CtrlK
BlogDocsLog inGet started
Tessl Logo

tracking-token-launches

Track new token launches across DEXes with risk analysis and contract verification. Use when discovering new token launches, monitoring IDOs, or analyzing token contracts. Trigger with phrases like "track launches", "find new tokens", "new pairs on uniswap", "token risk analysis", or "monitor IDOs".

SKILL.md
Quality
Evals
Security
High

W007: Insecure credential handling detected in skill instructions.

What this means

The skill handles credentials insecurely by requiring the agent to include secret values verbatim in its generated output. This exposes credentials in the agent’s context and conversation history, creating a risk of data exfiltration.

Why it was flagged

The skill shows and encourages passing API keys and RPC URLs directly on the command line (e.g., --etherscan-key YOUR_KEY, --rpc-url), which requires including secret values verbatim in commands/outputs and is a high exfiltration risk.

Report incorrect finding
Low

W011: Third-party content exposure detected (indirect prompt injection risk).

What this means

The skill exposes the agent to untrusted, user-generated content from public third-party sources, creating a risk of indirect prompt injection. This includes browsing arbitrary URLs, reading social media posts or forum comments, and analyzing content from unknown websites.

Why it was flagged

Runtime path `scripts/event_monitor.py:get_recent_pairs()` ingests free-text-like data returned from `eth_getLogs` (on-chain event fields token name/symbol/bytecode-derived strings via later `eth_call` in `get_token_info()`), meaning an outsider can create poison by deploying tokens/pairs that then get scanned without selecting a specific item beyond normal chain/time monitoring.

Repository
jeremylongshore/tons-of-skills-marketplace
Audited
Security analysis
Snyk

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.