Atlas / Skills / nousresearch / Evm

EvmSAFE

skills/nousresearch/evm

The agent that grows with you

Verdict
SAFE
Grade
B
Trust score
89 /100
Version
1.0.0
Hosts
—
License
MIT
Stars
247,828
01

Overview

The agent that grows with you

Read from source at commit 1e09e6ec6721OBSERVED · 2026-09-22
02

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: evm
description: "Read-only EVM client: wallets, tokens, gas across 8 chains."
version: 1.0.0
author: Mibayy (@Mibayy), youssefea (@youssefea), ethernet8023 (@ethernet8023), Hermes Agent
license: MIT
platforms: [linux, macos, windows]
metadata:
  hermes:
    tags: [EVM, Ethereum, BNB, BSC, Base, Arbitrum, Polygon, Optimism, Avalanche, zkSync, Blockchain, Crypto, Web3, DeFi, NFT, ENS, Whale, Security]
    category: blockchain
    related_skills: [solana]
    requires_toolsets: [terminal]
---

# EVM Blockchain Skill

Query EVM-compatible blockchain data across 8 chains with USD pricing.
14 commands: wallet portfolio, token info, transactions, activity, gas tracker,
network stats, price lookup, multi-chain scan, whale detection, ENS resolution,
allowance checker, contract inspector, and transaction decoder.

Supports 8 chains: Ethereum, BNB Chain (BSC), Base, Arbitrum One, Polygon,
Optimism, Avalanche (C-Chain), zkSync Era.

No API key needed. Zero external dependencies — Python standard library only
(urllib, json, argparse, threading).

> **Supersedes the standalone `base` skill.** Base-specific tokens (AERO, DEGEN,
> TOSHI, BRETT, WELL, cbETH, cbBTC, wstETH, rETH) and all Base RPC functionality
> previously living under `optional-skills/blockchain/base/` have been folded
> into this skill. Pass `--chain base` to any command for Base coverage.

---

## When to Use
- User asks for a wallet balance or portfolio on any EVM chain
- User wants to check the same wallet across ALL chains at once
- User wants to inspect a transaction by hash (or decode what it did)
- User wants ERC-20 token metadata, price, supply, or market cap
- User wants recent transaction history for an address
- User wants current gas prices or to compare fees across chains
- User wants to find large whale transfers in recent blocks
- User asks to resolve an ENS name (vitalik.eth) or reverse-lookup an address
- User wants to check if a contract has dangerous token approvals
- User wants to inspect a smart contract (proxy? ERC-20? ERC-721? bytecode size?)
- User wants to compare gas costs across chains before a transaction

---

## Prerequisites
Python 3.8+ standard library only. No pip installs required.
Pricing: CoinGecko free API (rate-limited, ~10-30 req/min).
ENS: ensideas.com public API.
Tx decoding: 4byte.directory public API.

Override RPC endpoint: `export EVM_RPC_URL=https://your-rpc.com`

Helper script path: `~/.hermes/skills/blockchain/evm/scripts/evm_client.py`

---

## Quick Reference

```
SCRIPT=~/.hermes/skills/blockchain/evm/scripts/evm_client.py

# Network & prices
python $SCRIPT stats                            # Ethereum stats
python $SCRIPT stats --chain arbitrum           # Arbitrum stats
python $SCRIPT compare                          # Gas + prices ALL 8 chains

# Wallet
python $SCRIPT wallet 0xd8dA...96045            # Portfolio (ETH + ERC-20)
python $SCRIPT wallet 0xd8dA...96045 --chain bsc
python $SCRIPT multichain 0xd8dA...96045        # Same wallet on ALL chains

# Tokens & prices
python $SCRIPT price ETH
python $SCRIPT price 0xdAC1...1ec7              # By contract address
python $SCRIPT token 0xdAC1...1ec7              # ERC-20 metadata + market cap

# Transactions
python $SCRIPT tx 0x5c50...f060                 # Transaction details
python $SCRIPT decode 0x5c50...f060             # Decode input data (4byte.directory)
python $SCRIPT activity 0xd8dA...96045          # Recent transactions

# Gas
python $SCRIPT gas                              # Gas prices + cost estimates
python $SCRIPT gas --chain optimism

# Security
python $SCRIPT allowance 0xd8dA...96045         # Dangerous ERC-20 approvals
python $SCRIPT contract 0xdAC1...1ec7           # Contract inspection (proxy? standards?)

# ENS
python $SCRIPT ens vitalik.eth                  # Name -> address + profile
python $SCRIPT ens 0xd8dA...96045               # Address -> ENS name

# Whale detection
python $SCRIPT whale                            # Large transfers (last 20 blocks, >$10k)
python $SCRIPT whale --blocks 50 --min-usd 100000 --chain arbitrum
```

---

## Procedure

### 0. Setup Check
```bash
python --version   # 3.8+ required
python ~/.hermes/skills/blockchain/evm/scripts/evm_client.py stats
```

### 1. Wallet Portfolio
Native balance + known ERC-20 tokens, sorted by USD value.
```bash
python $SCRIPT wallet 0xd8dA6BF26964aF9D7eEd9e03E53415D37aA96045
python $SCRIPT wallet 0xd8dA... --chain bsc --no-prices   # faster
```

### 2. Multi-Chain Scan
Scans all 8 chains simultaneously for the same address using threads.
```bash
python $SCRIPT multichain 0xd8dA6BF26964aF9D7eEd9e03E53415D37aA96045
```
Output: per-chain native balance + token holdings + grand total USD.

### 3. Compare (Gas + Prices)
All 8 chains queried in parallel. Shows cheapest/most expensive chain.
```bash
python $SCRIPT compare
```

### 4. Transaction Details & Decode
```bash
python $SCRIPT tx 0x5c504ed432cb51138bcf09aa5e8a410dd4a1e204ef84bfed1be16dfba1b22060
python $SCRIPT decode 0x5c504ed...   # Shows human-readable function signature
```
Decode uses 4byte.directory to translate 0xa9059cbb -> transfer(address,uint256).

### 5. ENS Resolution
```bash
python $SCRIPT ens vitalik.eth          # -> 0xd8dA... + avatar + social links
python $SCRIPT ens 0xd8dA...96045       # -> vitalik.eth
```

### 6. Allowance Checker (Security)
Checks ERC-20 approvals granted to known DEX/bridge contracts.
```bash
python $SCRIPT allowance 0xYourWallet
```
Flags UNLIMITED approvals as HIGH risk.

### 7. Contract Inspector
```bash
python $SCRIPT contract 0xA0b86991c6218b36c1d19D4a2e9Eb0cE3606eB48   # USDC (proxy)
python $SCRIPT contract 0xdAC17F958D2ee523a2206206994597C13D831ec7   # USDT (ERC-20)
```
Detects: proxy (EIP-1967/EIP-1167), ERC-20, ERC-721, ERC-165. Shows bytecode size and implementation address for proxies.

### 8. Whale Detection
```bash
python $SCRIPT whale                                    # ETH, last 20 blocks, >$10k
python $SCRIPT whale --blocks 50 --min-usd 50000 
03

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (2)

LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
scripts/evm_client.py:520
b = bytes.fromhex(raw)
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
scripts/evm_client.py:525
return bytes.fromhex(chars).decode("utf-8", errors="replace").strip()

Gates applied: no_behavioural_pass.

Audited 2026-09-22 · audit v0.4.1 · source sha 1e09e6ec6721full audit observations/trust-audit/skill/nousresearch__evm.json · Report an issue / request a re-scan
04

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-09-221e09e6ec6721SAFEB89first audit
05

Questions

What does the Evm skill do?

The agent that grows with you

Is Evm safe to install?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.

What can Evm access on my machine?

The audit observed that it reaches the network. Each of those is consistent with what it says it does. Secrets in the source: none found.

How current is this page?

The grade is for one exact copy of the source (1e09e6ec6721), read on 2026-09-22. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement