Skills boost
๐Ÿ“ฆ

boost

Content revision r1 Medium Risk โš™๏ธ External commands๐ŸŒ Network access๐Ÿ”‘ Env variables

Reduce RPC Provider Calls with Goldsky Boost

Historical blockchain reads can increase RPC provider costs. This skill guides Goldsky Boost setup and cache troubleshooting while keeping your existing upstream provider.

Supports: Claude Codex Code(CC)
๐Ÿ“Š 70 Adequate

Install with my Agent

Copy this request to your Agent. It includes the canonical Skill page and manifest.

Agent request
Review the Skillstore skill "boost" from https://skillstore.io/skills/goldsky-io-boost.md and its manifest at https://skillstore.io/api/skills/goldsky-io-boost/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.

Your Agent should still show its plan and request any confirmation required by the security policy.

Agent-readable resources

Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.

Test it

Using "boost". Why do log queries ending at latest always miss the cache?

Expected outcome:

  • Block tags always forward to your upstream provider.
  • For a fixed historical range, use concrete hexadecimal block heights for both bounds.
  • Repeat the request and inspect cache headers; eligible data can still forward when unavailable.

Using "boost". My receipt batch has 200 items and reports MISS. Is caching broken?

Expected outcome:

  • Batches over 100 items forward without CDN lookups.
  • Split requests into batches of at most 100 items and assign unique request identifiers.
  • A mixed batch reports MISS even when some items are served; inspect x-edge-billable for the served-item count.

Using "boost". Does an organization verification error stop our existing Boost traffic?

Expected outcome:

  • The documented verification gate applies to configuration changes, not existing request serving.
  • Check organization eligibility or contact Goldsky support with your team identifier.
  • Do not share API keys or provider credentials in chat.

Security Audit

Medium Risk
v1 โ€ข 9/28/2026 Open versioned report

All 104 static findings are false positives involving Markdown formatting, intended service URLs, credential placeholders, or provider setup documentation. One semantic finding concerns authentication secrets supplied through CLI arguments, which can expose them locally. No evidence found of prompt injection, malicious execution, or unauthorized exfiltration in the reviewed files.

3
Files scanned
323
Lines analyzed
0
Review items
0
False positives ignored

Confirmed security concerns (1)

Medium
Provider Credentials Exposed Through CLI Arguments
The guide recommends 'provider add --header k:v' for a persistent provider credential. Substituting secrets into command arguments can expose them through shell history and process listings.
Line 220 explicitly recommends CLI header arguments for credentials, while the interactive-input safeguard on line 174 covers only provider connect. Actual exposure depends on execution and host controls.
Audited by: codex
Share & cite this report

Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.

Open versioned report
Security Assessment

Copy report link

https://skillstore.io/skills/goldsky-io-boost/audits/1?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/goldsky-io-boost/security.svg)](https://skillstore.io/skills/goldsky-io-boost?utm_source=security_passport_badge)

HTML badge

<a href="https://skillstore.io/skills/goldsky-io-boost?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/goldsky-io-boost/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Embed card

<iframe src="https://skillstore.io/embed/skills/goldsky-io-boost.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Academic citations (APA ยท BibTeX ยท CFF)

APA citation

goldsky-io. (2026). boost security audit report (audit version 1) [Author version unspecified]. Skillstore. https://skillstore.io/skills/goldsky-io-boost/audits/1

BibTeX citation

@techreport{goldsky-io-goldsky-io-boost-2026, author = {goldsky-io}, title = {boost security audit report (audit version 1)}, institution = {Skillstore}, year = {2026}, number = {1}, url = {https://skillstore.io/skills/goldsky-io-boost/audits/1}, note = {Author version unspecified} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "boost security audit report (audit version 1)" version: "unspecified" type: report authors: - name: "goldsky-io" date-released: "2026-09-28" url: "https://skillstore.io/skills/goldsky-io-boost/audits/1" identifiers: - type: other value: "skillstore:goldsky-io-boost:audit:1" description: "Skillstore immutable audit report identifier"

Skillstore Score

Why this score Evidence Confidence: Medium
55
Architecture
85
Maintainability
87
Content
65
Community
91
Spec Compliance

What You Can Build

Reduce Historical Indexing Requests

Plan Boost adoption for Ethereum or Base backfills, using concrete block ranges while retaining an existing provider.

Investigate Cache Misses

Review cache headers, request history, and batch sizes to explain forwarding and identify eligible historical reads.

Connect an Application

Adapt a viem transport and understand authentication, verification, and HTTP subscription boundaries before deployment.

Try These Prompts

Understand Boost
Explain whether Goldsky Boost fits our historical Ethereum reads. We want to keep our current RPC provider. Describe prerequisites and limitations.
Plan Provider Setup
Plan Boost setup with QuickNode on Ethereum and Base. Use interactive credential entry, check verification requirements, and request approval before account changes.
Diagnose Forwarded Requests
Our eth_getLogs requests end at latest, and receipt batches contain 200 items. Explain the MISS responses and propose a read-only verification plan.
Review a Production Change
Plan a Boost upstream credential rotation with validation, explicit activation, and rollback. Keep secrets out of chat and command arguments. Require approval before mutations.

Best Practices

  • Check current CLI help and supported chains before planning changes, and validate the selected upstream against the intended chain.
  • Use concrete historical block heights, keep batches within 100 items, and interpret served-item counts alongside cache headers.
  • Keep secrets out of chat, logs, and command arguments; use supported secure credential entry and confirm account changes before execution.

Avoid

  • Expecting block tags, state calls, or batches over 100 items to receive CDN caching.
  • Treating one MISS response or a mixed-batch MISS as proof that Boost cannot serve historical data.
  • Pasting credentials into chat or treating provider removal and disconnection as harmless diagnostic steps.

Frequently Asked Questions

Does Boost replace my existing RPC provider?
No. Boost serves eligible reads and forwards other requests to your configured provider. Goldsky Edge is the separate managed RPC product.
Does Boost guarantee lower bills?
No. The guide describes Boost as free, but savings depend on served requests, provider pricing, and workload eligibility.
Why does eth_getLogs still forward?
Block-tag bounds always forward. Concrete bounds or a block hash enable eligibility, but unavailable data still forwards.
Can I use WebSocket subscriptions?
No. Boost is HTTP-only. Keep WebSocket subscriptions connected directly to your provider.
Do I need a verified organization?
The guide requires verification for enabling Boost and most configuration changes. Reading configuration and serving existing traffic do not require verification.
How should I provide credentials?
Never paste credentials into chat. Use the interactive prompt for provider connect and a supported secure input method for other secrets.

Developer Details

Author

goldsky-io

License

MIT

Skillstore revision

r1

Version notice

The author did not declare a version.

Ref

8b5ad1599e7c55e9b6c627bca3f556f6e9061cb1

Maintenance freshness

9/30/2026

Usage

0 downloads ยท 0 views

File structure

๐Ÿ“ evals/

๐Ÿ“„ evals.json

๐Ÿ“„ trigger-eval.json

๐Ÿ“„ SKILL.md

More from goldsky-io

View all
View all