Agent skill

Oracle Analysis

by PlamenTSV in PlamenTSV/plamen

Trigger Pattern ORACLE flag (required) - Inject Into Breadth agents, depth-external, depth-edge-case

MITAuto-check passedBackend & APIs

Install Oracle Analysis

skills CLI
$ npx skills add PlamenTSV/plamen --skill oracle-analysis -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install PlamenTSV/plamen oracle-analysis --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agents/skills/evm/oracle-analysis .claude/skills/oracle-analysis && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
oracle-analysis
GitHub stars
303
Token cost
~3.4k tokens
SKILL.md length
1,482 words
Files
1
Skills in repo
87
Repo updated
First seen
Licence
MIT

At a glance

Trigger Pattern ORACLE flag (required) - Inject Into Breadth agents, depth-external, depth-edge-case

  • Works in 6 steps: Oracle Inventory → Staleness Analysis → Decimal Normalization Audit → …
  • Pattern ORACLE flag (required) - Inject Into Breadth agents
  • SKILL.md covers 1. Oracle Inventory, 2. Staleness Analysis, 3. Decimal Normalization Audit and 4. TWAP-Specific Analysis, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Oracle Analysis is an agent skill from PlamenTSV/plamen. Trigger Pattern ORACLE flag (required) - Inject Into Breadth agents, depth-external, depth-edge-case

Its SKILL.md is about 3.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Smart contracts. The repository describes itself as: Autonomous Web3 security audit agent for Claude Code. The licence is MIT.

When your agent uses it

  • Pattern ORACLE flag (required) - Inject Into Breadth agents
  • Depth-edge-case

Example prompts

  • “/oracle-analysis”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Oracle Inventory
  2. Staleness Analysis
  3. Decimal Normalization Audit
  4. TWAP-Specific Analysis
  5. Oracle Weight / Threshold Boundaries
  6. Oracle Failure Modes

What it can do on your machine

Read from SKILL.md and the folder at commit 795962b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Oracle Analysis loads about 3.4k tokens when it runs. Until then it costs about 29 tokens; SKILL.md has 1,482 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~29
When it runs · the whole SKILL.md, loaded when a task matches
~3.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from PlamenTSV/plamen at commit 795962b, republished under its MIT licence (© PlamenTSV). 1,482 words, ~3,403 tokens.

Download SKILL.mdSave it as .claude/skills/oracle-analysis/SKILL.md (or your agent's skills folder).
name
oracle-analysis
description
Trigger Pattern ORACLE flag (required) - Inject Into Breadth agents, depth-external, depth-edge-case

ORACLE_ANALYSIS Skill

Trigger Pattern: ORACLE flag (required) Inject Into: Breadth agents, depth-external, depth-edge-case

For every oracle the protocol consumes:

⚠ STEP PRIORITY: Steps 6 (Failure Modes) and 5c (Deviation Reference) are where HIGH/CRITICAL severity findings most commonly hide. Do NOT rush these steps. If constrained, skip conditional sections (4a-4d, 5a) before skipping 5c or 6.

1. Oracle Inventory

Enumerate ALL oracle data sources the protocol reads:

OracleTypeSource ContractFunctions CalledConsumers (protocol functions)Update FrequencyHeartbeat
{name}Chainlink / TWAP / Spot / Custom / Band / Pyth{address}{latestRoundData / observe / etc.}{list all}{expected}{documented or UNKNOWN}

For each oracle: What decision does the protocol make based on this data? (pricing, liquidation threshold, reward rate, rebase trigger, etc.)

Hardcoded stablecoin pricing check: Does the protocol skip oracle lookup for any asset and hardcode its price to a constant (e.g., 1e8 for USDC, 1e18 for DAI)? If yes → FINDING. All assets require dynamic oracle pricing — stablecoins depeg, and hardcoded pricing fails silently when they do. Check: return 1e8, return 1e18, price = PRECISION, or an oracle mapping that excludes specific tokens.

2. Staleness Analysis

For each oracle identified in Step 1:

2a. Staleness Checks Present?
OracleupdatedAt Checked?Max Staleness Enforced?Staleness ThresholdAppropriate?
{name}YES/NOYES/NO{seconds or NONE}{analysis}

If NO staleness check: What happens when the oracle returns stale data?

  • Protocol uses stale price for liquidations → unfair liquidations
  • Protocol uses stale price for minting → mispriced assets
  • Protocol uses stale price for swaps → arbitrage opportunity
  • Protocol uses stale rate for rewards → incorrect distribution
2b. Stale Data Impact Trace

For each consumer function, trace the impact of receiving data that is {heartbeat × 2} old:

Consumer FunctionData UsedIf Stale By {X}: ImpactSeverity
{function}{price/rate}{specific impact}{H/M/L}
CheckCode ReferenceStatus
latestRoundData() return values ALL checked?{location}YES/NO
answeredInRound >= roundId verified?{location}YES/NO
price > 0 validated?{location}YES/NO
updatedAt != 0 validated?{location}YES/NO
Sequencer uptime feed checked? (L2 only){location}YES/NO/N/A
2d. Pull-Based Oracle Checks (Pyth, Redstone, etc.)

If the protocol uses a pull-based oracle where users supply price data in the transaction:

Processing: ENUMERATE all pull-based oracle update/read sites → PROCESS each against the checks below → verify coverage before proceeding to Section 3.

CheckCode ReferenceStatus
Timestamp monotonicity: Does the protocol verify the new update's timestamp >= the previously stored timestamp?{location}YES/NO
Pyth confidence interval: Is price.conf checked relative to price.price? (e.g., reject if conf/price > threshold){location}YES/NO
Pyth price sign: Is price.price validated as > 0? (Pyth returns int64){location}YES/NO
Pyth exponent handling: Is price.expo (typically negative, e.g., -8) correctly applied when converting to protocol decimals?{location}YES/NO

Timestamp monotonicity attack (Redstone, Pyth, any pull model): If the protocol stores a price at timestamp T and accepts a later update at timestamp T-Δ (within the allowed staleness window), an attacker can roll back the price. Example: price is $3000 at T=now; attacker updates to $2900 at T=now-3min (within Redstone's 3-min window); borrower is liquidated at the stale-but-accepted price. Defense: require(newTimestamp >= lastStoredTimestamp).

Pyth confidence interval attack: Pyth returns price ± confidence bracket. If the protocol uses the raw price without accounting for confidence, it may allow borrowing/liquidation at a price that is up to conf away from the true price. Defense: for collateral pricing use price - conf (pessimistic), for debt pricing use price + conf (pessimistic), always favoring protocol safety over user benefit.

3. Decimal Normalization Audit

For each oracle data flow:

OracleOracle DecimalsConsumer ExpectsNormalization Applied?Correct?
{name}{decimals()}{expected by math}YES/NO{analysis}

Check: Does the protocol call decimals() dynamically or hardcode it? If hardcoded → what if oracle upgrades and changes decimals?

MANDATORY GREP: Search all oracle consumer files for 1e18, 1e8, 1e6, 10**18, 10**8, 10**6, 1e10, 10**10. For each hit: (1) Is this a decimal normalization constant? (2) Does it match the ACTUAL oracle's decimals() return value? (3) If the oracle is swapped or upgraded, does this constant break?

Decimal chain trace: For each arithmetic operation using oracle data, trace the full decimal chain: oracle_output_decimals → normalization_step → consumer_expected_decimals. If any step uses a hardcoded constant rather than reading decimals() dynamically → FINDING.

Common decimal mismatches:

  • Chainlink USD feeds: 8 decimals, but protocol assumes 18
  • Chainlink ETH feeds: 18 decimals
  • Token decimals: varies (6 for USDC, 18 for DAI)
  • Cross-multiplication without normalization: price * amount where price and amount have different decimal bases

Trace: For each arithmetic operation using oracle data, verify dimensional consistency:

result_decimals = oracle_decimals + token_decimals - normalization_decimals
Expected: result_decimals == output_decimals
3d. Decimal Grep Sweep (MECHANICAL - MANDATORY)

Grep ALL oracle consumer files for 10**|decimals()|1e[0-9]|normaliz. For each match, fill:

File:LinePatternHardcoded ValueOracle's Actual DecimalsMatch?

If ANY row shows Match=NO or oracle decimals UNKNOWN with hardcoded constant → FINDING (R16). Skipping this step is a Step Execution violation (✗3d).

<!-- LOAD_IF: TWAP -->

4. TWAP-Specific Analysis

If protocol uses any TWAP oracle (Uniswap V3 observe(), custom TWAP, etc.):

4a. TWAP Window Analysis
TWAP OracleWindow LengthPool LiquidityManipulation Cost (est.)Sufficient?
{oracle}{seconds}{USD value}{estimated}YES/NO

Rule of thumb: TWAP window < 30 min AND pool TVL < $10M → potentially manipulable.

4b. TWAP Arithmetic
CheckStatusImpact if Wrong
Overflow protection on tickCumulatives difference?YES/NO{impact}
Geometric vs arithmetic mean - correct for use case?{which used}{impact if wrong}
Time-weighted vs block-weighted - which is used?{which}{manipulation vector}
Empty observation slots handled?YES/NO{impact}
4c. TWAP Lagging Behavior

During rapid price movements, TWAP lags spot price. Trace:

  • What happens when TWAP price is significantly lower than spot? (discounted minting/borrowing)
  • What happens when TWAP price is significantly higher than spot? (premium liquidations)
  • Is this lag exploitable by attackers who can predict the direction?
Show full SKILL.md (576 more words)Show less
4d. TWAP Cold-Start Analysis

Check oracle behavior when history is insufficient: (1) zero snapshots, (2) single snapshot, (3) window period not yet elapsed.

Cold-Start StateOracle Return ValueProtocol BehaviorExploitable?

For each exploitable state: can attacker act during cold-start window at manipulated price? Tag: [BOUNDARY:snapshots=0], [BOUNDARY:snapshots=1]. If TWAP returns 0 or reverts during cold-start with no fallback → FINDING (R16, minimum Medium).

<!-- END_LOAD_IF: TWAP -->

5. Oracle Weight / Threshold Boundaries

For multi-oracle systems or oracle-based thresholds:

<!-- LOAD_IF: MULTI_ORACLE -->
5a. Multi-Oracle Systems
Oracle SystemAggregation MethodOracle CountAgreement RequiredWhat if Disagreement?
{system}Median / Mean / Weighted / First-valid{N}{M of N}{fallback behavior}

Check: What happens at exact threshold boundaries?

  • If median of [100, 100, 101]: result = 100. Is that correct?
  • If weighted average with equal weights rounds down: impact?
  • If one oracle reverts: does fallback handle it gracefully?
<!-- END_LOAD_IF: MULTI_ORACLE -->
5b. Oracle-Based Thresholds
ThresholdOracle Data UsedThreshold ValueAt Exact BoundaryOff-by-One?
{name}{oracle field}{value}{behavior at exact value}YES/NO

Check > vs >=: At the exact threshold value, does the protocol behave as intended?

5c. Deviation Reference Point Audit

For each deviation check in the protocol (maxDeviation, priceDeviation, deviationThreshold, etc.):

ParameterMeasured AgainstReference SourceReference Manipulable?Reference Staleable?

Checks:

  1. What is the deviation MEASURED AGAINST? (previous on-chain price, TWAP, external oracle, hardcoded value)
  2. Is the reference point itself manipulable? (e.g., if deviation checks current vs last-recorded, and last-recorded is admin-settable → admin can set a stale reference that makes all future prices "within deviation")
  3. Can the reference become stale? (e.g., if reference is updated only on specific actions, and those actions stop occurring)
  4. Is the first recorded price special? (no prior reference → deviation check may be bypassed on first update)
  5. Chained feed deviation stacking: If the protocol computes a derived price from multiple oracle feeds (e.g., wBTC→BTC→ETH→UNI requires wBTC/BTC + BTC/ETH + UNI/ETH feeds), individual deviation thresholds compound. Sum the maximum deviations across all feeds in the chain to compute total worst-case deviation. If total compounded deviation exceeds the protocol's liquidation margin or LTV buffer → FINDING. Example: 0.5% + 2% + 2% = 4.5% total deviation; if liquidation threshold is only 5% above LTV, the oracle can be 4.5% stale before triggering, leaving <1% real buffer. Tag: [TRACE:deviation check: current vs {reference} → reference source: {X} → manipulable: {Y/N}]

6. Oracle Failure Modes

For each oracle, model failure scenarios:

Failure ModeOracle BehaviorProtocol ResponseImpactMitigation Present?
Zero returnReturns 0{what happens}{impact}YES/NO
RevertCall reverts{what happens}{impact}YES/NO - try/catch?
Stale (heartbeat exceeded)Returns old data{what happens}{impact}YES/NO - staleness check?
Extreme valueReturns outlier{what happens}{impact}YES/NO - bounds check?
Negative price (Chainlink int256)Returns < 0{what happens}{impact}YES/NO - sign check?
Sequencer down (L2)Stale + backlog{what happens}{impact}YES/NO - uptime feed?

For each unmitigated failure mode: What is the worst-case impact? Can it lead to fund loss?

Circuit breaker check: Does the protocol have a mechanism to pause oracle-dependent operations if the oracle enters a failure state?

Finding Template

markdown
**ID**: [OR-N]
**Severity**: [based on fund impact and likelihood of oracle failure/manipulation]
**Step Execution**: ✓1,2,3,4,5,6 | ✗(reasons) | ?(uncertain)
**Rules Applied**: [R1:✓, R4:✓, R10:✓, R16:✓]
**Location**: Contract.sol:LineN
**Title**: Oracle [issue type] in [function] enables [attack/failure]
**Description**: [Specific oracle issue with data flow trace]
**Impact**: [Quantified impact under worst-case oracle scenario]

Step Execution Checklist (MANDATORY)

SectionRequiredCompleted?Notes
1. Oracle InventoryYES✓/✗/?
2. Staleness AnalysisYES✓/✗/?For each oracle
3. Decimal Normalization AuditYES✓/✗/?
3d. Decimal Grep SweepYES✓/✗/?MANDATORY mechanical step
4. TWAP-Specific AnalysisIF TWAP used✓/✗(N/A)/?
4d. TWAP Cold-Start AnalysisIF TWAP used✓/✗(N/A)/?Zero/single snapshot states
5. Oracle Weight / Threshold BoundariesIF multi-oracle or thresholds✓/✗(N/A)/?
5c. Deviation Reference Point AuditIF deviation checks exist✓/✗(N/A)/?Reference manipulability
6. Oracle Failure ModesYES✓/✗/?For each oracle

© PlamenTSV, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in agents/skills/evm/oracle-analysis of PlamenTSV/plamen.

Open the folder on GitHubat commit 795962b

Compare with similar skills

Oracle Analysis next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Oracle Analysis compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Oracle Analysis this skillPlamenTSV/plamen303—~3.4kAutomated safety check: PassMIT
Fizz Convertpashov/skills1.2k2 repos~3.7kAutomated safety check: PassMIT
Solana Devsolana-foundation/solana-dev-skill574—~3.8kAutomated safety check: PassMIT
Feynman Auditor0xiehnnkta/nemesis-auditor2431 repos~11kAutomated safety check: PassMIT
Smart Contract Auditgreatpie/smart-contract-audit-skill101—~1.1kAutomated safety check: PassNone
RadarAuditware/radar154—~2.1kAutomated safety check: PassGPL-3.0

Similar skills

  • Fizz Convert

    pashov/skills

    Convert English-language properties in PROPERTIES.md (produced by the Fizz skill) into Solidity assertions inside the existing fuzz harness, then flip their checkboxes.

    1.2k GitHub starsUsed in 2 repos~3.7k tokens
    Backend & APIsAuto-check passed
  • Solana Dev

    solana-foundation/solana-dev-skill

    A skill your agent uses when user asks to "build a Solana dapp", "write an Anchor program", "create a token", "debug Solana errors", "set up wallet connection", "test my Solana program", "fuzz my…

    574 GitHub stars~3.8k tokensUpdated today
    Backend & APIsAuto-check passed
  • Feynman Auditor

    0xiehnnkta/nemesis-auditor

    Deep business logic bug finder using the Feynman technique. An agent skill from 0xiehnnkta/nemesis-auditor.

    243 GitHub starsUsed in 1 repo~11k tokens
    Backend & APIsAuto-check passed
  • Smart Contract Audit

    greatpie/smart-contract-audit-skill

    Script-backed, out-of-box auditing workflow for Solidity/EVM repositories based on EVMbench detect/patch/exploit methodology.

    101 GitHub stars~1.1k tokensUpdated 7 mo ago
    Backend & APIsAuto-check passed
  • Radar

    Auditware/radar

    Use radar for smart contract security analysis, AST generation, and detection template development.

    154 GitHub stars~2.1k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Solidity Auditor

    Gabson0x/bountyforge

    Security audit of Solidity code while you develop. An agent skill from Gabson0x/bountyforge.

    443 GitHub stars~3.7k tokensUpdated 21 days ago
    Backend & APIsAuto-check passed

More from PlamenTSV/plamen

All 87 skills in this repo
  • Audit Prep

    PlamenTSV/plamen

    Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project…

    303 GitHub stars~3.7k tokensUpdated 12 days ago
    Auto-check passed
  • Verification Protocol

    PlamenTSV/plamen

    Trigger Pattern Always (used by all verifier agents) - Inject Into security-verifier agents (Phase 5)

    303 GitHub stars~3.5k tokensUpdated 12 days ago
    Auto-check passed
  • Ability Analysis

    PlamenTSV/plamen

    Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth agents, depth agents

    303 GitHub stars~3.3k tokensUpdated 12 days ago
    Auto-check passed
  • Ability Analysis

    PlamenTSV/plamen

    Trigger Pattern Always (Sui Move) -- foundational security check - Inject Into Breadth agents, depth agents

    303 GitHub stars~3.2k tokensUpdated 12 days ago
    Auto-check passed
  • Account Lifecycle

    PlamenTSV/plamen

    Trigger Pattern ACCOUNTCLOSING flag detected (close/CloseAccount usage) - Inject Into Breadth agents, depth agents

    303 GitHub stars~1.2k tokensUpdated 12 days ago
    Auto-check passed
  • Account Validation

    PlamenTSV/plamen

    Trigger Pattern Always required for Solana audits - Inject Into Breadth agents, depth agents

    303 GitHub stars~1.7k tokensUpdated 12 days ago
    Auto-check passed

Categories

Questions about Oracle Analysis

What does Oracle Analysis do?

Trigger Pattern ORACLE flag (required) - Inject Into Breadth agents, depth-external, depth-edge-case. Oracle Analysis is an agent skill from PlamenTSV/plamen.

When should I use Oracle Analysis?

Oracle Analysis fits situations like: pattern ORACLE flag (required) - Inject Into Breadth agents; depth-edge-case.

How do I install Oracle Analysis in Claude Code?

Run `npx skills add PlamenTSV/plamen --skill oracle-analysis -a claude-code`. Or copy the skill folder (agents/skills/evm/oracle-analysis in PlamenTSV/plamen) into .claude/skills/oracle-analysis in your project. Claude Code loads it when a task matches its description.

How do I install Oracle Analysis in Codex?

Run `npx skills add PlamenTSV/plamen --skill oracle-analysis -a codex`. Or copy the skill folder (agents/skills/evm/oracle-analysis in PlamenTSV/plamen) into .agents/skills/oracle-analysis in your project. Codex loads it when a task matches its description.

Can I use Oracle Analysis in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PlamenTSV/plamen --skill oracle-analysis -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/oracle-analysis, .gemini/skills/oracle-analysis, .github/skills/oracle-analysis and .opencode/skills/oracle-analysis in your project.

What does Oracle Analysis need to run?

SKILL.md names no scripts, command-line tools or credentials: Oracle Analysis is instructions for the agent only.

Does Oracle Analysis access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Oracle Analysis safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Oracle Analysis use?

Oracle Analysis is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Oracle Analysis use?

About 3.4k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Oracle Analysis?

Skills that share tags, products or a category with Oracle Analysis: Fizz Convert (pashov/skills, 1.2k stars), Solana Dev (solana-foundation/solana-dev-skill, 574 stars), Feynman Auditor (0xiehnnkta/nemesis-auditor, 243 stars) and Smart Contract Audit (greatpie/smart-contract-audit-skill, 101 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Oracle Analysis?

PlamenTSV (a GitHub user) maintains it in PlamenTSV/plamen, which has 303 GitHub stars. The repository holds 87 skills in this directory. The repository was last updated on September 26, 2026.

Source: PlamenTSV/plamen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.