ability-analysis
Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth…
Trigger Pattern BALANCE_DEPENDENT flag (required) - Inject Into Depth-token-flow, breadth agents
$ npx -y skills add PlamenTSV/plamen --skill token-flow-tracing --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/token-flow-tracingContext preview
The summary Claude sees to decide when to auto-load this skill.
Trigger Pattern BALANCE_DEPENDENT flag (required) - Inject Into Depth-token-flow, breadth agents
name: "token-flow-tracing" description: "Trigger Pattern BALANCE_DEPENDENT flag (required) - Inject Into Depth-token-flow, breadth agents"
> **Trigger Pattern**: BALANCE_DEPENDENT flag (required) > **Inject Into**: Depth-token-flow, breadth agents > **Purpose**: Trace all token flows through Aptos Move protocols using FungibleAsset and Coin<T> models, identifying accounting desync, unsolicited deposit vectors, type confusion, and dispatchable hook side effects
For every token the protocol handles:
Enumerate ALL asset types the protocol handles:
| Asset | Model | Type Parameter / Metadata | Decimals | Entry Modules | Exit Modules | |-------|-------|--------------------------|----------|---------------|-------------| | {name} | Coin<T> / FungibleAsset | {CoinType or metadata Object} | {decimals} | {list} | {list} |
**Aptos dual token model**:
Where can tokens enter the protocol?
| Entry Path | Function | Asset Model | Accounting Updated? | Access Control | |------------|----------|-------------|--------------------|--------------| | Standard deposit | {deposit_fn} | {Coin/FA} | YES/NO | {who can call} | | `primary_fungible_store::deposit()` | External | FA | NO (protocol unaware) | Permissionless | | `coin::deposit<T>()` | External | Coin<T> | NO (protocol unaware) | Permissionless (if CoinStore registered) | | Direct `fungible_asset::deposit()` | Via store ref | FA | NO (protocol unaware) | Requires FungibleStore reference | | `move_to<T>()` | Internal | Resource | {depends} | Module only | | Side-effect receipts | External call returns | {varies} | {depends} | {depends} |
**Red flags**:
Where can tokens leave the protocol?
| Exit Path | Function | Asset Model | Accounting Updated? | Access Control | |-----------|----------|-------------|--------------------|--------------| | Standard withdraw | {withdraw_fn} | {Coin/FA} | YES/NO | {who can call} | | `primary_fungible_store::withdraw()` | Via signer | FA | {depends} | Requires signer capability | | `coin::withdraw<T>()` | Via signer | Coin<T> | {depends} | Requires signer | | `fungible_asset::withdraw()` | Via store ref | FA | {depends} | Requires store `&mut` ref or TransferRef | | Fee distribution | {fee_fn} | {varies} | YES/NO | {access} | | Emergency withdraw | {emergency_fn} | {varies} | YES/NO | {admin} |
For each exit: does the tracked balance decrease BEFORE or AFTER the actual transfer? For each transfer call: can the source account be underfunded at execution time? (funds deployed externally, locked, or lent out → transfer reverts)
For each transfer function: can the sender and recipient be the same account/address? If YES: does a self-transfer update accounting state (fees credited, rewards claimed, snapshots updated, share ratios changed) without net token movement? Flag as FINDING.
For each asset type:
| Asset | Internal Tracking Variable | On-Chain Balance Query | Can Desync? | Desync Vector | |-------|---------------------------|----------------------|-------------|---------------| | {name} | {e.g., total_deposited in resource} | `fungible_asset::balance(store)` or `coin::balance<T>(addr)` | YES/NO | {if YES: how} |
**Critical question**: Does the protocol use internal accounting or direct on-chain balance queries?
**Red flags**:
Can tokens be deposited to the protocol without calling its deposit function?
If **YES** (most cases on Aptos):
| Vector | Asset Model | Protocol Aware? | Impact | |--------|-------------|----------------|--------| | `primary_fungible_store::deposit(protocol_addr, fa)` | FA | NO | {impact} | | `coin::deposit<T>(protocol_addr, coin)` | Coin<T> | NO | {impact} | | Direct transfer to object-owned store | FA | NO | {impact} |
For EVERY external token type the protocol holds, queries, or receives as side effects:
| Token Type | Can Deposit Unsolicited? | Accounting Distortion? | Share Inflation? | Threshold Manipulation? | Reward Dilution? | Fee Calculation Impact? | |------------|------------------------|----------------------|-----------------|----------------------|-----------------|----------------------| | {token_a} | YES/NO | YES/NO | YES/NO | YES/NO | YES/NO | YES/NO |
**RULE**: If ANY token type is unsolicited-depositable AND affects state -> analyze each consequence:
Autonomous Web3 security auditor for Claude Code and OpenAI Codex CLI. Orchestrates 18-100 AI agents across 40+ phases to produce audit reports with verified PoC exploits — for smart contracts and L1 node-client infrastructure.
Repo: PlamenTSV/plamen
Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth…
Trigger Pattern Always (Aptos Move) - Move VM aborts on shift = bit width - Inject Into…
Trigger Protocol has privileged roles (admin, operator, governance, resource account owner) -…
Trigger EXTERNAL_LIB flag detected (protocol uses third-party Move dependencies) - Used by…
Trigger Pattern MONETARY_PARAMETER flag (required) - Inject Into Breadth agents (merged via…