CtrlK
BlogDocsLog inGet started
Tessl Logo

meme-coin-audit

Meme coin and token security audit — rug pull detection (honeypot, hidden mint, fee manipulation, LP lock bypass), Solana SPL token analysis (freeze authority, mint authority, metadata mutability), Token-2022 extension risks (transfer hooks, permanent delegate), DEX liquidity pool attacks (sandwich amplification, LP drain, bonding curve exploits), pump.fun/Raydium/Jupiter integration risks, and real exploit examples from 2024-2025. Use for any token audit, rug pull assessment, meme coin security review, or pre-investment due diligence.

68

Quality

83%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

71%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A dense, highly actionable audit skill built around concrete grep sweeps, kill criteria, and on-chain checks with a clear triage-first workflow. Its main gaps are a monolithic single-file structure with no progressive disclosure and a Foundry PoC template that is partly placeholder rather than fully runnable.

Suggestions

Move the Foundry PoC template and the Operator Notes (2025-2026 specifics, MEV mitigations) into separate reference files under references/ and link to them from the body to improve progressive disclosure.

Complete the Foundry PoC template by replacing the '// ... buy tokens' and '// Assert token price crashed' placeholders with actual swap and assert calls so it is copy-paste runnable.

Tighten the Operator Notes prose (e.g., the MEV/sandwich narrative and the 'THE ONE RULE' blockquote) to remove explanatory padding Claude does not need.

DimensionReasoningScore

Conciseness

The body is mostly lean and command-oriented (grep patterns, 'Kill if' criteria, checklists), but the Operator Notes prose — the MEV/sandwich narrative and ranked mitigations, plus the 'THE ONE RULE' blockquote — could be trimmed, so it is efficient with minor over-explanation rather than fully lean.

4 / 5

Actionability

Eight sets of copy-paste grep commands and on-chain CLI commands (solana account, spl-token display) are fully executable, but the Foundry PoC template contains '// ... buy tokens on Uniswap' and '// Assert token price crashed' placeholders, leaving minor gaps below fully copy-paste-ready.

4 / 5

Workflow Clarity

A clear sequence runs from PRE-DIVE KILL SIGNALS through the 8 bug classes (each gated by 'Kill if:') to the FAST RED-FLAG SWEEP and on-chain checks, with validation gates ('If any are true, skip the audit', 'verify these out-of-band'). It falls short of a 5 because there are no explicit error-recovery feedback loops.

4 / 5

Progressive Disclosure

The body is well-sectioned and navigable, but it is a ~250-line monolith with no bundle files; the Foundry PoC template and Operator Notes are content that could live in separate reference files and is inlined rather than split, matching the 'could be better organized; content that should be separate is inline' anchor.

3 / 5

Total

15

/

20

Passed

Description

96%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A highly specific, trigger-rich description that explicitly covers both capabilities and use-when conditions across EVM and Solana meme coins. Its only weakness is the slightly broad 'any token audit' phrasing, which invites minor overlap with general web3 audit skills.

DimensionReasoningScore

Specificity

Lists multiple concrete actions across four sub-domains — 'rug pull detection (honeypot, hidden mint, fee manipulation, LP lock bypass)', 'Solana SPL token analysis (freeze authority, mint authority, metadata mutability)', 'Token-2022 extension risks (transfer hooks, permanent delegate)', 'DEX liquidity pool attacks' — plus 'real exploit examples from 2024-2025', giving comprehensive coverage rather than the minor gaps of a 4.

5 / 5

Completeness

Explicitly answers both what (the detailed capability list) and when ('Use for any token audit, rug pull assessment, meme coin security review, or pre-investment due diligence') with concrete trigger phrases, matching the 5 anchor exactly.

5 / 5

Trigger Term Quality

Natural user phrases and synonyms are well covered: 'token audit', 'rug pull assessment', 'rug pull detection', 'meme coin security review', 'pre-investment due diligence', plus platform names (pump.fun, Raydium, Jupiter). Comprehensive natural-term coverage rather than the few-missing of a 4.

5 / 5

Distinctiveness Conflict Risk

The meme-coin/rug-pull framing carves a clear niche with distinct triggers, but the broad 'Use for any token audit' creates minor overlap risk with a closely related web3-audit skill, so it is mostly distinct rather than fully minimal-conflict.

4 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
elementalsouls/Claude-BugHunter
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.