowered.

    Against the Agent Skills spec

    ✓ No remarks against the Agent Skills spec

    Process rating: all ten parameters 51/100

    • 0Result and completion. Does not say what the result is
    • 0Inputs and preconditions. Does not say what the process needs to start
    • 0Failures and branches. Linear process with no failure handling
    • 0Progress reporting. Says nothing while it works
    • 20When it triggers. No condition that starts the skill
    • 30Running it twice. 5 mutating operations with no state check
    • 100Tools and files. No external tools needed
    • 100Steps. 12 steps
    • 100Consistency. Name and required fields are in place
    • 100Execution cost. Instruction body is 2682 tokens
    • medium Safety rules and hard prohibitions inside a skill: they belong in the system prompt, here they protect nothing
    • low 11 top-level sections: this looks like several domains in one skill

    Everything here is measured from the skill text rather than judged by a model, so the numbers are checkable. A parameter weighs more when it is a more common reason for the process to stall.

    Quality signals

    • +5Description has no quoted example phrases that should trigger the skill
    • +4Description does not say when NOT to use the skill (false activations)
    • +3Output format is not stated: the model decides each time
    • +1No license
    • +2Single-language instructions
    • +3Description length 249: enough signal without eating the budget
    • +4Structure: 25 headings
    • +3Step-by-step instructions: 12 items
    • +4Has examples (10 code blocks)

    Quality base 70; lint remarks subtract, signals add up to 100. Result: 84.

    External checks

    ClawHub: suspicious
    This skill does what it says, but it can move real Solana funds with a hot wallet and has under-scoped authorization and secret-handling risks users should review carefully.
    LLM: suspicious (high) · VirusTotal: benign · 10 Sept 2026