ability-analysis
Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth…
L1 trigger - audits peer-to-peer networking for DoS vectors (resource exhaustion, amplification), eclipse attack susceptibility, and discovery table poisoning (Kademlia/devp2p).
$ npx -y skills add PlamenTSV/plamen --skill p2p-dos-and-eclipse --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/p2p-dos-and-eclipseContext preview
The summary Claude sees to decide when to auto-load this skill.
L1 trigger - audits peer-to-peer networking for DoS vectors (resource exhaustion, amplification), eclipse attack susceptibility, and discovery table poisoning (Kademlia/devp2p).
name: "p2p-dos-and-eclipse" description: "L1 trigger - audits peer-to-peer networking for DoS vectors (resource exhaustion, amplification), eclipse attack susceptibility, and discovery table poisoning (Kademlia/devp2p)."
> **L1 trigger**: `L1_PATTERN=true` AND (`p2p/` OR `network/` OR `discovery/` OR `libp2p` OR `devp2p` OR `enr` OR `discv5` detected in recon subsystem map) > **Inject Into**: `depth-network-surface` > **Language**: Go and Rust > **Finding prefix**: `[P2P-N]` > **Status**: v0.1 draft, Round 4 exemplars pending
Recon identifies a P2P subsystem. Most attacks in this class are out-of-scope for typical bounty programs but are **in scope for Plamen audits** — firms like Sigma Prime and OpenZeppelin explicitly cover them. Severity downgrades to Low/Info when the exploit only eclipses a single node (see severity-matrix.md); upgrades when reachable by arbitrary peers and amplifies across the network.
Every P2P subsystem has a finite set of entry points for remote adversary bytes. Enumerate them using LSP `workspace/symbol` and ast-grep:
| Entry point type | How to find | Example functions | |---|---|---| | **Message handlers** | Trait/interface impl names ending in `Handler`, `Service`, `Listener` | `handleGetBlockHeaders`, `on_new_pooled_transaction_hashes` | | **Decoders** | Functions taking `&[u8]` or `Reader` and returning protocol types | `decode_enr`, `rlp_decode` | | **Connection accepters** | TCP/QUIC listener accept loops | `acceptLoop`, `handle_connection` | | **Discovery responders** | UDP packet handlers for discovery protocol | `handleDiscv5Packet`, `process_find_node` | | **Gossip handlers** | Pubsub topic subscribers | `process_gossip_message` |
Write the enumeration into `scratchpad/p2p_surface.md` before proceeding.
Attacker sends N bytes, node does O(N²) or O(N*log(N)) work. Classic example: decompression bombs, hash-map insertion of attacker-chosen keys (hash DoS), large RLP lists.
**Check**:
Tag: `[P2P-ASYMMETRIC:{loc}:{input-size}→{work-cost}]`
Handlers that buffer or queue indefinitely.
**Check**:
Tag: `[P2P-UNBOUNDED:{structure}:{growth-driver}]`
Handlers that can loop forever or spend minutes on malicious input.
**Check**:
Tag: `[P2P-CPU:{loc}:{termination-condition}]`
Attacker opens N connections with M peers, filling the connection table.
**Check**:
Tag: `[P2P-SLOTS:{limit}:{diversification}]`, `[P2P-BOOTSTRAP-FLOOD:{cap-or-unbounded}]`
Attacker sends small message, node sends large response — used to DDoS third parties.
**Check**:
Tag: `[P2P-AMPLIFY:{request-bytes}→{response-bytes}]`
For each gossip handler that RECEIVES data and then FORWARDS it to other peers (re-gossip), trace the dedup path. This is a separate concern from 2a (single-message cost) — it covers network-multiplication attacks.
**Check**:
**Fail mode**: an N-peer network re-gossips each message
Autonomous Web3 security auditor for Claude Code and OpenAI Codex CLI. Orchestrates 18-100 AI agents across 40+ phases to produce audit reports with verified PoC exploits — for smart contracts and L1 node-client infrastructure.
Repo: PlamenTSV/plamen
Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth…
Trigger Pattern Always (Aptos Move) - Move VM aborts on shift = bit width - Inject Into…
Trigger Protocol has privileged roles (admin, operator, governance, resource account owner) -…
Trigger EXTERNAL_LIB flag detected (protocol uses third-party Move dependencies) - Used by…
Trigger Pattern MONETARY_PARAMETER flag (required) - Inject Into Breadth agents (merged via…