Sponsor Suno AI Music arrow_forward
Skill

Base Trading Agent

Automated DEX Trading on Base - Execute high-speed token swaps, liquidity provision, and arbitrage on Base L2 with MEV protection and gas…

Type
Skill
Repository
snyk/agent-scan
GitHub stars
3.1k
License
Apache-2.0
Repo last updated
Sep 26, 2026
Source file
README.md

What Base Trading Agent is

Base Trading Agent is a skill published in the snyk/agent-scan repository on GitHub, which has about 3.1k stars. The repository describes itself as: “Security scanner for AI agents, MCP servers and agent skills.”

A skill is a folder with a SKILL.md file: frontmatter with a name and a description, followed by instructions Claude follows. Claude loads a skill automatically when a task matches its description, and you can also run it directly with a slash and its name.

Skills work in Claude Code and in Claude Cowork, which makes Base Trading Agent a portable way to give Claude the same method everywhere.

How to install Base Trading Agent

Claude Code

  1. Download the base-trading-agent folder from the repository.
  2. Save it as ~/.claude/skills/<skill-name>/SKILL.md for all projects, or .claude/skills/<skill-name>/SKILL.md for one project.
  3. Claude loads it automatically when a task matches; you can also run it with / and its name.

Claude Cowork

  1. Zip the skill folder so SKILL.md sits at the top level of the folder.
  2. Open Customize → Skills, click +, then upload the ZIP.
  3. Start a task that matches the description, or call it by name with /.

New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.

Inside the source file

An excerpt from README.md, shared under the repository's Apache-2.0 license. Read the full file on GitHub.

Snyk Agent Scan

Discover and scan agent components on your machine for prompt injections and vulnerabilities (including agents, MCP servers, skills).

> Note: We don't publish an npm package for Agent Scan. Install it via uvx or as a standalone binary.

> Note: CLI output is experimental and subject to change > > Agent Scan v0.5.x (planned for deprecation) > > The raw output of this CLI — including issue codes, field names, severity labels, and response structure — is experimental and may change without notice between releases. We do not recommend building production workflows that depend on specific CLI output fields or issue codes. > > Agent Scan v0.6 and later > > The raw output of this CLI — including risk indicator names, scores, field names, and response structure — is experimental and may change without notice between releases. We do not recommend building production workflows that depend on specific CLI output fields or risk names. > > If you are an enterprise customer using Snyk to manage agent security risk at scale, the CLI output may not reflect what is sent to and shown in the Evo platform. The underlying integration, discovery, and risk assessment that powers enterprise deployments is stable and supported — any changes will be communicated in line with standard Snyk product practices. Contact your account team for deployment guidance.

> NEW Read our technical report on the emerging threats of the agent skill eco-system published together with Agent Scan 0.4, which adds support for scanning agent skills.

Agent Scan v0.5.x output

> [!WARNING] > Agent Scan v0.5.x uses issue-code output. This CLI line is planned for deprecation.

Agent Scan v0.6 and later output

Agent Scan helps you discover all your installed agent components (harnesses, MCP servers, and skills) and scans them for common threats like prompt injections, sensitive data handling, or malware payloads hidden in natural language. Ignore analysis on skills by using --no-skills.

Security Warning

> ⚠️ IMPORTANT: Scanning MCP configurations can execute commands or make outbound network requests. > > To retrieve tool descriptions, Agent Scan starts stdio MCP servers by executing the commands in the config and connects to configured remote MCP server URLs with their configured headers. > > Recommendations: > - Run scans inside a sandbox (Docker container, VM, or disposable environment) when evaluating untrusted or third-party MCP configs > - Review the consent prompt carefully during interactive scans; it shows the command or remote URL for each server > - Use --dangerously-run-mcp-servers only in trusted environments where you've verified all MCP server commands and remote URLs > > Remote MCP requests refuse destinations resolving to link-local addresses or known cloud-metadata endpoints (169.254.0.0/16, fe80::/10, fd00:ec2::254, and 100.100.100.200). Loopback and private addresses remain allowed for local and internal MCP servers. HTTP redirects are not followed. DNS is validated before each request, but resolution again at connection time leaves a DNS-rebinding window. > > By default, Agent Scan requires explicit user consent (y/n) before contacting each discovered MCP server during foreground interactive runs. Background and push-key scans continue to inspect remote servers automatically for fleet coverage, but do not start stdio servers unless --dangerously-run-mcp-servers is set.

Before you install

  • Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
  • Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
  • Try it in a test project or a copy of your files before pointing it at real work.
  • Pin the version you tested, and review changes before updating.
  • Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.

FAQ

What is Base Trading Agent?

Base Trading Agent is a skill for Claude Code and Claude Cowork from the snyk/agent-scan repository on GitHub. Automated DEX Trading on Base - Execute high-speed token swaps, liquidity provision, and arbitrage on Base L2 with MEV protection and gas…

How do I install Base Trading Agent in Claude Code?

Download the base-trading-agent folder from the repository. Save it as ~/.claude/skills/<skill-name>/SKILL.md for all projects, or .claude/skills/<skill-name>/SKILL.md for one project. Claude loads it automatically when a task matches; you can also run it with / and its name.

Can I use Base Trading Agent in Claude Cowork?

Zip the skill folder so SKILL.md sits at the top level of the folder. Open Customize → Skills, click +, then upload the ZIP. Start a task that matches the description, or call it by name with /.

Is Base Trading Agent safe to install?

It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.

Similar resources

Browse all skills, subagents, and plugins →

Listing data comes from the public GitHub repository and was last checked in September 2026. Excerpts are © their authors and shared under Apache-2.0. This directory is independent and not affiliated with Anthropic or the resource's authors.