DeFi Yield Hunter

WarnAudited by ClawScan on May 16, 2026.

Overview

This skill advertises automated DeFi investing and rebalancing, but the artifacts do not define wallet permissions, transaction limits, or user-confirmation safeguards.

Review carefully before installing. Do not connect a real wallet or authorize transactions unless the skill provides clear per-transaction confirmation, spending limits, protocol allowlists, and transparent evidence for its risk and APY calculations.

Findings (4)

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

If an agent follows this skill too broadly, it could move or commit crypto assets without clear confirmation safeguards, creating risk of financial loss.

Why it was flagged

Automated rebalancing and auto-compounding are high-impact financial actions, but the artifacts do not specify user approval, transaction caps, allowlisted protocols, or rollback/containment rules.

Skill content
Includes liquidity pool analytics, token pair correlation analysis, and automated rebalancing. ... Builds and manages a diversified DeFi portfolio with auto-compounding.
Recommendation

Use only with explicit human confirmation for every transaction, a small test wallet, defined protocol and asset allowlists, and clear transaction limits.

What this means

The skill could require sensitive wallet permissions or transaction signing authority without making the scope of that authority clear before use.

Why it was flagged

Managing a DeFi portfolio across these services normally requires wallet or account transaction authority, but the supplied metadata declares no credential contract or privilege boundaries.

Skill content
Builds and manages a diversified DeFi portfolio with auto-compounding. ... Compatible with Raydium, Orca, Jupiter, Aave, Compound, Uniswap.
Recommendation

Do not grant wallet access unless the skill clearly documents which accounts, chains, protocols, and transaction types it can use, and requires per-transaction user approval.

What this means

Users may over-trust the skill's claimed risk analysis and make unsafe investment decisions based on unsupported assurances.

Why it was flagged

The skill makes strong safety and performance claims in a financial context, but no code, data sources, methodology, or provider integrations are present to substantiate them.

Skill content
Scans hundreds of protocols to find the highest APY opportunities, calculates real risk-adjusted returns accounting for impermanent loss, and identifies yield traps. Monitors rug pulls, honeypot detection, and protocol health scores.
Recommendation

Treat the skill as unverified financial automation; require independent validation of any APY, risk, rug-pull, or honeypot analysis before acting.

What this means

Users cannot easily verify how the advertised DeFi automation is implemented or maintained.

Why it was flagged

There is no source repository, homepage, install spec, or reviewed implementation. This is not malicious by itself, but it is a provenance gap for a high-impact finance-related skill.

Skill content
Source: unknown; Homepage: none; No install spec — this is an instruction-only skill.
Recommendation

Prefer finance automation skills with a documented source, reviewed code, clear provider integrations, and transparent risk methodology.