Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsCommunityBlog
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Uniswap Swap

ASecurity

Use when quoting or preparing a Uniswap token swap, reviewing Permit2 authorization, choosing an AMM versus UniswapX path, or reconciling a submitted swap. Uses the official Trading API with exact raw amounts and route-specific lifecycle handling.

2 stars
0 votes
0 copies
0 views
Added 9/28/2026
ai-agentsnodeapidocumentation

Works with

api

Security Analysis

A100/100

Scanned 9/28/2026

Install to Claude Code

$npx -y skills add galleonlabs/crypto-defi-skills --skill uniswap-swap --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Uniswap Swap?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Uniswap Swap
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/galleonlabs-uniswap-swap/badge)](https://www.skillsdirectory.com/skills/galleonlabs-uniswap-swap)

More formats (shields.io, HTML) on the badges page.

Files
SKILL.md
---
name: uniswap-swap
description: "Use when quoting or preparing a Uniswap token swap, reviewing Permit2 authorization, choosing an AMM versus UniswapX path, or reconciling a submitted swap. Uses the official Trading API with exact raw amounts and route-specific lifecycle handling."
license: MIT
compatibility: "Read-only EVM RPC and official protocol APIs or UI. Optional Node.js 20 for offline helpers. No signer included."
metadata:
  author: "Galleon Labs"
  version: "0.2.0"
---

# Uniswap Swap

Return a comparable quote and a bounded unsigned handoff, or resolve an existing transaction/order. Distinguish `CLASSIC` AMM transactions from UniswapX signed orders before constructing anything. Use the official Trading API or verified official interface; a wallet connection is not needed to explain or compare a public quote, but its real swapper address is needed for an executable one.

For application integration work, discover the official `swap-integration` skill from `uniswap/uniswap-ai` if already available. This operational recipe complements that upstream integration surface; it does not require an automatic install or replace upstream transaction builders.

## Gather and quote

Require chain IDs, exact input/output token addresses, raw integer amount, exact-input or exact-output intent, swapper, recipient intent, slippage and expiry/cost bounds. Look up token decimals on the selected chain; symbols do not identify assets. For exact-output intent show maximum input, not a fixed input debit.

Use [API recipes](references/recipes.md). Obtain an API key through the user's existing secret mechanism; never print it. Missing key means use a connected official tool/UI or produce a parameter-complete request marked unqueried, not a fabricated quote. Pin one supported `x-universal-router-version` consistently through the journey. For an AMM-only task request `protocols: ["V2","V3","V4"]` only if the user accepts those protocols; narrow to the approved subset when required.

Interpret the actual `routing` discriminator, `quoteId`, quoted input/output and minimum/maximum amounts. Preserve returned quote JSON rather than reconstructing it. Check `txFailureReason`, gas, recipient, chain, token identities and quote time. A successful quote endpoint does not prove allowance, affordability or a submitted swap.

## Approval and route lifecycle

1. Use `/check_approval` with the actual wallet, token, chain and required amount. Inspect any returned revoke/approval transaction: target, spender, token, raw cap and chain. ERC-20 allowance to Permit2 and a signed Permit2 message are different authorizations.
2. If quote contains `permitData`, inspect its domain chain/verifying contract, token, spender, amount, nonce and deadlines. The wallet must explicitly authorize that exact message in an execution workflow. A signature belonging to an older quote must never be attached to a refreshed one. Do not expose signatures in a report.
3. `CLASSIC`: `/swap` constructs an unsigned transaction from the preserved quote and matching permit data/signature when needed. Inspect and simulate returned from/to/data/value/chain before any authorized wallet sends it. The skill itself includes no signer. Do not request a signature merely to complete a research task.
4. UniswapX routes such as `DUTCH_V2`, `DUTCH_V3` or `PRIORITY`: an order signature can authorize spending. Use the corresponding official `/order` flow and track order identity/fills. Never feed an auction order into the AMM `/swap` recipe or label order acceptance a mined fill. Unsupported routing types require their documented flow, not a guessed fallback.
5. A changed token, recipient, chain, route, quote or limit invalidates the old packet. Refresh and recheck; do not silently relax slippage to make simulation pass. Native input has value/gas requirements, and wrapping is not an ERC-20 transferFrom.

## Reconcile the result

For AMM swaps record submitted hash, receipt status and block, input debit, output received by intended recipient, gas paid, and any unspent input/refund. Token transfer logs must agree with the actual token addresses and account deltas; handle unrelated concurrent transfers rather than blindly subtracting two balances. An RPC timeout after send is `submission-unknown`: inspect the original hash/nonce instead of creating a new send.

For orders query `/orders` using the documented order identifier and reconcile on-chain fills, remaining authorization, expiry and cancellation status. An expired quote is not proof an already signed order is cancelled. Never retry by signing another order while the first may still fill.

## Worked output

Synthetic exact-input 100 USDC (6 decimals): amount `100000000`; slippage `0.5` means 0.5 percent in this API. Returned CLASSIC minimum is `49000000000000000` WETH and permitData is present. Report minimum 0.049 WETH plus separately quoted gas; state `quote-only, signature and simulation absent`. If a second quote replaces the first, discard the earlier permit handoff. Do not use LI.FI's fractional slippage convention here.

## Sources and maintenance

Primary sources checked 2026-09-27. [Protocol recipes and sources](references/recipes.md) contain the concrete calls. Recheck deployments and API schemas before preparing financial actions; documentation access alone proves no live position or transaction.

Attribution

galleonlabsgalleonlabs
View sourceMore from galleonlabs →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Ultra-compressed communication mode that cuts output tokens while keeping technical accuracy. Levels: lite, full, ultra and the wenyan variants. Use for /caveman, "caveman mode", "talk like caveman", "be brief" or "less tokens".

1074701 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

695601 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3351 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

691 votes

math-skill

A comprehensive mathematical reasoning skill for AI assistants — handles arithmetic to research-level problems with rigorous step-by-step reasoning, systematic verification, and transparent uncertainty handling

381 votes
View all in ai-agents →