Squash Bugbot
LFDT-Lineth/lineth-monorepo
Triage unresolved bot review comments on a GitHub PR. An agent skill from LFDT-Lineth/lineth-monorepo.
Trigger Pattern Always (run during recon TASK 0, not breadth) - Inject Into Recon agent only (metabuffer.md enrichment)
$ npx skills add PlamenTSV/plamen --skill fork-ancestry -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install PlamenTSV/plamen fork-ancestry --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agents/skills/evm/fork-ancestry .claude/skills/fork-ancestry && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "fork-ancestry" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/evm/fork-ancestry into .claude/skills/fork-ancestry/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fork-ancestry", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/PlamenTSV/plamen/tree/main/agents/skills/evm/fork-ancestryType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add PlamenTSV/plamen --skill fork-ancestry -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install PlamenTSV/plamen fork-ancestry --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .agents/skills && cp -r skills-src/agents/skills/evm/fork-ancestry .agents/skills/fork-ancestry && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "fork-ancestry" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/evm/fork-ancestry into .agents/skills/fork-ancestry/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fork-ancestry", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add PlamenTSV/plamen --skill fork-ancestry -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install PlamenTSV/plamen fork-ancestry --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/agents/skills/evm/fork-ancestry .cursor/skills/fork-ancestry && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "fork-ancestry" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/evm/fork-ancestry into .cursor/skills/fork-ancestry/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fork-ancestry", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/PlamenTSV/plamen.git --path agents/skills/evm/fork-ancestry--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add PlamenTSV/plamen --skill fork-ancestry -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install PlamenTSV/plamen fork-ancestry --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/agents/skills/evm/fork-ancestry .gemini/skills/fork-ancestry && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "fork-ancestry" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/evm/fork-ancestry into .gemini/skills/fork-ancestry/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fork-ancestry", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install PlamenTSV/plamen fork-ancestryInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add PlamenTSV/plamen --skill fork-ancestry -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .github/skills && cp -r skills-src/agents/skills/evm/fork-ancestry .github/skills/fork-ancestry && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "fork-ancestry" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/evm/fork-ancestry into .github/skills/fork-ancestry/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fork-ancestry", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add PlamenTSV/plamen --skill fork-ancestry -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install PlamenTSV/plamen fork-ancestry --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/agents/skills/evm/fork-ancestry .opencode/skills/fork-ancestry && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "fork-ancestry" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/evm/fork-ancestry into .opencode/skills/fork-ancestry/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fork-ancestry", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
fork-ancestryTrigger Pattern Always (run during recon TASK 0, not breadth) - Inject Into Recon agent only (metabuffer.md enrichment)
Fork Ancestry is an agent skill from PlamenTSV/plamen. Trigger Pattern Always (run during recon TASK 0, not breadth) - Inject Into Recon agent only (metabuffer.md enrichment)
Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Smart contracts. It works with Git. The repository describes itself as: Autonomous Web3 security audit agent for Claude Code. The licence is MIT.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 795962b. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitvaultFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Fork Ancestry loads about 2.4k tokens when it runs. Until then it costs about 34 tokens; SKILL.md has 914 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from PlamenTSV/plamen at commit 795962b, republished under its MIT licence (© PlamenTSV). 914 words, ~2,414 tokens.
.claude/skills/fork-ancestry/SKILL.md (or your agent's skills folder).Trigger Pattern: Always (run during recon TASK 0, not breadth) Inject Into: Recon agent only (meta_buffer.md enrichment) Purpose: Detect known parent codebases and inherit their historical vulnerability patterns.
Grep the codebase for known parent signatures:
| Parent Project | Detection Patterns | Common Forks |
|---|---|---|
| Synthetix | SNX|synthetix|StakingRewards|RewardsDistribution|Issuer | Staking rewards forks |
| Compound | CToken|Comptroller|cToken|comptroller|InterestRateModel | Lending protocol forks |
| Uniswap V2 | UniswapV2|PairFactory|getReserves|MINIMUM_LIQUIDITY | DEX forks |
| Uniswap V3 | UniswapV3|TickMath|SqrtPriceMath|NonfungiblePositionManager | Concentrated liquidity forks |
| Aave | aToken|LendingPool|flashLoan.*initiator|AAVE | Lending forks |
| MasterChef | MasterChef|poolInfo|userInfo|pendingReward|massUpdatePools | Yield farming forks |
| Curve | StableSwap|get_dy|A_PRECISION|get_virtual_price|ramp_A|stop_ramp_A|calc_withdraw_one_coin|remove_liquidity_imbalance|admin_fee|commit_new_fee | Stableswap forks — set STABLESWAP_FORK flag if MEDIUM+ confidence |
| OpenZeppelin | Ownable|AccessControl|Pausable|ERC20Upgradeable | Most projects (check version) |
| Basis/Tomb | Boardroom|Treasury|seigniorage|epoch|TWAP.*peg | Algorithmic stablecoin forks |
| Olympus | OHM|gOHM|staking.*rebase|bond.*discount | Rebase token forks |
| Balancer | BPool|WeightedPool|BVault|flashLoan.*userData | Weighted pool forks |
| Yearn | Vault|Strategy|harvest|totalDebt|debtRatio | Yield vault forks |
Git-based detection (complements code-pattern matching — catches forks that renamed all identifiers).
Skip if REPO_SHAPE: squashed_import in build_status.md — single-commit repos have no meaningful git metadata.
.gitmodules for submodule URLs pointing to known parent reposgit remote -v for origin URLs matching known parent organizations (compound-finance, Uniswap, aave, sushiswap, curvefi, yearn, OlympusDAO, balancer)GIT_ONLY_FORK — the fork likely renamed all identifiers, which warrants deeper divergence analysisOutput: List of detected parents with confidence level (HIGH: 3+ patterns, MEDIUM: 2 patterns, LOW: 1 pattern, GIT_ONLY: git URL match but no code patterns).
For each detected parent (confidence MEDIUM or HIGH):
// Query 1: Known high-quality issues
search_solodit_live(
protocol="{parent_name}",
impact=["HIGH", "CRITICAL"],
language="Solidity",
quality_score=3,
sort_by="Quality",
max_results=15
)
// Query 2: Rare/unusual patterns specific to fork divergences
search_solodit_live(
keywords="{parent_name} fork modified divergence",
impact=["HIGH", "MEDIUM"],
language="Solidity",
sort_by="Rarity",
max_results=10
)tavily_search(query="{parent_name} smart contract vulnerability exploit audit finding 2024 2025 2026")Compile results into:
| Parent | Known Issue | Severity | Root Cause | Solodit Ref | Applicable to Fork? |
|---|---|---|---|---|---|
| {parent} | {issue title} | {severity} | {brief root cause} | {link/ID} | YES / NO / CHECK |
Applicability criteria:
If Solodit AND Tavily BOTH fail, use this minimum catalog -- check EACH applicable parent.
This floor is keyed on the parent's TYPE (generic mechanism), NOT on any specific protocol name — brand-keyed rows are prohibited (a floor row naming a specific protocol is the confirmed benchmark-contamination vector; see the HARD no-overfit rule). Classify the detected parent (from Section 1) into a type below and check the generic known-issue class; use at most one illustrative brand only in prose, never as the row key.
| Parent Type | Critical Known-Issue Class | Root Cause | Search Keywords |
|---|---|---|---|
| Staking-rewards distributor | Reward-rate manipulation via reward-notification timing | Reward duration reset when a new reward is notified mid-period | staking reward notify duration reset |
| Lending / money-market receipt token | First-depositor exchange-rate manipulation | Empty-market rounding in the exchange-rate calc | lending exchange rate first deposit empty market |
| Lending / money-market liquidation engine | Flash loan + oracle manipulation for unfair liquidation | Spot-price dependency in the liquidation health check | flash loan liquidation oracle manipulation |
| AMM constant-product pool (LP token) | First-LP inflation attack (minimum-liquidity bypass) | LP share rounding at low liquidity | amm minimum liquidity first LP inflation |
| Epoch-based seigniorage / rebasing treasury | Epoch-boundary distribution front-running + stake timing | Discrete epoch distribution creates a race at the boundary | epoch seigniorage boundary timing front-run |
| Epoch-based treasury with operator roles | Epoch-boundary timing + treasury allocation fairness + role privilege scope | Extended epoch model with additional operator roles and cooldown mechanisms | epoch treasury operator role cooldown |
| Yield-farming reward distributor (checkpoint-based) | Reward-rate manipulation via zero-amount deposit + unfair early-user dilution | Checkpoint timing where a zero-amount deposit triggers a reward-rate update | yield farming deposit zero reward rate checkpoint timing |
| Stableswap / invariant-curve AMM | Reentrancy via raw native-token transfer in liquidity removal + read-only reentrancy | Native-token callback fires before state update; view functions read stale state during the callback | stableswap reentrancy remove liquidity read-only |
| AMM vault / batched-swap pool | Flash loan + price-oracle manipulation via pool-balance change | Spot price manipulated within a single transaction via balance change | amm vault flash loan oracle manipulation balance |
| Yield vault (share-based accounting) | Share-price manipulation via strategy-report timing + first depositor | Donation before first deposit inflates price-per-share | vault share price first deposit donation strategy |
Note: This floor lists generic known-issue CLASSES by parent type only — it is minimum coverage, not exhaustive, and NOT a substitute for the live-searched Solodit/Tavily results (2a/2b). Real research typically surfaces several more issues specific to the actual parent.
For each detected parent:
Compare fork vs parent in security-critical paths:
| Component | Parent Behavior | Fork Behavior | Security Impact |
|---|---|---|---|
| {component} | {original} | {modified or SAME} | {new risk or NONE} |
Focus on:
For each modification:
Append to {SCRATCHPAD}/meta_buffer.md:
## Fork Ancestry Analysis
### Detected Parents
| Parent | Confidence | Patterns Found |
|--------|-----------|---------------|
### Inherited Vulnerabilities to Verify
| # | Parent Issue | Severity | Location in Fork | Status |
|---|-------------|----------|------------------|--------|
| 1 | {issue} | {severity} | {fork location} | CHECK / VERIFIED_SAFE / VULNERABLE |
### Fork Divergences (Security-Critical)
| # | Component | Change | New Risk? |
|---|-----------|--------|-----------|
### Questions for Breadth Agents
1. {derived from inherited vulnerabilities}
2. {derived from divergence analysis}| Section | Required | Completed? | Notes |
|---|---|---|---|
| 1. Detect Fork Indicators | YES | Y/N/? | |
| 2. Query Known Parent Issues | IF parent detected | Y/N(no parent)/? | |
| 3. Divergence Analysis | IF parent detected | Y/N(no parent)/? | |
| 4. Output to meta_buffer.md | YES | Y/N/? |
© PlamenTSV, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in agents/skills/evm/fork-ancestry of PlamenTSV/plamen.
Open the folder on GitHubat commit 795962b
Fork Ancestry next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Fork Ancestry this skillPlamenTSV/plamen | 303 | — | ~2.4k | Automated safety check: Pass | MIT | |
| Squash BugbotLFDT-Lineth/lineth-monorepo | 126 | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | |
| Verify Deployment PROriginProtocol/origin-dollar | 153 | — | ~2.6k | Automated safety check: Notes | MIT | |
| Flounderadshao/flounder | 519 | — | ~9.2k | Automated safety check: Pass | AGPL-3.0 | |
| Careful Mode Command Guardrailsgarrytan/gstack | 136k | — | ~931 | Automated safety check: Notes | MIT | |
| Agent Walletinternet-court/internet-court-skill | 6.4k | 2 repos | ~4.1k | Automated safety check: Pass | MIT |
LFDT-Lineth/lineth-monorepo
Triage unresolved bot review comments on a GitHub PR. An agent skill from LFDT-Lineth/lineth-monorepo.
OriginProtocol/origin-dollar
Verifies a POST-EXECUTION mainnet (or other network) smart-contract deployment PR for this repo: confirms every deployed contract is listed in the PR description, that the on-chain verified source…
adshao/flounder
Operates Flounder, an autonomous white-hat security auditor.
garrytan/gstack
Checks each shell command for destructive patterns such as recursive deletes, force pushes and dropped tables, and asks before letting them run.
internet-court/internet-court-skill
Give the AI agent its own EVM wallet with admin-controlled policies the agent CANNOT bypass even under prompt injection.
aviggiano/security
Build metric-driven Chimera/create-chimera-app stateful invariant testing campaigns for Solidity projects.
PlamenTSV/plamen
Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project…
PlamenTSV/plamen
Trigger Pattern Always (used by all verifier agents) - Inject Into security-verifier agents (Phase 5)
PlamenTSV/plamen
Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth agents, depth agents
PlamenTSV/plamen
Trigger Pattern Always (Sui Move) -- foundational security check - Inject Into Breadth agents, depth agents
PlamenTSV/plamen
Trigger Pattern ACCOUNTCLOSING flag detected (close/CloseAccount usage) - Inject Into Breadth agents, depth agents
PlamenTSV/plamen
Trigger Pattern Always required for Solana audits - Inject Into Breadth agents, depth agents
Works with
Categories
Trigger Pattern Always (run during recon TASK 0, not breadth) - Inject Into Recon agent only (metabuffer.md enrichment). Fork Ancestry is an agent skill from PlamenTSV/plamen.
Fork Ancestry fits situations like: pattern Always (run during recon TASK 0; not breadth) - Inject Into Recon agent only (metabuffer.md enrichment).
Run `npx skills add PlamenTSV/plamen --skill fork-ancestry -a claude-code`. Or copy the skill folder (agents/skills/evm/fork-ancestry in PlamenTSV/plamen) into .claude/skills/fork-ancestry in your project. Claude Code loads it when a task matches its description.
Run `npx skills add PlamenTSV/plamen --skill fork-ancestry -a codex`. Or copy the skill folder (agents/skills/evm/fork-ancestry in PlamenTSV/plamen) into .agents/skills/fork-ancestry in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PlamenTSV/plamen --skill fork-ancestry -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/fork-ancestry, .gemini/skills/fork-ancestry, .github/skills/fork-ancestry and .opencode/skills/fork-ancestry in your project.
Going by SKILL.md and its folder, Fork Ancestry needs the command-line tools its instructions call (git and vault).
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Fork Ancestry is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.4k tokens (SKILL.md is roughly 9.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Fork Ancestry: Squash Bugbot (LFDT-Lineth/lineth-monorepo, 126 stars), Verify Deployment PR (OriginProtocol/origin-dollar, 153 stars), Flounder (adshao/flounder, 519 stars) and Careful Mode Command Guardrails (garrytan/gstack, 136k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
PlamenTSV (a GitHub user) maintains it in PlamenTSV/plamen, which has 303 GitHub stars. The repository holds 87 skills in this directory. The repository was last updated on September 26, 2026.
Source: PlamenTSV/plamen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.