gstack/review/lenses/incentive-abuse.md

3.0 KiB

lens cli_aliases status summary primary_skill supported_skills severity ranking scope_disclaimer required_artifacts optional_artifacts required_context optional_context allowed_evidence_kinds on_missing_required_evidence invocation_triggers evidence_threshold materiality_threshold escalation_policy autofix_policy safety_directive
incentive-abuse
bad-faith-user
DRAFT Finds product states and economic incentives that make repeated user abuse rational, scalable, or cheap.
/review
/plan-eng-review
SYSTEMIC_ABUSE
FINANCIAL_ABUSE
ACCESS_BYPASS
INCENTIVE_EXPLOIT
MODERATION_GAP
expected user payoff divided by user cost, multiplied by repeatability Defensive incentive-abuse review. It does not provide payloads, evasion procedures, or step-by-step exploitation instructions.
diff_or_plan
state_transition_model
pricing_rules
abuse_controls
identity_model
incentive_structure
business_model
target_customer
file_line
file_range
cross_file
missing_control
missing_record
policy_mismatch
unmeasured_claim
INSUFFICIENT_EVIDENCE
path_globs semantic_triggers
**/credits/**
**/trials/**
**/refunds/**
**/referrals/**
**/promotions/**
**/rewards/**
**/moderation/**
**/entitlements/**
**/rate-limit*/**
**/recovery/**
pr_label=incentive-surface
file_metadata=@surface:incentive
user_declared=incentive-surface
STRONG_OR_MODERATE MATERIAL_OR_BLOCKING ADVISORY_PLUS_MATERIAL ask_always Identify abuse conditions, economic incentives, detection gaps, and controls. Do not provide harmful payloads, evasion procedures, or step-by-step exploitation instructions.

==== LENS PROMPT START | INCENTIVE ABUSE ====

When I use this lens

I use this lens for credits, trials, refunds, referrals, promotions, rewards, disputes, quotas, marketplaces, moderation, identity recovery, paid resources, entitlements, reputation systems, and any workflow where a user can gain value while imposing cost on the platform.

Objective

Identify where a rational user can manipulate incentives, edge cases, state transitions, or trust boundaries to obtain money, access, influence, compute, data, service, or preferential treatment beyond what the product intends.

Search strategy

Look for replayable actions, duplicate submissions, UI-only limits, client-controlled economic state, invalid transition ordering, low-cost automation, identity resets, weaponized disputes or appeals, partial-completion value, unbounded platform cost, weak anomaly detection, and enforcement that does not survive account recreation.

A valid finding must identify the user payoff, platform cost, scaling condition, detection gap, and smallest preventive, detective, economic, or recovery control.

Use middle_fields: abuse_scenario, user_payoff, platform_cost, scaling_condition, detection_gap.

Use severities: SYSTEMIC_ABUSE, FINANCIAL_ABUSE, ACCESS_BYPASS, INCENTIVE_EXPLOIT, MODERATION_GAP.

==== LENS PROMPT END | INCENTIVE ABUSE ====