Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Uniswap Build Hook

v0.1.0

Build a Uniswap V4 hook. Use when user wants to create a custom V4 hook contract. Generates Solidity code, Foundry tests, mines CREATE2 address for hook flags, and produces deployment scripts. Handles the full hook development lifecycle.

0· 782·0 current·0 all-time
Security Scan
VirusTotalVirusTotal
Suspicious
View report →
OpenClawOpenClaw
Benign
high confidence
Purpose & Capability
The name and description match what the SKILL.md instructs: generate Solidity, tests, CREATE2 mining and deployment scripts. Allowed tools (forge/npm/git, Task(subagent_type:hook-builder), an MCP getter) are appropriate for that workflow. Minor inconsistency: SKILL.md says it 'does not call MCP tools directly' but mcp__uniswap__get_supported_chains appears in allowed-tools; also the README lists a GitHub install path while the skill metadata marks source as unknown — you should verify the subagent and repo origin before use.
Instruction Scope
Instructions stay within the described development workflow and do not ask to read unrelated system files or credentials. However the skill delegates all behavior to a Task(subagent_type:hook-builder); that subagent could expand scope (read files, request secrets, call external endpoints). The skill itself does not include guardrails requiring code review of generated artifacts.
Install Mechanism
This is an instruction-only skill with no install spec (lowest disk risk). The SKILL.md includes a suggested Foundry install command (curl ... | bash) in its error/help text — a common but higher-risk convenience pattern; the skill won't automatically run it, it only suggests it to the user.
Credentials
The skill requests no environment variables or credentials, which is proportionate. Be aware generated deployment scripts will typically require RPC URLs and private keys to deploy — the skill does not request those but the developer will need to provide them; review scripts to ensure they don't hard-code or exfiltrate secrets.
Persistence & Privilege
always is false and the skill does not request persistent system changes. It delegates to a subagent but does not claim to modify other skills or global agent config.
Assessment
This skill is internally consistent with its purpose, but take these precautions before installing or running it: 1) Verify the provenance — the README points to a GitHub path but the skill metadata lists the source as unknown; confirm the repository and author. 2) Review the hook-builder subagent implementation (Task(subagent_type:hook-builder)) because the skill delegates full code generation and mining to that agent and it could perform additional actions. 3) Expect CREATE2 mining to be CPU/time intensive; test on a dev machine or CI with resource limits. 4) Carefully review generated deployment scripts before using them — they will need RPC URLs and private keys to deploy; never paste private keys into third-party agents and prefer using environment-based or hardware wallet signing. 5) The suggested Foundry install uses curl | bash — if you accept that, run it only from the official Foundry sources and on trusted machines. If you want a lower-risk path, ask the skill to provide code only (no automatic mining or deployment scripts) so you can run compilation/mining locally under your control.

Like a lobster shell, security has layers — review code before you run it.

latestvk976324jr37t3h5wtd4th6ywj180wf05
782downloads
0stars
1versions
Updated 14h ago
v0.1.0
MIT-0

Build Hook

Overview

Builds a complete Uniswap V4 hook by delegating to the hook-builder agent. Handles the full development lifecycle: understanding requirements, determining hook flags, generating Solidity contracts, generating Foundry tests, mining a CREATE2 address with correct flag bits, and producing deployment scripts. Returns production-ready code artifacts written directly to the project.

When to Use

Activate when the user asks:

  • "Build a V4 hook"
  • "Create a limit order hook"
  • "Build a dynamic fee hook"
  • "Create a TWAMM hook"
  • "Custom hook for V4"
  • "Hook that charges higher fees during volatility"
  • "Build a hook that distributes LP fees to stakers"
  • "Create a hook with oracle integration"

Parameters

ParameterRequiredDefaultDescription
behaviorYes--Hook behavior description (e.g., "limit orders", "dynamic fees", "TWAMM", "oracle-based pricing")
callbacksNoAuto-detectSpecific V4 callbacks if the user knows them (e.g., "beforeSwap, afterSwap")
constraintsNo--Gas budget, security requirements, or specific design constraints
chainNoethereumTarget chain for deployment (affects PoolManager address)

Workflow

  1. Extract parameters from the user's request: identify the hook behavior, any explicitly mentioned callbacks, constraints, and target chain.

  2. Delegate to hook-builder: Invoke Task(subagent_type:hook-builder) with the full context. The hook-builder agent will:

    • Understand the requirements and determine which callbacks are needed
    • Map callbacks to hook flags and validate the flag combination
    • Generate a Solidity contract extending BaseHook with proper NatSpec
    • Generate comprehensive Foundry tests (unit, integration, edge cases, gas snapshots)
    • Mine a CREATE2 salt that produces an address encoding the required flags
    • Produce a deployment script with verification steps
  3. Present results to the user with a summary covering:

    • Files written (contract path, test path, deployment script path)
    • Hook architecture explanation (what it does, how state flows)
    • Callbacks implemented and their flag bitmask
    • Gas estimates per callback (from Foundry test output)
    • Next steps for the developer (run tests, deploy to testnet, mainnet considerations)

Output Format

Present a summary followed by the generated files:

V4 Hook Built: LimitOrderHook

  Contract:   src/hooks/LimitOrderHook.sol (187 lines)
  Tests:      test/hooks/LimitOrderHook.t.sol (12 tests)
  Deployment: script/DeployLimitOrderHook.s.sol

  Callbacks: beforeSwap, afterSwap
  Flags:     0x00C0
  CREATE2:   Salt mined, address verified

  Gas Estimates:
    beforeSwap: ~45,000 gas
    afterSwap:  ~32,000 gas
    Total overhead per swap: ~77,000 gas

  Architecture:
    Orders are placed at specific ticks and stored in an on-chain order book.
    During beforeSwap, the hook checks for matching orders at the target tick.
    Matched orders are filled atomically within the same transaction.

  Next Steps:
    1. Run tests: forge test --match-contract LimitOrderHookTest
    2. Deploy to testnet: forge script script/DeployLimitOrderHook.s.sol --rpc-url sepolia
    3. Verify on Etherscan: forge verify-contract <address> LimitOrderHook

Important Notes

  • This skill delegates entirely to the hook-builder agent -- it does not call MCP tools directly.
  • The hook-builder generates production-quality Solidity code with reentrancy protection and access control.
  • CREATE2 address mining ensures the deployed address encodes the correct hook flags in its leading bytes (required by V4 PoolManager).
  • Foundry must be installed for test generation and compilation. If not found, the skill will provide installation instructions.
  • Generated code uses Solidity ^0.8.26 and imports from @uniswap/v4-core and @uniswap/v4-periphery.

Error Handling

ErrorUser-Facing MessageSuggested Action
INVALID_CALLBACK_COMBINATION"The requested behavior requires conflicting callbacks."Simplify hook behavior or split into multiple hooks
CREATE2_MINING_TIMEOUT"Could not mine a valid CREATE2 address within time limit."Increase mining time limit or reduce required flags
FORGE_NOT_INSTALLED"Foundry (forge) is required but not installed."Install: curl -L https://foundry.paradigm.xyz | bash && foundryup
VAGUE_REQUIREMENTS"Need more detail about the desired hook behavior."Describe specific behavior (e.g., "limit orders that execute at tick boundaries")
COMPILATION_ERROR"Generated contract has compilation errors."Review error output and adjust requirements

Comments

Loading comments...