Skip to content
Back to skills

Yellow Best Practices

ASecurity

Yellow Network and Nitrolite (ERC-7824) development best practices for building state channel applications. Use when building apps with Yellow SDK, implementing state channels, connecting to ClearNodes, managing off-chain transactions, or working with application sessions.

  • 207 stars
  • 0 votes
  • 0 copies
  • 3 views
  • Added February 7, 2026
developmentjavascriptgojavabashnodegitsecurityperformancedocumentation

Works with

  • cli

Security analysis

A96/100
  • mediumInstalls packages at runtime which could introduce malicious dependencies

Pro scans all 9 files and shows the line behind each finding

Scanned February 12, 2026

npx -y skills add NeverSight/skills_feed --skill yellow-best-practices --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Yellow Best Practices?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Yellow Best Practices
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/neversight-yellow-best-practices/badge)](https://www.skillsdirectory.com/skills/neversight-yellow-best-practices)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: yellow-best-practices
description: Yellow Network and Nitrolite (ERC-7824) development best practices for building state channel applications. Use when building apps with Yellow SDK, implementing state channels, connecting to ClearNodes, managing off-chain transactions, or working with application sessions.
---

# Yellow Network & Nitrolite Best Practices

Guidelines for building high-performance decentralized applications using Yellow Network's state channel infrastructure and the Nitrolite SDK (ERC-7824).

## Quick Start

```bash
npm install @erc7824/nitrolite
```

**ClearNode WebSocket URL**: `wss://clearnet.yellow.com/ws`

## Core Concepts

### What is Yellow Network?

Yellow Network is a decentralized clearing and settlement network that connects brokers, exchanges, and applications across multiple blockchains using state channels. Key features:

- **Chain Abstraction**: Unified balance across multiple chains
- **Off-chain Processing**: Up to 100,000 transactions per second
- **Non-custodial**: User funds are governed by smart contracts
- **ERC-7824 Protocol**: Challenge-dispute mechanism for fund recovery

### Architecture

```
┌─────────────────┐     ┌─────────────────┐
│   Your App      │────▶│   ClearNode     │
│  (Nitrolite SDK)│◀────│   (Broker)      │
└─────────────────┘     └─────────────────┘
        │                       │
        └───────────┬───────────┘
                    ▼
            ┌───────────────┐
            │  Blockchain   │
            │  (Settlement) │
            └───────────────┘
```

## Rules by Category

For detailed rules, see the `rules/` directory:

- [01-connection.md](rules/01-connection.md) - ClearNode connection patterns (Critical)
- [02-authentication.md](rules/02-authentication.md) - Authentication flow (Critical)
- [03-app-sessions.md](rules/03-app-sessions.md) - Application session management (High)
- [04-state-management.md](rules/04-state-management.md) - State and balance management (High)
- [05-security.md](rules/05-security.md) - Security best practices (Critical)
- [06-error-handling.md](rules/06-error-handling.md) - Error handling patterns (Medium)

## Essential Patterns

### 1. ClearNode Connection

Always implement reconnection logic with exponential backoff:

```javascript
class ClearNodeConnection {
  constructor(url) {
    this.url = url;
    this.reconnectAttempts = 0;
    this.maxReconnectAttempts = 5;
    this.reconnectInterval = 3000;
  }

  connect() {
    this.ws = new WebSocket(this.url);
    this.ws.onopen = () => {
      this.reconnectAttempts = 0;
      // Proceed with authentication
    };
    this.ws.onclose = () => this.attemptReconnect();
  }

  attemptReconnect() {
    if (this.reconnectAttempts >= this.maxReconnectAttempts) return;
    this.reconnectAttempts++;
    const delay = this.reconnectInterval * Math.pow(2, this.reconnectAttempts - 1);
    setTimeout(() => this.connect(), delay);
  }
}
```

### 2. Authentication Flow

Use EIP-712 structured data signatures:

```javascript
import {
  createAuthRequestMessage,
  createAuthVerifyMessage,
  createEIP712AuthMessageSigner,
  parseRPCResponse,
  RPCMethod,
} from '@erc7824/nitrolite';

// 1. Send auth_request
const authRequest = await createAuthRequestMessage({
  address: walletAddress,
  session_key: signerAddress,
  application: 'YourAppDomain',
  expires_at: (Math.floor(Date.now() / 1000) + 3600).toString(),
  scope: 'console',
  allowances: [],
});

// 2. Handle auth_challenge and send auth_verify
// 3. Store JWT token for reconnection
```

### 3. Message Signing

Sign plain JSON payloads (NOT EIP-191):

```javascript
const messageSigner = async (payload) => {
  const wallet = new ethers.Wallet(privateKey);
  const messageBytes = ethers.utils.arrayify(
    ethers.utils.id(JSON.stringify(payload))
  );
  const flatSignature = await wallet._signingKey().signDigest(messageBytes);
  return ethers.utils.joinSignature(flatSignature);
};
```

### 4. Application Sessions

```javascript
import { createAppSessionMessage } from '@erc7824/nitrolite';

const appDefinition = {
  protocol: 'nitroliterpc',
  participants: [participantA, participantB],
  weights: [100, 0],
  quorum: 100,
  challenge: 0,
  nonce: Date.now(),
};

const allocations = [
  { participant: participantA, asset: 'usdc', amount: '1000000' },
  { participant: participantB, asset: 'usdc', amount: '0' },
];

const message = await createAppSessionMessage(signer, [{
  definition: appDefinition,
  allocations,
}]);
```

## Critical Rules

### DO

1. **Always use `wss://`** - Never use unencrypted WebSocket connections
2. **Implement timeouts** - Add timeouts to all async operations (10-30 seconds)
3. **Store JWT tokens** - Reuse tokens for reconnection instead of re-authenticating
4. **Clean up listeners** - Remove message event listeners to prevent memory leaks
5. **Verify signatures** - Always verify received message signatures
6. **Use session keys** - Generate temporary keys for signing, not main wallet keys

### DON'T

1. **Don't expose private keys** - Never hardcode or log private keys
2. **Don't skip error handling** - Always handle WebSocket errors and auth failures
3. **Don't ignore timeouts** - Implement proper timeout handling for all operations
4. **Don't use EIP-191 prefix** - Sign plain JSON, not prefixed messages
5. **Don't forget to close sessions** - Always properly close app sessions when done

## SDK Components

| Component | Purpose |
|-----------|---------|
| `NitroliteRPC` | Message construction and signing |
| `NitroliteClient` | High-level channel management |
| `createAuthRequestMessage` | Auth request creation |
| `createAuthVerifyMessage` | Challenge response |
| `createAppSessionMessage` | App session creation |
| `createCloseAppSessionMessage` | Session closure |
| `createGetLedgerBalancesMessage` | Balance queries |
| `parseRPCResponse` | Response parsing |

## Additional Resources

- [Full LLM Documentation](https://erc7824.org/llms-full.txt)
- [Yellow Network Docs](https://docs.yellow.org/)
- [ERC-7824 Quick Start](https://erc7824.org/quick_start)
- [Nitrolite GitHub](https://github.com/erc7824/nitrolite)

Files in this skill

  • SKILL.md6.3 KB
  • description_cn.txt235 B
  • description_de.txt335 B
  • description_en.txt274 B
  • description_es.txt307 B
  • description_fr.txt362 B
  • description_ja.txt445 B
  • description_ko.txt330 B
  • description_tw.txt235 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…