CryptoSkill CryptoSkill
  • Official
  • Skills
  • Categories
  • How It Works
  • GitHub
Home › Wallets › Metamask Official Swaps Cpu Profile Audit

Metamask Official Swaps Cpu Profile Audit

Wallets by @metamask v1.0.0 B PASS 3 flags

Parse an already-recorded Hermes / React Native Release Profiler `.cpuprofile` (ideally symbolicated with source maps) and audit it for slow frames on the swaps/bridge screen and the modals or subpages it opens — quote select screen, post-trade modal, batch sell, asset picker/token selector. Use when a user hands you a `.cpuprofile` file (e.g. a `sampling-profiler-trace*.cpuprofile`, or its already-converted `*-converted.json`) recorded per `docs/readme/release-build-profiler.md` and asks to audit, analyze, explain, or find why the swaps/bridge flow is slow based on that trace. This is an offline, file-based analysis — no simulator, device, Metro, or `mm` session is required, unlike `swaps-perf-audit` (which measures live render counts on a running simulator). The audit accounts for ALL time in the capture, not just swaps-owned code: non-swaps frames that ran while the user sat on a swaps screen (navigation, redux, design system, polling controllers, React internals) are reported too, each labelled with whether the swaps team owns it and how it relates to the swaps call stacks. The report always leads with a timing table (capture metrics + by-area self time with an ownership column) and a short outcome line, and only adds a probable-cause/fix table when there is an actual issue — deep fixes are proposed for swaps-owned rows, while non-owned rows are named and routed. MetaMask Mobile only.

Install

$ cp -r cryptoskill/skills/wallets/metamask-official-swaps-cpu-profile-audit .claude/skills/
$ clawhub install metamask-official-swaps-cpu-profile-audit

Tags

official wallets

Quality Score

Score: 64/100 Grade: B Risk Gate: PASS

Trust profile trust grade not computed yet

3 red flags 7 cleared 1 not measured

Capabilities below are detected automatically by an open-source scanner that reads the skill's text and scripts (see how this is computed). Not measured means the scanner couldn't make a confident call — it is NOT a green check, and you should treat it as a possible red flag until a human or a stronger scanner has measured it.

3 Red flags things this skill can do that affect your security or funds
  • ⚠
    Can move funds this skill can sign and send transactions on your behalf
  • ⚠
    Can execute shell runs arbitrary shell commands on your machine
  • ⚠
    Can write files writes to your local filesystem
7 Cleared by scanner we scanned the skill's text & scripts and found no evidence of these
  • ✓
    Requires private key you must hand over a private key, mnemonic, or wallet config
  • ✓
    Requires hosted operator depends on a third-party hosted service to function
  • ✓
    Uses remote install script setup pipes a remote shell script (curl | sh class)
  • ✓
    Mutable remote runtime runs remote code that can change behavior without a local diff
  • ✓
    Can install code installs software at setup time (npx, pip, brew, etc.)
  • ✓
    Can browse the web fetches arbitrary URLs at runtime
  • ✓
    Can spawn sub-agents delegates to other skills or sub-agents
1 Not measured yet scanner couldn't make a confident call — treat as a possible red flag
  • ?
    Auto-invocable may be invoked by the agent without your explicit prompt

Execution mode

unsigned_tx_builder Phase 1 single-mode classification — multi-mode breakdown deferred to Phase 2.

Ingredients (services this skill talks to)

We did not find any well-known hosted services in this skill's text or scripts. This does NOT mean the skill is local-only — it might use services we don't yet recognize, or talk to them through code paths our scanner can't reach. A complete dependency list (every package, library, and binary, with integrity hashes) is on the roadmap; today we only show recognized hosts.

Audits

No one has audited this skill yet. That is different from “audited and clean” — it just means no professional reviewer (a security firm, the CryptoSkill team, or a verified independent researcher) has signed off on it. There are no audit reports to read. How reviewer levels work →

SKILL.md → SOURCE.md → TRUST.auto.yaml → Browse directory →

Auto-generated by cryptoskill/extract-capabilities/0.3.1 · hosted-service list version 2026-09-06 · how this is computed

More from Metamask

👛Metamask Official Oh My Opencode👛Metamask Official Perps Validate Multiproject👛Metamask Official Gemini👛Metamask Official Gator Cli👛Metamask Official X402 Payments👛Metamask Official Extension Testing

Other in Wallets

👛Bitget Wallet👛OKX Agentic Wallet👛Walletconnect Requester👛Vincent - A secure wallet for your agent👛Crypto Wallet👛Sponge Wallet

Source

View on GitHub →

CryptoSkillBuilt for the crypto community
GitHub Official Skills Categories Terms Privacy