ability-analysis
Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth…
Trigger 15 events detected in recon event_definitions.md (optional skill) - Used By breadth agents (assigned to core state or dedicated agent)
$ npx -y skills add PlamenTSV/plamen --skill event-correctness --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/event-correctnessContext preview
The summary Claude sees to decide when to auto-load this skill.
Trigger 15 events detected in recon event_definitions.md (optional skill) - Used By breadth agents (assigned to core state or dedicated agent)
name: "event-correctness" description: "Trigger 15 events detected in recon event_definitions.md (optional skill) - Used By breadth agents (assigned to core state or dedicated agent)"
> **Trigger**: >15 events detected in recon event_definitions.md (optional skill) > **Used By**: breadth agents (assigned to core state or dedicated agent) > **Purpose**: Verify emitted event parameters match actual state changes
From `{SCRATCHPAD}/emit_list.md`, extract every `emit` statement with:
For EACH emit statement, verify:
| # | Check | Question | |---|-------|----------| | 1 | **Value accuracy** | Does each parameter reflect the ACTUAL post-operation state? (not a stale pre-operation value, not an input parameter that was modified before use) | | 2 | **Index correctness** | If the event indexes an entity (ID, address, index), is the index the CORRECT entity? (not off-by-one, not a different entity's ID, not a loop variable after increment) | | 3 | **Ordering** | Is the emit placed AFTER all state changes it describes? (not before a conditional that could change the values) | | 4 | **Conditional coverage** | If the function has branching logic, does EVERY branch that modifies state emit the appropriate event? (no silent state changes) | | 5 | **Parameter count** | Do the emitted parameters match the event definition? (Solidity allows emitting fewer params - missing params default to zero) | | 6 | **Semantic correctness** | Does each emitted variable match the SEMANTIC INTENT of the parameter name? If the event parameter is named `tokensReceived`, is the emitted value the actual tokens received (output), or is it the input amount (e.g., DAI spent)? Compare the parameter name against the variable being emitted - a mismatch between name semantics and actual value is a finding even if types match. |
For events consumed by off-chain systems (indexers, frontends, monitoring):
Findings use IDs `[EVT-N]`. Include the emit location, the incorrect parameter, and the correct value it should emit.
Autonomous Web3 security auditor for Claude Code and OpenAI Codex CLI. Orchestrates 18-100 AI agents across 40+ phases to produce audit reports with verified PoC exploits — for smart contracts and L1 node-client infrastructure.
Repo: PlamenTSV/plamen
Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth…
Trigger Pattern Always (Aptos Move) - Move VM aborts on shift = bit width - Inject Into…
Trigger Protocol has privileged roles (admin, operator, governance, resource account owner) -…
Trigger EXTERNAL_LIB flag detected (protocol uses third-party Move dependencies) - Used by…
Trigger Pattern MONETARY_PARAMETER flag (required) - Inject Into Breadth agents (merged via…