CryptoSkill CryptoSkill
  • Official
  • Skills
  • Categories
  • How It Works
  • GitHub
Home › Chains › Base Official Plugin Review

Base Official Plugin Review

Chains by @base v1.0.0 B PASS 3 flags

Validate and review Base MCP plugin files against the Plugin Specification. Use when writing a new plugin, preparing a plugin PR for submission, self-checking a plugin before opening a PR, or reviewing someone else's plugin PR. Triggers on requests like "check my plugin against the spec", "validate this plugin file", "review my plugin PR", "does this plugin conform to the spec", "prepare my plugin for submission", "write a plugin for X protocol".

Install

$ cp -r cryptoskill/skills/chains/base-official-plugin-review .claude/skills/
$ clawhub install base-official-plugin-review

Tags

official chains

Quality Score

Score: 64/100 Grade: B Risk Gate: PASS

Trust profile trust grade not computed yet

3 red flags 7 cleared 1 not measured

Capabilities below are detected automatically by an open-source scanner that reads the skill's text and scripts (see how this is computed). Not measured means the scanner couldn't make a confident call — it is NOT a green check, and you should treat it as a possible red flag until a human or a stronger scanner has measured it.

3 Red flags things this skill can do that affect your security or funds
  • ⚠
    Mutable remote runtime runs remote code that can change behavior without a local diff
  • ⚠
    Can install code installs software at setup time (npx, pip, brew, etc.)
  • ⚠
    Can execute shell runs arbitrary shell commands on your machine
7 Cleared by scanner we scanned the skill's text & scripts and found no evidence of these
  • ✓
    Can move funds this skill can sign and send transactions on your behalf
  • ✓
    Requires private key you must hand over a private key, mnemonic, or wallet config
  • ✓
    Requires hosted operator depends on a third-party hosted service to function
  • ✓
    Uses remote install script setup pipes a remote shell script (curl | sh class)
  • ✓
    Can browse the web fetches arbitrary URLs at runtime
  • ✓
    Can write files writes to your local filesystem
  • ✓
    Can spawn sub-agents delegates to other skills or sub-agents
1 Not measured yet scanner couldn't make a confident call — treat as a possible red flag
  • ?
    Auto-invocable may be invoked by the agent without your explicit prompt

Execution mode

unknown

Ingredients (services this skill talks to)

We did not find any well-known hosted services in this skill's text or scripts. This does NOT mean the skill is local-only — it might use services we don't yet recognize, or talk to them through code paths our scanner can't reach. A complete dependency list (every package, library, and binary, with integrity hashes) is on the roadmap; today we only show recognized hosts.

Audits

No one has audited this skill yet. That is different from “audited and clean” — it just means no professional reviewer (a security firm, the CryptoSkill team, or a verified independent researcher) has signed off on it. There are no audit reports to read. How reviewer levels work →

SKILL.md → SOURCE.md → TRUST.auto.yaml → Browse directory →

Auto-generated by cryptoskill/extract-capabilities/0.3.1 · hosted-service list version 2026-09-06 · how this is computed

More from Base

⛓️Base Official Build On Base⛓️Base Official Convert Farcaster Miniapp To App⛓️Base Official Registering Agent Base Dev⛓️Base Official Deploying Contracts On Base⛓️Base Official Building With Base Account⛓️Base Official Adding Builder Codes

Other in Chains

⛓️NEAR Intents 1click Api⛓️Hedera Official Agent Kit Js⛓️Lightning MCP Server⛓️Dfinity Official Wallet Integration⛓️Dfinity Official Ic Dashboard⛓️Dfinity Official Caffeine App

Source

View on GitHub →

CryptoSkillBuilt for the crypto community
GitHub Official Skills Categories Terms Privacy