ability-analysis
Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth…
Protocol Type Trigger lending (detected when recon finds liquidate|borrow|repay|collateral|lend|loan|LTV|healthFactor|interestRate|debtToken) - Inject Into Breadth agents, depth...
$ npx -y skills add PlamenTSV/plamen --skill lending-protocol-security --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/lending-protocol-securityContext preview
The summary Claude sees to decide when to auto-load this skill.
Protocol Type Trigger lending (detected when recon finds liquidate|borrow|repay|collateral|lend|loan|LTV|healthFactor|interestRate|debtToken) - Inject Into Breadth agents, depth...
name: "lending-protocol-security" description: "Protocol Type Trigger lending (detected when recon finds liquidate|borrow|repay|collateral|lend|loan|LTV|healthFactor|interestRate|debtToken) - Inject Into Breadth agents, depth..."
> **Protocol Type Trigger**: `lending` (detected when recon finds: liquidate|borrow|repay|collateral|lend|loan|LTV|healthFactor|interestRate|debtToken) > **Inject Into**: Breadth agents, depth-token-flow, depth-edge-case, depth-state-trace > **Language**: Language-agnostic methodology > **Finding prefix**: `[LEND-N]`
When decomposing this skill into depth agent investigation questions, map sections to domains:
Recon classifies protocol as `lending` type based on indicators: liquidate, borrow, repay, collateral, lend, loan, LTV, healthFactor, interestRate, debtToken, reserve, utilizationRate, debtShare. This skill adds lending-specific checks that the general ECONOMIC_DESIGN_AUDIT does not cover.
---
Identify the health factor (HF) formula and trace each input:
Substitute boundary values into the formula: | State | HF Value | Expected Behavior | Actual? | |-------|----------|-------------------|---------| | HF = 1.0 exactly | | Liquidation threshold - which side? | | | HF = 1.0 + 1 wei | | Should NOT be liquidatable | | | HF = 1.0 - 1 wei | | Should be liquidatable | | | HF after max interest accrual | | Worst case between check intervals | | | HF with dust collateral | | Liquidation gas > reward? | |
Tag: `[BOUNDARY:HF={value} → liquidatable={YES/NO} → operator={>=/>}]`
---
For protocols that use transaction guards or post-transaction hooks with conditional enforcement checks (e.g., post-transaction guard/hook triggered by selector or return value):
1. Enumerate ALL function selectors the guard/hook handles 2. For each selector: does the operation affect HF? (changes collateral amount, debt amount, collateral factor, efficiency/isolation mode, reserve configuration) 3. For each HF-affecting selector: does the guard/hook trigger the post-transaction HF enforcement check? 4. Flag any HF-affecting selector where post-tx enforcement is skipped
| Selector | Function | Affects HF? | Triggers Post-Tx HF Check? | Gap? | |----------|----------|-------------|---------------------------|------|
Tag: `[TRACE:guard_hook_selector={fn} → HF_affecting={YES/NO} → post_tx_check={YES/NO}]`
---
Identify the interest accrual mechanism and trace when it updates:
For index-based interest (where `debt = principal * currentIndex / borrowIndex`):
Tag: `[TRACE:accrueInterest() → index_update_
Autonomous Web3 security auditor for Claude Code and OpenAI Codex CLI. Orchestrates 18-100 AI agents across 40+ phases to produce audit reports with verified PoC exploits — for smart contracts and L1 node-client infrastructure.
Repo: PlamenTSV/plamen
Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth…
Trigger Pattern Always (Aptos Move) - Move VM aborts on shift = bit width - Inject Into…
Trigger Protocol has privileged roles (admin, operator, governance, resource account owner) -…
Trigger EXTERNAL_LIB flag detected (protocol uses third-party Move dependencies) - Used by…
Trigger Pattern MONETARY_PARAMETER flag (required) - Inject Into Breadth agents (merged via…