Skip to content

Add Akita Share Token (■AKITA) on Base - #92

Closed
wenakita wants to merge 1363 commits into
Uniswap:masterfrom
wenakita:add-akita-share-token-base
Closed

Add Akita Share Token (■AKITA) on Base#92
wenakita wants to merge 1363 commits into
Uniswap:masterfrom
wenakita:add-akita-share-token-base

Conversation

@wenakita

Copy link
Copy Markdown

Add Akita Share Token on Base

Token details:

  • Name: Akita Share Token
  • Symbol: ■AKITA
  • Contract: 0x44710150A469DE368Abc82F05e6217086Be84626
  • Chain: Base (chainId 8453)
  • Decimals: 18
  • Type: BASE / ERC20

Project:
Share token for the Akita creator vault on 4626.fun (Base).

Website: https://4626.fun
Explorer: https://basescan.org/token/0x44710150A469DE368Abc82F05e6217086Be84626
Metadata: https://4626.fun/tokens/akita-share-token.json
Logo (canonical): https://4626.fun/tokens/akita-share-token.png

Checklist:

  • Token contract is verified / live on Basescan
  • Logo is 256x256 PNG under 100KB
  • info.json contains required fields
  • Folder name matches EIP-55 checksummed contract address

Made with Cursor

sunitha1814 and others added 30 commits February 13, 2026 11:06
* chore: update Machines Cash dapp logo

* chore: update MACHINES token logo on Base

* chore: update MACHINES token metadata on Base

* chore: update MACHINES links/tags metadata

* chore: update MACHINES links to allowed names and productivity tag

* chore: add source_code link and retrigger metadata checks

* chore: use allowed tag and coinmarketcap URL format

* chore: retrigger token validator on latest metadata

* Rename 'twitter' to 'x' in info.json

---------

Co-authored-by: twhino <231496232+twhino@users.noreply.github.com>
Co-authored-by: tw-jt <231277539+tw-jt@users.noreply.github.com>
* Create info.json

* Create logo.png

* Update logo.png
Delete logo.png files for Ethereum token 0x57e299eE8F1C5A92A9Ed54F934ACC7FF5F159699 and Tron asset 1001411. Removes two binary logo assets from the repository as part of asset cleanup.
Update pump.fun DApp logo

[sc-120452]
* Mark FAKE FAKE KAT as FAKE

* Update info.json

---------

Co-authored-by: tw-jt <231277539+tw-jt@users.noreply.github.com>
Co-authored-by: TWmLorejo <214106588+TWmLorejo@users.noreply.github.com>
* Add four meme AI logo

[sc-120984]

* Enlarge logo
* Mark FAKE FAKE YELOOW as FAKE

* Update info.json
* Mark FAKE YELLOW as FAKE

* Update token symbol in info.json

---------

Co-authored-by: curiouschonk <146854853+curiouschonk@users.noreply.github.com>
Co-authored-by: TWmLorejo <214106588+TWmLorejo@users.noreply.github.com>
Add Aave asset metadata and logo files for Arbitrum, Avalanche (C-Chain) and xDai, and update existing AAVE entries across Ethereum, Fantom, Polygon, BSC (Smart Chain) and Solana. Changes standardize website/explorer fields, add research, tags and links (github, x, reddit, blog, facebook, whitepaper, coinmarketcap, coingecko), correct explorer IDs/casing, and replace several logo images. Purpose: unify and enrich AAVE token metadata across multiple chains for consistent display and discovery.

[sc-122587]
TelaW19 and others added 11 commits July 22, 2026 22:27
* Update Asset Names High Priority

[sc-149289]

* Normalize token names across blockchains

Simplify token names by removing network-specific prefixes/suffixes (e.g., "BNB pegged", "(PoS)", "Bridged ... (Sonic Labs)") and standardize names for well-known tokens like USDC, Tether, Chainlink, and others across Avalanche, Ethereum, Meter, Polygon, BSC, Solana, and Sonic.
[sc-149289] Update asset metadata and token lists to use current token and project display names across Ethereum, Arbitrum, Avalanche, Fantom, Optimism, BSC, Solana, and xDai. This aligns bridged and native entries with consistent branding such as Yearn, 1inch, Synthetix, CoW Protocol, SafePal, and Ondo market assets.
* Update token names across multiple chains

[sc-149289] Standardize and simplify token display names across Ethereum, BSC, Polygon, Avalanche, Arbitrum, Optimism, Fantom, Base, Solana, Tron, TON, Binance, and Oasis chains. Changes include removing verbose suffixes (e.g. 'Token', 'Network', 'Binance-Peg', 'Portal'), renaming Ondo tokenized assets by dropping 'ETF' from names, and updating deprecated names (e.g. 'UST Token' → 'TerraClassicUSD', 'ZigCoin' → 'ZIGChain', 'CertiK Token' → 'Shentu').

* Add (Portal) suffix to bridged token names

[sc-149289] Clarify that UST on Avalanche C-Chain, SLP and SPELL on Solana are Portal-bridged versions by appending "(Portal)" to their names.
* chore(kb): sdd-init scaffold

Requested-by: Maksim Alov (+71356433702)
Session: kbb-acadef63-assets-1784718319528
Feature-id: kbb-acadef63
Agent-role: kb-bootstrap

* chore(kb): sdd-knowledge --full build

Requested-by: Maksim Alov (+71356433702)
Session: kbb-acadef63-assets-1784718319528
Feature-id: kbb-acadef63
Agent-role: kb-bootstrap

* chore(kb): LLM deep-analysis enrichment + repo manifest

Requested-by: Maksim Alov (+71356433702)
Session: kbb-acadef63-assets-1784718319528
Feature-id: kbb-acadef63
Agent-role: kb-bootstrap

* chore(kb): finalize knowledge base bootstrap

Requested-by: Maksim Alov (+71356433702)
Session: kbb-acadef63-assets-1784718319528
Feature-id: kbb-acadef63
Agent-role: kb-bootstrap

* fix(ci): allow kb bootstrap files in root folder validation

Requested-by: Conductor Bot (conductor-bot)
Session: ci-mon-292456d0-ci-1784719035411
Feature-id: ci-mon-292456d0
Agent-role: ci-monitor

---------

Co-authored-by: Maksim Alov <maksim.alov@trustwallet.com>
Co-authored-by: Conductor Bot <conductor-bot@trustwallet.com>
Co-authored-by: Ivan B <82358585+tw-covain@users.noreply.github.com>
PR trustwallet#37428 committed local agent/spec-kit scaffolding that does not belong
in this repository. Removes:

- `.claude/` — agent slash commands, skills and generated repo manifest
- `.github/workflows/knowledge-sync.yml` — a docs-sync workflow that
  depends on infrastructure unavailable to this repository
- `.specify/` — spec-kit scripts and templates
- `.mcp.json` — MCP server registration

Also drops the corresponding entries from the root-folder allowlist in
`.github/assets.config.yaml` (`CLAUDE.md` and `knowledge/` stay — those
files remain), trims `CLAUDE.md` down to the parts that apply to this
repository, and removes three empty `knowledge/` placeholders that only
existed to mirror the deleted spec-kit workflow, fixing every link that
pointed at them.

No asset files, validation logic or CI checks are affected.
`make check` passes (48843 files, 0 errors).

Co-authored-by: Max Alov <>
@wenakita

Copy link
Copy Markdown
Author

Updated logo.png to the curated Akita portrait (256×256 PNG, under 100KB).

@wenakita
wenakita force-pushed the add-akita-share-token-base branch from 07129ae to f796b1f Compare July 31, 2026 17:46
Comment on lines +36 to +41
run: |
SYNC_OPTIONS="--follow-symlinks --delete --exclude '*' --include 'dapps/*' --include 'blockchains/*'"
if [ "${{ github.event.inputs.use-size-only }}" == "true" ]; then
SYNC_OPTIONS="$SYNC_OPTIONS --size-only"
fi
eval "aws s3 sync . s3://$AWS_S3_BUCKET $SYNC_OPTIONS"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Semgrep identified a blocking 🔴 issue in your code:

User-controlled github.event.inputs.use-size-only is interpolated directly into a run: step and used in eval, allowing command injection via workflow dispatch input.

More details about this

The run: step passes ${{ github.event.inputs.use-size-only }} directly into a conditional that modifies SYNC_OPTIONS, which is then used in an eval statement. This creates a command injection vulnerability.

Exploit scenario:

  1. An attacker opens a workflow dispatch request (which triggers on workflow_dispatch events) and provides a malicious value for the use-size-only input parameter
  2. The attacker sets use-size-only to: true"; malicious_command; echo "
  3. When the conditional evaluates if [ "${{ github.event.inputs.use-size-only }}" == "true" ], it becomes: if [ "true"; malicious_command; echo "" == "true" ]
  4. The shell parses this as three commands: [ "true", malicious_command, and echo ""
  5. The malicious_command executes with full access to the runner environment, including AWS_S3_BUCKET secret
  6. The attacker can now read secrets, exfiltrate code, or modify the repository

The real danger is that SYNC_OPTIONS is later used in eval, which interprets shell metacharacters. Even if the attacker can't break out of the conditional, they could inject options into SYNC_OPTIONS that cause unintended behavior.

To resolve this comment:

✨ Commit fix suggestion

Suggested change
run: |
SYNC_OPTIONS="--follow-symlinks --delete --exclude '*' --include 'dapps/*' --include 'blockchains/*'"
if [ "${{ github.event.inputs.use-size-only }}" == "true" ]; then
SYNC_OPTIONS="$SYNC_OPTIONS --size-only"
fi
eval "aws s3 sync . s3://$AWS_S3_BUCKET $SYNC_OPTIONS"
run: |
SYNC_OPTIONS="--follow-symlinks --delete --exclude '*' --include 'dapps/*' --include 'blockchains/*'"
if [ "$USE_SIZE_ONLY" = "true" ]; then
SYNC_OPTIONS="$SYNC_OPTIONS --size-only"
fi
eval "aws s3 sync . s3://$AWS_S3_BUCKET $SYNC_OPTIONS"
env:
AWS_S3_BUCKET: ${{ secrets.AWS_S3_BUCKET }}
USE_SIZE_ONLY: ${{ github.event.inputs.use-size-only }}
View step-by-step instructions
  1. Move the untrusted workflow input out of the run: script and into the step env: block, for example by adding USE_SIZE_ONLY: ${{ github.event.inputs.use-size-only }}.
  2. Replace the direct GitHub expression inside the shell script with the environment variable, changing the condition to if [ "$USE_SIZE_ONLY" = "true" ]; then.
  3. Keep the environment variable quoted everywhere you read it in the shell script, because "$USE_SIZE_ONLY" prevents shell metacharacters in the input from being interpreted as code.
  4. Leave AWS_S3_BUCKET in env: as it is, and keep shell variable references quoted where possible, for example aws s3 sync . "s3://$AWS_S3_BUCKET" ....
  5. Remove GitHub ${{ ... }} interpolation from this run: block entirely so the script only reads shell variables provided through env:.
💬 Ignore this finding

Reply with Semgrep commands to ignore this finding.

  • /fp <comment> for false positive
  • /ar <comment> for acceptable risk
  • /other <comment> for all other reasons

Alternatively, triage in Semgrep AppSec Platform to ignore the finding created by run-shell-injection.

You can view more details about this finding in the Semgrep AppSec Platform.

@wenakita

wenakita commented Aug 3, 2026

Copy link
Copy Markdown
Author

Superseded: #92 targeted abandoned remine-1 ShareOFT 0xcCC10Ec9282F66dd4e344DF52F5D670D10Fd4626 (Base only) and carried a large unrelated commit history.

Canonical remine-2 ■AKITA is 0xe7e44b29E966E3f77EF491fef0F663573Fd74626 (CREATE2 parity) plus Solana mint A6HB5FWRjknVuMXpuwupr6QjZpsRSS98nBb1DW9dAZsH.

Closing in favor of the clean multi-chain PR opened from wenakita:add-akita-share-token-remine2.

@wenakita

wenakita commented Aug 3, 2026

Copy link
Copy Markdown
Author

Closing in favor of remine-2 multi-chain PR (see comment above).

@wenakita wenakita closed this Aug 3, 2026
@wenakita

wenakita commented Aug 3, 2026

Copy link
Copy Markdown
Author

New PR: #94

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.