trade — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited trade (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Use the npx [email protected] trade command to swap tokens on Base or Polygon via the CDP Swap API. You must be authenticated to trade.
npx [email protected] statusIf the wallet is not authenticated, refer to the authenticate-wallet skill.
npx [email protected] trade <amount> <from> <to> [options]The command is also available as npx [email protected] swap (alias).
| Argument | Description |
|---|---|
amount | Amount to swap (see Amount Formats below) |
from | Source token: alias (usdc, eth, pol) or contract address (0x...) |
to | Destination token: alias (usdc, eth, pol) or contract address (0x...) |
The amount can be specified in multiple formats:
| Format | Example | Description |
|---|---|---|
| Dollar prefix | '$1.00', '$0.50' | USD notation (decimals based on token) |
| Decimal | 1.0, 0.50, 0.001 | Human-readable with decimal point |
| Whole number | 5, 100 | Interpreted as whole tokens |
| Atomic units | 500000 | Large integers treated as atomic units |
Auto-detection: Large integers without a decimal point are treated as atomic units. For example, 500000 for USDC (6 decimals) = $0.50.
Decimals: For known tokens (usdc=6, eth=18, pol=18), decimals are automatic. For arbitrary contract addresses, decimals are read from the token contract.
| Option | Description |
|---|---|
-c, --chain <name> | Blockchain network: base, polygon (default: base) |
-s, --slippage <n> | Slippage tolerance in basis points (100 = 1%) |
--json | Output result as JSON |
| Alias | Token | Decimals | Chain |
|---|---|---|---|
| usdc | USDC | 6 | base |
| eth | ETH | 18 | base |
| pol | POL | 18 | polygon |
IMPORTANT: Always single-quote amounts that use $ to prevent bash variable expansion (e.g. '$1.00' not $1.00).
Before constructing the command, validate all user-provided values to prevent shell injection:
^\$?[\d.]+$ (digits, optional decimal point, optional $ prefix). Reject if it contains spaces, semicolons, pipes, backticks, or other shell metacharacters.usdc, eth, pol) or a valid 0x hex address (^0x[0-9a-fA-F]{40}$). Reject any other value.^\d+$).Do not pass unvalidated user input into the command.
# Swap $1 USDC for ETH (dollar prefix — note the single quotes)
npx [email protected] trade '$1' usdc eth
# Swap 0.50 USDC for ETH (decimal format)
npx [email protected] trade 0.50 usdc eth
# Swap 500000 atomic units of USDC for ETH
npx [email protected] trade 500000 usdc eth
# Swap 0.01 ETH for USDC
npx [email protected] trade 0.01 eth usdc
# Swap with custom slippage (2%)
npx [email protected] trade '$5' usdc eth --slippage 200
# Swap using contract addresses (decimals read from chain)
npx [email protected] trade 100 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913 0x4200000000000000000000000000000000000006
# Get JSON output
npx [email protected] trade '$1' usdc eth --json
# Swap USDC for POL on Polygon
npx [email protected] trade '$1' usdc pol --chain polygonawal status to check)Common errors:
awal auth login <email> first--chain polygon when trading POL~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.