ability-analysis
Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth…
Trigger Pattern Always required for Soroban audits - Inject Into Breadth agents, depth agents
$ npx -y skills add PlamenTSV/plamen --skill auth-validation --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/auth-validationContext preview
The summary Claude sees to decide when to auto-load this skill.
Trigger Pattern Always required for Soroban audits - Inject Into Breadth agents, depth agents
name: "auth-validation" description: "Trigger Pattern Always required for Soroban audits - Inject Into Breadth agents, depth agents"
> **Trigger Pattern**: Always required for Soroban audits > **Inject Into**: Breadth agents, depth agents > **Finding prefix**: `[AV-N]` > **Rules referenced**: R4, R6, R10, R13
Soroban's authorization model differs fundamentally from EVM: instead of `msg.sender`, callers invoke `require_auth()` or `require_auth_for_args()` on an `Address`. Missing or incorrectly scoped auth is the most common critical bug class on Soroban.
For EVERY `pub fn` in each contract, determine whether it modifies state and whether auth is present:
| Function | Modifies State? | Modifies Balance/Config/Ownership? | `require_auth` Present? | Auth Address | Missing? | |----------|----------------|-------------------------------------|------------------------|-------------|----------| | `{fn_name}` | YES/NO | YES/NO | YES/NO | `{address_var or NONE}` | FLAG if modifies state but NO auth |
**Critical patterns to flag**:
**Soroban note**: `require_auth()` panics if the address has not authorized the invocation. It does NOT return a bool — absence means the call proceeds without authorization.
When a contract calls another contract via `invoke_contract`, the auth context must propagate to sub-calls. Trace each cross-contract invocation:
| Calling Fn | Sub-Contract Invocation | Auth Expected in Sub-Call? | `AuthorizedInvocation` Provided? | Sub-Call Protected? | |------------|------------------------|---------------------------|----------------------------------|---------------------| | `{fn}` | `invoke_contract({contract}, {fn})` | YES/NO | YES/NO | YES/NO |
**Attack surface**: If a top-level function calls `require_auth(user)` but then invokes a sub-contract on behalf of the user without passing the correct `AuthorizedInvocation` tree, the sub-contract cannot verify the user actually authorized the sub-call.
**Check for**:
For any contract implementing the `CustomAccountInterface` (contains `__check_auth`):
| Check | Present? | Correct? | Notes | |-------|----------|---------|-------| | Signature verification against stored public keys | YES/NO | YES/NO | | | Replay protection (nonce or sequence number) | YES/NO | YES/NO | | | Signature threshold enforcement (multi-sig) | YES/NO | YES/NO | | | `context.signature_payload` used (not raw payload) | YES/NO | YES/NO | | | Auth invocation tree validated against expected function | YES/NO | YES/NO | |
**Critical**: `__check_auth` is called by the host to verify whether an address has authorized an invocation. Bugs here allow bypassing authorization for ALL operations that use this account contract.
**Specific checks**:
`require_auth_for_args` binds authorization to specific argument values. Verify the correct arguments are passed:
| Function | Uses `require_auth_for_args`? | Arguments Passed | Arguments That Should Be Bound | Mismatch? | |----------|------------------------------|-----------------|-------------------------------|-----------| | `{fn}` | YES/NO | `{args list}` | `{expected critical args}` | FLAG if mismatch |
**Attack**: If `approve(spender, amount)` calls `require_auth_for_args(owner, (spender, wrong_amount))`, an attacker can get the owner to authorize a small amount but then pass a larger amount in the actual call.
**Pattern to check**:
Autonomous Web3 security auditor for Claude Code and OpenAI Codex CLI. Orchestrates 18-100 AI agents across 40+ phases to produce audit reports with verified PoC exploits — for smart contracts and L1 node-client infrastructure.
Repo: PlamenTSV/plamen
Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth…
Trigger Pattern Always (Aptos Move) - Move VM aborts on shift = bit width - Inject Into…
Trigger Protocol has privileged roles (admin, operator, governance, resource account owner) -…
Trigger EXTERNAL_LIB flag detected (protocol uses third-party Move dependencies) - Used by…
Trigger Pattern MONETARY_PARAMETER flag (required) - Inject Into Breadth agents (merged via…