Back to skill

Security audit

web3-protocol-gtm

Security checks for vulnerabilities and agentic risk

Overview

This Markdown-only web3 GTM skill has no local execution or persistence behavior, but its token-launch guidance includes tactics that can help engineer misleading market and social signals.

Install only if you want broad web3 go-to-market reference material and will apply independent legal, compliance, and ethics review to token-launch or crypto-payment advice. Do not rely on this skill for market-making, token promotion, KOL campaigns, or serving restricted jurisdictions without clear disclosures and jurisdiction-specific counsel.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

other

Error
Location
references/token-launch-playbook.md:153
Finding
Coordinated Token Market and Social-Signal Manipulation Guidance<![CDATA[ ## Vulnerability Details **File Location**: `references/token-launch-playbook.md:153-167, 340-342, 396, 474, 520, 541`; propagated in `SKILL.md:477` **Vulnerability Type**: Guidance facilitating artificial market activity and misleading promotional signals **Risk Level**: High ### Vulnerable Content ```text references/token-launch-playbook.md:153 ACTION: Generate visible trading activity references/token-launch-playbook.md:167 - [ ] Hit 300+ holders in first hour (social proof) references/token-launch-playbook.md:340-342 - Pre-arrange 5-10 KOLs to post within 2-4 hours (staggered) - Core community ready with 20-30 meme variations - Goal: "everyone's talking about this" atmosphere within 24 hours references/token-launch-playbook.md:396 - [ ] Begin coordinated KOL push references/token-launch-playbook.md:474 - Buy 20-50% of own supply at launch (10% minimum for eligibility) references/token-launch-playbook.md:520 - Creator buys 20-50% at launch for team/development reserve references/token-launch-playbook.md:541 concentrated buying in few transactions. SKILL.md:477 Post-graduation on PumpSwap, you have 30 minutes before the token lives or dies. Add your own LP at minute 0-5. Ensure visible trading activity by minute 5-15. Be active on all channels by minute 15-30. Lock LP tokens for 6-12+ months. Revoke mint and freeze authority immediately. ``` ### Technical Analysis The playbook combines several tactics that can manufacture or exaggerate the appearance of independent token demand: 1. A creator is advised to acquire 20–50% of the token supply. 2. The creator is instructed to generate visible trading activity immediately after launch. 3. A target holder count is presented as social proof without requiring that the holders be independent or organically acquired. 4. Influencers are coordinated through staggered posts to create an “everyone's talking about this” atmosphere. 5. Concentrated early buying is identified as a desirable survival sign ...[truncated 2313 chars]
Remediation
<![CDATA[ ## Remediation Suggestions 1. Remove all instructions to “generate” visible trading activity or engineer holder-count targets. 2. Explicitly prohibit: - Wash trading and self-trading. - Coordinated trades intended to fabricate volume or price momentum. - Undisclosed market-making or price support. - Sybil wallets used to inflate holder counts. - Fabricated social proof or promotion presented as organic interest. 3. Replace the 20–50% creator-purchase recommendation with a transparent allocation framework: - Publish all team and treasury allocations before launch. - Use enforceable vesting schedules and long-term locks. - Identify related wallets and beneficial owners. - Obtain independent tokenomics and legal review. 4. Restrict launch guidance to legitimate liquidity provisioning: - Document the source and ownership of liquidity. - Disclose creator-provided liquidity prominently. - Use auditable lock contracts. - Avoid creator-controlled transactions that simulate outside demand. 5. Require clear and conspicuous disclosure for every compensated KOL or ambassador post, including the compensation arrangement and the promoter's token position. 6. Replace the goal of creating an “everyone's talking about this” atmosphere with accurate, non-deceptive communications based on verifiable product milestones. 7. Add a compliance checkpoint requiring jurisdiction-specific legal review before token creation, distribution, promotion, market making, or buyback activity. 8. Add monitoring and recordkeeping controls so all launch trades, related wallets, promoter agreements, disclosures, and liquidity changes are auditable. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Missing User Warnings

High
Confidence
96% confidence
Finding
This section gives operational guidance to manufacture visible market activity around a newly launched token, including adding liquidity immediately and generating trading activity during a fragile price-discovery window. In a web3 go-to-market skill, that context makes the advice more dangerous because it can directly facilitate manipulative launch behavior, mislead buyers about genuine demand, and expose users to legal, financial, and reputational harm.

Anti-Refusal Statement

High
Category
Anti-Refusal
Content
- [ ] Hit 300+ holders in first hour (social proof)
- [ ] Tweet about graduation with chart screenshot
- [ ] Be active in Telegram/community channels
- [ ] Respond to every question immediately
- [ ] Lock LP tokens for 6-12+ months
- [ ] Revoke mint authority and freeze authority
```
Confidence
60% confidence
Finding
Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.

Missing User Warnings

High
Confidence
98% confidence
Finding
The 'coordinated push' section explicitly aims to create an 'everyone's talking about this' atmosphere through pre-arranged KOL posting and meme deployment, which can simulate organic market interest. In token-launch context, this is especially risky because it can function as undisclosed promotion or manipulative hype, causing retail users to trade on distorted signals.

Missing User Warnings

High
Confidence
97% confidence
Finding
Recommending that creators buy 20-50% of their own supply at launch can enable price support, float constriction, and misleading signals about external demand if not accompanied by strong warnings and disclosure requirements. In this skill's token-launch setting, the advice is particularly dangerous because solo builders may copy it as a growth tactic without understanding manipulation, disclosure, liquidity, and holder-loss risks.

Natural-Language Policy Violations

Medium
Confidence
97% confidence
Finding
The document explicitly identifies 'users in sanctioned regions' and businesses that 'never touch banks' as target customers who 'NEED crypto rails,' without any compliance limitation, legal warning, or refusal condition. In skill context, this can steer operators toward facilitating sanctions evasion or servicing high-risk prohibited categories, creating legal, regulatory, and abuse-enablement risk.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The phrase "24/7 answers in all languages" sets a blanket language/locale expectation in the skill content without indicating user choice, opt-in, or any limits. This can conflict with organizational language-policy requirements because it prescribes multilingual behavior rather than offering language selection or documenting a justified locale scope.

Scope Creep

Low
Category
Excessive Agency
Content
permissions granted by this License.

"Source" form shall mean the preferred form for making modifications,
including but not limited to software source code, documentation source, and
configuration files.

"Object" form shall mean any form resulting from mechanical transformation or
Confidence
70% confidence
Finding
Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Scope Creep

Low
Category
Excessive Agency
Content
permissions granted by this License.

"Source" form shall mean the preferred form for making modifications,
including but not limited to software source code, documentation source, and
configuration files.

"Object" form shall mean any form resulting from mechanical transformation or
Confidence
70% confidence
Finding
Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Scope Creep

Low
Category
Excessive Agency
Content
permissions granted by this License.

"Source" form shall mean the preferred form for making modifications,
including but not limited to software source code, documentation source, and
configuration files.

"Object" form shall mean any form resulting from mechanical transformation or
Confidence
70% confidence
Finding
Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Scope Creep

Low
Category
Excessive Agency
Content
permissions granted by this License.

"Source" form shall mean the preferred form for making modifications,
including but not limited to software source code, documentation source, and
configuration files.

"Object" form shall mean any form resulting from mechanical transformation or
Confidence
70% confidence
Finding
Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Vague Triggers

Low
Confidence
84% confidence
Finding
The 'When to Use This Reference' section describes applicability in general terms such as charging end users directly and needing landing page conversion, but it does not define explicit trigger phrases or exclusion examples for activation. In a skill-routing context, this broad natural-language scope could overlap with many general product, payments, or GTM requests and cause unintended invocation.

Static analysis

No suspicious patterns detected.