Agent skill

Ptb Composability

by PlamenTSV in PlamenTSV/plamen

Trigger Pattern PTB flag (always for Sui -- Programmable Transaction Blocks are the Sui transaction model) - Inject Into Breadth agents, depth-external, depth-state-trace

MITAuto-check passed

Install Ptb Composability

skills CLI
$ npx skills add PlamenTSV/plamen --skill ptb-composability -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install PlamenTSV/plamen ptb-composability --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agents/skills/sui/ptb-composability .claude/skills/ptb-composability && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ptb-composability
GitHub stars
303
Token cost
~3.3k tokens
SKILL.md length
1,293 words
Files
1
Skills in repo
87
Repo updated
First seen
Licence
MIT

At a glance

Trigger Pattern PTB flag (always for Sui -- Programmable Transaction Blocks are the Sui transaction model) - Inject Into Breadth agents, depth-external, depth-state-trace

  • Works in 7 steps: Entry Point Inventory → Multi-Step Composition Analysis → Flash Loan via PTB → …
  • Pattern PTB flag (always for Sui -- Programmable Transaction Blocks are the Sui transaction model) - Inject Into Breadth agents
  • SKILL.md covers 1. Entry Point Inventory, 2. Multi-Step Composition…, 3. Flash Loan via PTB and 4. Shared Object Mutation…, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Ptb Composability is an agent skill from PlamenTSV/plamen. Trigger Pattern PTB flag (always for Sui -- Programmable Transaction Blocks are the Sui transaction model) - Inject Into Breadth agents, depth-external, depth-state-trace

Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: Autonomous Web3 security audit agent for Claude Code. The licence is MIT.

When your agent uses it

  • Pattern PTB flag (always for Sui -- Programmable Transaction Blocks are the Sui transaction model) - Inject Into Breadth agents
  • Depth-state-trace

Example prompts

  • “/ptb-composability”

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Entry Point Inventory
  2. Multi-Step Composition Analysis
  3. Flash Loan via PTB
  4. Shared Object Mutation Ordering
  5. Hot Potato Enforcement
  6. Object Wrapping/Unwrapping in PTB
  7. Gas Budget Manipulation

What it can do on your machine

Read from SKILL.md and the folder at commit 795962b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ptb Composability loads about 3.3k tokens when it runs. Until then it costs about 47 tokens; SKILL.md has 1,293 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~47
When it runs · the whole SKILL.md, loaded when a task matches
~3.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from PlamenTSV/plamen at commit 795962b, republished under its MIT licence (© PlamenTSV). 1,293 words, ~3,291 tokens.

Download SKILL.mdSave it as .claude/skills/ptb-composability/SKILL.md (or your agent's skills folder).
name
ptb-composability
description
Trigger Pattern PTB flag (always for Sui -- Programmable Transaction Blocks are the Sui transaction model) - Inject Into Breadth agents, depth-external, depth-state-trace

Skill: PTB_COMPOSABILITY (Sui)

Trigger Pattern: PTB flag (always for Sui -- Programmable Transaction Blocks are the Sui transaction model) Inject Into: Breadth agents, depth-external, depth-state-trace Finding prefix: [PTB-N] Rules referenced: R4, R5, R8, R10, R15

Programmable Transaction Blocks (PTBs) are Sui's transaction composition primitive. A single PTB can contain up to 1024 commands, each calling a different function, with return values routed between commands. This enables atomic multi-step sequences that are fundamentally different from EVM's single-entry-point model. Every public function is a potential PTB command -- there is no "internal only" visibility equivalent to Solidity's internal.

STEP PRIORITY: Steps 1 (Single-Call Assumption Audit) and 4 (Atomic Read-Modify-Write) are where HIGH/CRITICAL severity findings most commonly hide. Do NOT rush these steps. If constrained, skip conditional sections (6, 7) before skipping 1, 3, or 4.


1. Entry Point Inventory

For EVERY public and entry function in the protocol, classify composability:

#FunctionModuleVisibilityReturns Value?Takes Shared Obj?Composable in PTB?Notes
1{func}{mod}public / entry / public(package)YES / NOYES / NOYES / NO{context}

Sui visibility semantics:

  • entry functions: callable from PTB but return values CANNOT be used by subsequent commands (consumed or discarded within the command). Objects can only be transferred, not returned.
  • public functions: fully composable -- return values pass between commands. This is the primary composability surface.
  • public(package): callable only by other modules in the same package. NOT callable from PTB. Safe from external composition.
  • fun (private): Not callable from outside the module. Safe.

Key observation: Any function that is public (not entry, not public(package)) is fully composable. Its return values can be routed to ANY other function in the same PTB.

1b. Single-Call Assumption Audit

For EVERY public and entry function, check whether its security model implicitly assumes it is the ONLY function called in the transaction:

#FunctionAssumes Single-Call?What Assumption?Breakable via PTB?Impact
1{func}YES/NO{describe assumption}YES/NO{impact}

Common single-call assumptions that PTBs break:

  • Post-call state check: Function reads state, performs action, then a SEPARATE function checks the result. Attacker inserts commands between action and check.
  • Balance snapshot: Function reads a balance at start, assumes balance changed only due to its work. Another PTB command could have changed the balance.
  • One-operation-per-transaction: Protocol assumes a user can only deposit OR withdraw in a single transaction. PTB allows deposit + borrow + withdraw atomically.
  • Temporal separation: Protocol assumes time must pass between action A and action B (cooldown). If both functions are callable, PTB executes them in the same transaction with zero time delta.
  • Reentrancy-like patterns: Function A updates state partially, function B reads partial state. PTBs naturally enable "call A then call B" -- state IS updated between commands.

Key question for each function: "If an attacker calls this function as command N in a PTB, and can execute arbitrary commands 1..N-1 before it and N+1..1024 after it, what can go wrong?"


2. Multi-Step Composition Analysis

For each public function that returns objects:

#FunctionInput ObjectsOutput ObjectsCan Output Be Routed To?Can Be Called Multiple Times?
1{func}{owned/shared/immutable}{Coin<T> / Object / HotPotato}{any function accepting this type}YES/NO

Return value routing checks:

  • Coin routing: If function A returns Coin<T>, can it be routed to function C (external) instead of intended function B?
  • Coin splitting: PTB has native SplitCoins command. Returned Coin<T> can be split. Does protocol assume full amount passed?
  • Coin merging: PTB has native MergeCoins command. Can attacker merge extra coins to inflate amounts?
  • Mutable reference routing: &mut Object references are borrowed for a command and released after. Same object can be passed to multiple commands sequentially. Does command N assume the object wasn't modified by command N-1?
  • Recipient mismatch: If function returns a value-bearing object, the final TransferObjects command determines the recipient.
2b. Value Interception Pattern

Model this specific attack for each function returning value:

1. Attacker calls protocol_function_A() -> returns Coin<USDC> (intended for pool)
2. Attacker routes Coin<USDC> to their own address via TransferObjects
3. Protocol expects the Coin was consumed by the next step but it was intercepted

Check: Does the protocol rely on PTB command ordering to ensure returned values reach the right destination? If YES -> the user controls the ordering, not the protocol.


3. Flash Loan via PTB

Without explicit flash loan protocols, PTBs enable flash-loan-like patterns:

1. [Command 1] Split large Coin<SUI> from attacker's balance
2. [Command 2] Deposit into protocol (inflates TVL/balance)
3. [Command 3] Trigger reward distribution (calculated on inflated balance)
4. [Command 4] Withdraw from protocol
5. [Command 5] Join coins back (net zero capital, captured rewards)

Can protocol state be manipulated between PTB commands?

Function PairShared StateDeposit-Action-Withdraw Possible?Defense?
{deposit, claim}{pool balance}YES/NO{cooldown? same-epoch check? minimum lock?}

Hot potato flash loan pattern:

1. borrow(pool, amount) -> (Coin<T>, FlashReceipt)     // Creates hot potato
2. [attacker does arbitrary operations with Coin<T>]
3. repay(pool, coin, receipt)                            // Consumes hot potato

Checks for hot potato flash loans:

  • Does repay() verify returned amount >= borrowed amount + fee?
  • Can attacker call OTHER protocol functions between borrow and repay that benefit from temporarily inflated balance?
  • Is FlashReceipt type-parameterized to prevent cross-pool receipt reuse?
  • Verify hot potato struct has NO abilities (no key, store, drop, copy)

4. Shared Object Mutation Ordering

Within a PTB touching shared objects:

4a. Oracle Manipulation Within PTB
1. [Command 1] Call DEX swap to move on-chain price
2. [Command 2] Call protocol function that reads manipulated price
3. [Command 3] Reverse DEX swap to restore price
4. Net effect: Protocol acted on manipulated price, attacker profited

Check: Does protocol read spot prices (manipulable) or TWAP/oracle prices (resistant)?

Show full SKILL.md (515 more words)Show less
4b. Balance Manipulation Within PTB
1. [Command 1] Deposit large amount (inflate balance/shares)
2. [Command 2] Trigger reward distribution (on inflated balance)
3. [Command 3] Withdraw deposited amount
4. Net effect: Captured rewards with zero time commitment
4c. State Toggling Within PTB
1. [Command 1] Set state to value A (e.g., via AdminCap function)
2. [Command 2] Perform action requiring state A
3. [Command 3] Reset state back to original value B
4. Net effect: Privileged action performed, state appears unchanged

Check: Possible if attacker controls an AdminCap? (Rule 6: semi-trusted role analysis)

4d. Shared Object Reorder Sensitivity
Shared ObjectInvariantCommands That Mutate ItSequence-Dependent?Exploitable?
{obj}{invariant description}{cmd1, cmd2, cmd3}YES/NO{if YES, describe exploit}

Check for each shared object: Write down the invariant. Can a sequence of 2-3 valid individual operations (each maintaining the invariant) produce a combined state that violates the invariant?


5. Hot Potato Enforcement

For each zero-ability struct (hot potato):

#Hot Potato TypeCreated ByConsumed ByAbilitiesBypass Possible?
1{Receipt}{borrow()}{repay()}NONE (confirmed){analysis}

Checks:

  • Verify struct has NO abilities. If it has drop -> NOT a hot potato.
  • Is the consuming function the ONLY function accepting this type?
  • Can multiple hot potatoes be created in a single PTB? Does consumption order matter?
  • Does consuming function validate the hot potato matches the creating context?
  • Can attacker cause consumption precondition to fail AFTER hot potato created? (entire PTB aborts -- griefing vector)
  • Can a wrapper with store ability store the hot potato? (bypass via external module -- check for public generic wrappers)

6. Object Wrapping/Unwrapping in PTB

Can objects be wrapped, manipulated, and unwrapped within a single PTB to bypass checks?

Wrap OperationUnwrap OperationWhat's InsideCheck Bypassed?
{wrap_func}{unwrap_func}{object with restrictions}{describe bypass or NONE}

Pattern: Object has transfer restrictions (key only, no store). Attacker wraps it inside a store-capable struct, transfers the wrapper, then unwraps on the other side. If wrap and unwrap are both public functions -> transfer restriction bypassed within a single PTB.


7. Gas Budget Manipulation

PTB gas budget is shared across all commands.

Attack VectorDescriptionCheck
Many-small-operations1000+ tiny operations to circumvent aggregate limitsDo aggregate limits track across PTB commands?
Object creation spamPTB creates many objects (up to 1024 per PTB)Unbounded object creation paths?
Gas exhaustion griefingCraft PTB that consumes max gas on revertGas charged on abort -- attacker pays

Typically lower severity: Sui's gas model charges the sender, so resource attacks are self-penalizing. Focus on aggregate limit bypass.


Output Schema

markdown
## Finding [PTB-N]: Title

**Verdict**: CONFIRMED / PARTIAL / REFUTED / CONTESTED
**Step Execution**: check1,2,3,4,5,6,7 | skip(reason) | uncertain
**Rules Applied**: [R4:___, R5:___, R8:___, R10:___, R15:___]
**Severity**: Critical/High/Medium/Low/Info
**Location**: sources/{module}.move:LineN

**PTB Attack Type**: SINGLE_CALL_ASSUMPTION / RETURN_VALUE_ROUTING / FLASH_LOAN_VIA_PTB / ATOMIC_MANIPULATION / HOT_POTATO_BYPASS / WRAP_UNWRAP_BYPASS / AGGREGATE_LIMIT
**Attack Sequence**:
1. [Command 1]: {what attacker does}
2. [Command 2]: {what attacker does}
3. [Command N]: {what attacker does}
**Net Effect**: {what the attacker gained}

**Description**: What is wrong
**Impact**: What can happen (fund loss, unfair value capture, invariant violation)
**Evidence**: Code showing vulnerability + PTB command sequence

Step Execution Checklist (MANDATORY)

StepRequiredCompleted?Notes
1. Entry Point InventoryYESAll public/entry functions classified
1b. Single-Call Assumption AuditYESHIGH PRIORITY -- every public function checked
2. Multi-Step Composition AnalysisYESAll return values checked
2b. Value Interception PatternYESValue-returning functions modeled
3. Flash Loan via PTBYESDeposit-action-withdraw patterns
4. Shared Object Mutation OrderingYESHIGH PRIORITY -- oracle, balance, state toggle
4d. Shared Object Reorder SensitivityYESInvariant + multi-command sequences
5. Hot Potato EnforcementIF hot potatoes existZero-ability verified
6. Object Wrapping/UnwrappingIF wrap/unwrap functions existTransfer restriction bypass
7. Gas Budget ManipulationIF aggregate limits exist
Cross-Reference Markers

After Step 1b: If single-call assumption found on fund-critical function -> immediate HIGH finding.

After Step 3: Cross-reference with SHARE_ALLOCATION_FAIRNESS for deposit-action-withdraw reward capture.

After Step 4a: Cross-reference with ORACLE_ANALYSIS if on-chain DEX prices are used.

After Step 5: Cross-reference with ABILITY_ANALYSIS Section 5 (Hot Potato Enforcement).

If any step skipped, document valid reason (N/A, no hot potatoes, no external calls, no aggregate limits).

© PlamenTSV, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in agents/skills/sui/ptb-composability of PlamenTSV/plamen.

Open the folder on GitHubat commit 795962b

Compare with similar skills

Ptb Composability next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ptb Composability compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ptb Composability this skillPlamenTSV/plamen303—~3.3kAutomated safety check: PassMIT
Compose Multiplatform Patternsaffaan-m/ECC274k2 repos~1.8kAutomated safety check: PassMIT
Compose Multiplatform Patternsaffaan-m/ECC274k—~1.8kAutomated safety check: PassMIT
Docker Compose Development Patternsaffaan-m/ECC274k4 repos~2.1kAutomated safety check: NotesMIT
Kotlin Exposed Patternsaffaan-m/ECC274k4 repos~5.5kAutomated safety check: PassMIT
Golang Patternsaffaan-m/ECC274k—~1.1kAutomated safety check: PassMIT

Similar skills

  • KMP项目中的Compose Multiplatform和Jetpack Compose模式——状态管理、导航、主题化、性能优化和平台特定UI。

    274k GitHub starsUsed in 2 repos~1.8k tokens
    MobileAuto-check passed
  • KMPプロジェクト向けのCompose MultiplatformおよびJetpack Composeパターン — 状態管理、ナビゲーション、テーマ設定、パフォーマンス、プラットフォーム固有のUI。

    274k GitHub stars~1.8k tokensUpdated 2 days ago
    MobileAuto-check passed
  • Practical Docker and Docker Compose patterns for local development: stacks, override files, networking, volumes, container hardening and debugging.

    274k GitHub starsUsed in 4 repos~2.1k tokens
    DevOps & CloudAuto-check: notes
  • JetBrains Exposed ORM patterns including DSL queries, DAO pattern, transactions, HikariCP connection pooling, Flyway migrations, and repository pattern.

    274k GitHub starsUsed in 4 repos~5.5k tokens
    DatabasesAuto-check passed
  • Golang Patterns

    affaan-m/ECC

    Go-specific design patterns and best practices including functional options, small interfaces, dependency injection, concurrency patterns, error handling, and package organization.

    274k GitHub stars~1.1k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Prisma Patterns

    affaan-m/ECC

    Prisma ORM patterns for TypeScript backends — schema design, query optimization, transactions, pagination, and critical traps like updateMany returning count not records, $transaction timeouts…

    274k GitHub starsUsed in 1 repo~3.8k tokens
    DatabasesAuto-check: notes

More from PlamenTSV/plamen

All 87 skills in this repo
  • Audit Prep

    PlamenTSV/plamen

    Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project…

    303 GitHub stars~3.7k tokensUpdated 11 days ago
    Auto-check passed
  • Verification Protocol

    PlamenTSV/plamen

    Trigger Pattern Always (used by all verifier agents) - Inject Into security-verifier agents (Phase 5)

    303 GitHub stars~3.5k tokensUpdated 11 days ago
    Auto-check passed
  • Ability Analysis

    PlamenTSV/plamen

    Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth agents, depth agents

    303 GitHub stars~3.3k tokensUpdated 11 days ago
    Auto-check passed
  • Ability Analysis

    PlamenTSV/plamen

    Trigger Pattern Always (Sui Move) -- foundational security check - Inject Into Breadth agents, depth agents

    303 GitHub stars~3.2k tokensUpdated 11 days ago
    Auto-check passed
  • Account Lifecycle

    PlamenTSV/plamen

    Trigger Pattern ACCOUNTCLOSING flag detected (close/CloseAccount usage) - Inject Into Breadth agents, depth agents

    303 GitHub stars~1.2k tokensUpdated 11 days ago
    Auto-check passed
  • Account Validation

    PlamenTSV/plamen

    Trigger Pattern Always required for Solana audits - Inject Into Breadth agents, depth agents

    303 GitHub stars~1.7k tokensUpdated 11 days ago
    Auto-check passed

Questions about Ptb Composability

What does Ptb Composability do?

Trigger Pattern PTB flag (always for Sui -- Programmable Transaction Blocks are the Sui transaction model) - Inject Into Breadth agents, depth-external, depth-state-trace. Ptb Composability is an agent skill from PlamenTSV/plamen.

When should I use Ptb Composability?

Ptb Composability fits situations like: pattern PTB flag (always for Sui -- Programmable Transaction Blocks are the Sui transaction model) - Inject Into Breadth agents; depth-state-trace.

How do I install Ptb Composability in Claude Code?

Run `npx skills add PlamenTSV/plamen --skill ptb-composability -a claude-code`. Or copy the skill folder (agents/skills/sui/ptb-composability in PlamenTSV/plamen) into .claude/skills/ptb-composability in your project. Claude Code loads it when a task matches its description.

How do I install Ptb Composability in Codex?

Run `npx skills add PlamenTSV/plamen --skill ptb-composability -a codex`. Or copy the skill folder (agents/skills/sui/ptb-composability in PlamenTSV/plamen) into .agents/skills/ptb-composability in your project. Codex loads it when a task matches its description.

Can I use Ptb Composability in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PlamenTSV/plamen --skill ptb-composability -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ptb-composability, .gemini/skills/ptb-composability, .github/skills/ptb-composability and .opencode/skills/ptb-composability in your project.

What does Ptb Composability need to run?

SKILL.md names no scripts, command-line tools or credentials: Ptb Composability is instructions for the agent only.

Does Ptb Composability access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Ptb Composability safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Ptb Composability use?

Ptb Composability is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ptb Composability use?

About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ptb Composability?

Skills that share tags, products or a category with Ptb Composability: Compose Multiplatform Patterns (affaan-m/ECC, 274k stars), Compose Multiplatform Patterns (affaan-m/ECC, 274k stars), Docker Compose Development Patterns (affaan-m/ECC, 274k stars) and Kotlin Exposed Patterns (affaan-m/ECC, 274k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ptb Composability?

PlamenTSV (a GitHub user) maintains it in PlamenTSV/plamen, which has 303 GitHub stars. The repository holds 87 skills in this directory. The repository was last updated on September 26, 2026.

Source: PlamenTSV/plamen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.