ability-analysis
Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth…
L1 trigger - audits JSON-RPC and Engine API surfaces for authentication bypass, rate limiting, subscription buffer overflows, and method-specific DoS.
$ npx -y skills add PlamenTSV/plamen --skill rpc-surface-audit --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/rpc-surface-auditContext preview
The summary Claude sees to decide when to auto-load this skill.
L1 trigger - audits JSON-RPC and Engine API surfaces for authentication bypass, rate limiting, subscription buffer overflows, and method-specific DoS.
name: "rpc-surface-audit" description: "L1 trigger - audits JSON-RPC and Engine API surfaces for authentication bypass, rate limiting, subscription buffer overflows, and method-specific DoS."
> **L1 trigger**: `L1_PATTERN=true` AND (`rpc/` OR `jsonrpc` OR `engine_api` OR `eth/api` OR `websocket` OR `ipc` detected in recon subsystem map) > **Inject Into**: `depth-network-surface` > **Language**: Go and Rust > **Finding prefix**: `[RPC-N]` > **Status**: v0.1 draft, Round 4 exemplars pending
Recon identifies an RPC subsystem. RPC is the most publicly exposed attack surface on any L1 node — typically unauthenticated (HTTP JSON-RPC, WebSocket) or semi-authenticated (Engine API with JWT). Even a Medium-severity bug here often upgrades to High because of permissionless reachability (see severity-matrix.md modifier).
Enumerate all RPC entry points via LSP `workspace/symbol` filtered by known method-registration patterns:
| Transport | Registration pattern | Example | |---|---|---| | **HTTP JSON-RPC** | `rpc.Register`, `httpServer.Handle`, `#[method(name=...)]` | `eth_*`, `debug_*`, `admin_*` | | **WebSocket** | Same as HTTP + subscription handlers | `eth_subscribe` | | **IPC** (unix socket) | Often same as HTTP | Geth `admin` namespace | | **Engine API** | JWT-authenticated | `engine_newPayloadV*`, `engine_forkchoiceUpdatedV*` | | **Prometheus metrics** | `/metrics` endpoint | often bound to all interfaces | | **PPROF profiling** | `/debug/pprof/` (Go) | should NEVER be public |
Write the enumeration to `scratchpad/rpc_surface.md`.
Tag: `[RPC-AUTH:{issue}]`
Some RPC methods are cheap (`eth_blockNumber`), others are expensive (`eth_getLogs` with wide range, `debug_traceTransaction`). Is there a cost model that bounds work per request?
**Check**:
Tag: `[RPC-RATE:{scope}:{limit-or-unbounded}]`
The skill historically focused on incoming RPC. Audit OUTBOUND HTTP clients used by the node for peer fetches and inter-node API calls — they are a symmetric DoS vector.
**Check**:
Tag: `[RPC-CLIENT-NO-TIMEOUT:{file}:{line}]`
JavaScript clients (and many other dynamic languages) cannot represent integers above `2^53 - 1` precisely. L1 nodes that serialize `u64` fields as JSON numbers (not strings) will silently corrupt block heights, balances, gas values, and timestamps when consumed by JS clients.
**Check**:
Tag: `[RPC-JSON-PRECISION:{type}.{field}]`
For each RPC handler, peer HTTP endpoint, and outbound API client wrapper that returns `Ok(())`, HTTP 2xx, a success JSON body, or increments peer score,
Autonomous Web3 security auditor for Claude Code and OpenAI Codex CLI. Orchestrates 18-100 AI agents across 40+ phases to produce audit reports with verified PoC exploits — for smart contracts and L1 node-client infrastructure.
Repo: PlamenTSV/plamen
Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth…
Trigger Pattern Always (Aptos Move) - Move VM aborts on shift = bit width - Inject Into…
Trigger Protocol has privileged roles (admin, operator, governance, resource account owner) -…
Trigger EXTERNAL_LIB flag detected (protocol uses third-party Move dependencies) - Used by…
Trigger Pattern MONETARY_PARAMETER flag (required) - Inject Into Breadth agents (merged via…