Token integration and implementation analyzer based on Trail of Bits' token integration checklist. Analyzes token implementations for ERC20/ERC721 conformity, checks for 20+ weird token patterns, assesses contract composition and owner privileges, performs on-chain scarcity analysis, and evaluates how protocols handle non-standard tokens. Context-aware for both token implementations and token integrations.
The token-integration-analyzer skill provides a comprehensive framework for evaluating token implementations and integrations within smart contract projects. It is designed to identify security risks, non-standard behaviors, and potential vulnerabilities in ERC20 and ERC721 tokens. By leveraging the Trail of Bits' token integration checklist, the skill systematically analyzes both the creation of tokens and how protocols interact with them, ensuring compliance with established standards and detecting deviations that could lead to security or functional issues. This skill addresses the challenges developers face when integrating third-party tokens or creating new tokens while maintaining robust security and protocol integrity.
The skill features multiple analysis phases, including context discovery, code analysis, Slither-based Solidity checks, on-chain analysis, and risk assessment. Key capabilities include detecting 20+ known weird token patterns, assessing contract composition and owner privileges, evaluating token scarcity and distribution, and providing integration safety insights. For Solidity projects, it supports Slither-based ERC conformity checks, complexity summaries, function analysis, and property generation for testing. The skill also provides a prioritized risk assessment with identified vulnerabilities, non-standard behaviors, and integration risks, covering ten comprehensive security categories from general considerations to specific ERC20 and ERC721 conformity checks.
Target users include blockchain developers, smart contract auditors, and security researchers working with Ethereum or other EVM-compatible chains. It is particularly useful for teams developing their own tokens or integrating external tokens into protocols, ensuring adherence to standards, minimizing centralization risks, and detecting unusual token behaviors. Use cases range from pre-deployment token audits to on-chain monitoring of deployed contracts, helping teams maintain secure, transparent, and robust token ecosystems.
You provide the token contract code or address, and the skill runs context discovery, code analysis, Slither checks (for Solidity), on-chain analysis, and generates a risk assessment based on known token patterns and integration safety checks.
The skill is compatible with ERC20 and ERC721 tokens and can analyze standard compliance as well as non-standard behaviors or extensions within these token types.
Yes, if you provide a contract address, it queries on-chain data such as token scarcity, distribution, total supply, holder concentration, exchange listings, and configuration to assess risks.
Slither-based analysis is specific to Solidity, so projects using other languages or platforms may rely primarily on code inspection, integration pattern analysis, and on-chain queries where applicable.
It identifies vulnerabilities related to non-standard token behaviors, owner privileges, contract composition, ERC20/ERC721 conformity issues, known weird token patterns, and unsafe integration practices.
Quick Setup:
.claude/skills/Repository
trailofbits/skills