Agent skill

Reentrancy Analysis

by PlamenTSV in PlamenTSV/plamen

Trigger REENTRANCY flag detected (dynamic dispatch, closures, dispatchable FA, function values) - Used by Breadth agents, depth-state-trace

MITAuto-check passedSecurity

Install Reentrancy Analysis

skills CLI
$ npx skills add PlamenTSV/plamen --skill reentrancy-analysis -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install PlamenTSV/plamen reentrancy-analysis --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agents/skills/aptos/reentrancy-analysis .claude/skills/reentrancy-analysis && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
reentrancy-analysis
GitHub stars
303
Token cost
~2.9k tokens
SKILL.md length
1,110 words
Files
1
Skills in repo
87
Repo updated
First seen
Licence
MIT

At a glance

Trigger REENTRANCY flag detected (dynamic dispatch, closures, dispatchable FA, function values) - Used by Breadth agents, depth-state-trace

  • Works in 6 steps: Dynamic Dispatch Point Inventory → Module Lock Analysis → Third-Party Resource Lock Bypass → …
  • REENTRANCY flag detected (dynamic dispatch
  • SKILL.md covers Purpose, Background: Aptos Reentrancy…, Methodology and Key Questions (Must Answer All), plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Reentrancy Analysis is an agent skill from PlamenTSV/plamen. Trigger REENTRANCY flag detected (dynamic dispatch, closures, dispatchable FA, function values) - Used by Breadth agents, depth-state-trace

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Smart contract auditing. The repository describes itself as: Autonomous Web3 security audit agent for Claude Code. The licence is MIT.

When your agent uses it

  • REENTRANCY flag detected (dynamic dispatch
  • Dispatchable FA
  • Function values) - Used by Breadth agents
  • Depth-state-trace

Example prompts

  • “/reentrancy-analysis”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Dynamic Dispatch Point Inventory
  2. Module Lock Analysis
  3. Third-Party Resource Lock Bypass
  4. State Consistency Analysis (Check-Effect-Interaction)
  5. Dispatchable FA Specific Reentrancy
  6. Mitigation Recommendations Framework

What it can do on your machine

Read from SKILL.md and the folder at commit 795962b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are move and markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Reentrancy Analysis loads about 2.9k tokens when it runs. Until then it costs about 40 tokens; SKILL.md has 1,110 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~40
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from PlamenTSV/plamen at commit 795962b, republished under its MIT licence (© PlamenTSV). 1,110 words, ~2,927 tokens.

Download SKILL.mdSave it as .claude/skills/reentrancy-analysis/SKILL.md (or your agent's skills folder).
name
reentrancy-analysis
description
Trigger REENTRANCY flag detected (dynamic dispatch, closures, dispatchable FA, function values) - Used by Breadth agents, depth-state-trace

Skill: REENTRANCY_ANALYSIS

Trigger: REENTRANCY flag detected (dynamic dispatch, closures, dispatchable FA, function values) Used by: Breadth agents, depth-state-trace Covers: Cross-module reentrancy via closures, dispatchable FA hook reentrancy, direct/indirect reentrancy, resource lock gaps

Purpose

Audit reentrancy vectors in Aptos Move. Historically, Move's linear type system and static dispatch prevented reentrancy. Post Move 2.2, function values (closures) and dispatchable FungibleAsset hooks introduce dynamic dispatch, creating reentrancy surfaces analogous to EVM callbacks but with different mechanics and mitigations.

Background: Aptos Reentrancy Model

Pre Move 2.2: No dynamic dispatch. All function calls are statically resolved at compile time. Reentrancy was architecturally impossible (no callbacks, no external calls to untrusted code).

Post Move 2.2: Two reentrancy vectors exist:

  1. Function values / closures: |arg| { body } syntax allows passing executable code as parameters. A module calling a user-supplied closure can be reentered.
  2. Dispatchable FungibleAsset hooks: withdraw, deposit, and derived_balance hooks execute external module code during FA operations. This is framework-level dynamic dispatch.

#[module_lock]: Prevents INDIRECT reentrancy (cross-module reentry into the locked module). Does NOT prevent DIRECT reentrancy (closure calling back into the same module's function within the same execution frame).

Methodology

STEP 1: Dynamic Dispatch Point Inventory

Find ALL uses of dynamic dispatch in the audited modules:

1a. Function Values and Closures

MANDATORY SEARCH: Grep all .move files for:

  1. | followed by parameter patterns (closure syntax: |x| { ... }, |x, y| { ... })
  2. Function types in signatures (e.g., callback: |u64| -> u64, FunctionValue)
  3. move | (move closures that capture variables)
  4. Functions that accept function-typed parameters
#ModuleFunctionDynamic Dispatch TypeCaller-Controlled?Reentrancy Risk
1{module}{func}Closure parameterYES/NO{assess}
2{module}{func}Stored function valueYES/NO{assess}
1b. Dispatchable FA Hooks

MANDATORY SEARCH: Grep for:

  1. dispatchable_fungible_asset module usage
  2. register_dispatch_functions or equivalent hook registration
  3. withdraw_with_*, deposit_with_* function patterns
  4. derived_balance implementations
#ModuleHook TypeRegistered FunctionExternal Code Executed?
1{module}withdraw{module::withdraw_hook}YES - at every withdrawal
2{module}deposit{module::deposit_hook}YES - at every deposit
3{module}derived_balance{module::balance_hook}YES - at every balance query
STEP 2: Module Lock Analysis

For each module containing dynamic dispatch points:

ModuleHas #[module_lock]?Public Entry PointsProtected by Lock?Direct Reentry Possible?
{module}YES/NO{list entry/public functions}YES/NO{YES if lock present - lock prevents indirect but not direct}

CRITICAL DISTINCTION:

  • #[module_lock] = YES: Indirect reentrancy blocked (Module A -> closure -> Module A's function). Direct reentrancy still possible (within same function frame, closure calls same module's public function via friend or inline).
  • #[module_lock] = NO: Both direct and indirect reentrancy possible.

Check: For each module WITHOUT #[module_lock]:

  1. Does it have any dynamic dispatch points (from Step 1)?
  2. If YES: cross-module reentrancy is possible - trace all paths.
STEP 3: Third-Party Resource Lock Bypass

If the audited module stores data in a third-party resource abstraction:

Data StructureProvided By ModuleOur Module UsesThird-Party Lock Protects Us?
SmartTableaptos_stdYES/NONO - their lock protects THEIR invariants, not ours
Tableaptos_stdYES/NONO
{custom_struct}{third_party}YES/NONO

Pattern: Module A stores its accounting data in a SmartTable (from aptos_std). aptos_std may have #[module_lock]. But this lock only prevents reentry into aptos_std - it does NOT prevent reentry into Module A. An attacker can reenter Module A while Module A's SmartTable operation is in progress.

Check: Does the protocol rely on a third-party module's lock for its own reentrancy protection? If YES -> FINDING.

STEP 4: State Consistency Analysis (Check-Effect-Interaction)

For each dynamic dispatch point identified in Step 1:

4a. Pre-Dispatch State Snapshot
Dispatch PointState READ Before DispatchState MODIFIED Before DispatchState Modified AFTER Dispatch
{func:line}{variables/resources read}{variables/resources written}{variables/resources written}
4b. Reentrancy Impact Trace

For each dispatch point where state is modified before dispatch:

1. Function entry: Read state S1 (e.g., user_balance = 100)
2. Modify state: S1 partially updated (e.g., user_balance -= 50, but total_supply not yet updated)
3. Dynamic dispatch: closure/hook executes
4. REENTRY: Attacker calls back into same module
5. Reentrant call reads: S1 (modified) - sees user_balance = 50
6. Reentrant call reads: S2 (NOT yet modified) - sees stale total_supply = 1000 (should be 950)
7. Inconsistency: S1 and S2 are out of sync
8. Original execution resumes: modifies S2 (total_supply = 950)
9. Impact: [describe what the attacker gained]

Key question for each dispatch point: Is there ANY pair of state variables (S1, S2) where S1 is updated before dispatch but S2 is updated after? If YES, the reentrant call sees an inconsistent state.

STEP 5: Dispatchable FA Specific Reentrancy

If the protocol uses dispatchable FungibleAsset:

5a. Withdraw Hook Reentrancy
move
// Framework calls this DURING withdrawal:
fun withdraw_hook(store: Object<FungibleStore>, amount: u64, ...) {
    // This code runs AFTER the framework has decided to withdraw
    // but potentially BEFORE the calling module's post-withdrawal logic

    // Can this hook call back into the protocol?
    // What state has been partially modified at this point?
}

Trace: What is the call stack at the point the withdraw hook fires?

  1. Protocol function (e.g., redeem())
  2. Framework fungible_asset::withdraw()
  3. Hook: module::withdraw_hook()
  4. Hook can call: ??? (any public function accessible)
Show full SKILL.md (427 more words)Show less
5b. Deposit Hook Blocking

Can a deposit hook selectively revert to block specific operations?

  • If protocol performs a transfer (withdraw from A + deposit to B), can the deposit hook on B prevent the entire operation?
  • Can this be used to grief liquidations, reward distributions, or time-sensitive operations?
5c. Balance Query Reentrancy

If derived_balance hook is registered:

  • Does calling fungible_asset::balance() trigger external code?
  • Can this external code modify state that the caller depends on?
  • Is balance() called within a state modification sequence? (read-modify-write pattern where read triggers hook)
STEP 6: Mitigation Recommendations Framework

For each reentrancy vector found, categorize the recommended fix:

VectorRecommended FixImplementation
Cross-module via closureAdd #[module_lock]Module-level attribute
Direct reentrancyCheck-Effect-Interaction patternReorder operations: all state writes before dispatch
Dispatchable FA hookComplete all state updates before FA operationsMove all borrow_global_mut before withdraw/deposit
Third-party resource bypassModule-level boolean guardassert!(!is_executing, E_REENTRANCY) pattern

Key Questions (Must Answer All)

  1. Dynamic dispatch: Does the module use function values, closures, or dispatchable FA hooks?
  2. Module lock: Is #[module_lock] applied? What does it cover vs not cover?
  3. State ordering: For each dispatch point, is all state fully updated before the dispatch?
  4. Third-party reliance: Does the module rely on another module's lock for its own safety?
  5. Hook surface: If dispatchable FA, which hooks are registered and who controls them?

Common False Positives

  1. No dynamic dispatch: If the module has zero closure parameters, zero function values, and does not use dispatchable FA, reentrancy is not possible in Move
  2. Read-only callbacks: If the closure only reads state (no borrow_global_mut, no state writes), reentrancy cannot cause inconsistency
  3. Framework-only hooks: If hooks are registered by the framework and not by user-controllable code, the hook code is trusted
  4. Module lock + no direct reentry: If #[module_lock] is present AND the closure does not call the same module's functions, reentrancy is fully blocked
  5. Atomic transactions: Move transactions are atomic - partial state is never visible cross-transaction (only within the same transaction via reentrancy)

Output Schema

markdown
## Finding [RE-N]: Title

**Verdict**: CONFIRMED / PARTIAL / REFUTED / CONTESTED
**Step Execution**: ✓1,2,3,4,5,6 | ✗N(reason) | ?N(uncertain)
**Rules Applied**: [R4:✓/✗, R10:✓/✗, R12:✓/✗]
**Severity**: Critical/High/Medium/Low/Info
**Location**: module_name.move:LineN

**Reentrancy Type**: DIRECT / INDIRECT / HOOK_BASED / THIRD_PARTY_BYPASS
**Dispatch Point**: {function:line where dynamic dispatch occurs}
**Inconsistent State**: {which state variables are out of sync during callback}

**Description**: What's wrong
**Impact**: What can happen (double-spend, state corruption, fund theft)
**Evidence**: Code showing the dispatch point and state ordering

### Attack Sequence
1. [Attacker calls function X]
2. [State S1 is modified]
3. [Dynamic dispatch triggers callback]
4. [Callback reenters function Y which reads stale S2]
5. [Impact: ...]

### Precondition Analysis (if PARTIAL/REFUTED)
**Missing Precondition**: [What blocks exploitation]
**Precondition Type**: STATE / ACCESS / TIMING / EXTERNAL / BALANCE

### Postcondition Analysis (if CONFIRMED/PARTIAL)
**Postconditions Created**: [What conditions this creates]
**Postcondition Types**: [List applicable types]
**Who Benefits**: [Who can use these]

Step Execution Checklist (MANDATORY)

StepRequiredCompleted?Notes
1. Dynamic Dispatch Point InventoryYES✓/✗/?Both closures (1a) and FA hooks (1b)
2. Module Lock AnalysisYES✓/✗/?Direct vs indirect distinction
3. Third-Party Resource Lock BypassIF third-party data structures used✓/✗(N/A)/?
4. State Consistency AnalysisFOR EACH dispatch point✓/✗/?Pre/post dispatch state traced
5. Dispatchable FA SpecificIF dispatchable FA used✓/✗(N/A)/?5a, 5b, 5c sub-steps
6. Mitigation RecommendationsFOR EACH finding✓/✗/?

If any step skipped, document valid reason (N/A, no dynamic dispatch, no dispatchable FA, module lock covers all paths).

© PlamenTSV, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in agents/skills/aptos/reentrancy-analysis of PlamenTSV/plamen.

Open the folder on GitHubat commit 795962b

Compare with similar skills

Reentrancy Analysis next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Reentrancy Analysis compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Reentrancy Analysis this skillPlamenTSV/plamen303—~2.9kAutomated safety check: PassMIT
Web3 Smart Contract Auditawarexone/Agentic-Bug-Hunter5.3k3 repos~4.5kAutomated safety check: PassMIT
Fizzpashov/skills1.2k2 repos~11kAutomated safety check: PassMIT
Web3 Smart Contract Grep Arsenaltradecatlabs/vibe-coding-cn17k2 repos~3.3kAutomated safety check: PassMIT
X Raypashov/skills1.2k1 repos~10kAutomated safety check: PassMIT
Web3 Bug Bounty AI Toolstradecatlabs/vibe-coding-cn17k2 repos~3.9kAutomated safety check: WarnMIT

Similar skills

  • Web3 Smart Contract Audit

    awarexone/Agentic-Bug-Hunter

    Guides smart contract audits and bounty target selection with ten DeFi bug classes, kill signals, a Foundry PoC template and grep patterns.

    5.3k GitHub starsUsed in 3 repos~4.5k tokens
    SecurityAuto-check passed
  • Fizz

    pashov/skills

    Generate Echidna/Medusa-compatible Solidity fuzz suites from Foundry or Hardhat projects.

    1.2k GitHub starsUsed in 2 repos~11k tokens
    SecurityAuto-check passed
  • Web3 Smart Contract Grep Arsenal

    tradecatlabs/vibe-coding-cn

    A master set of ten grep command blocks that surface likely vulnerability classes in Solidity source within the first 30 minutes of auditing a new protocol.

    17k GitHub starsUsed in 2 repos~3.3k tokens
    SecurityAuto-check passed
  • X Ray

    pashov/skills

    Generates an x-ray.md pre-audit report covering overview, enhanced threat model (protocol-type profiling, git-weighted attack surfaces, temporal risk analysis, composability dependency mapping)…

    1.2k GitHub starsUsed in 1 repo~10k tokens
    SecurityAuto-check passed
  • Web3 Bug Bounty AI Tools

    tradecatlabs/vibe-coding-cn

    A selection guide to AI-driven tools for Web3 bug bounty work, from autonomous web pentesters to smart contract bug finders, with notes on authorization.

    17k GitHub starsUsed in 2 repos~3.9k tokens
    SecurityAuto-check: warnings
  • Fizz Sync

    pashov/skills

    Reconcile an existing Fizz harness with a changed source tree.

    1.2k GitHub starsUsed in 2 repos~3.9k tokens
    SecurityAuto-check passed

More from PlamenTSV/plamen

All 87 skills in this repo
  • Audit Prep

    PlamenTSV/plamen

    Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project…

    303 GitHub stars~3.7k tokensUpdated 13 days ago
    Auto-check passed
  • Verification Protocol

    PlamenTSV/plamen

    Trigger Pattern Always (used by all verifier agents) - Inject Into security-verifier agents (Phase 5)

    303 GitHub stars~3.5k tokensUpdated 13 days ago
    Auto-check passed
  • Ability Analysis

    PlamenTSV/plamen

    Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth agents, depth agents

    303 GitHub stars~3.3k tokensUpdated 13 days ago
    Auto-check passed
  • Ability Analysis

    PlamenTSV/plamen

    Trigger Pattern Always (Sui Move) -- foundational security check - Inject Into Breadth agents, depth agents

    303 GitHub stars~3.2k tokensUpdated 13 days ago
    Auto-check passed
  • Account Lifecycle

    PlamenTSV/plamen

    Trigger Pattern ACCOUNTCLOSING flag detected (close/CloseAccount usage) - Inject Into Breadth agents, depth agents

    303 GitHub stars~1.2k tokensUpdated 13 days ago
    Auto-check passed
  • Account Validation

    PlamenTSV/plamen

    Trigger Pattern Always required for Solana audits - Inject Into Breadth agents, depth agents

    303 GitHub stars~1.7k tokensUpdated 13 days ago
    Auto-check passed

Categories

Questions about Reentrancy Analysis

What does Reentrancy Analysis do?

Trigger REENTRANCY flag detected (dynamic dispatch, closures, dispatchable FA, function values) - Used by Breadth agents, depth-state-trace. Reentrancy Analysis is an agent skill from PlamenTSV/plamen.

When should I use Reentrancy Analysis?

Reentrancy Analysis fits situations like: REENTRANCY flag detected (dynamic dispatch; dispatchable FA; function values) - Used by Breadth agents; depth-state-trace.

How do I install Reentrancy Analysis in Claude Code?

Run `npx skills add PlamenTSV/plamen --skill reentrancy-analysis -a claude-code`. Or copy the skill folder (agents/skills/aptos/reentrancy-analysis in PlamenTSV/plamen) into .claude/skills/reentrancy-analysis in your project. Claude Code loads it when a task matches its description.

How do I install Reentrancy Analysis in Codex?

Run `npx skills add PlamenTSV/plamen --skill reentrancy-analysis -a codex`. Or copy the skill folder (agents/skills/aptos/reentrancy-analysis in PlamenTSV/plamen) into .agents/skills/reentrancy-analysis in your project. Codex loads it when a task matches its description.

Can I use Reentrancy Analysis in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PlamenTSV/plamen --skill reentrancy-analysis -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/reentrancy-analysis, .gemini/skills/reentrancy-analysis, .github/skills/reentrancy-analysis and .opencode/skills/reentrancy-analysis in your project.

What does Reentrancy Analysis need to run?

SKILL.md names no scripts, command-line tools or credentials: Reentrancy Analysis is instructions for the agent only.

Does Reentrancy Analysis access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Reentrancy Analysis safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Reentrancy Analysis use?

Reentrancy Analysis is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Reentrancy Analysis use?

About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Reentrancy Analysis?

Skills that share tags, products or a category with Reentrancy Analysis: Web3 Smart Contract Audit (awarexone/Agentic-Bug-Hunter, 5.3k stars), Fizz (pashov/skills, 1.2k stars), Web3 Smart Contract Grep Arsenal (tradecatlabs/vibe-coding-cn, 17k stars) and X Ray (pashov/skills, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Reentrancy Analysis?

PlamenTSV (a GitHub user) maintains it in PlamenTSV/plamen, which has 303 GitHub stars. The repository holds 87 skills in this directory. The repository was last updated on September 26, 2026.

Source: PlamenTSV/plamen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.