Security
Threat model
Who might attack a pool with rules, and what stops them.
Snipers at open
Bots buying in the first block. Mitigated by Snipe Guard's per-block cap and guard tax.
A creator changing rules later
Mitigated by freezing every parameter at creation. RuleCraftHook has no owner and no function that edits a live pool.
A creator pulling liquidity
Mitigated by Liquidity Timelock on the founding position, which the launcher holds and releases only to the creator after the unlock time. The unlock time is readable on the pool page before buying.
An admin taking funds
There is none to take them. No contract has an owner; the launcher's one-time setHook only wires the hook, and the treasury and protocol share are fixed in the registry constructor.
Look-alike hooks
Anyone can deploy a hook and call it anything. Check the hook address against the published RuleCraftHook address on the contracts page.
Front-end compromise
Your wallet shows what you sign. Contract addresses are listed in the docs, the footer and on chain; compare before signing.