Agent skill

Pda Security

by PlamenTSV in PlamenTSV/plamen

Trigger Pattern PDA flag detected (seeds/bump/findprogramaddress usage) - Inject Into Breadth agents, depth agents

MITAuto-check passed

Install Pda Security

skills CLI
$ npx skills add PlamenTSV/plamen --skill pda-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install PlamenTSV/plamen pda-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agents/skills/solana/pda-security .claude/skills/pda-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
pda-security
GitHub stars
303
Token cost
~1.2k tokens
SKILL.md length
465 words
Files
1
Skills in repo
87
Repo updated
First seen
Licence
MIT

At a glance

Trigger Pattern PDA flag detected (seeds/bump/findprogramaddress usage) - Inject Into Breadth agents, depth agents

  • Works in 7 steps: PDA Seed Inventory → Canonical Bump Enforcement → Seed Collision Analysis → …
  • Pattern PDA flag detected (seeds/bump/findprogramaddress usage) - Inject Into Breadth agents
  • SKILL.md covers 1. PDA Seed Inventory, 2. Canonical Bump Enforcement, 3. Seed Collision Analysis and 4. Seed Uniqueness, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Pda Security is an agent skill from PlamenTSV/plamen. Trigger Pattern PDA flag detected (seeds/bump/findprogramaddress usage) - Inject Into Breadth agents, depth agents

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with Solana. The repository describes itself as: Autonomous Web3 security audit agent for Claude Code. The licence is MIT.

When your agent uses it

  • Pattern PDA flag detected (seeds/bump/findprogramaddress usage) - Inject Into Breadth agents

Example prompts

  • “/pda-security”

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. PDA Seed Inventory
  2. Canonical Bump Enforcement
  3. Seed Collision Analysis
  4. Seed Uniqueness
  5. PDA Isolation
  6. PDA Sharing Detection
  7. Initialization Front-Running

What it can do on your machine

Read from SKILL.md and the folder at commit 795962b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Pda Security loads about 1.2k tokens when it runs. Until then it costs about 32 tokens; SKILL.md has 465 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~32
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from PlamenTSV/plamen at commit 795962b, republished under its MIT licence (© PlamenTSV). 465 words, ~1,220 tokens.

Download SKILL.mdSave it as .claude/skills/pda-security/SKILL.md (or your agent's skills folder).
name
pda-security
description
Trigger Pattern PDA flag detected (seeds/bump/find_program_address usage) - Inject Into Breadth agents, depth agents

PDA_SECURITY Skill

Trigger Pattern: PDA flag detected (seeds/bump/find_program_address usage) Inject Into: Breadth agents, depth agents Finding prefix: [PDA-N] Rules referenced: S2, S1

For every PDA in the Solana program:

1. PDA Seed Inventory

List all PDA seed declarations:

#PDA NameSeedsPurposeAnchor ConstraintLocation
1{name}[b"prefix", user.key().as_ref(), &[bump]]{what it stores}seeds = [...], bump{file:line}

2. Canonical Bump Enforcement

For each PDA:

PDABump SourceCanonical?Risk if Non-Canonical
{name}Anchor auto (bump) / find_program_address / USER INPUTYES/NO{if NO: multiple valid addresses}

Attack (S2): If bump is user-supplied, attacker can use a non-canonical bump to derive a DIFFERENT address that still passes create_program_address. This creates a separate PDA from the intended one. Defense: Always use find_program_address (returns canonical bump) or Anchor's bump constraint.

3. Seed Collision Analysis

For each PAIR of PDA seed schemas:

PDA A SeedsPDA B SeedsCan Byte Sequences Overlap?Collision Risk?
[b"vault", mint.as_ref()][b"vaultm", ...]CHECK: "vault" + mint_bytes could equal "vaultm" + other_bytes?YES/NO

Attack: Two different PDA types with seeds that can produce identical byte sequences → one PDA masquerades as another. Defense: Use unique fixed-length prefixes (e.g., b"vault\x00") or ensure seed structures cannot collide.

4. Seed Uniqueness

For each PDA type, verify seeds include sufficient uniqueness:

PDAUnique PerSeeds Include User/Entity Key?Could Two Users Share PDA?
{name}User / Mint / Pool / GlobalYES/NO{if YES: shared state corruption}

Pattern: User-specific PDAs MUST include the user's pubkey in seeds. Omitting it means all users share the same PDA.

5. PDA Isolation

For each PDA used as an authority or signer:

PDASigns ForIsolated to Scope?Can Different Instruction Misuse?
{name}{what operations}YES/NO{if NO: cross-instruction authority sharing}

Attack: A PDA authority used across multiple instructions where one instruction has weaker validation → attacker uses the weak path.

Show full SKILL.md (172 more words)Show less

6. PDA Sharing Detection

Check if multiple account types share the same PDA seed schema:

Seed SchemaAccount Types Using ItType Confusion Risk?
[b"data", key.as_ref()]{list all account types}{if >1: type confusion possible}

7. Initialization Front-Running

For each PDA created with init:

PDACreated ByFront-Runnable?Impact if Front-Run
{name}{instruction}YES/NO{attacker initializes with malicious data}

Attack (S2): Attacker front-runs PDA initialization, creating the account with attacker-controlled data before the legitimate initialization transaction. Defense: init (not init_if_needed) + seeds that include the authorized initializer's pubkey. Warning: init_if_needed is explicitly dangerous - it silently succeeds if account already exists with potentially malicious data.

Finding Template

markdown
**ID**: [PDA-N]
**Severity**: [based on impact: seed collision = Critical, non-canonical bump = High]
**Step Execution**: ✓1,2,3,4,5,6,7 | ✗(reasons) | ?(uncertain)
**Rules Applied**: [S2:✓, S1:✓]
**Location**: program/src/{file}.rs:LineN
**Title**: [PDA issue type] in [context] enables [attack]
**Description**: [Specific PDA vulnerability with seed analysis]
**Impact**: [Fund theft via PDA confusion / state corruption / front-running]

Step Execution Checklist (MANDATORY)

SectionRequiredCompleted?Notes
1. PDA Seed InventoryYES✓/✗/?For every PDA
2. Canonical Bump EnforcementYES✓/✗/?For every PDA
3. Seed Collision AnalysisYES✓/✗/?For every PDA pair
4. Seed UniquenessYES✓/✗/?User-specific PDAs
5. PDA IsolationIF PDA used as authority✓/✗(N/A)/?Cross-instruction misuse
6. PDA Sharing DetectionYES✓/✗/?Type confusion
7. Initialization Front-RunningIF init used✓/✗(N/A)/?init_if_needed is dangerous

© PlamenTSV, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in agents/skills/solana/pda-security of PlamenTSV/plamen.

Open the folder on GitHubat commit 795962b

Compare with similar skills

Pda Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Pda Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Pda Security this skillPlamenTSV/plamen303—~1.2kAutomated safety check: PassMIT
Minara Crypto Trading and WalletMinara-AI/minara-skills3581 repos~5.7kAutomated safety check: PassNone
NEAR Intents Swap Integrationinternet-court/internet-court-skill6.4k2 repos~939Automated safety check: PassCustom licence
Solana Devsolana-foundation/solana-dev-skill574—~3.8kAutomated safety check: PassMIT
Meme Coin Security Auditawarexone/Agentic-Bug-Hunter5.3k1 repos~2.4kAutomated safety check: PassMIT
Swapper Depositswapperfinance/swapper-toolkit852—~1.8kAutomated safety check: PassMIT

Similar skills

  • Minara Crypto Trading and Wallet

    Minara-AI/minara-skills

    Drives the Minara CLI for crypto swaps, perps, limit orders, wallet transfers, deposits and withdrawals, plus AI market analysis.

    358 GitHub starsUsed in 1 repo~5.7k tokens
    Business, Finance & HRAuto-check passed
  • NEAR Intents Swap Integration

    internet-court/internet-court-skill

    Builds cross-chain token swaps and bridge flows with the NEAR Intents 1Click API: quotes, deposit addresses, per-chain deposits and status polling.

    6.4k GitHub starsUsed in 2 repos~939 tokens
    Backend & APIsAuto-check passed
  • Solana Dev

    solana-foundation/solana-dev-skill

    A skill your agent uses when user asks to "build a Solana dapp", "write an Anchor program", "create a token", "debug Solana errors", "set up wallet connection", "test my Solana program", "fuzz my…

    574 GitHub stars~3.8k tokensUpdated today
    Backend & APIsAuto-check passed
  • Meme Coin Security Audit

    awarexone/Agentic-Bug-Hunter

    Screens EVM and Solana meme coins for rug pull signs such as hidden mint, honeypot logic and fee tricks, starting with fast kill signals before any code review.

    5.3k GitHub starsUsed in 1 repo~2.4k tokens
    SecurityAuto-check passed
  • Swapper Deposit

    swapperfinance/swapper-toolkit

    Deposit and bridge funds into a wallet or protocol using Swapper Finance.

    852 GitHub stars~1.8k tokensUpdated 6 mo ago
    Business, Finance & HRAuto-check passed
  • PNP Prediction Markets on Solana

    internet-court/internet-court-skill

    Creates, trades and settles permissionless prediction markets on Solana with any SPL token as collateral, including social-media and custom-oracle markets.

    6.4k GitHub stars~7.5k tokensUpdated 1 mo ago
    Business, Finance & HRAuto-check: notes

More from PlamenTSV/plamen

All 87 skills in this repo
  • Audit Prep

    PlamenTSV/plamen

    Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project…

    303 GitHub stars~3.7k tokensUpdated 11 days ago
    Auto-check passed
  • Verification Protocol

    PlamenTSV/plamen

    Trigger Pattern Always (used by all verifier agents) - Inject Into security-verifier agents (Phase 5)

    303 GitHub stars~3.5k tokensUpdated 11 days ago
    Auto-check passed
  • Ability Analysis

    PlamenTSV/plamen

    Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth agents, depth agents

    303 GitHub stars~3.3k tokensUpdated 11 days ago
    Auto-check passed
  • Ability Analysis

    PlamenTSV/plamen

    Trigger Pattern Always (Sui Move) -- foundational security check - Inject Into Breadth agents, depth agents

    303 GitHub stars~3.2k tokensUpdated 11 days ago
    Auto-check passed
  • Account Lifecycle

    PlamenTSV/plamen

    Trigger Pattern ACCOUNTCLOSING flag detected (close/CloseAccount usage) - Inject Into Breadth agents, depth agents

    303 GitHub stars~1.2k tokensUpdated 11 days ago
    Auto-check passed
  • Account Validation

    PlamenTSV/plamen

    Trigger Pattern Always required for Solana audits - Inject Into Breadth agents, depth agents

    303 GitHub stars~1.7k tokensUpdated 11 days ago
    Auto-check passed

Works with

Questions about Pda Security

What does Pda Security do?

Trigger Pattern PDA flag detected (seeds/bump/findprogramaddress usage) - Inject Into Breadth agents, depth agents. Pda Security is an agent skill from PlamenTSV/plamen.

When should I use Pda Security?

Pda Security fits situations like: pattern PDA flag detected (seeds/bump/findprogramaddress usage) - Inject Into Breadth agents.

How do I install Pda Security in Claude Code?

Run `npx skills add PlamenTSV/plamen --skill pda-security -a claude-code`. Or copy the skill folder (agents/skills/solana/pda-security in PlamenTSV/plamen) into .claude/skills/pda-security in your project. Claude Code loads it when a task matches its description.

How do I install Pda Security in Codex?

Run `npx skills add PlamenTSV/plamen --skill pda-security -a codex`. Or copy the skill folder (agents/skills/solana/pda-security in PlamenTSV/plamen) into .agents/skills/pda-security in your project. Codex loads it when a task matches its description.

Can I use Pda Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PlamenTSV/plamen --skill pda-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pda-security, .gemini/skills/pda-security, .github/skills/pda-security and .opencode/skills/pda-security in your project.

What does Pda Security need to run?

SKILL.md names no scripts, command-line tools or credentials: Pda Security is instructions for the agent only.

Does Pda Security access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Pda Security safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Pda Security use?

Pda Security is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Pda Security use?

About 1.2k tokens (SKILL.md is roughly 4.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Pda Security?

Skills that share tags, products or a category with Pda Security: Minara Crypto Trading and Wallet (Minara-AI/minara-skills, 358 stars), NEAR Intents Swap Integration (internet-court/internet-court-skill, 6.4k stars), Solana Dev (solana-foundation/solana-dev-skill, 574 stars) and Meme Coin Security Audit (awarexone/Agentic-Bug-Hunter, 5.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Pda Security?

PlamenTSV (a GitHub user) maintains it in PlamenTSV/plamen, which has 303 GitHub stars. The repository holds 87 skills in this directory. The repository was last updated on September 26, 2026.

Source: PlamenTSV/plamen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.