diff --git a/.github/workflows/auto-assign.yml b/.github/workflows/auto-assign.yml new file mode 100644 index 0000000..e69de29 diff --git a/.github/workflows/spam-detection.yml b/.github/workflows/spam-detection.yml new file mode 100644 index 0000000..fe1b26b --- /dev/null +++ b/.github/workflows/spam-detection.yml @@ -0,0 +1,80 @@ +name: Suspicious Comment Detection + +on: + issue_comment: + types: [created] + pull_request_review_comment: + types: [created] + +jobs: + check_comment: + runs-on: ubuntu-latest + steps: + - name: Check for suspicious patterns + uses: actions/github-script@v6 + with: + github-token: ${{ secrets.GITHUB_TOKEN }} + script: | + const comment = context.payload.comment; + const body = comment.body.toLowerCase(); + const author = comment.user.login; + + // Suspicious patterns + const suspiciousPatterns = [ + 'support team', + 'customer service', + 'telegram', + 'whatsapp', + 'contact us', + 'click here', + 'support group', + 't.me/', + 'wa.me/', + 'support chat', + 'live chat', + 'support ticket', + 'ticket id', + 'live support', + 'support line', + 'support agent', + 'support network', + 'dedicated support', + 'personalized assistance', + 'opened for you', + 'kindly talk to', + 'we apologize', + ]; + + // Check for external links (excluding common legitimate domains) + const hasExternalLinks = body.includes('http') || body.includes('www'); + const hasGithubLinks = body.includes('github.com'); + const suspiciousLinks = hasExternalLinks && !hasGithubLinks; + + // Check for suspicious patterns + const foundPatterns = suspiciousPatterns.filter(pattern => + body.includes(pattern) + ); + + if (foundPatterns.length > 0 || suspiciousLinks) { + // Create a warning comment + const warningMessage = `⚠️ Potential scam detected in comment by ${author}: + - Suspicious patterns found: ${foundPatterns.join(', ')} + ${suspiciousLinks ? '- Contains external links' : ''} + + @${context.repo.owner} Please review this comment.`; + + await github.rest.issues.createComment({ + owner: context.repo.owner, + repo: context.repo.repo, + issue_number: context.payload.issue ? context.payload.issue.number : context.payload.pull_request.number, + body: warningMessage + }); + + // Add 'potential-scam' label + await github.rest.issues.addLabels({ + owner: context.repo.owner, + repo: context.repo.repo, + issue_number: context.payload.issue ? context.payload.issue.number : context.payload.pull_request.number, + labels: ['potential-scam'] + }); + } \ No newline at end of file diff --git a/MAINTAINERS.md b/MAINTAINERS.md new file mode 100644 index 0000000..29a6ebc --- /dev/null +++ b/MAINTAINERS.md @@ -0,0 +1,3 @@ +The maintainers are: +@akegaviar (primary contact, issue manager) +@smypmsa \ No newline at end of file diff --git a/README.md b/README.md index eec457c..357c40d 100644 --- a/README.md +++ b/README.md @@ -1,3 +1,14 @@ +**WARNNING ON SCAMS IN ISSUES COMMENT SECTION** +The issues comment section is often targeted by scam bots willing to redirect you to an external resource and drain your funds. + +I have enabled a GitHub actions script to detect the common patterns and tag them, which obviously is not 100% accurate. + +The official maintainers are in the [MAINTAINERS.md](MAINTAINERS.md) file. + +Not everyone is a scammer though, sometimes there are helpful outside devs who comment and I absolutely appreciate it. + +**END OF WARNING** + For the full walkthrough, see [Solana: Creating a trading and sniping pump.fun bot](https://docs.chainstack.com/docs/solana-creating-a-pumpfun-bot). For near-instantaneous transaction propagation, you can use the [Chainstack Solana Trader nodes](https://docs.chainstack.com/docs/trader-nodes).