Agent Plugins Marketplace
All plugins

external-call-safety

v1.0.0

Detects unsafe external call patterns and token integration vulnerabilities in smart contracts. Covers unchecked call return values, fee-on-transfer tokens, rebasing tokens, missing ERC20 return values (USDT), ERC-777 callback risks, unsafe approve patterns, return data bombs, and pull vs push payment analysis. Addresses OWASP SC06.

Claude Code1 Skill

By QuillShield125 GitHub starsUpdated 5 months ago

Directory evidence

Runtimes
Claude Code
Parsed components
1 skill or MCP entry
Source updated
Mar 30, 2026
Manifest status
Canonical path parsed

The directory validates manifest shape and source location. It does not execute the plugin or provide a security endorsement. Review the indexing methodology

Install external-call-safety for Claude Code

Installs for the current user
claude plugin marketplace add IchenDEV/agent-plugin-mkt
claude plugin marketplace update agent-plugin-marketplace
claude plugin install external-call-safety@agent-plugin-marketplace

Paste and run these commands in a terminal with Claude Code. They add and refresh the PluginsMP catalog, then install this plugin.

The installer fetches third-party code from the source repository shown on this page. This directory validates manifest structure and source location, but does not perform a security audit; review the manifest, components, and source before installing.

Get the source manually
git clone https://github.com/quillai-network/quillshield_skills

Clone the source repository, then follow its setup instructions to add the plugin to a compatible client. The plugin root is plugins/external-call-safety/.

Plugin files

plugins/external-call-safety/
├── .claude-plugin/plugin.json
└── skills/external-call-safety/SKILL.md

Included Skills1

external-call-safetyskills/external-call-safety/SKILL.md

Detects unsafe external call patterns and token integration vulnerabilities in smart contracts. Covers unchecked call/delegatecall/staticcall return values, fee-on-transfer tokens, rebasing tokens, tokens with missing return values (USDT), ERC-777 callback risks, unsafe approve race conditions, return data bombs, gas stipend limitations, and push vs pull payment patterns. Use when auditing contracts that interact with external contracts, integrate arbitrary ERC20 tokens, distribute payments, or make low-level calls.

Plugin manifests1

plugins/external-call-safety/.claude-plugin/plugin.json
{
  "name": "external-call-safety",
  "version": "1.0.0",
  "description": "Detects unsafe external call patterns and token integration vulnerabilities in smart contracts. Covers unchecked call return values, fee-on-transfer tokens, rebasing tokens, missing ERC20 return values (USDT), ERC-777 callback risks, unsafe approve patterns, return data bombs, and pull vs push payment analysis. Addresses OWASP SC06.",
  "author": {
    "name": "QuillShield",
    "url": "https://github.com/quillai-network"
  }
}

If you maintain this plugin, link to this source-backed listing from your README so users can review its manifest and indexed components.

[external-call-safety on Agent Plugins Marketplace](https://pluginsmp.com/plugins/external-call-safety)