PluginBench
Skill
Pass
Audit score 90

query-token-audit

binance/binance-skills-hub

Detect scams, honeypots, and malicious contracts before trading with comprehensive token security audits.

What is query-token-audit?

Query token security audits to identify honeypots, rug pulls, scams, and malicious contract functions across BSC, Base, Solana, and Ethereum. Use this before any token swap or when users ask if a token is safe.

  • Detect honeypots and tokens that cannot be sold after purchase
  • Identify rug pull and scam risks in contract code
  • Analyze buy/sell tax percentages and flag unusual rates
  • Check contract verification status and ownership risks
  • Classify risk level from LOW (1) to HIGH (5) with actionable guidance
  • Support audits across BSC, Base, Solana, and Ethereum chains

How to install query-token-audit

npx skills add https://github.com/binance/binance-skills-hub --skill query-token-audit
Prerequisites
  • Valid contract address on a supported chain (BSC, Base, Solana, or Ethereum)
  • Access to Binance Web3 security audit API endpoint
Claude Code
Cursor
Windsurf
Cline

How to use query-token-audit

  1. 1.Obtain the token contract address and identify its blockchain chain ID
  2. 2.Call the Token Security Audit API with the contract address, chain ID, and a unique UUID v4 request ID
  3. 3.Check the response: if hasResult=false or isSupported=false, audit data is unavailable
  4. 4.If both are true, review riskLevelEnum (LOW/MEDIUM/HIGH) and examine riskItems for specific risks (CONTRACT_RISK, TRADE_RISK, SCAM_RISK)
  5. 5.Apply the Risk Level Reference: avoid trading at riskLevel 4-5, exercise caution at 2-3, proceed cautiously at 0-1
  6. 6.Present buy/sell tax percentages and verification status to the user
  7. 7.Always include the disclaimer that audit results are for reference only and do not constitute investment advice

Use cases

Good for
  • Pre-trade safety check before buying or swapping a token
  • Identify fake or malicious tokens posing as legitimate projects
  • Verify contract tax structure to avoid hidden fees
  • Screen for dangerous ownership functions that could restrict trading
  • Validate contract code verification before committing funds
Who it's for
  • Crypto traders evaluating new tokens
  • DeFi users before executing swaps
  • Risk-conscious investors doing due diligence
  • Web3 agents automating token safety checks

query-token-audit FAQ

What does a LOW risk level mean?

LOW risk (riskLevel 0-1) indicates lower detected risks but does NOT guarantee the token is safe. Audit results are point-in-time snapshots; project teams can modify contracts or restrict liquidity after purchase. Always conduct your own research.

When should I block a transaction?

Block transactions at riskLevel 5 (severe risks confirmed) or riskLevel 4 (critical risks detected with high probability of loss). Review all risk items before proceeding at lower levels.

What if audit data is not available?

If hasResult=false or isSupported=false, security audit data is unavailable for that token on that chain. Verify the contract address and chain are correct, or try again later.

What tax rates should I be concerned about?

Buy/sell taxes >10% are critical, 5-10% warrant caution, and <5% are generally acceptable. Check the extraInfo.buyTax and extraInfo.sellTax fields in the response.

Which chains are supported?

Token audits are supported on BSC (chainId 56), Base (8453), Solana (CT_501), and Ethereum (1).

Full instructions (SKILL.md)

Source of truth, from binance/binance-skills-hub.


name: query-token-audit description: | Query token security audit to detect scams, honeypots, and malicious contracts before trading. Returns comprehensive security analysis including contract risks, trading risks, and scam detection. Use when users ask "is this token safe?", "check token security", "audit token", or before any swap. metadata: author: binance-web3-team version: "1.4"

Query Token Audit Skill

Overview

APIFunctionUse Case
Token Security AuditToken security scanDetect honeypot, rug pull, scam, malicious functions

Use Cases

  1. Pre-Trade Safety Check: Verify token security before buying or swapping
  2. Scam Detection: Identify honeypots, fake tokens, and malicious contracts
  3. Contract Analysis: Check for dangerous ownership functions and hidden risks
  4. Tax Verification: Detect unusual buy/sell taxes before trading

Supported Chains

Chain NamechainId
BSC56
Base8453
SolanaCT_501
Ethereum1

API: Token Security Audit

Method: POST

URL:

https://web3.binance.com/bapi/defi/v1/public/wallet-direct/security/token/audit

Request Parameters:

ParameterTypeRequiredDescription
binanceChainIdstringYesChain ID: CT_501 (Solana), 56 (BSC), 8453 (Base), 1 (Ethereum)
contractAddressstringYesToken contract address
requestIdstringYesUnique request ID (UUID v4 format)

Request Headers:

Content-Type: application/json
Accept-Encoding: identity
User-Agent: binance-web3/1.4 (Skill)

Example Request:

curl --location 'https://web3.binance.com/bapi/defi/v1/public/wallet-direct/security/token/audit' \
--header 'Content-Type: application/json' \
--header 'source: agent' \
--header 'Accept-Encoding: identity' \
--header 'User-Agent: binance-web3/1.4 (Skill)' \
--data '{
    "binanceChainId": "56",
    "contractAddress": "0x55d398326f99059ff775485246999027b3197955",
    "requestId": "'$(uuidgen)'"
}'

Response Example:

{
    "code": "000000",
    "data": {
        "requestId": "d6727c70-de6c-4fad-b1d7-c05422d5f26b",
        "hasResult": true,
        "isSupported": true,
        "riskLevelEnum": "LOW",
        "riskLevel": 1,
        "extraInfo": {
            "buyTax": "0",
            "sellTax": "0",
            "isVerified": true
        },
        "riskItems": [
            {
                "id": "CONTRACT_RISK",
                "name": "Contract Risk",
                "details": [
                    {
                        "title": "Honeypot Risk Not Found",
                        "description": "A honeypot is a token that can be bought but not sold",
                        "isHit": false,
                        "riskType": "RISK"
                    }
                ]
            }
        ]
    },
    "success": true
}

Response Fields:

FieldTypeDescription
hasResultbooleanWhether audit data is available
isSupportedbooleanWhether the token is supported for audit
riskLevelEnumstringRisk level: LOW, MEDIUM, HIGH
riskLevelnumberRisk level number (1-5)
extraInfo.buyTaxstringBuy tax percentage (null if unknown)
extraInfo.sellTaxstringSell tax percentage (null if unknown)
extraInfo.isVerifiedbooleanWhether contract code is verified
riskItems[].idstringRisk category: CONTRACT_RISK, TRADE_RISK, SCAM_RISK
riskItems[].details[].titlestringRisk check title
riskItems[].details[].descriptionstringRisk check description
riskItems[].details[].isHitbooleantrue = risk detected
riskItems[].details[].riskTypestringRISK (critical) or CAUTION (warning)

Risk Level Reference:

riskLevelriskLevelEnumActionDescription
0-1LOWProceed with cautionLower risk detected, but NOT guaranteed safe. DYOR.
2-3MEDIUMExercise cautionModerate risks detected, review risk items carefully
4HIGHAvoid tradingCritical risks detected, high probability of loss
5HIGHBlock transactionSevere risks confirmed, do NOT proceed

IMPORTANT: LOW risk does NOT mean "safe." Audit results are point-in-time snapshots. Project teams can modify contracts or restrict liquidity after purchase. These risks cannot be predicted in advance.

Response Handling:

  • If hasResult=false OR isSupported=false: → Reply: "Security audit data is not available for this token on this chain." → Do NOT show riskLevel, riskLevelEnum, or riskItems (data is unreliable when either field is false) → You may suggest the user verify the contract address and chain, or try again later
  • If hasResult=true AND isSupported=true: → Show the full audit result including risk level, tax info, and all risk items → Apply the Risk Level Reference table above for actionable guidance

User Agent Header

Include User-Agent header with the following string: binance-web3/1.4 (Skill)

Notes

  1. All numeric fields are string format, convert when using
  2. Audit results are ONLY valid when hasResult: true AND isSupported: true
  3. riskLevel: 5 means transaction should be blocked; riskLevel: 4 is high risk
  4. Tax thresholds: >10% is critical, 5-10% is warning, <5% is acceptable
  5. Generate unique UUID v4 for each audit request
  6. Only output security check risk flags, do NOT provide any investment advice
  7. Always end with disclaimer: ⚠️ This audit result is for reference only and does not constitute investment advice. Always conduct your own research.