Dtvm Perf Profile
DTVMStack/DTVM
Profile DTVM execution using Linux perf and generate categorized analysis reports.
L1 trigger - audits execution engine (EVM interpreter, WASM, SVM) for memory corruption, gas mispricing (EXTCODESIZE class), opcode semantics, and VM invariant breaks.
$ npx skills add PlamenTSV/plamen --skill execution-client-hardening -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install PlamenTSV/plamen execution-client-hardening --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agents/skills/injectable/l1/execution-client-hardening .claude/skills/execution-client-hardening && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "execution-client-hardening" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/injectable/l1/execution-client-hardening into .claude/skills/execution-client-hardening/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "execution-client-hardening", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/PlamenTSV/plamen/tree/main/agents/skills/injectable/l1/execution-client-hardeningType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add PlamenTSV/plamen --skill execution-client-hardening -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install PlamenTSV/plamen execution-client-hardening --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .agents/skills && cp -r skills-src/agents/skills/injectable/l1/execution-client-hardening .agents/skills/execution-client-hardening && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "execution-client-hardening" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/injectable/l1/execution-client-hardening into .agents/skills/execution-client-hardening/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "execution-client-hardening", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add PlamenTSV/plamen --skill execution-client-hardening -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install PlamenTSV/plamen execution-client-hardening --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/agents/skills/injectable/l1/execution-client-hardening .cursor/skills/execution-client-hardening && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "execution-client-hardening" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/injectable/l1/execution-client-hardening into .cursor/skills/execution-client-hardening/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "execution-client-hardening", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/PlamenTSV/plamen.git --path agents/skills/injectable/l1/execution-client-hardening--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add PlamenTSV/plamen --skill execution-client-hardening -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install PlamenTSV/plamen execution-client-hardening --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/agents/skills/injectable/l1/execution-client-hardening .gemini/skills/execution-client-hardening && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "execution-client-hardening" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/injectable/l1/execution-client-hardening into .gemini/skills/execution-client-hardening/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "execution-client-hardening", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install PlamenTSV/plamen execution-client-hardeningInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add PlamenTSV/plamen --skill execution-client-hardening -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .github/skills && cp -r skills-src/agents/skills/injectable/l1/execution-client-hardening .github/skills/execution-client-hardening && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "execution-client-hardening" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/injectable/l1/execution-client-hardening into .github/skills/execution-client-hardening/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "execution-client-hardening", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add PlamenTSV/plamen --skill execution-client-hardening -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install PlamenTSV/plamen execution-client-hardening --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/agents/skills/injectable/l1/execution-client-hardening .opencode/skills/execution-client-hardening && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "execution-client-hardening" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/injectable/l1/execution-client-hardening into .opencode/skills/execution-client-hardening/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "execution-client-hardening", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
execution-client-hardeningL1 trigger - audits execution engine (EVM interpreter, WASM, SVM) for memory corruption, gas mispricing (EXTCODESIZE class), opcode semantics, and VM invariant breaks.
Execution Client Hardening is an agent skill from PlamenTSV/plamen. L1 trigger - audits execution engine (EVM interpreter, WASM, SVM) for memory corruption, gas mispricing (EXTCODESIZE class), opcode semantics, and VM invariant breaks.
Its SKILL.md is about 3.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Backend & APIs, covering Smart contracts. It works with WebAssembly. The repository describes itself as: Autonomous Web3 security audit agent for Claude Code. The licence is MIT.
11 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 795962b. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
eips.ethereum.orgblog.ethereum.orgethos.devusenix.orgthecyberexpress.commedium.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Execution Client Hardening loads about 3.9k tokens when it runs. Until then it costs about 49 tokens; SKILL.md has 1,893 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from PlamenTSV/plamen at commit 795962b, republished under its MIT licence (© PlamenTSV). 1,893 words, ~3,933 tokens.
.claude/skills/execution-client-hardening/SKILL.md (or your agent's skills folder).L1 trigger:
L1_PATTERN=trueAND (core/vm/ORrevmORinterpreterORopcodes.goORevm-execORsvm/ORmove-vmORwasmidetected in recon subsystem map) Inject Into:depth-state-traceordepth-externalLanguage: Go, Rust, occasionally C++ Finding prefix:[EX-N]Status: v0.1 draft, Round 4 exemplars pending
Recon identifies a VM / execution engine. Covered VMs: EVM (all execution clients), SVM (Solana), Move VM (Aptos, Sui), WASM runtimes (NEAR, Polkadot), custom VMs. Client-vs-client divergence in VM behavior is Critical — historically several Ethereum consensus splits were VM implementation bugs.
Enumerate every opcode / instruction the VM supports. For EVM, consult the latest Yellow Paper + EIPs. For others, the spec document.
| Opcode | Gas cost | Stack delta | State touched | Notes |
|---|
This mapping grounds later checks. A new client must implement every opcode; a fork client must not accidentally remove or reprice any opcode.
Tag: [OPCODE-COVERAGE:{missing-or-extra}]
Every operation must be priced to cover its real cost. Historical bugs: Ethereum Shanghai attacks (2016) — EXTCODESIZE was too cheap relative to disk I/O.
Tag: [GAS-MISPRICE:{opcode}:{actual-cost}:{charged-cost}]
For each opcode, the semantics must match the spec exactly. Common drift points:
Tag: [OPCODE-SEM:{opcode}:{drift}]
Precompiles are native implementations of common functions at fixed addresses.
Tag: [PRECOMPILE:{address}:{issue}]
For Go clients, memory safety is largely on the runtime. For Rust clients (reth, revm), unsafe blocks in the VM are a bug source.
Check:
unsafe in the interpreter hot pathInteraction with rust-unsafe-audit skill.
Trigger: The code assigns a compact numeric index or handle to a named entity (a type, account, resource, module, or similar) — typically to avoid storing the full name/key repeatedly — and one or more OTHER structures cache data derived from that entity, keyed by the compact index rather than by the entity's original identity. Common in interning tables, symbol/type caches, and any "intern this name once, refer to it by a small integer afterward" optimization (for example, a Move VM-style loader that interns module/type identities into a numeric table).
Why this is structurally distinct from §8's cache lifecycle set-cover: §8 concerns a SINGLE bounded cache whose OWN entries go stale or grow unbounded. This section concerns MULTIPLE structures that share one index/ handle space, where one structure can be reset/compacted while a SIBLING structure — keyed by the same index space — is not, so a recycled index silently points a stale consumer at a different entity's data. This is an asymmetric-invalidation bug across coupled structures, not a single eviction policy gap, and set-cover on one structure's legs will not catch it.
Methodology:
TypeIndex, ModuleHandle, or similar newtype) across the codebase and
list every map/vector/cache that uses it as a key, not just the one that
assigns it.Required check: for the primary index/handle-assigning structure and every sibling structure found in step 1, confirm they are reset by the SAME function/transaction boundary, not by independently-triggered paths. Two reset paths that are supposed to stay in lockstep but are invoked from different call sites are a red flag even if both eventually run.
Tag: [IDENTITY-COHERENCE:{index-space}:{structures-affected}]
Severity baseline: High to Critical when the recycled index can be attacker- influenced (attacker controls timing/ordering of the partial reset and the next allocation) and the derived identity affects storage/permission resolution; Medium when reachable only through operator/admin-triggered resets.
If the target is a fork of an upstream execution client:
git diff upstream/main...HEAD -- core/vm/ (or equivalent)py_ecc or execution-spec-tests)Tag: [VM-DRIFT:{opcode-or-precompile}]
| State | Test | Expected | Observed |
|---|---|---|---|
| Empty code | contract with 0 bytes | spec-defined | |
| Max code size | 24576 bytes (EIP-170) | accepted | |
| Code size + 1 | 24577 bytes | rejected on CREATE | |
| Gas = 0 | call with 0 gas | out-of-gas | |
| Stack overflow | 1025 items on stack | revert, not panic | |
| Stack underflow | POP on empty stack | revert, not panic | |
| Memory OOB | MLOAD from MAX_U256 | out-of-gas (memory expansion cost) | |
| SELFDESTRUCT after state change | tx does CREATE then SELFDESTRUCT | correct accounting (post-EIP-6780) |
[CONFORMANCE-PASS] (execution-spec-tests / Hive) > [DIFF-PASS] (Fluffy-style differential) > [LSP-TRACE]2016 Shanghai EXTCODESIZE DoS (block 2283416) — EXTCODESIZE cost ~20 gas but required a disk read of contract code. Attacker invoked it ~50k times per block, forcing 50k disk reads and 20-60s block validation times. Parity unaffected, Geth crawled to a halt. Fix codified as EIP-2929 years later. EF blog; ethos.dev Shanghai attacks. Skill catch point: Section 2 — the gas-per-disk-read ratio is the core invariant. Any opcode where (disk_reads × disk_latency) >> (gas_cost × gas_rate) is a gas-mispricing finding.
Geth RETURNDATACOPY corruption (CVE-2020-26241, Fluffy OSDI '21) — precompile dataCopy did shallow copy of input; subsequent memory write aliased RETURNDATA, causing divergence from other clients. Found via multi-tx differential fuzzing. Fluffy paper. Skill catch point: Section 4 (precompiles) — every opcode that writes to RETURNDATA must fully copy, not alias.
Geth transfer-after-destruct (CVE-2020-26265, Fluffy OSDI '21) — transfer semantics to already-destructed contract diverged between Geth and OpenEthereum. Caused mainnet hard fork event 4 months after disclosure. Skill catch point: Section 3a (SELFDESTRUCT semantics) — model contract lifecycle transitions (create → live → destruct → resurrect) and verify each produces identical output across clients.
Aptos MoveVM integer overflow DoS (October 2022) — MoveVM arithmetic lacked overflow guard; crafted input triggered DoS / chain halt potential. Patched. CyberExpress report. Skill catch point: Section 5 (memory safety / arithmetic) — every VM arithmetic op must use checked_* or explicit modular arithmetic. Every as cast between integer widths is a narrowing-overflow candidate.
Moonbeam precompile CALL/DELEGATECALL confusion ($1M + $50k bounty, pwning.eth, 2022) — Moonbeam's custom precompiles (XC-20, staking, democracy) did not distinguish CALL from DELEGATECALL. A malicious contract could DELEGATECALL the precompile and impersonate msg.sender of the original caller, accessing precompile storage of any user. Immunefi bugfix review. Skill catch point: Section 4 — for every custom precompile, assert context.call_type() != DELEGATECALL at entry. See also cross-environment-semantic-drift.
Insert as new Section 2f: The Shanghai lesson has been re-learned multiple times. The core invariant:
For every opcode O:
worst_case_wall_clock(O) <= gas_cost(O) / target_gas_rateWhere target_gas_rate is the protocol's gas-per-second target (Ethereum: ~10M gas / 12s = 833k gas/s).
Check: for every opcode that touches disk, network, or complex computation, compute worst_case_wall_clock / gas_cost. Any ratio suggesting the opcode can be invoked enough times per block to violate the gas-rate budget is a finding.
Tag: [GAS-RATIO:{opcode}:{worst-ns}:{gas-cost}:{violates?}]
A parameter declared in struct Config / Params / ChainSpec that is never read is often a missing enforcement — the developer intended the parameter to cap something but forgot to wire it in. This class hides real resource-bound vulnerabilities.
Methodology:
Config / Params / ConsensusParams / ChainConfig struct.{SCRATCHPAD}/scip/xref_map.md or Grep on .{field_name}. (MCP tools are unavailable in subagent contexts per Claude Code bug #25200.)max_*, min_*, limit_*, cap_*, ceiling_*, floor_*, bound_* — these are almost always intended as enforcement.Required artifact: {SCRATCHPAD}/config_parameter_usage.md:
| Field | Declared at | Read sites (count) | Enforced? | Notes |
|---|---|---|---|---|
| max_validators | ChainConfig:L42 | 3 | YES | EndBlocker.apply_updates |
| max_difficulty_adjustment_factor | ChainConfig:L51 | 0 | **NO** | **UNUSED — difficulty spike unbounded** |
| min_commit_depth | ChainConfig:L63 | 1 (test only) | **NO** | read only in test_harness.rs |
| max_commitment_txs_per_block | ChainConfig:L89 | 0 | **NO** | **UNUSED — commitment flood possible** |Every "NO" row is a finding. Severity depends on what the parameter was supposed to bound — parameters that would have capped a resource are Medium to High.
False positives: parameters read only by genesis (legitimately one-time), parameters read transitively through a cloned config struct (grep misses it — verify with SCIP), parameters reserved for future versions (should be commented // reserved, otherwise flag).
Tag: [CONFIG-UNUSED:{field_name}], [CONFIG-TEST-ONLY:{field_name}]
switch op in Go, match opcode in Rust)SELFDESTRUCT, CREATE2, MCOPY individuallycross-environment-semantic-drift (L1/L2 semantic differences), consensus-safety-invariants (cross-client divergence is a consensus bug), rust-unsafe-audit (for Rust VMs)depth-state-trace, depth-external, depth-consensus-invariantdocs/l1-mode/severity-matrix.md© PlamenTSV, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in agents/skills/injectable/l1/execution-client-hardening of PlamenTSV/plamen.
Open the folder on GitHubat commit 795962b
Execution Client Hardening next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Execution Client Hardening this skillPlamenTSV/plamen | 303 | — | ~3.9k | Automated safety check: Pass | MIT | |
| Dtvm Perf ProfileDTVMStack/DTVM | 157 | — | ~1.1k | Automated safety check: Pass | Custom licence | |
| Dmir Compiler AnalysisDTVMStack/DTVM | 157 | — | ~2.8k | Automated safety check: Pass | Custom licence | |
| Smart Contract Upgrade Governancesickn33/agentic-awesome-skills | 47k | 1 repos | ~1.4k | Automated safety check: Pass | MIT | |
| RuView CLI, API and WASMruvnet/RuView | 97k | — | ~1.2k | Automated safety check: Notes | MIT | |
| Fizz Convertpashov/skills | 1.2k | 2 repos | ~3.7k | Automated safety check: Pass | MIT |
DTVMStack/DTVM
Profile DTVM execution using Linux perf and generate categorized analysis reports.
DTVMStack/DTVM
Analyze DTVM's dMIR intermediate representation and compilation pipeline.
sickn33/agentic-awesome-skills
Soroban WASM upgrade governance register: executable bytecode hash, timelocked migration delays, and multi-sig authorization quorum.
ruvnet/RuView
Covers the RuView `wifi-densepose` command line binary, its Axum REST API and the WebAssembly builds for browsers and ESP32, for embedding or scripting RuView.
pashov/skills
Convert English-language properties in PROPERTIES.md (produced by the Fizz skill) into Solidity assertions inside the existing fuzz harness, then flip their checkboxes.
aoyunyang/spider-king-skill
Pure-web protocol reverse skill: turn hostile browser clients into browser-free Python collectors.
PlamenTSV/plamen
Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project…
PlamenTSV/plamen
Trigger Pattern Always (used by all verifier agents) - Inject Into security-verifier agents (Phase 5)
PlamenTSV/plamen
Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth agents, depth agents
PlamenTSV/plamen
Trigger Pattern Always (Sui Move) -- foundational security check - Inject Into Breadth agents, depth agents
PlamenTSV/plamen
Trigger Pattern ACCOUNTCLOSING flag detected (close/CloseAccount usage) - Inject Into Breadth agents, depth agents
PlamenTSV/plamen
Trigger Pattern Always required for Solana audits - Inject Into Breadth agents, depth agents
Works with
Categories
L1 trigger - audits execution engine (EVM interpreter, WASM, SVM) for memory corruption, gas mispricing (EXTCODESIZE class), opcode semantics, and VM invariant breaks. Execution Client Hardening is an agent skill from PlamenTSV/plamen. L1 trigger - audits execution engine (EVM interpreter, WASM, SVM) for memory corruption, gas mispricing (EXTCODESIZE class), opcode semantics, and VM invariant breaks.
Execution Client Hardening fits situations like: - audits execution engine (EVM interpreter; SVM) for memory corruption; gas mispricing (EXTCODESIZE class); opcode semantics.
Run `npx skills add PlamenTSV/plamen --skill execution-client-hardening -a claude-code`. Or copy the skill folder (agents/skills/injectable/l1/execution-client-hardening in PlamenTSV/plamen) into .claude/skills/execution-client-hardening in your project. Claude Code loads it when a task matches its description.
Run `npx skills add PlamenTSV/plamen --skill execution-client-hardening -a codex`. Or copy the skill folder (agents/skills/injectable/l1/execution-client-hardening in PlamenTSV/plamen) into .agents/skills/execution-client-hardening in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PlamenTSV/plamen --skill execution-client-hardening -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/execution-client-hardening, .gemini/skills/execution-client-hardening, .github/skills/execution-client-hardening and .opencode/skills/execution-client-hardening in your project.
Going by SKILL.md and its folder, Execution Client Hardening needs the command-line tools its instructions call (git).
SKILL.md names 6 domains. As links in the text: eips.ethereum.org, blog.ethereum.org, ethos.dev, usenix.org, thecyberexpress.com and medium.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Execution Client Hardening is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.9k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Execution Client Hardening: Dtvm Perf Profile (DTVMStack/DTVM, 157 stars), Dmir Compiler Analysis (DTVMStack/DTVM, 157 stars), Smart Contract Upgrade Governance (sickn33/agentic-awesome-skills, 47k stars) and RuView CLI, API and WASM (ruvnet/RuView, 97k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
PlamenTSV (a GitHub user) maintains it in PlamenTSV/plamen, which has 303 GitHub stars. The repository holds 87 skills in this directory. The repository was last updated on September 26, 2026.
Source: PlamenTSV/plamen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.