Agent skill

Fungible Asset Security

by PlamenTSV in PlamenTSV/plamen

Trigger FASTANDARD flag detected (protocol uses FungibleAsset standard) - Used by Breadth agents, depth-token-flow

MITAuto-check passedSecurity

Install Fungible Asset Security

skills CLI
$ npx skills add PlamenTSV/plamen --skill fungible-asset-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install PlamenTSV/plamen fungible-asset-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agents/skills/aptos/fungible-asset-security .claude/skills/fungible-asset-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
fungible-asset-security
GitHub stars
303
Token cost
~3.3k tokens
SKILL.md length
1,322 words
Files
1
Skills in repo
87
Repo updated
First seen
Licence
MIT

At a glance

Trigger FASTANDARD flag detected (protocol uses FungibleAsset standard) - Used by Breadth agents, depth-token-flow

  • Works in 6 steps: Metadata Validation Audit → Zero-Value Exploitation → Store Creation and Ownership Analysis → …
  • FASTANDARD flag detected (protocol uses FungibleAsset standard) - Used by Breadth agents
  • SKILL.md covers Purpose, Methodology, Key Questions (Must Answer All) and Common False Positives, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Fungible Asset Security is an agent skill from PlamenTSV/plamen. Trigger FASTANDARD flag detected (protocol uses FungibleAsset standard) - Used by Breadth agents, depth-token-flow

Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security. The repository describes itself as: Autonomous Web3 security audit agent for Claude Code. The licence is MIT.

When your agent uses it

  • FASTANDARD flag detected (protocol uses FungibleAsset standard) - Used by Breadth agents
  • Depth-token-flow

Example prompts

  • “/fungible-asset-security”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Metadata Validation Audit
  2. Zero-Value Exploitation
  3. Store Creation and Ownership Analysis
  4. Dispatchable Hook Analysis
  5. Ref Safety Analysis
  6. Coin-to-FA Migration Accounting

What it can do on your machine

Read from SKILL.md and the folder at commit 795962b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are move and markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Fungible Asset Security loads about 3.3k tokens when it runs. Until then it costs about 35 tokens; SKILL.md has 1,322 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~35
When it runs · the whole SKILL.md, loaded when a task matches
~3.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from PlamenTSV/plamen at commit 795962b, republished under its MIT licence (© PlamenTSV). 1,322 words, ~3,310 tokens.

Download SKILL.mdSave it as .claude/skills/fungible-asset-security/SKILL.md (or your agent's skills folder).
name
fungible-asset-security
description
Trigger FA_STANDARD flag detected (protocol uses FungibleAsset standard) - Used by Breadth agents, depth-token-flow

Skill: FUNGIBLE_ASSET_SECURITY

Trigger: FA_STANDARD flag detected (protocol uses FungibleAsset standard) Used by: Breadth agents, depth-token-flow Covers: FungibleAsset metadata validation, zero-value exploitation, store ownership, dispatchable hooks, Ref safety, Coin-to-FA migration

Purpose

Audit FungibleAsset standard usage for Aptos-specific vulnerabilities. The FA standard introduces object-based token management with capabilities (MintRef, BurnRef, TransferRef, FreezeRef) and optional dispatchable hooks. Incorrect usage creates counterfeit token acceptance, forced transfers, reentrancy, and accounting mismatches.

Methodology

STEP 1: Metadata Validation Audit

For EVERY function that accepts a FungibleAsset parameter or reads from a FungibleStore:

#FunctionAccepts FA/Reads StoreValidates Metadata?Expected MetadataBypass Possible?
1{func}FungibleAsset paramYES/NO{expected_metadata_obj}YES/NO

How metadata validation works:

move
// CORRECT: validates the asset is the expected type
let metadata = fungible_asset::metadata(&fa);
assert!(metadata == expected_metadata, ERROR_WRONG_ASSET);

// VULNERABLE: no validation - accepts ANY FungibleAsset
public fun deposit(fa: FungibleAsset) {
    // Attacker can pass a worthless FA created from their own metadata
    fungible_asset::deposit(store, fa);
}

MANDATORY SEARCH: Grep all .move files for:

  1. FungibleAsset in function signatures (parameters)
  2. For each hit: trace whether fungible_asset::metadata(&fa) is called and compared
  3. Functions that ONLY use fungible_asset::amount(&fa) without metadata check -> FLAG

Severity: Accepting unvalidated FungibleAsset = accepting counterfeit tokens. If the function credits the user or modifies protocol state based on the FA amount -> HIGH/CRITICAL.

STEP 2: Zero-Value Exploitation

Analyze zero-value FungibleAsset paths:

#Zero-Value SourceCode Path TriggeredState Modified?Cleanup Correct?
1fungible_asset::zero(metadata){trace what happens}YES/NOYES/NO
2Withdrawal of 0 amount{trace}YES/NOYES/NO

Check for each:

  1. Can fungible_asset::zero(metadata) be used to trigger code paths that modify state? (e.g., register a user, set a flag, emit an event)
  2. Does fungible_asset::destroy_zero(fa) clean up properly, or does it leave dangling state?
  3. Can zero-value deposits/withdrawals:
    • Register a new FungibleStore where one shouldn't exist?
    • Trigger reward distribution checkpoints?
    • Bypass minimum deposit requirements (checked after or before deposit)?
    • Create entries in tracking data structures (SmartTable, vector)?
  4. Does amount == 0 get explicitly checked and rejected at entry points?

Pattern: Zero-value operations often bypass amount > 0 checks that were assumed but never written, allowing state modifications without economic cost.

STEP 3: Store Creation and Ownership Analysis

Audit FungibleStore creation, ownership chains, and access control:

3a. Store Creation Inventory
Store TypeCreated ByCreation Permissionless?OwnerCan Attacker Create?
Primary storeprimary_fungible_store::ensure_primary_store_exists()YES - anyone can create for any addressAddress ownerYES (for any address)
Custom storefungible_asset::create_store() on ConstructorRefOnly during object constructionObject ownerDepends on who can construct

CRITICAL: primary_fungible_store::ensure_primary_store_exists(addr, metadata) is permissionless. An attacker can create a primary store for ANY address for ANY metadata. If the protocol assumes a store's existence means the user has interacted with the protocol -> FINDING.

3b. Transitive Ownership
Object AOwns Object BB Has FungibleStoreA Can Withdraw from B?
{object}{child_object}YES/NOYES - via object ownership chain

Check: If Object A owns Object B which owns a FungibleStore, the owner of Object A can withdraw from B's store through the ownership chain. Trace all object ownership hierarchies for unintended fund access paths.

3c. Store Address Confusion
FunctionExpects Store AtActually Reads FromMatch?
{func}Protocol-controlled storeUser-supplied addressVERIFY

Pattern: Protocol calculates expected store address but user can supply a different store address. If the function doesn't verify the store belongs to the expected object/address -> FINDING.

STEP 4: Dispatchable Hook Analysis

If the protocol uses dispatchable FungibleAsset (custom withdraw, deposit, or derived_balance hooks):

4a. Hook Inventory
Hook TypeRegistered?Implementation ModuleCan Reenter?Can Revert?Can Manipulate?
withdrawYES/NO{module::func}ANALYZEANALYZEANALYZE
depositYES/NO{module::func}ANALYZEANALYZEANALYZE
derived_balanceYES/NO{module::func}ANALYZEN/AANALYZE
4b. Reentrancy via Hooks

For each registered hook:

  1. Does the hook call back into the registering module's public functions?
  2. Does the hook call into any other module that reads/writes shared state?
  3. Is #[module_lock] applied to the registering module? (prevents indirect reentrancy but NOT direct)
  4. What state has been modified BEFORE the hook executes? Can the hook see inconsistent state?

Reentrancy sequence:

Module::transfer() {
    1. Read balance (CHECK)
    2. Deduct from source store → triggers withdraw hook (INTERACTION before EFFECT completion)
    3. Withdraw hook reenters Module::another_function()
    4. another_function() sees partially-updated state
    // ...
}
4c. Deposit Hook Blocking

Can a deposit hook unconditionally revert to prevent deposits into a specific store?

  • If YES: can this be used to DoS the protocol? (e.g., prevent liquidations, block reward distribution)
  • Who controls the hook? (protocol, user, external party)
4d. Derived Balance Manipulation

If derived_balance hook is registered:

  1. Does the protocol call fungible_asset::balance(store) expecting the real balance?
  2. balance() calls derived_balance hook if registered - the returned value may differ from actual stored amount
  3. Can the hook return inflated values to trick the protocol? (e.g., appear to have more collateral)
  4. Can the hook return deflated values? (e.g., trigger incorrect liquidation)
STEP 5: Ref Safety Analysis

Audit the lifecycle and access control of FungibleAsset capability references:

5a. Ref Inventory
Ref TypeStored WhereWho Has AccessCan Be Extracted?Impact If Leaked
MintRef{object/resource}{module/address}YES/NOInfinite token minting
BurnRef{object/resource}{module/address}YES/NODestroy any user's tokens
TransferRef{object/resource}{module/address}YES/NOBypass freeze, forced transfers
FreezeRef{object/resource}{module/address}YES/NOFreeze any user's store

MANDATORY CHECK for each Ref:

  1. Is the Ref stored in a resource with key only? (safe - not extractable)
  2. Is the Ref stored in a struct with store ability? (dangerous - can be moved out)
  3. Is the Ref stored in an Object? Who owns the Object? Can ownership be transferred?
  4. Are there public functions that return the Ref or pass it to external code?
Show full SKILL.md (480 more words)Show less
5b. TransferRef Bypass Analysis

TransferRef allows transfers that bypass freeze status:

  1. Is there a TransferRef for the protocol's main token?
  2. Can TransferRef be used to force-transfer tokens FROM users? (fungible_asset::transfer_with_ref(ref, from_store, to_store, amount))
  3. Who holds the TransferRef? Is this documented as a trust assumption?
  4. Can TransferRef bypass any protocol-level transfer restrictions (not just freeze)?
5c. Ref Destruction Audit
Ref TypeCan Be Destroyed?Destruction FunctionConsequences of Destruction
MintRefNO (no destroy function)N/APermanent minting capability
BurnRefYES (burn_ref::destroy){if exists}Cannot burn tokens anymore
TransferRef{check}{if exists}Cannot force-transfer anymore
STEP 6: Coin-to-FA Migration Accounting

If the protocol handles both Coin<T> and FungibleAsset:

#CheckStatusImpact
1Are Coin and FA treated equivalently in balance accounting?YES/NO{if NO: describe discrepancy}
2Does total_supply track both representations?YES/NO{if NO: supply tracking broken}
3Can user deposit as Coin, then withdraw as FA (or vice versa), exploiting accounting difference?YES/NO{describe path}
4Are there functions that only accept Coin but credit FA internally (or vice versa)?YES/NO{conversion correct?}
5If protocol converts Coin<T> to FA: does coin::coin_to_fungible_asset() preserve exact amount?VERIFY{check for fees or rounding}

Pattern: When a protocol accepts both Coin<T> and FungibleAsset for the same underlying token, internal accounting that tracks only one representation can be exploited by depositing in one form and withdrawing in the other.

Key Questions (Must Answer All)

  1. Metadata validation: Does every FA-accepting function verify the asset type?
  2. Zero-value: Are zero-amount operations explicitly guarded?
  3. Store creation: Can permissionless store creation be exploited?
  4. Hooks: If dispatchable, can hooks reenter, block, or manipulate balances?
  5. Refs: Where are MintRef/BurnRef/TransferRef/FreezeRef stored, and who can access them?
  6. Coin-FA parity: If both types supported, is accounting consistent?

Common False Positives

  1. Framework-enforced metadata: Some framework functions internally validate metadata - verify before flagging
  2. Primary store determinism: Primary store addresses are deterministic (primary_fungible_store_address(owner, metadata)) - "unexpected address" may be intentional
  3. Intentional TransferRef usage: Protocol may document that TransferRef is needed for authorized transfers (e.g., liquidation)
  4. Zero-value guards in framework: Some framework functions (e.g., deposit) may already reject zero amounts internally - verify

Output Schema

markdown
## Finding [FA-N]: Title

**Verdict**: CONFIRMED / PARTIAL / REFUTED / CONTESTED
**Step Execution**: ✓1,2,3,4,5,6 | ✗N(reason) | ?N(uncertain)
**Rules Applied**: [R1:✓/✗, R4:✓/✗, R10:✓/✗, R11:✓/✗]
**Severity**: Critical/High/Medium/Low/Info
**Location**: module_name.move:LineN

**FA Component**: {metadata/store/hook/ref/accounting}
**Attack Vector**: {counterfeit deposit / reentrancy via hook / forced transfer via TransferRef / ...}

**Description**: What's wrong
**Impact**: What can happen (fund theft, accounting mismatch, DoS)
**Evidence**: Code snippets showing the vulnerability
**Recommendation**: How to fix

### Precondition Analysis (if PARTIAL/REFUTED)
**Missing Precondition**: [What blocks exploitation]
**Precondition Type**: STATE / ACCESS / TIMING / EXTERNAL / BALANCE

### Postcondition Analysis (if CONFIRMED/PARTIAL)
**Postconditions Created**: [What conditions this creates]
**Postcondition Types**: [List applicable types]
**Who Benefits**: [Who can use these]

Step Execution Checklist (MANDATORY)

StepRequiredCompleted?Notes
1. Metadata Validation AuditYES✓/✗/?Every FA-accepting function checked
2. Zero-Value ExploitationYES✓/✗/?
3. Store Creation and OwnershipYES✓/✗/?Primary store permissionless creation checked
3b. Transitive OwnershipYES✓/✗/?Object ownership chains traced
4. Dispatchable Hook AnalysisIF dispatchable FA used✓/✗(N/A)/?
4b. Reentrancy via HooksIF hooks registered✓/✗(N/A)/?
4c. Deposit Hook BlockingIF deposit hook registered✓/✗(N/A)/?
4d. Derived Balance ManipulationIF derived_balance hook✓/✗(N/A)/?
5. Ref Safety AnalysisYES✓/✗/?All 4 Ref types located and access traced
5b. TransferRef BypassIF TransferRef exists✓/✗(N/A)/?
6. Coin-to-FA Migration AccountingIF both Coin and FA supported✓/✗(N/A)/?

If any step skipped, document valid reason (N/A, no dispatchable hooks, no Coin support, no TransferRef).

© PlamenTSV, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in agents/skills/aptos/fungible-asset-security of PlamenTSV/plamen.

Open the folder on GitHubat commit 795962b

Compare with similar skills

Fungible Asset Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Fungible Asset Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Fungible Asset Security this skillPlamenTSV/plamen303—~3.3kAutomated safety check: PassMIT
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Skill Scannergetsentry/skills1k4 repos~2.5kAutomated safety check: WarnApache-2.0
Serenity Aleabitoreddityan-labs/serenity-aleabitoreddit4811 repos~3.3kAutomated safety check: PassNone
Security Alert Triageelastic/agent-skills5921 repos~3.5kAutomated safety check: NotesApache-2.0
Shiro Attack CLISummerSec/ShiroAttack22.6k—~945Automated safety check: PassMIT

Similar skills

  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 12 days ago
    SecurityAuto-check passed
  • Skill Scanner

    getsentry/skills

    Official

    Scan agent skills for security issues. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.5k tokens
    SecurityAuto-check: warnings
  • Serenity Aleabitoreddit

    yan-labs/serenity-aleabitoreddit

    Apply trader Serenity's (@aleabitoreddit) AI/semiconductor supply-chain analytical lens to US-stock ideas and market judgment.

    481 GitHub starsUsed in 1 repo~3.3k tokens
    SecurityAuto-check passed
  • Security Alert Triage

    elastic/agent-skills

    Official

    Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

    592 GitHub starsUsed in 1 repo~3.5k tokens
    SecurityAuto-check: notes
  • Shiro Attack CLI

    SummerSec/ShiroAttack2

    当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…

    2.6k GitHub stars~945 tokensUpdated 4 mo ago
    SecurityAuto-check passed
  • Cve Remediation

    rundeck/rundeck

    Verify if a CVE affects the project and remediate it. An agent skill from rundeck/rundeck.

    6.3k GitHub stars~2.9k tokensUpdated yesterday
    SecurityAuto-check passed

More from PlamenTSV/plamen

All 87 skills in this repo
  • Audit Prep

    PlamenTSV/plamen

    Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project…

    303 GitHub stars~3.7k tokensUpdated 14 days ago
    Auto-check passed
  • Verification Protocol

    PlamenTSV/plamen

    Trigger Pattern Always (used by all verifier agents) - Inject Into security-verifier agents (Phase 5)

    303 GitHub stars~3.5k tokensUpdated 14 days ago
    Auto-check passed
  • Ability Analysis

    PlamenTSV/plamen

    Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth agents, depth agents

    303 GitHub stars~3.3k tokensUpdated 14 days ago
    Auto-check passed
  • Ability Analysis

    PlamenTSV/plamen

    Trigger Pattern Always (Sui Move) -- foundational security check - Inject Into Breadth agents, depth agents

    303 GitHub stars~3.2k tokensUpdated 14 days ago
    Auto-check passed
  • Account Lifecycle

    PlamenTSV/plamen

    Trigger Pattern ACCOUNTCLOSING flag detected (close/CloseAccount usage) - Inject Into Breadth agents, depth agents

    303 GitHub stars~1.2k tokensUpdated 14 days ago
    Auto-check passed
  • Account Validation

    PlamenTSV/plamen

    Trigger Pattern Always required for Solana audits - Inject Into Breadth agents, depth agents

    303 GitHub stars~1.7k tokensUpdated 14 days ago
    Auto-check passed

Categories

Questions about Fungible Asset Security

What does Fungible Asset Security do?

Trigger FASTANDARD flag detected (protocol uses FungibleAsset standard) - Used by Breadth agents, depth-token-flow. Fungible Asset Security is an agent skill from PlamenTSV/plamen.

When should I use Fungible Asset Security?

Fungible Asset Security fits situations like: FASTANDARD flag detected (protocol uses FungibleAsset standard) - Used by Breadth agents; depth-token-flow.

How do I install Fungible Asset Security in Claude Code?

Run `npx skills add PlamenTSV/plamen --skill fungible-asset-security -a claude-code`. Or copy the skill folder (agents/skills/aptos/fungible-asset-security in PlamenTSV/plamen) into .claude/skills/fungible-asset-security in your project. Claude Code loads it when a task matches its description.

How do I install Fungible Asset Security in Codex?

Run `npx skills add PlamenTSV/plamen --skill fungible-asset-security -a codex`. Or copy the skill folder (agents/skills/aptos/fungible-asset-security in PlamenTSV/plamen) into .agents/skills/fungible-asset-security in your project. Codex loads it when a task matches its description.

Can I use Fungible Asset Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PlamenTSV/plamen --skill fungible-asset-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/fungible-asset-security, .gemini/skills/fungible-asset-security, .github/skills/fungible-asset-security and .opencode/skills/fungible-asset-security in your project.

What does Fungible Asset Security need to run?

SKILL.md names no scripts, command-line tools or credentials: Fungible Asset Security is instructions for the agent only.

Does Fungible Asset Security access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Fungible Asset Security safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Fungible Asset Security use?

Fungible Asset Security is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Fungible Asset Security use?

About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Fungible Asset Security?

Skills that share tags, products or a category with Fungible Asset Security: Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Skill Scanner (getsentry/skills, 1k stars), Serenity Aleabitoreddit (yan-labs/serenity-aleabitoreddit, 481 stars) and Security Alert Triage (elastic/agent-skills, 592 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Fungible Asset Security?

PlamenTSV (a GitHub user) maintains it in PlamenTSV/plamen, which has 303 GitHub stars. The repository holds 87 skills in this directory. The repository was last updated on September 26, 2026.

Source: PlamenTSV/plamen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.