Track new token launches across DEXes with risk analysis and contract verification. Use when discovering new token launches, monitoring IDOs, or analyzing token contracts. Trigger with phrases like "track launches", "find new tokens", "new pairs on uniswap", "token risk analysis", or "monitor IDOs".
The skill handles credentials insecurely by requiring the agent to include secret values verbatim in its generated output. This exposes credentials in the agent’s context and conversation history, creating a risk of data exfiltration.
The skill shows and encourages passing API keys and RPC URLs directly on the command line (e.g., --etherscan-key YOUR_KEY, --rpc-url), which requires including secret values verbatim in commands/outputs and is a high exfiltration risk.
The skill exposes the agent to untrusted, user-generated content from public third-party sources, creating a risk of indirect prompt injection. This includes browsing arbitrary URLs, reading social media posts or forum comments, and analyzing content from unknown websites.
Runtime path `scripts/event_monitor.py:get_recent_pairs()` ingests free-text-like data returned from `eth_getLogs` (on-chain event fields token name/symbol/bytecode-derived strings via later `eth_call` in `get_token_info()`), meaning an outsider can create poison by deploying tokens/pairs that then get scanned without selecting a specific item beyond normal chain/time monitoring.
88dcf65
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.