Agent skill

Beacon Proxy

by ccashwell in ccashwell/evm-cortex

A skill your agent uses when deploying many identical upgradeable proxies using the Beacon proxy pattern.

MITAuto-check passed

Install Beacon Proxy

skills CLI
$ npx skills add ccashwell/evm-cortex --skill beacon-proxy -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ccashwell/evm-cortex beacon-proxy --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ccashwell/evm-cortex.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/beacon-proxy .claude/skills/beacon-proxy && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
beacon-proxy
GitHub stars
131
Token cost
~1.9k tokens
SKILL.md length
214 words
Files
1
Skills in repo
89
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when deploying many identical upgradeable proxies using the Beacon proxy pattern.

  • Deploying many identical upgradeable proxies using the Beacon proxy pattern
  • SKILL.md covers Overview, UpgradeableBeacon, BeaconProxy Deployment and Complete Factory Pattern, plus 7 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Beacon Proxy is an agent skill from ccashwell/evm-cortex. Use when deploying many identical upgradeable proxies using the Beacon proxy pattern. Covers UpgradeableBeacon, BeaconProxy, bulk upgrades, use cases, and comparison with UUPS/Transparent.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: Ethereum protocol engineering squad for AI coding assistants. The licence is MIT.

When your agent uses it

  • Deploying many identical upgradeable proxies using the Beacon proxy pattern

Example prompts

  • “/beacon-proxy”

What it can do on your machine

Read from SKILL.md and the folder at commit f8f3301. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are solidity).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Beacon Proxy loads about 1.9k tokens when it runs. Until then it costs about 50 tokens; SKILL.md has 214 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~50
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ccashwell/evm-cortex at commit f8f3301, republished under its MIT licence (© ccashwell). 214 words, ~1,926 tokens.

Download SKILL.mdSave it as .claude/skills/beacon-proxy/SKILL.md (or your agent's skills folder).
name
beacon-proxy
description
Use when deploying many identical upgradeable proxies using the Beacon proxy pattern. Covers UpgradeableBeacon, BeaconProxy, bulk upgrades, use cases, and comparison with UUPS/Transparent.

Beacon Proxy Pattern

Overview

The Beacon proxy pattern stores the implementation address in a shared Beacon contract. Multiple proxies point to the same Beacon. Upgrading the Beacon upgrades ALL proxies in a single transaction.

BeaconProxy-1 ──┐
BeaconProxy-2 ──┼──→ UpgradeableBeacon ──→ Implementation v1
BeaconProxy-3 ──┘

After upgrade:

BeaconProxy-1 ──┐
BeaconProxy-2 ──┼──→ UpgradeableBeacon ──→ Implementation v2
BeaconProxy-3 ──┘

UpgradeableBeacon

solidity
import {UpgradeableBeacon} from "@openzeppelin/contracts/proxy/beacon/UpgradeableBeacon.sol";

// Deploy beacon with initial implementation
address impl = address(new VaultV1());
UpgradeableBeacon beacon = new UpgradeableBeacon(impl, msg.sender);

// Upgrade all proxies at once
address newImpl = address(new VaultV2());
beacon.upgradeTo(newImpl);

BeaconProxy Deployment

solidity
import {BeaconProxy} from "@openzeppelin/contracts/proxy/beacon/BeaconProxy.sol";

// Each proxy points to the beacon (not the implementation directly)
bytes memory initData = abi.encodeCall(VaultV1.initialize, (owner, asset));
BeaconProxy proxy = new BeaconProxy(address(beacon), initData);

Complete Factory Pattern

solidity
// SPDX-License-Identifier: MIT
pragma solidity ^0.8.20;

import {UpgradeableBeacon} from "@openzeppelin/contracts/proxy/beacon/UpgradeableBeacon.sol";
import {BeaconProxy} from "@openzeppelin/contracts/proxy/beacon/BeaconProxy.sol";
import {Ownable} from "@openzeppelin/contracts/access/Ownable.sol";

contract VaultFactory is Ownable {
    UpgradeableBeacon public immutable beacon;
    address[] public allVaults;

    event VaultCreated(address indexed vault, address indexed owner, uint256 index);
    event ImplementationUpgraded(address indexed newImpl);

    constructor(address initialImpl) Ownable(msg.sender) {
        beacon = new UpgradeableBeacon(initialImpl, address(this));
    }

    function createVault(address vaultOwner, address asset)
        external returns (address vault)
    {
        bytes memory initData = abi.encodeCall(
            IVault.initialize, (vaultOwner, asset)
        );
        vault = address(new BeaconProxy(address(beacon), initData));
        allVaults.push(vault);
        emit VaultCreated(vault, vaultOwner, allVaults.length - 1);
    }

    function upgradeImplementation(address newImpl) external onlyOwner {
        beacon.upgradeTo(newImpl);
        emit ImplementationUpgraded(newImpl);
    }

    function implementation() external view returns (address) {
        return beacon.implementation();
    }

    function vaultCount() external view returns (uint256) {
        return allVaults.length;
    }
}

Implementation Contract

solidity
// SPDX-License-Identifier: MIT
pragma solidity ^0.8.20;

import {Initializable} from "@openzeppelin/contracts-upgradeable/proxy/utils/Initializable.sol";
import {IERC20} from "@openzeppelin/contracts/token/ERC20/IERC20.sol";
import {SafeERC20} from "@openzeppelin/contracts/token/ERC20/utils/SafeERC20.sol";

interface IVault {
    function initialize(address owner, address asset) external;
}

contract VaultV1 is Initializable, IVault {
    using SafeERC20 for IERC20;

    address public owner;
    IERC20 public asset;
    uint256 public totalDeposited;

    /// @custom:oz-upgrades-unsafe-allow constructor
    constructor() { _disableInitializers(); }

    function initialize(address owner_, address asset_) external override initializer {
        owner = owner_;
        asset = IERC20(asset_);
    }

    function deposit(uint256 amount) external {
        asset.safeTransferFrom(msg.sender, address(this), amount);
        totalDeposited += amount;
    }

    function withdraw(uint256 amount) external {
        require(msg.sender == owner, "Not owner");
        totalDeposited -= amount;
        asset.safeTransfer(owner, amount);
    }
}

contract VaultV2 is Initializable, IVault {
    using SafeERC20 for IERC20;

    address public owner;
    IERC20 public asset;
    uint256 public totalDeposited;
    // V2: new storage variable (appended, never reorder)
    uint256 public depositCap;

    /// @custom:oz-upgrades-unsafe-allow constructor
    constructor() { _disableInitializers(); }

    function initialize(address owner_, address asset_) external override initializer {
        owner = owner_;
        asset = IERC20(asset_);
    }

    function setDepositCap(uint256 cap) external {
        require(msg.sender == owner, "Not owner");
        depositCap = cap;
    }

    function deposit(uint256 amount) external {
        require(depositCap == 0 || totalDeposited + amount <= depositCap, "Cap exceeded");
        asset.safeTransferFrom(msg.sender, address(this), amount);
        totalDeposited += amount;
    }

    function withdraw(uint256 amount) external {
        require(msg.sender == owner, "Not owner");
        totalDeposited -= amount;
        asset.safeTransfer(owner, amount);
    }
}

Beacon vs UUPS vs Transparent

FeatureBeaconUUPSTransparent
Upgrade scopeAll proxies at onceOne proxy at a timeOne proxy at a time
Who upgradesBeacon ownerImplementationProxy admin
Gas per call+2600 (SLOAD beacon)+200+2100 (admin check)
Deploy cost/proxy~47k~65k~120k
Best forMany identical instancesGeneral purposeGoverned contracts

When to Use Beacon

  • Deploying many proxies with the same implementation (vaults, accounts, pools)
  • Need to upgrade all instances simultaneously
  • Factory pattern where users deploy their own instance
  • Protocol wants single upgrade transaction (simpler governance)

Gas Considerations

Each call to a BeaconProxy costs an extra SLOAD (~2100 gas cold, ~100 warm) to read the implementation address from the Beacon. For high-frequency calls, consider caching patterns or UUPS instead.

Deterministic Beacon Proxies

solidity
function createVaultDeterministic(
    address vaultOwner,
    address asset,
    bytes32 salt
) external returns (address vault) {
    bytes memory initData = abi.encodeCall(IVault.initialize, (vaultOwner, asset));
    vault = address(new BeaconProxy{salt: salt}(address(beacon), initData));
    allVaults.push(vault);
}

Testing

solidity
function test_beaconUpgrade() public {
    VaultV1 implV1 = new VaultV1();
    VaultFactory factory = new VaultFactory(address(implV1));

    address vault = factory.createVault(alice, address(usdc));
    assertEq(factory.implementation(), address(implV1));

    // Deposit with V1
    vm.startPrank(alice);
    usdc.approve(vault, 100e6);
    VaultV1(vault).deposit(100e6);
    assertEq(VaultV1(vault).totalDeposited(), 100e6);
    vm.stopPrank();

    // Upgrade to V2
    VaultV2 implV2 = new VaultV2();
    factory.upgradeImplementation(address(implV2));

    // State preserved, new function available
    assertEq(VaultV2(vault).totalDeposited(), 100e6);
    vm.prank(alice);
    VaultV2(vault).setDepositCap(1000e6);
    assertEq(VaultV2(vault).depositCap(), 1000e6);
}

Security Checklist

  • Beacon owner is a multisig or governance contract
  • Implementation follows storage layout rules (append-only)
  • _disableInitializers() in implementation constructor
  • Test upgrade path preserves all existing state
  • New implementation is deployed and verified before upgrade
  • Beacon address is immutable in factory (cannot be swapped)

© ccashwell, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/beacon-proxy of ccashwell/evm-cortex.

Open the folder on GitHubat commit f8f3301

Compare with similar skills

Beacon Proxy next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Beacon Proxy compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Beacon Proxy this skillccashwell/evm-cortex131—~1.9kAutomated safety check: PassMIT
Configuring Identity Aware Proxy With Google Iapmukul975/Anthropic-Cybersecurity-Skills34k—~3.7kAutomated safety check: PassApache-2.0
Deploy Setupgarrytan/gstack136k—~11kAutomated safety check: NotesMIT
Deployment Patternsaffaan-m/ECC274k1 repos~2.9kAutomated safety check: PassMIT
Vercel Deploybytedance/deer-flow83k10 repos~797Automated safety check: PassMIT
Land and Deploygarrytan/gstack136k—~18kAutomated safety check: NotesMIT

Similar skills

  • Configuring Identity Aware Proxy With Google Iap

    mukul975/Anthropic-Cybersecurity-Skills

    Configures Google Cloud Identity-Aware Proxy (IAP) via gcloud to enforce per-request identity verification on Compute Engine, App Engine, Cloud Run, and GKE, including IAM bindings, Access Context…

    34k GitHub stars~3.7k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Deploy Setup

    garrytan/gstack

    Detects where an app deploys, its production URL and health checks, then saves the deploy configuration in CLAUDE.md for /land-and-deploy.

    136k GitHub stars~11k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Deployment iş akışları, CI/CD pipeline kalıpları, Docker konteynerizasyonu, sağlık kontrolleri, rollback stratejileri ve web uygulamaları için üretim hazırlığı kontrol listeleri.

    274k GitHub starsUsed in 1 repo~2.9k tokens
    DevOps & CloudAuto-check passed
  • Vercel Deploy

    bytedance/deer-flow

    Deploys a project to Vercel with one script and no login, then returns a live preview URL and a claim link for moving the deployment into your own Vercel account.

    83k GitHub starsUsed in 10 repos~797 tokens
    DevOps & CloudAuto-check passed
  • Land and Deploy

    garrytan/gstack

    Merges a pull request, waits for CI and the deploy, then verifies production health with canary checks, picking up where /ship leaves off.

    136k GitHub stars~18k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Covers rolling, blue-green and canary deployments, multi-stage Dockerfiles, a GitHub Actions pipeline, health checks and production readiness for web apps.

    274k GitHub starsUsed in 6 repos~2.8k tokens
    DevOps & CloudAuto-check passed

More from ccashwell/evm-cortex

All 89 skills in this repo
  • Xray Pre Audit

    ccashwell/evm-cortex

    A skill your agent uses when preparing for a security audit, performing reconnaissance on a new codebase, or creating a protocol overview.

    131 GitHub stars~25k tokensUpdated 8 days ago
    Auto-check passed
  • Aave Integration

    ccashwell/evm-cortex

    A skill your agent uses when integrating with Aave V3 for lending, borrowing, flash loans, or building on top of Aave markets.

    131 GitHub stars~1.3k tokensUpdated 8 days ago
    Auto-check passed
  • Access Control Patterns

    ccashwell/evm-cortex

    Access control design patterns for Solidity protocols. An agent skill from ccashwell/evm-cortex.

    131 GitHub stars~1.8k tokensUpdated 8 days ago
    Auto-check passed
  • Anvil Patterns

    ccashwell/evm-cortex

    A skill your agent uses when running a local Ethereum node with Anvil.

    131 GitHub stars~1.3k tokensUpdated 8 days ago
    Auto-check passed
  • Audit Breadth Scan

    ccashwell/evm-cortex

    A skill your agent uses when performing systematic breadth-first review of all contracts during a security audit.

    131 GitHub stars~1.4k tokensUpdated 8 days ago
    Auto-check passed
  • Audit Depth Analysis

    ccashwell/evm-cortex

    A skill your agent uses when performing deep analysis of specific findings or high-risk areas during a security audit.

    131 GitHub stars~1.6k tokensUpdated 8 days ago
    Auto-check passed

Questions about Beacon Proxy

What does Beacon Proxy do?

A skill your agent uses when deploying many identical upgradeable proxies using the Beacon proxy pattern. Beacon Proxy is an agent skill from ccashwell/evm-cortex. Use when deploying many identical upgradeable proxies using the Beacon proxy pattern.

When should I use Beacon Proxy?

Beacon Proxy fits situations like: deploying many identical upgradeable proxies using the Beacon proxy pattern.

How do I install Beacon Proxy in Claude Code?

Run `npx skills add ccashwell/evm-cortex --skill beacon-proxy -a claude-code`. Or copy the skill folder (skills/beacon-proxy in ccashwell/evm-cortex) into .claude/skills/beacon-proxy in your project. Claude Code loads it when a task matches its description.

How do I install Beacon Proxy in Codex?

Run `npx skills add ccashwell/evm-cortex --skill beacon-proxy -a codex`. Or copy the skill folder (skills/beacon-proxy in ccashwell/evm-cortex) into .agents/skills/beacon-proxy in your project. Codex loads it when a task matches its description.

Can I use Beacon Proxy in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ccashwell/evm-cortex --skill beacon-proxy -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/beacon-proxy, .gemini/skills/beacon-proxy, .github/skills/beacon-proxy and .opencode/skills/beacon-proxy in your project.

What does Beacon Proxy need to run?

SKILL.md names no scripts, command-line tools or credentials: Beacon Proxy is instructions for the agent only.

Does Beacon Proxy access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Beacon Proxy safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Beacon Proxy use?

Beacon Proxy is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Beacon Proxy use?

About 1.9k tokens (SKILL.md is roughly 7.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Beacon Proxy?

Skills that share tags, products or a category with Beacon Proxy: Configuring Identity Aware Proxy With Google Iap (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Deploy Setup (garrytan/gstack, 136k stars), Deployment Patterns (affaan-m/ECC, 274k stars) and Vercel Deploy (bytedance/deer-flow, 83k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Beacon Proxy?

ccashwell (a GitHub user) maintains it in ccashwell/evm-cortex, which has 131 GitHub stars. The repository holds 89 skills in this directory. The repository was last updated on September 30, 2026.

Source: ccashwell/evm-cortex on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.