Atlas / Skills / leoyeai / Qfc

QfcBLOCK

skills/leoyeai/qfc

🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai

Verdict
BLOCK
Grade
D
Trust score
69 /100
Version
—
Hosts
1 documented
License
MIT
Stars
2,160
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://clawhub.ai/lai3d/qfc)

AI agent skill for interacting with the QFC blockchain. Provides wallet management, chain queries, staking info, and more — with built-in security policies.

Install

# OpenClaw native
openclaw skills add https://github.com/qfc-network/qfc-openclaw-skill

# or via ClawHub
clawhub install qfc

# or without installing clawhub globally:
npx clawhub@latest install qfc
Tip: To use clawhub directly, install it globally: npm install -g clawhub

Update

# via ClawHub
clawhub update qfc
# or: npx clawhub@latest update qfc

# or if installed via openclaw skills add
cd ~/.openclaw/skills/qfc-openclaw-skill
git pull && npm install && npm run build

Install from Source

git clone https://github.com/qfc-network/qfc-openclaw-skill.git
cd qfc-openclaw-skill
npm install && npm run build

Features

Wallet

  • Create / import wallets (HD, private key)
  • Balance queries & QFC transfers
  • Message signing

Wallet Persistence

  • AES-encrypted keystore on disk (~/.openclaw/qfc-wallets/)
  • Save, load, list, remove, and export keystore JSON
  • Compatible with MetaMask / Geth keystore format

Chain Queries

  • Block, transaction, and receipt lookups

Network & Validators

  • Node info, network state, gas price
  • Validator list with contribution scores & score breakdown

Epoch & Finality

  • Current epoch info, finalized block height

ERC-20 Tokens

  • Deploy new tokens — create ERC-20 tokens with one command (no compiler needed)
  • Get token info (name, symbol, decimals, totalSupply)
  • Check token balances, transfer tokens, approve spenders
  • Auto-handles decimal conversion

Smart Contracts

  • Read contract state (call), write transactions (send), deploy contracts
  • Check if an address is a contract, retrieve bytecode

AI Inference

  • Submit public inference tasks to QFC's decentralized GPU network
Read from source at commit 4f3b4a2a472eOBSERVED · 2026-10-08
02

Install

Commands as the repository documents them. They are shown, not run.

git clone https://github.com/qfc-network/qfc-openclaw-skill.git
npm install && npm run build
03

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
openclawmentioned
04

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: qfc-openclaw-skill
description: QFC blockchain interaction — wallet, faucet, chain queries, staking, epoch & finality, AI inference
homepage: https://github.com/qfc-network/qfc-openclaw-skill
license: MIT
metadata: {"openclaw":{"requires":{"bins":["node"]}}}
---

# QFC OpenClaw Skill

> AI agent skill for full QFC blockchain interaction

## Capabilities

### Wallet Management
- **Create Wallet**: Generate a new HD wallet with mnemonic, address, and private key
- **Import Wallet**: Restore wallet from private key
- **Get Balance**: Query QFC balance for any address
- **Send QFC**: Transfer QFC tokens to another address
- **Sign Message**: Sign an arbitrary message with the wallet's private key

### Wallet Persistence
- **Save Wallet**: Encrypt and persist a wallet to disk (`~/.openclaw/qfc-wallets/`) using industry-standard keystore format (scrypt KDF, compatible with MetaMask/Geth)
- **Load Wallet**: Decrypt and restore a previously saved wallet by address + password
- **List Saved Wallets**: Show all persisted wallets (address, name, network) without needing a password
- **Remove Wallet**: Delete a saved wallet's keystore file and metadata
- **Export Keystore JSON**: Get the encrypted keystore JSON for a saved wallet (for import into MetaMask or other tools)

### Faucet (Testnet Only)
- **Request Test QFC**: Get test tokens on testnet (chain_id=9000)

### Chain Queries
- **Get Block Number**: Latest block height
- **Get Block**: Block details by number or 'latest'
- **Get Transaction**: Transaction info by hash
- **Get Receipt**: Transaction receipt with logs

### Network Status
- **Node Info**: Version, chain ID, peer count, validator status
- **Network State**: Current network condition (normal/congested)
- **Chain ID / Block Number / Gas Price**: Basic network parameters

### Staking & Validators
- **List Validators**: All validators with stake, score, and compute mode
- **Get Stake**: Staked QFC amount for an address
- **Contribution Score**: Validator score (0-10000)
- **Score Breakdown**: Detailed 7-dimension scoring with metrics

### Epoch & Finality
- **Current Epoch**: Epoch number, start time, duration
- **Finalized Block**: Latest finalized block number

### Smart Contracts (v2.1)
- **Call Contract**: Read contract state (no gas needed) — pass address, ABI, method, and args
- **Send Transaction**: Write to a contract (requires wallet signer, costs gas)
- **Deploy Contract**: Deploy a new contract from ABI + bytecode
- **Check Contract**: Verify if an address has contract code deployed
- **Get Code**: Retrieve raw bytecode at an address
- **Verify Contract**: Submit source code to QFC explorer for verification (compiler version, EVM version, optimizer settings)

### ERC-20 Tokens (v2.1)
- **Deploy Token**: Create a new ERC-20 token on QFC — specify name, symbol, and initial supply. All tokens are minted to the deployer. No compiler needed (pre-compiled bytecode). Set `mintable: true` for a token with mint/burn/owner support. Auto-verifies source code on QFC explorer after deployment.
- **Mint Tokens**: Mint new tokens to any address (mintable tokens only, caller must be owner)
- **Burn Tokens**: Burn tokens from your balance (reduces total supply, mintable tokens only)
- **Token Info**: Get name, symbol, decimals, and total supply of any ERC-20 token
- **Token Balance**: Check token balance for any address
- **Transfer Tokens**: Send ERC-20 tokens to another address (auto-handles decimals)
- **Approve Spender**: Approve a contract/address to spend tokens (supports "max" for unlimited)
- **Check Allowance**: Query how much a spender is approved to use
- **Token Portfolio** (v2.3): View all token holdings for a wallet — native QFC balance plus every ERC-20 token with non-zero balance
- **Transfer History** (v2.3): View token transfer history from the explorer — filter by token and/or address
- **Batch Transfer Tokens** (v2.4): Send tokens to multiple addresses in one operation (sequential transfers)
- **Batch Send QFC** (v2.4): Send native QFC to multiple addresses
- **Deploy Airdrop Contract** (v2.5): Deploy a reusable Airdrop contract — batch transfer any ERC-20 in a single transaction (saves gas vs sequential). Auto-verifies source on explorer.
- **Smart Airdrop** (v2.5): Airdrop tokens via the Airdrop contract — auto-approves, supports variable or fixed amounts per recipient

### NFT / ERC-721 (v2.4)
- **Deploy NFT Collection**: Create a new ERC-721 NFT contract with name and symbol
- **Mint NFT**: Mint a new NFT with metadata URI to any address (owner only)
- **View NFT**: Query token URI, owner, and balance for any NFT
- **Transfer NFT**: Transfer an NFT to another address

### Token Swap / DEX (v2.5)
- **Deploy Pool**: Create a constant-product AMM pool (x*y=k) for any ERC-20 token pair. 0.3% swap fee. LP tokens track liquidity shares. Auto-verifies source on explorer.
- **Pool Info**: View pool reserves, token details, current price, and total LP supply
- **Add Liquidity**: Deposit both tokens into a pool to earn LP tokens (auto-approves)
- **Remove Liquidity**: Burn LP tokens to withdraw proportional share of both tokens
- **Swap Tokens**: Swap one token for another with slippage protection (default 1%)
- **Get Quote**: Preview expected output amount, price impact, and fee before swapping
- **LP Balance**: Check LP token balance for any address
- **Deploy WQFC** (v3.0): Deploy the Wrapped QFC (ERC-20 wrapper for native QFC)
- **Wrap/Unwrap QFC** (v3.0): Convert native QFC ↔ WQFC for use in DEX pools
- **Swap QFC for Token** (v3.0): Auto-wrap native QFC and swap in one call
- **Swap Token for QFC** (v3.0): Swap token to WQFC and auto-unwrap to native QFC

### Token Launchpad (v3.0)
- **Launch Token**: One-command token launch — deploy token + deploy WQFC pool + add initial liquidity. Returns token address, pool address, and LP details.

### NFT Marketplace (v3.0)
- **Deploy Marketplace**: Deploy an on-chain NFT marketplace contract with configurable platform fe
05

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (8)

HIGHPrompt injection · prompt.credential_read · CWE-94, CWE-1427
SKILL.md:232
List my saved QFC wallets and load the first one with password "mypass"
Why it matters. asks the agent to read credentials
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
skills/compdf-conversion-cli/scripts/license.xml:9
<key>k5Ey9KFlkqpj+SDkUw+5ED9lTA3En/qUi0zdrydUCH3kMWTE3Eh65NXnFCaxlY2omY2JHnlEoK7Li7oOEvM7eG5VPdcO/sFlMfoCRdnLYdepJ+uLzYwOWR8W4yQVve/clxVFTVRL4DFleKInGdpAxIbHZT2yi4ADAMENls1N1XSLojRuqXePXDeAT/4Mv4TTx0s
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
src/marketplace.ts:36
const MARKETPLACE_DEPLOY_BYTECODE = '0x608060405234801561001057600080fd5b50604051610def380380610def83398101604081905261002f916100ca565b6103e88211156100745760405162461bcd60e51b815260206004820152600c602
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
src/multicall.ts:12
const MULTICALL_DEPLOY_BYTECODE = '0x6080604052348015600f57600080fd5b506104a68061001f6000396000f3fe608060405234801561001057600080fd5b506004361061002b5760003560e01c806382ad56cb14610030575b600080fd5b610
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
src/nft.ts:108
const ERC721_DEPLOY_BYTECODE = '0x608060405234801561001057600080fd5b50604051610dbf380380610dbf83398101604081905261002f9161011b565b600061003b838261021a565b506001610048828261021a565b50506002805460016001
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
src/swap.ts:47
const WQFC_DEPLOY_BYTECODE = '0x60c0604052600b60809081526a577261707065642051464360a81b60a05260009061002a9082610112565b506040805180820190915260048152635751464360e01b60208201526001906100539082610112565b
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
ethers, typescript
Why it matters. 2 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
references/wallet-operations.md:77
const wallet = await QFCWallet.load('0xAddress', 'mypassword', 'testnet');
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 4f3b4a2a472efull audit observations/trust-audit/skill/leoyeai__qfc.json · Report an issue / request a re-scan
06

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-084f3b4a2a472eBLOCKD69first audit
07

Questions

What does the Qfc skill do?

🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai

Is Qfc safe to install?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What can Qfc access on my machine?

The audit observed that it reaches the network and reads or writes files. Each of those is consistent with what it says it does. Secrets in the source: none found.

Which assistants does Qfc work with?

Its documentation mentions openclaw. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (4f3b4a2a472e), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement