Agent skill

Integration Hazard Research

by PlamenTSV in PlamenTSV/plamen

Protocol Type Trigger NAMEDEXTERNALPROTOCOL (detected when recon finds import/interface for an identifiable external protocol — not standard libraries).

MITAuto-check passedSecurity

Install Integration Hazard Research

skills CLI
$ npx skills add PlamenTSV/plamen --skill integration-hazard-research -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install PlamenTSV/plamen integration-hazard-research --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agents/skills/injectable/integration-hazard-research .claude/skills/integration-hazard-research && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
integration-hazard-research
GitHub stars
303
Token cost
~3.7k tokens
SKILL.md length
1,823 words
Files
1
Skills in repo
87
Repo updated
First seen
Licence
MIT

At a glance

Protocol Type Trigger NAMEDEXTERNALPROTOCOL (detected when recon finds import/interface for an identifiable external protocol — not standard libraries).

  • Works in 3 steps: Target Protocol Hazard Research → Third-Party Race Conditions → Integration State TOCTOU
  • NAMEDEXTERNALPROTOCOL (detected when recon finds import/interface for an identifiable external protocol — not standard libraries)
  • SKILL.md covers Orchestrator Decomposition Guide, When This Skill Activates, Processing Protocol (MANDATORY) and 0. Target Protocol Hazard…, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Integration Hazard Research is an agent skill from PlamenTSV/plamen. Protocol Type Trigger NAMEDEXTERNALPROTOCOL (detected when recon finds import/interface for an identifiable external protocol — not standard libraries). Researches known integration hazards of the target protocol.

Its SKILL.md is about 3.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security. The repository describes itself as: Autonomous Web3 security audit agent for Claude Code. The licence is MIT.

When your agent uses it

  • NAMEDEXTERNALPROTOCOL (detected when recon finds import/interface for an identifiable external protocol — not standard libraries)

Example prompts

  • “/integration-hazard-research”

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Target Protocol Hazard Research
  2. Third-Party Race Conditions
  3. Integration State TOCTOU

What it can do on your machine

Read from SKILL.md and the folder at commit 795962b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Integration Hazard Research loads about 3.7k tokens when it runs. Until then it costs about 61 tokens; SKILL.md has 1,823 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~61
When it runs · the whole SKILL.md, loaded when a task matches
~3.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from PlamenTSV/plamen at commit 795962b, republished under its MIT licence (© PlamenTSV). 1,823 words, ~3,692 tokens.

Download SKILL.mdSave it as .claude/skills/integration-hazard-research/SKILL.md (or your agent's skills folder).
name
integration-hazard-research
description
Protocol Type Trigger NAMED_EXTERNAL_PROTOCOL (detected when recon finds import/interface for an identifiable external protocol — not standard libraries). Researches known integration hazards of the target protocol.

Injectable Skill: Integration Hazard Research

Protocol Type Trigger: NAMED_EXTERNAL_PROTOCOL — detected when recon identifies imports or interface calls to a named external protocol (Uniswap, Aave, Balancer, Compound, Curve, Chainlink, Lido, MakerDAO, etc.) that is NOT a standard library (OpenZeppelin, solmate, solady) and NOT the protocol under audit itself. Inject Into: depth-external agent Language: All chains (EVM primary; Solana/Aptos/Sui when integrating with named on-chain protocols) Finding prefix: [IHR-N] Added in: v1.1.5

Orchestrator Decomposition Guide

This skill adds a research phase (Section 0) before depth-external's existing code analysis. All sections map to depth-external's domain. The orchestrator includes this skill in the depth-external agent's prompt when NAMED_EXTERNAL_PROTOCOL is flagged.

When decomposing into investigation questions:

  • Section 0 (research): produces a hazard catalog that informs all of depth-external's existing Sections 1-4
  • Section 1 (third-party race): extends depth-external Section 1 (side effects)
  • Section 2 (state TOCTOU): extends depth-external Section 4 (governance/parameter change)

When This Skill Activates

Recon Agent 3 detects named external protocol imports during TASK 6 pattern scanning. Indicators:

  • Named protocol interfaces: IUniswapV2Router, IUniswapV3Pool, IBalancerVault, IPool, IAToken, ICToken, ILendingPool, ICurvePool, IChainlinkAggregator, IStETH
  • Named protocol library imports: @uniswap/, @aave/, @balancer-labs/, @chainlink/, @openzeppelin/ (only when calling protocol-specific functions, not generic utilities)
  • Solana: CPI targets to known program IDs (Jupiter, Marinade, Raydium, Orca, Drift)
  • Sui: external package calls to known protocols (Cetus, DeepBook, Suilend, NAVI)
  • Aptos: external module calls to known protocols (Thala, Echelon, Liquidswap, PancakeSwap)
  • Soroban: cross-contract calls to known protocols (SoroSwap, Blend Protocol, Phoenix DEX, Aqua Network, OrbitCDP)

The flag records which protocols were detected: NAMED_EXTERNAL_PROTOCOL: [Uniswap V3, Chainlink]


Processing Protocol (MANDATORY)

For each section below, execute in order:

  1. ENUMERATE targets: List every entity the section applies to (external protocols, hazard catalog entries, race condition candidates, TOCTOU pairs) as a numbered list before analysis begins.
  2. PROCESS exhaustively: Analyze each numbered entity. Mark each "DONE" or "N/A (reason)" before moving to the next.
  3. COVERAGE GATE: Count enumerated vs processed. If any entity lacks a marker, process it before proceeding to the next section.

0. Target Protocol Hazard Research

For EACH named external protocol detected by recon:

0a. Read the Recon-Baked External Dependency Research Ledger (PRIMARY — MANDATORY)

DO NOT call mcp__unified-vuln-db__search_solodit_live or any tavily/web-search MCP tool for dependency research. They are unavailable in depth-phase subagent contexts — the driver launches depth workers with --disallowedTools mcp__* and an empty MCP server config to prevent cold-start hangs. Any Solodit/Tavily MCP call in this phase will silently fail or hang; do not attempt it.

Read {SCRATCHPAD}/external_dependency_research.md instead. This is the recon-baked research ledger: recon runs as a phase-LLM with live WebSearch/WebFetch/tavily_search access and already researched every detected external dependency's real interface/semantics (deployed source, ABI/arity, monotonicity, gas/error behavior) before depth ever runs. For each target protocol/dependency, find its row: Dependency | Integration Surface (file:line) | Assumed Behavior (as coded) | Real Behavior (researched) | Source (URL + fetch date) | Conformance MATCH/MISMATCH/CHECK | Fetch Status OK/FETCH_FAILED:reason. Use the ledger's Real Behavior / Conformance columns as your hazard-catalog input for Section 0c below instead of live search results.

0b. Escalate Uncovered Surfaces — Do Not Guess (MANDATORY)

For an integration surface in your target that is NOT covered by any ledger row (a dependency the ledger missed, or a row with Fetch Status: FETCH_FAILED), do NOT guess the real behavior and do NOT silently fall through to the 0d floor catalog as if it were live research. Emit, in your finding output, one escalation line per uncovered surface:

NEEDS_DEPENDENCY_RESEARCH: <dependency>:<file:line>: <what you need to know>

Then proceed under the assumed WORST-CASE realistic external condition per Rule 10 (rules/finding-output-format.md), tagging the finding [EXTERNAL-ASSUMPTION: <assumed condition>]. Note: native WebSearch/ WebFetch (non-MCP Claude Code tools) remain available if you need a single targeted check beyond the ledger — but the ledger is the primary source and should cover the large majority of surfaces; ad-hoc web search is not a substitute for reading it first.

0c. Compile Hazard Catalog
Target ProtocolKnown Integration HazardSeverityRoot CauseSourceApplicable to This Integration?
{protocol}{hazard title}{sev}{brief root cause}{ledger row dependency name / URL from external_dependency_research.md}YES / NO / CHECK

Applicability criteria (same as FORK_ANCESTRY):

  • YES: The audited code calls the function or reads the state involved in this hazard
  • NO: The audited code does not interact with the affected function/state (document why)
  • CHECK: Cannot determine without deeper analysis — flag for depth trace
0c-bis. Asset-Form Delivery Check (MANDATORY for every bridge/gateway/router callback + outbound deposit/withdraw)

Cross-chain gateways frequently deliver the gas token in a DIFFERENT FORM than the handler assumes — native vs wrapped (e.g. ETH vs WETH). This is an asset-FORM mismatch, distinct from the asset-IDENTITY (declared-output-token vs delivered-token) mismatch. For EACH inbound callback (onCall/onReceive/onRevert/router callback) and EACH outbound deposit/withdraw:

  1. From the external protocol's docs/source, determine whether it DELIVERS/EXPECTS the asset in NATIVE or WRAPPED form (many gas-token bridges auto-unwrap to native on delivery and auto-wrap on send).
  2. Assert the handler's FIRST value-moving op matches that form: a wrapped-ERC20 approve/transferFrom/swap requires the asset to already be wrapped; a .call{value:}/native send requires it to be native.
  3. RED FLAG → emit a CHECK candidate (never a silent UNVERIFIED): the callback names a wrapped-token address as the asset param but the handler moves it via ERC20 approve/transfer with NO deposit{value:}/withdraw() reconciliation (or vice-versa). The missing inbound native→wrapped (or wrapped→native) conversion is a candidate asset-form mismatch — verify reachability and impact.
  4. If the delivery form cannot be confirmed from docs/source, escalate to a CHECK candidate for depth tracing — do NOT drop it as UNVERIFIED.
Show full SKILL.md (936 more words)Show less
0d. Hardcoded Hazard Floor (TERTIARY FALLBACK — ledger-miss only, NOT the default)

This floor is a coarse last resort, not a substitute for 0a. Use it ONLY when BOTH hold: (1) external_dependency_research.md has no row for the dependency (or the row is Fetch Status: FETCH_FAILED), AND (2) you have already emitted the matching NEEDS_DEPENDENCY_RESEARCH escalation line for it per 0b. Do NOT reach for this table as a first move, and do NOT treat a hit here as equivalent to a live-researched ledger row — it only lists historical bug classes for a fixed list of famous protocols, not the dependency's current real interface/semantics. Check EACH applicable protocol against this minimum catalog:

This floor is keyed on the dependency's TYPE (generic mechanism), NOT on any specific protocol name — brand-keyed rows are prohibited (a floor row naming a specific protocol is the confirmed benchmark-contamination vector; see the HARD no-overfit rule). Classify the detected dependency into a type below and check the generic hazard class; use at most one illustrative brand only in prose, never as the row key.

Dependency TypeGeneric Integration Hazard (class)Check For
AMM / swap poolSlippage bypass when min-out may be 0; stale TWAP/observation read from an inactive pool; read-only reentrancy via pool-balance views during a callbackany swap call with zero/unbounded slippage; a price/observation read with no freshness assertion; a balance query during or after the external interaction
Lending / money marketFirst-depositor / empty-market exchange-rate rounding; flash-borrow-driven oracle shift within one tx; governance-mutable collateral factor assumed constantreceipt-token interaction at low total supply; an oracle read after interacting with the dependency; a hardcoded LTV / collateral factor
Oracle / price feedStale price (publisher or L2-sequencer downtime) consumed without a max-staleness check; confidence / exponent field ignored; feed or aggregator address assumed permanenta price read with no freshness/staleness bound; use of the price without checking its confidence/exponent; a hardcoded feed address
Bridge / cross-chain messengerDelivered value in a different FORM than the handler assumes (native vs wrapped auto-(un)wrap); message/return arity or ABI differing from the vendored interface; zero- or underfunded-gas send that "succeeds" without deliverythe inbound native↔wrapped conversion is present and the first value-moving op's form matches the delivered form; the real deployed message signature vs the vendored trait; the messenger's zero-gas success semantics
Staking / rebasing tokenBalance changing between blocks with no transfer (rebase) used as an accounting input; share↔underlying conversion rate assumed constanta balanceOf used as accounting that can rebase; a hardcoded or cached conversion rate
Delayed-claim / epoch ticketState claimable only after an epoch/time boundary read as if immediately availableticket/order state reads across an epoch or time boundary
Concentrated-liquidity / order-book DEXTick-density gas-exhaustion DoS on swap; permissionless cancellation of an order a third party can raceswap calls into narrow-tick pools; reading order/position state a third party can cancel or mutate

Note: This floor lists generic hazard CLASSES by dependency type only — it is minimum coverage, not exhaustive, and NOT a substitute for the live-researched ledger (0a). Real research typically surfaces several more hazards specific to the actual dependency.

0e. Record Research Results

Write the hazard catalog to {SCRATCHPAD}/integration_hazard_catalog.md. This file is consumed by:

  • depth-external (this agent) for Sections 1-4 analysis
  • Chain analysis for enabler enumeration (integration hazards may create preconditions for other findings)

1. Third-Party Race Conditions

For each YES/CHECK hazard in the catalog, ask:

Permissionless function race: Does the target protocol expose permissionless functions that modify state the audited code depends on? Can a third party call that function between the audited code's transactions?

Target FunctionPermissionless?State ModifiedOur Code Reads This State?Race Window
{function}YES/NO{state var}{where our code reads it}{blocks/time}

For each race with Permissionless=YES AND Our Code Reads=YES:

  • Trace what happens if the third party acts first. Does our code read stale/zeroed state?
  • Is the race atomic (same block) or cross-block?
  • Can our code detect and recover, or is the damage permanent?

Tag: [TRACE:third_party_call({target_function}) → our_read({our_function}) → state_is={stale/zeroed/modified} → impact={loss/revert/incorrect_accounting}]


2. Integration State TOCTOU

For each external state the audited code reads:

State ReadRead LocationUsed AtTime Between Read and UseCan State Change In Window?
{value}{our function:line}{downstream use:line}{same tx / cross-tx / cross-block}YES/NO

For each Can Change=YES:

  • What changes it? (governance, permissionless function, oracle update, rebase, fee accrual)
  • What is the worst-case delta in realistic conditions?
  • Does the audited code have a freshness check or snapshot mechanism?

Tag: [VARIATION:external_state({value}) fresh_at_read=X → stale_at_use=Y → delta={amount} → impact={consequence}]


Common False Positives

  • Hazard catalog hit with NO matching code path: A known hazard exists for Protocol X, but the audited code never calls the affected function or reads the affected state. Do NOT report.
  • Permissionless function race with atomic protection: If the audited code reads and uses external state within a single transaction AND verifies the result (e.g., slippage check, balance delta), the race window is zero. Do NOT report.
  • State TOCTOU with governance-only trigger: If external state can only change via governance (timelock, multisig), and the audited code operates on a per-transaction timescale, the TOCTOU risk is informational at most.

Coverage assertion: Before returning, verify every entity enumerated under each section has been processed. Report enumerated vs analyzed counts in your return message.

Step Execution Checklist (MANDATORY)

SectionRequiredCompleted?Notes
0a. Ledger read (external_dependency_research.md) per target dependencyYES — no MCP callsY/N/?
0b. NEEDS_DEPENDENCY_RESEARCH emitted for every ledger-uncovered surfaceYES for each uncovered surfaceY/N/?
0c. Hazard catalog compiledYESY/N/?
0d. Floor catalog checked (TERTIARY — ledger-miss AND 0b escalation only)IF 0a had no row AND 0b escalatedY/N/?
0e. integration_hazard_catalog.md writtenYESY/N/?
1. Third-party race conditionsFOR EACH YES/CHECK hazardY/N/?
2. Integration state TOCTOUFOR EACH external state readY/N/?

© PlamenTSV, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in agents/skills/injectable/integration-hazard-research of PlamenTSV/plamen.

Open the folder on GitHubat commit 795962b

Compare with similar skills

Integration Hazard Research next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Integration Hazard Research compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Integration Hazard Research this skillPlamenTSV/plamen303—~3.7kAutomated safety check: PassMIT
Fla Ascend Performancefla-org/flash-linear-attention5.8k—~6.3kAutomated safety check: PassMIT
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Skill Scannergetsentry/skills1k4 repos~2.5kAutomated safety check: WarnApache-2.0
Serenity Aleabitoreddityan-labs/serenity-aleabitoreddit4811 repos~3.3kAutomated safety check: PassNone
Security Alert Triageelastic/agent-skills5921 repos~3.5kAutomated safety check: NotesApache-2.0

Similar skills

  • Fla Ascend Performance

    fla-org/flash-linear-attention

    Guidelines for Ascend NPU kernel / Triton-Ascend backend performance work in the FLA repo.

    5.8k GitHub stars~6.3k tokensUpdated today
    SecurityAuto-check passed
  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 10 days ago
    SecurityAuto-check passed
  • Skill Scanner

    getsentry/skills

    Official

    Scan agent skills for security issues. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.5k tokens
    SecurityAuto-check: warnings
  • Serenity Aleabitoreddit

    yan-labs/serenity-aleabitoreddit

    Apply trader Serenity's (@aleabitoreddit) AI/semiconductor supply-chain analytical lens to US-stock ideas and market judgment.

    481 GitHub starsUsed in 1 repo~3.3k tokens
    SecurityAuto-check passed
  • Security Alert Triage

    elastic/agent-skills

    Official

    Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

    592 GitHub starsUsed in 1 repo~3.5k tokens
    SecurityAuto-check: notes
  • Shiro Attack CLI

    SummerSec/ShiroAttack2

    当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…

    2.6k GitHub stars~945 tokensUpdated 4 mo ago
    SecurityAuto-check passed

More from PlamenTSV/plamen

All 87 skills in this repo
  • Audit Prep

    PlamenTSV/plamen

    Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project…

    303 GitHub stars~3.7k tokensUpdated 13 days ago
    Auto-check passed
  • Verification Protocol

    PlamenTSV/plamen

    Trigger Pattern Always (used by all verifier agents) - Inject Into security-verifier agents (Phase 5)

    303 GitHub stars~3.5k tokensUpdated 13 days ago
    Auto-check passed
  • Ability Analysis

    PlamenTSV/plamen

    Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth agents, depth agents

    303 GitHub stars~3.3k tokensUpdated 13 days ago
    Auto-check passed
  • Ability Analysis

    PlamenTSV/plamen

    Trigger Pattern Always (Sui Move) -- foundational security check - Inject Into Breadth agents, depth agents

    303 GitHub stars~3.2k tokensUpdated 13 days ago
    Auto-check passed
  • Account Lifecycle

    PlamenTSV/plamen

    Trigger Pattern ACCOUNTCLOSING flag detected (close/CloseAccount usage) - Inject Into Breadth agents, depth agents

    303 GitHub stars~1.2k tokensUpdated 13 days ago
    Auto-check passed
  • Account Validation

    PlamenTSV/plamen

    Trigger Pattern Always required for Solana audits - Inject Into Breadth agents, depth agents

    303 GitHub stars~1.7k tokensUpdated 13 days ago
    Auto-check passed

Categories

Questions about Integration Hazard Research

What does Integration Hazard Research do?

Protocol Type Trigger NAMEDEXTERNALPROTOCOL (detected when recon finds import/interface for an identifiable external protocol — not standard libraries). Integration Hazard Research is an agent skill from PlamenTSV/plamen. Protocol Type Trigger NAMEDEXTERNALPROTOCOL (detected when recon finds import/interface for an identifiable external protocol — not standard libraries).

When should I use Integration Hazard Research?

Integration Hazard Research fits situations like: NAMEDEXTERNALPROTOCOL (detected when recon finds import/interface for an identifiable external protocol — not standard libraries).

How do I install Integration Hazard Research in Claude Code?

Run `npx skills add PlamenTSV/plamen --skill integration-hazard-research -a claude-code`. Or copy the skill folder (agents/skills/injectable/integration-hazard-research in PlamenTSV/plamen) into .claude/skills/integration-hazard-research in your project. Claude Code loads it when a task matches its description.

How do I install Integration Hazard Research in Codex?

Run `npx skills add PlamenTSV/plamen --skill integration-hazard-research -a codex`. Or copy the skill folder (agents/skills/injectable/integration-hazard-research in PlamenTSV/plamen) into .agents/skills/integration-hazard-research in your project. Codex loads it when a task matches its description.

Can I use Integration Hazard Research in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PlamenTSV/plamen --skill integration-hazard-research -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/integration-hazard-research, .gemini/skills/integration-hazard-research, .github/skills/integration-hazard-research and .opencode/skills/integration-hazard-research in your project.

What does Integration Hazard Research need to run?

SKILL.md names no scripts, command-line tools or credentials: Integration Hazard Research is instructions for the agent only.

Does Integration Hazard Research access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Integration Hazard Research safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Integration Hazard Research use?

Integration Hazard Research is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Integration Hazard Research use?

About 3.7k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Integration Hazard Research?

Skills that share tags, products or a category with Integration Hazard Research: Fla Ascend Performance (fla-org/flash-linear-attention, 5.8k stars), Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Skill Scanner (getsentry/skills, 1k stars) and Serenity Aleabitoreddit (yan-labs/serenity-aleabitoreddit, 481 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Integration Hazard Research?

PlamenTSV (a GitHub user) maintains it in PlamenTSV/plamen, which has 303 GitHub stars. The repository holds 87 skills in this directory. The repository was last updated on September 26, 2026.

Source: PlamenTSV/plamen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.