ability-analysis
Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth…
Type Thought-template (instantiate before use) - Trigger Pattern CROSS_CHAIN_MSG flag detected (protocol RECEIVES cross-chain messages)
$ npx -y skills add PlamenTSV/plamen --skill cross-chain-message-integrity --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/cross-chain-message-integrityContext preview
The summary Claude sees to decide when to auto-load this skill.
Type Thought-template (instantiate before use) - Trigger Pattern CROSS_CHAIN_MSG flag detected (protocol RECEIVES cross-chain messages)
name: "cross-chain-message-integrity" description: "Type Thought-template (instantiate before use) - Trigger Pattern CROSS_CHAIN_MSG flag detected (protocol RECEIVES cross-chain messages)"
> **Type**: Thought-template (instantiate before use) > **Trigger Pattern**: CROSS_CHAIN_MSG flag detected (protocol RECEIVES cross-chain messages) > **Inject Into**: Breadth agents, depth-external > **Finding prefix**: `[CMI-N]` > **Rules referenced**: R1, R2, R4, R8, R10
Covers: message endpoint authentication, peer/remote verification, replay protection, payload validation, and message ordering for bridge-receiving protocols.
This skill is SEPARATE from CROSS_CHAIN_TIMING (which covers stale state and latency arbitrage for L2 interactions). Use this skill when the protocol RECEIVES and PROCESSES inbound cross-chain messages. Use CROSS_CHAIN_TIMING when the protocol READS state synced across chains.
---
lzReceive|_ccipReceive|receiveWormholeMessages|onOFTReceived| setPeer|setTrustedRemote|_nonblockingLzReceive|executeMessage| _processMessageFrom|ILayerZeroReceiver|IAny2EVMMessageReceiver| endpoint.*receive|bridge.*receive|relayer.*deliver|_lzReceive
---
For each function that processes inbound cross-chain messages:
| # | Function | Bridge Protocol | Source Auth? | Payload Validated? | State Modified | Access Control | |---|----------|----------------|-------------|-------------------|----------------|---------------|
For each entry:
---
For EACH message-receiving function:
| # | Check | Status | Location | |---|-------|--------|----------| | 1 | `msg.sender == endpoint/router` verified | YES/NO | {line} | | 2 | Endpoint address immutable or admin-protected | YES/NO | {line} | | 3 | Modifier checks the CORRECT address variable | YES/NO | {line} |
**Missing caller check → CRITICAL**: Anyone can fabricate message data and trigger mints/unlocks.
| # | Check | Status | Location | |---|-------|--------|----------| | 1 | Source chain ID validated against allowed set | YES/NO | {line} | | 2 | Source sender validated against registered peer | YES/NO | {line} | | 3 | BOTH checks present (chain AND sender) | YES/NO | {line} |
**Pattern**: Checks `_origin.srcEid` (chain) but not `_origin.sender` (peer) → accepts messages from ANY contract on allowed chains.
---
For each function that configures trusted peers/remotes:
| # | Check | Status | Location | |---|-------|--------|----------| | 1 | Access-controlled (onlyOwner/multisig/timelock) | YES/NO | {line} | | 2 | Validates new peer is non-zero | YES/NO | {line} | | 3 | Emits event for off-chain monitoring | YES/NO | {line} | | 4 | Timelock/delay on peer changes | YES/NO | {line} |
Tag: `[TRACE:setPeer(chain={X}) → access={check} → zero_check={YES/NO} → default_peer={value}]`
---
| # | Check | Status | Location | |---|-------|--------|----------| | 1 | Each message processed exactly once | YES/NO | {line} | | 2 | Replay check BEFORE state changes | YES/NO | {line} | | 3 | Out-of-order messages handled | YES/NO | {line} | | 4 | Sequence gaps handled gracefully | YES/NO | {line} |
Tag: `[TRACE:message_nonce={N} → replay_check={method} → before_state_change={YES/NO}]`
---
For each decoded value:
If message triggers execution of decoded calldata:
Tag: `[BOUNDARY:payload_amount={MAX} → decoded → processed_as={result}]`
---
Autonomous Web3 security auditor for Claude Code and OpenAI Codex CLI. Orchestrates 18-100 AI agents across 40+ phases to produce audit reports with verified PoC exploits — for smart contracts and L1 node-client infrastructure.
Repo: PlamenTSV/plamen
Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth…
Trigger Pattern Always (Aptos Move) - Move VM aborts on shift = bit width - Inject Into…
Trigger Protocol has privileged roles (admin, operator, governance, resource account owner) -…
Trigger EXTERNAL_LIB flag detected (protocol uses third-party Move dependencies) - Used by…
Trigger Pattern MONETARY_PARAMETER flag (required) - Inject Into Breadth agents (merged via…