Agent skill

Bit Shift Safety

by PlamenTSV in PlamenTSV/plamen

Trigger Pattern Always (Sui Move) -- Move VM aborts on shift = bit width - Inject Into Breadth agents, depth-edge-case

MITAuto-check passed

Install Bit Shift Safety

skills CLI
$ npx skills add PlamenTSV/plamen --skill bit-shift-safety -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install PlamenTSV/plamen bit-shift-safety --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agents/skills/sui/bit-shift-safety .claude/skills/bit-shift-safety && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
bit-shift-safety
GitHub stars
303
Token cost
~2.2k tokens
SKILL.md length
846 words
Files
1
Skills in repo
87
Repo updated
First seen
Licence
MIT

At a glance

Trigger Pattern Always (Sui Move) -- Move VM aborts on shift = bit width - Inject Into Breadth agents, depth-edge-case

  • Works in 6 steps: Shift Operation Inventory → Shift Amount Source Classification → Abort Impact Analysis → …
  • Pattern Always (Sui Move) -- Move VM aborts on shift = bit width - Inject Into Breadth agents
  • SKILL.md covers 1. Shift Operation Inventory, 2. Shift Amount Source…, 3. Abort Impact Analysis and 4. Common Vulnerable Patterns, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Bit Shift Safety is an agent skill from PlamenTSV/plamen. Trigger Pattern Always (Sui Move) -- Move VM aborts on shift = bit width - Inject Into Breadth agents, depth-edge-case

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: Autonomous Web3 security audit agent for Claude Code. The licence is MIT.

When your agent uses it

  • Pattern Always (Sui Move) -- Move VM aborts on shift = bit width - Inject Into Breadth agents
  • Depth-edge-case

Example prompts

  • “/bit-shift-safety”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Shift Operation Inventory
  2. Shift Amount Source Classification
  3. Abort Impact Analysis
  4. Common Vulnerable Patterns
  5. Validation Pattern Verification
  6. Cross-Function Shift Propagation

What it can do on your machine

Read from SKILL.md and the folder at commit 795962b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are move and markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Bit Shift Safety loads about 2.2k tokens when it runs. Until then it costs about 34 tokens; SKILL.md has 846 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~34
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from PlamenTSV/plamen at commit 795962b, republished under its MIT licence (© PlamenTSV). 846 words, ~2,207 tokens.

Download SKILL.mdSave it as .claude/skills/bit-shift-safety/SKILL.md (or your agent's skills folder).
name
bit-shift-safety
description
Trigger Pattern Always (Sui Move) -- Move VM aborts on shift = bit width - Inject Into Breadth agents, depth-edge-case

BIT_SHIFT_SAFETY Skill

Trigger Pattern: Always (Sui Move) -- Move VM aborts on shift >= bit width Inject Into: Breadth agents, depth-edge-case

For every bit shift operation in the protocol:

BACKGROUND: The Move VM (shared by Sui and Aptos) aborts the entire transaction if a bit shift operand equals or exceeds the bit width of the type. For u64, shifting by 64 or more aborts. For u128, shifting by 128 or more aborts. This is NOT a revert with an error code -- it is a VM abort that cannot be caught. On Sui, a PTB (Programmable Transaction Block) abort means ALL commands in the PTB fail, and shared objects that were locked for the transaction are released without state changes.

1. Shift Operation Inventory

Enumerate ALL bit shift operations (<< and >>) across all modules:

ModuleFunctionLineOperationTypeBit WidthShift Amount SourceValidated?
{mod}{func}{L}<< / >>u8/u64/u128/u2568/64/128/256{literal/parameter/computed}YES/NO

Grep pattern: Search all .move files for << and >> operators.

Type-to-width mapping:

TypeMax Safe Shift
u87
u6463
u128127
u256255

2. Shift Amount Source Classification

For each shift operation, classify the shift amount source:

2a. Literal Shifts (Low Risk)
move
let x = value << 32;  // Literal: always safe if < bit width

Check: Is the literal < bit width of the type? If yes -> SAFE. If no -> compilation may succeed but runtime aborts.

2b. Parameter-Derived Shifts (Medium Risk)
move
public fun shift_by(value: u64, amount: u8): u64 {
    value << (amount as u8)  // Parameter: caller controls shift amount
}

Check: Is the amount parameter validated before the shift? Common patterns:

  • assert!(amount < 64, E_SHIFT_OVERFLOW) -- explicit validation
  • amount % 64 -- wrapping (changes semantics but prevents abort)
  • No validation -- FINDING
2c. Computed Shifts (High Risk)
move
let shift = calculate_precision(decimals);  // Computed: depends on runtime state
let result = base << shift;

Check: Can the computation ever produce a value >= bit width? Trace the computation to its inputs. If any input is user-controlled or state-derived -> HIGH RISK.

3. Abort Impact Analysis

For each unvalidated shift operation, assess the abort impact:

FunctionCalled ByShared Objects Locked?PTB ContextAbort Impact
{func}{callers}YES/NO{typical PTB}{impact}

Sui-specific abort consequences:

  • PTB abort: All commands in the Programmable Transaction Block fail atomically. If the shift is in command 3 of a 5-command PTB, commands 1-2 are also rolled back.
  • Shared object locking: If the aborting function locks shared objects (accessed via &mut reference), those objects are temporarily unavailable during consensus. Repeated aborts can cause transient unavailability. This is NOT permanent locking -- Sui releases locks after the transaction fails.
  • Gas consumption: The sender pays gas for the aborted transaction up to the abort point.
  • Griefing vector: If an attacker can trigger the abort via a public function with a user-controlled shift amount, they can grief other users by causing their PTBs to abort. This is especially impactful when the aborting function is called as part of a common user flow (deposit, swap, claim).
3a. Griefing Scenario Modeling

For each unvalidated shift in a public/entry function:

Scenario: Shift Abort Griefing
1. Attacker calls {FUNCTION} with shift amount = {BIT_WIDTH}
2. Move VM aborts the transaction
3. Impact on other users: {IMPACT}
   - If function modifies shared state: other PTBs depending on that state must retry
   - If function is part of a multi-step user flow: user loses gas + must restart
4. Attacker cost: gas for one failed transaction
5. Severity: {based on impact}

4. Common Vulnerable Patterns

4a. Decimal Conversion Shifts
move
// VULNERABLE: decimals comes from token metadata, could be >= 64
let scale = 1u64 << decimals;

Fix pattern: assert!(decimals < 64, E_INVALID_DECIMALS) or use math::pow(10, decimals) instead.

4b. Bit Packing / Unpacking
move
// VULNERABLE if position is not bounds-checked
let field = (packed >> position) & mask;

Check: Is position derived from user input or configuration? If yes and no validation -> FINDING.

4c. Fixed-Point Arithmetic
move
// Common in DeFi: fixed-point multiplication with shift
let result = (a * b) >> PRECISION_BITS;

Check: Is PRECISION_BITS a constant? If yes and < bit width -> SAFE. If computed -> trace source.

Show full SKILL.md (344 more words)Show less
4d. Loop-Based Shifts
move
let mut i = 0;
while (i < n) {
    value = value << 1;  // Safe per iteration, but after 64 iterations value = 0 (not abort)
    i = i + 1;
};

Note: Shifting by 1 repeatedly does NOT abort (shift amount is always 1). But the value overflows silently to 0 after bit-width iterations. Check if this silent overflow causes logic errors.

5. Validation Pattern Verification

For each shift operation that IS validated, verify the validation is correct:

FunctionValidationCorrect?Edge Case
{func}assert!(n < 64)YESn=63 is max safe
{func}assert!(n <= 64)NOn=64 aborts
{func}n % 64SAFE but semantic changeshift by 0 when n=64

Common validation errors:

  • Off-by-one: <= bit_width instead of < bit_width
  • Wrong bit width: validating against 64 for a u128 shift (allows 64-127 to abort)
  • Missing cast: amount is u64 but shift operand must be u8 -- does the cast truncate?

6. Cross-Function Shift Propagation

Trace shift amounts across function boundaries:

entry_function(user_input: u64)
  -> helper_a(derived_value)  // derived_value = user_input * 2
    -> helper_b(shift_amount) // shift_amount = derived_value + offset
      -> actual_shift: value << shift_amount  // Is shift_amount < bit_width?

For each chain: Can ANY combination of valid inputs to the entry function produce a shift amount >= bit width at the actual shift site? Document the full trace.

Finding Template

markdown
**ID**: [BS-N]
**Severity**: [HIGH if public function, MEDIUM if restricted caller, LOW if constant shift]
**Step Execution**: check1,2,3,4,5,6 | X(reasons) | ?(uncertain)
**Rules Applied**: [R4:Y, R10:Y, ...]
**Depth Evidence**: [BOUNDARY:shift=bit_width], [TRACE:user_input->shift_amount->abort]
**Location**: module::function:LineN
**Title**: Unvalidated bit shift in [function] causes VM abort on [condition]
**Description**: [Specific shift operation, source of shift amount, why it can reach bit width]
**Impact**: [Transaction abort, shared object locking, griefing potential, gas waste]

Step Execution Checklist (MANDATORY)

CRITICAL: You MUST report completion status for ALL sections. Findings with incomplete sections will be flagged for depth review.

SectionRequiredCompleted?Notes
1. Shift Operation InventoryYESY/X/?Grep all .move files
2. Shift Amount Source ClassificationYESY/X/?For each shift
3. Abort Impact AnalysisIF unvalidated shifts foundY/X(N/A)/?
3a. Griefing Scenario ModelingIF unvalidated in public fnY/X(N/A)/?
4. Common Vulnerable PatternsYESY/X/?Check all 4 sub-patterns
5. Validation Pattern VerificationIF validated shifts existY/X(N/A)/?Off-by-one check
6. Cross-Function Shift PropagationIF shift amount crosses functionsY/X(N/A)/?
Cross-Reference Markers

After Section 1 (Shift Inventory):

  • IF zero shift operations found -> mark skill as N/A, skip remaining sections
  • IF shifts found in math/fixed-point libraries -> prioritize Section 4c

After Section 3 (Abort Impact):

  • IF abort affects shared objects -> cross-reference with ABILITY_ANALYSIS Section 2b (shared object analysis)
  • IF abort is in a hot potato consumption path -> cross-reference with ABILITY_ANALYSIS Section 5 (hot potato enforcement) -- abort before consumption = permanent PTB failure

After Section 6 (Cross-Function Propagation):

  • IF any chain reaches bit width with valid inputs -> FINDING (minimum Medium)
  • Tag: [BOUNDARY:shift={bit_width}], [TRACE:input_path->abort_site]

© PlamenTSV, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in agents/skills/sui/bit-shift-safety of PlamenTSV/plamen.

Open the folder on GitHubat commit 795962b

Compare with similar skills

Bit Shift Safety next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Bit Shift Safety compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Bit Shift Safety this skillPlamenTSV/plamen303—~2.2kAutomated safety check: PassMIT
Python Patternsaffaan-m/ECC275k—~2.3kAutomated safety check: PassMIT
Memory Safety Patternswshobson/agents40k9 repos~646Automated safety check: PassMIT
Golang Patternsaffaan-m/ECC275k—~1.1kAutomated safety check: PassMIT
RTK Rust Design Patternsrtk-ai/rtk83k—~1.9kAutomated safety check: PassApache-2.0
Kotlin Exposed Patternsaffaan-m/ECC275k4 repos~5.5kAutomated safety check: PassMIT

Similar skills

  • Python Patterns

    affaan-m/ECC

    Python-specific design patterns and best practices including protocols, dataclasses, context managers, decorators, async/await, type hints, and package organization.

    275k GitHub stars~2.3k tokensUpdated 3 days ago
    DevelopmentAuto-check passed
  • Memory Safety Patterns

    wshobson/agents

    Implement memory-safe programming with RAII, ownership, smart pointers, and resource management across Rust, C++, and C.

    40k GitHub starsUsed in 9 repos~646 tokens
    Auto-check passed
  • Golang Patterns

    affaan-m/ECC

    Go-specific design patterns and best practices including functional options, small interfaces, dependency injection, concurrency patterns, error handling, and package organization.

    275k GitHub stars~1.1k tokensUpdated 3 days ago
    DevelopmentAuto-check passed
  • Describes seven Rust design patterns for the RTK CLI filter modules, with when to use each, RTK examples, and notes on when a pattern is overkill.

    83k GitHub stars~1.9k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • JetBrains Exposed ORM patterns including DSL queries, DAO pattern, transactions, HikariCP connection pooling, Flyway migrations, and repository pattern.

    275k GitHub starsUsed in 4 repos~5.5k tokens
    DatabasesAuto-check passed
  • Dotnet Patterns

    affaan-m/ECC

    Idiomatic C and .NET patterns, conventions, dependency injection, async/await, and best practices for building robust, maintainable .NET applications.

    275k GitHub starsUsed in 1 repo~2.3k tokens
    DevelopmentAuto-check passed

More from PlamenTSV/plamen

All 87 skills in this repo
  • Audit Prep

    PlamenTSV/plamen

    Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project…

    303 GitHub stars~3.7k tokensUpdated 12 days ago
    Auto-check passed
  • Verification Protocol

    PlamenTSV/plamen

    Trigger Pattern Always (used by all verifier agents) - Inject Into security-verifier agents (Phase 5)

    303 GitHub stars~3.5k tokensUpdated 12 days ago
    Auto-check passed
  • Ability Analysis

    PlamenTSV/plamen

    Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth agents, depth agents

    303 GitHub stars~3.3k tokensUpdated 12 days ago
    Auto-check passed
  • Ability Analysis

    PlamenTSV/plamen

    Trigger Pattern Always (Sui Move) -- foundational security check - Inject Into Breadth agents, depth agents

    303 GitHub stars~3.2k tokensUpdated 12 days ago
    Auto-check passed
  • Account Lifecycle

    PlamenTSV/plamen

    Trigger Pattern ACCOUNTCLOSING flag detected (close/CloseAccount usage) - Inject Into Breadth agents, depth agents

    303 GitHub stars~1.2k tokensUpdated 12 days ago
    Auto-check passed
  • Account Validation

    PlamenTSV/plamen

    Trigger Pattern Always required for Solana audits - Inject Into Breadth agents, depth agents

    303 GitHub stars~1.7k tokensUpdated 12 days ago
    Auto-check passed

Questions about Bit Shift Safety

What does Bit Shift Safety do?

Trigger Pattern Always (Sui Move) -- Move VM aborts on shift = bit width - Inject Into Breadth agents, depth-edge-case. Bit Shift Safety is an agent skill from PlamenTSV/plamen.

When should I use Bit Shift Safety?

Bit Shift Safety fits situations like: pattern Always (Sui Move) -- Move VM aborts on shift = bit width - Inject Into Breadth agents; depth-edge-case.

How do I install Bit Shift Safety in Claude Code?

Run `npx skills add PlamenTSV/plamen --skill bit-shift-safety -a claude-code`. Or copy the skill folder (agents/skills/sui/bit-shift-safety in PlamenTSV/plamen) into .claude/skills/bit-shift-safety in your project. Claude Code loads it when a task matches its description.

How do I install Bit Shift Safety in Codex?

Run `npx skills add PlamenTSV/plamen --skill bit-shift-safety -a codex`. Or copy the skill folder (agents/skills/sui/bit-shift-safety in PlamenTSV/plamen) into .agents/skills/bit-shift-safety in your project. Codex loads it when a task matches its description.

Can I use Bit Shift Safety in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PlamenTSV/plamen --skill bit-shift-safety -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/bit-shift-safety, .gemini/skills/bit-shift-safety, .github/skills/bit-shift-safety and .opencode/skills/bit-shift-safety in your project.

What does Bit Shift Safety need to run?

SKILL.md names no scripts, command-line tools or credentials: Bit Shift Safety is instructions for the agent only.

Does Bit Shift Safety access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Bit Shift Safety safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Bit Shift Safety use?

Bit Shift Safety is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Bit Shift Safety use?

About 2.2k tokens (SKILL.md is roughly 8.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Bit Shift Safety?

Skills that share tags, products or a category with Bit Shift Safety: Python Patterns (affaan-m/ECC, 275k stars), Memory Safety Patterns (wshobson/agents, 40k stars), Golang Patterns (affaan-m/ECC, 275k stars) and RTK Rust Design Patterns (rtk-ai/rtk, 83k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Bit Shift Safety?

PlamenTSV (a GitHub user) maintains it in PlamenTSV/plamen, which has 303 GitHub stars. The repository holds 87 skills in this directory. The repository was last updated on September 26, 2026.

Source: PlamenTSV/plamen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.