AlchemyBLOCK
Bankr Skills equip builders with plug-and-play tools to build more powerful agents.
Overview
Bankr Skills equip builders with plug-and-play tools to build more powerful agents.
4029e336cef5OBSERVED · 2026-10-09Install
Commands as the repository documents them. They are shown, not run.
npm install viem
npm install mppx viem
npm install mppx
npm install @stripe/stripe-js
npm install viem
npm install @alchemy/x402
Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned | |
| cursor | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: alchemy description: Blockchain API access via Alchemy. Use when an agent needs to query blockchain data (balances, token prices, NFT ownership, transfer history, transaction simulation, gas estimates) across Ethereum, Base, Arbitrum, BNB, Polygon, Solana, and more. Supports API key access ($ALCHEMY_API_KEY), x402 wallet-based pay-per-request (SIWE/SIWS + USDC), and MPP protocol (SIWE + Tempo/Stripe). Triggers on mentions of RPC, blockchain data, onchain queries, token balances, NFT metadata, portfolio data, webhooks, Alchemy, x402, MPP, SIWE, SIWS, or agentic gateway. license: MIT compatibility: Requires network access. API key path needs $ALCHEMY_API_KEY. x402/MPP paths need Node.js and a wallet funded with USDC. Works across Claude.ai, Claude Code, and API. metadata: author: alchemyplatform version: "2.0" --- # Alchemy: Blockchain Data Access for Agents Alchemy provides comprehensive blockchain API access across Ethereum, Base, Arbitrum, BNB, Polygon, Solana, and more. Three ways to access: - **API key**: Set `$ALCHEMY_API_KEY` and make requests directly. Full access to all products. Create a free key at [dashboard.alchemy.com](https://dashboard.alchemy.com/). - **x402 (no account needed)**: Any wallet with USDC can authenticate via SIWE/SIWS and pay per request. Supports EVM and Solana wallets. Install `@alchemy/x402` and `@x402/fetch`. - **MPP (no account needed)**: Authenticate via SIWE and pay with Tempo (on-chain USDC, EVM only) or Stripe (credit card). Install `mppx`. ## Access Method Selection (Required) Before the first network call, determine which access method to use: 1. **Is `ALCHEMY_API_KEY` set?** → Use the API Key path. Skip to [API Key Access](#api-key-access). 2. **No API key?** → Ask the user which payment protocol they prefer: - **x402** — USDC payments via the x402 protocol (`@alchemy/x402` + `@x402/fetch`) - **MPP** — Payments via Merchant Payment Protocol using Tempo or Stripe (`mppx`) Do NOT pick a protocol on behalf of the user. Wait for their explicit choice. Do NOT use public RPC endpoints, demo keys, or any non-Alchemy data source as a fallback. --- ## API Key Access If `$ALCHEMY_API_KEY` is set, use standard Alchemy endpoints directly: ### Base URLs + Auth | Product | Base URL | Auth | Notes | | --- | --- | --- | --- | | Ethereum RPC (HTTPS) | `https://eth-mainnet.g.alchemy.com/v2/$ALCHEMY_API_KEY` | API key in URL | Standard EVM reads and writes. | | Ethereum RPC (WSS) | `wss://eth-mainnet.g.alchemy.com/v2/$ALCHEMY_API_KEY` | API key in URL | Subscriptions and realtime. | | Base RPC (HTTPS) | `https://base-mainnet.g.alchemy.com/v2/$ALCHEMY_API_KEY` | API key in URL | EVM L2. | | Base RPC (WSS) | `wss://base-mainnet.g.alchemy.com/v2/$ALCHEMY_API_KEY` | API key in URL | Subscriptions and realtime. | | Arbitrum RPC (HTTPS) | `https://arb-mainnet.g.alchemy.com/v2/$ALCHEMY_API_KEY` | API key in URL | EVM L2. | | Arbitrum RPC (WSS) | `wss://arb-mainnet.g.alchemy.com/v2/$ALCHEMY_API_KEY` | API key in URL | Subscriptions and realtime. | | BNB RPC (HTTPS) | `https://bnb-mainnet.g.alchemy.com/v2/$ALCHEMY_API_KEY` | API key in URL | EVM L1. | | BNB RPC (WSS) | `wss://bnb-mainnet.g.alchemy.com/v2/$ALCHEMY_API_KEY` | API key in URL | Subscriptions and realtime. | | Solana RPC (HTTPS) | `https://solana-mainnet.g.alchemy.com/v2/$ALCHEMY_API_KEY` | API key in URL | Solana JSON-RPC. | | Solana Yellowstone gRPC | `https://solana-mainnet.g.alchemy.com` | `X-Token: $ALCHEMY_API_KEY` | gRPC streaming (Yellowstone). | | NFT API | `https://<network>.g.alchemy.com/nft/v3/$ALCHEMY_API_KEY` | API key in URL | NFT ownership and metadata. | | Prices API | `https://api.g.alchemy.com/prices/v1/$ALCHEMY_API_KEY` | API key in URL | Prices by symbol or address. | | Portfolio API | `https://api.g.alchemy.com/data/v1/$ALCHEMY_API_KEY` | API key in URL | Multi-chain wallet views. | | Notify API | `https://dashboard.alchemy.com/api` | `X-Alchemy-Token: <ALCHEMY_NOTIFY_AUTH_TOKEN>` | Generate token in dashboard. | --- ## x402 Access (No Account Needed) x402 is ideal for autonomous agents. No signup, no API keys. Pay with USDC on EVM or Solana. - **Gateway URL**: `https://x402.alchemy.com` - **SIWE/SIWS domain**: `x402.alchemy.com` - **Payment header**: `Payment-Signature: <base64>` - **Auth**: SIWE (EVM) or SIWS (Solana) For full setup and wallet bootstrapping, see: - [references/x402/overview.md](references/x402/overview.md) — End-to-end flow and packages - [references/x402/wallet-bootstrap.md](references/x402/wallet-bootstrap.md) — Wallet setup and USDC funding - [references/x402/authentication.md](references/x402/authentication.md) — SIWE/SIWS token creation - [references/x402/making-requests.md](references/x402/making-requests.md) — Sending requests with `@x402/fetch` - [references/x402/curl-workflow.md](references/x402/curl-workflow.md) — Quick RPC calls via curl - [references/x402/payment.md](references/x402/payment.md) — Payment creation from a 402 response - [references/x402/reference.md](references/x402/reference.md) — Endpoints, networks, headers, status codes --- ## MPP Access (No Account Needed) MPP supports Tempo (on-chain USDC, EVM only) and Stripe (credit card) payments. - **Gateway URL**: `https://mpp.alchemy.com` - **SIWE domain**: `mpp.alchemy.com` - **Payment header**: `Authorization: Payment <credential>` - **Auth**: SIWE only (EVM) For full setup, see: - [references/mpp/overview.md](references/mpp/overview.md) — End-to-end flow and packages - [references/mpp/wallet-bootstrap.md](references/mpp/wallet-bootstrap.md) — Wallet setup and funding - [references/mpp/authentication.md](references/mpp/authentication.md) — SIWE token creation - [references/mpp/making-requests.md](references/mpp/making-requests.md) — Sending requests with `mppx` - [references/mpp/curl-workflow.md](references/mpp/curl-workflow.md) — Quick RPC calls via curl - [references/mpp/payment.md](references/mpp/payment.md) — Payment creation from a 402 response - [refer
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (11)
curl -s -X POST "https://api.g.alchemy.com/prices/v1/$ALCHEMY_API_KEY/tokens/historical" \
curl -s -X POST "https://x402.alchemy.com/data/v1/assets/tokens/by-address" \
curl -s -X POST "https://x402.alchemy.com/data/v1/assets/tokens/balances/by-address" \
curl -s -X POST "https://x402.alchemy.com/prices/v1/tokens/by-address" \
curl -s -X POST "https://x402.alchemy.com/prices/v1/tokens/historical" \
- **API key**: Set `$ALCHEMY_API_KEY` and make requests directly. Full access to all products. Create a free key at [dashboard.alchemy.com](https://dashboard.alchemy.com/).
For applications, use `viem` to generate a SIWE token. Read the private key from an environment variable — never hardcode it. **Important:** Use `domain: "mpp.alchemy.com"` to target the MPP gateway:
For building applications, use `viem` for wallet management and `mppx` for payments. Always read the private key from an environment variable — never hardcode it in source files:
| `references/operational-roles-and-sso.md` | Roles and SSO | Team access control ensures API keys and billing settings are managed safely |
For applications, use the `signSiwe` or `signSiws` function from `@alchemy/x402`. Read the private key from an environment variable — never hardcode it:
For applications, use `createPayment` (EVM) or `createSolanaPayment` (Solana) from `@alchemy/x402`. Read the private key from an environment variable — never hardcode it:
Gates applied: critical_finding, no_behavioural_pass, undeclared_transfer.
4029e336cef5full audit observations/trust-audit/skill/bankrbot__alchemy.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 4029e336cef5 | BLOCK | D | 69 | first audit |
Questions
What does the Alchemy skill do?
Bankr Skills equip builders with plug-and-play tools to build more powerful agents.
Is Alchemy safe to install?
No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What can Alchemy access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
What do I need installed to use Alchemy?
Its own instructions reference mppx. Dependencies are pinned to exact versions.
Which assistants does Alchemy work with?
Its documentation mentions claude-code and cursor. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (4029e336cef5), read on 2026-10-09. The repository is watched, and a new audit runs when it changes — this is the first audit.