Agent skill

Mempool Asymmetric Dos

by PlamenTSV in PlamenTSV/plamen

L1 trigger - audits mempool / transaction pool for eviction asymmetries, replacement policy abuse, blob-pool exhaustion, and DETER-class denial of service.

MITAuto-check passed

Install Mempool Asymmetric Dos

skills CLI
$ npx skills add PlamenTSV/plamen --skill mempool-asymmetric-dos -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install PlamenTSV/plamen mempool-asymmetric-dos --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agents/skills/injectable/l1/mempool-asymmetric-dos .claude/skills/mempool-asymmetric-dos && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
mempool-asymmetric-dos
GitHub stars
303
Token cost
~3.7k tokens
SKILL.md length
1,770 words
Files
1
Skills in repo
87
Repo updated
First seen
Licence
MIT

At a glance

L1 trigger - audits mempool / transaction pool for eviction asymmetries, replacement policy abuse, blob-pool exhaustion, and DETER-class denial of service.

  • Works in 10 steps: The Core Asymmetry Check → Eviction Policy Correctness → Propagation Multiplier → …
  • - audits mempool / transaction pool for eviction asymmetries
  • SKILL.md covers Orchestrator Decomposition Guide, When This Skill Activates, 1. The Core Asymmetry Check and 2. Eviction Policy Correctness, plus 10 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Mempool Asymmetric Dos is an agent skill from PlamenTSV/plamen. L1 trigger - audits mempool / transaction pool for eviction asymmetries, replacement policy abuse, blob-pool exhaustion, and DETER-class denial of service.

Its SKILL.md is about 3.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: Autonomous Web3 security audit agent for Claude Code. The licence is MIT.

When your agent uses it

  • - audits mempool / transaction pool for eviction asymmetries
  • Replacement policy abuse
  • Blob-pool exhaustion
  • DETER-class denial of service

Example prompts

  • “/mempool-asymmetric-dos”

Workflow steps

10 steps, taken from the step headings in SKILL.md.

  1. The Core Asymmetry Check
  2. Eviction Policy Correctness
  3. Propagation Multiplier
  4. Ordering and Priority
  5. Blob pool specifics (Ethereum post-4844)
  6. Boundary conditions
  7. Output schema
  8. Known bug exemplars (v0.2 — Round 4 verified)
  9. Per-Transaction-Type Count Cap Audit
  10. Fallback if primitives unavailable

What it can do on your machine

Read from SKILL.md and the folder at commit 795962b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • arxiv.org
    • tristartom.github.io
    • usenix.org
    • medium.com
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Mempool Asymmetric Dos loads about 3.7k tokens when it runs. Until then it costs about 45 tokens; SKILL.md has 1,770 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~45
When it runs · the whole SKILL.md, loaded when a task matches
~3.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from PlamenTSV/plamen at commit 795962b, republished under its MIT licence (© PlamenTSV). 1,770 words, ~3,672 tokens.

Download SKILL.mdSave it as .claude/skills/mempool-asymmetric-dos/SKILL.md (or your agent's skills folder).
name
mempool-asymmetric-dos
description
L1 trigger - audits mempool / transaction pool for eviction asymmetries, replacement policy abuse, blob-pool exhaustion, and DETER-class denial of service.

Injectable Skill: Mempool Asymmetric DoS

L1 trigger: L1_PATTERN=true AND (txpool/ OR mempool/ OR tx_pool OR blob_pool OR reth-transaction-pool detected in recon subsystem map) Inject Into: depth-network-surface or depth-state-trace Language: Go and Rust Finding prefix: [MP-N] Status: v0.1 draft, Round 4 exemplars pending

Orchestrator Decomposition Guide

  • Section 1, 2: depth-network-surface (entry cost vs eviction cost)
  • Section 3: depth-state-trace (mempool state consistency)
  • Section 4: depth-edge-case (boundaries of the pool)

When This Skill Activates

Recon identifies a mempool module. Mempools are uniquely exposed: every RPC client and every peer can insert transactions. The DETER paper (USENIX CCS '21) and MemPurge follow-ups showed that most production mempools had asymmetric cost models exploitable at near-zero attacker cost.

1. The Core Asymmetry Check

The DETER insight: if an attacker can insert transactions with lower cost than it takes to evict them, they can fill the pool faster than honest transactions can reclaim space.

For each mempool:

  1. Identify the insert cost in (gas, fee, stake, or other resource): what does the attacker pay per byte of pool space occupied?
  2. Identify the eviction threshold: when does a new higher-fee transaction kick out a lower-fee one?
  3. Identify the eviction cost to the attacker: to evict an honest transaction, what must the attacker's replacement pay?
  4. Compute the ratio: insert_cost / eviction_cost. If this is much less than 1, the pool is asymmetric.

Specific patterns:

1a. Invalid-but-accepted transactions

Transactions that are initially accepted into the pool but will later fail validation (nonce gap, insufficient balance, invalid signature for a new state root). These cost the attacker 0 but occupy space until the validator reprocesses them.

Check: Look for a "pending" vs "valid" split. When is validity re-checked? Can an attacker keep an invalid tx in "pending" indefinitely?

1b. Nonce-gap attacks

A transaction with a nonce 100 above the current nonce is "futureNonce" — it occupies space waiting for the lower-nonce gap to fill. Attacker sends 99 futureNonce placeholders + never sends the gap-filler.

Check: Is there a cap on futureNonce slots per account? What's the eviction policy when the cap is hit? Is the cap per-account or shared?

1c. Replace-by-fee (RBF) exploitation

If an attacker can replace a low-fee tx with a slightly-higher-fee tx indefinitely, they churn pool state and cost honest reorganization work. The Bitcoin min_relay_fee_increment and Ethereum's 10% bump rule address this — verify the implementation.

Check: What is the minimum fee bump for replacement? Is it enforced cumulatively (across multiple replacements) or only per-replacement?

1d. Blob pool asymmetry (post-EIP-4844)

Blob transactions have a separate gas market (blob_gas_price). If the blob pool eviction uses only blob-gas-price but insertion is cheap (or the pool is not strictly separated from legacy), asymmetric exploitation is possible.

Check: Is the blob pool size-capped independently of the main pool? Can an attacker spam blobs to evict legacy txs or vice versa?

Tag: [MP-ASYMMETRIC:{insert-cost}:{eviction-cost}:{ratio}]

2. Eviction Policy Correctness

When the pool is full, which transaction gets evicted?

Patterns to check
  • Purely-fee-based: is the "cheapest" metric fee-per-gas, fee-per-byte, or absolute fee? Fee-per-gas is standard; absolute-fee allows large low-rate transactions to displace small high-rate ones.
  • Per-sender quota: does any single sender have a hard cap? If not, one attacker fills the pool with one-sender transactions.
  • Eviction cost consistency: does eviction correctly update all dependent state (sender's nonce tracking, per-topic indexes, reverse-lookup maps)?
  • Deterministic ordering on ties: when two transactions have identical fee, which gets evicted? If it's random, it's non-deterministic across nodes.

Tag: [MP-EVICT:{policy}:{gap}]

3. Propagation Multiplier

A mempool bug is worse if the bad transaction propagates:

  1. Does the node broadcast incoming transactions before validating them?
  2. Is there a per-peer rate limit on transaction gossip?
  3. Does the node track which peer sent which transaction to avoid re-sending?
  4. What happens if a peer floods with transactions that all fail validation? Is the peer scored down?

Tag: [MP-PROPAGATE:{behavior}]

4. Ordering and Priority

For transactions that do make it into blocks, the ordering algorithm affects MEV and fairness:

  • Priority-fee ordering: verify tie-break is deterministic (hash-based, not insertion-order)
  • Fee-market simulation: if the client simulates optimal inclusion, is the simulation correctness verified?
  • Bundle / PBS integration: if the mempool hands off to mev-boost or builder, what's the trust boundary? Any injection attack possible?

5. Blob pool specifics (Ethereum post-4844)

  1. Blob transactions are large (>128KB each). The pool must cap total blob size.
  2. Blob versioning: are versioned hash checks in place?
  3. Blob retrieval: if blob data is requested from peers, is there a DoS vector in the retrieval path?
  4. Blob expiry: 18-day retention. What happens when blobs are pruned mid-mempool-lifetime?

Tag: [BLOB:{concern}:{bound}]

6. Boundary conditions

StateTestExpectedObserved
Empty poolfirst tx insertedaccepted
Full pool, same-fee txnew tx with equal feerejected (no displacement)
Full pool, 10% higher feenew tx with RBF-threshold feeold tx evicted, new accepted
Same-sender N txssender sends pool_cap+1 txsoldest or lowest-fee evicted; sender not DoSed
futureNonce onlyattacker fills with gap transactionscap enforced; pool does not grow unbounded
Invalid sig batch1000 txs with invalid sigsall rejected quickly; peer scored
Blob size capblobs sum to > capexcess rejected

Tag: [BOUNDARY:mempool:{state}:{result}]

7. Output schema

  • Layer: mempool
  • Bug class: asymmetric-cost / eviction-policy / propagation-amplification / ordering / blob-pool
  • Preferred evidence tags: [FUZZ-PASS] (parameterized pool harness) > [LSP-TRACE] > [CODE-TRACE]
  • Severity baseline: Medium-High; Critical if network-wide eviction of all honest transactions is demonstrated

8. Known bug exemplars (v0.2 — Round 4 verified)

  1. DETER — Geth and 4 other Ethereum clients (USENIX CCS '21 + USENIX Security '24) — asymmetric eviction. Attackers send "future" nonce or "latent overdraft" transactions that pass cheap admission checks but are invalid at execution time. They fill the mempool and evict valid victim transactions at much lower cost to attacker than damage caused. Fixed in all major Ethereum clients as of Fall 2023. Mempool Symbolic Fuzzing USENIX '24; DETER 2.0. Skill catch point: Section 1 — the core asymmetry invariant. Insertion cost ≥ eviction damage.

  2. MemPurge — Geth pending pool (USENIX '24) — chain-of-txs eviction. Attacker sends chain of ≤65 transactions that appear valid but become invalid after first executes. Attacker pays for only 1 tx worth of fees but evicts 65 honest txs. Combined with ConditionalExhaust, total attack cost ≈ $376 for full pool replacement. Speculative DoS paper; Yaish summary. Skill catch point: Section 1b — model multi-tx transitive validity; admission of tx_1 must account for worst-case state after tx_1 executes, not current state.

  3. Geth GetHeadersFrom integer underflow (CVE-2024-32972) — GetHeadersFrom(number, count uint64) received count-1 where count was 0, producing UINT64_MAX and bypassing maxHeadersServe. Single p2p request forced node to stream all headers from latest back to genesis. GHSA-4xc9-8hmq-j652; fix in PR #29534, shipped v1.13.15. Skill catch point: boundary substitution — every p2p request handler with a count/range parameter must have underflow guard (subtraction below 0), overflow guard (u64 wraparound), and upper bound enforcement after arithmetic, not before. (Shared with p2p-dos-and-eclipse.)

Show full SKILL.md (644 more words)Show less
Critical methodology addition from Round 4 (DETER invariant)

Insert as new Section 1e (MANDATORY invariant): For every mempool, quantify:

insert_cost  = minimum resource expenditure to place one tx in the pool
              (accounts for: fee, stake, gas, bandwidth, all admission gates)
eviction_damage = maximum resource removal this tx can cause
              (accounts for: bytes freed, slot evictions, state churn, propagation)

Invariant: insert_cost ≥ eviction_damage for every admission path.

Check:

  • Invalid-but-admitted transactions (nonce gap, future balance, wrong sig) must be pruned from the pool before their slot is counted against any cap — or the admission check must have already charged the full eviction damage
  • Transitive validity: if admitting tx_A makes tx_B invalid, the mempool must not count both against admission quota
  • Test by constructing the worst-case attacker: fill the pool with minimally-costing entries and measure how much honest traffic is evicted

Tag: [MP-COST-RATIO:{insert_cost}:{eviction_damage}:{ratio}]

Ratios < 1 are CRITICAL; ratios just above 1 are High (a small-margin attacker can still cause damage under peak load).

8. Per-Transaction-Type Count Cap Audit

When a block can contain MULTIPLE transaction types (regular data tx, commitment tx, system tx, deposit, slashing, governance, oracle update, etc.), each type needs its OWN count cap. A single max_txs_per_block applied uniformly is insufficient — one attacker-controlled free tx type can flood blocks while "expensive" types are correctly bounded.

Methodology:

  1. Find the block header / body struct and enumerate EVERY field that holds a list or count of transactions. Typical names: data_ledgers, commitment_txs, system_txs, slashings, deposits, attestations, seal_operations.
  2. For each list field, find the block validator check for that specific field's length. 2a. Verify the cap is enforced in BOTH places:
    • block production / assembly
    • block validation / acceptance
  3. For each tx type, find the cost-per-tx (bytes, compute, state writes).
  4. Red flag: if one type has len(txs) <= MaxTxPerBlock but another type has no per-type cap (only the total byte cap), the unbounded type is a DoS vector — especially if the unbounded type is cheap to produce (no signature fee, no stake requirement, free-to-spam).

Required artifact: {SCRATCHPAD}/tx_type_caps.md:

markdown
| Tx Type | Field name | Per-type cap? | Cap value | Cost per tx | Spam risk |
|---|---|---|---|---|---|
| Regular data tx | `data_ledgers[].txs` | YES | MaxTxPerBlock=5000 | signature + state write | OK |
| Commitment tx | `commitment_txs` | **NO** | — | signature only (cheap) | **HIGH — no cap** |
| System tx | `system_txs` | YES | MaxSystemPerBlock=16 | none (privileged) | OK if validated |
| Slashing evidence | `slashings` | YES | MaxSlashPerBlock=32 | free to submit | OK |

Every "NO" in the "Per-type cap?" column is a finding — severity is at least High when the type is cheap to produce and propagates through p2p (commitment txs, attestations, gossip messages). A cap enforced only at production or only at validation is also a finding.

Tag: [MP-NO-PER-TYPE-CAP:{tx_type}]

8a. CometBFT Mempool Priority / FIFO Front-running

CometBFT/Tendermint mempools are FIFO by default; a priority mempool exists but must be explicitly configured and implemented correctly. FIFO ordering enables ordering games (an observer races a target tx by submitting earlier), and either ordering mode can STARVE critical low-volume messages (oracle price updates, emergency pause, slashing evidence) behind a flood of cheap txs.

Bounded reads: read SCIP graph artifacts (caller_map.md, callee_map.md, state_write_map.md, function_summary.md) to find mempool insert/reap call-sites and any priority assignment; on-demand single-symbol source reads for the CheckTx/reap/priority functions only; never bulk-read large files.

Heuristics:

  1. Grep for mempool.Priority, priority, ReapMaxBytesMaxGas, CheckTx, Mempool, recheck, fifo. Identify whether the mempool is FIFO or priority-based.
  2. Ordering exposure: if FIFO, any logic whose outcome depends on relative tx ordering (oracle-feeds, auctions, first-come settlement) is front-runnable by an observer who submits earlier — flag the affected app-level path.
  3. Critical-message starvation: identify protocol-critical message types (oracle update, pause/halt, governance, slashing evidence). Verify they cannot be indefinitely delayed behind attacker spam — i.e. they get a reserved lane, a priority floor, or a dedicated cap. A critical message subject to the same shared FIFO/priority queue as spammable txs, with no reservation, is a finding.
  4. Priority assignment integrity: if mempool.Priority is set in CheckTx, verify the priority is derived from a non-attacker-gameable signal (validated fee/stake), not from a self-declared field a sender can inflate for free.

Severity: starvation of an oracle/pause/evidence message is High–Critical (stale price / un-haltable incident / missed slashing); ordering front-run is Medium–High per the affected app path.

Tag: [MP-FIFO-FRONTRUN:{path}], [MP-CRITICAL-STARVE:{msg-type}]

9. Fallback if primitives unavailable

  • Locate the mempool directory
  • Find the Add / insert / add_transaction function
  • Find the pop / evict / remove function
  • Read both, check if they maintain the same cost function

Cross-references

  • Related: p2p-dos-and-eclipse (peer scoring interaction), rpc-surface-audit (RPC eth_sendRawTransaction is an insertion path), execution-client-hardening
  • Consumed by: depth-network-surface, depth-state-trace
  • Severity: docs/l1-mode/severity-matrix.md

© PlamenTSV, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in agents/skills/injectable/l1/mempool-asymmetric-dos of PlamenTSV/plamen.

Open the folder on GitHubat commit 795962b

Compare with similar skills

Mempool Asymmetric Dos next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Mempool Asymmetric Dos compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Mempool Asymmetric Dos this skillPlamenTSV/plamen303—~3.7kAutomated safety check: PassMIT
Web3 Transaction Relayer Poolsickn33/agentic-awesome-skills47k1 repos~1.3kAutomated safety check: PassMIT
Production Auditaffaan-m/ECC276k1 repos~1.9kAutomated safety check: PassMIT
Aims Auditalirezarezvani/claude-skills28k—~1.3kAutomated safety check: PassMIT
Eviction Policy Regret Auditben-manes/caffeine18k—~16kAutomated safety check: NotesApache-2.0
Geo Auditsickn33/agentic-awesome-skills47k1 repos~3.4kAutomated safety check: NotesMIT

Similar skills

  • Web3 Transaction Relayer Pool

    sickn33/agentic-awesome-skills

    Gasless transaction relayer node pool register: fee sponsorship limits, nonce synchronization, and balance replenishment alerts.

    47k GitHub starsUsed in 1 repo~1.3k tokens
    Business, Finance & HRAuto-check passed
  • Production Audit

    affaan-m/ECC

    Local-evidence production readiness audit for shipped apps, pre-launch reviews, post-merge checks, and "what breaks in prod?" questions without sending repo data to an external audit service.

    276k GitHub starsUsed in 1 repo~1.9k tokens
    Product & Project ManagementAuto-check passed
  • Aims Audit

    alirezarezvani/claude-skills

    /cs:aims-audit <scope — ISO/IEC 42001 AIMS internal-audit 6-question forcing interrogation.

    28k GitHub stars~1.3k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Searches synthetic workloads for cases where Caffeine's adaptive eviction policy falls short of its achievable hit rate, then classifies each gap by cause.

    18k GitHub stars~16k tokensUpdated yesterday
    DevelopmentAuto-check: notes
  • Geo Audit

    sickn33/agentic-awesome-skills

    Full website GEO+SEO audit with parallel subagent delegation.

    47k GitHub starsUsed in 1 repo~3.4k tokens
    Marketing & SEOAuto-check: notes
  • OmniRoute Audit and Policy CLI

    diegosouzapw/OmniRoute

    Command reference for omniroute's audit, logs, policy and telemetry commands: search and export audit trails, manage access policies and review request history for compliance work.

    75k GitHub stars~733 tokensUpdated today
    SecurityAuto-check passed

More from PlamenTSV/plamen

All 87 skills in this repo
  • Audit Prep

    PlamenTSV/plamen

    Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project…

    303 GitHub stars~3.7k tokensUpdated 13 days ago
    Auto-check passed
  • Verification Protocol

    PlamenTSV/plamen

    Trigger Pattern Always (used by all verifier agents) - Inject Into security-verifier agents (Phase 5)

    303 GitHub stars~3.5k tokensUpdated 13 days ago
    Auto-check passed
  • Ability Analysis

    PlamenTSV/plamen

    Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth agents, depth agents

    303 GitHub stars~3.3k tokensUpdated 13 days ago
    Auto-check passed
  • Ability Analysis

    PlamenTSV/plamen

    Trigger Pattern Always (Sui Move) -- foundational security check - Inject Into Breadth agents, depth agents

    303 GitHub stars~3.2k tokensUpdated 13 days ago
    Auto-check passed
  • Account Lifecycle

    PlamenTSV/plamen

    Trigger Pattern ACCOUNTCLOSING flag detected (close/CloseAccount usage) - Inject Into Breadth agents, depth agents

    303 GitHub stars~1.2k tokensUpdated 13 days ago
    Auto-check passed
  • Account Validation

    PlamenTSV/plamen

    Trigger Pattern Always required for Solana audits - Inject Into Breadth agents, depth agents

    303 GitHub stars~1.7k tokensUpdated 13 days ago
    Auto-check passed

Questions about Mempool Asymmetric Dos

What does Mempool Asymmetric Dos do?

L1 trigger - audits mempool / transaction pool for eviction asymmetries, replacement policy abuse, blob-pool exhaustion, and DETER-class denial of service. Mempool Asymmetric Dos is an agent skill from PlamenTSV/plamen. L1 trigger - audits mempool / transaction pool for eviction asymmetries, replacement policy abuse, blob-pool exhaustion, and DETER-class denial of service.

When should I use Mempool Asymmetric Dos?

Mempool Asymmetric Dos fits situations like: - audits mempool / transaction pool for eviction asymmetries; replacement policy abuse; blob-pool exhaustion; DETER-class denial of service.

How do I install Mempool Asymmetric Dos in Claude Code?

Run `npx skills add PlamenTSV/plamen --skill mempool-asymmetric-dos -a claude-code`. Or copy the skill folder (agents/skills/injectable/l1/mempool-asymmetric-dos in PlamenTSV/plamen) into .claude/skills/mempool-asymmetric-dos in your project. Claude Code loads it when a task matches its description.

How do I install Mempool Asymmetric Dos in Codex?

Run `npx skills add PlamenTSV/plamen --skill mempool-asymmetric-dos -a codex`. Or copy the skill folder (agents/skills/injectable/l1/mempool-asymmetric-dos in PlamenTSV/plamen) into .agents/skills/mempool-asymmetric-dos in your project. Codex loads it when a task matches its description.

Can I use Mempool Asymmetric Dos in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PlamenTSV/plamen --skill mempool-asymmetric-dos -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/mempool-asymmetric-dos, .gemini/skills/mempool-asymmetric-dos, .github/skills/mempool-asymmetric-dos and .opencode/skills/mempool-asymmetric-dos in your project.

What does Mempool Asymmetric Dos need to run?

SKILL.md names no scripts, command-line tools or credentials: Mempool Asymmetric Dos is instructions for the agent only.

Does Mempool Asymmetric Dos access the network?

SKILL.md names 5 domains. As links in the text: arxiv.org, tristartom.github.io, usenix.org, medium.com and github.com. This is read from the text; nothing was executed.

Is Mempool Asymmetric Dos safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Mempool Asymmetric Dos use?

Mempool Asymmetric Dos is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Mempool Asymmetric Dos use?

About 3.7k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Mempool Asymmetric Dos?

Skills that share tags, products or a category with Mempool Asymmetric Dos: Web3 Transaction Relayer Pool (sickn33/agentic-awesome-skills, 47k stars), Production Audit (affaan-m/ECC, 276k stars), Aims Audit (alirezarezvani/claude-skills, 28k stars) and Eviction Policy Regret Audit (ben-manes/caffeine, 18k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Mempool Asymmetric Dos?

PlamenTSV (a GitHub user) maintains it in PlamenTSV/plamen, which has 303 GitHub stars. The repository holds 87 skills in this directory. The repository was last updated on September 26, 2026.

Source: PlamenTSV/plamen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.