Agent skill

Flash Loan Interaction

by PlamenTSV in PlamenTSV/plamen

Trigger Pattern FLASHLOAN flag (required) or BALANCEDEPENDENT flag (optional complement) - Inject Into Breadth agents, depth-token-flow, depth-edge-case

MITAuto-check passedBackend & APIs

Install Flash Loan Interaction

skills CLI
$ npx skills add PlamenTSV/plamen --skill flash-loan-interaction -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install PlamenTSV/plamen flash-loan-interaction --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agents/skills/evm/flash-loan-interaction .claude/skills/flash-loan-interaction && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
flash-loan-interaction
GitHub stars
303
Token cost
~2.9k tokens
SKILL.md length
1,135 words
Files
1
Skills in repo
87
Repo updated
First seen
Licence
MIT

At a glance

Trigger Pattern FLASHLOAN flag (required) or BALANCEDEPENDENT flag (optional complement) - Inject Into Breadth agents, depth-token-flow, depth-edge-case

  • Works in 6 steps: External Flash Susceptibility Check → Flash-Loan-Accessible State Inventory → Atomic Attack Sequence Modeling → …
  • Pattern FLASHLOAN flag (required)
  • SKILL.md covers 0. External Flash…, 1. Flash-Loan-Accessible State…, 2. Atomic Attack Sequence… and 3. Cross-Function Flash Loan…, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Flash Loan Interaction is an agent skill from PlamenTSV/plamen. Trigger Pattern FLASHLOAN flag (required) or BALANCEDEPENDENT flag (optional complement) - Inject Into Breadth agents, depth-token-flow, depth-edge-case

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Smart contracts. The repository describes itself as: Autonomous Web3 security audit agent for Claude Code. The licence is MIT.

When your agent uses it

  • Pattern FLASHLOAN flag (required)
  • BALANCEDEPENDENT flag (optional complement) - Inject Into Breadth agents
  • Depth-token-flow
  • Depth-edge-case

Example prompts

  • “/flash-loan-interaction”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. External Flash Susceptibility Check
  2. Flash-Loan-Accessible State Inventory
  3. Atomic Attack Sequence Modeling
  4. Cross-Function Flash Loan Chains
  5. Flash Loan + Donation Compound Attacks
  6. Flash Loan Defense Audit

What it can do on your machine

Read from SKILL.md and the folder at commit 795962b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Flash Loan Interaction loads about 2.9k tokens when it runs. Until then it costs about 44 tokens; SKILL.md has 1,135 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~44
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from PlamenTSV/plamen at commit 795962b, republished under its MIT licence (© PlamenTSV). 1,135 words, ~2,878 tokens.

Download SKILL.mdSave it as .claude/skills/flash-loan-interaction/SKILL.md (or your agent's skills folder).
name
flash-loan-interaction
description
Trigger Pattern FLASH_LOAN flag (required) or BALANCE_DEPENDENT flag (optional complement) - Inject Into Breadth agents, depth-token-flow, depth-edge-case

FLASH_LOAN_INTERACTION Skill

Trigger Pattern: FLASH_LOAN flag (required) or BALANCE_DEPENDENT flag (optional complement) Inject Into: Breadth agents, depth-token-flow, depth-edge-case

For every flash-loan-accessible state variable or precondition in the protocol:

⚠ STEP PRIORITY: Steps 5 (Defense Audit) and 5b (Defense Parity) are where HIGH/CRITICAL severity findings most commonly hide. Do NOT rush these steps. If constrained, skip conditional sections (0c, 4) before skipping 5, 5b, or 3d.

0. External Flash Susceptibility Check

Before analyzing the protocol's OWN flash loan paths, check whether external protocols the contract interacts with are susceptible to third-party flash manipulation.

0a: External Interaction Inventory
External ProtocolInteraction TypeState Read by Our ProtocolCan 3rd Party Flash-Manipulate That State?
{DEX/pool/vault}{swap/deposit/query}{reserves, price, balance}{YES if spot state / NO if TWAP or time-weighted}
0b: Third-Party Flash Attack Modeling

For each external state marked YES in 0a, model:

  1. Before: Protocol reads external state X (e.g., pool reserves, spot price)
  2. Flash manipulate: Attacker flash-borrows and trades on the external protocol to move state X
  3. Victim call: Attacker calls OUR protocol function that reads manipulated state X
  4. Restore: Attacker reverses the external manipulation
  5. Impact: What did the attacker gain from our protocol acting on manipulated state?

Key question: Does our protocol use spot state (manipulable) or time-weighted state (resistant)?

<!-- LOAD_IF: DEX_INTERACTION -->
0c: DEX Price Manipulation Cost Estimation

For each external DEX/pool whose spot state is read by the protocol, estimate manipulation cost:

PoolLiquidity (USD)Target Price ChangeEst. Trade SizeSlippage CostProtocol Extractable ValueProfitable?
{pool}{TVL}{%}{USD}{USD}{USD}{YES/NO}

Cost formula: manipulation_cost = slippage * trade_size where trade_size = (target_price_change / price_impact_per_unit) * pool_liquidity. If manipulation_cost < extractable_value → VIABLE.

For Uniswap V2-style: price_impact = trade_size / (reserve + trade_size). For V3 concentrated liquidity: impact depends on tick range - use actual liquidity in the affected range, not total TVL.

<!-- END_LOAD_IF: DEX_INTERACTION -->

1. Flash-Loan-Accessible State Inventory

Enumerate ALL protocol state that can be manipulated within a single transaction via flash-borrowed capital:

State Variable / QueryLocationRead ByWrite PathFlash-Accessible?Manipulation Cost
balanceOf(address(this)){contract}{functions}Direct transferYES0 (donation)
totalSupply{contract}{functions}mint/burnYES if permissionlessDeposit amount
getReserves(){pool}{functions}SwapYESSlippage cost
Oracle spot price{oracle}{functions}Trade on sourceYESMarket depth
Threshold/quorum state{contract}{functions}Deposit/stakeYESThreshold amount

For each YES entry: trace all functions that READ this state and make decisions based on it.

Rule 15 check: For each balance/oracle/threshold/rate precondition, model the flash loan atomic sequence.

2. Atomic Attack Sequence Modeling

For each flash-loan-accessible state identified in Step 1:

Attack Template
1. BORROW: Flash-borrow {amount} of {token} from {source}
2. MANIPULATE: {action} to change {state_variable} from {value_before} to {value_after}
3. CALL: Invoke {target_function} which reads manipulated state
4. EXTRACT: {what_is_gained} - quantify: {amount}
5. RESTORE: {action} to return state (if needed for repayment)
6. REPAY: Return {amount + fee} to flash loan source
7. PROFIT: {extract - fee - gas} = {net_profit}

Profitability gate: If net_profit ≤ 0 for all realistic amounts → document as NON-PROFITABLE but check Step 3 for multi-call chains.

For each sequence, verify:

  • Can steps 2-5 execute atomically (same transaction)?
  • Does any step revert under normal conditions?
  • Is the manipulation detectable/preventable by the protocol?
  • What is the minimum flash loan amount needed?

3. Cross-Function Flash Loan Chains

Model multi-call atomic sequences within a single flash loan:

StepFunction CalledState BeforeState AfterEnables Next Step?
1{function_A}{state}{state'}YES - changes {X}
2{function_B}{state'}{state''}YES - enables {Y}
N{function_N}{state^N}{final}EXTRACT profit

Key question: Can calling function A then function B in the same transaction produce a state that neither function alone could create?

Common multi-call patterns:

  • Deposit → manipulate rate → withdraw (sandwich own deposit)
  • Stake → trigger reward calculation → unstake (flash-stake rewards)
  • Borrow → manipulate collateral price → liquidate others → repay
  • Deposit to inflate shares → withdraw deflated shares
3b. Flash-Loan-Enabled Debounce DoS

For each permissionless function with a cooldown/debounce that affects OTHER users (global cooldown, shared timestamp): Can attacker flash-borrow → call debounced function → trigger cooldown, blocking legitimate callers?

FunctionCooldown ScopeShared Across Users?Flash-Triggerable?DoS Duration

If cooldown is global/shared AND function is permissionless AND flash-triggerable → FINDING (R2, minimum Medium).

3c. No-Op Resource Consumption

For each state-modifying function with a limited-use resource (cooldown, one-time flag, nonce, epoch-bound action): Can it be called with parameters producing zero economic effect (amount=0, same-token swap, self-transfer) while consuming the resource?

FunctionResource ConsumedNo-Op ParametersResource Wasted?Impact

If a no-op call consumes a resource blocking legitimate use → FINDING (R2, resource waste).

Show full SKILL.md (467 more words)Show less
3d. External Flash × Debounce Cross-Reference (MANDATORY)

For EACH external protocol flagged as flash-susceptible in Section 0:

External ProtocolFlash-Accessible ActionDebounce/Cooldown Affected (from 3b)Combined Severity

Cross-reference: Can the external flash loan trigger ANY debounce/cooldown found in Step 3b? If YES:

  1. Is the debounce consumption permanent (no admin reset) or temporary (auto-expires)?
  2. If permanent: is there ANY on-chain path to reset? (admin function, governance, time-based expiry)
  3. Combined finding inherits the HIGHER severity of the two individual findings
  4. Tag: [TRACE:flash({external}) → call({debounce_fn}) → cooldown consumed → {duration/permanent}]

If no debounce functions exist from 3b: mark N/A and skip.

<!-- LOAD_IF: BALANCE_DEPENDENT -->

4. Flash Loan + Donation Compound Attacks

Combine flash loan capital with unsolicited token transfers:

Donation TargetFlash Loan ActionCombined EffectProfitable?
{contract}.balanceOfDeposit/withdrawRate manipulation{YES/NO}
{pool}.reservesSwapPrice oracle manipulation{YES/NO}
{governance}.balanceVote/proposeQuorum manipulation{YES/NO}

Check: Can a flash-borrowed amount be donated (not deposited) to the protocol to manipulate balanceOf(this) accounting, and then extracted via a subsequent protocol call within the same transaction?

<!-- END_LOAD_IF: BALANCE_DEPENDENT -->

5. Flash Loan Defense Audit

For each flash-loan-accessible attack path identified:

DefensePresent?Effective?Bypass?
Reentrancy guard (nonReentrant)YES/NO{analysis}{if YES: how}
Same-block prevention (block.number check)YES/NO{analysis}Multi-block possible?
TWAP instead of spot priceYES/NOTWAP window length: {N}Short TWAP vulnerable?
Minimum lock period / cooldownYES/NODuration: {N blocks/seconds}Bypass via partial?
Balance snapshot (before/after comparison)YES/NO{analysis}{if YES: how}
Flash loan fee exceeds profitYES/NOFee: {X}, max profit: {Y}Fee < profit?

TWAP-specific: If TWAP window < 30 minutes AND pool liquidity < $10M → flag as potentially manipulable.

5b. Defense Parity Audit (Cross-Contract)

For each user-facing action that exists in multiple contracts (stake, withdraw, claim, exit):

ActionContract AFlash DefenseContract BFlash DefenseParity?
{action}{contract}{defense list}{contract}{defense list}{GAP if different}

Key question: If ContractA.stake() has a cooldown that prevents flash-stake-claim-withdraw, but ContractB.stake() has NO cooldown for the same economic action - can an attacker use ContractB as the undefended path to extract the same value?

For each GAP found:

  1. Can the undefended contract be used to achieve the same economic outcome?
  2. Does the defended contract's protection become meaningless if the undefended path exists?
  3. Is the defense difference intentional (documented) or accidental?

Finding Template

markdown
**ID**: [FL-N]
**Severity**: [based on profitability and fund impact]
**Step Execution**: ✓1,2,3,4,5 | ✗(reasons) | ?(uncertain)
**Rules Applied**: [R2:✓, R4:✓, R10:✓, R15:✓]
**Location**: Contract.sol:LineN
**Title**: Flash loan enables [manipulation] via [mechanism]
**Description**: [Full atomic attack sequence with amounts]
**Impact**: [Quantified profit/loss with realistic flash loan amounts]

Step Execution Checklist (MANDATORY)

SectionRequiredCompleted?Notes
0. External Flash Susceptibility CheckYES✓/✗/?For each external protocol interaction
1. Flash-Loan-Accessible State InventoryYES✓/✗/?
2. Atomic Attack Sequence ModelingYES✓/✗/?For each accessible state
3. Cross-Function Flash Loan ChainsYES✓/✗/?
3b. Flash-Loan-Enabled Debounce DoSYES✓/✗/?Shared cooldown functions
3c. No-Op Resource ConsumptionYES✓/✗/?Zero-effect calls consuming resources
3d. External Flash × Debounce Cross-RefYES✓/✗/?Cross-reference 0 × 3b
4. Flash Loan + Donation CompoundsIF BALANCE_DEPENDENT✓/✗(N/A)/?
5. Flash Loan Defense AuditYES✓/✗/?For each attack path
5b. Defense Parity AuditYES✓/✗/?For each action in multiple contracts

© PlamenTSV, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in agents/skills/evm/flash-loan-interaction of PlamenTSV/plamen.

Open the folder on GitHubat commit 795962b

Compare with similar skills

Flash Loan Interaction next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Flash Loan Interaction compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Flash Loan Interaction this skillPlamenTSV/plamen303—~2.9kAutomated safety check: PassMIT
Fizz Convertpashov/skills1.2k2 repos~3.7kAutomated safety check: PassMIT
Solana Devsolana-foundation/solana-dev-skill574—~3.8kAutomated safety check: PassMIT
Feynman Auditor0xiehnnkta/nemesis-auditor2431 repos~11kAutomated safety check: PassMIT
Smart Contract Auditgreatpie/smart-contract-audit-skill101—~1.1kAutomated safety check: PassNone
RadarAuditware/radar154—~2.1kAutomated safety check: PassGPL-3.0

Similar skills

  • Fizz Convert

    pashov/skills

    Convert English-language properties in PROPERTIES.md (produced by the Fizz skill) into Solidity assertions inside the existing fuzz harness, then flip their checkboxes.

    1.2k GitHub starsUsed in 2 repos~3.7k tokens
    Backend & APIsAuto-check passed
  • Solana Dev

    solana-foundation/solana-dev-skill

    A skill your agent uses when user asks to "build a Solana dapp", "write an Anchor program", "create a token", "debug Solana errors", "set up wallet connection", "test my Solana program", "fuzz my…

    574 GitHub stars~3.8k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Feynman Auditor

    0xiehnnkta/nemesis-auditor

    Deep business logic bug finder using the Feynman technique. An agent skill from 0xiehnnkta/nemesis-auditor.

    243 GitHub starsUsed in 1 repo~11k tokens
    Backend & APIsAuto-check passed
  • Smart Contract Audit

    greatpie/smart-contract-audit-skill

    Script-backed, out-of-box auditing workflow for Solidity/EVM repositories based on EVMbench detect/patch/exploit methodology.

    101 GitHub stars~1.1k tokensUpdated 7 mo ago
    Backend & APIsAuto-check passed
  • Radar

    Auditware/radar

    Use radar for smart contract security analysis, AST generation, and detection template development.

    154 GitHub stars~2.1k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Solidity Auditor

    Gabson0x/bountyforge

    Security audit of Solidity code while you develop. An agent skill from Gabson0x/bountyforge.

    443 GitHub stars~3.7k tokensUpdated 22 days ago
    Backend & APIsAuto-check passed

More from PlamenTSV/plamen

All 87 skills in this repo
  • Audit Prep

    PlamenTSV/plamen

    Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project…

    303 GitHub stars~3.7k tokensUpdated 12 days ago
    Auto-check passed
  • Verification Protocol

    PlamenTSV/plamen

    Trigger Pattern Always (used by all verifier agents) - Inject Into security-verifier agents (Phase 5)

    303 GitHub stars~3.5k tokensUpdated 12 days ago
    Auto-check passed
  • Ability Analysis

    PlamenTSV/plamen

    Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth agents, depth agents

    303 GitHub stars~3.3k tokensUpdated 12 days ago
    Auto-check passed
  • Ability Analysis

    PlamenTSV/plamen

    Trigger Pattern Always (Sui Move) -- foundational security check - Inject Into Breadth agents, depth agents

    303 GitHub stars~3.2k tokensUpdated 12 days ago
    Auto-check passed
  • Account Lifecycle

    PlamenTSV/plamen

    Trigger Pattern ACCOUNTCLOSING flag detected (close/CloseAccount usage) - Inject Into Breadth agents, depth agents

    303 GitHub stars~1.2k tokensUpdated 12 days ago
    Auto-check passed
  • Account Validation

    PlamenTSV/plamen

    Trigger Pattern Always required for Solana audits - Inject Into Breadth agents, depth agents

    303 GitHub stars~1.7k tokensUpdated 12 days ago
    Auto-check passed

Categories

Questions about Flash Loan Interaction

What does Flash Loan Interaction do?

Trigger Pattern FLASHLOAN flag (required) or BALANCEDEPENDENT flag (optional complement) - Inject Into Breadth agents, depth-token-flow, depth-edge-case. Flash Loan Interaction is an agent skill from PlamenTSV/plamen.

When should I use Flash Loan Interaction?

Flash Loan Interaction fits situations like: pattern FLASHLOAN flag (required); BALANCEDEPENDENT flag (optional complement) - Inject Into Breadth agents; depth-token-flow; depth-edge-case.

How do I install Flash Loan Interaction in Claude Code?

Run `npx skills add PlamenTSV/plamen --skill flash-loan-interaction -a claude-code`. Or copy the skill folder (agents/skills/evm/flash-loan-interaction in PlamenTSV/plamen) into .claude/skills/flash-loan-interaction in your project. Claude Code loads it when a task matches its description.

How do I install Flash Loan Interaction in Codex?

Run `npx skills add PlamenTSV/plamen --skill flash-loan-interaction -a codex`. Or copy the skill folder (agents/skills/evm/flash-loan-interaction in PlamenTSV/plamen) into .agents/skills/flash-loan-interaction in your project. Codex loads it when a task matches its description.

Can I use Flash Loan Interaction in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PlamenTSV/plamen --skill flash-loan-interaction -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/flash-loan-interaction, .gemini/skills/flash-loan-interaction, .github/skills/flash-loan-interaction and .opencode/skills/flash-loan-interaction in your project.

What does Flash Loan Interaction need to run?

SKILL.md names no scripts, command-line tools or credentials: Flash Loan Interaction is instructions for the agent only.

Does Flash Loan Interaction access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Flash Loan Interaction safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Flash Loan Interaction use?

Flash Loan Interaction is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Flash Loan Interaction use?

About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Flash Loan Interaction?

Skills that share tags, products or a category with Flash Loan Interaction: Fizz Convert (pashov/skills, 1.2k stars), Solana Dev (solana-foundation/solana-dev-skill, 574 stars), Feynman Auditor (0xiehnnkta/nemesis-auditor, 243 stars) and Smart Contract Audit (greatpie/smart-contract-audit-skill, 101 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Flash Loan Interaction?

PlamenTSV (a GitHub user) maintains it in PlamenTSV/plamen, which has 303 GitHub stars. The repository holds 87 skills in this directory. The repository was last updated on September 26, 2026.

Source: PlamenTSV/plamen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.