Agent skill

Ability Analysis

by PlamenTSV in PlamenTSV/plamen

Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth agents, depth agents

MITAuto-check passed

Install Ability Analysis

skills CLI
$ npx skills add PlamenTSV/plamen --skill ability-analysis -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install PlamenTSV/plamen ability-analysis --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agents/skills/aptos/ability-analysis .claude/skills/ability-analysis && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ability-analysis
GitHub stars
303
Token cost
~3.3k tokens
SKILL.md length
1,433 words
Files
1
Skills in repo
87
Repo updated
First seen
Licence
MIT

At a glance

Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth agents, depth agents

  • Works in 7 steps: Struct Ability Inventory → Copy Ability Audit → Drop Ability Audit → …
  • Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth agents
  • SKILL.md covers 1. Struct Ability Inventory, 2. Copy Ability Audit, 3. Drop Ability Audit and 4. Store Ability Audit, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Ability Analysis is an agent skill from PlamenTSV/plamen. Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth agents, depth agents

Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: Autonomous Web3 security audit agent for Claude Code. The licence is MIT.

When your agent uses it

  • Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth agents

Example prompts

  • “/ability-analysis”

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Struct Ability Inventory
  2. Copy Ability Audit
  3. Drop Ability Audit
  4. Store Ability Audit
  5. Key Ability Audit
  6. Ability Combination Analysis
  7. Generic Type Parameter Abilities

What it can do on your machine

Read from SKILL.md and the folder at commit 795962b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ability Analysis loads about 3.3k tokens when it runs. Until then it costs about 31 tokens; SKILL.md has 1,433 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~31
When it runs · the whole SKILL.md, loaded when a task matches
~3.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from PlamenTSV/plamen at commit 795962b, republished under its MIT licence (© PlamenTSV). 1,433 words, ~3,286 tokens.

Download SKILL.mdSave it as .claude/skills/ability-analysis/SKILL.md (or your agent's skills folder).
name
ability-analysis
description
Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth agents, depth agents

ABILITY_ANALYSIS Skill

Trigger Pattern: Always (Aptos Move) --- foundational security check Inject Into: Breadth agents, depth agents

For every struct defined in the audited modules:

STEP PRIORITY: Steps 2 (Copy Ability Audit) and 6 (Ability Combination Analysis) are where HIGH/CRITICAL severity findings most commonly hide. Do NOT rush these steps. If constrained, skip conditional sections (7) before skipping 2 or 6.

1. Struct Ability Inventory

Enumerate ALL structs defined in the audited modules:

StructModuleAbilitiesRepresents Value?Represents Obligation?Is Resource?Security Assessment
{name}{module}copy, drop, store, keyYES/NOYES/NOYES/NO{assessment}

Classification guide:

  • Value-bearing: Coins, LP tokens, shares, receipts, vouchers, NFTs --- anything that represents transferable economic value or a claim to value
  • Obligation-bearing: Hot potatoes, flash loan receipts, callback obligations, lock receipts --- anything that MUST be consumed before transaction ends
  • Resource: Singleton state containers, registries, configuration stores --- things that should exist at most once per address/globally
  • Data: Purely informational structs with no security-sensitive lifecycle (events, parameters, intermediate computation results)

For each struct: What abilities does it NEED vs what abilities does it HAVE? Excess abilities are the attack surface.

2. Copy Ability Audit

For each struct with the copy ability:

2a. Value Duplication Check
StructHas copy?Represents Value?Duplication Exploitable?Severity
{name}YES/NOYES/NOYES/NO --- {reason}{H/M/L/N/A}

CRITICAL: copy on a value-bearing type means the value can be duplicated at zero cost. This is the Move equivalent of a double-spend.

Check for each copy struct:

  1. Can this struct be copied and then used multiple times? (e.g., copied receipt redeemed twice)
  2. Does the module rely on move semantics to enforce single-use? If yes, copy breaks that assumption.
  3. Is copy needed for legitimate operations? (e.g., snapshot reads, event emission) --- if not, it should be removed.
  4. Trace all functions that accept this struct as a parameter: do they consume (move) or borrow (&) it? If they consume, copy lets callers retain the original.

MANDATORY GREP: Search all .move files for has copy and copy, in struct definitions. For each hit: (1) classify the struct, (2) if value-bearing, mark as FINDING.

2b. Copy-Then-Use Trace

For each copy struct identified as potentially dangerous:

1. Caller obtains instance I of struct S
2. Caller copies: I_copy = copy I
3. Caller uses I in function F1 (consumed/moved)
4. Caller uses I_copy in function F2 (consumed/moved)
5. Impact: {double-spend, double-claim, double-vote, obligation bypass}

Tag: [TRACE:copy S → use1 in F1 → use2 in F2 → impact: {X}]

3. Drop Ability Audit

For each struct with the drop ability:

3a. Obligation Bypass Check
StructHas drop?Represents Obligation?Drop Bypasses Cleanup?Severity
{name}YES/NOYES/NOYES/NO --- {reason}{H/M/L/N/A}

CRITICAL: drop on an obligation-bearing struct means the obligation can be silently discarded. This is the Move equivalent of skipping a required finally-block.

Hot potato pattern check: The hot potato pattern relies on structs having NO drop ability, forcing the caller to pass them to a consuming function. If drop is present, the pattern is broken.

Check for each drop struct:

  1. Is this struct a receipt or proof that must be returned to a specific function? (flash loan receipt, lock receipt, callback proof)
  2. Does any function create this struct with the expectation that a corresponding "finalize" function will consume it?
  3. What state changes happen in the finalize function? If the struct is dropped instead, those state changes never occur.
  4. Does dropping this struct leave the protocol in an inconsistent state? (borrowed funds not returned, locks not released, counters not decremented)
3b. Drop-Instead-of-Consume Trace

For each obligation struct:

1. Function F_create creates struct S (e.g., flash_loan returns receipt)
2. EXPECTED: Caller passes S to F_consume (e.g., repay(receipt))
3. ACTUAL (if drop): Caller drops S, F_consume never called
4. Impact: {funds not returned, lock not released, state inconsistent}

Tag: [TRACE:drop obligation S → F_consume skipped → impact: {X}]

4. Store Ability Audit

For each struct with the store ability:

4a. Module Control Escape Check
StructHas store?Can Escape Module?Invariant Break If Escaped?Severity
{name}YES/NOYES --- via {mechanism} / NOYES/NO --- {which invariant}{H/M/L/N/A}

Check for each store struct:

  1. store allows the struct to be placed inside other structs, into Table/SmartTable, or moved to global storage via a wrapping resource. Can an attacker store this struct in their own resource, bypassing module-controlled access?
  2. Does the module rely on controlling where instances of this struct live? If instances escape to user-controlled storage, can they be replayed, hoarded, or used out of context?
  3. For structs with store but without key: can they be wrapped in a user-defined key struct to achieve unauthorized global storage?
  4. If the struct contains mutable references to shared state (e.g., via &mut in the functions that operate on it), does escaping the module allow stale or orphaned references?
4b. Unauthorized Persistence Trace

For structs not intended to persist outside module control:

1. Module M creates struct S with `store` ability
2. Attacker wraps S in their own struct W (has key + store)
3. Attacker calls move_to<W>(@attacker, W { s: obtained_S })
4. S now persists at attacker's address outside M's control
5. Impact: {replay, hoarding, context-escape, stale state}

5. Key Ability Audit

For each struct with the key ability:

5a. Resource Lifecycle Check
StructHas key?Intended as Global Resource?move_from Protected?move_to Protected?Severity
{name}YES/NOYES/NOYES --- {by what} / NOYES --- {by what} / NO{H/M/L/N/A}

Check for each key struct:

  1. Who can call move_to for this resource? Is creation properly gated by access control (signer capability, admin checks)?
  2. Who can call move_from for this resource? Can an attacker remove a critical resource from an address?
  3. Is the resource intended to be a singleton (one per address/globally)? If yes, can an attacker cause duplicate creation or premature deletion?
  4. Does the module use exists<S>(addr) checks? Can an attacker manipulate resource existence to bypass guards?
  5. For resources published at a shared/module address: what happens if the resource is removed? Does the protocol become non-functional?
Show full SKILL.md (569 more words)Show less
5b. Resource Deletion Impact

For each resource that other functions depend on:

ResourceFunctions That Read ItFunctions That Require exists<S>Impact If Deleted
{name}{list}{list}{abort, DoS, state corruption}

6. Ability Combination Analysis

Analyze dangerous ability combinations:

StructAbilitiesCombination RiskAttack VectorSeverity
{name}copy + storeReplicate and persist duplicates in global storageInfinite value creation via copy then store each copyCritical
{name}drop + keyAbandon a top-level resourceDelete critical protocol state, DoSHigh
{name}copy + dropInfinite creation + no cleanup obligationValue duplication with no consumption requirementCritical (if value-bearing)
{name}copy + drop + storeAll of the above combinedMaximum exploitation surfaceCritical (if value-bearing)
{name}key + copyResource duplication at global levelMove resource to address, copy, move copy elsewhereHigh

MANDATORY: For every value-bearing or obligation-bearing struct, verify that NONE of these dangerous combinations are present. If present, classify as FINDING with severity based on the struct's role.

Safe combinations:

  • store alone on data structs (stored inside other resources, no standalone risk)
  • copy + drop on purely informational structs (events, read-only parameters)
  • key + store + drop on administrative resources with proper access control

7. Generic Type Parameter Abilities

For every generic struct and generic function in the audited modules:

7a. Generic Struct Constraints
StructType ParamConstraintSufficient?Unexpected Instantiation?
Wrapper<T: store>Tstore{analysis}{can attacker use T = MaliciousType?}

Check:

  1. Is the ability constraint on the type parameter the MINIMUM required? Overly permissive constraints (e.g., T: store + copy + drop when only store is needed) expand the attack surface.
  2. Can an attacker instantiate the generic with a type that has unexpected properties? Example: Pool<T: store> instantiated with a custom token type that has transfer hooks or non-standard behavior.
  3. For phantom type parameters (phantom T): does the module correctly use them for type-level discrimination without relying on runtime properties of T?
  4. Do ability constraints on generic parameters match the constraints required by all functions that operate on the containing struct?
7b. Ability Constraint Mismatch

Check for mismatches between struct definition and function signatures:

struct Container<T: store> has key, store { item: T }

// POTENTIAL ISSUE: Function requires T: copy + store, but Container only requires T: store
// Can Container be created with a non-copy T, then this function fails?
public fun clone_item<T: copy + store>(c: &Container<T>): T { *&c.item }

Impact: If a module publishes a Container<NonCopyType>, the clone_item function aborts at runtime. Is this a DoS vector?

Finding Template

When this skill identifies an issue:

markdown
**ID**: [AB-N]
**Severity**: [based on struct role and exploitation impact]
**Step Execution**: check1,2,3,4,5,6,7 | X(reasons) | ?(uncertain)
**Rules Applied**: [R4:Y, R5:Y, R10:Y, R17:Y]
**Location**: module::struct_name (source_file.move:LineN)
**Title**: [Struct] has [ability] enabling [attack: duplication/obligation bypass/escape/deletion]
**Description**: [Trace the ability exploitation from struct definition to impact]
**Impact**: [What breaks: double-spend, obligation bypass, state corruption, DoS]

Step Execution Checklist (MANDATORY)

CRITICAL: You MUST report completion status for ALL sections. Steps 2 and 6 are highest priority.

SectionRequiredCompleted?Notes
1. Struct Ability InventoryYESY/X/?Enumerate ALL structs
2. Copy Ability AuditYESY/X/?MANDATORY --- highest-severity source
2b. Copy-Then-Use TraceIF copy on value typeY/X(N/A)/?
3. Drop Ability AuditYESY/X/?Hot potato pattern check
3b. Drop-Instead-of-Consume TraceIF drop on obligation typeY/X(N/A)/?
4. Store Ability AuditYESY/X/?Module control escape
5. Key Ability AuditYESY/X/?Resource lifecycle
5b. Resource Deletion ImpactIF key resources foundY/X(N/A)/?
6. Ability Combination AnalysisYESY/X/?MANDATORY --- dangerous combos
7. Generic Type Parameter AbilitiesIF generics presentY/X(N/A)/?Constraint sufficiency
Cross-Reference Markers

After Section 2 (Copy Ability Audit):

  • IF copy on value-bearing struct found -> cross-reference with TYPE_SAFETY.md Section 2 for type substitution amplification
  • IF copy enables double-use -> severity minimum HIGH

After Section 3 (Drop Ability Audit):

  • IF drop on obligation struct found -> cross-reference with token flow analysis for flash loan receipt handling
  • IF drop bypasses repayment -> severity minimum CRITICAL

After Section 6 (Ability Combination Analysis):

  • IF dangerous combination found on value-bearing struct -> severity minimum HIGH
  • Document all structs with safe ability justification for audit trail

© PlamenTSV, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in agents/skills/aptos/ability-analysis of PlamenTSV/plamen.

Open the folder on GitHubat commit 795962b

Compare with similar skills

Ability Analysis next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ability Analysis compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ability Analysis this skillPlamenTSV/plamen303—~3.3kAutomated safety check: PassMIT
Golang Patternsaffaan-m/ECC275k—~1.1kAutomated safety check: PassMIT
Kotlin Exposed Patternsaffaan-m/ECC275k4 repos~5.5kAutomated safety check: PassMIT
Dotnet Patternsaffaan-m/ECC275k1 repos~2.3kAutomated safety check: PassMIT
Fastapi Patternsaffaan-m/ECC275k—~2.3kAutomated safety check: PassMIT
Python Patternsaffaan-m/ECC275k—~2.3kAutomated safety check: PassMIT

Similar skills

  • Golang Patterns

    affaan-m/ECC

    Go-specific design patterns and best practices including functional options, small interfaces, dependency injection, concurrency patterns, error handling, and package organization.

    275k GitHub stars~1.1k tokensUpdated 3 days ago
    DevelopmentAuto-check passed
  • JetBrains Exposed ORM patterns including DSL queries, DAO pattern, transactions, HikariCP connection pooling, Flyway migrations, and repository pattern.

    275k GitHub starsUsed in 4 repos~5.5k tokens
    DatabasesAuto-check passed
  • Dotnet Patterns

    affaan-m/ECC

    Idiomatic C and .NET patterns, conventions, dependency injection, async/await, and best practices for building robust, maintainable .NET applications.

    275k GitHub starsUsed in 1 repo~2.3k tokens
    DevelopmentAuto-check passed
  • Fastapi Patterns

    affaan-m/ECC

    FastAPI patterns for async APIs, dependency injection, Pydantic request and response models, OpenAPI docs, tests, security, and production readiness.

    275k GitHub stars~2.3k tokensUpdated 3 days ago
    Backend & APIsAuto-check passed
  • Python Patterns

    affaan-m/ECC

    Python-specific design patterns and best practices including protocols, dataclasses, context managers, decorators, async/await, type hints, and package organization.

    275k GitHub stars~2.3k tokensUpdated 3 days ago
    DevelopmentAuto-check passed
  • Motion Patterns

    affaan-m/ECC

    Production-ready animation patterns for React / Next.js — button, modal, toast, stagger, page transitions, exit animations, scroll, and layout — built on motion-foundations tokens and springs.

    275k GitHub starsUsed in 1 repo~3.3k tokens
    Auto-check passed

More from PlamenTSV/plamen

All 87 skills in this repo
  • Audit Prep

    PlamenTSV/plamen

    Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project…

    303 GitHub stars~3.7k tokensUpdated 11 days ago
    Auto-check passed
  • Verification Protocol

    PlamenTSV/plamen

    Trigger Pattern Always (used by all verifier agents) - Inject Into security-verifier agents (Phase 5)

    303 GitHub stars~3.5k tokensUpdated 11 days ago
    Auto-check passed
  • Ability Analysis

    PlamenTSV/plamen

    Trigger Pattern Always (Sui Move) -- foundational security check - Inject Into Breadth agents, depth agents

    303 GitHub stars~3.2k tokensUpdated 11 days ago
    Auto-check passed
  • Account Lifecycle

    PlamenTSV/plamen

    Trigger Pattern ACCOUNTCLOSING flag detected (close/CloseAccount usage) - Inject Into Breadth agents, depth agents

    303 GitHub stars~1.2k tokensUpdated 11 days ago
    Auto-check passed
  • Account Validation

    PlamenTSV/plamen

    Trigger Pattern Always required for Solana audits - Inject Into Breadth agents, depth agents

    303 GitHub stars~1.7k tokensUpdated 11 days ago
    Auto-check passed
  • Auth Validation

    PlamenTSV/plamen

    Trigger Pattern Always required for Soroban audits - Inject Into Breadth agents, depth agents

    303 GitHub stars~2.2k tokensUpdated 11 days ago
    Auto-check passed

Questions about Ability Analysis

What does Ability Analysis do?

Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth agents, depth agents. Ability Analysis is an agent skill from PlamenTSV/plamen.

When should I use Ability Analysis?

Ability Analysis fits situations like: pattern Always (Aptos Move) - foundational security check - Inject Into Breadth agents.

How do I install Ability Analysis in Claude Code?

Run `npx skills add PlamenTSV/plamen --skill ability-analysis -a claude-code`. Or copy the skill folder (agents/skills/aptos/ability-analysis in PlamenTSV/plamen) into .claude/skills/ability-analysis in your project. Claude Code loads it when a task matches its description.

How do I install Ability Analysis in Codex?

Run `npx skills add PlamenTSV/plamen --skill ability-analysis -a codex`. Or copy the skill folder (agents/skills/aptos/ability-analysis in PlamenTSV/plamen) into .agents/skills/ability-analysis in your project. Codex loads it when a task matches its description.

Can I use Ability Analysis in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PlamenTSV/plamen --skill ability-analysis -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ability-analysis, .gemini/skills/ability-analysis, .github/skills/ability-analysis and .opencode/skills/ability-analysis in your project.

What does Ability Analysis need to run?

SKILL.md names no scripts, command-line tools or credentials: Ability Analysis is instructions for the agent only.

Does Ability Analysis access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Ability Analysis safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Ability Analysis use?

Ability Analysis is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ability Analysis use?

About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ability Analysis?

Skills that share tags, products or a category with Ability Analysis: Golang Patterns (affaan-m/ECC, 275k stars), Kotlin Exposed Patterns (affaan-m/ECC, 275k stars), Dotnet Patterns (affaan-m/ECC, 275k stars) and Fastapi Patterns (affaan-m/ECC, 275k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ability Analysis?

PlamenTSV (a GitHub user) maintains it in PlamenTSV/plamen, which has 303 GitHub stars. The repository holds 87 skills in this directory. The repository was last updated on September 26, 2026.

Source: PlamenTSV/plamen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.