Agent skill

Fork Ancestry

by PlamenTSV in PlamenTSV/plamen

Trigger Pattern Always (run during recon TASK 0, not breadth) - Inject Into Recon agent only (metabuffer.md enrichment)

MITAuto-check passedSecurity

Install Fork Ancestry

skills CLI
$ npx skills add PlamenTSV/plamen --skill fork-ancestry -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install PlamenTSV/plamen fork-ancestry --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agents/skills/evm/fork-ancestry .claude/skills/fork-ancestry && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
fork-ancestry
GitHub stars
303
Token cost
~2.4k tokens
SKILL.md length
914 words
Files
1
Skills in repo
87
Repo updated
First seen
Licence
MIT

At a glance

Trigger Pattern Always (run during recon TASK 0, not breadth) - Inject Into Recon agent only (metabuffer.md enrichment)

  • Works in 4 steps: Detect Fork Indicators → Query Known Parent Issues → Divergence Analysis → …
  • Pattern Always (run during recon TASK 0
  • SKILL.md covers 1. Detect Fork Indicators, 2. Query Known Parent Issues, 3. Divergence Analysis and 4. Output to meta_buffer.md, plus 1 more section
  • Calls git and vault

What it does

Fork Ancestry is an agent skill from PlamenTSV/plamen. Trigger Pattern Always (run during recon TASK 0, not breadth) - Inject Into Recon agent only (metabuffer.md enrichment)

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Smart contracts. It works with Git. The repository describes itself as: Autonomous Web3 security audit agent for Claude Code. The licence is MIT.

When your agent uses it

  • Pattern Always (run during recon TASK 0
  • Not breadth) - Inject Into Recon agent only (metabuffer.md enrichment)

Example prompts

  • “/fork-ancestry”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Detect Fork Indicators
  2. Query Known Parent Issues
  3. Divergence Analysis
  4. Output to meta_buffer.md

What it can do on your machine

Read from SKILL.md and the folder at commit 795962b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • vault

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Fork Ancestry loads about 2.4k tokens when it runs. Until then it costs about 34 tokens; SKILL.md has 914 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~34
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from PlamenTSV/plamen at commit 795962b, republished under its MIT licence (© PlamenTSV). 914 words, ~2,414 tokens.

Download SKILL.mdSave it as .claude/skills/fork-ancestry/SKILL.md (or your agent's skills folder).
name
fork-ancestry
description
Trigger Pattern Always (run during recon TASK 0, not breadth) - Inject Into Recon agent only (meta_buffer.md enrichment)

FORK_ANCESTRY Skill

Trigger Pattern: Always (run during recon TASK 0, not breadth) Inject Into: Recon agent only (meta_buffer.md enrichment) Purpose: Detect known parent codebases and inherit their historical vulnerability patterns.

1. Detect Fork Indicators

Grep the codebase for known parent signatures:

Parent ProjectDetection PatternsCommon Forks
SynthetixSNX|synthetix|StakingRewards|RewardsDistribution|IssuerStaking rewards forks
CompoundCToken|Comptroller|cToken|comptroller|InterestRateModelLending protocol forks
Uniswap V2UniswapV2|PairFactory|getReserves|MINIMUM_LIQUIDITYDEX forks
Uniswap V3UniswapV3|TickMath|SqrtPriceMath|NonfungiblePositionManagerConcentrated liquidity forks
AaveaToken|LendingPool|flashLoan.*initiator|AAVELending forks
MasterChefMasterChef|poolInfo|userInfo|pendingReward|massUpdatePoolsYield farming forks
CurveStableSwap|get_dy|A_PRECISION|get_virtual_price|ramp_A|stop_ramp_A|calc_withdraw_one_coin|remove_liquidity_imbalance|admin_fee|commit_new_feeStableswap forks — set STABLESWAP_FORK flag if MEDIUM+ confidence
OpenZeppelinOwnable|AccessControl|Pausable|ERC20UpgradeableMost projects (check version)
Basis/TombBoardroom|Treasury|seigniorage|epoch|TWAP.*pegAlgorithmic stablecoin forks
OlympusOHM|gOHM|staking.*rebase|bond.*discountRebase token forks
BalancerBPool|WeightedPool|BVault|flashLoan.*userDataWeighted pool forks
YearnVault|Strategy|harvest|totalDebt|debtRatioYield vault forks

Git-based detection (complements code-pattern matching — catches forks that renamed all identifiers). Skip if REPO_SHAPE: squashed_import in build_status.md — single-commit repos have no meaningful git metadata.

  • Parse .gitmodules for submodule URLs pointing to known parent repos
  • Check git remote -v for origin URLs matching known parent organizations (compound-finance, Uniswap, aave, sushiswap, curvefi, yearn, OlympusDAO, balancer)
  • If a git-URL match is found but NO code-pattern match exists, flag as GIT_ONLY_FORK — the fork likely renamed all identifiers, which warrants deeper divergence analysis

Output: List of detected parents with confidence level (HIGH: 3+ patterns, MEDIUM: 2 patterns, LOW: 1 pattern, GIT_ONLY: git URL match but no code patterns).

2. Query Known Parent Issues

For each detected parent (confidence MEDIUM or HIGH):

2a. Solodit Search (two queries, run in parallel)
// Query 1: Known high-quality issues
search_solodit_live(
  protocol="{parent_name}",
  impact=["HIGH", "CRITICAL"],
  language="Solidity",
  quality_score=3,
  sort_by="Quality",
  max_results=15
)
// Query 2: Rare/unusual patterns specific to fork divergences
search_solodit_live(
  keywords="{parent_name} fork modified divergence",
  impact=["HIGH", "MEDIUM"],
  language="Solidity",
  sort_by="Rarity",
  max_results=10
)
tavily_search(query="{parent_name} smart contract vulnerability exploit audit finding 2024 2025 2026")
2c. Known Issue Catalog

Compile results into:

ParentKnown IssueSeverityRoot CauseSolodit RefApplicable to Fork?
{parent}{issue title}{severity}{brief root cause}{link/ID}YES / NO / CHECK

Applicability criteria:

  • YES: Fork retains the vulnerable code path unchanged
  • NO: Fork modified the vulnerable code path (document what changed)
  • CHECK: Cannot determine without deeper analysis (flag for breadth agent)
2d. Hardcoded Known-Issue Floor (Web Search Fallback)

If Solodit AND Tavily BOTH fail, use this minimum catalog -- check EACH applicable parent.

This floor is keyed on the parent's TYPE (generic mechanism), NOT on any specific protocol name — brand-keyed rows are prohibited (a floor row naming a specific protocol is the confirmed benchmark-contamination vector; see the HARD no-overfit rule). Classify the detected parent (from Section 1) into a type below and check the generic known-issue class; use at most one illustrative brand only in prose, never as the row key.

Parent TypeCritical Known-Issue ClassRoot CauseSearch Keywords
Staking-rewards distributorReward-rate manipulation via reward-notification timingReward duration reset when a new reward is notified mid-periodstaking reward notify duration reset
Lending / money-market receipt tokenFirst-depositor exchange-rate manipulationEmpty-market rounding in the exchange-rate calclending exchange rate first deposit empty market
Lending / money-market liquidation engineFlash loan + oracle manipulation for unfair liquidationSpot-price dependency in the liquidation health checkflash loan liquidation oracle manipulation
AMM constant-product pool (LP token)First-LP inflation attack (minimum-liquidity bypass)LP share rounding at low liquidityamm minimum liquidity first LP inflation
Epoch-based seigniorage / rebasing treasuryEpoch-boundary distribution front-running + stake timingDiscrete epoch distribution creates a race at the boundaryepoch seigniorage boundary timing front-run
Epoch-based treasury with operator rolesEpoch-boundary timing + treasury allocation fairness + role privilege scopeExtended epoch model with additional operator roles and cooldown mechanismsepoch treasury operator role cooldown
Yield-farming reward distributor (checkpoint-based)Reward-rate manipulation via zero-amount deposit + unfair early-user dilutionCheckpoint timing where a zero-amount deposit triggers a reward-rate updateyield farming deposit zero reward rate checkpoint timing
Stableswap / invariant-curve AMMReentrancy via raw native-token transfer in liquidity removal + read-only reentrancyNative-token callback fires before state update; view functions read stale state during the callbackstableswap reentrancy remove liquidity read-only
AMM vault / batched-swap poolFlash loan + price-oracle manipulation via pool-balance changeSpot price manipulated within a single transaction via balance changeamm vault flash loan oracle manipulation balance
Yield vault (share-based accounting)Share-price manipulation via strategy-report timing + first depositorDonation before first deposit inflates price-per-sharevault share price first deposit donation strategy
Show full SKILL.md (265 more words)Show less

Note: This floor lists generic known-issue CLASSES by parent type only — it is minimum coverage, not exhaustive, and NOT a substitute for the live-searched Solodit/Tavily results (2a/2b). Real research typically surfaces several more issues specific to the actual parent.

3. Divergence Analysis

For each detected parent:

3a. Identify What Changed

Compare fork vs parent in security-critical paths:

ComponentParent BehaviorFork BehaviorSecurity Impact
{component}{original}{modified or SAME}{new risk or NONE}

Focus on:

  • Modified access control (added/removed roles, changed modifiers)
  • Changed mathematical formulas (fee calculations, exchange rates, reward distribution)
  • Parameter semantic verification: When the parent has a mathematical specification, verify that each core parameter carries the same mathematical meaning in the fork — not just the same name and numeric range. Forks may store a raw value where the parent stores a derived form (e.g., raw coefficient vs. coefficient scaled by a function of pool dimensions). Compare the fork's formula usage against the parent's specification to confirm the encoding convention matches.
  • Added external dependencies (new oracles, new tokens, new protocols)
  • Removed safety checks (validation removed, guard removed)
  • Changed state variable types or visibility
3b. New Attack Surface from Divergence

For each modification:

  • Does the change introduce a NEW vulnerability not in the parent?
  • Does the change REMOVE a parent fix/mitigation?
  • Does the change create an INCONSISTENCY with parent's invariants?

4. Output to meta_buffer.md

Append to {SCRATCHPAD}/meta_buffer.md:

markdown
## Fork Ancestry Analysis

### Detected Parents
| Parent | Confidence | Patterns Found |
|--------|-----------|---------------|

### Inherited Vulnerabilities to Verify
| # | Parent Issue | Severity | Location in Fork | Status |
|---|-------------|----------|------------------|--------|
| 1 | {issue} | {severity} | {fork location} | CHECK / VERIFIED_SAFE / VULNERABLE |

### Fork Divergences (Security-Critical)
| # | Component | Change | New Risk? |
|---|-----------|--------|-----------|

### Questions for Breadth Agents
1. {derived from inherited vulnerabilities}
2. {derived from divergence analysis}

Step Execution Checklist (MANDATORY)

SectionRequiredCompleted?Notes
1. Detect Fork IndicatorsYESY/N/?
2. Query Known Parent IssuesIF parent detectedY/N(no parent)/?
3. Divergence AnalysisIF parent detectedY/N(no parent)/?
4. Output to meta_buffer.mdYESY/N/?

© PlamenTSV, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in agents/skills/evm/fork-ancestry of PlamenTSV/plamen.

Open the folder on GitHubat commit 795962b

Compare with similar skills

Fork Ancestry next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Fork Ancestry compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Fork Ancestry this skillPlamenTSV/plamen303—~2.4kAutomated safety check: PassMIT
Squash BugbotLFDT-Lineth/lineth-monorepo126—~3.3kAutomated safety check: PassApache-2.0
Verify Deployment PROriginProtocol/origin-dollar153—~2.6kAutomated safety check: NotesMIT
Flounderadshao/flounder519—~9.2kAutomated safety check: PassAGPL-3.0
Careful Mode Command Guardrailsgarrytan/gstack136k—~931Automated safety check: NotesMIT
Agent Walletinternet-court/internet-court-skill6.4k2 repos~4.1kAutomated safety check: PassMIT

Similar skills

  • Squash Bugbot

    LFDT-Lineth/lineth-monorepo

    Triage unresolved bot review comments on a GitHub PR. An agent skill from LFDT-Lineth/lineth-monorepo.

    126 GitHub stars~3.3k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Verify Deployment PR

    OriginProtocol/origin-dollar

    Verifies a POST-EXECUTION mainnet (or other network) smart-contract deployment PR for this repo: confirms every deployed contract is listed in the PR description, that the on-chain verified source…

    153 GitHub stars~2.6k tokensUpdated yesterday
    Backend & APIsAuto-check: notes
  • Flounder

    adshao/flounder

    Operates Flounder, an autonomous white-hat security auditor.

    519 GitHub stars~9.2k tokensUpdated 3 days ago
    SecurityAuto-check passed
  • Checks each shell command for destructive patterns such as recursive deletes, force pushes and dropped tables, and asks before letting them run.

    136k GitHub stars~931 tokensUpdated today
    SecurityAuto-check: notes
  • Agent Wallet

    internet-court/internet-court-skill

    Give the AI agent its own EVM wallet with admin-controlled policies the agent CANNOT bypass even under prompt injection.

    6.4k GitHub starsUsed in 2 repos~4.1k tokens
    SecurityAuto-check passed
  • Stateful Invariant Testing

    aviggiano/security

    Build metric-driven Chimera/create-chimera-app stateful invariant testing campaigns for Solidity projects.

    144 GitHub stars~2.8k tokensUpdated 23 days ago
    SecurityAuto-check passed

More from PlamenTSV/plamen

All 87 skills in this repo
  • Audit Prep

    PlamenTSV/plamen

    Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project…

    303 GitHub stars~3.7k tokensUpdated 12 days ago
    Auto-check passed
  • Verification Protocol

    PlamenTSV/plamen

    Trigger Pattern Always (used by all verifier agents) - Inject Into security-verifier agents (Phase 5)

    303 GitHub stars~3.5k tokensUpdated 12 days ago
    Auto-check passed
  • Ability Analysis

    PlamenTSV/plamen

    Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth agents, depth agents

    303 GitHub stars~3.3k tokensUpdated 12 days ago
    Auto-check passed
  • Ability Analysis

    PlamenTSV/plamen

    Trigger Pattern Always (Sui Move) -- foundational security check - Inject Into Breadth agents, depth agents

    303 GitHub stars~3.2k tokensUpdated 12 days ago
    Auto-check passed
  • Account Lifecycle

    PlamenTSV/plamen

    Trigger Pattern ACCOUNTCLOSING flag detected (close/CloseAccount usage) - Inject Into Breadth agents, depth agents

    303 GitHub stars~1.2k tokensUpdated 12 days ago
    Auto-check passed
  • Account Validation

    PlamenTSV/plamen

    Trigger Pattern Always required for Solana audits - Inject Into Breadth agents, depth agents

    303 GitHub stars~1.7k tokensUpdated 12 days ago
    Auto-check passed

Works with

Questions about Fork Ancestry

What does Fork Ancestry do?

Trigger Pattern Always (run during recon TASK 0, not breadth) - Inject Into Recon agent only (metabuffer.md enrichment). Fork Ancestry is an agent skill from PlamenTSV/plamen.

When should I use Fork Ancestry?

Fork Ancestry fits situations like: pattern Always (run during recon TASK 0; not breadth) - Inject Into Recon agent only (metabuffer.md enrichment).

How do I install Fork Ancestry in Claude Code?

Run `npx skills add PlamenTSV/plamen --skill fork-ancestry -a claude-code`. Or copy the skill folder (agents/skills/evm/fork-ancestry in PlamenTSV/plamen) into .claude/skills/fork-ancestry in your project. Claude Code loads it when a task matches its description.

How do I install Fork Ancestry in Codex?

Run `npx skills add PlamenTSV/plamen --skill fork-ancestry -a codex`. Or copy the skill folder (agents/skills/evm/fork-ancestry in PlamenTSV/plamen) into .agents/skills/fork-ancestry in your project. Codex loads it when a task matches its description.

Can I use Fork Ancestry in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PlamenTSV/plamen --skill fork-ancestry -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/fork-ancestry, .gemini/skills/fork-ancestry, .github/skills/fork-ancestry and .opencode/skills/fork-ancestry in your project.

What does Fork Ancestry need to run?

Going by SKILL.md and its folder, Fork Ancestry needs the command-line tools its instructions call (git and vault).

Does Fork Ancestry access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Fork Ancestry safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Fork Ancestry use?

Fork Ancestry is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Fork Ancestry use?

About 2.4k tokens (SKILL.md is roughly 9.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Fork Ancestry?

Skills that share tags, products or a category with Fork Ancestry: Squash Bugbot (LFDT-Lineth/lineth-monorepo, 126 stars), Verify Deployment PR (OriginProtocol/origin-dollar, 153 stars), Flounder (adshao/flounder, 519 stars) and Careful Mode Command Guardrails (garrytan/gstack, 136k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Fork Ancestry?

PlamenTSV (a GitHub user) maintains it in PlamenTSV/plamen, which has 303 GitHub stars. The repository holds 87 skills in this directory. The repository was last updated on September 26, 2026.

Source: PlamenTSV/plamen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.