Skip to content
Back to skills

Chainlink

ASecurity

Assist with Chainlink LINK tokens, oracle integrations, staking, and price feed usage.

  • 17 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 6, 2026
developmentrustgonodegitapisecuritydocumentation

Works with

  • api

Security analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned September 6, 2026

npx -y skills add clawic/skills --skill chainlink --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Chainlink?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Chainlink
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/clawic-chainlink/badge)](https://www.skillsdirectory.com/skills/clawic-chainlink)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: Chainlink
slug: chainlink
version: 1.0.0
description: Assist with Chainlink LINK tokens, oracle integrations, staking, and price feed usage.
homepage: https://clawic.com/skills/chainlink
metadata:
  clawdbot:
    emoji: ⬡
    os:
    - linux
    - darwin
    - win32
    displayName: Chainlink
---

## LINK Token Basics
- LINK is an ERC-20 token on Ethereum — standard wallet and exchange support
- Also available on multiple chains — Arbitrum, Optimism, Polygon, Avalanche, BSC
- Bridging LINK between chains uses official Chainlink bridge — verify bridge address before using
- Different chains have different LINK contract addresses — verify correct address per network

## Token Transfers
- Standard ERC-20 transfer rules apply — gas paid in native token (ETH, MATIC, etc.)
- Some DeFi protocols accept LINK as collateral — Aave, Compound
- LINK has no special transfer restrictions — no tax tokens, no rebasing
- Decimals: 18 — same as ETH, standard precision

## Staking (v0.2)
- Community staking allows LINK holders to stake — earn rewards for securing network
- Staking has capacity limits — pool may be full, waitlist exists
- Unbonding period applies — can't withdraw instantly after unstaking
- Rewards in LINK — automatically added to staked balance
- Slashing risk exists — node operators can lose stake for misbehavior

## Price Feeds (For Developers)
- Chainlink price feeds are the standard for DeFi — Aave, Synthetix, and most protocols use them
- Feed addresses differ per network and pair — always verify on docs.chain.link
- Feeds update based on deviation threshold and heartbeat — not every block
- Check `latestRoundData()` not just `latestAnswer()` — includes timestamp and round info
- Stale data check critical — verify `updatedAt` timestamp is recent

## Oracle Integration Patterns
- Direct consumer: your contract calls feed directly — simplest approach
- Chainlink Automation (Keepers): trigger actions based on conditions — no server needed
- VRF (Verifiable Random Function): provably fair randomness — for NFT mints, games, lotteries
- Functions: connect to any API — custom off-chain computation
- CCIP: cross-chain messaging — official Chainlink interoperability protocol

## VRF Usage
- Request/receive pattern: request randomness, receive in callback — not synchronous
- Each request costs LINK — fund subscription or pay per request
- Confirmation blocks add security but delay — more confirmations = more secure
- Randomness is verifiable on-chain — anyone can verify it wasn't manipulated

## Common Developer Mistakes
- Hardcoding feed addresses — use address registry or config
- Not checking for stale data — price feeds can stop updating
- Assuming instant updates — deviation thresholds mean prices can be slightly stale
- Not handling VRF callback failures — callback can revert, losing the randomness
- Insufficient LINK for subscriptions — requests fail silently when underfunded

## Network Comparisons
- Ethereum mainnet: highest security, highest gas costs
- L2s (Arbitrum, Optimism): lower cost, same security model
- Alt-L1s (Polygon, Avalanche): native integration, different trust assumptions
- Testnets: Sepolia for Ethereum, network-specific for others

## Security Considerations
- Only use official Chainlink feeds — verify contract addresses on docs.chain.link
- Monitor for feed deprecation — Chainlink announces deprecated feeds
- Multi-oracle pattern for critical systems — don't rely on single source
- Circuit breakers for extreme price movements — protect against oracle manipulation

## CCIP (Cross-Chain)
- Send messages and tokens across chains — official Chainlink bridge
- Lane availability varies — not all chain pairs supported
- Fee estimation before sending — paid in LINK or native token
- Message finality depends on source and destination chains

## Ecosystem
- Node operators earn LINK for providing data — professional infrastructure required
- BUILD program for projects integrating Chainlink — access to resources and support
- Extensive documentation at docs.chain.link — primary reference for developers
- Community resources: Discord, Stack Overflow, GitHub

Files in this skill

  • SKILL.md4.1 KB
  • _meta.json170 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…