credential-pooling-analysis skill
Analyze credential pooling operations and API reseller business models — economics, risks, detection patterns, and sustainability
Is the credential-pooling-analysis skill safe?
Clean: nothing in its files matched our rules. We read 3 files in the folder on 2026-09-28.
No findings.
Install the credential-pooling-analysis skill
A skill is a folder. Copy it into your agent's skills folder and the agent loads it when the task matches its description.
git clone --depth 1 https://github.com/kevinnft/ai-agent-skills.git /tmp/ai-agent-skills mkdir -p ~/.claude/skills cp -r /tmp/ai-agent-skills/skills/research/credential-pooling-analysis ~/.claude/skills/credential-pooling-analysis
In the Claude apps, zip the folder and upload it from the Skills settings. The folder on GitHub
The instructions your agent would load
SKILL.md as published, without the frontmatter. Read it on GitHub
Credential Pooling Analysis
Framework for analyzing API reseller operations that use credential pooling (bulk account creation → free tier exploitation → resell access at markup).
What is Credential Pooling?
Definition: Acquiring many free/trial accounts from a service, pooling their credits/quotas, and reselling access to end-users at a markup.
Common pattern:
User → Reseller API → Credential Pool (100s of accounts) → Official API (Claude/GPT/etc)Economics:
- Input: Bulk accounts (e.g., 100 Google accounts = $1-2)
- Multiplier: Each account gets $5-10 free credits
- Output: $500-1000 total credits
- Markup: Sell at 50-70% of official API price
- ROI: 50-100x return on account cost
Analysis Framework
1. Identify the Operation
Signals that indicate credential pooling:
✅ Pricing signals:
- Significantly cheaper than official API (30-70% discount)
- Credit-based, not subscription
- "No subscription, just credits" messaging
- Prices that don't match any official tier
✅ Technical signals:
- Unified API for multiple providers (Claude + GPT + Gemini in one endpoint)
- OpenAI-compatible API (drop-in replacement)
- Frequent "maintenance" or "rate limit" messages
- Inconsistent response times
✅ Business signals:
- New/small operation (not official partner)
- Located in regions with cheap bulk accounts (Indonesia, India, etc)
- Telegram/Discord-only support (no official business presence)
- Vague about "how we get access"
2. Scrape and Extract Data
Target pages:
- Homepage (tagline, value prop)
- Pricing page (model list, credit costs)
- Docs (API endpoints, authentication)
- About/Contact (location, team, legitimacy signals)
Use escalation ladder (see cloud-browser-automation skill):
- Try web_fetch first
- Try direct curl with headers
- Try Hermes browser
- Use Browserbase if Cloudflare-protected
Key data to extract:
{
"site": "example.com",
"tagline": "...",
"models": ["claude-opus-4", "gpt-5", ...],
"pricing": {"claude-opus-4": "$X per 1M tokens"},
"features": ["streaming", "openai-compatible", ...],
"contact": {"email": "...", "discord": "...", "telegram": "..."},
"location": "...",
"legal_docs": ["terms", "privacy", ...]
}3. Economic Analysis
Calculate unit economics:
# Input costs
accounts_cost = 100 * 0.02 # $2 for 100 Google accounts
credits_per_account = 7.5 # $7.50 average free credits
total_credits = 100 * credits_per_account # $750
# Output revenue
markup = 0.5 # 50% of official price
official_price = 1.0
reseller_price = official_price * markup
revenue = total_credits / reseller_price # How much they can sell
# Profit
profit = revenue - accounts_cost
roi = profit / accounts_costKey metrics:
- ROI: Return on investment (target: 20-100x)
- Burn rate: How fast credits deplete
- Ban rate: % of accounts that get banned
- Sustainability: Can they maintain supply?
4. Risk Assessment
Operational risks:
Provider-specific ban rates (from user's data):
- Kiro: 58% ban rate (AWS actively blocks third-party harness)
- CodeBuddy: 0% ban rate (Tencent detection weak)
- Cursor: Unknown (not tested)
Detection signals providers look for:
- Same IP for many accounts
- Identical usage patterns
- Rapid sequential requests
- Unusual geographic distribution
- API key sharing patterns
5. Sustainability Analysis
Short-term (0-6 months):
- ✅ Highly profitable (ROI 50-100x)
- ✅ Easy to scale (bulk accounts cheap)
- ⚠️ High churn (ban rate 30-60%)
Medium-term (6-18 months):
- ⚠️ Provider detection improves
- ⚠️ Free tiers get restricted
- ⚠️ Competition increases (price war)
Long-term (18+ months):
- ❌ Unsustainable (providers close loopholes)
- ❌ Legal risk increases
- ❌ Need to pivot to legitimate model
6. Competitive Analysis
Compare multiple operations:
| Operator | Models | Pricing | Location | Stage | Risk Level |
|----------|--------|---------|----------|-------|------------|
| adye.dev | 7 models | 50% off | Unknown | Operational | High |
| enowxlabs.com | Unknown | Unknown | Indonesia | Beta | Medium |Differentiation strategies:
- Price: Race to bottom (unsustainable)
- Reliability: Better uptime (requires more accounts)
- Features: Better API, docs, support
- Niche: Specific models or use cases
Common Patterns
Pattern 1: Pure API Reseller (adye.dev style)
Characteristics:
- Direct API proxy
- Multiple models in one endpoint
- Credit-based pricing
- Minimal branding
Pros:
- Simple to build
- Fast to market
- High margins
Cons:
- Commodity (easy to copy)
- High ban risk
- No moat
Pattern 2: Software Marketplace (enowxlabs.com style)
Characteristics:
- Platform for developer tools
- Built-in licensing system
- API access as backend
- More legitimate appearance
Pros:
- Better optics (not just reseller)
- Multiple revenue streams
- Harder to shut down
More skills from kevinnft/ai-agent-skills
- Aaddyosmani-tddDrives development with tests. Use when implementing any logic, fixing any bug, or changing any behavior. Use when you need to prove that code works, when a bug report arrives, or when you're about to modify existing functionality.
- AairtableAirtable REST API via curl. Records CRUD, filters, upserts.
- Aapi-and-interface-designGuides stable API and interface design. Use when designing APIs, module boundaries, or any public interface. Use when creating REST or GraphQL endpoints, defining type contracts between modules, or establishing boundaries between frontend and backend.
- Aapi-monitoring-botsBuild monitoring bots that poll APIs and send notifications on state changes (new listings, price alerts, status updates)
- Aapple-notesManage Apple Notes via memo CLI: create, search, edit.
- Aapple-remindersApple Reminders via remindctl: add, list, complete.
- Aarchitecture-diagramDark-themed SVG architecture/cloud/infra diagrams as HTML.
- AarxivSearch arXiv papers by keyword, author, category, or ID.
- Aascii-artASCII art: pyfiglet, cowsay, boxes, image-to-ascii.
- Aascii-videoASCII video: convert video/audio to colored ASCII MP4/GIF.
- AaudiocraftAudioCraft: MusicGen text-to-music, AudioGen text-to-sound.
- CaxolotlAxolotl: YAML LLM fine-tuning (LoRA, DPO, GRPO).