Agent skill

External Precondition Audit

by PlamenTSV in PlamenTSV/plamen

Trigger Pattern Any external module interaction detected in attacksurface.md - Inject Into Breadth agents (merged via M5 hierarchy)

MITAuto-check passedSecurity

Install External Precondition Audit

skills CLI
$ npx skills add PlamenTSV/plamen --skill external-precondition-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install PlamenTSV/plamen external-precondition-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agents/skills/aptos/external-precondition-audit .claude/skills/external-precondition-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
external-precondition-audit
GitHub stars
303
Token cost
~1.1k tokens
SKILL.md length
412 words
Files
1
Skills in repo
87
Repo updated
First seen
Licence
MIT

At a glance

Trigger Pattern Any external module interaction detected in attacksurface.md - Inject Into Breadth agents (merged via M5 hierarchy)

  • Works in 3 steps: Interface-Level Requirement Inference → Return Value Consumption → State Dependency Mapping
  • Pattern Any external module interaction detected in attacksurface.md - Inject Into Breadth agents (merged via M5 hierarchy)
  • SKILL.md covers 1. Interface-Level Requirement…, 2. Return Value Consumption, 3. State Dependency Mapping and Instantiation Parameters, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

External Precondition Audit is an agent skill from PlamenTSV/plamen. Trigger Pattern Any external module interaction detected in attacksurface.md - Inject Into Breadth agents (merged via M5 hierarchy)

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Threat modeling. The repository describes itself as: Autonomous Web3 security audit agent for Claude Code. The licence is MIT.

When your agent uses it

  • Pattern Any external module interaction detected in attacksurface.md - Inject Into Breadth agents (merged via M5 hierarchy)
  • Tasks that involve Threat modeling

Example prompts

  • “/external-precondition-audit”

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Interface-Level Requirement Inference
  2. Return Value Consumption
  3. State Dependency Mapping

What it can do on your machine

Read from SKILL.md and the folder at commit 795962b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

External Precondition Audit loads about 1.1k tokens when it runs. Until then it costs about 40 tokens; SKILL.md has 412 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~40
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from PlamenTSV/plamen at commit 795962b, republished under its MIT licence (© PlamenTSV). 412 words, ~1,149 tokens.

Download SKILL.mdSave it as .claude/skills/external-precondition-audit/SKILL.md (or your agent's skills folder).
name
external-precondition-audit
description
Trigger Pattern Any external module interaction detected in attack_surface.md - Inject Into Breadth agents (merged via M5 hierarchy)

EXTERNAL_PRECONDITION_AUDIT Skill

Trigger Pattern: Any external module interaction detected in attack_surface.md Inject Into: Breadth agents (merged via M5 hierarchy) Constraint: Interface-level inference only -- no production fetch required

For every external module the protocol interacts with:

1. Interface-Level Requirement Inference

From the use imports and function calls to external modules, infer what the external module requires:

External Function CalledModule::FunctionParameters PassedLikely Preconditions (from signature + abort codes)Our Protocol Validates?

Inference method: Read the function signature, type parameters, ability constraints, and abort conditions. Example: coin::withdraw<CoinType>(account: &signer, amount: u64) -> infer that account must have sufficient balance, CoinType must be initialized, amount must be > 0. Check abort codes in framework source if available.

Aptos-specific patterns:

  • &signer parameters: does external module require the signer to own a specific resource?
  • Generic type parameters <T>: does external module require T to be registered/initialized?
  • Object<T> parameters: does external module validate object ownership or type?
  • Abort conditions: enumerate all assert! / abort in external function that could revert our call

2. Return Value Consumption

External CallReturn TypeHow Protocol Uses ReturnFailure Mode if Return Unexpected

For each return value:

  • What happens if it returns 0? What happens if it returns MAX_U64?
  • What happens if the external call aborts?
  • For Option<T> returns: does our protocol handle none correctly?
  • For FungibleAsset returns: is metadata validated after receiving?
  • For Object<T> returns: is the object type verified before use?
  • For each external data structure received (Vec, array, Map, list): (a) What ordering/uniqueness does the consuming code assume? (b) Does the external contract's spec guarantee that ordering? (c) What happens if the assumption is violated (unsorted, duplicates, gaps)?
Show full SKILL.md (145 more words)Show less

3. State Dependency Mapping

Protocol StateDepends on External StateExternal Module Upgradeable?State Can Change Without Our Knowledge?

For each dependency:

  • Upgrade risk: Aptos modules are upgradeable by default (compatible policy). Can the external module add new abort conditions to a function we call? Can it change return value semantics within compatible upgrade bounds?
  • Immutability check: Is the external module published as immutable? If so, behavior is frozen.
  • State mutation timing: Can external module state change between our module's read and use within the same transaction? (e.g., another instruction in a multi-instruction transaction modifies external state)
  • Framework dependency: If depending on aptos_framework modules, are there governance-controlled parameters that could change? (e.g., transaction_fee, staking_config)

Instantiation Parameters

{CONTRACTS}           -- List of modules to analyze
{EXTERNAL_MODULES}    -- External modules identified during recon
{FRAMEWORK_DEPS}      -- aptos_framework / aptos_std / aptos_token dependencies

Output Schema

For each finding:

markdown
## Finding [EP-N]: Title

**Verdict**: CONFIRMED / PARTIAL / REFUTED / CONTESTED
**Step Execution**: S1,S2,S3 | X(reasons) | ?(uncertain)
**Rules Applied**: [R1:Y, R4:Y, R8:Y]
**Severity**: Critical/High/Medium/Low/Info
**Location**: module::function (source_file.move:LineN)

**External Dependency**: {module::function}
**Failure Mode**: {what breaks}

**Description**: What's wrong
**Impact**: What can happen (abort DoS, wrong state, fund loss)
**Evidence**: Code showing dependency and missing validation

Step Execution Checklist

SectionRequiredCompleted?
1. Interface-Level Requirement InferenceYESY/N/?
2. Return Value ConsumptionYESY/N/?
3. State Dependency MappingYESY/N/?

© PlamenTSV, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in agents/skills/aptos/external-precondition-audit of PlamenTSV/plamen.

Open the folder on GitHubat commit 795962b

Compare with similar skills

External Precondition Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

External Precondition Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
External Precondition Audit this skillPlamenTSV/plamen303—~1.1kAutomated safety check: PassMIT
Fla Ascend Performancefla-org/flash-linear-attention5.8k—~6.3kAutomated safety check: PassMIT
Forensifyalexgreensh/repo-forensics188—~2.5kAutomated safety check: NotesCustom licence
Create Rulecartography-cncf/cartography4.1k—~3kAutomated safety check: PassApache-2.0
Commit Security Scancodexstar69/bug-hunter519—~629Automated safety check: PassMIT
Auditing Code For Vulnerabilitiestrilwu/secskills156—~3.2kAutomated safety check: PassMIT

Similar skills

  • Fla Ascend Performance

    fla-org/flash-linear-attention

    Guidelines for Ascend NPU kernel / Triton-Ascend backend performance work in the FLA repo.

    5.8k GitHub stars~6.3k tokensUpdated today
    SecurityAuto-check passed
  • Forensify

    alexgreensh/repo-forensics

    Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.

    188 GitHub stars~2.5k tokensUpdated 11 days ago
    SecurityAuto-check: notes
  • Create Rule

    cartography-cncf/cartography

    Author a Cartography security rule (one or more Cypher Facts plus a Pydantic Finding output model) under cartography/rules/data/rules/.

    4.1k GitHub stars~3k tokensUpdated today
    SecurityAuto-check passed
  • Commit Security Scan

    codexstar69/bug-hunter

    Scan code changes for security vulnerabilities using Bug Hunter-native artifacts and STRIDE context.

    519 GitHub stars~629 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.

    156 GitHub stars~3.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Match identified threats to preventive, detective and corrective controls across network, application, data, endpoint and process layers to plan remediation.

    40k GitHub starsUsed in 8 repos~742 tokens
    SecurityAuto-check passed

More from PlamenTSV/plamen

All 87 skills in this repo
  • Audit Prep

    PlamenTSV/plamen

    Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project…

    303 GitHub stars~3.7k tokensUpdated 12 days ago
    Auto-check passed
  • Verification Protocol

    PlamenTSV/plamen

    Trigger Pattern Always (used by all verifier agents) - Inject Into security-verifier agents (Phase 5)

    303 GitHub stars~3.5k tokensUpdated 12 days ago
    Auto-check passed
  • Ability Analysis

    PlamenTSV/plamen

    Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth agents, depth agents

    303 GitHub stars~3.3k tokensUpdated 12 days ago
    Auto-check passed
  • Ability Analysis

    PlamenTSV/plamen

    Trigger Pattern Always (Sui Move) -- foundational security check - Inject Into Breadth agents, depth agents

    303 GitHub stars~3.2k tokensUpdated 12 days ago
    Auto-check passed
  • Account Lifecycle

    PlamenTSV/plamen

    Trigger Pattern ACCOUNTCLOSING flag detected (close/CloseAccount usage) - Inject Into Breadth agents, depth agents

    303 GitHub stars~1.2k tokensUpdated 12 days ago
    Auto-check passed
  • Account Validation

    PlamenTSV/plamen

    Trigger Pattern Always required for Solana audits - Inject Into Breadth agents, depth agents

    303 GitHub stars~1.7k tokensUpdated 12 days ago
    Auto-check passed

Categories

Questions about External Precondition Audit

What does External Precondition Audit do?

Trigger Pattern Any external module interaction detected in attacksurface.md - Inject Into Breadth agents (merged via M5 hierarchy). External Precondition Audit is an agent skill from PlamenTSV/plamen.

When should I use External Precondition Audit?

External Precondition Audit fits situations like: pattern Any external module interaction detected in attacksurface.md - Inject Into Breadth agents (merged via M5 hierarchy); tasks that involve Threat modeling.

How do I install External Precondition Audit in Claude Code?

Run `npx skills add PlamenTSV/plamen --skill external-precondition-audit -a claude-code`. Or copy the skill folder (agents/skills/aptos/external-precondition-audit in PlamenTSV/plamen) into .claude/skills/external-precondition-audit in your project. Claude Code loads it when a task matches its description.

How do I install External Precondition Audit in Codex?

Run `npx skills add PlamenTSV/plamen --skill external-precondition-audit -a codex`. Or copy the skill folder (agents/skills/aptos/external-precondition-audit in PlamenTSV/plamen) into .agents/skills/external-precondition-audit in your project. Codex loads it when a task matches its description.

Can I use External Precondition Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PlamenTSV/plamen --skill external-precondition-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/external-precondition-audit, .gemini/skills/external-precondition-audit, .github/skills/external-precondition-audit and .opencode/skills/external-precondition-audit in your project.

What does External Precondition Audit need to run?

SKILL.md names no scripts, command-line tools or credentials: External Precondition Audit is instructions for the agent only.

Does External Precondition Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is External Precondition Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does External Precondition Audit use?

External Precondition Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does External Precondition Audit use?

About 1.1k tokens (SKILL.md is roughly 4.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to External Precondition Audit?

Skills that share tags, products or a category with External Precondition Audit: Fla Ascend Performance (fla-org/flash-linear-attention, 5.8k stars), Forensify (alexgreensh/repo-forensics, 188 stars), Create Rule (cartography-cncf/cartography, 4.1k stars) and Commit Security Scan (codexstar69/bug-hunter, 519 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains External Precondition Audit?

PlamenTSV (a GitHub user) maintains it in PlamenTSV/plamen, which has 303 GitHub stars. The repository holds 87 skills in this directory. The repository was last updated on September 26, 2026.

Source: PlamenTSV/plamen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.