Web3 Transaction Relayer Pool
sickn33/agentic-awesome-skills
Gasless transaction relayer node pool register: fee sponsorship limits, nonce synchronization, and balance replenishment alerts.
L1 trigger - audits mempool / transaction pool for eviction asymmetries, replacement policy abuse, blob-pool exhaustion, and DETER-class denial of service.
$ npx skills add PlamenTSV/plamen --skill mempool-asymmetric-dos -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install PlamenTSV/plamen mempool-asymmetric-dos --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agents/skills/injectable/l1/mempool-asymmetric-dos .claude/skills/mempool-asymmetric-dos && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "mempool-asymmetric-dos" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/injectable/l1/mempool-asymmetric-dos into .claude/skills/mempool-asymmetric-dos/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mempool-asymmetric-dos", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/PlamenTSV/plamen/tree/main/agents/skills/injectable/l1/mempool-asymmetric-dosType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add PlamenTSV/plamen --skill mempool-asymmetric-dos -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install PlamenTSV/plamen mempool-asymmetric-dos --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .agents/skills && cp -r skills-src/agents/skills/injectable/l1/mempool-asymmetric-dos .agents/skills/mempool-asymmetric-dos && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "mempool-asymmetric-dos" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/injectable/l1/mempool-asymmetric-dos into .agents/skills/mempool-asymmetric-dos/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mempool-asymmetric-dos", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add PlamenTSV/plamen --skill mempool-asymmetric-dos -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install PlamenTSV/plamen mempool-asymmetric-dos --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/agents/skills/injectable/l1/mempool-asymmetric-dos .cursor/skills/mempool-asymmetric-dos && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "mempool-asymmetric-dos" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/injectable/l1/mempool-asymmetric-dos into .cursor/skills/mempool-asymmetric-dos/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mempool-asymmetric-dos", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/PlamenTSV/plamen.git --path agents/skills/injectable/l1/mempool-asymmetric-dos--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add PlamenTSV/plamen --skill mempool-asymmetric-dos -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install PlamenTSV/plamen mempool-asymmetric-dos --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/agents/skills/injectable/l1/mempool-asymmetric-dos .gemini/skills/mempool-asymmetric-dos && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "mempool-asymmetric-dos" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/injectable/l1/mempool-asymmetric-dos into .gemini/skills/mempool-asymmetric-dos/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mempool-asymmetric-dos", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install PlamenTSV/plamen mempool-asymmetric-dosInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add PlamenTSV/plamen --skill mempool-asymmetric-dos -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .github/skills && cp -r skills-src/agents/skills/injectable/l1/mempool-asymmetric-dos .github/skills/mempool-asymmetric-dos && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "mempool-asymmetric-dos" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/injectable/l1/mempool-asymmetric-dos into .github/skills/mempool-asymmetric-dos/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mempool-asymmetric-dos", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add PlamenTSV/plamen --skill mempool-asymmetric-dos -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install PlamenTSV/plamen mempool-asymmetric-dos --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/agents/skills/injectable/l1/mempool-asymmetric-dos .opencode/skills/mempool-asymmetric-dos && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "mempool-asymmetric-dos" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/injectable/l1/mempool-asymmetric-dos into .opencode/skills/mempool-asymmetric-dos/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mempool-asymmetric-dos", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
mempool-asymmetric-dosL1 trigger - audits mempool / transaction pool for eviction asymmetries, replacement policy abuse, blob-pool exhaustion, and DETER-class denial of service.
Mempool Asymmetric Dos is an agent skill from PlamenTSV/plamen. L1 trigger - audits mempool / transaction pool for eviction asymmetries, replacement policy abuse, blob-pool exhaustion, and DETER-class denial of service.
Its SKILL.md is about 3.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
The repository describes itself as: Autonomous Web3 security audit agent for Claude Code. The licence is MIT.
10 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 795962b. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
arxiv.orgtristartom.github.iousenix.orgmedium.comgithub.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Mempool Asymmetric Dos loads about 3.7k tokens when it runs. Until then it costs about 45 tokens; SKILL.md has 1,770 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from PlamenTSV/plamen at commit 795962b, republished under its MIT licence (© PlamenTSV). 1,770 words, ~3,672 tokens.
.claude/skills/mempool-asymmetric-dos/SKILL.md (or your agent's skills folder).L1 trigger:
L1_PATTERN=trueAND (txpool/ORmempool/ORtx_poolORblob_poolORreth-transaction-pooldetected in recon subsystem map) Inject Into:depth-network-surfaceordepth-state-traceLanguage: Go and Rust Finding prefix:[MP-N]Status: v0.1 draft, Round 4 exemplars pending
Recon identifies a mempool module. Mempools are uniquely exposed: every RPC client and every peer can insert transactions. The DETER paper (USENIX CCS '21) and MemPurge follow-ups showed that most production mempools had asymmetric cost models exploitable at near-zero attacker cost.
The DETER insight: if an attacker can insert transactions with lower cost than it takes to evict them, they can fill the pool faster than honest transactions can reclaim space.
For each mempool:
insert_cost / eviction_cost. If this is much less than 1, the pool is asymmetric.Specific patterns:
Transactions that are initially accepted into the pool but will later fail validation (nonce gap, insufficient balance, invalid signature for a new state root). These cost the attacker 0 but occupy space until the validator reprocesses them.
Check: Look for a "pending" vs "valid" split. When is validity re-checked? Can an attacker keep an invalid tx in "pending" indefinitely?
A transaction with a nonce 100 above the current nonce is "futureNonce" — it occupies space waiting for the lower-nonce gap to fill. Attacker sends 99 futureNonce placeholders + never sends the gap-filler.
Check: Is there a cap on futureNonce slots per account? What's the eviction policy when the cap is hit? Is the cap per-account or shared?
If an attacker can replace a low-fee tx with a slightly-higher-fee tx indefinitely, they churn pool state and cost honest reorganization work. The Bitcoin min_relay_fee_increment and Ethereum's 10% bump rule address this — verify the implementation.
Check: What is the minimum fee bump for replacement? Is it enforced cumulatively (across multiple replacements) or only per-replacement?
Blob transactions have a separate gas market (blob_gas_price). If the blob pool eviction uses only blob-gas-price but insertion is cheap (or the pool is not strictly separated from legacy), asymmetric exploitation is possible.
Check: Is the blob pool size-capped independently of the main pool? Can an attacker spam blobs to evict legacy txs or vice versa?
Tag: [MP-ASYMMETRIC:{insert-cost}:{eviction-cost}:{ratio}]
When the pool is full, which transaction gets evicted?
Tag: [MP-EVICT:{policy}:{gap}]
A mempool bug is worse if the bad transaction propagates:
Tag: [MP-PROPAGATE:{behavior}]
For transactions that do make it into blocks, the ordering algorithm affects MEV and fairness:
Tag: [BLOB:{concern}:{bound}]
| State | Test | Expected | Observed |
|---|---|---|---|
| Empty pool | first tx inserted | accepted | |
| Full pool, same-fee tx | new tx with equal fee | rejected (no displacement) | |
| Full pool, 10% higher fee | new tx with RBF-threshold fee | old tx evicted, new accepted | |
| Same-sender N txs | sender sends pool_cap+1 txs | oldest or lowest-fee evicted; sender not DoSed | |
| futureNonce only | attacker fills with gap transactions | cap enforced; pool does not grow unbounded | |
| Invalid sig batch | 1000 txs with invalid sigs | all rejected quickly; peer scored | |
| Blob size cap | blobs sum to > cap | excess rejected |
Tag: [BOUNDARY:mempool:{state}:{result}]
[FUZZ-PASS] (parameterized pool harness) > [LSP-TRACE] > [CODE-TRACE]DETER — Geth and 4 other Ethereum clients (USENIX CCS '21 + USENIX Security '24) — asymmetric eviction. Attackers send "future" nonce or "latent overdraft" transactions that pass cheap admission checks but are invalid at execution time. They fill the mempool and evict valid victim transactions at much lower cost to attacker than damage caused. Fixed in all major Ethereum clients as of Fall 2023. Mempool Symbolic Fuzzing USENIX '24; DETER 2.0. Skill catch point: Section 1 — the core asymmetry invariant. Insertion cost ≥ eviction damage.
MemPurge — Geth pending pool (USENIX '24) — chain-of-txs eviction. Attacker sends chain of ≤65 transactions that appear valid but become invalid after first executes. Attacker pays for only 1 tx worth of fees but evicts 65 honest txs. Combined with ConditionalExhaust, total attack cost ≈ $376 for full pool replacement. Speculative DoS paper; Yaish summary. Skill catch point: Section 1b — model multi-tx transitive validity; admission of tx_1 must account for worst-case state after tx_1 executes, not current state.
Geth GetHeadersFrom integer underflow (CVE-2024-32972) — GetHeadersFrom(number, count uint64) received count-1 where count was 0, producing UINT64_MAX and bypassing maxHeadersServe. Single p2p request forced node to stream all headers from latest back to genesis. GHSA-4xc9-8hmq-j652; fix in PR #29534, shipped v1.13.15. Skill catch point: boundary substitution — every p2p request handler with a count/range parameter must have underflow guard (subtraction below 0), overflow guard (u64 wraparound), and upper bound enforcement after arithmetic, not before. (Shared with p2p-dos-and-eclipse.)
Insert as new Section 1e (MANDATORY invariant): For every mempool, quantify:
insert_cost = minimum resource expenditure to place one tx in the pool
(accounts for: fee, stake, gas, bandwidth, all admission gates)
eviction_damage = maximum resource removal this tx can cause
(accounts for: bytes freed, slot evictions, state churn, propagation)Invariant: insert_cost ≥ eviction_damage for every admission path.
Check:
Tag: [MP-COST-RATIO:{insert_cost}:{eviction_damage}:{ratio}]
Ratios < 1 are CRITICAL; ratios just above 1 are High (a small-margin attacker can still cause damage under peak load).
When a block can contain MULTIPLE transaction types (regular data tx, commitment tx, system tx, deposit, slashing, governance, oracle update, etc.), each type needs its OWN count cap. A single max_txs_per_block applied uniformly is insufficient — one attacker-controlled free tx type can flood blocks while "expensive" types are correctly bounded.
Methodology:
data_ledgers, commitment_txs, system_txs, slashings, deposits, attestations, seal_operations.len(txs) <= MaxTxPerBlock but another type has no per-type cap (only the total byte cap), the unbounded type is a DoS vector — especially if the unbounded type is cheap to produce (no signature fee, no stake requirement, free-to-spam).Required artifact: {SCRATCHPAD}/tx_type_caps.md:
| Tx Type | Field name | Per-type cap? | Cap value | Cost per tx | Spam risk |
|---|---|---|---|---|---|
| Regular data tx | `data_ledgers[].txs` | YES | MaxTxPerBlock=5000 | signature + state write | OK |
| Commitment tx | `commitment_txs` | **NO** | — | signature only (cheap) | **HIGH — no cap** |
| System tx | `system_txs` | YES | MaxSystemPerBlock=16 | none (privileged) | OK if validated |
| Slashing evidence | `slashings` | YES | MaxSlashPerBlock=32 | free to submit | OK |Every "NO" in the "Per-type cap?" column is a finding — severity is at least High when the type is cheap to produce and propagates through p2p (commitment txs, attestations, gossip messages). A cap enforced only at production or only at validation is also a finding.
Tag: [MP-NO-PER-TYPE-CAP:{tx_type}]
CometBFT/Tendermint mempools are FIFO by default; a priority mempool exists but must be explicitly configured and implemented correctly. FIFO ordering enables ordering games (an observer races a target tx by submitting earlier), and either ordering mode can STARVE critical low-volume messages (oracle price updates, emergency pause, slashing evidence) behind a flood of cheap txs.
Bounded reads: read SCIP graph artifacts (caller_map.md, callee_map.md, state_write_map.md, function_summary.md) to find mempool insert/reap call-sites and any priority assignment; on-demand single-symbol source reads for the CheckTx/reap/priority functions only; never bulk-read large files.
Heuristics:
mempool.Priority, priority, ReapMaxBytesMaxGas, CheckTx, Mempool, recheck, fifo. Identify whether the mempool is FIFO or priority-based.mempool.Priority is set in CheckTx, verify the priority is derived from a non-attacker-gameable signal (validated fee/stake), not from a self-declared field a sender can inflate for free.Severity: starvation of an oracle/pause/evidence message is High–Critical (stale price / un-haltable incident / missed slashing); ordering front-run is Medium–High per the affected app path.
Tag: [MP-FIFO-FRONTRUN:{path}], [MP-CRITICAL-STARVE:{msg-type}]
Add / insert / add_transaction functionpop / evict / remove functionp2p-dos-and-eclipse (peer scoring interaction), rpc-surface-audit (RPC eth_sendRawTransaction is an insertion path), execution-client-hardeningdepth-network-surface, depth-state-tracedocs/l1-mode/severity-matrix.md© PlamenTSV, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in agents/skills/injectable/l1/mempool-asymmetric-dos of PlamenTSV/plamen.
Open the folder on GitHubat commit 795962b
Mempool Asymmetric Dos next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Mempool Asymmetric Dos this skillPlamenTSV/plamen | 303 | — | ~3.7k | Automated safety check: Pass | MIT | |
| Web3 Transaction Relayer Poolsickn33/agentic-awesome-skills | 47k | 1 repos | ~1.3k | Automated safety check: Pass | MIT | |
| Production Auditaffaan-m/ECC | 276k | 1 repos | ~1.9k | Automated safety check: Pass | MIT | |
| Aims Auditalirezarezvani/claude-skills | 28k | — | ~1.3k | Automated safety check: Pass | MIT | |
| Eviction Policy Regret Auditben-manes/caffeine | 18k | — | ~16k | Automated safety check: Notes | Apache-2.0 | |
| Geo Auditsickn33/agentic-awesome-skills | 47k | 1 repos | ~3.4k | Automated safety check: Notes | MIT |
sickn33/agentic-awesome-skills
Gasless transaction relayer node pool register: fee sponsorship limits, nonce synchronization, and balance replenishment alerts.
affaan-m/ECC
Local-evidence production readiness audit for shipped apps, pre-launch reviews, post-merge checks, and "what breaks in prod?" questions without sending repo data to an external audit service.
alirezarezvani/claude-skills
/cs:aims-audit <scope — ISO/IEC 42001 AIMS internal-audit 6-question forcing interrogation.
ben-manes/caffeine
Searches synthetic workloads for cases where Caffeine's adaptive eviction policy falls short of its achievable hit rate, then classifies each gap by cause.
sickn33/agentic-awesome-skills
Full website GEO+SEO audit with parallel subagent delegation.
diegosouzapw/OmniRoute
Command reference for omniroute's audit, logs, policy and telemetry commands: search and export audit trails, manage access policies and review request history for compliance work.
PlamenTSV/plamen
Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project…
PlamenTSV/plamen
Trigger Pattern Always (used by all verifier agents) - Inject Into security-verifier agents (Phase 5)
PlamenTSV/plamen
Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth agents, depth agents
PlamenTSV/plamen
Trigger Pattern Always (Sui Move) -- foundational security check - Inject Into Breadth agents, depth agents
PlamenTSV/plamen
Trigger Pattern ACCOUNTCLOSING flag detected (close/CloseAccount usage) - Inject Into Breadth agents, depth agents
PlamenTSV/plamen
Trigger Pattern Always required for Solana audits - Inject Into Breadth agents, depth agents
L1 trigger - audits mempool / transaction pool for eviction asymmetries, replacement policy abuse, blob-pool exhaustion, and DETER-class denial of service. Mempool Asymmetric Dos is an agent skill from PlamenTSV/plamen. L1 trigger - audits mempool / transaction pool for eviction asymmetries, replacement policy abuse, blob-pool exhaustion, and DETER-class denial of service.
Mempool Asymmetric Dos fits situations like: - audits mempool / transaction pool for eviction asymmetries; replacement policy abuse; blob-pool exhaustion; DETER-class denial of service.
Run `npx skills add PlamenTSV/plamen --skill mempool-asymmetric-dos -a claude-code`. Or copy the skill folder (agents/skills/injectable/l1/mempool-asymmetric-dos in PlamenTSV/plamen) into .claude/skills/mempool-asymmetric-dos in your project. Claude Code loads it when a task matches its description.
Run `npx skills add PlamenTSV/plamen --skill mempool-asymmetric-dos -a codex`. Or copy the skill folder (agents/skills/injectable/l1/mempool-asymmetric-dos in PlamenTSV/plamen) into .agents/skills/mempool-asymmetric-dos in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PlamenTSV/plamen --skill mempool-asymmetric-dos -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/mempool-asymmetric-dos, .gemini/skills/mempool-asymmetric-dos, .github/skills/mempool-asymmetric-dos and .opencode/skills/mempool-asymmetric-dos in your project.
SKILL.md names no scripts, command-line tools or credentials: Mempool Asymmetric Dos is instructions for the agent only.
SKILL.md names 5 domains. As links in the text: arxiv.org, tristartom.github.io, usenix.org, medium.com and github.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Mempool Asymmetric Dos is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.7k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Mempool Asymmetric Dos: Web3 Transaction Relayer Pool (sickn33/agentic-awesome-skills, 47k stars), Production Audit (affaan-m/ECC, 276k stars), Aims Audit (alirezarezvani/claude-skills, 28k stars) and Eviction Policy Regret Audit (ben-manes/caffeine, 18k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
PlamenTSV (a GitHub user) maintains it in PlamenTSV/plamen, which has 303 GitHub stars. The repository holds 87 skills in this directory. The repository was last updated on September 26, 2026.
Source: PlamenTSV/plamen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.