# Skylens Transaction Analysis

> Inspects one EVM transaction with Skylens APIs and returns human-readable trace, balance, storage, and nonce changes. Use when the user asks for tx-level investigation on supported chains (for example Ethereum) via `get-trace`, `balance-change`, `state-change`, or `nonce-change`.

- **Type:** Skill
- **Install:** `agentstack add skill-certikdev-skills-skylens`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [CertiKDev](https://agentstack.voostack.com/s/certikdev)
- **Installs:** 0
- **Category:** [Agent Skills](https://agentstack.voostack.com/c/agent-skills)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [CertiKDev](https://github.com/CertiKDev)
- **Source:** https://github.com/CertiKDev/skills/tree/main/skills/skylens
- **Website:** https://www.certik.com

## Install

```sh
agentstack add skill-certikdev-skills-skylens
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# Skylens Transaction Analysis

Use `{skillDir}/scripts/skylens.py` to inspect one transaction with Skylens APIs.

## When To Use This Skill

Use this skill when the user wants transaction-level investigation for a single EVM transaction on a supported chain. Typical triggers:

- The user provides a transaction hash and asks what happened.
- The user wants an execution trace or call flow for one transaction.
- The user asks which balances changed for a specific address in one transaction.
- The user asks which storage slots changed for a contract in one transaction.
- The user asks whether an address nonce changed in one transaction.
- The user wants contract source files tied to addresses touched by one transaction.

## Quick Triage Workflow

1. Run `get-trace` to identify key calls/contracts.
2. Run `list-source-files` for suspicious contract addresses to enumerate available files.
3. Run `get-source-file` with selected `--FILE_INDEX` (and optional `--OUTPUT`) to fetch source code.
4. Run `state-change` for suspicious contract addresses (storage deltas).
5. Run `nonce-change` for addresses that sent/triggered actions.
6. Run `balance-change` for holder asset impact.

## Commands

- `get-trace`: readable execution trace (paged)
- `balance-change`: balance deltas for one holder
- `state-change`: storage slot changes for one address
- `nonce-change`: nonce before/after for one address
- `list-source-files`: list contract source files (or AST-only files) by tx
- `get-source-file`: get one contract file by index from `list-source-files`

## Supported Chains

`eth`, `bsc`, `polygon`, `optimism`, `arb`, `base`, `blast`, `avalanche`, `scroll`, `linea`, `sonic`, `kaia`, `world`, `unichain`, `hyperliquid`, `plasma`

## Shared Parameter Rules

- `tx_hash`: full hash with `0x`
- `chain`: must be one of supported chains above
- `address` / `holder`: case-insensitive, accepts with or without `0x`

## `get-trace`

CLI:

`{skillDir}/scripts/skylens.py get-trace --TX  --CHAIN  --OFFSET 0 --SIZE 100`

Output:

- Prints one readable trace line per event.
- Prints only `[offset, offset+size)`.

Output format:

`{index}({depth}) {op} {description} [source: ...]`

Source suffix (optional):

`source: [c: {contractAddress}, f:{fileIdx}, s:{start}, o:{length}]`

Current event variants:

- `callEvent`
- `createEvent`
- `storageAccessEvent`
- `logEvent`
- `keccak256Event`

## `balance-change`

CLI:

`{skillDir}/scripts/skylens.py balance-change --TX  --CHAIN  --HOLDER `

Output:

- Prints balance deltas for the target `holder`.
- May include native/token/NFT sections when available.

Printed shapes:

- `BalanceOf Native ETH: holder=... before=... after=... delta=...`
- `BalanceOf Token: token=... holder=... before=... after=... delta=...`
- `BalanceOf NFT: collection=... holder=... before=... after=... delta=...`

## `state-change`

CLI:

`{skillDir}/scripts/skylens.py state-change --TX  --CHAIN  --ADDRESS `

Output:

- Prints storage changes for the target `address` only.

Printed shape:

`Storage: address=... slot=0x... before=... after=...`

## `nonce-change`

CLI:

`{skillDir}/scripts/skylens.py nonce-change --TX  --CHAIN  --ADDRESS `

Output:

- Prints nonce before/after for the target `address`.

Printed shape:

`Nonce: address=... before=... after=...`

## `list-source-files`

CLI:

`{skillDir}/scripts/skylens.py list-source-files --TX  --CHAIN  --ADDRESS `

Output:

- Lists source files for the target contract.
- Includes file indexes used by `get-source-file`.

Printed shape:

- `Contract: ...`
- `Files: ...`
- `[index] fileName (artifact=..., available=source|none)`

## `get-source-file`

CLI:

`{skillDir}/scripts/skylens.py get-source-file --TX  --CHAIN  --ADDRESS  --FILE_INDEX  [--OUTPUT ]`

Output:

- Returns source content for one selected file index.
- If `--OUTPUT` is provided, saves source content to that path.

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [CertiKDev](https://github.com/CertiKDev)
- **Source:** [CertiKDev/skills](https://github.com/CertiKDev/skills)
- **License:** MIT
- **Homepage:** https://www.certik.com

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-certikdev-skills-skylens
- Seller: https://agentstack.voostack.com/s/certikdev
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
