ability-analysis
Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth…
L1 supplement - audits Go modules and Rust crates for known vulnerabilities, outdated versions, supply chain risks, and replace/patch directives.
$ npx -y skills add PlamenTSV/plamen --skill dependency-audit-nodeclient --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/dependency-audit-nodeclientContext preview
The summary Claude sees to decide when to auto-load this skill.
L1 supplement - audits Go modules and Rust crates for known vulnerabilities, outdated versions, supply chain risks, and replace/patch directives.
name: "dependency-audit-nodeclient" description: "L1 supplement - audits Go modules and Rust crates for known vulnerabilities, outdated versions, supply chain risks, and replace/patch directives."
> **L1 trigger**: `L1_PATTERN=true` — always runs > **Inject Into**: Recon + any breadth agent > **Finding prefix**: `[DEP-N]` > **Status**: v0.1 draft, Round 4 exemplars pending
Always active in L1 mode. Extends Plamen's existing `dependency-audit` skill with Go/Rust-specific checks relevant to node clients.
Tag: `[GO-REPLACE:{original}:{replacement}:{trust-note}]`
Tag: `[GO-VENDOR-DIFF:{module}]`
Tag: `[RS-PATCH:{original}:{replacement}:{trust-note}]`
Tag: `[RS-GIT-DEP:{crate}:{rev-pinned}]`
Patterns that warrant deeper review across both ecosystems:
1. **Typosquatting**: check for dep names that are one character off common names (e.g., `tokio-util` vs `tokio-utils`) 2. **Recently created deps with large version numbers**: `1.0.0` published 2 weeks ago is suspicious 3. **Deps maintained by a single individual with no org backing**: not a bug per se, but worth flagging for critical-path deps 4. **Deps with obvious abandonment signals**: last commit >2 years ago on a security-critical dep 5. **Deps with known compromises**: cross-reference against the `event-stream` / `ua-parser-js` / `xz-utils` class of events
Tag: `[SUPPLY-CHAIN:{dep}:{concern}]`
These deps are security-critical for L1 clients and deserve extra scrutiny:
For each of these in the target, report: version, whether it's current, any recent advisories.
Tag: `[VERSION-DRIFT:{dep}:{pin-status}]`
1. **BNB Chain bridge $100M+ loss (October 2022)** — root cause: unmaintained IAVL Merkle proof library consumed by the BNB bridge. Dragonberry-class verification flaw in the shared library. Single unmaintained dependency, catastrophic impact. [Halborn writeup](https://www.halborn.com/blog/post/explained-the-bnb-chain-hack-october-2022). **Skill catch point**: Section 3 — unmaintained cryptographic library flag. Last commit >2 years ago on a security-critical dep = automatic finding.
2. **Moonbeam / Astar / Acala shared `paritytech/frontier` bug (~$200M at risk, 2022-2023)** — single shared dependency blew up across 3 projects. The Immunefi $1M bugfix review covers the initial Moonbeam discovery; Zellic re-discovered the same class in Astar 18 months later after the library was patched. [Immunefi Moonbeam/Astar/Acala review](https://medium.com/immunefi/moonbeam-astar-and-acala-library-truncation-bugfix-review-1m-payout-41a862877a5b); [Zel
Autonomous Web3 security auditor for Claude Code and OpenAI Codex CLI. Orchestrates 18-100 AI agents across 40+ phases to produce audit reports with verified PoC exploits — for smart contracts and L1 node-client infrastructure.
Repo: PlamenTSV/plamen
Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth…
Trigger Pattern Always (Aptos Move) - Move VM aborts on shift = bit width - Inject Into…
Trigger Protocol has privileged roles (admin, operator, governance, resource account owner) -…
Trigger EXTERNAL_LIB flag detected (protocol uses third-party Move dependencies) - Used by…
Trigger Pattern MONETARY_PARAMETER flag (required) - Inject Into Breadth agents (merged via…