MR
Mayur Rathi
@sickn33
⭐ 47.3k GitHub stars

meme-coin-audit

meme-coin-audit is an code AI skill with a core value of Meme coin and token security audit. It helps developers solve real-world problems in the code domain, boosting efficiency, automating repetitive tasks, and optimizing workflows.

Meme coin and token security audit

Last verified on: 2026-10-06

Quick Facts

Category code
Works With Claude
Source sickn33/antigravity-awesome-skills
Stars ⭐ 47.3k
Last Verified 2026-10-06
Risk Level High
mkdir -p ./skills/meme-coin-audit && curl -sfL https://raw.githubusercontent.com/sickn33/antigravity-awesome-skills/main/skills/meme-coin-audit/SKILL.md -o ./skills/meme-coin-audit/SKILL.md

Run in terminal / PowerShell. Requires curl (Unix) or PowerShell 5+ (Windows).

Skill Content

> **⚠️ AUTHORIZED USE ONLY**

> This skill is for educational purposes or authorized security assessments only.

> You must have explicit, written permission from the system owner before using this tool.

> Misuse of this tool is illegal and strictly prohibited.


> **Mandatory confirmation gate**

> Before running any command that probes, exploits, changes, persists on, extracts data from, or attempts credential access against a target:

> 1. Ask the user to state the exact target URL, IP, account, or resource.

> 2. Ask the user to confirm written authorization and the permitted scope.

> 3. Show the exact command(s) and explain their expected effect.

> 4. Wait for explicit confirmation in the current conversation.

>

> Without that confirmation, remain read-only and provide defensive guidance only. Prefer a sandbox, disposable VM, or controlled lab.


# MEME COIN & TOKEN SECURITY AUDIT


Fast-kill rug pull detection and deep token security analysis for EVM and Solana meme coins.


---


PRE-DIVE KILL SIGNALS


Check these BEFORE reading a single line of code. If any are true, skip the audit — the token is likely a rug or not worth the time.


Hard Kills (Skip Immediately)

- **Contract not verified** on Etherscan/Solscan → Cannot audit source = cannot trust

- **Deployer wallet** has history of rug pulls (check Etherscan deployer page)

- **Token age < 1 hour** AND no known team → Too early, wait for more data

- **Mint authority retained** (Solana) AND no cap → Infinite mint = certain rug

- **Freeze authority retained** (Solana) on meme coin → Honeypot confirmed

- **Transfer hook present** (Token-2022) with mutable hook program → Honeypot vector

- **Permanent delegate** extension (Token-2022) → Can steal all holder tokens


Soft Kills (Proceed with Extreme Caution)

- Top holder > 20% of supply (excluding DEX pools)

- LP not burned or locked in verified contract

- Contract is upgradeable / proxy with retained admin

- Less than $5K liquidity in the pool

- No social presence / anonymous deployer with no history


---


THE ONE RULE


> **"Check ALL authorities and owner functions. The retained authority IS the rug vector."**

>

> Every rug pull requires a privileged operation: mint, blacklist, fee change, LP removal, or authority abuse. If you find the privilege, you found the bug.


---


BUG CLASSES (8 TOKEN-SPECIFIC)


1. HIDDEN MINT / UNLIMITED SUPPLY

> Common rug pattern. Deployer mints tokens post-launch, dumps on LP.


**Quick grep (EVM):**

bash
grep -rn "function mint\|_mint(\|_balances\[.*\] +=" src/ --include="*.sol" | grep -v "test\|lib\|node_modules"

**Quick grep (Solana):**

bash
grep -rn "MintTo\|mint_to\|mint_authority" src/ --include="*.rs" | grep -v "test\|target"

**Kill if:** MAX_SUPPLY enforced in every mint path, or mint function removed entirely.


2. HONEYPOT / TRANSFER RESTRICTION

> Common scam pattern. Buy works, sell blocked.


**Quick grep:**

bash
grep -rn "blacklist\|isBlacklisted\|_bots\|maxTxAmount\|approve.*override\|tradingEnabled" src/ --include="*.sol"

**Solana equivalent:**

bash
grep -rn "freeze_authority\|transfer_hook\|TransferHook\|permanent_delegate" src/ --include="*.rs"

**Kill if:** No blacklist mapping, no transfer hooks, no freeze authority.


3. FEE MANIPULATION

> Common rug pattern. Sell fee set to 99% after initial buys.


**Quick grep:**

bash
grep -rn "setFee\|setSellFee\|_taxFee\|_sellFee" src/ --include="*.sol"
grep -rn "function set.*Fee" -A5 src/ --include="*.sol" | grep -v "require\|MAX\|<="

**Kill if:** Fee setter has `require(fee <= MAX_FEE)` with MAX_FEE <= 10%.


4. LIQUIDITY POOL DRAIN

> LP removal, migration, or manipulation to crash price.


**Quick grep:**

bash
grep -rn "migrateLP\|emergencyWithdraw\|\.sync()\|setPair\|setRouter" src/ --include="*.sol"

**Kill if:** LP tokens burned to dead address, no migration function, no pair setter.


5. BONDING CURVE MANIPULATION

> Exploits in pump.fun-style bonding curves.


**Quic

🎯 Best For

  • Security auditors
  • DevSecOps teams
  • Compliance officers
  • Claude users
  • Software engineers

💡 Use Cases

  • Auditing dependencies for known CVEs
  • Scanning API endpoints for auth gaps
  • Code quality improvement
  • Best practice enforcement

📖 How to Use This Skill

  1. 1

    Install the Skill

    Copy the install command from the Terminal tab and run it. The SKILL.md file downloads to your local skills directory.

  2. 2

    Load into Your AI Assistant

    Open Claude and reference the skill. Paste the SKILL.md content or use the system prompt tab.

  3. 3

    Apply meme-coin-audit to Your Work

    Open your project in the AI assistant and ask it to apply the skill. Start with a small module to verify the output quality.

  4. 4

    Review and Refine

    Review AI suggestions before committing. Run tests, check for regressions, and iterate on the skill output.

❓ Frequently Asked Questions

Can this replace a dedicated SAST tool?

AI-based security review is complementary to SAST tools. Use it as a first-pass filter, not a replacement.

Is meme-coin-audit compatible with Cursor and VS Code?

Yes — this skill works with any AI coding assistant including Cursor, VS Code with Copilot, and JetBrains IDEs.

Do I need specific dependencies for meme-coin-audit?

Check the install command and Works With section. Most code skills only require the AI assistant and your codebase.

How do I install meme-coin-audit?

Copy the install command from the Terminal tab and run it. The skill downloads to ./skills/meme-coin-audit/SKILL.md, ready to use.

Can I customize this skill for my team?

Absolutely. Edit the SKILL.md file to add team-specific instructions, examples, or workflows.

⚠️ Common Mistakes to Avoid

Only scanning surface-level issues

Deep security review requires understanding your app architecture, not just regex patterns.

Skipping validation

Always test AI-generated code changes, even for simple refactors.

Missing dependency updates

Check if the skill requires updated dependencies or new packages.

🔗 Related Skills