ZappushZappush
SkillsUse CasesBenchmarkCommunitySign In
      Back to Skills
      supah-based

      Safety Report

      SUPAH Wallet X-Ray

      @supah-based

      Instant wallet intelligence for any EVM address. Know who you're dealing with before you interact. Wallet age, transaction history, token holdings, DeFi acti...

      202Downloads
      1Installs
      0Stars
      4Versions
      API Integration11,971Finance & Accounting2,590Maps & Geolocation2,013

      Security Analysis

      high confidence
      Suspicious0.08 risk

      This is a coherent paid wallet-lookup skill, but its script has a user-input code execution risk and it can automatically spend USDC per scan.

      May 1, 20263 files4 concerns
      Purpose & Capabilitynote

      The wallet intelligence purpose matches the documented API calls, ENS resolution, and paid x402 scan model, but the automatic paid scan behavior is financially sensitive.

      Instruction Scopeconcern

      The script embeds user-controlled address and chain values directly into a Node.js command string, creating an unexpected code execution risk for crafted inputs.

      Install Mechanismok

      No install-time execution or remote installer is shown; the included executable logic is in the provided shell script.

      Credentialsconcern

      The skill makes paid outbound API calls and also contacts an ENS provider beyond the main SUPAH API, so users should understand both the spending and data-flow implications.

      Persistence & Privilegenote

      The script writes the latest JSON result to a fixed /tmp path and requires an agent wallet funded with USDC, but it does not show background persistence.

      Guidance

      Install only if you are comfortable with paid per-scan API usage. Use a limited-balance wallet, require confirmation for paid calls, and avoid passing untrusted or oddly formatted address/chain strings until the script validates and safely handles user input.

      Latest Release

      v1.3.0

      Clean x402 only publish.

      Popular Skills

      self-improving-agent

      @pskoett · 1,456 stars

      Gog

      @steipete · 672 stars

      Tavily Web Search

      @arun-8687 · 620 stars

      Find Skills

      @JimLiuxinghai · 529 stars

      Proactive Agent

      @halthelobster · 426 stars

      Summarize

      @summarize · 415 stars

      Published by @supah-based on ClawHub

      Zappush© 2026 Zappush
      HomeGuaranteeSupport

      Something feels unusual? We want to help: [email protected]