Agent skill

Ability Analysis

by PlamenTSV in PlamenTSV/plamen

Trigger Pattern Always (Sui Move) -- foundational security check - Inject Into Breadth agents, depth agents

MITAuto-check passed

Install Ability Analysis

skills CLI
$ npx skills add PlamenTSV/plamen --skill ability-analysis -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install PlamenTSV/plamen ability-analysis --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agents/skills/sui/ability-analysis .claude/skills/ability-analysis && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ability-analysis
GitHub stars
303
Token cost
~3.2k tokens
SKILL.md length
1,527 words
Files
1
Skills in repo
87
Repo updated
First seen
Licence
MIT

At a glance

Trigger Pattern Always (Sui Move) -- foundational security check - Inject Into Breadth agents, depth agents

  • Works in 8 steps: Struct Ability Inventory → Object Model Classification → Ability Mismatch Analysis → …
  • Pattern Always (Sui Move) -- foundational security check - Inject Into Breadth agents
  • SKILL.md covers 1. Struct Ability Inventory, 2. Object Model Classification, 3. Ability Mismatch Analysis and 4. Capability Pattern Audit, plus 6 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Ability Analysis is an agent skill from PlamenTSV/plamen. Trigger Pattern Always (Sui Move) -- foundational security check - Inject Into Breadth agents, depth agents

Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: Autonomous Web3 security audit agent for Claude Code. The licence is MIT.

When your agent uses it

  • Pattern Always (Sui Move) -- foundational security check - Inject Into Breadth agents

Example prompts

  • “/ability-analysis”

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Struct Ability Inventory
  2. Object Model Classification
  3. Ability Mismatch Analysis
  4. Capability Pattern Audit
  5. Hot Potato Enforcement
  6. Transfer Restriction Analysis
  7. Dynamic Field Ability Propagation
  8. Module Initializer Audit

What it can do on your machine

Read from SKILL.md and the folder at commit 795962b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ability Analysis loads about 3.2k tokens when it runs. Until then it costs about 31 tokens; SKILL.md has 1,527 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~31
When it runs · the whole SKILL.md, loaded when a task matches
~3.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from PlamenTSV/plamen at commit 795962b, republished under its MIT licence (© PlamenTSV). 1,527 words, ~3,249 tokens.

Download SKILL.mdSave it as .claude/skills/ability-analysis/SKILL.md (or your agent's skills folder).
name
ability-analysis
description
Trigger Pattern Always (Sui Move) -- foundational security check - Inject Into Breadth agents, depth agents

ABILITY_ANALYSIS Skill

Trigger Pattern: Always (Sui Move) -- foundational security check Inject Into: Breadth agents, depth agents

For every struct defined in the protocol:

STEP PRIORITY: Steps 5 (Hot Potato Enforcement) and 7 (Dynamic Field Ability Propagation) are where HIGH/CRITICAL severity findings most commonly hide. Do NOT rush these steps. If constrained, skip conditional sections before skipping 5 or 7.

1. Struct Ability Inventory

Enumerate ALL structs across all modules:

ModuleStructAbilitiesHas id: UID?Is Object?Transferable?Notes
{mod}{name}{key, store, drop, copy}YES/NOYES/NOYES/NO{context}

Sui ability semantics:

  • key = Object type. MUST have id: UID as the first field. Can be owned, shared, or frozen.
  • store = Can be transferred freely via public_transfer / public_share_object. Can be stored inside other objects via dynamic fields or wrapping.
  • drop = Can be implicitly discarded. Without drop, the value MUST be explicitly consumed (unpacked, transferred, or destroyed).
  • copy = Can be duplicated. copy + key is IMPOSSIBLE in Sui -- objects cannot be copied.
  • No abilities at all = Hot potato pattern. Value must be consumed within the same transaction.

Consistency check: For each struct with key:

  • Does it have id: UID as the FIRST field? If not -> compilation error (catch misplaced UID).
  • Is store intentionally included or omitted? key without store = only the defining module can transfer it (custom transfer rules).

2. Object Model Classification

Classify each object (key ability) by ownership model:

ObjectOwnershipCreated ViaTransfer Restricted?Freeze Possible?
{name}Owned / Shared / Frozen / Wrapped{function}YES (no store) / NO (store)YES/NO

Security checks per ownership type:

2a. Owned Objects
  • Can the owner transfer to themselves via transfer::transfer to reset state?
  • Are there time-locks or cooldowns that reset on transfer?
  • Can owned objects be wrapped inside other objects to bypass module restrictions?
2b. Shared Objects
  • Is the object made shared via transfer::share_object at creation?
  • Once shared, can never be un-shared -- is this intended?
  • Shared objects require consensus ordering -- are there ordering-dependent operations?
  • Critical: Can an attacker create a competing shared object of the same type?
2c. Frozen Objects (Immutable)
  • Is the object frozen via transfer::freeze_object?
  • Once frozen, can never be mutated -- is this intended?
  • Are there references to the frozen object that expect mutation?
2d. Wrapped Objects
  • Objects stored as fields inside other objects lose their independent existence.
  • Can wrapping bypass transfer restrictions (object with key only, no store, wrapped inside a key + store parent)?
  • When unwrapped, does the object retain its original ID and state?

3. Ability Mismatch Analysis

For each struct, verify ability assignments match intended behavior:

3a. Missing drop -- Intentional?
StructHas drop?Explicit Destroy Function?Can Leak?
{name}NOYES: destroy_{name}() / NOYES/NO

Rule: A struct without drop that has no explicit destroy/consume path creates a resource leak. The transaction will abort if the value is not consumed. This is sometimes intentional (hot potato) but often a bug when the struct is created in error paths.

3b. Unnecessary store -- Over-Permissive?
StructHas store?Stored in Dynamic Fields?Freely Transferable?Should Be Restricted?
{name}YESYES/NOYES{analysis}

Check: If a struct has store but the protocol intends restricted transfers (e.g., non-transferable receipts, bound tickets), the store ability enables bypass via public_transfer. Does any security invariant depend on transfer restriction?

3c. copy Abuse Potential
StructHas copy?Contains Balances/IDs?Duplication Dangerous?
{name}YES/NOYES/NOYES/NO

Rule: copy on a struct containing Balance<T>, capability tokens, or unique identifiers is almost always a bug -- it enables double-spending or capability duplication. copy + key is impossible (enforced by Sui), but copy + store on inner structs is allowed and dangerous if they hold value.

4. Capability Pattern Audit

Identify all capability/admin structs:

CapabilityAbilitiesCreated InTransferred ToCan Be Duplicated?Revocable?
{name}{abilities}init(){recipient}YES (copy) / NOYES/NO

Checks:

  • Is the capability created only in init() (module initializer)? If created elsewhere, can it be minted by unauthorized parties?
  • Does the capability have store? If yes, the holder can transfer it freely -- is this intended?
  • Is there a revocation mechanism? (Capability patterns in Sui are typically one-way -- once issued, not revocable without wrapping in a shared object with access control.)
  • One-Time Witness (OTW) vs Capability: Is this struct actually an OTW being misused as a persistent capability? OTW types should be consumed in init, not stored.

5. Hot Potato Enforcement

Identify all structs with NO abilities:

StructModuleCreated ByMust Be Consumed ByEnforced?
{name}{mod}{function}{function}YES/NO

Hot potato security checks:

  • Is the hot potato created and consumed within a single PTB (Programmable Transaction Block)?
  • Can the consumption function be called by anyone, or only specific callers?
  • Does the consumption function validate the hot potato's contents match expectations?
  • If the hot potato is a receipt/ticket/flash-loan proof, does it store the source object ID (order_id, pool_id, position_id, loan_id) that created it?
  • Does every consumption function assert the stored source ID matches object::id() of the object being repaid, settled, claimed, or mutated?
  • Does the consumption function validate all relevant fields, not just that the receipt exists (type pair, amount, fee, epoch/deadline, pool/order/position identity)?
  • Can any alternate consume/repay/settle path skip the source-ID or field validation?
  • Can an attacker create a fake hot potato of the same type from a different module? (NO -- Move type system prevents cross-module struct creation.)
  • Can the hot potato be stored if someone adds store via a wrapper? (Check: is there a public wrapper that accepts arbitrary store types.)
  • Transaction abort impact: If the hot potato cannot be consumed (e.g., consumption function reverts), the entire PTB aborts. Can this be used for griefing? (e.g., attacker causes the consumption precondition to fail after the hot potato is created.)

Pattern validation: Trace every hot potato from creation to consumption. Document the full lifecycle:

create: module::start_action() -> HotPotato
  ... intervening calls that rely on HotPotato's existence ...
consume: module::finish_action(potato: HotPotato)

If any code path creates a hot potato without a guaranteed consumption path -> FINDING (transaction will always abort on that path). If a receipt enforces consumption but is not bound to the source object it came from -> FINDING (the receipt can settle the wrong order/pool/position).

Show full SKILL.md (542 more words)Show less

6. Transfer Restriction Analysis

For objects with key but NOT store:

ObjectModule Transfer FunctionCustom RulesBypass Possible?
{name}{function or NONE}{description}YES/NO

Sui transfer rules:

  • key + store: Anyone can transfer via transfer::public_transfer.
  • key only: Only the defining module can transfer via transfer::transfer (requires module-level access).
  • Bypass check: Can the restricted object be wrapped inside a store-capable struct, then the wrapper transferred freely? If the wrapping struct is from a DIFFERENT module, this is a transfer restriction bypass.

Check each restricted object:

  1. Does any public function accept this object type and wrap it?
  2. Does any public function accept this object type and place it in a dynamic field of a freely transferable object?
  3. If yes to either -> the transfer restriction is bypassable -> FINDING.

7. Dynamic Field Ability Propagation

For every use of dynamic_field::add or dynamic_object_field::add:

Parent ObjectField Key TypeField Value TypeValue Has store?Parent Has store?
{parent}{key_type}{value_type}YES/NOYES/NO

Rules:

  • dynamic_field::add requires the value type to have store.
  • dynamic_object_field::add requires the value type to have key + store.
  • Security check: If a value with store is added as a dynamic field, anyone who can access the parent object can potentially extract it via dynamic_field::remove. Is extraction access-controlled?
  • Orphan check: If the parent object is destroyed, are dynamic fields cleaned up? Orphaned dynamic fields remain in storage and can never be accessed again -> permanent storage leak.
  • Type confusion: Dynamic fields are keyed by type. Can an attacker add a dynamic field with a key type that collides with an expected key type? (Unlikely due to Move type system, but check for generic key types like vector<u8> or String.)

8. Module Initializer Audit

For each module with an init function:

Moduleinit ParametersObjects CreatedCapabilities IssuedOTW Consumed?
{mod}{params}{list}{list}YES/NO/N/A

Checks:

  • Is init the ONLY place critical capabilities are created?
  • Does init properly consume the One-Time Witness if one is passed?
  • Can the module be re-initialized via package upgrade? (Sui package upgrades do NOT re-run init.)
  • Are shared objects created in init? (They must be -- you cannot share an owned object after creation in Sui.)

Finding Template

markdown
**ID**: [AB-N]
**Severity**: [based on ability misuse impact]
**Step Execution**: check1,2,3,4,5,6,7,8 | X(reasons) | ?(uncertain)
**Rules Applied**: [R4:Y, R5:Y, R10:Y, ...]
**Location**: module::struct_name
**Title**: [Ability issue type] in [struct] enables [attack/bypass]
**Description**: [Specific ability misconfiguration with type-level trace]
**Impact**: [What breaks: transfer restriction bypass, capability duplication, resource leak, hot potato griefing]

Step Execution Checklist (MANDATORY)

CRITICAL: You MUST report completion status for ALL sections. Findings with incomplete sections will be flagged for depth review.

SectionRequiredCompleted?Notes
1. Struct Ability InventoryYESY/X/?
2. Object Model ClassificationYESY/X/?
2b. Shared Object AnalysisIF shared objectsY/X(N/A)/?
3. Ability Mismatch AnalysisYESY/X/?
3b. Unnecessary store CheckYESY/X/?
3c. copy Abuse CheckYESY/X/?
4. Capability Pattern AuditYESY/X/?
5. Hot Potato EnforcementIF hot potatoes existY/X(N/A)/?HIGH PRIORITY
6. Transfer Restriction AnalysisIF key-only objectsY/X(N/A)/?
7. Dynamic Field Ability PropagationIF dynamic fields usedY/X(N/A)/?HIGH PRIORITY
8. Module Initializer AuditYESY/X/?
Cross-Reference Markers

After Section 4 (Capability Pattern Audit):

  • Cross-reference with TYPE_SAFETY.md Section on OTW analysis
  • IF capability has store -> flag for SEMI_TRUSTED_ROLES analysis

After Section 5 (Hot Potato Enforcement):

  • IF hot potato consumption depends on external state -> cross-reference with EXTERNAL_PRECONDITION_AUDIT
  • IF hot potato abort causes shared object locking -> document consensus impact

After Section 7 (Dynamic Field Ability Propagation):

  • IF dynamic field values extractable by non-owners -> FINDING (minimum Medium)
  • Cross-reference with TOKEN_FLOW_TRACING for dynamic field token storage

© PlamenTSV, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in agents/skills/sui/ability-analysis of PlamenTSV/plamen.

Open the folder on GitHubat commit 795962b

Compare with similar skills

Ability Analysis next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ability Analysis compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ability Analysis this skillPlamenTSV/plamen303—~3.2kAutomated safety check: PassMIT
Golang Patternsaffaan-m/ECC275k—~1.1kAutomated safety check: PassMIT
Kotlin Exposed Patternsaffaan-m/ECC275k4 repos~5.5kAutomated safety check: PassMIT
Dotnet Patternsaffaan-m/ECC275k1 repos~2.3kAutomated safety check: PassMIT
Fastapi Patternsaffaan-m/ECC275k—~2.3kAutomated safety check: PassMIT
Python Patternsaffaan-m/ECC275k—~2.3kAutomated safety check: PassMIT

Similar skills

  • Golang Patterns

    affaan-m/ECC

    Go-specific design patterns and best practices including functional options, small interfaces, dependency injection, concurrency patterns, error handling, and package organization.

    275k GitHub stars~1.1k tokensUpdated 3 days ago
    DevelopmentAuto-check passed
  • JetBrains Exposed ORM patterns including DSL queries, DAO pattern, transactions, HikariCP connection pooling, Flyway migrations, and repository pattern.

    275k GitHub starsUsed in 4 repos~5.5k tokens
    DatabasesAuto-check passed
  • Dotnet Patterns

    affaan-m/ECC

    Idiomatic C and .NET patterns, conventions, dependency injection, async/await, and best practices for building robust, maintainable .NET applications.

    275k GitHub starsUsed in 1 repo~2.3k tokens
    DevelopmentAuto-check passed
  • Fastapi Patterns

    affaan-m/ECC

    FastAPI patterns for async APIs, dependency injection, Pydantic request and response models, OpenAPI docs, tests, security, and production readiness.

    275k GitHub stars~2.3k tokensUpdated 3 days ago
    Backend & APIsAuto-check passed
  • Python Patterns

    affaan-m/ECC

    Python-specific design patterns and best practices including protocols, dataclasses, context managers, decorators, async/await, type hints, and package organization.

    275k GitHub stars~2.3k tokensUpdated 3 days ago
    DevelopmentAuto-check passed
  • Motion Patterns

    affaan-m/ECC

    Production-ready animation patterns for React / Next.js — button, modal, toast, stagger, page transitions, exit animations, scroll, and layout — built on motion-foundations tokens and springs.

    275k GitHub starsUsed in 1 repo~3.3k tokens
    Auto-check passed

More from PlamenTSV/plamen

All 87 skills in this repo
  • Audit Prep

    PlamenTSV/plamen

    Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project…

    303 GitHub stars~3.7k tokensUpdated 12 days ago
    Auto-check passed
  • Verification Protocol

    PlamenTSV/plamen

    Trigger Pattern Always (used by all verifier agents) - Inject Into security-verifier agents (Phase 5)

    303 GitHub stars~3.5k tokensUpdated 12 days ago
    Auto-check passed
  • Ability Analysis

    PlamenTSV/plamen

    Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth agents, depth agents

    303 GitHub stars~3.3k tokensUpdated 12 days ago
    Auto-check passed
  • Account Lifecycle

    PlamenTSV/plamen

    Trigger Pattern ACCOUNTCLOSING flag detected (close/CloseAccount usage) - Inject Into Breadth agents, depth agents

    303 GitHub stars~1.2k tokensUpdated 12 days ago
    Auto-check passed
  • Account Validation

    PlamenTSV/plamen

    Trigger Pattern Always required for Solana audits - Inject Into Breadth agents, depth agents

    303 GitHub stars~1.7k tokensUpdated 12 days ago
    Auto-check passed
  • Auth Validation

    PlamenTSV/plamen

    Trigger Pattern Always required for Soroban audits - Inject Into Breadth agents, depth agents

    303 GitHub stars~2.2k tokensUpdated 12 days ago
    Auto-check passed

Questions about Ability Analysis

What does Ability Analysis do?

Trigger Pattern Always (Sui Move) -- foundational security check - Inject Into Breadth agents, depth agents. Ability Analysis is an agent skill from PlamenTSV/plamen.

When should I use Ability Analysis?

Ability Analysis fits situations like: pattern Always (Sui Move) -- foundational security check - Inject Into Breadth agents.

How do I install Ability Analysis in Claude Code?

Run `npx skills add PlamenTSV/plamen --skill ability-analysis -a claude-code`. Or copy the skill folder (agents/skills/sui/ability-analysis in PlamenTSV/plamen) into .claude/skills/ability-analysis in your project. Claude Code loads it when a task matches its description.

How do I install Ability Analysis in Codex?

Run `npx skills add PlamenTSV/plamen --skill ability-analysis -a codex`. Or copy the skill folder (agents/skills/sui/ability-analysis in PlamenTSV/plamen) into .agents/skills/ability-analysis in your project. Codex loads it when a task matches its description.

Can I use Ability Analysis in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PlamenTSV/plamen --skill ability-analysis -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ability-analysis, .gemini/skills/ability-analysis, .github/skills/ability-analysis and .opencode/skills/ability-analysis in your project.

What does Ability Analysis need to run?

SKILL.md names no scripts, command-line tools or credentials: Ability Analysis is instructions for the agent only.

Does Ability Analysis access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Ability Analysis safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Ability Analysis use?

Ability Analysis is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ability Analysis use?

About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ability Analysis?

Skills that share tags, products or a category with Ability Analysis: Golang Patterns (affaan-m/ECC, 275k stars), Kotlin Exposed Patterns (affaan-m/ECC, 275k stars), Dotnet Patterns (affaan-m/ECC, 275k stars) and Fastapi Patterns (affaan-m/ECC, 275k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ability Analysis?

PlamenTSV (a GitHub user) maintains it in PlamenTSV/plamen, which has 303 GitHub stars. The repository holds 87 skills in this directory. The repository was last updated on September 26, 2026.

Source: PlamenTSV/plamen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.