Kotlin Exposed Patterns
affaan-m/ECC
JetBrains Exposed ORM patterns including DSL queries, DAO pattern, transactions, HikariCP connection pooling, Flyway migrations, and repository pattern.
Trigger Pattern Package upgrades, version transitions, deprecated functions, object layout changes - Inject Into Breadth agents, depth-state-trace
$ npx skills add PlamenTSV/plamen --skill migration-analysis -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install PlamenTSV/plamen migration-analysis --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agents/skills/sui/migration-analysis .claude/skills/migration-analysis && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "migration-analysis" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/sui/migration-analysis into .claude/skills/migration-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "migration-analysis", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/PlamenTSV/plamen/tree/main/agents/skills/sui/migration-analysisType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add PlamenTSV/plamen --skill migration-analysis -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install PlamenTSV/plamen migration-analysis --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .agents/skills && cp -r skills-src/agents/skills/sui/migration-analysis .agents/skills/migration-analysis && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "migration-analysis" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/sui/migration-analysis into .agents/skills/migration-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "migration-analysis", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add PlamenTSV/plamen --skill migration-analysis -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install PlamenTSV/plamen migration-analysis --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/agents/skills/sui/migration-analysis .cursor/skills/migration-analysis && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "migration-analysis" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/sui/migration-analysis into .cursor/skills/migration-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "migration-analysis", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/PlamenTSV/plamen.git --path agents/skills/sui/migration-analysis--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add PlamenTSV/plamen --skill migration-analysis -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install PlamenTSV/plamen migration-analysis --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/agents/skills/sui/migration-analysis .gemini/skills/migration-analysis && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "migration-analysis" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/sui/migration-analysis into .gemini/skills/migration-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "migration-analysis", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install PlamenTSV/plamen migration-analysisInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add PlamenTSV/plamen --skill migration-analysis -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .github/skills && cp -r skills-src/agents/skills/sui/migration-analysis .github/skills/migration-analysis && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "migration-analysis" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/sui/migration-analysis into .github/skills/migration-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "migration-analysis", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add PlamenTSV/plamen --skill migration-analysis -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install PlamenTSV/plamen migration-analysis --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/agents/skills/sui/migration-analysis .opencode/skills/migration-analysis && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "migration-analysis" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/sui/migration-analysis into .opencode/skills/migration-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "migration-analysis", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
migration-analysisTrigger Pattern Package upgrades, version transitions, deprecated functions, object layout changes - Inject Into Breadth agents, depth-state-trace
Migration Analysis is an agent skill from PlamenTSV/plamen. Trigger Pattern Package upgrades, version transitions, deprecated functions, object layout changes - Inject Into Breadth agents, depth-state-trace
Its SKILL.md is about 3.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
The repository describes itself as: Autonomous Web3 security audit agent for Claude Code. The licence is MIT.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 795962b. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are move and markdown).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Migration Analysis loads about 3.4k tokens when it runs. Until then it costs about 41 tokens; SKILL.md has 1,281 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from PlamenTSV/plamen at commit 795962b, republished under its MIT licence (© PlamenTSV). 1,281 words, ~3,421 tokens.
.claude/skills/migration-analysis/SKILL.md (or your agent's skills folder).Trigger Pattern: Package upgrades, version transitions, deprecated functions, object layout changes Inject Into: Breadth agents, depth-state-trace Finding prefix:
[MG-N]Rules referenced: R4, R8, R9, R10, R13
upgrade|UpgradeCap|UpgradeTicket|version|v2|V2|deprecated|migrat|legacy|old_coin|new_coin|
compatible|additive|dependency_only|package::authorize_upgradeSui packages are immutable once published. "Upgrades" create new package versions at new addresses via the UpgradeCap mechanism. Old objects may reference old package versions, and mixed-version state is a primary Sui migration concern. Unlike EVM proxy upgrades where old code is replaced, Sui old package code remains callable forever.
Find all token/object migration patterns:
Coin<OldType> -> New Coin<NewType> (token rebranding, coin type changes)For each transition:
| Old Entity | New Entity | Migration Function | Bidirectional? | Entity Type |
|---|
Sui-specific check: Is this a true package upgrade (same package lineage via UpgradeCap) or a separate package deployment (new address, no lineage)? True upgrades maintain type compatibility; separate deployments create entirely new types -- pkg_v1::module::Type != pkg_v2::module::Type.
For each function in the new package version interacting with existing objects:
compatible upgrade rules?// Example: V1 object layout
struct Pool has key, store {
id: UID,
balance: Balance<SUI>,
fee_bps: u64,
}
// V2 cannot change this layout under `compatible` policy.
// New fields require a new struct or dynamic fields.| Object Type | V1 Fields | V2 Fields | Compatible Upgrade? | Breaking Change? |
|---|
Sui upgrade compatibility rules:
compatible: Can change function implementations, add new functions, add new types. CANNOT change existing struct layouts, remove public functions, or change function signatures.additive: Can only add new modules/functions. Cannot change existing code.dependency_only: Can only change dependency versions.immutable: No changes possible (UpgradeCap destroyed).For each function that interacts with migrated tokens/objects:
| Function | User Provides | Protocol Expects | External Expects | Mismatch? |
When migration changes token types or interaction patterns, check whether external package side effects produce tokens/objects the current logic handles:
| External Call | Pre-Migration Side Effect | Post-Migration Side Effect | Logic Handles Both? | Mismatch? |
|---|
Pattern: Migration changes the primary coin type (e.g., V1 -> V2), but external packages still return the old type as rewards or receipts.
Before analyzing stranded asset paths, inventory what shared objects and owned objects exist on-chain:
| Object Type | Ownership | How Created | Current Contents | Post-Upgrade Logic Handles? | Exit Path Post-Upgrade? |
|---|---|---|---|---|---|
| {pool_obj} | Shared | init() | Balance<SUI> + config | YES/NO | {function or NONE} |
| {user_position} | Owned | open_position() | Balance + tracking | YES/NO | {function or NONE} |
| {legacy_receipt} | Owned | V1 deposit() | Receipt token | YES/NO | {function or NONE} |
Sui-specific: Unlike EVM where contract storage persists across upgrades, Sui objects are typed. If a new package is published (not a lineage upgrade), V1 objects CANNOT be read by new package functions because the types differ.
CRITICAL: This step uses exhaustive methodology. Every sub-step is MANDATORY.
| Asset/Object | V1 Entry Path | V2 Entry Path | V1 Exit Path | V2 Exit Path |
|---|---|---|---|---|
| {shared_pool} | create_pool() | create_pool() (same) | N/A (shared) | N/A (shared) |
| {user_receipt} | deposit() | deposit_v2() | redeem() | redeem_v2() |
Rule: If V1 Entry exists but V2 Exit doesn't handle V1-created objects -> potential stranding.
Sui-specific: Shared objects persist across compatible upgrades. For new package publications (not upgrades), the type is a DIFFERENT type even if structurally identical.
| Object Version | State Condition | Available Exit Paths | Works? | Reason |
|---|---|---|---|---|
| V1 user receipt | V2 package active | redeem_v2() with V1 receipt | Y/N | {struct type compatibility} |
| V1 shared pool | V2 functions called on it | V2 withdraw() | Y/N | {field access compatibility} |
| V1 owned object | New package published (not upgraded) | ANY V2 function | Y/N | {type mismatch} |
STRANDING RULE: If ALL exit paths = N for any object state -> STRANDED ASSETS FINDING (apply Rule 9: minimum MEDIUM)
| Function | Who Can Call | What Objects Can Recover | Limitations |
|---|---|---|---|
migrate_v1() | Object owner | V1 owned objects | One-time per object |
admin_sweep() | AdminCap holder | Shared object balances | Requires active AdminCap |
Question: Is there a recovery path for EVERY stranding scenario in 4b?
Scenario 1: V1 Object + V2 Package (Compatible Upgrade)
State: User holds Receipt object created by V1 package
Event: Package upgraded to V2 via compatible upgrade
Question: Can user call V2 redeem() with V1 Receipt?
Trace: [document type compatibility and field access]
Result: [SUCCESS/STRANDED + amount]Scenario 2: V1 Object + New Package (Non-Upgrade Publication)
State: User holds Receipt<OldPackage::COIN> object
Event: Protocol publishes new package at new address
Question: Can user interact with new package using old object?
Trace: [OldPackage::Receipt != NewPackage::Receipt -- different types]
Result: [STRANDED unless explicit migration exists]Scenario 3: Old Package Bypass After Upgrade
State: Protocol upgrades to V2 with new security checks
Event: Attacker calls V1 functions on shared objects
Question: Do V1 functions bypass V2 security checks?
Trace: [document old function code path]
Result: [SAFE/BYPASS POSSIBLE]Scenario 4: Dynamic Field Key Type Mismatch
State: Objects have dynamic fields with V1 key types
Event: V2 changes key type or field structure
Question: Can V2 code read/remove V1-era dynamic fields?
Trace: [document dynamic field access path]
Result: [SUCCESS/STRANDED + orphaned dynamic fields]| Admin/Migration Function | Precondition Required | User Action That Blocks It | Timing Window | Severity |
|---|---|---|---|---|
| {admin_func} | {precondition} | {user_action} | {window} | {assess} |
Sui-specific patterns:
If blocking is possible AND permanent -> minimum MEDIUM severity If blocking is temporary but repeatable -> assess with Rule 10 worst-state
For each external package dependency:
| External Package | Published Version | Upgrade Policy | Our Package Pins To | Compatible With Our Usage? |
|---|---|---|---|---|
| {package_id} | {version} | {compatible/additive/immutable} | {specific version or latest} | YES/NO |
Check:
UpgradeCap holder pose a risk?| Protocol Change | Downstream Consumer Type | Expected Interface/Type | Actual Post-Migration | Breaking Change? |
|---|---|---|---|---|
| {change} | Other Sui packages (composability) | {expected type} | {actual type} | YES/NO |
| {change} | Indexers/explorers | {expected event structure} | {actual} | YES/NO |
| {change} | Frontend/SDK | {expected PTB structure} | {actual} | YES/NO |
| {change} | PTB composers (DeFi aggregators) | {expected function signature} | {actual} | YES/NO |
Sui-specific: PTB composability means other protocols may compose our public functions into their PTBs. If function signatures or return types change, ALL downstream PTB composers break silently.
compatible policy preserves existing types## Finding [MG-N]: Title
**Verdict**: CONFIRMED / PARTIAL / REFUTED / CONTESTED
**Step Execution**: checkmark1,2,3,4,5,6 | xN(reason) | ?N(uncertain)
**Rules Applied**: [R4:___, R9:___, R10:___, R13:___]
**Severity**: Critical/High/Medium/Low/Info
**Location**: sources/{module}.move:LineN
**Object Transition**:
- Old: {old_package::module}
- New: {new_package::module}
- Mismatch Point: {where types/versions diverge}
**Description**: What is wrong
**Impact**: What can happen (stranded funds, bypassed security, broken composability)
**Evidence**: Code showing mismatch
### Precondition Analysis (if PARTIAL/REFUTED)
**Missing Precondition**: [What blocks exploitation]
**Precondition Type**: STATE / ACCESS / TIMING / EXTERNAL / BALANCE
### Postcondition Analysis (if CONFIRMED/PARTIAL)
**Postconditions Created**: [What conditions this creates]
**Postcondition Types**: [List applicable types]| Step | Required | Completed? | Notes |
|---|---|---|---|
| 1. Identify Token Transitions | YES | Upgrade lineage vs separate deployment | |
| 2. Check Interface Compatibility | YES | Sui upgrade policy rules | |
| 3. Trace Token Flow Paths | YES | ||
| 3b. External Side Effect Compatibility | YES | ||
| 3c. Pre-Upgrade Object Inventory | YES | ||
| 4. Stranded Asset Analysis (4a-4e) | YES | All four scenarios modeled | |
| 4f. User-Blocks-Admin Scenarios | YES | ||
| 5. External Package Verification | YES | ||
| 6. Downstream Integration Compatibility | YES |
If any step skipped, document valid reason (N/A, immutable package, single version, no downstream consumers).
© PlamenTSV, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in agents/skills/sui/migration-analysis of PlamenTSV/plamen.
Open the folder on GitHubat commit 795962b
Migration Analysis next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Migration Analysis this skillPlamenTSV/plamen | 303 | — | ~3.4k | Automated safety check: Pass | MIT | |
| Kotlin Exposed Patternsaffaan-m/ECC | 275k | 4 repos | ~5.5k | Automated safety check: Pass | MIT | |
| Safe Database Migration Patternsaffaan-m/ECC | 275k | — | ~3.3k | Automated safety check: Pass | MIT | |
| Golang Patternsaffaan-m/ECC | 275k | — | ~1.1k | Automated safety check: Pass | MIT | |
| Deprecate R Functions and Argumentstidyverse/dplyr | 5.1k | 1 repos | ~1.2k | Automated safety check: Pass | Custom licence | |
| Database Migrationsaffaan-m/ECC | 275k | 4 repos | ~3k | Automated safety check: Pass | MIT |
affaan-m/ECC
JetBrains Exposed ORM patterns including DSL queries, DAO pattern, transactions, HikariCP connection pooling, Flyway migrations, and repository pattern.
affaan-m/ECC
Rules and examples for safe, reversible schema changes in production: zero-downtime column and index changes, large data backfills and ORM migration workflows.
affaan-m/ECC
Go-specific design patterns and best practices including functional options, small interfaces, dependency injection, concurrency patterns, error handling, and package organization.
tidyverse/dplyr
Walks through deprecating an R function or argument in a package: lifecycle warning, silenced tests, a new snapshot test, documentation badge and NEWS entry.
affaan-m/ECC
Safe, reversible database migration patterns: forward-only production changes, expand-contract zero-downtime renames, concurrent indexes, batched backfills, and per-tool workflows for PostgreSQL…
jeremylongshore/tons-of-skills-marketplace
Plan and execute Deepgram SDK upgrades and model migrations.
PlamenTSV/plamen
Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project…
PlamenTSV/plamen
Trigger Pattern Always (used by all verifier agents) - Inject Into security-verifier agents (Phase 5)
PlamenTSV/plamen
Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth agents, depth agents
PlamenTSV/plamen
Trigger Pattern Always (Sui Move) -- foundational security check - Inject Into Breadth agents, depth agents
PlamenTSV/plamen
Trigger Pattern ACCOUNTCLOSING flag detected (close/CloseAccount usage) - Inject Into Breadth agents, depth agents
PlamenTSV/plamen
Trigger Pattern Always required for Solana audits - Inject Into Breadth agents, depth agents
Trigger Pattern Package upgrades, version transitions, deprecated functions, object layout changes - Inject Into Breadth agents, depth-state-trace. Migration Analysis is an agent skill from PlamenTSV/plamen.
Migration Analysis fits situations like: pattern Package upgrades; version transitions; deprecated functions; object layout changes - Inject Into Breadth agents.
Run `npx skills add PlamenTSV/plamen --skill migration-analysis -a claude-code`. Or copy the skill folder (agents/skills/sui/migration-analysis in PlamenTSV/plamen) into .claude/skills/migration-analysis in your project. Claude Code loads it when a task matches its description.
Run `npx skills add PlamenTSV/plamen --skill migration-analysis -a codex`. Or copy the skill folder (agents/skills/sui/migration-analysis in PlamenTSV/plamen) into .agents/skills/migration-analysis in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PlamenTSV/plamen --skill migration-analysis -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/migration-analysis, .gemini/skills/migration-analysis, .github/skills/migration-analysis and .opencode/skills/migration-analysis in your project.
SKILL.md names no scripts, command-line tools or credentials: Migration Analysis is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Migration Analysis is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.4k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Migration Analysis: Kotlin Exposed Patterns (affaan-m/ECC, 275k stars), Safe Database Migration Patterns (affaan-m/ECC, 275k stars), Golang Patterns (affaan-m/ECC, 275k stars) and Deprecate R Functions and Arguments (tidyverse/dplyr, 5.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
PlamenTSV (a GitHub user) maintains it in PlamenTSV/plamen, which has 303 GitHub stars. The repository holds 87 skills in this directory. The repository was last updated on September 26, 2026.
Source: PlamenTSV/plamen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.