Agent skill

Custom Type Safety

by PlamenTSV in PlamenTSV/plamen

Trigger Pattern contractimport!. An agent skill from PlamenTSV/plamen.

MITAuto-check passedDevelopment

Install Custom Type Safety

skills CLI
$ npx skills add PlamenTSV/plamen --skill custom-type-safety -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install PlamenTSV/plamen custom-type-safety --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agents/skills/soroban/custom-type-safety .claude/skills/custom-type-safety && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
custom-type-safety
GitHub stars
303
Token cost
~2.1k tokens
SKILL.md length
863 words
Files
1
Skills in repo
87
Repo updated
First seen
Licence
MIT

At a glance

Trigger Pattern contractimport!. An agent skill from PlamenTSV/plamen.

  • Works in 5 steps: Import Dependency Audit → Type Boundary Safety → Stale Dependency Detection → …
  • Pattern contractimport!
  • SKILL.md covers 1. Import Dependency Audit, 2. Type Boundary Safety, 3. Stale Dependency Detection and 4. Custom Type Validation, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Custom Type Safety is an agent skill from PlamenTSV/plamen. Trigger Pattern contractimport! or contracttype detected - Inject Into Breadth agents, depth-external

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Type safety and Smart contract auditing. It works with Stellar and WebAssembly. The repository describes itself as: Autonomous Web3 security audit agent for Claude Code. The licence is MIT.

When your agent uses it

  • Pattern contractimport!
  • Tasks that involve Type safety
  • Tasks that involve Smart contract auditing

Example prompts

  • “/custom-type-safety”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Import Dependency Audit
  2. Type Boundary Safety
  3. Stale Dependency Detection
  4. Custom Type Validation
  5. Val Conversion Safety

What it can do on your machine

Read from SKILL.md and the folder at commit 795962b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are rust and markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Custom Type Safety loads about 2.1k tokens when it runs. Until then it costs about 30 tokens; SKILL.md has 863 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~30
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from PlamenTSV/plamen at commit 795962b, republished under its MIT licence (© PlamenTSV). 863 words, ~2,137 tokens.

Download SKILL.mdSave it as .claude/skills/custom-type-safety/SKILL.md (or your agent's skills folder).
name
custom-type-safety
description
Trigger Pattern contractimport! or contracttype detected - Inject Into Breadth agents, depth-external

CUSTOM_TYPE_SAFETY Skill (Soroban)

Trigger Pattern: contractimport! or #[contracttype] detected in codebase Inject Into: Breadth agents, depth-external Finding prefix: [CT-N] Rules referenced: R4, R8, R10

Soroban contracts interact with external contracts through generated client bindings (contractimport!) and pass structured data across boundaries using #[contracttype] types. Both mechanisms carry security-relevant assumptions about versioning, type stability, and deserialization behavior that must be verified.

1. Import Dependency Audit

For every contractimport! macro invocation, identify what is being imported and whether it is pinned:

Import TargetFile/Path or Wasm HashVersion Pinned?Pinning MethodStable?
contractimport!("{target}"){resolved path or hash}YES/NOHash / Path / NoneYES/NO

Pinning methods (strongest to weakest):

  1. WASM hash: contractimport!(file = "...", sha256 = "0xabc...") — exact bytecode pinning, most secure
  2. Specific file path in repo: deterministic if the file is version-controlled alongside the contract
  3. Dynamic path or URL: fetched at build time, non-deterministic — flag as HIGH risk

Checks:

  • Is the imported contract itself audited / trusted?
  • Does the import target a well-known protocol (e.g., the Stellar DEX, a lending protocol)? If so, any upgrade to that protocol silently changes the interface the importing contract relies on.
  • For imported WASM: is the hash pinned in the build manifest? If the WASM file is replaced without updating the hash, the build fails (good). If no hash is required, the build silently uses a new version.

2. Type Boundary Safety

When values of #[contracttype] types cross contract boundaries via invoke_contract, the receiving contract must be able to deserialize them. Verify semantic meaning is preserved:

TypeCrosses Boundary?Sending Contract VersionReceiving Contract VersionCompatibility?
{StructName}YES/NO{version or hash}{version or hash}YES/NO

Safety rules:

  • #[contracttype] types serialize to ScVal using field names as keys (for structs) or variant names (for enums). Adding fields with defaults is safe; removing fields or renaming them breaks existing serialized data.
  • If both the sending and receiving contracts are part of the same audit scope, verify the types match exactly.
  • If the receiving contract is external (different deploy), verify the external contract's expected type schema matches what the sending contract sends.

Type confusion risk: A #[contracttype] enum variant that serializes to the same ScVal representation as a variant in a different enum is a type confusion vector. This is rare but check when two enums use identical variant names or when raw Val conversions are used.

3. Stale Dependency Detection

An imported contract may have been upgraded since the contractimport! snapshot was taken. If the imported ABI has changed, calling the contract with the old-generated client will fail at runtime:

Imported ContractImport Snapshot Date / HashCurrently Deployed HashABI Drift?Breaking Changes?
{contract name}{date or hash from file}{check stellar explorer or build_status}YES/NO/UNKNOWNYES/NO/UNKNOWN

How to detect:

  1. Compare the WASM hash in the contractimport! statement against the currently deployed contract's WASM hash via the Stellar network
  2. If hashes differ, inspect the changelog or diff the generated client bindings against the current contract interface
  3. Flag any function signature changes: added required parameters, changed parameter types, removed functions

Impact of stale imports: Runtime deserialization errors (InvalidAction / WasmError) when calling functions whose signatures have changed. The contract compiles successfully but fails at runtime, potentially during critical operations.

Show full SKILL.md (333 more words)Show less

4. Custom Type Validation

#[contracttype] enums and structs must handle all serialization edge cases. Verify correct handling:

TypeAll Enum Variants Handled in Match?Default/Fallback for Unknown Variants?Deserialization Panic on Unknown?
{EnumName}YES/NOYES/NOYES/NO → FLAG if YES

Enum exhaustiveness:

rust
#[contracttype]
pub enum Status {
    Active,
    Paused,
    Closed,
}

// SAFE: all variants covered
match status {
    Status::Active => ...,
    Status::Paused => ...,
    Status::Closed => ...,
}

// RISKY: if a new variant is added to the external contract's Status,
// deserialization succeeds but the match panics
match status {
    Status::Active => ...,
    Status::Paused => ...,
    // Missing: Status::Closed → panic at runtime
}

Struct field additions: If an external contract's #[contracttype] struct gains new fields, the importing contract's deserialization will fail with a type mismatch unless it uses versioned types or handles extra fields gracefully.

For each #[contracttype] enum used in deserialization:

  • Verify the match arm is exhaustive (no missing variants)
  • Verify the type is used as received from the same contract version it was imported from

5. Val Conversion Safety

Direct Val conversions (e.g., Val::from_val, TryFromVal, raw RawVal casts) bypass the typed #[contracttype] system. These must be handled with explicit error checking:

LocationVal ConversionError Handled?Type Confusion Risk?
{file:line}{conversion expression}YES/NOYES/NO

Unsafe patterns:

  • val.unchecked_into::<i128>() — no type check, interprets raw bits as i128 regardless of actual type
  • TryFromVal::try_from_val(&env, val).unwrap() — panics on type mismatch instead of returning an error
  • Using Val::from_bool / Val::from_i32 on unverified external input

Safe patterns:

  • TryFromVal::try_from_val(&env, val).map_err(|_| Error::InvalidInput)? — handles type mismatch gracefully
  • Using #[contracttype] types for all cross-boundary data (avoids raw Val entirely)
  • Validating the Val tag before conversion: val.is_i32 / val.get_tag() == Tag::I32Val

Type confusion attacks: If an attacker can influence the Val type tag (e.g., by passing an Address where an i128 is expected), raw conversion will interpret the Address bits as an integer, producing arbitrary numeric values — potential for balance manipulation, permission bypass, or incorrect calculation results.

Finding Template

markdown
**ID**: [CT-N]
**Severity**: [High if type confusion enables fund theft or auth bypass, Medium if stale import causes DoS, Low if missing variant or pinning only]
**Step Execution**: ✓1,2,3,4,5 | ✗(reasons) | ?(uncertain)
**Rules Applied**: [R4:✓/✗, R8:✓/✗, R10:✓/✗]
**Location**: src/{contract}.rs:LineN (or Cargo.toml/build.rs for Section 1)
**Title**: {Unpinned import / stale dependency / Val type confusion / missing variant} in `{context}`
**Description**: [Specific type safety issue with import target, type name, or conversion expression]
**Impact**: [Runtime deserialization panic / incorrect value interpretation / type confusion enabling exploit]

Step Execution Checklist (MANDATORY)

SectionRequiredCompleted?Notes
1. Import Dependency AuditIF contractimport! present✓/✗(N/A)/?All import targets, pinning method
2. Type Boundary SafetyIF types cross contract boundaries✓/✗(N/A)/?All #[contracttype] types in cross-boundary calls
3. Stale Dependency DetectionIF contractimport! present✓/✗(N/A)/?Snapshot hash vs deployed hash
4. Custom Type ValidationIF #[contracttype] enums used in match✓/✗(N/A)/?All match arms exhaustive
5. Val Conversion SafetyIF raw Val conversions present✓/✗(N/A)/?All unchecked_into / try_from_val calls

© PlamenTSV, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in agents/skills/soroban/custom-type-safety of PlamenTSV/plamen.

Open the folder on GitHubat commit 795962b

Compare with similar skills

Custom Type Safety next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Custom Type Safety compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Custom Type Safety this skillPlamenTSV/plamen303—~2.1kAutomated safety check: PassMIT
Smart Contract Upgrade Governancesickn33/agentic-awesome-skills47k1 repos~1.4kAutomated safety check: PassMIT
Merjsjustrach/merjs357—~4kAutomated safety check: NotesMIT
Stellar iOS Mac SDKSoneso/stellar-ios-mac-sdk132—~4.3kAutomated safety check: PassApache-2.0
Stellar DevVelaPayments/vela-payments131—~1.8kAutomated safety check: PassMIT
Smart Contract Formal Verificationsickn33/agentic-awesome-skills47k1 repos~1.4kAutomated safety check: PassMIT

Similar skills

  • Smart Contract Upgrade Governance

    sickn33/agentic-awesome-skills

    Soroban WASM upgrade governance register: executable bytecode hash, timelocked migration delays, and multi-sig authorization quorum.

    47k GitHub starsUsed in 1 repo~1.4k tokens
    Backend & APIsAuto-check passed
  • Merjs

    justrach/merjs

    Work with the merjs Zig web framework. An agent skill from justrach/merjs.

    357 GitHub stars~4k tokensUpdated 1 mo ago
    DevelopmentAuto-check: notes
  • Stellar iOS Mac SDK

    Soneso/stellar-ios-mac-sdk

    Guides Stellar blockchain development in Swift using stellar-ios-mac-sdk.

    132 GitHub stars~4.3k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Stellar Dev

    VelaPayments/vela-payments

    End-to-end Stellar development playbook. An agent skill from VelaPayments/vela-payments.

    131 GitHub stars~1.8k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Smart Contract Formal Verification

    sickn33/agentic-awesome-skills

    Foundry and Soroban formal invariant verification register: state transition rules, boundary invariant properties, and symbolic execution checks.

    47k GitHub starsUsed in 1 repo~1.4k tokens
    Backend & APIsAuto-check passed
  • Soroban Contract Audit

    sickn33/agentic-awesome-skills

    Soroban smart contract security audit register: authorization checks, panic pathways, integer overflows, and storage footprint verification for Stellar.

    47k GitHub starsUsed in 1 repo~1.4k tokens
    SecurityAuto-check passed

More from PlamenTSV/plamen

All 87 skills in this repo
  • Audit Prep

    PlamenTSV/plamen

    Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project…

    303 GitHub stars~3.7k tokensUpdated 12 days ago
    Auto-check passed
  • Verification Protocol

    PlamenTSV/plamen

    Trigger Pattern Always (used by all verifier agents) - Inject Into security-verifier agents (Phase 5)

    303 GitHub stars~3.5k tokensUpdated 12 days ago
    Auto-check passed
  • Ability Analysis

    PlamenTSV/plamen

    Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth agents, depth agents

    303 GitHub stars~3.3k tokensUpdated 12 days ago
    Auto-check passed
  • Ability Analysis

    PlamenTSV/plamen

    Trigger Pattern Always (Sui Move) -- foundational security check - Inject Into Breadth agents, depth agents

    303 GitHub stars~3.2k tokensUpdated 12 days ago
    Auto-check passed
  • Account Lifecycle

    PlamenTSV/plamen

    Trigger Pattern ACCOUNTCLOSING flag detected (close/CloseAccount usage) - Inject Into Breadth agents, depth agents

    303 GitHub stars~1.2k tokensUpdated 12 days ago
    Auto-check passed
  • Account Validation

    PlamenTSV/plamen

    Trigger Pattern Always required for Solana audits - Inject Into Breadth agents, depth agents

    303 GitHub stars~1.7k tokensUpdated 12 days ago
    Auto-check passed

Categories

Questions about Custom Type Safety

What does Custom Type Safety do?

Trigger Pattern contractimport!. An agent skill from PlamenTSV/plamen. Custom Type Safety is an agent skill from PlamenTSV/plamen. Trigger Pattern contractimport!

When should I use Custom Type Safety?

Custom Type Safety fits situations like: pattern contractimport!; tasks that involve Type safety; tasks that involve Smart contract auditing.

How do I install Custom Type Safety in Claude Code?

Run `npx skills add PlamenTSV/plamen --skill custom-type-safety -a claude-code`. Or copy the skill folder (agents/skills/soroban/custom-type-safety in PlamenTSV/plamen) into .claude/skills/custom-type-safety in your project. Claude Code loads it when a task matches its description.

How do I install Custom Type Safety in Codex?

Run `npx skills add PlamenTSV/plamen --skill custom-type-safety -a codex`. Or copy the skill folder (agents/skills/soroban/custom-type-safety in PlamenTSV/plamen) into .agents/skills/custom-type-safety in your project. Codex loads it when a task matches its description.

Can I use Custom Type Safety in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PlamenTSV/plamen --skill custom-type-safety -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/custom-type-safety, .gemini/skills/custom-type-safety, .github/skills/custom-type-safety and .opencode/skills/custom-type-safety in your project.

What does Custom Type Safety need to run?

SKILL.md names no scripts, command-line tools or credentials: Custom Type Safety is instructions for the agent only.

Does Custom Type Safety access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Custom Type Safety safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Custom Type Safety use?

Custom Type Safety is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Custom Type Safety use?

About 2.1k tokens (SKILL.md is roughly 8.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Custom Type Safety?

Skills that share tags, products or a category with Custom Type Safety: Smart Contract Upgrade Governance (sickn33/agentic-awesome-skills, 47k stars), Merjs (justrach/merjs, 357 stars), Stellar iOS Mac SDK (Soneso/stellar-ios-mac-sdk, 132 stars) and Stellar Dev (VelaPayments/vela-payments, 131 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Custom Type Safety?

PlamenTSV (a GitHub user) maintains it in PlamenTSV/plamen, which has 303 GitHub stars. The repository holds 87 skills in this directory. The repository was last updated on September 26, 2026.

Source: PlamenTSV/plamen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.