query-token-audit
binance/binance-skills-hub
Detect scams, honeypots, and malicious contracts before trading with comprehensive token security audits.
What is query-token-audit?
Query token security audits to identify honeypots, rug pulls, scams, and malicious contract functions across BSC, Base, Solana, and Ethereum. Use this before any token swap or when users ask if a token is safe.
- Detect honeypots and tokens that cannot be sold after purchase
- Identify rug pull and scam risks in contract code
- Analyze buy/sell tax percentages and flag unusual rates
- Check contract verification status and ownership risks
- Classify risk level from LOW (1) to HIGH (5) with actionable guidance
- Support audits across BSC, Base, Solana, and Ethereum chains
How to install query-token-audit
npx skills add https://github.com/binance/binance-skills-hub --skill query-token-audit- Valid contract address on a supported chain (BSC, Base, Solana, or Ethereum)
- Access to Binance Web3 security audit API endpoint
How to use query-token-audit
- 1.Obtain the token contract address and identify its blockchain chain ID
- 2.Call the Token Security Audit API with the contract address, chain ID, and a unique UUID v4 request ID
- 3.Check the response: if hasResult=false or isSupported=false, audit data is unavailable
- 4.If both are true, review riskLevelEnum (LOW/MEDIUM/HIGH) and examine riskItems for specific risks (CONTRACT_RISK, TRADE_RISK, SCAM_RISK)
- 5.Apply the Risk Level Reference: avoid trading at riskLevel 4-5, exercise caution at 2-3, proceed cautiously at 0-1
- 6.Present buy/sell tax percentages and verification status to the user
- 7.Always include the disclaimer that audit results are for reference only and do not constitute investment advice
Use cases
- Pre-trade safety check before buying or swapping a token
- Identify fake or malicious tokens posing as legitimate projects
- Verify contract tax structure to avoid hidden fees
- Screen for dangerous ownership functions that could restrict trading
- Validate contract code verification before committing funds
- Crypto traders evaluating new tokens
- DeFi users before executing swaps
- Risk-conscious investors doing due diligence
- Web3 agents automating token safety checks
query-token-audit FAQ
LOW risk (riskLevel 0-1) indicates lower detected risks but does NOT guarantee the token is safe. Audit results are point-in-time snapshots; project teams can modify contracts or restrict liquidity after purchase. Always conduct your own research.
Block transactions at riskLevel 5 (severe risks confirmed) or riskLevel 4 (critical risks detected with high probability of loss). Review all risk items before proceeding at lower levels.
If hasResult=false or isSupported=false, security audit data is unavailable for that token on that chain. Verify the contract address and chain are correct, or try again later.
Buy/sell taxes >10% are critical, 5-10% warrant caution, and <5% are generally acceptable. Check the extraInfo.buyTax and extraInfo.sellTax fields in the response.
Token audits are supported on BSC (chainId 56), Base (8453), Solana (CT_501), and Ethereum (1).
Full instructions (SKILL.md)
Source of truth, from binance/binance-skills-hub.
name: query-token-audit description: | Query token security audit to detect scams, honeypots, and malicious contracts before trading. Returns comprehensive security analysis including contract risks, trading risks, and scam detection. Use when users ask "is this token safe?", "check token security", "audit token", or before any swap. metadata: author: binance-web3-team version: "1.4"
Query Token Audit Skill
Overview
| API | Function | Use Case |
|---|---|---|
| Token Security Audit | Token security scan | Detect honeypot, rug pull, scam, malicious functions |
Use Cases
- Pre-Trade Safety Check: Verify token security before buying or swapping
- Scam Detection: Identify honeypots, fake tokens, and malicious contracts
- Contract Analysis: Check for dangerous ownership functions and hidden risks
- Tax Verification: Detect unusual buy/sell taxes before trading
Supported Chains
| Chain Name | chainId |
|---|---|
| BSC | 56 |
| Base | 8453 |
| Solana | CT_501 |
| Ethereum | 1 |
API: Token Security Audit
Method: POST
URL:
https://web3.binance.com/bapi/defi/v1/public/wallet-direct/security/token/audit
Request Parameters:
| Parameter | Type | Required | Description |
|---|---|---|---|
| binanceChainId | string | Yes | Chain ID: CT_501 (Solana), 56 (BSC), 8453 (Base), 1 (Ethereum) |
| contractAddress | string | Yes | Token contract address |
| requestId | string | Yes | Unique request ID (UUID v4 format) |
Request Headers:
Content-Type: application/json
Accept-Encoding: identity
User-Agent: binance-web3/1.4 (Skill)
Example Request:
curl --location 'https://web3.binance.com/bapi/defi/v1/public/wallet-direct/security/token/audit' \
--header 'Content-Type: application/json' \
--header 'source: agent' \
--header 'Accept-Encoding: identity' \
--header 'User-Agent: binance-web3/1.4 (Skill)' \
--data '{
"binanceChainId": "56",
"contractAddress": "0x55d398326f99059ff775485246999027b3197955",
"requestId": "'$(uuidgen)'"
}'
Response Example:
{
"code": "000000",
"data": {
"requestId": "d6727c70-de6c-4fad-b1d7-c05422d5f26b",
"hasResult": true,
"isSupported": true,
"riskLevelEnum": "LOW",
"riskLevel": 1,
"extraInfo": {
"buyTax": "0",
"sellTax": "0",
"isVerified": true
},
"riskItems": [
{
"id": "CONTRACT_RISK",
"name": "Contract Risk",
"details": [
{
"title": "Honeypot Risk Not Found",
"description": "A honeypot is a token that can be bought but not sold",
"isHit": false,
"riskType": "RISK"
}
]
}
]
},
"success": true
}
Response Fields:
| Field | Type | Description |
|---|---|---|
| hasResult | boolean | Whether audit data is available |
| isSupported | boolean | Whether the token is supported for audit |
| riskLevelEnum | string | Risk level: LOW, MEDIUM, HIGH |
| riskLevel | number | Risk level number (1-5) |
| extraInfo.buyTax | string | Buy tax percentage (null if unknown) |
| extraInfo.sellTax | string | Sell tax percentage (null if unknown) |
| extraInfo.isVerified | boolean | Whether contract code is verified |
| riskItems[].id | string | Risk category: CONTRACT_RISK, TRADE_RISK, SCAM_RISK |
| riskItems[].details[].title | string | Risk check title |
| riskItems[].details[].description | string | Risk check description |
| riskItems[].details[].isHit | boolean | true = risk detected |
| riskItems[].details[].riskType | string | RISK (critical) or CAUTION (warning) |
Risk Level Reference:
| riskLevel | riskLevelEnum | Action | Description |
|---|---|---|---|
| 0-1 | LOW | Proceed with caution | Lower risk detected, but NOT guaranteed safe. DYOR. |
| 2-3 | MEDIUM | Exercise caution | Moderate risks detected, review risk items carefully |
| 4 | HIGH | Avoid trading | Critical risks detected, high probability of loss |
| 5 | HIGH | Block transaction | Severe risks confirmed, do NOT proceed |
IMPORTANT: LOW risk does NOT mean "safe." Audit results are point-in-time snapshots. Project teams can modify contracts or restrict liquidity after purchase. These risks cannot be predicted in advance.
Response Handling:
- If
hasResult=falseORisSupported=false: → Reply: "Security audit data is not available for this token on this chain." → Do NOT showriskLevel,riskLevelEnum, orriskItems(data is unreliable when either field is false) → You may suggest the user verify the contract address and chain, or try again later - If
hasResult=trueANDisSupported=true: → Show the full audit result including risk level, tax info, and all risk items → Apply the Risk Level Reference table above for actionable guidance
User Agent Header
Include User-Agent header with the following string: binance-web3/1.4 (Skill)
Notes
- All numeric fields are string format, convert when using
- Audit results are ONLY valid when
hasResult: trueANDisSupported: true riskLevel: 5means transaction should be blocked;riskLevel: 4is high risk- Tax thresholds: >10% is critical, 5-10% is warning, <5% is acceptable
- Generate unique UUID v4 for each audit request
- Only output security check risk flags, do NOT provide any investment advice
- Always end with disclaimer:
⚠️ This audit result is for reference only and does not constitute investment advice. Always conduct your own research.
Related skills
More from binance/binance-skills-hub and the wider catalog.

query-token-info
Search tokens and fetch real-time price, metadata, and candlestick data across Ethereum, BSC, Base, and Solana.

simple-earn
Manage Binance Simple Earn products and BFUSD/RWUSD accounts via authenticated API.

spot
Execute authenticated Binance Spot API requests for trading, market data, and order management.

square-post
Publish text, images, articles, and videos to Binance Square with a single command.

sub-account
Manage Binance sub-accounts via API: create, enable features, transfer assets, and monitor positions.

trading-signal
Track smart-money buy/sell signals on BSC and Solana with trigger prices, max gains, and exit rates.