ability-analysis
Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth…
L1 trigger - audits validator entry/exit transitions, slashing correctness, leader-duplicate handling, and lifecycle state invariants for PoS / DPoS / BFT consensus clients.
$ npx -y skills add PlamenTSV/plamen --skill validator-lifecycle-and-slashing --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/validator-lifecycle-and-slashingContext preview
The summary Claude sees to decide when to auto-load this skill.
L1 trigger - audits validator entry/exit transitions, slashing correctness, leader-duplicate handling, and lifecycle state invariants for PoS / DPoS / BFT consensus clients.
name: "validator-lifecycle-and-slashing" description: "L1 trigger - audits validator entry/exit transitions, slashing correctness, leader-duplicate handling, and lifecycle state invariants for PoS / DPoS / BFT consensus clients."
> **L1 trigger**: `L1_PATTERN=true` AND (`slashing/` OR `validator/` OR `staking/` OR `x/slashing` OR `x/staking` OR `unbonding` OR `delegator` detected in recon subsystem map) > **Inject Into**: `depth-state-trace` or `depth-consensus-invariant` > **Language**: Go and Rust > **Finding prefix**: `[VL-N]` > **Status**: v0.1 draft (added from Round 4 gap analysis)
Recon identifies a PoS / DPoS / BFT staking subsystem. This skill is ADJACENT to but distinct from `fork-choice-audit` and `consensus-safety-invariants`: those cover "which chain is head" and "does the state machine stay consistent," while this one covers **"who counts as a validator right now, and when must they be punished."**
Round 4 gap analysis identified this as a pattern with ≥3 public exemplars not well-covered by the existing skill pack.
Every staking system has a finite state machine for validator status. Common states:
| State | Meaning | Typical transitions | |---|---|---| | **Pending / Deposited** | Funds deposited, not yet active | → Active (on epoch boundary) | | **Active** | Currently producing blocks / signing attestations | → Exiting (voluntary), → Slashed (on misbehavior), → Jailed (on downtime) | | **Exiting** | Requested to leave, funds locked | → Unbonding | | **Unbonding** | Exit period elapsing; still slashable | → Withdrawable | | **Withdrawable** | Funds claimable | → (removed) | | **Jailed / Tombstoned** | Temporarily removed for downtime | → Active (on unjail) | | **Slashed** | Permanently penalized | → Unbonding (with reduced stake) |
1. Enumerate every state transition in the validator state machine 2. For each, identify the trigger (epoch boundary, tx message, slashing evidence, timeout) 3. For each transition, enumerate the state variables that MUST be updated (active set, delegator shares, power index, reward accumulator, slashing index) 4. Check: does every code path through the transition update ALL variables? 5. **Check idempotency**: can the same transition fire twice? What happens?
Tag: `[VL-STATE:{transition}:{missing-update}]`
Slashing is the enforcement mechanism for validator misbehavior. Bugs here let malicious validators escape penalty or let honest validators be wrongly punished.
Enumerate every offense the protocol defines:
For each, find the detection code and verify: 1. Detection is triggered on every path the offense can occur through (not just the obvious one) 2. The slashing amount is correct per protocol spec 3. The slashing is **attributable** to a specific validator (not a validator set) 4. The slashing is **immediate** or **delayed** per spec (not accidentally skipped)
Attacker wants to escape slashing by transitioning to a non-slashable state before detection fires. Key check:
**Can a validator exit / re-delegate / unbond between committing an offense and being detected?**
If yes, the evidence window is too short — the protocol has a slashing evasion bug. Examples:
Tag: `[VL-EVASION:{offense}:{window-gap}]`
Conversely: a validator should not be slashed twice for the same evidence. Check: is there a slashed-offenses set / bitmap? Is it consulted before slashing?
Slashing burns stake. Verify:
Tag: `[VL-MATH:{op}:{issue}]`
Related to `fork-choice-audit` Section 3, but focused on validator-level accountability:
Tag: `[VL-DUPLICATE:{handling}]`
Epoch transitions are a critical moment when pending validators become active, exiting validators leave, and the total stake changes. Bugs at epoch boundaries:
Autonomous Web3 security auditor for Claude Code and OpenAI Codex CLI. Orchestrates 18-100 AI agents across 40+ phases to produce audit reports with verified PoC exploits — for smart contracts and L1 node-client infrastructure.
Repo: PlamenTSV/plamen
Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth…
Trigger Pattern Always (Aptos Move) - Move VM aborts on shift = bit width - Inject Into…
Trigger Protocol has privileged roles (admin, operator, governance, resource account owner) -…
Trigger EXTERNAL_LIB flag detected (protocol uses third-party Move dependencies) - Used by…
Trigger Pattern MONETARY_PARAMETER flag (required) - Inject Into Breadth agents (merged via…