Agent skill

Migration Analysis

by PlamenTSV in PlamenTSV/plamen

Trigger Pattern Program upgrades, account data layout changes, deprecated instructions, token migrations - Inject Into Breadth agents, depth-state-trace

MITAuto-check passed

Install Migration Analysis

skills CLI
$ npx skills add PlamenTSV/plamen --skill migration-analysis -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install PlamenTSV/plamen migration-analysis --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agents/skills/solana/migration-analysis .claude/skills/migration-analysis && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
migration-analysis
GitHub stars
303
Token cost
~2.7k tokens
SKILL.md length
941 words
Files
1
Skills in repo
87
Repo updated
First seen
Licence
MIT

At a glance

Trigger Pattern Program upgrades, account data layout changes, deprecated instructions, token migrations - Inject Into Breadth agents, depth-state-trace

  • Works in 6 steps: Identify Token and Account Transitions → Check Account Data Layout Compatibility → Trace Account Flow Paths → …
  • Pattern Program upgrades
  • SKILL.md covers Reasoning Template, Key Questions (Must Answer All), Common False Positives and Finding Template, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Migration Analysis is an agent skill from PlamenTSV/plamen. Trigger Pattern Program upgrades, account data layout changes, deprecated instructions, token migrations - Inject Into Breadth agents, depth-state-trace

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with Solana. The repository describes itself as: Autonomous Web3 security audit agent for Claude Code. The licence is MIT.

When your agent uses it

  • Pattern Program upgrades
  • Account data layout changes
  • Deprecated instructions
  • Token migrations - Inject Into Breadth agents

Example prompts

  • “/migration-analysis”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Identify Token and Account Transitions
  2. Check Account Data Layout Compatibility
  3. Trace Account Flow Paths
  4. Stranded Asset Analysis (ENHANCED)
  5. Upgrade Authority Lifecycle
  6. Downstream Integration Compatibility

What it can do on your machine

Read from SKILL.md and the folder at commit 795962b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are rust and markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Migration Analysis loads about 2.7k tokens when it runs. Until then it costs about 43 tokens; SKILL.md has 941 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~43
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from PlamenTSV/plamen at commit 795962b, republished under its MIT licence (© PlamenTSV). 941 words, ~2,652 tokens.

Download SKILL.mdSave it as .claude/skills/migration-analysis/SKILL.md (or your agent's skills folder).
name
migration-analysis
description
Trigger Pattern Program upgrades, account data layout changes, deprecated instructions, token migrations - Inject Into Breadth agents, depth-state-trace

Skill: Migration Analysis (Solana)

Trigger Pattern: Program upgrades, account data layout changes, deprecated instructions, token migrations Inject Into: Breadth agents, depth-state-trace Finding prefix: [MG-N] Rules referenced: S1, S3, S4, S9, R4, R9, R10

upgrade|authority|reinitialize|deprecated|migrat|legacy|v2|V2|old_mint|new_mint|
BPFLoaderUpgradeable|set_authority|close_account

Reasoning Template

Step 1: Identify Token and Account Transitions

Find all migration patterns:

  • Old mint -> New mint (SPL Token migrations, token rebranding, Token-2022 migration)
  • Deprecated instructions still callable
  • Account data layout changes across program versions
  • PDA seed schema changes

For each transition:

Old EntityNew EntityMigration InstructionBidirectional?Account Type
Step 2: Check Account Data Layout Compatibility

For each program upgrade that changes account data structures:

  1. What fields exist in the OLD account data layout?
  2. What fields exist in the NEW account data layout?
  3. Are new fields APPENDED (safe) or INSERTED/REORDERED (breaking)?
  4. Does the discriminator change between versions? (Anchor uses first 8 bytes)
rust
// Example mismatch:
// V1 layout: [discriminator(8)][authority(32)][amount(8)]  = 48 bytes
// V2 layout: [discriminator(8)][authority(32)][new_field(8)][amount(8)] = 56 bytes
// BREAKING: V1 accounts read `amount` at offset 40, but V2 expects it at offset 48
Account TypeV1 Layout (fields + offsets)V2 Layout (fields + offsets)Compatible?Migration Path
Step 3: Trace Account Flow Paths

For each instruction that interacts with migrated accounts:

  1. Entry point: What account data version does the user provide?
  2. Internal flow: What version does the program expect?
  3. CPI calls: What version do CPI target programs expect?
  4. Return data: What version does the program write back?
InstructionAccount ExpectedActual Account VersionCPI Target ExpectsMismatch?
Step 3b: CPI Side Effect Compatibility

When migration changes program behavior, check whether CPI callers handle the changes:

CPI CallPre-Migration BehaviorPost-Migration BehaviorCaller Handles Both?Mismatch?

Pattern: Program upgrade changes return data or account mutations from a CPI, but callers were written for the old behavior. After upgrade, CPI results are misinterpreted.

Step 3c: Pre-Upgrade Account Inventory

Before analyzing stranded asset paths, inventory all accounts the program owns:

Account TypeHow CreatedCurrent Lamports/TokensPost-Upgrade Logic Handles?Close Path Post-Upgrade?
{pda_vault}PDA initSOL + SPL tokensYES/NO{instruction or NONE}
{user_state}User initRent-exempt SOLYES/NO{instruction or NONE}
{legacy_acct}V1 initHeld from V1 opsYES/NO{instruction or NONE}

Pattern: Upgrade changes which accounts the program reads/writes, but old accounts still hold SOL (rent) and tokens. If new logic cannot close or drain old accounts, assets are stranded.

Step 4: Stranded Asset Analysis (ENHANCED)
4a. Asset Inventory by Era
Asset/AccountV1 Creation PathV2 Creation PathV1 Close PathV2 Close Path
{pda_vault}initialize()initialize_v2()close_vault()close_vault_v2()
{user_account}create_user()create_user()close_user()close_user()

Rule: If V1 Creation exists but V2 Close doesn't handle V1 state -> potential stranding.

4b. Cross-Era Path Matrix
Account EraState ConditionAvailable Close/Drain PathsWorks?Reason
V1 PDA vaultV2 program deployedclose_vault_v2()Y/N{why}
V1 PDA vaultV1 instruction removedclose_vault()Y/N{why}
V1 user stateIn-flight during upgrade???Y/N{why}

STRANDING RULE: If ALL close/drain paths fail for any account state -> STRANDED ASSETS FINDING

4c. Recovery Function Inventory
FunctionWho Can CallWhat Accounts Can RecoverLimitations
close_account()Authority onlyProgram-owned accountsRequires active authority
migrate_v1()Any userV1 user accountsOne-time per account
sweep_lamports()AuthorityUnclaimed rentCannot recover user deposits
4d. Worst-Case Scenarios (MANDATORY)

Scenario 1: V1 Account + V2 Program

State: User created account via V1 initialize() with deposited tokens
Event: Program upgraded to V2 with new data layout
Question: Can user close/withdraw via V2 instructions?
Trace: [document instruction path and deserialization]
Result: [SUCCESS/STRANDED + amount]

Scenario 2: In-Flight During Upgrade

State: User initiated multi-instruction operation (e.g., unstake request) at slot N
Event: Program upgrade deployed at slot N+1
Question: Can user complete operation at slot N+2?
Trace: [document instruction path]
Result: [SUCCESS/STRANDED + amount]

Scenario 3: PDA Seed Change

State: PDA derived with seeds [b"vault", user.key()] in V1
Event: V2 changes seeds to [b"vault_v2", user.key()]
Question: Can V2 program access the V1 PDA? Are V1 tokens recoverable?
Trace: [document PDA derivation and account lookup]
Result: [SUCCESS/STRANDED + amount]
4e. Step 4 Completion Checklist
  • 4a: ALL accounts inventoried with creation/close paths per era
  • 4b: Cross-era path matrix completed for all state combinations
  • 4c: Recovery instructions enumerated with limitations
  • 4d: All three worst-case scenarios modeled with traces
  • For EVERY stranding possibility: recovery path exists OR finding created
Show full SKILL.md (376 more words)Show less
Step 4f: User-Blocks-Admin Scenarios
Admin/Migration InstructionPrecondition RequiredUser Action That Blocks ItTiming WindowSeverity
{admin_ix}{precondition}{user_action}{window}{assess}

Solana-specific patterns:

  • User creates token accounts owned by program PDA -> non-zero balance prevents PDA closure
  • User initiates pending operations (unstake, withdrawal request) -> in-flight state blocks migration
  • User creates many small accounts -> iteration over accounts exceeds CU limit for admin migration instruction
Step 5: Upgrade Authority Lifecycle
CheckStatusEvidence
Upgrade authority identified?{pubkey or multisig}{source location}
Is authority a multisig (Squads)?YES/NO
Can authority be revoked (program made immutable)?YES/NO
If revoked: are all config parameters frozen?YES/NO
If revoked: can stranded assets be recovered?YES/NOApply Rule 9
Buffer validation during upgrade?YES/NOCan malicious buffer be substituted?
IDL discriminator stability?YES/NOChanged discriminators break all callers
Step 6: Downstream Integration Compatibility
Program ChangeDownstream ConsumerExpected InterfacePost-Migration ActualBreaking?
{change}CPI callers{expected IDL}{actual IDL}YES/NO
{change}Indexers (Geyser, Helius){expected account layout}{actual layout}YES/NO
{change}Frontend/SDK{expected instruction format}{actual}YES/NO

Pattern: Program upgrade changes instruction discriminators, account layouts, or CPI behavior, but downstream consumers (other programs calling via CPI, indexers, SDKs) were built for the old interface.

Key Questions (Must Answer All)

  1. Data Layout: Are ALL existing accounts readable by the new program version?
  2. PDA Stability: Do ALL PDAs remain derivable with the same seeds after upgrade?
  3. Migration Completeness: Can ALL V1 accounts be migrated/closed via V2 paths?
  4. Stranded Assets: Is there any combination of (old_account_state + new_program) that traps funds?
  5. Authority Lifecycle: Is the upgrade authority appropriately secured and revocable?

Common False Positives

  1. Append-only layout changes: New fields added at end with defaults -- backward compatible
  2. Versioned deserialization: Program explicitly handles both V1 and V2 layouts
  3. Admin-controlled migration: Stranded accounts recoverable via authority instructions

Finding Template

markdown
**ID**: [MG-N]
**Verdict**: CONFIRMED / PARTIAL / REFUTED / CONTESTED
**Step Execution**: (see checklist below)
**Rules Applied**: [S1:___, S3:___, S4:___, S9:___, R4:___, R9:___, R10:___]
**Severity**: Critical/High/Medium/Low/Info
**Location**: programs/{program}/src/{file}.rs:LineN

**Account Transition**:
- Old: {old_layout/mint/PDA}
- New: {new_layout/mint/PDA}
- Mismatch Point: {where layouts/seeds diverge}

**Description**: {what is wrong}
**Impact**: {stranded funds, corrupted state, broken CPI callers}
**Evidence**: {code showing mismatch}

Step Execution Checklist (MANDATORY)

StepRequiredCompleted?Notes
1. Identify Token and Account TransitionsYES
2. Check Account Data Layout CompatibilityYES
3. Trace Account Flow PathsYES
3b. CPI Side Effect CompatibilityYES
3c. Pre-Upgrade Account InventoryYES
4. Stranded Asset Analysis (4a-4e)YES
4f. User-Blocks-Admin ScenariosYES
5. Upgrade Authority LifecycleYES
6. Downstream Integration CompatibilityYES

If any step skipped, document valid reason (N/A, immutable program, single version, no CPI callers).

© PlamenTSV, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in agents/skills/solana/migration-analysis of PlamenTSV/plamen.

Open the folder on GitHubat commit 795962b

Compare with similar skills

Migration Analysis next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Migration Analysis compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Migration Analysis this skillPlamenTSV/plamen303—~2.7kAutomated safety check: PassMIT
Minara Crypto Trading and WalletMinara-AI/minara-skills3581 repos~5.7kAutomated safety check: PassNone
NEAR Intents Swap Integrationinternet-court/internet-court-skill6.4k2 repos~939Automated safety check: PassCustom licence
Solana Devsolana-foundation/solana-dev-skill574—~3.8kAutomated safety check: PassMIT
Meme Coin Security Auditawarexone/Agentic-Bug-Hunter5.3k1 repos~2.4kAutomated safety check: PassMIT
Swapper Depositswapperfinance/swapper-toolkit852—~1.8kAutomated safety check: PassMIT

Similar skills

  • Minara Crypto Trading and Wallet

    Minara-AI/minara-skills

    Drives the Minara CLI for crypto swaps, perps, limit orders, wallet transfers, deposits and withdrawals, plus AI market analysis.

    358 GitHub starsUsed in 1 repo~5.7k tokens
    Business, Finance & HRAuto-check passed
  • NEAR Intents Swap Integration

    internet-court/internet-court-skill

    Builds cross-chain token swaps and bridge flows with the NEAR Intents 1Click API: quotes, deposit addresses, per-chain deposits and status polling.

    6.4k GitHub starsUsed in 2 repos~939 tokens
    Backend & APIsAuto-check passed
  • Solana Dev

    solana-foundation/solana-dev-skill

    A skill your agent uses when user asks to "build a Solana dapp", "write an Anchor program", "create a token", "debug Solana errors", "set up wallet connection", "test my Solana program", "fuzz my…

    574 GitHub stars~3.8k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Meme Coin Security Audit

    awarexone/Agentic-Bug-Hunter

    Screens EVM and Solana meme coins for rug pull signs such as hidden mint, honeypot logic and fee tricks, starting with fast kill signals before any code review.

    5.3k GitHub starsUsed in 1 repo~2.4k tokens
    SecurityAuto-check passed
  • Swapper Deposit

    swapperfinance/swapper-toolkit

    Deposit and bridge funds into a wallet or protocol using Swapper Finance.

    852 GitHub stars~1.8k tokensUpdated 6 mo ago
    Business, Finance & HRAuto-check passed
  • PNP Prediction Markets on Solana

    internet-court/internet-court-skill

    Creates, trades and settles permissionless prediction markets on Solana with any SPL token as collateral, including social-media and custom-oracle markets.

    6.4k GitHub stars~7.5k tokensUpdated 1 mo ago
    Business, Finance & HRAuto-check: notes

More from PlamenTSV/plamen

All 87 skills in this repo
  • Audit Prep

    PlamenTSV/plamen

    Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project…

    303 GitHub stars~3.7k tokensUpdated 12 days ago
    Auto-check passed
  • Verification Protocol

    PlamenTSV/plamen

    Trigger Pattern Always (used by all verifier agents) - Inject Into security-verifier agents (Phase 5)

    303 GitHub stars~3.5k tokensUpdated 12 days ago
    Auto-check passed
  • Ability Analysis

    PlamenTSV/plamen

    Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth agents, depth agents

    303 GitHub stars~3.3k tokensUpdated 12 days ago
    Auto-check passed
  • Ability Analysis

    PlamenTSV/plamen

    Trigger Pattern Always (Sui Move) -- foundational security check - Inject Into Breadth agents, depth agents

    303 GitHub stars~3.2k tokensUpdated 12 days ago
    Auto-check passed
  • Account Lifecycle

    PlamenTSV/plamen

    Trigger Pattern ACCOUNTCLOSING flag detected (close/CloseAccount usage) - Inject Into Breadth agents, depth agents

    303 GitHub stars~1.2k tokensUpdated 12 days ago
    Auto-check passed
  • Account Validation

    PlamenTSV/plamen

    Trigger Pattern Always required for Solana audits - Inject Into Breadth agents, depth agents

    303 GitHub stars~1.7k tokensUpdated 12 days ago
    Auto-check passed

Works with

Questions about Migration Analysis

What does Migration Analysis do?

Trigger Pattern Program upgrades, account data layout changes, deprecated instructions, token migrations - Inject Into Breadth agents, depth-state-trace. Migration Analysis is an agent skill from PlamenTSV/plamen.

When should I use Migration Analysis?

Migration Analysis fits situations like: pattern Program upgrades; account data layout changes; deprecated instructions; token migrations - Inject Into Breadth agents.

How do I install Migration Analysis in Claude Code?

Run `npx skills add PlamenTSV/plamen --skill migration-analysis -a claude-code`. Or copy the skill folder (agents/skills/solana/migration-analysis in PlamenTSV/plamen) into .claude/skills/migration-analysis in your project. Claude Code loads it when a task matches its description.

How do I install Migration Analysis in Codex?

Run `npx skills add PlamenTSV/plamen --skill migration-analysis -a codex`. Or copy the skill folder (agents/skills/solana/migration-analysis in PlamenTSV/plamen) into .agents/skills/migration-analysis in your project. Codex loads it when a task matches its description.

Can I use Migration Analysis in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PlamenTSV/plamen --skill migration-analysis -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/migration-analysis, .gemini/skills/migration-analysis, .github/skills/migration-analysis and .opencode/skills/migration-analysis in your project.

What does Migration Analysis need to run?

SKILL.md names no scripts, command-line tools or credentials: Migration Analysis is instructions for the agent only.

Does Migration Analysis access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Migration Analysis safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Migration Analysis use?

Migration Analysis is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Migration Analysis use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Migration Analysis?

Skills that share tags, products or a category with Migration Analysis: Minara Crypto Trading and Wallet (Minara-AI/minara-skills, 358 stars), NEAR Intents Swap Integration (internet-court/internet-court-skill, 6.4k stars), Solana Dev (solana-foundation/solana-dev-skill, 574 stars) and Meme Coin Security Audit (awarexone/Agentic-Bug-Hunter, 5.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Migration Analysis?

PlamenTSV (a GitHub user) maintains it in PlamenTSV/plamen, which has 303 GitHub stars. The repository holds 87 skills in this directory. The repository was last updated on September 26, 2026.

Source: PlamenTSV/plamen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.