token-integration-analyzer

by trailofbits 6.6k CC-BY-SA-4.0 Updated Aug 18, 2026
token-integration-analyzer skill by trailofbits
token-integration-analyzer — Integrations skill by trailofbits

token-integration-analyzer is an open-source integrations skill for Claude Code and compatible agents, published by trailofbits. Its author describes it as: “Token integration and implementation analyzer based on Trail of Bits' token integration checklist. Analyzes token implementations for ERC20/ERC721 conformity, checks for 20+ weird token patterns, assesses contract com…”. The project has 6.6k stars on GitHub and is available under the CC-BY-SA-4.0 license. Add it to your setup with `/plugin marketplace add trailofbits/skills`.

What token-integration-analyzer does

Systematically analyzes the codebase for token-related security concerns using Trail of Bits' token integration checklist:

Installation

Add token-integration-analyzer to your agent with:

/plugin marketplace add trailofbits/skills

Always review a skill's source before installing it. This command comes from the skill's public repository; the linked repo is the source of truth for exact setup steps.

What's inside

The SKILL.md for token-integration-analyzer is organised into these sections:

  • Purpose
  • How This Works
  • Phase 1: Context Discovery
  • Phase 2: Slither Analysis (if Solidity)
  • Phase 3: Code Analysis
  • Phase 4: On-chain Analysis (if deployed)
  • Phase 5: Risk Assessment
  • Assessment Categories
  • Quick Reference:
  • Example Output
  • Rationalizations (Do Not Skip)
  • Deliverables

When to use it

Reach for token-integration-analyzer when you want integrations help from your agent without writing the same instructions every session. Load the skill and the agent picks it up automatically for relevant tasks.

Strengths

  • Clear CC-BY-SA-4.0 license — safe to read and adapt
  • Ships in trailofbits/skills, an established project with 6,646 GitHub stars
  • Actively maintained (recent commits)

Topics

agent-skills

Frequently asked questions

What does token-integration-analyzer do?
Token integration and implementation analyzer based on Trail of Bits' token integration checklist. Analyzes token implementations for ERC20/ERC721 conformity, checks for 20+ weird token patterns, assesses contract composition and owner privileges, performs on-chain scarcity analysis, and evaluates how protocols handle non-standard tokens. Context-aware for both token implementations and token integrations.
How do I install token-integration-analyzer?
Run /plugin marketplace add trailofbits/skills in your agent, then reload your skills. Review the source at https://github.com/trailofbits/skills before installing.
Is token-integration-analyzer free to use?
Yes. token-integration-analyzer is free and open source under the CC-BY-SA-4.0 license, so you can read, run, and adapt it within that license's terms.
Where does token-integration-analyzer come from?
token-integration-analyzer ships inside trailofbits/skills, a repository that contains 41 catalogued skills in total. The repository's 6,646 GitHub stars apply to that whole collection, not to this skill on its own.

Related skills

More Integrations →

Diagnose and fix Claude in Chrome MCP extension connectivity issues. Use when mcp__claude-in-chrome__* tools fail, return "Browser extension is not connected", or behave erratically.

6.6k trailofbits CC-BY-SA-4.0

Triages a repository's open GitHub issues and pull requests via the gh CLI. Optionally reviews and merges ready PRs — incrementally merging passing automated/bot PRs and maintainer-approved ones, and spawning review subagents for never-reviewed ones — then closes already-resolved issues with comments citing the resolving PR or commit, cross-links issues with their pending fix PRs, and assigns local-only priority and change-size estimates for everything outstanding. Use when triaging, grooming, or reviewing a repository's open issues and PRs.

6.6k trailofbits CC-BY-SA-4.0

Add a DeepChat LLM provider through explicit reviewed source changes. Use when a developer asks Codex to add a provider, provider profile, upstream provider config, model catalog mapping, provider auth behavior, or a special provider adapter in this repository.

6.2k ThinkInAIXYZ Apache-2.0

Drive native desktop apps through DeepChat's built-in Computer Use tools. Use when the user asks to operate, inspect, automate, or perform a GUI task in a real desktop application.

6.2k ThinkInAIXYZ Apache-2.0

Drive a native macOS app via the cua-driver MCP server or CLI — snapshot its AX tree, click/type/scroll by element_index, verify via re-snapshot. Use when the user asks you to operate, drive, automate, or perform a GUI task in a real macOS application on the host (e.g. "open a file in TextEdit", "navigate to /Applications in Finder", "click the Save button in Numbers").

6.2k ThinkInAIXYZ Apache-2.0