alchemy
github/BankrBot/skills#alchemy
litmus-skill-v2 · 2026-06-25
graded at commit 65e9a9e · 2026-06-17
The alchemy skill is graded A by polygraph under litmus-skill-v2, as of 2026-06-25, anchored to its content hash.
Self-reported “Blockchain API access via Alchemy. Use when an agent needs to query blockchain data (balances, token prices, NFT ownership, transfer history, transaction simulation, gas estimates) across Ethereum, Base, Arbitrum, BNB, Polygon, Solana, and more. Supports API key access…” — the skill’s own SKILL.md description at the graded commit, not part of the grade.
A static safety grade — a deterministic scan of the skill’s SKILL.md and bundled files. An A means static-clean, not behavioral proof: a skill’s instructions are interpreted by an agent at runtime.
no bundled executable scripts
content hash · 0xb4a0b312b6…93ff
Source · github.com/BankrBot/skills/tree/main/alchemy
Watch for changes
This grade is a snapshot of the skill’s files at one commit. Get an email when a new commit changes alchemy and polygraph re-runs the litmus — one message per change, one-click unsubscribe.
Monitor this skillReproduce this grade
The skill litmus is open and deterministic. Point it at the skill directory and compare the grade and content hash — a false grade is falsifiable, not merely disputable.
npx -p @polygraphso/litmus polygraphso-litmus-skill <skill-dir>Embed this badge
Drop it in the skill’s README, docs, or listing. It always shows the current grade and links back here.
[](https://www.polygraph.so/skill/github/BankrBot/skills/alchemy)<a href="https://www.polygraph.so/skill/github/BankrBot/skills/alchemy"><img src="https://www.polygraph.so/api/badge/skill?skill=github/BankrBot/skills/alchemy" alt="polygraph grade"></a>[](https://www.polygraph.so/skill/github/BankrBot/skills/alchemy)Questions
- What does the A skill grade mean for alchemy?
- It’s a static safety grade(A/B/D/F) from a deterministic scan of the skill’s
SKILL.mdand bundled files. An A means static-clean — not behavioral proof, since a skill’s instructions are interpreted by an agent at runtime. - What did polygraph check?
- Three static checks: S-01 prompt-injection and context-poisoning, S-03 data-exfiltration instructions, and S-04 dangerous bundled commands. The full battery is in the methodology.
- How do I reproduce this grade?
- Run
npx -p @polygraphso/litmus polygraphso-litmus-skill <skill-dir>. The scan is open and deterministic, anchored to the skill’s content hash, so the same directory yields the same grade.