ability-analysis
Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth…
Protocol Type Trigger nft (detected when ERC721/ERC1155 with marketplace, minting, staking, or collateral logic found) - Inject Into Breadth agents, depth-token-flow, depth-edge...
$ npx -y skills add PlamenTSV/plamen --skill nft-protocol-security --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/nft-protocol-securityContext preview
The summary Claude sees to decide when to auto-load this skill.
Protocol Type Trigger nft (detected when ERC721/ERC1155 with marketplace, minting, staking, or collateral logic found) - Inject Into Breadth agents, depth-token-flow, depth-edge...
name: "nft-protocol-security" description: "Protocol Type Trigger nft (detected when ERC721/ERC1155 with marketplace, minting, staking, or collateral logic found) - Inject Into Breadth agents, depth-token-flow, depth-edge..."
> **Protocol Type Trigger**: `nft` (detected when ERC721/ERC1155 with marketplace, minting, staking, or collateral logic found) > **Inject Into**: Breadth agents, depth-token-flow, depth-edge-case > **Language**: EVM only (Solana/Move NFT models use different mechanisms without callbacks or enumeration) > **Finding prefix**: `[NFT-N]`
When decomposing this skill into depth agent investigation questions, map sections to domains:
Recon detects NFT protocol patterns: ERC721/ERC1155 with state-modifying logic beyond simple transfer (marketplace listing, staking, collateral, minting with conditions, royalty enforcement, batch operations).
Pure ERC721/ERC1155 token implementations without protocol logic do NOT trigger this skill.
---
For each function that triggers NFT callbacks:
Enumerate all code paths that invoke `_safeMint`, `_safeTransfer`, `safeTransferFrom`, or `onERC1155Received`/`onERC1155BatchReceived`:
| # | Function | Callback Triggered | State Modified BEFORE Callback | State Modified AFTER Callback | Reentrancy Guard? | |---|----------|-------------------|-------------------------------|------------------------------|-------------------|
For each entry:
For contracts implementing ERC1155:
Tag: `[TRACE:_safeMint → onERC721Received callback → state_before={list} → reentrant_path={YES/NO}]`
---
For each approval mechanism:
For each transfer function:
If royalties are enforced:
Tag: `[TRACE:transfer_path={function} → auth_check={method} → royalty_enforced={YES/NO}]`
---
For contracts using ERC721Enumerable or custom enumeration:
For batch mint/burn/transfer:
Tag: `[BOUNDARY:burn_last_token → _ownedTokens[owner].length={0} → tokenOfOwnerByIndex={result}]`
---
If `tokenURI` or `uri` returns dynamic content:
If tokens have properties assigned at mint time (rarity, type, attributes):
Autonomous Web3 security auditor for Claude Code and OpenAI Codex CLI. Orchestrates 18-100 AI agents across 40+ phases to produce audit reports with verified PoC exploits — for smart contracts and L1 node-client infrastructure.
Repo: PlamenTSV/plamen
Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth…
Trigger Pattern Always (Aptos Move) - Move VM aborts on shift = bit width - Inject Into…
Trigger Protocol has privileged roles (admin, operator, governance, resource account owner) -…
Trigger EXTERNAL_LIB flag detected (protocol uses third-party Move dependencies) - Used by…
Trigger Pattern MONETARY_PARAMETER flag (required) - Inject Into Breadth agents (merged via…