Atlas / Skills / bankrbot / Bankr Token Scam Analysis

Bankr Token Scam AnalysisBLOCK

skills/bankrbot/bankr-token-scam-analysis

Bankr Skills equip builders with plug-and-play tools to build more powerful agents.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Version
—
Hosts
—
License
—
Stars
1,202
01

Overview

Bankr Skills equip builders with plug-and-play tools to build more powerful agents.

Read from source at commit 4029e336cef5OBSERVED · 2026-10-09
02

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: token-scam-analysis
description: Deep on-chain scam / rug / soft-rug analysis for EVM tokens (especially Clanker, Doppler, Bankr-style single-admin ERC-20s). Use when the user asks to "analyze this token for scam", "is this a rug", "should I trust this migration", "do a deep dive on holders and deployer", or provides one or more token addresses and wants a risk verdict backed by on-chain facts. Especially useful for migration narratives where a team claims they are "redeploying to fix tokenomics".
emoji: 🔍
tags: [scam, rug, analysis, forensics, clanker, doppler, evm, security]
visibility: public
---

# Token Scam Analysis Skill

You are performing a forensic on-chain analysis to determine whether a token (or set of tokens) is a scam, rug-pull, or soft-rug. The output is a written report saved to the user's file storage plus a verdict in chat.

## When to use this skill
- User gives one or more token contract addresses and asks for a risk assessment.
- User mentions a "migration" / "redeploy" / "new contract" narrative.
- User names a Twitter/X handle of the project and wants to cross-reference claims vs on-chain reality.
- Comparing old vs new contracts from the same team.

## Core principle
Narrative is noise. On-chain state is signal. Every claim the team makes should be checked against what the contract and the deployer's wallet actually did. If the two conflict, the chain wins.

**BUT: on-chain cleanliness ≠ not a scam.** A team can deploy a perfectly clean LayerZero OFT or ERC-20, hand it to a multisig, and still run a textbook insider pump-and-dump via CEX coordination and concentrated supply. You MUST always run the off-chain intel pass (Step Final-1) before issuing a verdict, or you will under-call real manipulation cases.

---

## Step 0 — Read the platform's deploy docs BEFORE judging tokenomics claims
Before making any claim about what a team "could not" or "should have" configured, read the deployment docs for the launch platform. Otherwise you will miss capabilities and bait on the team's narrative. Identify the platform by looking at the `allData()` `context` field (e.g., `"interface":"clanker.world"`), the deploy factory address, or the token ABI (`admin/originalAdmin/allData/isVerified` is Clanker-style).

Priority reads by platform:

- **Clanker v4** (`allData()` context = `clanker.world`, factory `0xe85a59c628f7d27878aceb4bf3b35733630083a9`):
  - https://clanker.gitbook.io/clanker-documentation/general/token-deployments  — overview: 100B ERC-20, extensions up to 90% of supply.
  - https://clanker.gitbook.io/clanker-documentation/authenticated/deploy-token-v4.0.0  — full deploy payload (vault, airdrop, fees, up to 7 reward recipients, pool config).
  - https://clanker.gitbook.io/clanker-documentation/references/core-contracts/v4  — ClankerVault / Airdrop extension internals.
  - What you MUST know before judging:
    - Tokenomics (allocations, lockups, vesting, multiple reward splits, custom paired token, initial market cap, static/dynamic fees) are set in the **deploy payload**. A team cannot say "we had to redeploy because we couldn't configure tokenomics" — Clanker v4 supports all of that in one transaction.
    - Min vault lockup 7 days, min airdrop lockup 1 day.
    - Max 90% of supply across all extensions (rest goes to LP).
    - Token bytecode being identical across deploys is **expected** (it's a factory template) — do not use bytecode-sameness as a red flag by itself. Configuration differences live in the deploy payload, not in the token runtime code.
- **Bankr / Doppler / Scheduled Multicurve**: deployer beneficiary shares, no migration, locked pool, 95/5 fee split.
- **Zora / Virtuals / Pump.fun**: platform-specific, look for official docs via `search_tool`.
- **LayerZero OFT multichain tokens** (source has `import "@layerzerolabs/oft-evm/contracts/OFT.sol"` and `peers(uint32)`, `setPeer`, `send`, `setEnforcedOptions`): standard multichain pattern. `setPeer` by owner is the main live admin power — if signers collude they can add a malicious peer chain and mint via `_credit`. Existing peers matching across chain explorers = legit bridge config. LZ V2 endpoint on Base: `0x1a44076050125825900e736c501f859c50fE728c`.

**Save this step to your report.** The "Claim vs reality" section needs to quote a specific docs capability the team *could* have used and chose not to.

---

## Tool map (roughly in order of use)

1. **`token_search`** (identifier_type=address, chain=...) — baseline market data: price, mcap, volume, 24h change, holder count, security scan flag. Set include_chart=false, include_market_data_image=false to keep context lean.
2. **`get_token_launch_info`** — if the token was deployed via Bankr/Doppler, you get the deployer wallet + twitter handle + tweet URL for free. Always try this first even if you think it's Clanker; the tool returns cleanly on non-match.
3. **`get_contract_abi`** (chain=...) — confirm the address is a real contract and enumerate read/write functions. Flag dangerous functions: `mint`, `crosschainMint`, `setOwner`, `updateAdmin`, `blacklist`, `setFee`, `pause`, `updateImage`, `updateMetadata`. For OFTs, note `setPeer` / `setEnforcedOptions` — these are owner-gated but not exit-scam primitives by themselves.
4. **`read_contract`** for on-chain state. For Clanker v4 tokens:
   - `totalSupply() view returns (uint256)` — expect 100_000_000_000 * 10^18.
   - `allData() view returns (address originalAdmin, address admin, string image, string metadata, string context)` — the single richest read. Tells you deployer admin, current admin (if different = admin handoff happened), whether metadata/socials/audits are populated, and which interface launched it (`clanker.world`, Farcaster, etc.).
   - `isVerified() view returns (bool)` — Clanker's own verification flag.
   - `balanceOf(address) view returns (uint256)` — for any wallet you want to check (admin, top holders, pool manager).
   For OFTs: `owner()`, `peers(uint32)` for each kno
03

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeNA
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (1)

CRITICALPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
SKILL.md:42
- **LayerZero OFT multichain tokens** (source has `import "@layerzerolabs/oft-evm/contracts/OFT.sol"` and `peers(uint32)`, `setPeer`, `send`, `setEnforcedOptions`): standard multichain pattern. `setPe
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: critical_finding, no_behavioural_pass, undeclared_transfer.

Audited 2026-10-09 · audit v0.4.1 · source sha 4029e336cef5full audit observations/trust-audit/skill/bankrbot__bankr-token-scam-analysis.json · Report an issue / request a re-scan
04

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-094029e336cef5BLOCKD69first audit
05

Questions

What does the Bankr Token Scam Analysis skill do?

Bankr Skills equip builders with plug-and-play tools to build more powerful agents.

Is Bankr Token Scam Analysis safe to install?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What can Bankr Token Scam Analysis access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

How current is this page?

The grade is for one exact copy of the source (4029e336cef5), read on 2026-10-09. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement