[new-plugin] stablecoin-chain-explorer#101
Conversation
…blecoin data explorer across multiple chains
✅ Phase 1: Structure Validation — PASSED→ Proceeding to Phase 2: Build Verification |
📋 Phase 3: AI Code Review Report — Score: 92/100
1. Plugin Overview
Summary: A read-only analytics skill that compares stablecoin TVL distribution and yield opportunities across blockchains by calling Barker's public API (api.barker.money). Returns cross-chain comparison tables with TVL share, top APYs, and gas estimates. Target Users: DeFi users researching where to allocate stablecoins across chains (Ethereum, BSC, Arbitrum, Base, Polygon, etc.) for yield optimization. 2. Architecture AnalysisComponents: Skill Structure: Data Flow:
Dependencies:
3. Auto-Detected Permissionsonchainos Commands Used
Wallet Operations
External APIs / URLs
Chains Operated OnRead-only references to Ethereum, BSC, Arbitrum, Base, Polygon, Optimism, Avalanche, Solana. No on-chain operations. Overall Permission SummaryThis is a pure read-only analytics skill. It calls two public, unauthenticated endpoints on 4. onchainos API ComplianceDoes this plugin use onchainos CLI for all on-chain write operations?N/A — plugin performs no on-chain write operations. onchainos usage is optional per Plugin Store policy. On-Chain Write Operations (MUST use onchainos)
Data Queries (allowed to use external sources)
External APIs / Libraries DetectedOnly Verdict: ✅ Fully CompliantRead-only analytics plugin with no on-chain operations. Public data API usage is allowed. 5. Security AssessmentStatic Rule Scan (C01-C09, H01-H09, M01-M08, L01-L02)
No other static rules match. No curl|sh, no credential access, no persistence, no obfuscation, no prompt injection, no hardcoded secrets, no dangerous network patterns, no resource exhaustion, no skill chaining. LLM Judge Analysis (L-PINJ, L-MALI, L-MEMA, L-IINJ, L-AEXE, L-FINA, L-FISO)
Toxic Flow Detection (TF001-TF006)No toxic flows detected. No combination of network access + sensitive paths + financial operations. Prompt Injection ScanNo Result: ✅ Clean Dangerous Operations CheckNo transfers, signing, contract calls, or transaction broadcasts. Plugin is pure read-only data retrieval. Result: ✅ Safe Data Exfiltration RiskPlugin transmits only public query parameters (chain name, asset symbol, sort, limit) to Result: ✅ No Risk Overall Security Rating: 🟢 Low Risk7. Code ReviewQuality Score: 92/100
Strengths
Issues Found
8. Language Check
Chinese phrases in SKILL.md ("哪条链稳定币多", "找稳定币理财,上 Barker") are localized trigger keywords and brand slogan — body text is English. 9. SUMMARY.md Review
11. Recommendations
12. Reviewer SummaryOne-line verdict: Clean, well-scoped read-only analytics plugin with strong security hygiene and explicit untrusted-data declarations — ready to merge. Merge recommendation: ✅ Ready to merge Blockers (if any — list every issue that MUST be fixed before merge, each prefixed with ❌): No blockers found. Minor improvements (non-blocking) listed in Recommendations above. Generated by Claude AI via Anthropic API — review the full report before approving. |
✅ Phase 4: Publish CompletePlugins:
Published by Plugin Store CI |
Plugin Submission
Plugin name: stablecoin-chain-explorer
Version: 0.1.0
Author: Barker (@YBSbarker)
Type: new-plugin (skill-only)
What does this plugin do?
Checklist
name,description).claude-plugin/plugin.jsonpresentSource:
barker-stablecoin-skills-7bc027c.zip