Project 0BLOCK
🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai
Overview
🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai
4f3b4a2a472eOBSERVED · 2026-10-08Install
Commands as the repository documents them. They are shown, not run.
npm install @0dotxyz/p0-ts-sdk
Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| openclaw | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
---
name: project0
version: 2.2.6
description: >
Permissionless DeFi yield and credit on Solana via the Project 0 (P0) protocol.
Deposit funds to earn yield across Solana's highest-yielding venues.
Borrow stablecoins against deposited collateral instead of selling crypto.
Execute advanced yield strategies via rate arbitrage and looping.
All operations are on-chain and permissionless -- no accounts, no approval process.
Note: This skill requires a wallet keypair to sign transactions. Use a dedicated
wallet with limited funds -- never expose your main private key. The agent will
always ask for confirmation before signing. Read-only operations need no keypair.
homepage: https://0.xyz
metadata:
openclaw:
requires:
env:
- RPC_URL
- WALLET_KEYPAIR
- WALLET_ADDRESS
- P0_ACCOUNT
- JUPITER_API_KEY
primaryEnv: RPC_URL
---
# Project 0 Skill
## What is Project 0?
P0 is a permissionless DeFi prime broker on Solana. It provides unified margin
accounts that span multiple lending venues (P0 native, Kamino, Drift), giving
agents access to the best yields and deepest liquidity across the ecosystem.
All operations are on-chain, non-custodial, and require no signup.
**Documentation:**
- Protocol overview: https://docs.0.xyz/
- TypeScript SDK: https://docs.0.xyz/typescript-sdk/overview
### Use Case 1: Yield + Credit
Deposit funds to earn the best yield across DeFi. When the user needs
liquidity (e.g. to make a purchase), borrow stablecoins against deposited
collateral instead of selling crypto. The user keeps earning yield while
accessing cash.
**Flow:** Deposit -> Earn yield -> Borrow stablecoins when needed -> Repay.
**Example prompts:**
- "Deposit my SOL on P0 for the best yield."
- "I need $500 USDC but don't want to sell my SOL."
- "What is the cheapest stablecoin to borrow on P0?"
### Use Case 2: Advanced Yield Strategies
Find the absolute best yields on Solana, which often come from rate arbitrage
and looping strategies. These involve depositing one asset, borrowing another,
and managing the leveraged position. Higher yields, but requires active health
monitoring.
**Flow:** Identify strategy -> Deposit collateral -> Borrow -> Monitor health.
**Example prompts:**
- "What are the highest-yield strategies on P0 right now?"
- "Set up a bbSOL/SOL rate arb on P0."
- "Put my funds to work on P0 for the best yield."
---
## Agent Workflow
When a user asks to earn yield, deposit, borrow, or manage positions on P0,
follow these steps in order. Do NOT skip ahead to writing code.
### Step 1: Check wallet balances
Resolve the wallet address: check `.env` for `WALLET_ADDRESS`, or derive
it from the keypair if `WALLET_KEYPAIR` is set, or ask the user.
Fetch the wallet's token holdings from the wallet API (see Wallet endpoint
below). No credentials needed. Use the `address` field from each token to
match against P0 banks by `mint`.
### Step 2: Fetch P0 data
Fetch banks and strategies from the P0 APIs (see Read-Only APIs below).
### Step 3: Recommend optimal action
Determine which use case fits the user's request:
- If the user wants to **earn yield or access credit**, recommend the best
deposit opportunity and mention borrowing as an option (Use Case 1).
- If the user wants the **highest possible yield** or mentions strategies,
rate arbs, or looping, recommend the best strategy and explain the
deposit + borrow setup required (Use Case 2).
Match wallet holdings to available bank yields. For each token the wallet
holds, find the best deposit APY from the banks data. Compare across all
holdings to find the highest overall yield.
If the wallet holds tokens that have no corresponding P0 bank (e.g.
memecoins), suggest swapping them into a supported token.
If swapping to a different token would yield significantly more, recommend
the swap and explain the tradeoff.
Consider depositing multiple assets if the wallet holds several supported
tokens -- not just the single highest-yield one.
**Present the plan to the user with specific numbers before executing.**
Example: _"Your wallet holds 0.09 bbSOL (~$18) and 0.10 SOL (~$15). bbSOL
earns 15.2% APY on P0 vs SOL at 4.9%. I recommend depositing your bbSOL
for the higher yield. Shall I proceed?"_
### Step 4: Collect credentials
Before executing on-chain operations, the agent needs an RPC URL and a
wallet keypair.
**RPC URL:** Check `.env` for `RPC_URL`, `SOLANA_RPC_URL`, or `HELIUS_RPC_URL`.
If not found, ask the user: _"I need a paid Solana RPC URL to execute
transactions. (Helius has a free tier at https://www.helius.dev)"_
**Wallet address:** Check `.env` for `WALLET_ADDRESS`. If set, use it for
read-only operations (wallet balances, account discovery) without needing
the keypair. The keypair is only required when signing transactions.
**Wallet keypair:** If the user provided a keypair path in their message,
use it directly. Otherwise check `.env` for `WALLET_KEYPAIR`. If neither,
ask: _"I need a Solana keypair to sign transactions. Set `WALLET_KEYPAIR`
in your `.env` to the file path, or tell me where your keypair JSON file
is."_
**P0 account (optional):** Check `.env` for `P0_ACCOUNT`. If set, use it
directly when loading the account (skip discovery/prompt). If not set,
follow the account discovery logic in "Create or load account" below.
Do not fabricate URLs, file paths, or account addresses. Wait for the user
to provide real values.
### Step 5: Collect swap credentials (only if needed)
If the plan from step 3 involves swapping tokens, the agent needs a Jupiter
API key.
Check for an existing key in the environment:
- Look for `JUPITER_API_KEY` or `JUP_API_KEY` in the environment variables
or `.env` file
- If found, use it and skip the prompt
If no key is found, ask the user:
_"I need a Jupiter API key for the token swap. Get a free one at
https://portal.jup.ag (60 req/min)"_
If no swap is needed, skip this step entirely.
### Step 6: Execute
Execute Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (3)
### Step 4: Collect credentials
### Step 5: Collect swap credentials (only if needed)
<key>k5Ey9KFlkqpj+SDkUw+5ED9lTA3En/qUi0zdrydUCH3kMWTE3Eh65NXnFCaxlY2omY2JHnlEoK7Li7oOEvM7eG5VPdcO/sFlMfoCRdnLYdepJ+uLzYwOWR8W4yQVve/clxVFTVRL4DFleKInGdpAxIbHZT2yi4ADAMENls1N1XSLojRuqXePXDeAT/4Mv4TTx0s
Gates applied: no_behavioural_pass.
4f3b4a2a472efull audit observations/trust-audit/skill/leoyeai__project-0.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 4f3b4a2a472e | BLOCK | D | 69 | first audit |
Questions
What does the Project 0 skill do?
🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai
Is Project 0 safe to install?
No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What can Project 0 access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Project 0 work with?
Its documentation mentions openclaw. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (4f3b4a2a472e), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.