Skip to content
Back to skills

Erc20

ASecurity

Implement a standards-compliant ERC-20 token using OpenZeppelin with tests

  • 3 stars
  • 0 votes
  • 0 copies
  • 3 views
  • Added September 3, 2026
ai-agentsgo

Security analysis

A100/100

Scanned September 3, 2026

npx -y skills add black141312/ada --skill erc20 --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Erc20?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Erc20
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/black141312-erc20/badge)](https://www.skillsdirectory.com/skills/black141312-erc20)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: erc20
description: Implement a standards-compliant ERC-20 token using OpenZeppelin with tests
category: web3
---

# ERC-20 Token

Reach for this to ship a fungible token. Extend OpenZeppelin's audited base rather than implementing the standard by hand.

1. Inherit `ERC20` from OpenZeppelin and set name/symbol in the constructor; decimals default to 18 unless you override for a reason.
2. Decide supply policy: fixed (mint all in constructor) or mintable (`ERC20` + `Ownable`/`AccessControl` gating `mint`); add `ERC20Burnable` only if burning is intended.
3. Add only the extensions you need — `ERC20Permit` (EIP-2612 gasless approvals), `ERC20Pausable`, `ERC20Capped` — and avoid feature creep.
4. Wire access control: restrict `mint`/`pause` to roles, never leave them public.
5. Write tests covering transfer, `approve`/`transferFrom`, allowance edge cases, zero-address reverts, and supply invariants.
6. Deploy with a script that records the token address, then verify the source on the block explorer (Etherscan/Sourcify).

## Rules
- Do not reimplement transfer/allowance logic — inherit it; custom logic reintroduces known bugs.
- Be aware of the `approve` race; prefer `ERC20Permit` or increase/decrease-allowance patterns.
- Never override `decimals()` casually — wallets and integrators assume the value you publish.
- Gate `mint` and `pause`; an open mint function is an instant exploit.
- Don't add transfer fees/rebasing without warning — they break DEXes and many integrators.
- Account for decimals in every amount; mixing raw and human units is a common bug.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…