Agent skill

Meme Coin Security Audit

by awarexone in awarexone/Agentic-Bug-Hunter

Screens EVM and Solana meme coins for rug pull signs such as hidden mint, honeypot logic and fee tricks, starting with fast kill signals before any code review.

MITAuto-check passedSecurity

Install Meme Coin Security Audit

skills CLI
$ npx skills add awarexone/Agentic-Bug-Hunter --skill meme-coin-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install awarexone/Agentic-Bug-Hunter meme-coin-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/awarexone/Agentic-Bug-Hunter.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/meme-coin-audit .claude/skills/meme-coin-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
meme-coin-audit
GitHub stars
5.3k
Used in
1 other repo
Token cost
~2.4k tokens
SKILL.md length
556 words
Files
1
Skills in repo
10
Repo updated
First seen
Licence
MIT

At a glance

Screens EVM and Solana meme coins for rug pull signs such as hidden mint, honeypot logic and fee tricks, starting with fast kill signals before any code review.

  • Works in 8 steps: HIDDEN MINT / UNLIMITED SUPPLY → HONEYPOT / TRANSFER RESTRICTION → FEE MANIPULATION → …
  • Assessing a new meme coin for rug pull risk before putting money in
  • SKILL.md covers PRE-DIVE KILL SIGNALS, THE ONE RULE, BUG CLASSES (8 TOKEN-SPECIFIC) and AUTOMATED SCANNER, plus 3 more sections
  • Calls python3

What it does

The audit begins with conditions that rule a token out before any source is read: an unverified contract, a deployer with a history of rug pulls, a brand-new token with no known team, or a Solana mint or freeze authority that was never given up. Softer warnings include one holder with more than 20% of supply, liquidity that is neither burned nor locked, an upgradeable contract with an admin, thin liquidity and an anonymous deployer.

Its guiding rule is that the retained authority is the rug vector, so the agent hunts for every privileged operation: mint, blacklist, fee change, liquidity removal. It then works through token-specific bug classes, beginning with hidden mint and unlimited supply, honeypots and transfer restrictions, and fee manipulation, using grep patterns for Solidity and Rust sources. The description also lists Token-2022 extension risks, DEX pool attacks and a `token_scanner.py` helper, though the excerpt shown covers only the first three classes.

When your agent uses it

  • Assessing a new meme coin for rug pull risk before putting money in
  • Reviewing a Solana SPL token's mint, freeze and metadata authorities
  • Auditing token contract source for hidden mint functions or sell restrictions
  • Checking Token-2022 extensions such as transfer hooks and permanent delegates

Example prompts

  • “Is this token contract on Etherscan safe? Look for a hidden mint or a blacklist.”
  • “Check the mint and freeze authority on this Solana SPL token before I buy.”
  • “Grep the Solidity source in ./token/src for ways the deployer could raise the sell fee.”
  • “Run a rug pull assessment on this pump.fun launch.”

Requirements

  • Token contract source code, such as Solidity or Rust files

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. HIDDEN MINT / UNLIMITED SUPPLY
  2. HONEYPOT / TRANSFER RESTRICTION
  3. FEE MANIPULATION
  4. LIQUIDITY POOL DRAIN
  5. BONDING CURVE MANIPULATION
  6. AUTHORITY RETENTION (SOLANA)
  7. FAKE RENOUNCE / HIDDEN OWNERSHIP
  8. SANDWICH AMPLIFICATION BY DESIGN

What it can do on your machine

Read from SKILL.md and the folder at commit 40b03ee. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Meme Coin Security Audit loads about 2.4k tokens when it runs. Until then it costs about 147 tokens; SKILL.md has 556 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~147
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from awarexone/Agentic-Bug-Hunter at commit 40b03ee, republished under its MIT licence (© awarexone). 556 words, ~2,392 tokens.

Download SKILL.mdSave it as .claude/skills/meme-coin-audit/SKILL.md (or your agent's skills folder).
name
meme-coin-audit
description
Meme coin and token security audit — rug pull detection (honeypot, hidden mint, fee manipulation, LP lock bypass), Solana SPL token analysis (freeze authority, mint authority, metadata mutability), Token-2022 extension risks (transfer hooks, permanent delegate), DEX liquidity pool attacks (sandwich amplification, LP drain, bonding curve exploits), pump.fun/Raydium/Jupiter integration risks, token_scanner.py automation, and real exploit examples from 2024-2025. Use for any token audit, rug pull assessment, meme coin security review, or pre-investment due diligence.

MEME COIN & TOKEN SECURITY AUDIT

Fast-kill rug pull detection and deep token security analysis for EVM and Solana meme coins.


PRE-DIVE KILL SIGNALS

Check these BEFORE reading a single line of code. If any are true, skip the audit — the token is likely a rug or not worth the time.

Hard Kills (Skip Immediately)
  • Contract not verified on Etherscan/Solscan → Cannot audit source = cannot trust
  • Deployer wallet has history of rug pulls (check Etherscan deployer page)
  • Token age < 1 hour AND no known team → Too early, wait for more data
  • Mint authority retained (Solana) AND no cap → Infinite mint = certain rug
  • Freeze authority retained (Solana) on meme coin → Honeypot confirmed
  • Transfer hook present (Token-2022) with mutable hook program → Honeypot vector
  • Permanent delegate extension (Token-2022) → Can steal all holder tokens
Soft Kills (Proceed with Extreme Caution)
  • Top holder > 20% of supply (excluding DEX pools)
  • LP not burned or locked in verified contract
  • Contract is upgradeable / proxy with retained admin
  • Less than $5K liquidity in the pool
  • No social presence / anonymous deployer with no history

THE ONE RULE

"Check ALL authorities and owner functions. The retained authority IS the rug vector."

Every rug pull requires a privileged operation: mint, blacklist, fee change, LP removal, or authority abuse. If you find the privilege, you found the bug.


BUG CLASSES (8 TOKEN-SPECIFIC)

1. HIDDEN MINT / UNLIMITED SUPPLY

35% of meme coin rugs. Deployer mints tokens post-launch, dumps on LP.

Quick grep (EVM):

bash
grep -rn "function mint\|_mint(\|_balances\[.*\] +=" src/ --include="*.sol" | grep -v "test\|lib\|node_modules"

Quick grep (Solana):

bash
grep -rn "MintTo\|mint_to\|mint_authority" src/ --include="*.rs" | grep -v "test\|target"

Kill if: MAX_SUPPLY enforced in every mint path, or mint function removed entirely.

2. HONEYPOT / TRANSFER RESTRICTION

25% of meme coin scams. Buy works, sell blocked.

Quick grep:

bash
grep -rn "blacklist\|isBlacklisted\|_bots\|maxTxAmount\|approve.*override\|tradingEnabled" src/ --include="*.sol"

Solana equivalent:

bash
grep -rn "freeze_authority\|transfer_hook\|TransferHook\|permanent_delegate" src/ --include="*.rs"

Kill if: No blacklist mapping, no transfer hooks, no freeze authority.

3. FEE MANIPULATION

20% of rugs. Sell fee set to 99% after initial buys.

Quick grep:

bash
grep -rn "setFee\|setSellFee\|_taxFee\|_sellFee" src/ --include="*.sol"
grep -rn "function set.*Fee" -A5 src/ --include="*.sol" | grep -v "require\|MAX\|<="

Kill if: Fee setter has require(fee <= MAX_FEE) with MAX_FEE <= 10%.

4. LIQUIDITY POOL DRAIN

LP removal, migration, or manipulation to crash price.

Quick grep:

bash
grep -rn "migrateLP\|emergencyWithdraw\|\.sync()\|setPair\|setRouter" src/ --include="*.sol"

Kill if: LP tokens burned to dead address, no migration function, no pair setter.

Show full SKILL.md (221 more words)Show less
5. BONDING CURVE MANIPULATION

Exploits in pump.fun-style bonding curves.

Quick grep:

bash
grep -rn "virtualReserve\|setCurve\|graduate\|bonding_curve" src/ --include="*.sol" --include="*.rs"

Kill if: Curve parameters immutable, graduation permissionless.

6. AUTHORITY RETENTION (SOLANA)

Retained mint/freeze/update authorities on Solana tokens.

Quick grep:

bash
grep -rn "mint_authority\|freeze_authority\|update_authority\|close_authority" src/ --include="*.rs"
grep -rn "set_authority.*None" src/ --include="*.rs"  # Good sign: revocation

Kill if: All authorities = None, verified on-chain.

7. FAKE RENOUNCE / HIDDEN OWNERSHIP

Ownership appears renounced but backdoor control retained.

Quick grep:

bash
grep -rn "renounceOwnership.*override\|_shadowAdmin\|_backupOwner\|selfdestruct" src/ --include="*.sol"

Kill if: renounceOwnership NOT overridden, no second admin role, no selfdestruct.

8. SANDWICH AMPLIFICATION BY DESIGN

Contract makes holders maximally sandwichable.

Quick grep:

bash
grep -rn "swapExactTokensForETH" -A5 src/ --include="*.sol" | grep "0,"
grep -rn "swapThreshold\|_rebase\|mandatoryPool" src/ --include="*.sol"

Kill if: Auto-swap has proper slippage, no rebase mechanics.


AUTOMATED SCANNER

Run the token scanner tool for fast red flag detection:

bash
# EVM token
python3 tools/token_scanner.py contracts/Token.sol

# Solana program
python3 tools/token_scanner.py programs/token/ --chain solana --recursive

# Full directory scan with report
python3 tools/token_scanner.py src/ --recursive --output findings/token-report.md

The scanner checks all 8 bug classes via regex patterns. It catches:

  • Direct mint/balance manipulation
  • Blacklist and transfer restriction patterns
  • Unbounded fee setters
  • LP migration and emergency withdraw functions
  • Fake renounce overrides
  • Zero slippage auto-swaps
  • All Solana authority patterns
  • Token-2022 dangerous extensions

Scanner does NOT check:

  • On-chain state (use Etherscan/Solscan for authority verification)
  • Holder distribution (use DEXTools/Birdeye)
  • LP lock status (use Unicrypt/PinkLock/Solscan)
  • Deployer wallet history (manual check)

FOUNDRY POC TEMPLATE (TOKEN EXPLOITS)

solidity
// SPDX-License-Identifier: MIT
pragma solidity ^0.8.0;

import "forge-std/Test.sol";
import "../src/Token.sol";

contract TokenExploitTest is Test {
    Token token;
    address owner = makeAddr("owner");
    address victim = makeAddr("victim");
    address attacker = makeAddr("attacker");

    // Uniswap V2 router (mainnet fork)
    address constant ROUTER = 0x7a250d5630B4cF539739dF2C5dAcb4c659F2488D;
    address constant WETH = 0xC02aaA39b223FE8D0A0e5C4F27eAD9083C756Cc2;

    function setUp() public {
        vm.createSelectFork("mainnet");
        // Deploy token as owner
        vm.startPrank(owner);
        token = new Token();
        // Add liquidity...
        vm.stopPrank();
    }

    function test_hiddenMint_rug() public {
        // Step 1: Victim buys tokens
        vm.startPrank(victim);
        // ... buy tokens on Uniswap
        vm.stopPrank();

        // Step 2: Owner mints and dumps
        vm.startPrank(owner);
        uint256 supplyBefore = token.totalSupply();
        token.mint(owner, 1_000_000_000e18);
        assertGt(token.totalSupply(), supplyBefore, "Supply should increase");
        // ... sell minted tokens
        vm.stopPrank();

        // Step 3: Victim's tokens are now worthless
        // Assert token price crashed
    }

    function test_honeypot_blacklist() public {
        // Step 1: Victim buys
        vm.startPrank(victim);
        // ... buy tokens
        vm.stopPrank();

        // Step 2: Owner blacklists victim
        vm.startPrank(owner);
        token.blacklist(victim);
        vm.stopPrank();

        // Step 3: Victim cannot sell
        vm.startPrank(victim);
        vm.expectRevert("Blacklisted");
        token.transfer(address(1), 100e18);
        vm.stopPrank();
    }

    function test_fee_manipulation_rug() public {
        // Step 1: Verify initial fee is low
        assertEq(token.sellFee(), 3); // 3%

        // Step 2: Owner sets fee to 99%
        vm.prank(owner);
        token.setFees(3, 99); // Buy 3%, Sell 99%

        // Step 3: Victim sells — loses 99% to fees
        vm.startPrank(victim);
        uint256 balanceBefore = address(victim).balance;
        // ... sell tokens
        // Assert: received almost nothing
        vm.stopPrank();
    }
}

SOLANA QUICK CHECKS (NO SOURCE CODE NEEDED)

When you don't have source code, check on-chain:

1. MINT AUTHORITY → solana account <MINT> --output json | check mint_authority
   - Should be null
   - If Some(pubkey) → CRITICAL: can mint infinite tokens

2. FREEZE AUTHORITY → same as above, check freeze_authority
   - Should be null
   - If Some(pubkey) → CRITICAL: honeypot

3. LP STATUS → Check Raydium/Orca pool
   - LP burned? (tokens sent to 1111...1111)
   - LP locked? (in verified locker with no backdoor)
   - LP held by deployer? → CRITICAL: instant rug

4. TOP HOLDERS → Birdeye/Solscan holders tab
   - Top 10 < 30% of supply (excluding pools)
   - Creator wallets (check first transactions)

5. PROGRAM UPGRADEABILITY
   - Is the program upgradeable? → can change any logic
   - Upgrade authority should be None for immutable programs

6. TOKEN-2022 EXTENSIONS
   - Any transfer hook? → potential honeypot
   - Permanent delegate? → CRITICAL

FULL REFERENCE FILES

For deep dives into specific areas:

  • web3/10-meme-coin-bugs.md — All 8 bug classes with full code examples and variants
  • web3/11-solana-token-audit.md — Solana-specific: SPL authorities, Token-2022, pump.fun, Raydium, Jupiter
  • web3/12-dex-lp-attacks.md — DEX & LP manipulation patterns (sandwich, pool sniping, CL position attacks)

© awarexone, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/meme-coin-audit of awarexone/Agentic-Bug-Hunter.

Open the folder on GitHubat commit 40b03ee

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in awarexone/Agentic-Bug-Hunter, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Meme Coin Security Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Meme Coin Security Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Meme Coin Security Audit this skillawarexone/Agentic-Bug-Hunter5.3k1 repos~2.4kAutomated safety check: PassMIT
Behavioral State Analysisquillai-network/quillshield_skills130—~1.4kAutomated safety check: PassMIT
Smart Contract Entry Point Analyzertrailofbits/skills7.5k1 repos~2.4kAutomated safety check: NotesCC-BY-SA-4.0
Defi Amm Securityaffaan-m/ECC276k1 repos~1.3kAutomated safety check: PassMIT
Solana Devsolana-foundation/solana-dev-skill573—~3.8kAutomated safety check: PassMIT
Solana Develophanto/EloPhanto106—~1.4kAutomated safety check: PassMIT

Similar skills

  • Behavioral State Analysis

    quillai-network/quillshield_skills

    Token-efficient smart contract security auditing via Behavioral State Analysis (BSA).

    130 GitHub stars~1.4k tokensUpdated 6 mo ago
    SecurityAuto-check passed
  • Official

    Maps the state-changing entry points of a smart contract codebase and sorts them by access level, producing a structured audit report that leaves out read-only functions.

    7.5k GitHub starsUsed in 1 repo~2.4k tokens
    SecurityAuto-check: notes
  • Defi Amm Security

    affaan-m/ECC

    Security checklist for Solidity AMM contracts, liquidity pools, and swap flows.

    276k GitHub starsUsed in 1 repo~1.3k tokens
    Business, Finance & HRAuto-check passed
  • Solana Dev

    solana-foundation/solana-dev-skill

    A skill your agent uses when user asks to "build a Solana dapp", "write an Anchor program", "create a token", "debug Solana errors", "set up wallet connection", "test my Solana program", "fuzz my…

    573 GitHub stars~3.8k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Solana Dev

    elophanto/EloPhanto

    A skill your agent uses when user asks to "build a Solana dapp", "write an Anchor program", "create a token", "debug Solana errors", "set up wallet connection", "test my Solana program", or "deploy…

    106 GitHub stars~1.4k tokensUpdated 9 days ago
    Backend & APIsAuto-check passed
  • Solana Dev

    aiskillstore/marketplace

    A skill your agent uses when user asks to "build a Solana dapp", "write an Anchor program", "create a token", "debug Solana errors", "set up wallet connection", "test my Solana program", "deploy to…

    433 GitHub stars~2.4k tokensUpdated today
    Backend & APIsAuto-check passed

More from awarexone/Agentic-Bug-Hunter

All 10 skills in this repo
  • Web3 Smart Contract Audit

    awarexone/Agentic-Bug-Hunter

    Guides smart contract audits and bounty target selection with ten DeFi bug classes, kill signals, a Foundry PoC template and grep patterns.

    5.3k GitHub starsUsed in 3 repos~4.5k tokens
    Auto-check passed
  • Bug Bounty Hunting Methodology

    awarexone/Agentic-Bug-Hunter

    Orchestrates a bug bounty session with a 5-phase workflow and a critical-thinking framework covering developer psychology, anomaly detection and What-If experiments.

    5.3k GitHub starsUsed in 2 repos~4.7k tokens
    Auto-check passed
  • Client Request Signature Reversal

    awarexone/Agentic-Bug-Hunter

    Recovers a client-side request signature or anti-bot token just far enough to replay blocked requests in bug bounty testing, starting from a captured packet.

    5.3k GitHub stars~4.7k tokensUpdated today
    Auto-check passed
  • Bug Bounty Triage Validation

    awarexone/Agentic-Bug-Hunter

    Screens a vulnerability finding with a seven-question gate and pre-submission checks before any report is written, so weak or out-of-scope findings are dropped early.

    5.3k GitHub starsUsed in 3 repos~3.4k tokens
    Auto-check passed
  • Bug Bounty Report Writing

    awarexone/Agentic-Bug-Hunter

    Guides writing bug bounty reports for HackerOne, Bugcrowd, Intigriti and Immunefi: impact-first titles, proven claims, CVSS 3.1 scoring and a pre-submit checklist.

    5.3k GitHub starsUsed in 2 repos~3.9k tokens
    Auto-check passed
  • Web2 Recon

    awarexone/Agentic-Bug-Hunter

    Web2 recon pipeline — subdomain enumeration (subfinder, Chaos API, assetfinder), live host discovery (dnsx, httpx), URL crawling (katana, waybackurls, gau), directory fuzzing (ffuf), JS analysis…

    5.3k GitHub starsUsed in 2 repos~6.4k tokens
    Auto-check: warnings

Works with

Questions about Meme Coin Security Audit

What does Meme Coin Security Audit do?

Screens EVM and Solana meme coins for rug pull signs such as hidden mint, honeypot logic and fee tricks, starting with fast kill signals before any code review. The audit begins with conditions that rule a token out before any source is read: an unverified contract, a deployer with a history of rug pulls, a brand-new token with no known team, or a Solana mint or freeze authority that was never given up. Softer warnings include one holder with more than 20% of supply, liquidity that is neither burned nor locked, an upgradeable contract with an admin, thin liquidity and an anonymous deployer.

When should I use Meme Coin Security Audit?

Meme Coin Security Audit fits situations like: assessing a new meme coin for rug pull risk before putting money in; reviewing a Solana SPL token's mint, freeze and metadata authorities; auditing token contract source for hidden mint functions or sell restrictions; checking Token-2022 extensions such as transfer hooks and permanent delegates.

How do I install Meme Coin Security Audit in Claude Code?

Run `npx skills add awarexone/Agentic-Bug-Hunter --skill meme-coin-audit -a claude-code`. Or copy the skill folder (skills/meme-coin-audit in awarexone/Agentic-Bug-Hunter) into .claude/skills/meme-coin-audit in your project. Claude Code loads it when a task matches its description.

How do I install Meme Coin Security Audit in Codex?

Run `npx skills add awarexone/Agentic-Bug-Hunter --skill meme-coin-audit -a codex`. Or copy the skill folder (skills/meme-coin-audit in awarexone/Agentic-Bug-Hunter) into .agents/skills/meme-coin-audit in your project. Codex loads it when a task matches its description.

Can I use Meme Coin Security Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add awarexone/Agentic-Bug-Hunter --skill meme-coin-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/meme-coin-audit, .gemini/skills/meme-coin-audit, .github/skills/meme-coin-audit and .opencode/skills/meme-coin-audit in your project.

What does Meme Coin Security Audit need to run?

Going by SKILL.md and its folder, Meme Coin Security Audit needs the command-line tools its instructions call (python3). Our summary lists: Token contract source code, such as Solidity or Rust files.

Does Meme Coin Security Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Meme Coin Security Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Meme Coin Security Audit use?

Meme Coin Security Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Meme Coin Security Audit use?

About 2.4k tokens (SKILL.md is roughly 9.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Meme Coin Security Audit?

Skills that share tags, products or a category with Meme Coin Security Audit: Behavioral State Analysis (quillai-network/quillshield_skills, 130 stars), Smart Contract Entry Point Analyzer (trailofbits/skills, 7.5k stars), Defi Amm Security (affaan-m/ECC, 276k stars) and Solana Dev (solana-foundation/solana-dev-skill, 573 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Meme Coin Security Audit?

awarexone (a GitHub organization) maintains it in awarexone/Agentic-Bug-Hunter, which has 5,312 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on October 9, 2026.

Source: awarexone/Agentic-Bug-Hunter on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.