Smart Contract Upgrade Governance
sickn33/agentic-awesome-skills
Soroban WASM upgrade governance register: executable bytecode hash, timelocked migration delays, and multi-sig authorization quorum.
Trigger Pattern contractimport!. An agent skill from PlamenTSV/plamen.
$ npx skills add PlamenTSV/plamen --skill custom-type-safety -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install PlamenTSV/plamen custom-type-safety --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agents/skills/soroban/custom-type-safety .claude/skills/custom-type-safety && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "custom-type-safety" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/soroban/custom-type-safety into .claude/skills/custom-type-safety/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "custom-type-safety", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/PlamenTSV/plamen/tree/main/agents/skills/soroban/custom-type-safetyType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add PlamenTSV/plamen --skill custom-type-safety -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install PlamenTSV/plamen custom-type-safety --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .agents/skills && cp -r skills-src/agents/skills/soroban/custom-type-safety .agents/skills/custom-type-safety && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "custom-type-safety" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/soroban/custom-type-safety into .agents/skills/custom-type-safety/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "custom-type-safety", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add PlamenTSV/plamen --skill custom-type-safety -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install PlamenTSV/plamen custom-type-safety --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/agents/skills/soroban/custom-type-safety .cursor/skills/custom-type-safety && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "custom-type-safety" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/soroban/custom-type-safety into .cursor/skills/custom-type-safety/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "custom-type-safety", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/PlamenTSV/plamen.git --path agents/skills/soroban/custom-type-safety--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add PlamenTSV/plamen --skill custom-type-safety -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install PlamenTSV/plamen custom-type-safety --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/agents/skills/soroban/custom-type-safety .gemini/skills/custom-type-safety && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "custom-type-safety" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/soroban/custom-type-safety into .gemini/skills/custom-type-safety/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "custom-type-safety", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install PlamenTSV/plamen custom-type-safetyInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add PlamenTSV/plamen --skill custom-type-safety -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .github/skills && cp -r skills-src/agents/skills/soroban/custom-type-safety .github/skills/custom-type-safety && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "custom-type-safety" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/soroban/custom-type-safety into .github/skills/custom-type-safety/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "custom-type-safety", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add PlamenTSV/plamen --skill custom-type-safety -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install PlamenTSV/plamen custom-type-safety --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/agents/skills/soroban/custom-type-safety .opencode/skills/custom-type-safety && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "custom-type-safety" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/soroban/custom-type-safety into .opencode/skills/custom-type-safety/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "custom-type-safety", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
custom-type-safetyTrigger Pattern contractimport!. An agent skill from PlamenTSV/plamen.
Custom Type Safety is an agent skill from PlamenTSV/plamen. Trigger Pattern contractimport! or contracttype detected - Inject Into Breadth agents, depth-external
Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development, covering Type safety and Smart contract auditing. It works with Stellar and WebAssembly. The repository describes itself as: Autonomous Web3 security audit agent for Claude Code. The licence is MIT.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 795962b. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are rust and markdown).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Custom Type Safety loads about 2.1k tokens when it runs. Until then it costs about 30 tokens; SKILL.md has 863 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from PlamenTSV/plamen at commit 795962b, republished under its MIT licence (© PlamenTSV). 863 words, ~2,137 tokens.
.claude/skills/custom-type-safety/SKILL.md (or your agent's skills folder).Trigger Pattern:
contractimport!or#[contracttype]detected in codebase Inject Into: Breadth agents, depth-external Finding prefix:[CT-N]Rules referenced: R4, R8, R10
Soroban contracts interact with external contracts through generated client bindings (contractimport!) and pass structured data across boundaries using #[contracttype] types. Both mechanisms carry security-relevant assumptions about versioning, type stability, and deserialization behavior that must be verified.
For every contractimport! macro invocation, identify what is being imported and whether it is pinned:
| Import Target | File/Path or Wasm Hash | Version Pinned? | Pinning Method | Stable? |
|---|---|---|---|---|
contractimport!("{target}") | {resolved path or hash} | YES/NO | Hash / Path / None | YES/NO |
Pinning methods (strongest to weakest):
contractimport!(file = "...", sha256 = "0xabc...") — exact bytecode pinning, most secureChecks:
When values of #[contracttype] types cross contract boundaries via invoke_contract, the receiving contract must be able to deserialize them. Verify semantic meaning is preserved:
| Type | Crosses Boundary? | Sending Contract Version | Receiving Contract Version | Compatibility? |
|---|---|---|---|---|
{StructName} | YES/NO | {version or hash} | {version or hash} | YES/NO |
Safety rules:
#[contracttype] types serialize to ScVal using field names as keys (for structs) or variant names (for enums). Adding fields with defaults is safe; removing fields or renaming them breaks existing serialized data.Type confusion risk: A #[contracttype] enum variant that serializes to the same ScVal representation as a variant in a different enum is a type confusion vector. This is rare but check when two enums use identical variant names or when raw Val conversions are used.
An imported contract may have been upgraded since the contractimport! snapshot was taken. If the imported ABI has changed, calling the contract with the old-generated client will fail at runtime:
| Imported Contract | Import Snapshot Date / Hash | Currently Deployed Hash | ABI Drift? | Breaking Changes? |
|---|---|---|---|---|
{contract name} | {date or hash from file} | {check stellar explorer or build_status} | YES/NO/UNKNOWN | YES/NO/UNKNOWN |
How to detect:
contractimport! statement against the currently deployed contract's WASM hash via the Stellar networkImpact of stale imports: Runtime deserialization errors (InvalidAction / WasmError) when calling functions whose signatures have changed. The contract compiles successfully but fails at runtime, potentially during critical operations.
#[contracttype] enums and structs must handle all serialization edge cases. Verify correct handling:
| Type | All Enum Variants Handled in Match? | Default/Fallback for Unknown Variants? | Deserialization Panic on Unknown? |
|---|---|---|---|
{EnumName} | YES/NO | YES/NO | YES/NO → FLAG if YES |
Enum exhaustiveness:
#[contracttype]
pub enum Status {
Active,
Paused,
Closed,
}
// SAFE: all variants covered
match status {
Status::Active => ...,
Status::Paused => ...,
Status::Closed => ...,
}
// RISKY: if a new variant is added to the external contract's Status,
// deserialization succeeds but the match panics
match status {
Status::Active => ...,
Status::Paused => ...,
// Missing: Status::Closed → panic at runtime
}Struct field additions: If an external contract's #[contracttype] struct gains new fields, the importing contract's deserialization will fail with a type mismatch unless it uses versioned types or handles extra fields gracefully.
For each #[contracttype] enum used in deserialization:
Direct Val conversions (e.g., Val::from_val, TryFromVal, raw RawVal casts) bypass the typed #[contracttype] system. These must be handled with explicit error checking:
| Location | Val Conversion | Error Handled? | Type Confusion Risk? |
|---|---|---|---|
{file:line} | {conversion expression} | YES/NO | YES/NO |
Unsafe patterns:
val.unchecked_into::<i128>() — no type check, interprets raw bits as i128 regardless of actual typeTryFromVal::try_from_val(&env, val).unwrap() — panics on type mismatch instead of returning an errorVal::from_bool / Val::from_i32 on unverified external inputSafe patterns:
TryFromVal::try_from_val(&env, val).map_err(|_| Error::InvalidInput)? — handles type mismatch gracefully#[contracttype] types for all cross-boundary data (avoids raw Val entirely)Val tag before conversion: val.is_i32 / val.get_tag() == Tag::I32ValType confusion attacks: If an attacker can influence the Val type tag (e.g., by passing an Address where an i128 is expected), raw conversion will interpret the Address bits as an integer, producing arbitrary numeric values — potential for balance manipulation, permission bypass, or incorrect calculation results.
**ID**: [CT-N]
**Severity**: [High if type confusion enables fund theft or auth bypass, Medium if stale import causes DoS, Low if missing variant or pinning only]
**Step Execution**: ✓1,2,3,4,5 | ✗(reasons) | ?(uncertain)
**Rules Applied**: [R4:✓/✗, R8:✓/✗, R10:✓/✗]
**Location**: src/{contract}.rs:LineN (or Cargo.toml/build.rs for Section 1)
**Title**: {Unpinned import / stale dependency / Val type confusion / missing variant} in `{context}`
**Description**: [Specific type safety issue with import target, type name, or conversion expression]
**Impact**: [Runtime deserialization panic / incorrect value interpretation / type confusion enabling exploit]| Section | Required | Completed? | Notes |
|---|---|---|---|
| 1. Import Dependency Audit | IF contractimport! present | ✓/✗(N/A)/? | All import targets, pinning method |
| 2. Type Boundary Safety | IF types cross contract boundaries | ✓/✗(N/A)/? | All #[contracttype] types in cross-boundary calls |
| 3. Stale Dependency Detection | IF contractimport! present | ✓/✗(N/A)/? | Snapshot hash vs deployed hash |
| 4. Custom Type Validation | IF #[contracttype] enums used in match | ✓/✗(N/A)/? | All match arms exhaustive |
| 5. Val Conversion Safety | IF raw Val conversions present | ✓/✗(N/A)/? | All unchecked_into / try_from_val calls |
© PlamenTSV, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in agents/skills/soroban/custom-type-safety of PlamenTSV/plamen.
Open the folder on GitHubat commit 795962b
Custom Type Safety next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Custom Type Safety this skillPlamenTSV/plamen | 303 | — | ~2.1k | Automated safety check: Pass | MIT | |
| Smart Contract Upgrade Governancesickn33/agentic-awesome-skills | 47k | 1 repos | ~1.4k | Automated safety check: Pass | MIT | |
| Merjsjustrach/merjs | 357 | — | ~4k | Automated safety check: Notes | MIT | |
| Stellar iOS Mac SDKSoneso/stellar-ios-mac-sdk | 132 | — | ~4.3k | Automated safety check: Pass | Apache-2.0 | |
| Stellar DevVelaPayments/vela-payments | 131 | — | ~1.8k | Automated safety check: Pass | MIT | |
| Smart Contract Formal Verificationsickn33/agentic-awesome-skills | 47k | 1 repos | ~1.4k | Automated safety check: Pass | MIT |
sickn33/agentic-awesome-skills
Soroban WASM upgrade governance register: executable bytecode hash, timelocked migration delays, and multi-sig authorization quorum.
justrach/merjs
Work with the merjs Zig web framework. An agent skill from justrach/merjs.
Soneso/stellar-ios-mac-sdk
Guides Stellar blockchain development in Swift using stellar-ios-mac-sdk.
VelaPayments/vela-payments
End-to-end Stellar development playbook. An agent skill from VelaPayments/vela-payments.
sickn33/agentic-awesome-skills
Foundry and Soroban formal invariant verification register: state transition rules, boundary invariant properties, and symbolic execution checks.
sickn33/agentic-awesome-skills
Soroban smart contract security audit register: authorization checks, panic pathways, integer overflows, and storage footprint verification for Stellar.
PlamenTSV/plamen
Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project…
PlamenTSV/plamen
Trigger Pattern Always (used by all verifier agents) - Inject Into security-verifier agents (Phase 5)
PlamenTSV/plamen
Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth agents, depth agents
PlamenTSV/plamen
Trigger Pattern Always (Sui Move) -- foundational security check - Inject Into Breadth agents, depth agents
PlamenTSV/plamen
Trigger Pattern ACCOUNTCLOSING flag detected (close/CloseAccount usage) - Inject Into Breadth agents, depth agents
PlamenTSV/plamen
Trigger Pattern Always required for Solana audits - Inject Into Breadth agents, depth agents
Works with
Categories
Trigger Pattern contractimport!. An agent skill from PlamenTSV/plamen. Custom Type Safety is an agent skill from PlamenTSV/plamen. Trigger Pattern contractimport!
Custom Type Safety fits situations like: pattern contractimport!; tasks that involve Type safety; tasks that involve Smart contract auditing.
Run `npx skills add PlamenTSV/plamen --skill custom-type-safety -a claude-code`. Or copy the skill folder (agents/skills/soroban/custom-type-safety in PlamenTSV/plamen) into .claude/skills/custom-type-safety in your project. Claude Code loads it when a task matches its description.
Run `npx skills add PlamenTSV/plamen --skill custom-type-safety -a codex`. Or copy the skill folder (agents/skills/soroban/custom-type-safety in PlamenTSV/plamen) into .agents/skills/custom-type-safety in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PlamenTSV/plamen --skill custom-type-safety -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/custom-type-safety, .gemini/skills/custom-type-safety, .github/skills/custom-type-safety and .opencode/skills/custom-type-safety in your project.
SKILL.md names no scripts, command-line tools or credentials: Custom Type Safety is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Custom Type Safety is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.1k tokens (SKILL.md is roughly 8.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Custom Type Safety: Smart Contract Upgrade Governance (sickn33/agentic-awesome-skills, 47k stars), Merjs (justrach/merjs, 357 stars), Stellar iOS Mac SDK (Soneso/stellar-ios-mac-sdk, 132 stars) and Stellar Dev (VelaPayments/vela-payments, 131 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
PlamenTSV (a GitHub user) maintains it in PlamenTSV/plamen, which has 303 GitHub stars. The repository holds 87 skills in this directory. The repository was last updated on September 26, 2026.
Source: PlamenTSV/plamen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.