ability-analysis
Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth…
Type Thought-template (instantiate before use) - Research basis Donation attacks via unsolicited token transfers
$ npx -y skills add PlamenTSV/plamen --skill staking-receipt-tokens --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/staking-receipt-tokensContext preview
The summary Claude sees to decide when to auto-load this skill.
Type Thought-template (instantiate before use) - Research basis Donation attacks via unsolicited token transfers
name: "staking-receipt-tokens" description: "Type Thought-template (instantiate before use) - Research basis Donation attacks via unsolicited token transfers"
> **Type**: Thought-template (instantiate before use) > **Research basis**: Donation attacks via unsolicited token transfers
delegation|staking.*receipt|liquid.*staking|getLiquidRewards|unbond| stake.*share|validator|deposit.*voucher|withdraw.*voucher|claimReward
For each EXTERNAL staking/delegation token the protocol interacts with (not just the protocol's own receipt token):
1. Is it ERC20-transferable? (check if extends IERC20/IERC20Upgradeable) 2. Can it be transferred TO the protocol contract unsolicited (without calling deposit/stake)? 3. If YES to both: a. Does the protocol iterate over these tokens or their sources? (gas DoS from many unsolicited transfers) b. Does `getTotalStake(protocol)` or equivalent change? (accounting impact on withdrawal calculations) c. Does `transfer()` trigger side effects? (reward auto-claim, delegation state changes) d. Does non-zero balance block any admin/privileged operations? (e.g., entity removal requires balance == 0)
| External Token | ERC20? | Unsolicited Transfer? | Iteration DoS? | Balance Impact? | Side Effects? | Blocks Operations? | |----------------|--------|----------------------|-----------------|-----------------|---------------|-------------------| | {token_name} | YES/NO | YES/NO | YES/NO | YES/NO | YES/NO | YES/NO |
**RULE**: If ANY external token is ERC20-transferable AND affects protocol state → finding with severity >= MEDIUM.
1. Attacker acquires {RECEIPT_TOKEN} externally via {EXTERNAL_ACQUISITION}
2. Attacker transfers {DONATION_AMOUNT} to {PROTOCOL_CONTRACT}
3. Protocol's balanceOf(this) increases by {DONATION_AMOUNT}
4. Next operation at {AFFECTED_FUNCTION} uses inflated balance
5. Impact: {IMPACT_DESCRIPTION}1. Can {RECEIPT_TOKEN} be acquired without going through {PROTOCOL_CONTRACT}? 2. Does {PROTOCOL_CONTRACT} use `balanceOf(this)` for {RECEIPT_TOKEN} in any calculation? 3. Is there a tracked state variable that should equal the actual balance? 4. What happens if tracked ≠ actual?
For protocols with N entities:
Single entity dust: X tokens (below threshold, ignored) N entities with dust: N × X tokens Compounding factor: If dust compounds over time → N × X × T Check: Can attacker spread small amounts across many entities to: 1. Accumulate significant total value? 2. Avoid per-entity dust thresholds? 3. Exploit aggregation rounding?
When receipt tokens are transferred:
**Specific checks**: | Token | transfer() Side Effect | Exploitable? | |-------|----------------------|--------------| | Staking receipts | May claim rewards | Check if rewards go to sender/receiver/neither | | stETH | Rebases on transfer | Check exchange rate impact | | LP tokens | May trigger sync | Check for manipulation window | | cTokens/aTokens | May accrue interest | Check balance vs shares discrepancy |
For protocols managing multiple validators:
Pattern A: Dust Spreading - Attacker creates dust positions across N validators - Each position below withdrawal threshold - Total value: significant - Impact: locked value, accounting discrepancies Pattern B: Selective Validator Manipulation - Attacker identifies validator with exploitable state - Moves delegation to that specific validator - Exploits validator-specific vulnerability - Impact: depends on vulnerability Pattern C: Aggregation Rounding - Protocol rounds down per-validator withdrawals - Attacker exploits: N validators × rounding_error = significant loss/gain
When the p
Autonomous Web3 security auditor for Claude Code and OpenAI Codex CLI. Orchestrates 18-100 AI agents across 40+ phases to produce audit reports with verified PoC exploits — for smart contracts and L1 node-client infrastructure.
Repo: PlamenTSV/plamen
Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth…
Trigger Pattern Always (Aptos Move) - Move VM aborts on shift = bit width - Inject Into…
Trigger Protocol has privileged roles (admin, operator, governance, resource account owner) -…
Trigger EXTERNAL_LIB flag detected (protocol uses third-party Move dependencies) - Used by…
Trigger Pattern MONETARY_PARAMETER flag (required) - Inject Into Breadth agents (merged via…