ability-analysis
Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth…
Trigger Pattern Any external module interaction detected in attack_surface.md - Inject Into Breadth agents (merged via M5 hierarchy)
$ npx -y skills add PlamenTSV/plamen --skill external-precondition-audit --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/external-precondition-auditContext preview
The summary Claude sees to decide when to auto-load this skill.
Trigger Pattern Any external module interaction detected in attack_surface.md - Inject Into Breadth agents (merged via M5 hierarchy)
name: "external-precondition-audit" description: "Trigger Pattern Any external module interaction detected in attack_surface.md - Inject Into Breadth agents (merged via M5 hierarchy)"
> **Trigger Pattern**: Any external module interaction detected in attack_surface.md > **Inject Into**: Breadth agents (merged via M5 hierarchy) > **Constraint**: Interface-level inference only -- no production fetch required
For every external module the protocol interacts with:
From the `use` imports and function calls to external modules, infer what the external module requires:
| External Function Called | Module::Function | Parameters Passed | Likely Preconditions (from signature + abort codes) | Our Protocol Validates? | |--------------------------|-----------------|-------------------|-----------------------------------------------------|------------------------|
**Inference method**: Read the function signature, type parameters, ability constraints, and abort conditions. Example: `coin::withdraw<CoinType>(account: &signer, amount: u64)` -> infer that `account` must have sufficient balance, `CoinType` must be initialized, amount must be > 0. Check abort codes in framework source if available.
**Aptos-specific patterns**:
| External Call | Return Type | How Protocol Uses Return | Failure Mode if Return Unexpected | |--------------|-------------|-------------------------|----------------------------------|
For each return value:
| Protocol State | Depends on External State | External Module Upgradeable? | State Can Change Without Our Knowledge? | |---------------|--------------------------|-----------------------------|-----------------------------------------|
For each dependency:
{CONTRACTS} -- List of modules to analyze
{EXTERNAL_MODULES} -- External modules identified during recon
{FRAMEWORK_DEPS} -- aptos_framework / aptos_std / aptos_token dependenciesFor each finding:
## Finding [EP-N]: Title
**Verdict**: CONFIRMED / PARTIAL / REFUTED / CONTESTED
**Step Execution**: S1,S2,S3 | X(reasons) | ?(uncertain)
**Rules Applied**: [R1:Y, R4:Y, R8:Y]
**Severity**: Critical/High/Medium/Low/Info
**Location**: module::function (source_file.move:LineN)
**External Dependency**: {module::function}
**Failure Mode**: {what breaks}
**Description**: What's wrong
**Impact**: What can happen (abort DoS, wrong state, fund loss)
**Evidence**: Code showing dependency and missing validation| Section | Required | Completed? | |---------|----------|------------| | 1. Interface-Level Requirement Inference | YES | Y/N/? | | 2. Return Value Consumption | YES | Y/N/? | | 3. State Dependency Mapping | YES | Y/N/? |
Autonomous Web3 security auditor for Claude Code and OpenAI Codex CLI. Orchestrates 18-100 AI agents across 40+ phases to produce audit reports with verified PoC exploits — for smart contracts and L1 node-client infrastructure.
Repo: PlamenTSV/plamen
Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth…
Trigger Pattern Always (Aptos Move) - Move VM aborts on shift = bit width - Inject Into…
Trigger Protocol has privileged roles (admin, operator, governance, resource account owner) -…
Trigger EXTERNAL_LIB flag detected (protocol uses third-party Move dependencies) - Used by…
Trigger Pattern MONETARY_PARAMETER flag (required) - Inject Into Breadth agents (merged via…