ability-analysis
Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth…
L1 supplement - audits Rust-specific hazards: unsafe blocks, uninitialized memory, Send/Sync violations, panic safety in hot paths, drop order, FFI.
$ npx -y skills add PlamenTSV/plamen --skill rust-unsafe-audit --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/rust-unsafe-auditContext preview
The summary Claude sees to decide when to auto-load this skill.
L1 supplement - audits Rust-specific hazards: unsafe blocks, uninitialized memory, Send/Sync violations, panic safety in hot paths, drop order, FFI.
name: "rust-unsafe-audit" description: "L1 supplement - audits Rust-specific hazards: unsafe blocks, uninitialized memory, Send/Sync violations, panic safety in hot paths, drop order, FFI."
> **L1 trigger**: `L1_PATTERN=true` AND target language = Rust > **Inject Into**: Every L1 depth agent working on Rust code, in addition to the main skill > **Finding prefix**: `[RS-N]` > **Status**: v0.1 draft, Round 4 exemplars pending
Supplement to the main L1 skills when the target is written in Rust. Rust's safe subset prevents most memory safety bugs by default, but node clients use `unsafe` for performance (crypto, serialization), `panic!` for unrecoverable states, and FFI (blst, rocksdb, librocksdb-sys). Each is a bug class.
Every `unsafe` block is a memory-safety assertion by the author: "I guarantee this is safe." The audit must verify that guarantee.
**Detection**:
**Checklist per unsafe block**:
Tag: `[RS-UNSAFE:{loc}:{category}]`
Rust allows uninitialized memory via `MaybeUninit` or `mem::uninitialized` (deprecated). Reading uninitialized memory is Undefined Behavior.
**Detection**:
Tag: `[RS-UNINIT:{loc}]`
`Send` allows a type to be transferred between threads; `Sync` allows shared references across threads. Manually implementing them (`unsafe impl Send for T`) is an assertion.
**Detection**:
Tag: `[RS-SEND-SYNC:{type}:{justification}]`
Panics in Rust unwind the stack by default. In a consensus-critical hot path, a panic kills the node. Exception: `panic = "abort"` in Cargo.toml makes panics immediately terminate the process.
**Detection**:
Tag: `[RS-PANIC:{loc}:{input-source}]`
**Rule of thumb**: any function that parses peer/RPC input must not `.unwrap()` or panic-index. Use `?` and `Result` throughout.
Rust's Drop trait runs deterministically when a value goes out of scope. Bugs:
**Detection**:
Tag: `[RS-DROP:{issue}]`
Most L1 Rust clients call C libraries: `blst` (BLS), `rocksdb-sys` (storage), `libsecp256k1-sys` (signatures).
**Detection**:
Tag: `[RS-FFI:{function}:{issue}]`
When binding to C / C++ / CUDA / HIP via FFI (`extern "C"`, `bindgen`, hand-written headers, `*.cu` / `*.hip` files), audit every C integer type use. C type sizes differ between platforms:
| C type | Linux/macOS (LP64) | Windows MSVC (LLP64) | Safe? | |---|---|---|---| | `unsigned long` / `long` | 64 bits | **32 bits** | NO — silent truncation on Windows | | `unsigned long long` / `long long` | 64 bits | 64 bits | YES | | `int` / `unsigned int` | 32 bits | 32 bits | YES | | `size_t` / `uintptr_t` | pointer-width | pointer-width | YES (verify) | | `uint64_t` / `int64_t` (`<stdint.h>`) | 64 bits | 64 bits | YES — preferred |
**Check**:
**Fail mode**: 64-bit values (chunk offsets, partition hashes, block heights) silently truncated to 32 bits on Windows builds, producing different consensus output from Linux builds → silent network split between operators on different platforms.
Tag: `[RS-FFI:c-type-portability:{file}:{line}]`
Many Rust DB wrappers (mdbx-rs, sled, rocksdb) provide an `update`-style helper that runs a closure inside a transaction and commits afterwards. A common bug pattern: the wrapper commits the transaction unconditionally before checking whether
Autonomous Web3 security auditor for Claude Code and OpenAI Codex CLI. Orchestrates 18-100 AI agents across 40+ phases to produce audit reports with verified PoC exploits — for smart contracts and L1 node-client infrastructure.
Repo: PlamenTSV/plamen
Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth…
Trigger Pattern Always (Aptos Move) - Move VM aborts on shift = bit width - Inject Into…
Trigger Protocol has privileged roles (admin, operator, governance, resource account owner) -…
Trigger EXTERNAL_LIB flag detected (protocol uses third-party Move dependencies) - Used by…
Trigger Pattern MONETARY_PARAMETER flag (required) - Inject Into Breadth agents (merged via…