Third Party Cookies
thedaviddias/Front-End-Checklist
A skill your agent uses when reviewing a website for privacy compliance, third-party resource loading, or cookie consent implementation.
Trigger Pattern EXTERNALLIB flag (third-party Move dependencies detected in Move.toml beyond Sui framework) - Inject Into Breadth agents, depth-external
$ npx skills add PlamenTSV/plamen --skill dependency-audit -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install PlamenTSV/plamen dependency-audit --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agents/skills/sui/dependency-audit .claude/skills/dependency-audit && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "dependency-audit" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/sui/dependency-audit into .claude/skills/dependency-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-audit", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/PlamenTSV/plamen/tree/main/agents/skills/sui/dependency-auditType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add PlamenTSV/plamen --skill dependency-audit -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install PlamenTSV/plamen dependency-audit --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .agents/skills && cp -r skills-src/agents/skills/sui/dependency-audit .agents/skills/dependency-audit && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "dependency-audit" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/sui/dependency-audit into .agents/skills/dependency-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-audit", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add PlamenTSV/plamen --skill dependency-audit -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install PlamenTSV/plamen dependency-audit --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/agents/skills/sui/dependency-audit .cursor/skills/dependency-audit && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "dependency-audit" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/sui/dependency-audit into .cursor/skills/dependency-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-audit", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/PlamenTSV/plamen.git --path agents/skills/sui/dependency-audit--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add PlamenTSV/plamen --skill dependency-audit -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install PlamenTSV/plamen dependency-audit --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/agents/skills/sui/dependency-audit .gemini/skills/dependency-audit && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "dependency-audit" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/sui/dependency-audit into .gemini/skills/dependency-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-audit", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install PlamenTSV/plamen dependency-auditInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add PlamenTSV/plamen --skill dependency-audit -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .github/skills && cp -r skills-src/agents/skills/sui/dependency-audit .github/skills/dependency-audit && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "dependency-audit" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/sui/dependency-audit into .github/skills/dependency-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-audit", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add PlamenTSV/plamen --skill dependency-audit -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install PlamenTSV/plamen dependency-audit --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/agents/skills/sui/dependency-audit .opencode/skills/dependency-audit && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "dependency-audit" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/sui/dependency-audit into .opencode/skills/dependency-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-audit", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
dependency-auditTrigger Pattern EXTERNALLIB flag (third-party Move dependencies detected in Move.toml beyond Sui framework) - Inject Into Breadth agents, depth-external
Dependency Audit is an agent skill from PlamenTSV/plamen. Trigger Pattern EXTERNALLIB flag (third-party Move dependencies detected in Move.toml beyond Sui framework) - Inject Into Breadth agents, depth-external
Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
The repository describes itself as: Autonomous Web3 security audit agent for Claude Code. The licence is MIT.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 795962b. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Dependency Audit loads about 3.3k tokens when it runs. Until then it costs about 43 tokens; SKILL.md has 1,478 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from PlamenTSV/plamen at commit 795962b, republished under its MIT licence (© PlamenTSV). 1,478 words, ~3,330 tokens.
.claude/skills/dependency-audit/SKILL.md (or your agent's skills folder).Trigger Pattern: EXTERNAL_LIB flag (third-party Move dependencies detected in Move.toml beyond Sui framework) Inject Into: Breadth agents, depth-external Finding prefix:
[DEP-N]Rules referenced: R1, R4, R8, R10
Move's dependency model is package-based: Move.toml declares dependencies with git URLs and revisions. Unlike EVM's compiled-and-deployed model where dependencies are inlined at compile time, Sui Move packages can depend on other PUBLISHED packages (on-chain) or source packages (compiled together). Third-party math libraries, utility packages, and protocol SDKs are common dependency vectors.
STEP PRIORITY: Steps 3 (Critical Function Audit, especially Step 4 Math Library Audit) and 5 (Shared Object Dependencies) are where HIGH/CRITICAL severity findings most commonly hide. The Cetus hack originated from a custom math library bit shift bug. Do NOT rush these steps.
[dependencies]|git\s*=|subdir\s*=|rev\s*=|published-at|math|utils|library|helpers|commonParse Move.toml and build a complete dependency tree. Categorize:
| # | Dependency Name | Source Type | Source URL/Address | Version/Rev Pinned? | Trust Level | Upgrade Risk |
|---|---|---|---|---|---|---|
| 1 | Sui | Framework | sui framework | Validator-controlled | TRUSTED | Framework upgrade by validators |
| 2 | MoveStdlib | Framework | std library | Validator-controlled | TRUSTED | Framework upgrade by validators |
| 3 | {third_party} | Git source | {url} | YES (rev={hash}) / NO (branch) | MUST_AUDIT | {describe} |
| 4 | {on_chain_dep} | Published | {on-chain address} | YES (version pinned) / NO | MUST_AUDIT | {describe} |
| 5 | {protocol_own} | Local path | {path} | N/A (in scope) | IN_SCOPE | N/A |
Trust classification:
sui, std). Audited by Mysten Labs, upgraded by validator governance. Minimal audit needed (but check for version-specific quirks).For each third-party dependency, assess immutability and upgrade risk:
| Dependency | Pinned to Specific Rev? | Published On-Chain? | UpgradeCap Status | Upgrade Policy | Risk |
|---|---|---|---|---|---|
| {dep} | YES (rev: {hash}) / NO (branch: main) | YES/NO | Destroyed (immutable) / Held by {who} / UNKNOWN | {compatible/additive/dep_only/immutable} | {assess} |
Source dependencies (compiled together):
main) -> upstream pushes automatically affect next compilation. FINDING: unpinned dependency.rev field -> defaults to latest on default branch. Highest risk.Published on-chain dependencies (referenced via published-at):
compatible policy -> behavior CAN change.Known upgrade history: Has the dependency been upgraded before? How many versions exist? Frequent upgrades indicate active development but also active change risk.
Checklist:
latest or main branch referenceMap the full dependency tree:
| Dependency A | Depends On | Dep B Audited? | Dep B Upgrade Risk | Version Conflict? |
|---|---|---|---|---|
| {dep_A} | {dep_B, dep_C} | YES/NO | {describe} | YES/NO |
Transitive dependency risks:
If Dep B upgrades, does it affect us through Dep A?
Historical context: A major DeFi exploit targeted a bug in a custom bit shift helper function in a math library. This step is MANDATORY for any custom math/arithmetic library in the dependency tree.
For any custom math/arithmetic library dependency:
Trace ALL bit shift operations (<<, >>) in the math library:
| # | Function | Shift Operation | Shift Amount Source | Bounds Checked? | Overflow Possible? |
|---|---|---|---|---|---|
| 1 | {func} | value << amount | {parameter / constant / computed} | YES/NO | YES/NO |
Move bit shift rules:
<< and >> do NOT abort if shift amount >= bit width -- they produce 0Specific checks:
| # | Function | Operation | Input Range | Overflow Possible? | Handling |
|---|---|---|---|---|---|
| 1 | {func} | a * b | {describe} | YES if a,b > sqrt(MAX_U128) | abort (safe) / wrapping (DANGEROUS) |
Move arithmetic safety:
+, -, * abort on overflow/underflow -- safeas casts between integer types abort on overflow (e.g., (x as u64) where x > MAX_U64)(a * b) / SCALE -- intermediate a * b may overflow u128 even if final result fits in u64| # | Function | Rounding Direction | Consistent? | Impact if Wrong Direction |
|---|---|---|---|---|
| 1 | {mul_div} | {up / down / nearest / truncation} | YES/NO | {describe: e.g., attacker extracts extra dust per operation} |
Check: For every division operation in the math library:
If the protocol uses shared objects from external packages:
| External Shared Object | Package | Our Functions That Access It | What We Read/Write | Behavior Change If Package Upgrades? |
|---|---|---|---|---|
| {oracle_obj} | {oracle_pkg} | {our_module::read_price} | READ price field | YES -- oracle upgrade could change price format |
| {dex_pool} | {dex_pkg} | {our_module::swap} | WRITE (swap) | YES -- DEX upgrade could change swap logic |
Are we validating shared object state after external calls?
Key risk: External package with compatible upgrade policy can change function implementations. Our calls to those functions produce different results after upgrade, with no code change or compilation on our side.
Could new abort conditions be added in dependency upgrades?
| Dependency Function | Current Abort Conditions | Possible New Abort Conditions | Impact on Our Protocol |
|---|---|---|---|
| {dep::func} | {list current aborts} | {what upgrades could add} | {describe: e.g., our transaction aborts unexpectedly} |
Check:
sui::* and std::* are validator-controlled and well-audited. Findings about framework functions are rarely valid unless version-specific.## Finding [DEP-N]: Title
**Verdict**: CONFIRMED / PARTIAL / REFUTED / CONTESTED
**Step Execution**: check1,2,3,4,5,6 | skip(reason) | uncertain
**Rules Applied**: [R1:___, R4:___, R8:___, R10:___]
**Severity**: Critical/High/Medium/Low/Info
**Location**: Move.toml or sources/{module}.move:LineN (where dep function is called)
**Dependency**: {dependency_name}
**Function**: {specific function if applicable}
**Issue Type**: UNPINNED_VERSION / ARITHMETIC_UNSAFE / BIT_SHIFT_UNSAFE / EDGE_CASE_UNHANDLED / SPEC_MISMATCH / TRANSITIVE_RISK / UPGRADE_RISK / SHARED_OBJECT_DEP
**Description**: What is wrong
**Impact**: What can happen (incorrect calculation, overflow, unexpected abort, supply manipulation)
**Evidence**: Code showing the issue
**Recommendation**: How to fix (pin version, add validation, use alternative, wrap with checks)| Step | Required | Completed? | Notes |
|---|---|---|---|
| 1. Dependency Inventory | YES | All deps from Move.toml enumerated | |
| 2. Package Immutability Check | YES | Pinning and on-chain policy for each dep | |
| 3. Transitive Dependency Risk | YES | Full dependency tree mapped | |
| 4. Math Library Audit | IF math/arithmetic deps exist | HIGH PRIORITY -- Cetus precedent | |
| 4a. Bit Shift Operation Audit | IF bit shifts in math deps | Every shift bounds-checked | |
| 4b. Overflow/Underflow Audit | IF math deps | Checked vs unchecked arithmetic | |
| 4c. Rounding and Precision | IF division in math deps | Direction documented and consistent | |
| 5. Shared Object Dependencies | IF external shared objects used | Behavior change on upgrade | |
| 6. Interface Compatibility | IF upgradeable deps | New abort conditions, return value changes |
After Step 2: If any dependency unpinned -> immediate Informational/Low finding.
After Step 4: If math library has unchecked bit shifts -> cross-reference with BIT_SHIFT_SAFETY skill for protocol-level impact analysis.
After Step 5: If shared object dependencies from upgradeable packages -> cross-reference with PACKAGE_VERSION_SAFETY Step 3 and EXTERNAL_PRECONDITION_AUDIT Step 3b.
If any step skipped, document valid reason (N/A, no third-party deps, framework-only, no math functions used).
© PlamenTSV, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in agents/skills/sui/dependency-audit of PlamenTSV/plamen.
Open the folder on GitHubat commit 795962b
Dependency Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Dependency Audit this skillPlamenTSV/plamen | 303 | — | ~3.3k | Automated safety check: Pass | MIT | |
| Third Party Cookiesthedaviddias/Front-End-Checklist | 74k | — | ~580 | Automated safety check: Pass | MIT | |
| Third Party Scriptsthedaviddias/Front-End-Checklist | 74k | — | ~417 | Automated safety check: Pass | MIT | |
| Golang Patternsaffaan-m/ECC | 275k | — | ~1.1k | Automated safety check: Pass | MIT | |
| Managing Third Party Vendor Riskmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | |
| Audit Third Party Contractsben-manes/caffeine | 18k | — | ~943 | Automated safety check: Pass | Apache-2.0 |
thedaviddias/Front-End-Checklist
A skill your agent uses when reviewing a website for privacy compliance, third-party resource loading, or cookie consent implementation.
thedaviddias/Front-End-Checklist
A skill your agent uses when auditing slow page loads, heavy assets, or rendering delays related to Optimize third-party script loading.
affaan-m/ECC
Go-specific design patterns and best practices including functional options, small interfaces, dependency injection, concurrency patterns, error handling, and package organization.
mukul975/Anthropic-Cybersecurity-Skills
Build and run a third-party/vendor risk management (TPRM) program aligned to NIST SP 800-161 C-SCRM: inventory and tier vendors, issue SIG/CAIQ questionnaires, review SOC 2/ISO 27001 evidence, set…
ben-manes/caffeine
Verify every third-party and sharp-edged JDK API usage against the contract the upstream documentation actually states
affaan-m/ECC
Idiomatic C and .NET patterns, conventions, dependency injection, async/await, and best practices for building robust, maintainable .NET applications.
PlamenTSV/plamen
Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project…
PlamenTSV/plamen
Trigger Pattern Always (used by all verifier agents) - Inject Into security-verifier agents (Phase 5)
PlamenTSV/plamen
Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth agents, depth agents
PlamenTSV/plamen
Trigger Pattern Always (Sui Move) -- foundational security check - Inject Into Breadth agents, depth agents
PlamenTSV/plamen
Trigger Pattern ACCOUNTCLOSING flag detected (close/CloseAccount usage) - Inject Into Breadth agents, depth agents
PlamenTSV/plamen
Trigger Pattern Always required for Solana audits - Inject Into Breadth agents, depth agents
Trigger Pattern EXTERNALLIB flag (third-party Move dependencies detected in Move.toml beyond Sui framework) - Inject Into Breadth agents, depth-external. Dependency Audit is an agent skill from PlamenTSV/plamen.
Dependency Audit fits situations like: pattern EXTERNALLIB flag (third-party Move dependencies detected in Move.toml beyond Sui framework) - Inject Into Breadth agents.
Run `npx skills add PlamenTSV/plamen --skill dependency-audit -a claude-code`. Or copy the skill folder (agents/skills/sui/dependency-audit in PlamenTSV/plamen) into .claude/skills/dependency-audit in your project. Claude Code loads it when a task matches its description.
Run `npx skills add PlamenTSV/plamen --skill dependency-audit -a codex`. Or copy the skill folder (agents/skills/sui/dependency-audit in PlamenTSV/plamen) into .agents/skills/dependency-audit in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PlamenTSV/plamen --skill dependency-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dependency-audit, .gemini/skills/dependency-audit, .github/skills/dependency-audit and .opencode/skills/dependency-audit in your project.
SKILL.md names no scripts, command-line tools or credentials: Dependency Audit is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Dependency Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Dependency Audit: Third Party Cookies (thedaviddias/Front-End-Checklist, 74k stars), Third Party Scripts (thedaviddias/Front-End-Checklist, 74k stars), Golang Patterns (affaan-m/ECC, 275k stars) and Managing Third Party Vendor Risk (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
PlamenTSV (a GitHub user) maintains it in PlamenTSV/plamen, which has 303 GitHub stars. The repository holds 87 skills in this directory. The repository was last updated on September 26, 2026.
Source: PlamenTSV/plamen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.