Behavioral State Analysis
quillai-network/quillshield_skills
Token-efficient smart contract security auditing via Behavioral State Analysis (BSA).
Screens EVM and Solana meme coins for rug pull signs such as hidden mint, honeypot logic and fee tricks, starting with fast kill signals before any code review.
$ npx skills add awarexone/Agentic-Bug-Hunter --skill meme-coin-audit -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install awarexone/Agentic-Bug-Hunter meme-coin-audit --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/awarexone/Agentic-Bug-Hunter.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/meme-coin-audit .claude/skills/meme-coin-audit && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "meme-coin-audit" agent skill from https://github.com/awarexone/Agentic-Bug-Hunter/tree/main/skills/meme-coin-audit into .claude/skills/meme-coin-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "meme-coin-audit", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/awarexone/Agentic-Bug-Hunter/tree/main/skills/meme-coin-auditType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add awarexone/Agentic-Bug-Hunter --skill meme-coin-audit -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install awarexone/Agentic-Bug-Hunter meme-coin-audit --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/awarexone/Agentic-Bug-Hunter.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/meme-coin-audit .agents/skills/meme-coin-audit && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "meme-coin-audit" agent skill from https://github.com/awarexone/Agentic-Bug-Hunter/tree/main/skills/meme-coin-audit into .agents/skills/meme-coin-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "meme-coin-audit", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add awarexone/Agentic-Bug-Hunter --skill meme-coin-audit -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install awarexone/Agentic-Bug-Hunter meme-coin-audit --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/awarexone/Agentic-Bug-Hunter.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/meme-coin-audit .cursor/skills/meme-coin-audit && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "meme-coin-audit" agent skill from https://github.com/awarexone/Agentic-Bug-Hunter/tree/main/skills/meme-coin-audit into .cursor/skills/meme-coin-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "meme-coin-audit", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/awarexone/Agentic-Bug-Hunter.git --path skills/meme-coin-audit--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add awarexone/Agentic-Bug-Hunter --skill meme-coin-audit -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install awarexone/Agentic-Bug-Hunter meme-coin-audit --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/awarexone/Agentic-Bug-Hunter.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/meme-coin-audit .gemini/skills/meme-coin-audit && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "meme-coin-audit" agent skill from https://github.com/awarexone/Agentic-Bug-Hunter/tree/main/skills/meme-coin-audit into .gemini/skills/meme-coin-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "meme-coin-audit", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install awarexone/Agentic-Bug-Hunter meme-coin-auditInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add awarexone/Agentic-Bug-Hunter --skill meme-coin-audit -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/awarexone/Agentic-Bug-Hunter.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/meme-coin-audit .github/skills/meme-coin-audit && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "meme-coin-audit" agent skill from https://github.com/awarexone/Agentic-Bug-Hunter/tree/main/skills/meme-coin-audit into .github/skills/meme-coin-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "meme-coin-audit", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add awarexone/Agentic-Bug-Hunter --skill meme-coin-audit -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install awarexone/Agentic-Bug-Hunter meme-coin-audit --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/awarexone/Agentic-Bug-Hunter.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/meme-coin-audit .opencode/skills/meme-coin-audit && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "meme-coin-audit" agent skill from https://github.com/awarexone/Agentic-Bug-Hunter/tree/main/skills/meme-coin-audit into .opencode/skills/meme-coin-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "meme-coin-audit", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
meme-coin-auditScreens EVM and Solana meme coins for rug pull signs such as hidden mint, honeypot logic and fee tricks, starting with fast kill signals before any code review.
The audit begins with conditions that rule a token out before any source is read: an unverified contract, a deployer with a history of rug pulls, a brand-new token with no known team, or a Solana mint or freeze authority that was never given up. Softer warnings include one holder with more than 20% of supply, liquidity that is neither burned nor locked, an upgradeable contract with an admin, thin liquidity and an anonymous deployer.
Its guiding rule is that the retained authority is the rug vector, so the agent hunts for every privileged operation: mint, blacklist, fee change, liquidity removal. It then works through token-specific bug classes, beginning with hidden mint and unlimited supply, honeypots and transfer restrictions, and fee manipulation, using grep patterns for Solidity and Rust sources. The description also lists Token-2022 extension risks, DEX pool attacks and a `token_scanner.py` helper, though the excerpt shown covers only the first three classes.
8 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 40b03ee. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
python3From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Meme Coin Security Audit loads about 2.4k tokens when it runs. Until then it costs about 147 tokens; SKILL.md has 556 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from awarexone/Agentic-Bug-Hunter at commit 40b03ee, republished under its MIT licence (© awarexone). 556 words, ~2,392 tokens.
.claude/skills/meme-coin-audit/SKILL.md (or your agent's skills folder).Fast-kill rug pull detection and deep token security analysis for EVM and Solana meme coins.
Check these BEFORE reading a single line of code. If any are true, skip the audit — the token is likely a rug or not worth the time.
"Check ALL authorities and owner functions. The retained authority IS the rug vector."
Every rug pull requires a privileged operation: mint, blacklist, fee change, LP removal, or authority abuse. If you find the privilege, you found the bug.
35% of meme coin rugs. Deployer mints tokens post-launch, dumps on LP.
Quick grep (EVM):
grep -rn "function mint\|_mint(\|_balances\[.*\] +=" src/ --include="*.sol" | grep -v "test\|lib\|node_modules"Quick grep (Solana):
grep -rn "MintTo\|mint_to\|mint_authority" src/ --include="*.rs" | grep -v "test\|target"Kill if: MAX_SUPPLY enforced in every mint path, or mint function removed entirely.
25% of meme coin scams. Buy works, sell blocked.
Quick grep:
grep -rn "blacklist\|isBlacklisted\|_bots\|maxTxAmount\|approve.*override\|tradingEnabled" src/ --include="*.sol"Solana equivalent:
grep -rn "freeze_authority\|transfer_hook\|TransferHook\|permanent_delegate" src/ --include="*.rs"Kill if: No blacklist mapping, no transfer hooks, no freeze authority.
20% of rugs. Sell fee set to 99% after initial buys.
Quick grep:
grep -rn "setFee\|setSellFee\|_taxFee\|_sellFee" src/ --include="*.sol"
grep -rn "function set.*Fee" -A5 src/ --include="*.sol" | grep -v "require\|MAX\|<="Kill if: Fee setter has require(fee <= MAX_FEE) with MAX_FEE <= 10%.
LP removal, migration, or manipulation to crash price.
Quick grep:
grep -rn "migrateLP\|emergencyWithdraw\|\.sync()\|setPair\|setRouter" src/ --include="*.sol"Kill if: LP tokens burned to dead address, no migration function, no pair setter.
Exploits in pump.fun-style bonding curves.
Quick grep:
grep -rn "virtualReserve\|setCurve\|graduate\|bonding_curve" src/ --include="*.sol" --include="*.rs"Kill if: Curve parameters immutable, graduation permissionless.
Retained mint/freeze/update authorities on Solana tokens.
Quick grep:
grep -rn "mint_authority\|freeze_authority\|update_authority\|close_authority" src/ --include="*.rs"
grep -rn "set_authority.*None" src/ --include="*.rs" # Good sign: revocationKill if: All authorities = None, verified on-chain.
Ownership appears renounced but backdoor control retained.
Quick grep:
grep -rn "renounceOwnership.*override\|_shadowAdmin\|_backupOwner\|selfdestruct" src/ --include="*.sol"Kill if: renounceOwnership NOT overridden, no second admin role, no selfdestruct.
Contract makes holders maximally sandwichable.
Quick grep:
grep -rn "swapExactTokensForETH" -A5 src/ --include="*.sol" | grep "0,"
grep -rn "swapThreshold\|_rebase\|mandatoryPool" src/ --include="*.sol"Kill if: Auto-swap has proper slippage, no rebase mechanics.
Run the token scanner tool for fast red flag detection:
# EVM token
python3 tools/token_scanner.py contracts/Token.sol
# Solana program
python3 tools/token_scanner.py programs/token/ --chain solana --recursive
# Full directory scan with report
python3 tools/token_scanner.py src/ --recursive --output findings/token-report.mdThe scanner checks all 8 bug classes via regex patterns. It catches:
Scanner does NOT check:
// SPDX-License-Identifier: MIT
pragma solidity ^0.8.0;
import "forge-std/Test.sol";
import "../src/Token.sol";
contract TokenExploitTest is Test {
Token token;
address owner = makeAddr("owner");
address victim = makeAddr("victim");
address attacker = makeAddr("attacker");
// Uniswap V2 router (mainnet fork)
address constant ROUTER = 0x7a250d5630B4cF539739dF2C5dAcb4c659F2488D;
address constant WETH = 0xC02aaA39b223FE8D0A0e5C4F27eAD9083C756Cc2;
function setUp() public {
vm.createSelectFork("mainnet");
// Deploy token as owner
vm.startPrank(owner);
token = new Token();
// Add liquidity...
vm.stopPrank();
}
function test_hiddenMint_rug() public {
// Step 1: Victim buys tokens
vm.startPrank(victim);
// ... buy tokens on Uniswap
vm.stopPrank();
// Step 2: Owner mints and dumps
vm.startPrank(owner);
uint256 supplyBefore = token.totalSupply();
token.mint(owner, 1_000_000_000e18);
assertGt(token.totalSupply(), supplyBefore, "Supply should increase");
// ... sell minted tokens
vm.stopPrank();
// Step 3: Victim's tokens are now worthless
// Assert token price crashed
}
function test_honeypot_blacklist() public {
// Step 1: Victim buys
vm.startPrank(victim);
// ... buy tokens
vm.stopPrank();
// Step 2: Owner blacklists victim
vm.startPrank(owner);
token.blacklist(victim);
vm.stopPrank();
// Step 3: Victim cannot sell
vm.startPrank(victim);
vm.expectRevert("Blacklisted");
token.transfer(address(1), 100e18);
vm.stopPrank();
}
function test_fee_manipulation_rug() public {
// Step 1: Verify initial fee is low
assertEq(token.sellFee(), 3); // 3%
// Step 2: Owner sets fee to 99%
vm.prank(owner);
token.setFees(3, 99); // Buy 3%, Sell 99%
// Step 3: Victim sells — loses 99% to fees
vm.startPrank(victim);
uint256 balanceBefore = address(victim).balance;
// ... sell tokens
// Assert: received almost nothing
vm.stopPrank();
}
}When you don't have source code, check on-chain:
1. MINT AUTHORITY → solana account <MINT> --output json | check mint_authority
- Should be null
- If Some(pubkey) → CRITICAL: can mint infinite tokens
2. FREEZE AUTHORITY → same as above, check freeze_authority
- Should be null
- If Some(pubkey) → CRITICAL: honeypot
3. LP STATUS → Check Raydium/Orca pool
- LP burned? (tokens sent to 1111...1111)
- LP locked? (in verified locker with no backdoor)
- LP held by deployer? → CRITICAL: instant rug
4. TOP HOLDERS → Birdeye/Solscan holders tab
- Top 10 < 30% of supply (excluding pools)
- Creator wallets (check first transactions)
5. PROGRAM UPGRADEABILITY
- Is the program upgradeable? → can change any logic
- Upgrade authority should be None for immutable programs
6. TOKEN-2022 EXTENSIONS
- Any transfer hook? → potential honeypot
- Permanent delegate? → CRITICALFor deep dives into specific areas:
web3/10-meme-coin-bugs.md — All 8 bug classes with full code examples and variantsweb3/11-solana-token-audit.md — Solana-specific: SPL authorities, Token-2022, pump.fun, Raydium, Jupiterweb3/12-dex-lp-attacks.md — DEX & LP manipulation patterns (sandwich, pool sniping, CL position attacks)© awarexone, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/meme-coin-audit of awarexone/Agentic-Bug-Hunter.
Open the folder on GitHubat commit 40b03ee
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in awarexone/Agentic-Bug-Hunter, which our catalogue first saw on October 7, 2026.
Meme Coin Security Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Meme Coin Security Audit this skillawarexone/Agentic-Bug-Hunter | 5.3k | 1 repos | ~2.4k | Automated safety check: Pass | MIT | |
| Behavioral State Analysisquillai-network/quillshield_skills | 130 | — | ~1.4k | Automated safety check: Pass | MIT | |
| Smart Contract Entry Point Analyzertrailofbits/skills | 7.5k | 1 repos | ~2.4k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Defi Amm Securityaffaan-m/ECC | 276k | 1 repos | ~1.3k | Automated safety check: Pass | MIT | |
| Solana Devsolana-foundation/solana-dev-skill | 573 | — | ~3.8k | Automated safety check: Pass | MIT | |
| Solana Develophanto/EloPhanto | 106 | — | ~1.4k | Automated safety check: Pass | MIT |
quillai-network/quillshield_skills
Token-efficient smart contract security auditing via Behavioral State Analysis (BSA).
trailofbits/skills
Maps the state-changing entry points of a smart contract codebase and sorts them by access level, producing a structured audit report that leaves out read-only functions.
affaan-m/ECC
Security checklist for Solidity AMM contracts, liquidity pools, and swap flows.
solana-foundation/solana-dev-skill
A skill your agent uses when user asks to "build a Solana dapp", "write an Anchor program", "create a token", "debug Solana errors", "set up wallet connection", "test my Solana program", "fuzz my…
elophanto/EloPhanto
A skill your agent uses when user asks to "build a Solana dapp", "write an Anchor program", "create a token", "debug Solana errors", "set up wallet connection", "test my Solana program", or "deploy…
aiskillstore/marketplace
A skill your agent uses when user asks to "build a Solana dapp", "write an Anchor program", "create a token", "debug Solana errors", "set up wallet connection", "test my Solana program", "deploy to…
awarexone/Agentic-Bug-Hunter
Guides smart contract audits and bounty target selection with ten DeFi bug classes, kill signals, a Foundry PoC template and grep patterns.
awarexone/Agentic-Bug-Hunter
Orchestrates a bug bounty session with a 5-phase workflow and a critical-thinking framework covering developer psychology, anomaly detection and What-If experiments.
awarexone/Agentic-Bug-Hunter
Recovers a client-side request signature or anti-bot token just far enough to replay blocked requests in bug bounty testing, starting from a captured packet.
awarexone/Agentic-Bug-Hunter
Screens a vulnerability finding with a seven-question gate and pre-submission checks before any report is written, so weak or out-of-scope findings are dropped early.
awarexone/Agentic-Bug-Hunter
Guides writing bug bounty reports for HackerOne, Bugcrowd, Intigriti and Immunefi: impact-first titles, proven claims, CVSS 3.1 scoring and a pre-submit checklist.
awarexone/Agentic-Bug-Hunter
Web2 recon pipeline — subdomain enumeration (subfinder, Chaos API, assetfinder), live host discovery (dnsx, httpx), URL crawling (katana, waybackurls, gau), directory fuzzing (ffuf), JS analysis…
Works with
Categories
Screens EVM and Solana meme coins for rug pull signs such as hidden mint, honeypot logic and fee tricks, starting with fast kill signals before any code review. The audit begins with conditions that rule a token out before any source is read: an unverified contract, a deployer with a history of rug pulls, a brand-new token with no known team, or a Solana mint or freeze authority that was never given up. Softer warnings include one holder with more than 20% of supply, liquidity that is neither burned nor locked, an upgradeable contract with an admin, thin liquidity and an anonymous deployer.
Meme Coin Security Audit fits situations like: assessing a new meme coin for rug pull risk before putting money in; reviewing a Solana SPL token's mint, freeze and metadata authorities; auditing token contract source for hidden mint functions or sell restrictions; checking Token-2022 extensions such as transfer hooks and permanent delegates.
Run `npx skills add awarexone/Agentic-Bug-Hunter --skill meme-coin-audit -a claude-code`. Or copy the skill folder (skills/meme-coin-audit in awarexone/Agentic-Bug-Hunter) into .claude/skills/meme-coin-audit in your project. Claude Code loads it when a task matches its description.
Run `npx skills add awarexone/Agentic-Bug-Hunter --skill meme-coin-audit -a codex`. Or copy the skill folder (skills/meme-coin-audit in awarexone/Agentic-Bug-Hunter) into .agents/skills/meme-coin-audit in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add awarexone/Agentic-Bug-Hunter --skill meme-coin-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/meme-coin-audit, .gemini/skills/meme-coin-audit, .github/skills/meme-coin-audit and .opencode/skills/meme-coin-audit in your project.
Going by SKILL.md and its folder, Meme Coin Security Audit needs the command-line tools its instructions call (python3). Our summary lists: Token contract source code, such as Solidity or Rust files.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Meme Coin Security Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.4k tokens (SKILL.md is roughly 9.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Meme Coin Security Audit: Behavioral State Analysis (quillai-network/quillshield_skills, 130 stars), Smart Contract Entry Point Analyzer (trailofbits/skills, 7.5k stars), Defi Amm Security (affaan-m/ECC, 276k stars) and Solana Dev (solana-foundation/solana-dev-skill, 573 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
awarexone (a GitHub organization) maintains it in awarexone/Agentic-Bug-Hunter, which has 5,312 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on October 9, 2026.
Source: awarexone/Agentic-Bug-Hunter on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.