ability-analysis
Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth…
Type Thought-template (instantiate before use) - Trigger Pattern Always (Aptos Move) -- ConstructorRef/TransferRef/MintRef/BurnRef lifecycle
$ npx -y skills add PlamenTSV/plamen --skill ref-lifecycle --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/ref-lifecycleContext preview
The summary Claude sees to decide when to auto-load this skill.
Type Thought-template (instantiate before use) - Trigger Pattern Always (Aptos Move) -- ConstructorRef/TransferRef/MintRef/BurnRef lifecycle
name: "ref-lifecycle" description: "Type Thought-template (instantiate before use) - Trigger Pattern Always (Aptos Move) -- ConstructorRef/TransferRef/MintRef/BurnRef lifecycle"
> **Type**: Thought-template (instantiate before use) > **Trigger Pattern**: Always (Aptos Move) -- ConstructorRef/TransferRef/MintRef/BurnRef lifecycle > **Inject Into**: Breadth agents, depth-state-trace, depth-token-flow > **Research basis**: Aptos Object model capability-based access control, permanent reference semantics
In Aptos Move, object capabilities (Refs) are unforgeable tokens that grant specific permissions over objects. Unlike role-based access control in EVM, Refs are permanent once created -- they CANNOT be revoked. A leaked or improperly stored Ref grants permanent capability to its holder.
Key Ref types:
ConstructorRef|TransferRef|MintRef|BurnRef|DeleteRef|ExtendRef| object::create_named_object|object::create_sticky_object|object::create_object| fungible_asset::generate_mint_ref|fungible_asset::generate_burn_ref| fungible_asset::generate_transfer_ref|object::generate_delete_ref| object::generate_extend_ref|object::generate_transfer_ref
Enumerate ALL Ref types found in the codebase. For each:
| Ref Type | Created In (module::function) | Stored Location | Access Control | Capability Granted | |----------|-------------------------------|-----------------|----------------|--------------------| | ConstructorRef | {module}::{init_fn} | {consumed / stored in resource} | {who can access} | Generate all other Refs | | MintRef | {module}::{init_fn} | {global resource at @addr} | {who can access} | Unlimited minting of {asset} | | BurnRef | {module}::{init_fn} | {global resource at @addr} | {who can access} | Burn {asset} from any store | | TransferRef | {module}::{init_fn} | {global resource at @addr} | {who can access} | Transfer {asset} bypassing freeze | | DeleteRef | {module}::{init_fn} | {global resource at @addr} | {who can access} | Delete {object} | | ExtendRef | {module}::{init_fn} | {global resource at @addr} | {who can access} | Generate signer for {object} |
**Completeness check**: Search for ALL `generate_*_ref` calls and `object::create_*` calls. Every Ref created MUST appear in the table.
The ConstructorRef is the root capability. It exists only during the `init_module` or object creation call.
**Check 2a: Is ConstructorRef stored?**
**Check 2b: What Refs are generated from it?**
**Check 2c: ExtendRef derived signer**
**Check 3a: Storage access control**
**Check 3b: Mint amount validation**
**Check 3c: BurnRef scope**
**Check 3d: Mint/Burn symmetry**
**Check 4a: Freeze bypass**
Autonomous Web3 security auditor for Claude Code and OpenAI Codex CLI. Orchestrates 18-100 AI agents across 40+ phases to produce audit reports with verified PoC exploits — for smart contracts and L1 node-client infrastructure.
Repo: PlamenTSV/plamen
Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth…
Trigger Pattern Always (Aptos Move) - Move VM aborts on shift = bit width - Inject Into…
Trigger Protocol has privileged roles (admin, operator, governance, resource account owner) -…
Trigger EXTERNAL_LIB flag detected (protocol uses third-party Move dependencies) - Used by…
Trigger Pattern MONETARY_PARAMETER flag (required) - Inject Into Breadth agents (merged via…