Agent skill

Cross Chain Message Integrity

by PlamenTSV in PlamenTSV/plamen

Type Thought-template (instantiate before use) - Trigger Pattern CROSSCHAINMSG flag detected (protocol RECEIVES cross-chain messages)

MITAuto-check passedBackend & APIs

Install Cross Chain Message Integrity

skills CLI
$ npx skills add PlamenTSV/plamen --skill cross-chain-message-integrity -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install PlamenTSV/plamen cross-chain-message-integrity --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agents/skills/evm/cross-chain-message-integrity .claude/skills/cross-chain-message-integrity && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cross-chain-message-integrity
GitHub stars
303
Token cost
~2.1k tokens
SKILL.md length
884 words
Files
1
Skills in repo
87
Repo updated
First seen
Licence
MIT

At a glance

Type Thought-template (instantiate before use) - Trigger Pattern CROSSCHAINMSG flag detected (protocol RECEIVES cross-chain messages)

  • Works in 6 steps: Message Receiving Surface Inventory → Endpoint Authentication Audit → Peer Registry Security → …
  • Pattern CROSSCHAINMSG flag detected (protocol RECEIVES cross-chain messages)
  • SKILL.md covers Trigger Patterns, Step 1: Message Receiving…, Step 2: Endpoint… and Step 3: Peer Registry Security, plus 7 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Cross Chain Message Integrity is an agent skill from PlamenTSV/plamen. Type Thought-template (instantiate before use) - Trigger Pattern CROSSCHAINMSG flag detected (protocol RECEIVES cross-chain messages)

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Smart contracts. The repository describes itself as: Autonomous Web3 security audit agent for Claude Code. The licence is MIT.

When your agent uses it

  • Pattern CROSSCHAINMSG flag detected (protocol RECEIVES cross-chain messages)
  • Tasks that involve Smart contracts

Example prompts

  • “/cross-chain-message-integrity”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Message Receiving Surface Inventory
  2. Endpoint Authentication Audit
  3. Peer Registry Security
  4. Replay Protection
  5. Payload Validation
  6. Message Ordering and Delivery

What it can do on your machine

Read from SKILL.md and the folder at commit 795962b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cross Chain Message Integrity loads about 2.1k tokens when it runs. Until then it costs about 41 tokens; SKILL.md has 884 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~41
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from PlamenTSV/plamen at commit 795962b, republished under its MIT licence (© PlamenTSV). 884 words, ~2,101 tokens.

Download SKILL.mdSave it as .claude/skills/cross-chain-message-integrity/SKILL.md (or your agent's skills folder).
name
cross-chain-message-integrity
description
Type Thought-template (instantiate before use) - Trigger Pattern CROSS_CHAIN_MSG flag detected (protocol RECEIVES cross-chain messages)

Skill: Cross-Chain Message Integrity

Type: Thought-template (instantiate before use) Trigger Pattern: CROSS_CHAIN_MSG flag detected (protocol RECEIVES cross-chain messages) Inject Into: Breadth agents, depth-external Finding prefix: [CMI-N] Rules referenced: R1, R2, R4, R8, R10

Covers: message endpoint authentication, peer/remote verification, replay protection, payload validation, and message ordering for bridge-receiving protocols.

This skill is SEPARATE from CROSS_CHAIN_TIMING (which covers stale state and latency arbitrage for L2 interactions). Use this skill when the protocol RECEIVES and PROCESSES inbound cross-chain messages. Use CROSS_CHAIN_TIMING when the protocol READS state synced across chains.


Trigger Patterns

lzReceive|_ccipReceive|receiveWormholeMessages|onOFTReceived|
setPeer|setTrustedRemote|_nonblockingLzReceive|executeMessage|
_processMessageFrom|ILayerZeroReceiver|IAny2EVMMessageReceiver|
endpoint.*receive|bridge.*receive|relayer.*deliver|_lzReceive

Step 1: Message Receiving Surface Inventory

For each function that processes inbound cross-chain messages:

#FunctionBridge ProtocolSource Auth?Payload Validated?State ModifiedAccess Control

For each entry:

  • What bridge/messaging protocol delivers the message?
  • Can the function be called DIRECTLY by anyone, or only via the bridge endpoint?
  • What state does the function modify based on message content? (mint, unlock, update, execute)

Step 2: Endpoint Authentication Audit

For EACH message-receiving function:

2a. Caller Verification
#CheckStatusLocation
1msg.sender == endpoint/router verifiedYES/NO{line}
2Endpoint address immutable or admin-protectedYES/NO{line}
3Modifier checks the CORRECT address variableYES/NO{line}

Missing caller check → CRITICAL: Anyone can fabricate message data and trigger mints/unlocks.

2b. Source Origin Verification
#CheckStatusLocation
1Source chain ID validated against allowed setYES/NO{line}
2Source sender validated against registered peerYES/NO{line}
3BOTH checks present (chain AND sender)YES/NO{line}

Pattern: Checks _origin.srcEid (chain) but not _origin.sender (peer) → accepts messages from ANY contract on allowed chains.


Step 3: Peer Registry Security

For each function that configures trusted peers/remotes:

3a. Setter Access Control
#CheckStatusLocation
1Access-controlled (onlyOwner/multisig/timelock)YES/NO{line}
2Validates new peer is non-zeroYES/NO{line}
3Emits event for off-chain monitoringYES/NO{line}
4Timelock/delay on peer changesYES/NO{line}
3b. Peer Binding Completeness
  • Peer mapping keyed by chain ID? One peer per chain, or multiple?
  • Can in-flight messages from OLD peer be processed after peer change?
  • Default state for unregistered chain: does _origin.sender == peers[chainId] pass when BOTH are zero?
3c. Cross-Chain Address Assumptions
  • Does the protocol assume address(X) on Chain A == address(X) on Chain B means same owner?
  • For CREATE-deployed contracts: different deployer nonce across chains → same address, different owner.
  • For EOAs: private key owner is the same across chains (safe). For contracts: NOT guaranteed.

Tag: [TRACE:setPeer(chain={X}) → access={check} → zero_check={YES/NO} → default_peer={value}]


Step 4: Replay Protection

4a. Message Uniqueness
#CheckStatusLocation
1Each message processed exactly onceYES/NO{line}
2Replay check BEFORE state changesYES/NO{line}
3Out-of-order messages handledYES/NO{line}
4Sequence gaps handled gracefullyYES/NO{line}
4b. Cross-Chain Replay
  • Message valid on chain A replayable on chain B?
  • Payload includes destination chain ID AND destination address?
  • Same contract deployed on N chains: message for chain A processable on chain B?
4c. Re-org Safety
  • Source chain re-org: can previously-processed message be re-delivered with different nonce?
  • Protocol responsibility vs bridge responsibility for re-org handling?

Tag: [TRACE:message_nonce={N} → replay_check={method} → before_state_change={YES/NO}]


Step 5: Payload Validation

5a. Format Enforcement
  • Payload decoded with explicit type checks? (abi.decode with expected types)
  • Malformed payload handling: revert, silent skip, or partial decode?
  • Payload length mismatch: can it cause incorrect ABI decoding of dynamic types?
Show full SKILL.md (357 more words)Show less
5b. Value Bounds

For each decoded value:

  • Bounds checks present? (amount ≤ supply cap, address ≠ zero, deadline not expired)
  • Can source chain send payload causing overflow/underflow when processed?
  • Addresses decoded from payload: treated as address on THIS chain or source chain?
5c. Arbitrary Execution

If message triggers execution of decoded calldata:

  • Target restricted to known contracts?
  • Function selector restricted to safe set?
  • Can decoded calldata invoke transferFrom/approve on tokens the contract holds or has approvals for?

Tag: [BOUNDARY:payload_amount={MAX} → decoded → processed_as={result}]


Step 6: Message Ordering and Delivery

6a. Ordering Dependencies
  • Any messages depend on previous messages being processed first?
  • Out-of-order arrival: state corruption or graceful handling?
  • Queue/retry mechanism for failed deliveries?
6b. Blocked Message Recovery
  • Failed message: retryable? By whom? With what gas limit?
  • Permanently blocked message prevents subsequent messages? (head-of-line blocking)
  • Admin mechanism to skip/clear blocked messages?
  • Can attacker intentionally cause failure to block the queue?

Tag: [TRACE:message_N_fails → message_N+1={blocked/processed} → recovery={mechanism}]


Key Questions (must answer all)

  1. Can any receiving function be called directly without going through the bridge endpoint?
  2. Are BOTH source chain AND source address validated against registered peers?
  3. What is the default behavior for messages from an UNREGISTERED chain/peer?
  4. Is each message processed exactly once with replay check BEFORE state changes?
  5. Can decoded payload values cause overflow, underflow, or arbitrary execution?
  6. What happens when delivery fails or messages arrive out of order?

Common False Positives

  • Bridge-level replay: Bridge protocol itself prevents replay AND protocol correctly verifies bridge auth → protocol-level replay may be unnecessary
  • Idempotent operations: Protocol allows re-delivery by design (same result regardless of count) → not a replay vulnerability
  • Admin peer with timelock: setPeer behind multisig + timelock → low unauthorized change risk
  • View-only consumption: Message updates state also validated by other mechanisms (oracle bounds, rate limits) → bounded impact

Instantiation Parameters

{CONTRACTS}           -- Contracts with message receiving functions
{BRIDGE_PROTOCOL}     -- Bridge/messaging protocol (LayerZero, CCIP, Wormhole, Axelar, Hyperlane)
{RECEIVE_FUNCTIONS}   -- Functions that process inbound messages
{PEER_SETTERS}        -- Functions that configure trusted peers/remotes
{STATE_MODIFIED}      -- State modified by message processing

Step Execution Checklist (MANDATORY)

StepRequiredCompleted?Notes
1. Message Receiving Surface InventoryYESAll receiving functions
2. Endpoint Authentication AuditYESCaller + source origin
3. Peer Registry SecurityIF configurable peersSetter access, binding, defaults
4. Replay ProtectionYESUniqueness, cross-chain, re-org
5. Payload ValidationYESFormat, bounds, arbitrary execution
6. Message Ordering and DeliveryIF ordered messagesDependencies, blocked recovery

© PlamenTSV, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in agents/skills/evm/cross-chain-message-integrity of PlamenTSV/plamen.

Open the folder on GitHubat commit 795962b

Compare with similar skills

Cross Chain Message Integrity next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cross Chain Message Integrity compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cross Chain Message Integrity this skillPlamenTSV/plamen303—~2.1kAutomated safety check: PassMIT
Fizz Convertpashov/skills1.2k2 repos~3.7kAutomated safety check: PassMIT
Solana Devsolana-foundation/solana-dev-skill574—~3.8kAutomated safety check: PassMIT
Feynman Auditor0xiehnnkta/nemesis-auditor2431 repos~11kAutomated safety check: PassMIT
Smart Contract Auditgreatpie/smart-contract-audit-skill101—~1.1kAutomated safety check: PassNone
RadarAuditware/radar154—~2.1kAutomated safety check: PassGPL-3.0

Similar skills

  • Fizz Convert

    pashov/skills

    Convert English-language properties in PROPERTIES.md (produced by the Fizz skill) into Solidity assertions inside the existing fuzz harness, then flip their checkboxes.

    1.2k GitHub starsUsed in 2 repos~3.7k tokens
    Backend & APIsAuto-check passed
  • Solana Dev

    solana-foundation/solana-dev-skill

    A skill your agent uses when user asks to "build a Solana dapp", "write an Anchor program", "create a token", "debug Solana errors", "set up wallet connection", "test my Solana program", "fuzz my…

    574 GitHub stars~3.8k tokensUpdated today
    Backend & APIsAuto-check passed
  • Feynman Auditor

    0xiehnnkta/nemesis-auditor

    Deep business logic bug finder using the Feynman technique. An agent skill from 0xiehnnkta/nemesis-auditor.

    243 GitHub starsUsed in 1 repo~11k tokens
    Backend & APIsAuto-check passed
  • Smart Contract Audit

    greatpie/smart-contract-audit-skill

    Script-backed, out-of-box auditing workflow for Solidity/EVM repositories based on EVMbench detect/patch/exploit methodology.

    101 GitHub stars~1.1k tokensUpdated 7 mo ago
    Backend & APIsAuto-check passed
  • Radar

    Auditware/radar

    Use radar for smart contract security analysis, AST generation, and detection template development.

    154 GitHub stars~2.1k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Solidity Auditor

    Gabson0x/bountyforge

    Security audit of Solidity code while you develop. An agent skill from Gabson0x/bountyforge.

    442 GitHub stars~3.7k tokensUpdated 22 days ago
    Backend & APIsAuto-check passed

More from PlamenTSV/plamen

All 87 skills in this repo
  • Audit Prep

    PlamenTSV/plamen

    Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project…

    303 GitHub stars~3.7k tokensUpdated 13 days ago
    Auto-check passed
  • Verification Protocol

    PlamenTSV/plamen

    Trigger Pattern Always (used by all verifier agents) - Inject Into security-verifier agents (Phase 5)

    303 GitHub stars~3.5k tokensUpdated 13 days ago
    Auto-check passed
  • Ability Analysis

    PlamenTSV/plamen

    Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth agents, depth agents

    303 GitHub stars~3.3k tokensUpdated 13 days ago
    Auto-check passed
  • Ability Analysis

    PlamenTSV/plamen

    Trigger Pattern Always (Sui Move) -- foundational security check - Inject Into Breadth agents, depth agents

    303 GitHub stars~3.2k tokensUpdated 13 days ago
    Auto-check passed
  • Account Lifecycle

    PlamenTSV/plamen

    Trigger Pattern ACCOUNTCLOSING flag detected (close/CloseAccount usage) - Inject Into Breadth agents, depth agents

    303 GitHub stars~1.2k tokensUpdated 13 days ago
    Auto-check passed
  • Account Validation

    PlamenTSV/plamen

    Trigger Pattern Always required for Solana audits - Inject Into Breadth agents, depth agents

    303 GitHub stars~1.7k tokensUpdated 13 days ago
    Auto-check passed

Categories

Questions about Cross Chain Message Integrity

What does Cross Chain Message Integrity do?

Type Thought-template (instantiate before use) - Trigger Pattern CROSSCHAINMSG flag detected (protocol RECEIVES cross-chain messages). Cross Chain Message Integrity is an agent skill from PlamenTSV/plamen.

When should I use Cross Chain Message Integrity?

Cross Chain Message Integrity fits situations like: pattern CROSSCHAINMSG flag detected (protocol RECEIVES cross-chain messages); tasks that involve Smart contracts.

How do I install Cross Chain Message Integrity in Claude Code?

Run `npx skills add PlamenTSV/plamen --skill cross-chain-message-integrity -a claude-code`. Or copy the skill folder (agents/skills/evm/cross-chain-message-integrity in PlamenTSV/plamen) into .claude/skills/cross-chain-message-integrity in your project. Claude Code loads it when a task matches its description.

How do I install Cross Chain Message Integrity in Codex?

Run `npx skills add PlamenTSV/plamen --skill cross-chain-message-integrity -a codex`. Or copy the skill folder (agents/skills/evm/cross-chain-message-integrity in PlamenTSV/plamen) into .agents/skills/cross-chain-message-integrity in your project. Codex loads it when a task matches its description.

Can I use Cross Chain Message Integrity in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PlamenTSV/plamen --skill cross-chain-message-integrity -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cross-chain-message-integrity, .gemini/skills/cross-chain-message-integrity, .github/skills/cross-chain-message-integrity and .opencode/skills/cross-chain-message-integrity in your project.

What does Cross Chain Message Integrity need to run?

SKILL.md names no scripts, command-line tools or credentials: Cross Chain Message Integrity is instructions for the agent only.

Does Cross Chain Message Integrity access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Cross Chain Message Integrity safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cross Chain Message Integrity use?

Cross Chain Message Integrity is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cross Chain Message Integrity use?

About 2.1k tokens (SKILL.md is roughly 8.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Cross Chain Message Integrity?

Skills that share tags, products or a category with Cross Chain Message Integrity: Fizz Convert (pashov/skills, 1.2k stars), Solana Dev (solana-foundation/solana-dev-skill, 574 stars), Feynman Auditor (0xiehnnkta/nemesis-auditor, 243 stars) and Smart Contract Audit (greatpie/smart-contract-audit-skill, 101 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cross Chain Message Integrity?

PlamenTSV (a GitHub user) maintains it in PlamenTSV/plamen, which has 303 GitHub stars. The repository holds 87 skills in this directory. The repository was last updated on September 26, 2026.

Source: PlamenTSV/plamen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.