docs › LARP detector
LARP detector
Vet the product behind a coin: its website, domain registration and GitHub, read-only, only when you ask.
A memecoin's advertised website, X and Telegram are claims. The LARP detector fetches what it can, reads it mechanically, and lets the analyst grade the claims against what it found. It runs only when you press V on a live token; nothing is fetched automatically.
What it looks at#
| evidence | source | what counts |
|---|---|---|
| the advertised links | DexScreener info + Jupiter metadata (get_links), de-duplicated and classified; a note when the two sources disagree | a mismatch across sources is a flag in itself |
| the website | one SSRF-safe, read-only GET (fetch_page): no JavaScript, no cookies, no downloads, 512 KiB and 8 s caps, robots.txt honoured on every redirect hop, private and loopback addresses refused, DNS re-validated at connect time | site-builder or default-page signals, a live app or demo, docs, wallet-connect patterns, drainer and approval signatures in scripts, external script hosts, whether the symbol and name appear, team-claim and stock-placeholder text |
| the domain | RDAP lookup of the exact advertised domain (check_domain) | registration age, registrar, registrant privacy. A days-old domain behind privacy is a mild signal, not proof. Novelty TLDs without an RDAP server come back as unverifiable. |
| GitHub | the keyless GitHub API (check_github) for a github.com/owner/repo link | created and last-push dates, stars, open issues, archived or fork, up to five real commit hashes with dates |
| pump.fun metadata | the metadata URI GoPlus reports, through the same safe fetch | the advertised description and links, when they exist |
X is usually login-walled keyless, so account age and follower counts are reported as unverifiable rather than guessed. Every fetched string reaches the model through the prompt firewall: normalised, control and bidi characters stripped, URLs and addresses masked, wrapped as untrusted data, tags stripped so a planted closing tag cannot break out.
The verdict#
The larp-check skill returns a structured assessment: REAL_PRODUCT · EARLY_BUT_REAL · LARP · UNVERIFIABLE · AMBIGUOUS, with a confidence, a status per claim (supported, contradicted, unverifiable), missing_data, the facts and flags it used, injection_detected and a short summary. It is separate from the dossier's risk verdict and does not replace it.
Once computed, a badge appears in the screener's FLAGS column and in the token screen's title strip for that mint only: LARP (red), REAL (green), REAL? (mixed), UNKNOWN for unverifiable or ambiguous. Nothing shows before you vet a coin. A LARP verdict also vetoes an AI scan lock on that coin.
Open-link keys#
W, X and T open the advertised website, X and Telegram in your browser; L lists every advertised link (including secondary socials from DexScreener) in a menu. The URL is drawn on screen before anything launches; only http and https links are ever passed to the opener (open on macOS, xdg-open on Linux, as a single argument, no shell). The footer shows these keys only when the token actually advertises links.