# Brief for External LLM — Mech #2 Crypto Security Audit (paste this whole thing)

## Role you're playing

You are a senior growth strategist for a small dev/security SaaS company. You are NOT generic; you are a skeptic who challenges the founder's plan. The goal is to produce a brutal reality-check on the current strategy + 3 concrete actions for the next 48 hours.

The founder reads dense text and prefers no fluff. Tables and ranked lists are fine. Tone: direct, even if uncomfortable. **No marketing-speak**.

---

## Company snapshot (GuardLabs)

- **What we sell:** small SaaS tools for security/dev audience (WordPress maintenance "Care" $39-99/mo, crypto trading course "nexus-bot.pro" $199-600 one-time, gamified Q&A app "AskOracle" with in-app currency 💎).
- **Brand law (self-imposed):** "we sell shovels, not gold" — tools for developers/traders, not financial advice or get-rich content.
- **Audience (real, measured):** Python/security/DevOps developers, crypto-curious traders (mostly Telegram + YouTube short-form consumers), small-business WordPress owners. Mixed RU/EN/ES — RU is largest, EN growing.
- **Distribution channels touched:** DevTo, Hashnode, WordPress.com, Blogspot ×3 domains, YouTube ×3 channels (Sspoisk = main organic, GuardLabs Studio, GuardLabs ES), Telegram bot @CryptoOracleNexusBot, Binance Square, X/Twitter (@sspoisk, 13 followers).
- **Failed channels recently:** X free tier (402 Payment Required), Hashnode (Cloudflare bot block 1010), WordPress.com REST (endpoint disabled).
- **Team:** 1 founder + Claude (me, the AI dev). Founder is asleep right now — I'm running operations autonomously.
- **Budget:** $0 default, $50 quick-test cap, $200+ requires founder approval next morning.
- **Latest revenue signals:** 0 sales today. Last week ~$0 from new channels. Existing course gets ~$50-300/wk organic.

---

## The new product (shipped 2026-05-15 — 4 hours ago)

**Name:** AskOracle Crypto Security Audit (internally "Mech #2")
**URL:** https://askoracle.site/audit  (RU + EN + ES)
**Upsell URL:** https://guardlabs.online/care/audit-pro/  ($49 manual audit)

**What it does:** 12-question crypto security hygiene scan. AI scores user 0-100 across 4 categories (wallet / 2FA / DeFi / operational), names top-3 vulnerabilities with real 2024-25 incident-case anchors (Inferno Drainer, Lazarus SIM-swap, address poisoning) and specific tool fixes (revoke.cash, YubiKey 5C, Cryptosteel, SimpleLogin).

**Pricing model:**
- Free for users with ≥500💎 of AskOracle activity (existing in-app currency)
- $49 one-time for full manual audit by a human engineer (wallet forensics + phishing test + custom playbook)
- Optional email capture after scan → drip-sequence (T0 / T+3d / T+7d) leading to course at nexus-bot.pro

**Tech stack:** Flask + Postgres + multi-LLM fallback (Groq×5 → DeepSeek → Vertex Pro CLI → deterministic template). Total cost shipped: $0.

**Cost to build:** ~$0.05 LLM committee + 2 hours work.

---

## What I've done in the last 4 hours (distribution push)

| Action | Status |
|---|---|
| Published DevTo engineering article | ✅ live, 12 views |
| Cross-posted to 3 Blogspot blogs (guardlabs / askoracle / nexus-bot) | ✅ live |
| Updated 4 viral YouTube shorts descriptions (Ep.6 Sneaky Bug 268% APV / Ep.7 Aunt Nastya 144%) with /audit CTA | ✅ live |
| Generated 6 NEW "Bug Universe" cartoon shorts (Veo, $12) — same winning format | ✅ uploaded × 2 channels = 12 new videos with /audit funnel |
| Added /audit command to Telegram bot @CryptoOracleNexusBot | ✅ live |
| Added "🛡 АУДИТ" button to AskOracle main nav | ✅ live |
| Pushed 3 URLs to Google Search Console Indexing API | ✅ 200 OK |
| Built daily KPI tracker (cron 07:30 UTC) | ✅ live |
| Built drip-sequence script (Gmail OAuth, test/live modes) | ⚠ ready, needs founder to approve Gmail send scope |
| Failed to publish to: Hashnode (bot block), WordPress.com (endpoint disabled), X (out of credits), GuardLabs Studio YT (token scope refresh fail) | ❌ logged |

---

## Current measured state

- **DevTo article views:** ~12 (baseline only)
- **/audit completions all-time:** 0 (just shipped, only my E2E tests cleaned up)
- **Email captures:** 0
- **/care/audit-pro/ unique hits:** ~6-8 human (60+ bots — my own monitoring)
- **Sspoisk Ep.6 YouTube views:** 950 (was 909 before update — slow growth)
- **Bug Universe v2 (just uploaded):** 0 views, will know in 24h
- **Revenue from Mech #2 since launch:** $0

---

## Reality-check thresholds I set (deadline 2026-05-17 19:30 UTC = 48h)

- DevTo views ≥ 100 → keep using DevTo
- /care/audit-pro/ unique visitors ≥ 20 → funnel works
- /audit completions ≥ 5 → demand validated
- Revenue $49 sale ≥ 1 → unit economics proven
- Bug Universe v2 total views ≥ 500 → format scales

---

## What the founder wants from you

**Three questions. Answer all three. Be brutal.**

### Q1. Reality probability
Given the audience profile, the channels touched, the current baseline, and the 48-hour window — what's the **realistic probability of hitting each KPI threshold above**? Express as % with one-sentence reasoning per threshold. If you think a threshold is fantasy, say so.

### Q2. Hidden flaw
What's the **most likely thing the founder is missing** about why this product won't sell? Pick exactly ONE — the one that, if true, makes the whole exercise futile. Examples of the kind of flaw I mean: "your audience isn't actually crypto-holders, they're aspirational traders who don't have $50k to protect," or "the AI report is good but $49 is the wrong price point for this audience — the impulse-buy ceiling is $19," or "Mech #2 competes with free Etherscan-style tools and lost before launch."

Be willing to say "the entire strategy is wrong." That's a valid answer if you can defend it.

### Q3. Top-3 actions for next 48 hours
The founder has 48 hours, a $50 budget, and access to: Claude (me, autonomous), Veo for video, Gmail OAuth, Postgres, YouTube×3 channels, 3 Blogspot blogs, Telegram bot, DevTo, the existing course email list (size unknown, likely <500), 1 viral YouTube video with 950+ views (Ep.6 Sneaky Bug, 268% APV).

Rank top-3 actions by **probability of producing a paying customer within 48 hours**, not by "growth potential" or "long-term value." Each action: one-sentence what + one-sentence why it might fail.

DO NOT recommend:
- Generic SEO content (we have a separate stream for that)
- "Build community on Discord" (1-person team)
- "Wait and gather data" (data is collected, decisions needed now)
- Anything that requires the founder to talk on camera (he's introverted)
- Hashnode (already blocked us)
- Twitter ads (account out of credits)

DO consider:
- Reddit posts (account is aged, no spam history)
- Hacker News submission (account is 5+ years old)
- Telegram crypto-channel outreach (manual DM-ing 5-10 channel admins)
- Producthunt launch (kit ready, can launch in 1-2 days)
- Email-blasting existing course subscriber list with a "first 10 free manual audits" offer
- Cold-DM 5-10 indie hackers on X who recently posted about crypto security

---

## What "right answer" looks like

A response that:
1. Names a specific probability for each KPI
2. Picks ONE concrete hidden flaw (no hedging with "could be multiple things")
3. Ranks 3 actions with realistic failure modes for each
4. Is under 600 words total
5. Doesn't end with "what do you want me to do next" (decision goes back to founder)

---

## Optional context if you ask

If you want extra data, I can paste any of:
- The actual 12 audit questions and weights
- The AI report system prompt
- The Producthunt launch kit
- The Reddit post drafts
- The drip-sequence email templates
- Past 3 months of failed product launches and what we learned

Don't ask for it preemptively — only if your answer genuinely depends on it.

---

End of brief. Respond now.
