Agent skill

P2p Dos And Eclipse

by PlamenTSV in PlamenTSV/plamen

L1 trigger - audits peer-to-peer networking for DoS vectors (resource exhaustion, amplification), eclipse attack susceptibility, and discovery table poisoning (Kademlia/devp2p).

MITAuto-check passedSecurity

Install P2p Dos And Eclipse

skills CLI
$ npx skills add PlamenTSV/plamen --skill p2p-dos-and-eclipse -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install PlamenTSV/plamen p2p-dos-and-eclipse --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agents/skills/injectable/l1/p2p-dos-and-eclipse .claude/skills/p2p-dos-and-eclipse && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
p2p-dos-and-eclipse
GitHub stars
303
Token cost
~4k tokens
SKILL.md length
1,905 words
Files
1
Skills in repo
87
Repo updated
First seen
Licence
MIT

At a glance

L1 trigger - audits peer-to-peer networking for DoS vectors (resource exhaustion, amplification), eclipse attack susceptibility, and discovery table poisoning (Kademlia/devp2p).

  • Works in 8 steps: Attack Surface Enumeration (Entry Points) → DoS Classes to Check per Entry Point → Eclipse Attack Vectors → …
  • - audits peer-to-peer networking for DoS vectors (resource exhaustion
  • SKILL.md covers Orchestrator Decomposition Guide, When This Skill Activates, 1. Attack Surface Enumeration… and 2. DoS Classes to Check per…, plus 8 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

P2p Dos And Eclipse is an agent skill from PlamenTSV/plamen. L1 trigger - audits peer-to-peer networking for DoS vectors (resource exhaustion, amplification), eclipse attack susceptibility, and discovery table poisoning (Kademlia/devp2p).

Its SKILL.md is about 4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security. The repository describes itself as: Autonomous Web3 security audit agent for Claude Code. The licence is MIT.

When your agent uses it

  • - audits peer-to-peer networking for DoS vectors (resource exhaustion
  • Eclipse attack susceptibility
  • Discovery table poisoning (Kademlia/devp2p)

Example prompts

  • “/p2p-dos-and-eclipse”

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Attack Surface Enumeration (Entry Points)
  2. DoS Classes to Check per Entry Point
  3. Eclipse Attack Vectors
  4. Peer Scoring and Banning
  5. Gossip / Pubsub
  6. Output schema
  7. Known bug exemplars (v0.2 — Round 4 verified)
  8. Fallback if primitives unavailable

What it can do on your machine

Read from SKILL.md and the folder at commit 795962b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • zellic.io
    • eprint.iacr.org
    • researchgate.net
    • arxiv.org
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

P2p Dos And Eclipse loads about 4k tokens when it runs. Until then it costs about 49 tokens; SKILL.md has 1,905 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~49
When it runs · the whole SKILL.md, loaded when a task matches
~4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from PlamenTSV/plamen at commit 795962b, republished under its MIT licence (© PlamenTSV). 1,905 words, ~3,955 tokens.

Download SKILL.mdSave it as .claude/skills/p2p-dos-and-eclipse/SKILL.md (or your agent's skills folder).
name
p2p-dos-and-eclipse
description
L1 trigger - audits peer-to-peer networking for DoS vectors (resource exhaustion, amplification), eclipse attack susceptibility, and discovery table poisoning (Kademlia/devp2p).

Injectable Skill: P2P DoS and Eclipse Attacks

L1 trigger: L1_PATTERN=true AND (p2p/ OR network/ OR discovery/ OR libp2p OR devp2p OR enr OR discv5 detected in recon subsystem map) Inject Into: depth-network-surface Language: Go and Rust Finding prefix: [P2P-N] Status: v0.1 draft, Round 4 exemplars pending

Orchestrator Decomposition Guide

  • Sections 1, 2: depth-network-surface (attack surface + DoS)
  • Section 3: depth-state-trace (peer table state)
  • Section 4: depth-edge-case (boundary/adversarial peer states)

When This Skill Activates

Recon identifies a P2P subsystem. Most attacks in this class are out-of-scope for typical bounty programs but are in scope for Plamen audits — firms like Sigma Prime and OpenZeppelin explicitly cover them. Severity downgrades to Low/Info when the exploit only eclipses a single node (see severity-matrix.md); upgrades when reachable by arbitrary peers and amplifies across the network.

1. Attack Surface Enumeration (Entry Points)

Every P2P subsystem has a finite set of entry points for remote adversary bytes. Enumerate them using LSP workspace/symbol and ast-grep:

Entry point typeHow to findExample functions
Message handlersTrait/interface impl names ending in Handler, Service, ListenerhandleGetBlockHeaders, on_new_pooled_transaction_hashes
DecodersFunctions taking &[u8] or Reader and returning protocol typesdecode_enr, rlp_decode
Connection acceptersTCP/QUIC listener accept loopsacceptLoop, handle_connection
Discovery respondersUDP packet handlers for discovery protocolhandleDiscv5Packet, process_find_node
Gossip handlersPubsub topic subscribersprocess_gossip_message

Write the enumeration into scratchpad/p2p_surface.md before proceeding.

2. DoS Classes to Check per Entry Point

2a. Asymmetric processing cost

Attacker sends N bytes, node does O(N²) or O(N*log(N)) work. Classic example: decompression bombs, hash-map insertion of attacker-chosen keys (hash DoS), large RLP lists.

Check:

  • For each decoder, is there a max size limit before parsing begins?
  • For each list/vector field, is there a max element count enforced?
  • For each recursive decoder, is there a max recursion depth?
  • For each hash-map insert of attacker-controlled data, is the map key pre-hashed or is a SipHash-random-keyed map used?

Tag: [P2P-ASYMMETRIC:{loc}:{input-size}→{work-cost}]

2b. Unbounded memory growth

Handlers that buffer or queue indefinitely.

Check:

  • Every channel/queue: does it have a bounded capacity? What happens on overflow — block, drop, or OOM?
  • Every append / Vec::push in a loop that can be driven by adversary: is there a bound?
  • Every peer-keyed map (peer → state): is there an eviction policy when size > threshold?

Tag: [P2P-UNBOUNDED:{structure}:{growth-driver}]

2c. Unbounded CPU: infinite loops or pathological inputs

Handlers that can loop forever or spend minutes on malicious input.

Check:

  • Every for loop in a handler: what bounds termination? Attacker-controlled?
  • Regex with catastrophic backtracking (if any regex is used on peer input)
  • Crypto operations on unvalidated length inputs

Tag: [P2P-CPU:{loc}:{termination-condition}]

2d. Connection slot exhaustion

Attacker opens N connections with M peers, filling the connection table.

Check:

  • What is the max inbound connection limit? (Geth: 50, Bitcoin: 125)
  • Is there a per-IP limit? Per-/24-subnet limit? Per-ASN limit?
  • How long can a half-open (TCP SYN + no handshake) connection hold a slot?
  • Does the node prioritize connections from diverse IP ranges?
  • Outbound bootstrap handshake cap: when a joining node receives a peer list from a bootnode, does it cap the number of addresses it attempts to handshake in parallel? Without a cap, a malicious bootnode (or a peer-list response with N>>peer-table-size) forces the joiner to exhaust file descriptors / memory / connection slots during startup. Verify both the per-bootstrap response cap AND the in-flight handshake concurrency limit.

Tag: [P2P-SLOTS:{limit}:{diversification}], [P2P-BOOTSTRAP-FLOOD:{cap-or-unbounded}]

2e. Amplification

Attacker sends small message, node sends large response — used to DDoS third parties.

Check:

  • For every request-response pair, compare input size vs output size
  • Discovery protocols (UDP) are especially dangerous — no handshake, easy spoofing
  • Is source-address validation (rate-limited ENR responses, etc.) in place?

Tag: [P2P-AMPLIFY:{request-bytes}→{response-bytes}]

2g. Re-gossip dedup discipline (echo-chamber amplification)

For each gossip handler that RECEIVES data and then FORWARDS it to other peers (re-gossip), trace the dedup path. This is a separate concern from 2a (single-message cost) — it covers network-multiplication attacks.

Check:

  • Is there a "recent-seen" or "recent-valid" cache that BLOCKS re-broadcast on duplicates?
  • Is the cache check BEFORE the broadcast spawn / .send() call, not after?
  • Is the cache key the message hash (not the message contents, which an attacker can mutate while preserving semantics)?
  • Is the cache populated AFTER signature/validity verification, not before? Recording-as-seen pre-verification creates a "seen-cache poisoning" primitive: an attacker injects an invalid item with a valid ID, the cache records it, the legitimate version from honest peers is then dropped as "already seen".
  • For each handler, walk the order of operations: verify_signature → record_seen → broadcast. Any other order is a finding.

Fail mode: an N-peer network re-gossips each message O(N²) times, saturating bandwidth in an "echo chamber" pattern. NEAR / Tendermint / Geth have all had variants of this bug. Combined with seen-cache poisoning, an attacker can both flood the network AND censor legitimate items.

Tag: [P2P-AMPLIFY:re-gossip-dedup:{file}:{line}] and [P2P-CACHE-POISON:record-before-verify:{file}:{line}]

2h. Sequential broadcast vs parallel broadcast

Many P2P implementations naively use for peer in active_peers { client.send(peer, msg).await; } to broadcast. Each peer's response time blocks the next. A single slow peer (intentional or not) delays the entire broadcast cycle.

Check:

  • For each broadcast loop, identify whether peers are processed sequentially with .await or in parallel with tokio::join_all / FuturesUnordered / select!.
  • For sequential broadcast loops, calculate worst-case wall-clock: peer_count × per-peer-timeout. If this exceeds block time, propagation is broken under adversarial peer growth.
  • Cap the total broadcast peer count to a constant (e.g., 200 randomly sampled peers); rely on gossip amplification for full propagation.

Tag: [P2P-CPU:sequential-broadcast:{loc}]

3. Eclipse Attack Vectors

An eclipse attack isolates a target node by monopolizing its peer table entries.

3a. Peer table structure
  • Identify the peer table data structure (Kademlia k-buckets, flat table, discovery v5 ENR table)
  • For each bucket, what is the k value and eviction policy?
  • Is peer selection stratified by IP/ASN diversity, or purely by XOR distance?
3b. Peer ID generation cost
  • How expensive is it to produce a peer ID that lands in a target bucket?
  • Ethereum discovery v5: node ID = hash(public key). Generating thousands of node IDs is cheap.
  • Some protocols require proof-of-work for peer IDs; most don't.
  • Is there a rate limit on accepting new peer announcements?
3c. Bootstrap / rejoin vulnerability

On restart, the node uses a static bootstrap list, then populates its peer table from responses. If an attacker can intercept or outrun the bootstrap response, they control the initial peer set.

Check: What bootnodes are used? Are they hardcoded or configurable? What happens if all bootnodes are unreachable?

3d. ENR/record poisoning

Discovery v5 uses signed ENRs. Can an attacker poison a victim's ENR cache with malicious entries?

Check: ENR signature verification on every incoming record. ENR seqnum monotonic update.

Tag: [ECLIPSE:{vector}:{countermeasure-state}]

Known exemplar class: devp2p issue #109 (Ethereum discv5 eclipse concerns); academic low-resource eclipse attacks on older Geth.

4. Peer Scoring and Banning

Most clients have a peer scoring system: peers that misbehave (send invalid data, stall, equivocate) accumulate negative score and get banned.

Show full SKILL.md (787 more words)Show less
Patterns to flag
  • Integer overflow in score: if score is i32, repeatedly adding -MAX causes wrap. Geth has historically had integer-overflow issues in peer scoring.
  • Permanent ban on transient fault: banning on a single protocol error can be exploited to deny service to honest peers via spoofed errors
  • Asymmetric scoring: does good behavior recover lost score? If not, a single bad day permanently bans a good peer
  • Scoring based on attacker-controlled timing: if score updates on every packet and attacker can drive packet rate, scoring becomes attacker-controlled

Tag: [P2P-SCORE:{vulnerability-class}]

5. Gossip / Pubsub

If the protocol uses gossipsub or similar pubsub:

  • Message deduplication: is there a seen-cache? How large? What TTL? Can it be exhausted?
  • Topic validation: are topic names validated before subscribing? Can an attacker force the node to subscribe to an expensive topic?
  • Mesh sizing: mesh degree (D, D_low, D_high) — are these enforced? Can an attacker manipulate mesh composition?
  • Message size: max message size in the pubsub layer vs the application layer — mismatch is a DoS vector

Tag: [GOSSIP:{param}:{value-or-unbounded}]

6. Output schema

  • Layer: network
  • Bug class: asymmetric-cost / unbounded-resource / slot-exhaustion / amplification / eclipse / peer-score / gossip
  • Preferred evidence tags: [FUZZ-PASS] (D2PFuzz or libfuzzer on decoder) > [LSP-TRACE] > [CODE-TRACE]
  • Severity baseline: Medium by default; upgrade to High if network-wide amplification; downgrade to Low/Info if single-node eclipse only

7. Known bug exemplars (v0.2 — Round 4 verified)

  1. NEAR Signature::verify pre-auth handshake panic (December 2023) — $150,000 bounty. In SECP256K1 branch of Signature::verify(), Message::from_slice(data).expect("32 bytes") panics when payload > 32 bytes; RecoveryId::from_i32().unwrap() panics on recovery byte > 3. A single crafted Tier1Handshake/Tier2Handshake message kills any node. Pre-auth = any peer can do it. Fixed PR #10385 (commit e0f0da5c3dde29122e956dfd905811890de9a570). Zellic Web3 Ping of Death. Skill catch point: pre-auth panic check — for every handshake / pre-auth message handler, trace every .unwrap(), .expect(), panic!(), slice index, conversion. Assert graceful error return for all input classes.

  2. Marcus-Heilman low-resource Ethereum eclipse (2018) — Geth's Kademlia discovery table could be monopolized by an attacker with only 2 IPs. Fixed in geth 1.8 (Feb 2018). Low-Resource Eclipse Attacks on Ethereum. Skill catch point: Section 3a — bucket eviction policy, IP/ASN stratification, rate-limit on new peer announcements.

  3. D2PFuzz differential p2p bugs across 5 clients (IEEE 2025) — network-layer differential fuzzer found 15 unique bugs, 12 previously unknown by mutating DevP2P messages and diffing responses across geth, erigon, reth, besu, nethermind. Network-Layer Differential Fuzzing for Ethereum. Skill catch point: Section 1 — enumerate every DevP2P message type; verify response semantics against spec for valid / malformed / boundary / timing inputs; compare against ≥2 other client responses.

  4. Henningsen "false friends" Ethereum eclipse (2019) — follow-up to Marcus-Heilman. Geth's peer-eviction policy could be gamed with valid-looking false-friend nodes. Eclipsing Ethereum Peers with False Friends. Skill catch point: Section 4 — audit peer scoring for monotonicity; new peers from unknown sources must not displace established trusted peers.

  5. Geth CVE-2025-24883 RLPx handshake crash — all-zero secp256k1 public key accepted without subgroup validation. Single malicious peer crashes any node. GHSA-q26p-9cq4-7fc2. Skill catch point: cryptographic handshake inputs must be validated as on-curve AND in-subgroup BEFORE any math operation. (Shared with bls-aggregation-audit Section 2.)

Critical methodology addition from Round 4 (pre-auth panic = single-packet node kill)

Insert as new Section 2f (highest priority): Pre-auth message handlers are the hottest P2P surface. Every panic in a pre-auth path is a single-packet node-kill primitive. Methodology:

  • List every message handler reachable before authentication/handshake completion
  • For each, ast-grep or manual-read: .unwrap(), .expect(, panic!(, slice indexing [i], type assertion .(T) without ok, unreachable!(), integer division
  • Every one of these is a finding until proven bounded (e.g., a length check earlier in the call chain)

Tag: [P2P-PANIC-PREAUTH:{handler}:{panic-site}]

2i. Peer Scoring Symmetry Audit

Peer scoring only works if rewards AND penalties are both applied. A one-sided system lets malicious peers farm reputation without consequence. This section forces enumeration.

Required artifact: write {SCRATCHPAD}/peer_scoring_symmetry.md:

markdown
# Peer Scoring Symmetry: {protocol_name}

| Event | Reward path | Penalty path | Symmetric? |
|---|---|---|---|
| Successful block delivery | score.rs:L42 +1 | — | **ASYMMETRIC** |
| Invalid block response | — | score.rs:L78 -5 | OK |
| Health check failure | — | — | **MISSING** |
| /get_data served | +1 | — | **FARMABLE** |

Methodology:

  1. Find the peer scoring module (peer_score, reputation, scoring).
  2. Enumerate EVERY event type the scoring system knows about — extract from the enum/struct mapping events to score deltas, not from memory.
  3. For each event, find BOTH reward and penalty paths. Missing either → ASYMMETRIC finding.
  4. check_health specifically: does it decrement on HTTP errors / timeouts, or only on explicit Ok(false)? A no-op on failure is a finding.
  5. Verify failure-class coverage: "only InvalidData triggers penalty" while "BlockPool" or other validation failures are silent → finding.
  6. Data request endpoints (/get_data, request_blocks): if the success path increments score with no rate limit or deduplication → FARMABLE finding.
  7. Asymmetric scoring is always at least Medium severity.

Tag: [PEER-SCORE-ASYMMETRIC:{event}], [PEER-SCORE-FARMABLE:{event}], [PEER-SCORE-NO-PENALTY:{failure_class}]

8. Fallback if primitives unavailable

  • List files under p2p/ and discovery/
  • Grep for handleRLP, decode_rlp, handle_message function definitions
  • Check for explicit size limits: grep MaxSize, MAX_, limit
  • Read the bootstrap node list

Cross-references

  • Related: mempool-asymmetric-dos, consensus-safety-invariants (equivocation detection interacts with peer scoring)
  • Consumed by: depth-network-surface
  • Severity: docs/l1-mode/severity-matrix.md

© PlamenTSV, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in agents/skills/injectable/l1/p2p-dos-and-eclipse of PlamenTSV/plamen.

Open the folder on GitHubat commit 795962b

Compare with similar skills

P2p Dos And Eclipse next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

P2p Dos And Eclipse compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
P2p Dos And Eclipse this skillPlamenTSV/plamen303—~4kAutomated safety check: PassMIT
Fla Ascend Performancefla-org/flash-linear-attention5.8k—~6.3kAutomated safety check: PassMIT
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Skill Scannergetsentry/skills1k4 repos~2.5kAutomated safety check: WarnApache-2.0
Serenity Aleabitoreddityan-labs/serenity-aleabitoreddit4801 repos~3.3kAutomated safety check: PassNone
Security Alert Triageelastic/agent-skills5921 repos~3.5kAutomated safety check: NotesApache-2.0

Similar skills

  • Fla Ascend Performance

    fla-org/flash-linear-attention

    Guidelines for Ascend NPU kernel / Triton-Ascend backend performance work in the FLA repo.

    5.8k GitHub stars~6.3k tokensUpdated today
    SecurityAuto-check passed
  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 9 days ago
    SecurityAuto-check passed
  • Skill Scanner

    getsentry/skills

    Official

    Scan agent skills for security issues. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.5k tokens
    SecurityAuto-check: warnings
  • Serenity Aleabitoreddit

    yan-labs/serenity-aleabitoreddit

    Apply trader Serenity's (@aleabitoreddit) AI/semiconductor supply-chain analytical lens to US-stock ideas and market judgment.

    480 GitHub starsUsed in 1 repo~3.3k tokens
    SecurityAuto-check passed
  • Security Alert Triage

    elastic/agent-skills

    Official

    Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

    592 GitHub starsUsed in 1 repo~3.5k tokens
    SecurityAuto-check: notes
  • Shiro Attack CLI

    SummerSec/ShiroAttack2

    当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…

    2.6k GitHub stars~945 tokensUpdated 4 mo ago
    SecurityAuto-check passed

More from PlamenTSV/plamen

All 87 skills in this repo
  • Audit Prep

    PlamenTSV/plamen

    Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project…

    303 GitHub stars~3.7k tokensUpdated 12 days ago
    Auto-check passed
  • Verification Protocol

    PlamenTSV/plamen

    Trigger Pattern Always (used by all verifier agents) - Inject Into security-verifier agents (Phase 5)

    303 GitHub stars~3.5k tokensUpdated 12 days ago
    Auto-check passed
  • Ability Analysis

    PlamenTSV/plamen

    Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth agents, depth agents

    303 GitHub stars~3.3k tokensUpdated 12 days ago
    Auto-check passed
  • Ability Analysis

    PlamenTSV/plamen

    Trigger Pattern Always (Sui Move) -- foundational security check - Inject Into Breadth agents, depth agents

    303 GitHub stars~3.2k tokensUpdated 12 days ago
    Auto-check passed
  • Account Lifecycle

    PlamenTSV/plamen

    Trigger Pattern ACCOUNTCLOSING flag detected (close/CloseAccount usage) - Inject Into Breadth agents, depth agents

    303 GitHub stars~1.2k tokensUpdated 12 days ago
    Auto-check passed
  • Account Validation

    PlamenTSV/plamen

    Trigger Pattern Always required for Solana audits - Inject Into Breadth agents, depth agents

    303 GitHub stars~1.7k tokensUpdated 12 days ago
    Auto-check passed

Categories

Questions about P2p Dos And Eclipse

What does P2p Dos And Eclipse do?

L1 trigger - audits peer-to-peer networking for DoS vectors (resource exhaustion, amplification), eclipse attack susceptibility, and discovery table poisoning (Kademlia/devp2p). P2p Dos And Eclipse is an agent skill from PlamenTSV/plamen. L1 trigger - audits peer-to-peer networking for DoS vectors (resource exhaustion, amplification), eclipse attack susceptibility, and discovery table poisoning (Kademlia/devp2p).

When should I use P2p Dos And Eclipse?

P2p Dos And Eclipse fits situations like: - audits peer-to-peer networking for DoS vectors (resource exhaustion; eclipse attack susceptibility; discovery table poisoning (Kademlia/devp2p).

How do I install P2p Dos And Eclipse in Claude Code?

Run `npx skills add PlamenTSV/plamen --skill p2p-dos-and-eclipse -a claude-code`. Or copy the skill folder (agents/skills/injectable/l1/p2p-dos-and-eclipse in PlamenTSV/plamen) into .claude/skills/p2p-dos-and-eclipse in your project. Claude Code loads it when a task matches its description.

How do I install P2p Dos And Eclipse in Codex?

Run `npx skills add PlamenTSV/plamen --skill p2p-dos-and-eclipse -a codex`. Or copy the skill folder (agents/skills/injectable/l1/p2p-dos-and-eclipse in PlamenTSV/plamen) into .agents/skills/p2p-dos-and-eclipse in your project. Codex loads it when a task matches its description.

Can I use P2p Dos And Eclipse in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PlamenTSV/plamen --skill p2p-dos-and-eclipse -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/p2p-dos-and-eclipse, .gemini/skills/p2p-dos-and-eclipse, .github/skills/p2p-dos-and-eclipse and .opencode/skills/p2p-dos-and-eclipse in your project.

What does P2p Dos And Eclipse need to run?

SKILL.md names no scripts, command-line tools or credentials: P2p Dos And Eclipse is instructions for the agent only.

Does P2p Dos And Eclipse access the network?

SKILL.md names 5 domains. As links in the text: zellic.io, eprint.iacr.org, researchgate.net, arxiv.org and github.com. This is read from the text; nothing was executed.

Is P2p Dos And Eclipse safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does P2p Dos And Eclipse use?

P2p Dos And Eclipse is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does P2p Dos And Eclipse use?

About 4k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to P2p Dos And Eclipse?

Skills that share tags, products or a category with P2p Dos And Eclipse: Fla Ascend Performance (fla-org/flash-linear-attention, 5.8k stars), Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Skill Scanner (getsentry/skills, 1k stars) and Serenity Aleabitoreddit (yan-labs/serenity-aleabitoreddit, 480 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains P2p Dos And Eclipse?

PlamenTSV (a GitHub user) maintains it in PlamenTSV/plamen, which has 303 GitHub stars. The repository holds 87 skills in this directory. The repository was last updated on September 26, 2026.

Source: PlamenTSV/plamen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.