Web3 Marketing & GTM

Security checks across static analysis, malware telemetry, and agentic risk

Overview

This is a benign instruction-only marketing template, with the main caution that its generated plans may suggest wallet-activity tracking and human-like community outreach.

Safe to install as an instruction-only marketing skill. Before using its output publicly, review any wallet-address collection, on-chain user segmentation, or targeted outreach recommendations for privacy, consent, and brand suitability.

Static analysis

No static analysis findings were reported for this release.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Risk analysis

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

Generated strategies may encourage tracking wallet behavior or contacting users based on wallet activity, which can affect user privacy if implemented without clear consent and data limits.

Why it was flagged

The retention playbook recommends building user segments from wallet/on-chain activity and using those segments for outreach. This is aligned with the Web3 retention purpose, but it involves behavioral profiling that should be handled carefully.

Skill content
Segment all users into 4 tiers based on on-chain behavior... Discord DM / Telegram message... Targeted Telegram message to dormant segment
Recommendation

Review retention plans before acting on them, minimize wallet-level tracking, avoid unnecessary public collection of wallet addresses, and follow privacy and platform rules for outreach.

What this means

Public posts or community messages generated from the templates could be perceived as personally written by a human team member.

Why it was flagged

The skill asks for human-like community copy. This is common for marketing content and is not paired with impersonation or automation, but it could blur AI-authorship expectations if published without review.

Skill content
Scripts must feel human-written, not bot-generated.
Recommendation

Manually review generated copy before publishing and disclose AI assistance where appropriate for the community or platform.