ability-analysis
Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth…
Trigger Pattern SEMI_TRUSTED_ROLE flag (required) - Inject Into Breadth agents, depth-state-trace
$ npx -y skills add PlamenTSV/plamen --skill semi-trusted-roles --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/semi-trusted-rolesContext preview
The summary Claude sees to decide when to auto-load this skill.
Trigger Pattern SEMI_TRUSTED_ROLE flag (required) - Inject Into Breadth agents, depth-state-trace
name: "semi-trusted-roles" description: "Trigger Pattern SEMI_TRUSTED_ROLE flag (required) - Inject Into Breadth agents, depth-state-trace"
> **Trigger Pattern**: SEMI_TRUSTED_ROLE flag (required) > **Inject Into**: Breadth agents, depth-state-trace > **Purpose**: Analyze semi-trusted roles in Aptos Move protocols using capability-based access control, modeling both role-to-user and user-to-role attack vectors
signer|SignerCapability|AdminCap|OperatorCap|KeeperCap|has_role| assert_admin|assert_operator|friend|acquires|ExtendRef| DeleteRef|TransferRef|MintRef|BurnRef
Enumerate ALL privileged roles in the protocol:
| Role | Capability / Check | Module | Functions Callable | State Modifiable | External Calls | |------|-------------------|--------|-------------------|-----------------|----------------| | {role} | {SignerCapability / custom Cap struct / signer check / friend} | {module} | {fn list} | {state list} | {calls list} |
**Aptos capability patterns to inventory**:
For each role at {ROLE_FUNCTIONS}:
For each permitted action, ask:
**Timing Abuse**:
**Parameter Abuse**:
**Sequence Abuse**:
**Omission Abuse**:
Scenario A: Timing Attack
1. {ROLE_NAME} monitors mempool for user transaction {USER_ACTION}
2. {ROLE_NAME} front-runs with {ROLE_ACTION}
3. User's transaction executes with worse conditions
4. Impact: {TIMING_IMPACT}
Scenario B: Parameter Attack
1. {ROLE_NAME} calls {ROLE_FUNCTION} with {MALICIOUS_PARAMS}
2. Parameters are not validated against {EXPECTED_CONSTRAINTS}
3. Impact: {PARAM_IMPACT}
Scenario C: Key Compromise
1. {ROLE_NAME} private key is compromised (or SignerCapability is leaked)
2. Attacker can call: {ROLE_FUNCTIONS}
3. Maximum extractable value: {MAX_DAMAGE}
4. Recovery options: {RECOVERY_PATH}| Mitigation | Present? | Implementation | Effective? | |-----------|----------|----------------|-----------| | Timelock on role actions | YES/NO | {code ref} | {analysis} | | Multisig requirement | YES/NO | {code ref} | {analysis} | | Role revocation function | YES/NO | {code ref} | {analysis} | | Rate limits / cooldowns | YES/NO | {code ref} | {analysis} | | Parameter bounds validation | YES/NO | {code ref} | {analysis} | | Event emission for monitoring | YES/NO | {code ref} | {analysis} |
**Does a removal/revocation function for {ROLE_NAME} EXIST?** If NO -> FINDING: role is irrevocable without module upgrade. Severity: minimum Medium if role can modify user-facing state.
| Capability | Stored Where | Can Be Duplicated? | Can Escalate? | Escalation Path | |-----------|-------------|-------------------|---------------|----------------| | {cap} | {resource/object} | YES/NO (`copy` ability?) | YES/NO | {if YES: how} |
**Aptos-specific escalation vectors**:
| Capability | Has `copy`? | Has `drop`? | Has `store`? | Transfer Function Exists? | Risk | |-----------|------------|------------|-------------|--------------------------|------| | {cap} | YES/NO | YES/NO | YES/NO | YES/NO | {assessment} |
**Key checks**:
**Predictability Analysis**:
Autonomous Web3 security auditor for Claude Code and OpenAI Codex CLI. Orchestrates 18-100 AI agents across 40+ phases to produce audit reports with verified PoC exploits — for smart contracts and L1 node-client infrastructure.
Repo: PlamenTSV/plamen
Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth…
Trigger Pattern Always (Aptos Move) - Move VM aborts on shift = bit width - Inject Into…
Trigger Protocol has privileged roles (admin, operator, governance, resource account owner) -…
Trigger EXTERNAL_LIB flag detected (protocol uses third-party Move dependencies) - Used by…
Trigger Pattern MONETARY_PARAMETER flag (required) - Inject Into Breadth agents (merged via…