Agent skill

Defi Invariant Check

by mtarcure in mtarcure/claude-vibe-squad

A skill your agent uses when the audit target is a DeFi protocol — AMM, lending market, yield vault, stablecoin, or perps — and you must author the economic properties generic campaigns miss, such…

MITAuto-check passedBusiness, Finance & HR

Install Defi Invariant Check

skills CLI
$ npx skills add mtarcure/claude-vibe-squad --skill defi-invariant-check -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mtarcure/claude-vibe-squad defi-invariant-check --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mtarcure/claude-vibe-squad.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/defi-invariant-check .claude/skills/defi-invariant-check && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
defi-invariant-check
GitHub stars
165
Token cost
~2.5k tokens
SKILL.md length
1,144 words
Files
1
Skills in repo
17
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when the audit target is a DeFi protocol — AMM, lending market, yield vault, stablecoin, or perps — and you must author the economic properties generic campaigns miss, such…

  • Works in 8 steps: Identify the protocol class. AMM,… → Author Echidna properties. Write… → Run Echidna — minimum 30 minutes for… → …
  • The audit target is a DeFi protocol — AMM
  • SKILL.md covers Invariant categories, Order of ops, When to pivot and Anti-patterns, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Defi Invariant Check is an agent skill from mtarcure/claude-vibe-squad. Use when the audit target is a DeFi protocol — AMM, lending market, yield vault, stablecoin, or perps — and you must author the economic properties generic campaigns miss, such as token-conservation, constant-product k, share accounting, collateralization, and oracle-deviation invariants, then falsify them.

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Business, Finance & HR, covering Crypto and DeFi analysis. The repository describes itself as: Multi-model AI orchestration where behaviour is Markdown, not code. One coordinator routes scoped task packets to 71 role-based specialists across 5 model families (Codex /… The licence is MIT.

When your agent uses it

  • The audit target is a DeFi protocol — AMM
  • Perps — and you must author the economic properties generic campaigns miss
  • Such as token-conservation
  • Constant-product k

Example prompts

  • “/defi-invariant-check”

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. Identify the protocol class. AMM, lending, vault, bridge, stablecoin, or perps. Each class has a canonical invariant set (use the category…
  2. Author Echidna properties. Write properties as Solidity functions with prefix echidna_ that return bool. Properties must be pure…
  3. Run Echidna — minimum 30 minutes for DeFi protocols
  4. Run Medusa as a second pass if Echidna does not find violations — Medusa's
  5. Flash-loan attack simulation. Manually construct a flash-loan attack call sequence in a
  6. Price-oracle and NAV manipulation check. For protocols with on-chain price oracles
  7. Governance/timelock check. Queue each value-moving privileged operation, then mutate
  8. Rounding/precision check. Fuzz zero-supply initialization, dust values around every

What it can do on your machine

Read from SKILL.md and the folder at commit 7bd69f8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash and solidity).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Defi Invariant Check loads about 2.5k tokens when it runs. Until then it costs about 82 tokens; SKILL.md has 1,144 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~82
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from mtarcure/claude-vibe-squad at commit 7bd69f8, republished under its MIT licence (© mtarcure). 1,144 words, ~2,511 tokens.

Download SKILL.mdSave it as .claude/skills/defi-invariant-check/SKILL.md (or your agent's skills folder).
name
defi-invariant-check
description
Use when the audit target is a DeFi protocol — AMM, lending market, yield vault, stablecoin, or perps — and you must author the economic properties generic campaigns miss, such as token-conservation, constant-product k, share accounting, collateralization, and oracle-deviation invariants, then falsify them.
audience
specialist
<!-- inspired by trailofbits/skills (concept); repointed to native CLIs for Chrono -->

defi-invariant-check

DeFi-specific invariant authoring and testing discipline. Use this as a sub-skill during evm-audit-flow when the target is a DeFi protocol (AMM, lending, yield, bridge, stablecoin, perps). Generic Echidna/Medusa campaigns miss DeFi-specific invariants — this skill provides the property checklist. All tools are the native host CLIs (echidna, medusa, forge, halmos) run in the target project directory; there is no wrapper layer.

Invariant categories

Token accounting invariants (always required):

  • totalSupply == sum(balanceOf(all_holders)) — no spurious minting or burning.
  • reserve0 * reserve1 >= k (for constant-product AMMs) — k-invariant never decreases except via fee accrual.
  • totalBorrow <= totalDeposit for all lending pools — protocol cannot lend out more than deposited.
  • sum(userShares) == totalShares for yield vaults — share accounting is consistent.

Access-control invariants:

  • Only authorized roles can set oracle addresses, fee parameters, or pause state.
  • onlyOwner/onlyGovernance functions cannot be called by arbitrary external accounts.
  • Upgradeable proxy implementation slots cannot be modified except through the upgrade pathway.

Economic/oracle invariants:

  • Flash loan callbacks cannot leave the protocol in a net-loss state after the loan repayment.
  • Liquidation proceeds must cover the borrowed amount plus protocol fee — no bad-debt accrual from liquidations.

2026 incident-derived oracle-input robustness invariants (highest-priority economic class):

  • Spot versus TWAP: a price used for collateral, borrowing, liquidation, minting, or redemption must reject or clamp a same-block spot price when abs(spot - TWAP) / TWAP > maxDeviation; no value-affecting path may silently fall back to the divergent spot. This targets the oracle/valuation-manipulation class represented by Moonwell (2026-08-27), Lazy Summer (2026-07-06), Makina (2026-01-20), and Edel (2026-07-01) in V114-51.
  • Low-liquidity collateral: within the protocol's configured manipulation budget, an atomic trade against a thin market cannot increase an account's borrowable value or liquidation proceeds by more than the attacker's net cost plus the configured safety margin. Reject collateral whose observable depth cannot support the valuation notional. This is the Moonwell low-liquidity-collateral oracle shape from V114-51.
  • NAV manipulation bound: absent external profit or loss, a deposit/reprice/redeem round trip across any supported asset must not return more value than entered after fees and rounding tolerance, and one manipulable component price must not move total NAV beyond its configured exposure and deviation caps. This targets the Lazy Summer, Makina, and Edel valuation/NAV incident class from V114-51.

2026 incident-derived governance/timelock invariants (second priority):

  • Delay cannot be bypassed or shortened: for every queued privileged operation, executedAt - queuedAt >= max(delayAtQueue, protocolMinimumDelay). Changing the delay, executor, proposer, or role graph after queueing cannot accelerate that operation, and a delay change itself becomes effective only after the pre-change delay. This targets Term Finance's 2026-08-24 timelock-zeroing shape from V114-51.
  • A role or executor change cannot authorize its own proposal or execution; every privilege expansion must be queued and executed by the pre-change authority after the full pre-change delay. Snapshot the audited role graph and assert that no post-deployment role drift broadens value-moving authority outside that path. This targets the TOP (2026-06-26) and BonkDAO (2026-07-26) governance-bypass shapes from V114-51.

Rounding/precision invariants (third priority, still required):

  • Exercise zero-supply initialization, one-unit deposits/withdrawals, values immediately below and above every division boundary, and repeated dust operations. No non-zero asset input may mint zero shares unless the transaction reverts or the loss is explicitly bounded; no positive supply or assets may exist without corresponding claimable shares.
  • A deposit/redeem or mint/withdraw round trip, with no external profit or loss, must return the starting economic value within the documented fee and rounding bound; splitting one operation into many dust-sized operations cannot improve that bound.
  • Fuzz solver domains and every fixed-point math-library boundary used by share conversion, including zero denominators, scale changes, and minimum/maximum supported values. These properties retain the dust/zero-supply class seen twice at Thetanuts in June 2026, while placing it behind the two larger 2026 code-level classes identified by V114-51.

Reentrancy invariants:

  • Protocol state (balances, reserves, shares) after any external call must equal the state written before the call (CEI pattern verification).
  • No re-entrant call can increase the caller's balance beyond their pre-call entitlement.
Show full SKILL.md (519 more words)Show less

Order of ops

  1. Identify the protocol class. AMM, lending, vault, bridge, stablecoin, or perps. Each class has a canonical invariant set (use the category checklist above).

  2. Author Echidna properties. Write properties as Solidity functions with prefix echidna_ that return bool. Properties must be pure invariants (no state mutations inside the property). Place in test/invariants/EchidnaTest.sol.

  3. Run Echidna — minimum 30 minutes for DeFi protocols:

    bash
    echidna . --contract EchidnaTest --config echidna.yaml --test-limit 500000

    Use testMode: assertion in echidna.yaml for complex multi-step violations.

  4. Run Medusa as a second pass if Echidna does not find violations — Medusa's coverage-guided corpus often finds violations Echidna's random mutation misses:

    bash
    medusa fuzz --config medusa.json
  5. Flash-loan attack simulation. Manually construct a flash-loan attack call sequence in a Forge test that instantiates a FlashLoanAttacker contract, then run forge test --match-contract FlashLoanAttacker -vvvv. Verify the k-invariant or balance-conservation invariant holds after the attack sequence.

  6. Price-oracle and NAV manipulation check. For protocols with on-chain price oracles: write a Forge test that varies market depth, creates large single-block spot/TWAP divergence, and reprices each NAV component. Check whether the oracle-derived price would enable profitable liquidations, under-collateralized borrows, or a profitable deposit/reprice/redeem round trip (forge test --match-test testOracleManip -vvvv).

  7. Governance/timelock check. Queue each value-moving privileged operation, then mutate the delay and role graph and attempt early or self-authorized execution. Use the target framework's time-warp primitive to assert that execution remains impossible until the greater of the queued delay and protocol minimum has elapsed.

  8. Rounding/precision check. Fuzz zero-supply initialization, dust values around every division boundary, split-versus-batched operations, and deposit/redeem round trips. Keep tolerances in the protocol's documented units; a tolerance must not erase a zero-share mint or ghost-supply state.

When to pivot

  • Echidna cannot construct valid state transitions: the protocol requires complex setup (governance votes, time-locks, external oracle seeding). Author a setup harness in a CryticSetup contract that initializes the protocol to a valid post-deployment state.
  • Invariant is too weak: Echidna falsifies it immediately with trivial inputs. Tighten the property — e.g., add a precondition (require(totalSupply > 0)) to avoid vacuous falsification.
  • Protocol uses proxy pattern: Echidna tests the proxy ABI; ensure the proxy's fallback routes correctly to the implementation in the test environment.

Anti-patterns

  • Do NOT author invariants that pass by construction — e.g., an echidna_ property that trivially returns true because the function under test is never called.
  • Do NOT treat a single Echidna passed result as proof of correctness — Echidna is a fuzzer, not a prover. Use halmos for bounded formal guarantees on critical properties (halmos --function check_ --loop 4).
  • Do NOT skip flash-loan simulation for lending/AMM protocols — flash loans invalidate many invariants that hold under normal call conditions.

Example

Writing and running an Echidna token conservation invariant:

solidity
// test/invariants/EchidnaTest.sol
contract EchidnaTest {
    Token token;

    function echidna_total_supply_equals_sum() public view returns (bool) {
        // totalSupply must equal sum of all holder balances
        return token.totalSupply() == token.balanceOf(address(this))
                                     + token.balanceOf(address(0xdead));
    }
}
bash
echidna . --contract EchidnaTest --config echidna.yaml --test-limit 500000

Recording (chrono-vault)

The task packet's injected memory contract owns the exact call shape, sequence, and fields - see wirework-reflect. Do not copy a record(...) example or add fields (including source_task) from memory; the server binds them, and a baked example violates the run's authenticated schema. Memory is best-effort telemetry and never gates the work. What is worth recording here is the task-specific outcome: protocol class, invariants tested, violations, flash-loan/oracle-manip tested?.

© mtarcure, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/defi-invariant-check of mtarcure/claude-vibe-squad.

Open the folder on GitHubat commit 7bd69f8

Compare with similar skills

Defi Invariant Check next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Defi Invariant Check compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Defi Invariant Check this skillmtarcure/claude-vibe-squad165—~2.5kAutomated safety check: PassMIT
Technical Analysttradermonty/claude-trading-skills3k4 repos~4.6kAutomated safety check: PassMIT
Polyclawchainstacklabs/polyclaw3591 repos~2kAutomated safety check: PassApache-2.0
Longbridge Researchhelsome/folio2713 repos~2.1kAutomated safety check: PassMIT
Stock Analysis24mlight/StockClaw1012 repos~2kAutomated safety check: NotesMIT
Swapper Depositswapperfinance/swapper-toolkit852—~1.8kAutomated safety check: PassMIT

Similar skills

  • Technical Analyst

    tradermonty/claude-trading-skills

    This skill should be used when analyzing weekly price charts for stocks, stock indices, cryptocurrencies, or forex pairs.

    3k GitHub starsUsed in 4 repos~4.6k tokens
    Business, Finance & HRAuto-check passed
  • Polyclaw

    chainstacklabs/polyclaw

    Trade on Polymarket via split + CLOB execution. An agent skill from chainstacklabs/polyclaw.

    359 GitHub starsUsed in 1 repo~2k tokens
    Business, Finance & HRAuto-check passed
  • Longbridge Research

    helsome/folio

    Institution ratings, consensus price targets, EPS/revenue forecasts, finance calendar, shareholder data, fund holders, insider trades (SEC Form 4), short interest, industry rankings, peer group…

    271 GitHub starsUsed in 3 repos~2.1k tokens
    Business, Finance & HRAuto-check passed
  • Stock Analysis

    24mlight/StockClaw

    Analyze stocks and cryptocurrencies using Yahoo Finance data.

    101 GitHub starsUsed in 2 repos~2k tokens
    Business, Finance & HRAuto-check: notes
  • Swapper Deposit

    swapperfinance/swapper-toolkit

    Deposit and bridge funds into a wallet or protocol using Swapper Finance.

    852 GitHub stars~1.8k tokensUpdated 6 mo ago
    Business, Finance & HRAuto-check passed
  • Okx Cex Earn

    okx/agent-skills

    Manages OKX Simple Earn (flexible savings/lending), Flash Earn, On-chain Earn (staking/DeFi), Dual Investment (DCD/双币赢), and AutoEarn (自动赚币) via the okx CLI.

    187 GitHub starsUsed in 2 repos~3.3k tokens
    Business, Finance & HRAuto-check passed

More from mtarcure/claude-vibe-squad

All 17 skills in this repo
  • Systematic Attacking

    mtarcure/claude-vibe-squad

    A skill your agent uses for ALL authorized offensive-security / bug-bounty work — the single method to find, chain, prove, dedup, and package the highest-value (High/Critical) findings across every…

    165 GitHub stars~3.6k tokensUpdated 19 days ago
    Auto-check passed
  • Blind Rediscovery

    mtarcure/claude-vibe-squad

    Operational checklist + helper for blind-rediscovery fan-out work.

    165 GitHub stars~1.6k tokensUpdated 19 days ago
    Auto-check passed
  • Chain Construct Smart Contract

    mtarcure/claude-vibe-squad

    A skill your agent uses when you have a confirmed on-chain vulnerability hypothesis and must demonstrate it with a passing proof-of-concept — author an attacker contract or crafted instruction…

    165 GitHub stars~1.5k tokensUpdated 19 days ago
    Auto-check passed
  • Compact Now

    mtarcure/claude-vibe-squad

    Operator-triggered proactive compaction — Chrono externalizes load-bearing state (active decisions, open tasks, next action) to a snapshot + a durable Vault learning note before invoking Claude…

    165 GitHub stars~1.6k tokensUpdated 19 days ago
    Auto-check passed
  • Agent Prompt Engineering

    mtarcure/claude-vibe-squad

    A skill your agent uses when building or revising the system prompt for a product agent and you need an eval-backed boundary, tool-use, grounding, and output contract.

    165 GitHub stars~872 tokensUpdated 19 days ago
    Auto-check: warnings
  • Dependency Cycle Audit

    mtarcure/claude-vibe-squad

    A skill your agent uses when module, package, or build dependencies may contain cycles, especially load-order failures, broad rebuilds, or a planned extraction: derive the real graph, compute…

    165 GitHub stars~1.5k tokensUpdated 19 days ago
    Auto-check passed

Questions about Defi Invariant Check

What does Defi Invariant Check do?

A skill your agent uses when the audit target is a DeFi protocol — AMM, lending market, yield vault, stablecoin, or perps — and you must author the economic properties generic campaigns miss, such…. Defi Invariant Check is an agent skill from mtarcure/claude-vibe-squad. Use when the audit target is a DeFi protocol — AMM, lending market, yield vault, stablecoin, or perps — and you must author the economic properties generic campaigns miss, such as token-conservation, constant-product k, share accounting, collateralization, and oracle-deviation invariants, then falsify them.

When should I use Defi Invariant Check?

Defi Invariant Check fits situations like: the audit target is a DeFi protocol — AMM; perps — and you must author the economic properties generic campaigns miss; such as token-conservation; constant-product k.

How do I install Defi Invariant Check in Claude Code?

Run `npx skills add mtarcure/claude-vibe-squad --skill defi-invariant-check -a claude-code`. Or copy the skill folder (.agents/skills/defi-invariant-check in mtarcure/claude-vibe-squad) into .claude/skills/defi-invariant-check in your project. Claude Code loads it when a task matches its description.

How do I install Defi Invariant Check in Codex?

Run `npx skills add mtarcure/claude-vibe-squad --skill defi-invariant-check -a codex`. Or copy the skill folder (.agents/skills/defi-invariant-check in mtarcure/claude-vibe-squad) into .agents/skills/defi-invariant-check in your project. Codex loads it when a task matches its description.

Can I use Defi Invariant Check in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mtarcure/claude-vibe-squad --skill defi-invariant-check -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/defi-invariant-check, .gemini/skills/defi-invariant-check, .github/skills/defi-invariant-check and .opencode/skills/defi-invariant-check in your project.

What does Defi Invariant Check need to run?

SKILL.md names no scripts, command-line tools or credentials: Defi Invariant Check is instructions for the agent only.

Does Defi Invariant Check access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Defi Invariant Check safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Defi Invariant Check use?

Defi Invariant Check is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Defi Invariant Check use?

About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Defi Invariant Check?

Skills that share tags, products or a category with Defi Invariant Check: Technical Analyst (tradermonty/claude-trading-skills, 3k stars), Polyclaw (chainstacklabs/polyclaw, 359 stars), Longbridge Research (helsome/folio, 271 stars) and Stock Analysis (24mlight/StockClaw, 101 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Defi Invariant Check?

mtarcure (a GitHub user) maintains it in mtarcure/claude-vibe-squad, which has 165 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on September 21, 2026.

Source: mtarcure/claude-vibe-squad on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.