ability-analysis
Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth…
L1 trigger - audits bugs that surface only at fork boundaries / protocol upgrade points: activation logic, dormant code paths, upgrade epoch correctness, version gating.
$ npx -y skills add PlamenTSV/plamen --skill hardfork-activation-and-protocol-upgrade --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/hardfork-activation-and-protocol-upgradeContext preview
The summary Claude sees to decide when to auto-load this skill.
L1 trigger - audits bugs that surface only at fork boundaries / protocol upgrade points: activation logic, dormant code paths, upgrade epoch correctness, version gating.
name: "hardfork-activation-and-protocol-upgrade" description: "L1 trigger - audits bugs that surface only at fork boundaries / protocol upgrade points: activation logic, dormant code paths, upgrade epoch correctness, version gating."
> **L1 trigger**: `L1_PATTERN=true` AND (`fork_rules` OR `chain_config` OR `hardfork` OR `upgrade_handler` OR `x/upgrade` OR `ActivationHeight` OR `ActivationEpoch` detected in recon subsystem map) > **Inject Into**: `depth-state-trace` or `depth-consensus-invariant` > **Language**: Go and Rust > **Finding prefix**: `[HF-N]` > **Status**: v0.1 draft (added from Round 4 gap analysis)
Recon identifies fork-activation, chain-config, or upgrade-handler code. This skill addresses a distinct bug class surfaced by Round 4: **bugs that are invisible until an upgrade epoch arrives**. The Prysm Fusaka bug (Dec 2025) is the canonical example — perfectly working code in v7.0.0, Critical-severity bug the moment Fusaka activated.
The defining feature: these bugs cannot be found by analyzing "current behavior" alone. They live in code paths that are dormant until a specific block height, epoch, or version condition fires.
Every hardfork has an activation condition: a block height, timestamp, epoch, or version number. Verify:
If a hardfork activates multiple rule changes (new opcode, new gas cost, new pricing), ALL must activate at the same height. Partial activation = consensus split.
Check: the code gated by `if block.Number >= ForkBlock` actually runs. Dead code that was meant to activate but never does is a finding (late activation = missed hardfork).
Testnet activation heights are different from mainnet. Verify: the code does not have a hardcoded mainnet block number that breaks on testnet, or vice versa. Every activation condition should be config-driven.
Tag: `[HF-ACTIVATE:{fork}:{issue}]`
The hardest class: code that exists for a future fork but has never run in production. Prysm Fusaka is the exemplar — v7.0.0 shipped with the Fusaka code path, but that path was dormant until the upgrade epoch. When it activated, bugs surfaced that no amount of testing on the pre-Fusaka chain would have caught.
Tag: `[HF-DORMANT:{fork}:{gated-code}]`
**Critical methodology nuance**: dormant code is under-tested by definition. Any finding in dormant code should be flagged **High or Critical** because the production blast radius is the entire upgrade.
For protocols with multiple client implementations, version gating must agree:
Check:
Tag: `[HF-VERSION:{client}:{divergence}]`
At the upgrade epoch itself, two rule sets coexist: pre-upgrade rules apply to blocks at epoch N-1, post-upgrade rules apply to N. At the boundary:
Tag: `[HF-BOUNDARY:{issue}]`
If an upgrade fails post-deployment, the protocol may need to be rolled back.
Tag: `[HF-ROLLBACK:{state}]`
| State | Test | Expected | |---|---|---| | Genesis = fork block | chain starts at upgrade | handled | | Reorg across fork | reorg to block before fork activation | state rolled back to pre-fork rules | |
Autonomous Web3 security auditor for Claude Code and OpenAI Codex CLI. Orchestrates 18-100 AI agents across 40+ phases to produce audit reports with verified PoC exploits — for smart contracts and L1 node-client infrastructure.
Repo: PlamenTSV/plamen
Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth…
Trigger Pattern Always (Aptos Move) - Move VM aborts on shift = bit width - Inject Into…
Trigger Protocol has privileged roles (admin, operator, governance, resource account owner) -…
Trigger EXTERNAL_LIB flag detected (protocol uses third-party Move dependencies) - Used by…
Trigger Pattern MONETARY_PARAMETER flag (required) - Inject Into Breadth agents (merged via…