ability-analysis
Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth…
L1 supplement - audits Go-specific concurrency hazards in node client code: map iteration non-determinism, goroutine leaks, mutex ordering, panic boundaries, context cancellation.
$ npx -y skills add PlamenTSV/plamen --skill go-concurrency-safety --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/go-concurrency-safetyContext preview
The summary Claude sees to decide when to auto-load this skill.
L1 supplement - audits Go-specific concurrency hazards in node client code: map iteration non-determinism, goroutine leaks, mutex ordering, panic boundaries, context cancellation.
name: "go-concurrency-safety" description: "L1 supplement - audits Go-specific concurrency hazards in node client code: map iteration non-determinism, goroutine leaks, mutex ordering, panic boundaries, context cancellation."
> **L1 trigger**: `L1_PATTERN=true` AND target language = Go > **Inject Into**: Every L1 depth agent working on Go code, in addition to the main skill > **Finding prefix**: `[GO-N]` > **Status**: v0.1 draft, Round 4 exemplars pending
Supplement to the main L1 skills when the target is written in Go. It codifies the Go-specific traps that turn otherwise-correct logic into production bugs. These are drawn from the Cosmos-SDK, Geth, Erigon, and CometBFT bug histories.
Go maps iterate in **unspecified order**. Production bug class: any consensus computation that ranges over a `map[K]V` and uses the order in its output will produce different results on different nodes.
**Detection**:
**Fix pattern**:
keys := make([]string, 0, len(m))
for k := range m {
keys = append(keys, k)
}
sort.Strings(keys)
for _, k := range keys {
v := m[k]
// use (k, v)
}**Alternative**: use `btree` or `sort.SliceStable` on a converted slice.
Tag: `[GO-MAP-ITER:{loc}:{consumer}]`
Goroutines that are started but never terminated. Over hours/days, a leak accumulates and eventually OOMs the node.
**Common patterns**:
**Detection**:
Tag: `[GO-GOROUTINE-LEAK:{spawn-loc}:{blocked-on}]`
Locking order inversions cause deadlocks. In node clients, locks are often acquired across subsystem boundaries (consensus holds lock A, calls into p2p which acquires lock B; p2p holds lock B, calls into consensus which acquires lock A → deadlock).
**Detection**:
Tag: `[GO-LOCK-ORDER:{lock-a}:{lock-b}:{inversion-site}]`
Sending on a closed channel panics. In Go, closing a channel you don't own is usually wrong.
**Detection**:
Tag: `[GO-CLOSED-CHAN:{loc}]`
A goroutine panic crashes the whole process (unless recovered). In RPC handlers, HTTP middleware typically recovers; in background workers, often not.
**Detection**:
Tag: `[GO-PANIC:{loc}:{recovered}]`
The `context.Context` pattern propagates cancellation. Every long-running operation should accept a context and check it.
**Detection**:
Tag: `[GO-CTX:{loc}:{missing-propagation}]`
Tag: `[GO-DEFER:{loc}:{issue}]`
Go doesn't panic on integer overflow (wraps silently). In consensus math, this is dangerous.
**Detection**:
Tag: `[GO-OVERFLOW:{loc}:{type}]`
1. **btcd signed-int transaction version (CVE-2024-34478)** — transaction version treated as signed int instead of unsigned, combined with a data race in the consensus-rule check. Chain split and fund loss possible. [Snyk advisory](https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMBTCSUITEBTCDBLOCKCHAIN-6808762). **Skill catch point**: Section 8 (integer overflow) + `go test -race`. Every signed/unsigned mismatch on a consensus-relevant field is a finding.
2. **Geth concurrent map iteration and map write panic (issue #17750)** — map accessed from multiple goroutines without sync; Go runtime panics with `fatal error: concurrent map iteration and map write`. [go-ethereum #17750](https://github.com/ethereum/go-ethereum/issues/17750). **Skill catch point**: Section 3 — for every map field on a struct shared acr
Autonomous Web3 security auditor for Claude Code and OpenAI Codex CLI. Orchestrates 18-100 AI agents across 40+ phases to produce audit reports with verified PoC exploits — for smart contracts and L1 node-client infrastructure.
Repo: PlamenTSV/plamen
Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth…
Trigger Pattern Always (Aptos Move) - Move VM aborts on shift = bit width - Inject Into…
Trigger Protocol has privileged roles (admin, operator, governance, resource account owner) -…
Trigger EXTERNAL_LIB flag detected (protocol uses third-party Move dependencies) - Used by…
Trigger Pattern MONETARY_PARAMETER flag (required) - Inject Into Breadth agents (merged via…