ability-analysis
Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth…
Trigger Pattern MONETARY_PARAMETER flag (required) - Inject Into Breadth agents (merged via M4 hierarchy)
$ npx -y skills add PlamenTSV/plamen --skill economic-design-audit --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/economic-design-auditContext preview
The summary Claude sees to decide when to auto-load this skill.
Trigger Pattern MONETARY_PARAMETER flag (required) - Inject Into Breadth agents (merged via M4 hierarchy)
name: "economic-design-audit" description: "Trigger Pattern MONETARY_PARAMETER flag (required) - Inject Into Breadth agents (merged via M4 hierarchy)"
> **Trigger Pattern**: MONETARY_PARAMETER flag (required) > **Inject Into**: Breadth agents (merged via M4 hierarchy) > **Purpose**: Analyze admin-settable economic parameters (fees, rates, thresholds, emission schedules) for boundary violations, invariant breaks, interaction extremes, and fee formula correctness
For every monetary parameter setter (rate, rebase, supply, mint, burn, emission, inflation, peg, price cap/floor, fee, reward rate) in the protocol:
| Parameter | Setter Function | Min Value | Max Value | Enforced? | Impact at Min | Impact at Max | |-----------|----------------|-----------|-----------|-----------|---------------|---------------| | {param} | {set_fn} | {min} | {max} | YES/NO | {impact} | {impact} |
For each parameter: substitute min and max into ALL consuming functions. Tag: [BOUNDARY:param=val -> outcome]
**Aptos-specific checks**:
List all economic invariants the protocol must maintain:
| Invariant | Parameters Involved | Can Admin Break It? | Functions That Assume It | |-----------|-------------------|--------------------|-----------------------| | total_supply == sum(all_balances) | mint/burn params | YES/NO | {fn list} | | fees < principal | fee_rate | YES/NO | {fn list} | | collateral_ratio >= min_ratio | ratio_param | YES/NO | {fn list} | | rewards_distributed <= rewards_pool | emission_rate | YES/NO | {fn list} |
For each setter: can changing this parameter break an invariant that user-facing functions depend on? If yes -> finding.
**Aptos-specific invariants**:
For protocols with multiple monetary parameters that interact:
| Parameter A | Parameter B | Interaction | Can A*B Produce Extreme Output? | |-------------|-------------|-------------|-------------------------------| | {param_a} | {param_b} | {relationship} | YES/NO: {at what values} |
Check: can two independently-valid parameter settings combine to create an extreme or invalid economic state? (Rule 14 constraint coherence)
**Examples**:
For every fee-related computation (fee calculation, fee deduction, fee distribution):
Pick 3 representative fee rates (e.g., 1% = 100 BPS, 5% = 500 BPS, 10% = 1000 BPS) and trace through the actual code formula:
| Fee Param | Value | Formula | Input Amount | Expected Output | Actual Output | Match? | |-----------|-------|---------|-------------|----------------|---------------|--------| | {fee_bps} | 100 | {code formula} | 1_000_000_00 (1e8) | {expected} | {computed} | YES/NO | | {fee_bps} | 500 | {code formula} | 1_000_000_00 (1e8) | {expected} | {computed} | YES/NO | | {fee_bps} | 1000 | {code formula} | 1_000_000_00 (1e8) | {expected} | {computed} | YES/NO |
Tag: `[BOUNDARY:fee_bps={val} -> effective_rate={computed_rate}]`
**Red flags**:
For protocols with multiple fee types:
| Fee A | Fee B | A Output Feeds B Input? | Combined Effective Rate | Independent Rate Sum | Discrepancy? | |-------|-------|------------------------|------------------------|---------------------|-------------|
If the protocol uses share-based accounting (vaults, LP tokens):
For every fee computation, trace the base amount (the value the fee is computed on) through ALL subsequent code paths:
| Fee Site | Base Amount Variable | Modified After Fee? | Modified How | Fee Recomputed? | Overcharge? | |----------|---------------------|--------------------:|-------------|-----------------|-------------|
**Methodology**:
Autonomous Web3 security auditor for Claude Code and OpenAI Codex CLI. Orchestrates 18-100 AI agents across 40+ phases to produce audit reports with verified PoC exploits — for smart contracts and L1 node-client infrastructure.
Repo: PlamenTSV/plamen
Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth…
Trigger Pattern Always (Aptos Move) - Move VM aborts on shift = bit width - Inject Into…
Trigger Protocol has privileged roles (admin, operator, governance, resource account owner) -…
Trigger EXTERNAL_LIB flag detected (protocol uses third-party Move dependencies) - Used by…
Trigger Pattern Any external module interaction detected in attack_surface.md - Inject Into…