Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsCommunityBlog
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Galleon Morpho Market

ASecurity

Use when evaluating a specific Morpho Blue market or Morpho vault allocation, oracle, LLTV, borrow liquidity or exit risk.

2 stars
0 votes
0 copies
0 views
Added 9/28/2026
ai-agentsgogitdocumentation

Security Analysis

A100/100

Scanned 9/28/2026

Install to Claude Code

$npx -y skills add galleonlabs/crypto-defi-skills --skill galleon-morpho-market --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Galleon Morpho Market?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Galleon Morpho Market
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/galleonlabs-galleon-morpho-market/badge)](https://www.skillsdirectory.com/skills/galleonlabs-galleon-morpho-market)

More formats (shields.io, HTML) on the badges page.

Files
SKILL.md
---
name: galleon-morpho-market
description: "Use when evaluating a specific Morpho Blue market or Morpho vault allocation, oracle, LLTV, borrow liquidity or exit risk."
license: MIT
compatibility: "Read-only EVM RPC or official provider tools; Bun is optional for offline examples. No signer required."
metadata:
  version: "0.2.0"
  author: "Andrew Wilkinson and Galleon Labs"
  source: "https://github.com/galleonlabs/crypto-defi-skills"
---

# Morpho market diligence

Resolve the **chain plus market ID or vault address** before evaluating yield. Morpho Blue markets are permissionless. A listed market or curator brand is discovery evidence, not a risk endorsement.

## Identify the object

For a Blue market, read `idToMarketParams(id)` and record all five fields: loanToken, collateralToken, oracle, IRM and LLTV. Recompute the ID with the maintained SDK or the deployed market-ID library. Similar collateral tickers with different oracle, IRM or LLTV are different markets. Read code presence and token decimals on that chain.

For a vault, identify the implementation/version first. A legacy MetaMorpho V1 withdrawal queue is not the interface for Vault V2 adapters. Record asset, share decimals, curator/owner/guardian authority, fees, timelocks, caps and each allocation's downstream market identity. If version or adapter semantics are unknown, stop at a diligence report; do not fabricate a queue call.

## Market observations

Read `market(id)` and `position(id, account)` at a common block. Raw market totals can lag interest accrual; use the official accrual/share-conversion implementation for a current debt estimate. In particular, borrow shares are not loan-token units. Do not replace rounding and virtual-share offsets with a floating-point ratio.

Read the configured oracle's `price()` and its composition. Verify both token decimal conventions and the feed's freshness, fallback and manipulation assumptions. The Blue oracle price uses 1e36 scaling for raw collateral-to-loan conversion; token decimals are already embodied in that price. Applying token decimals twice can make the loan appear many orders of magnitude safer.

Calculate LTV against accrued debt and compare with the market's LLTV, then stress collateral price, loan price and interest. Read supply/borrow totals and identify immediately available liquidity. Liquidation eligibility and profitable liquidation are different: oracle delay, liquidation incentive and collateral market depth matter.

## Vault decision

Return reward-free yield, incentive yield separately, top allocations, concentration, oracle dependencies, governance delay and an exit estimate. For legacy V1, inspect supply and withdrawal queues and downstream utilization; deposits and exits use different constraints. For V2, follow each adapter's documented withdrawal route and loss accounting. A vault's high total assets or unfilled deposit cap does not prove redeemability.

For an account exit, pair share balance and `maxWithdraw`/`maxRedeem` with the appropriate previews and same-state simulation. Shared collateral across markets creates correlated exposure even when market IDs differ. Refuse to rank by headline APY when withdrawal liquidity or the relevant oracle cannot be read.

## Evidence and completion

Return the requested decision, exact deployment and chain, block/time, raw-unit observations, calculation assumptions, and the next missing read. Distinguish an indexed estimate, an onchain read, a simulated call and a confirmed transaction. Research ends with an actionable decision record; it does not require connecting a wallet.

For a requested write, prepare the complete unsigned sequence and simulate with the actual sender, amount, recipient and allowance state. Preserve authorization already supplied; research does not grant debt, spending or signing authority. Never request keys. After an authorized transaction, verify its receipt and the relevant balance or position change. On an ambiguous timeout, reconcile its hash and nonce before retrying.

Read [protocol references and worked record](references/recipe.md) only for the selected operation. Documentation checked 2026-09-27; refresh deployments and current parameters at use time. This directory is independently installable.

Attribution

galleonlabsgalleonlabs
View sourceMore from galleonlabs →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Ultra-compressed communication mode that cuts output tokens while keeping technical accuracy. Levels: lite, full, ultra and the wenyan variants. Use for /caveman, "caveman mode", "talk like caveman", "be brief" or "less tokens".

1074701 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

695601 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3351 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

691 votes

math-skill

A comprehensive mathematical reasoning skill for AI assistants — handles arithmetic to research-level problems with rigorous step-by-step reasoning, systematic verification, and transparent uncertainty handling

381 votes
View all in ai-agents →