Web3 Smart Contract Audit
awarexone/Agentic-Bug-Hunter
Guides smart contract audits and bounty target selection with ten DeFi bug classes, kill signals, a Foundry PoC template and grep patterns.
Trigger REENTRANCY flag detected (dynamic dispatch, closures, dispatchable FA, function values) - Used by Breadth agents, depth-state-trace
$ npx skills add PlamenTSV/plamen --skill reentrancy-analysis -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install PlamenTSV/plamen reentrancy-analysis --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agents/skills/aptos/reentrancy-analysis .claude/skills/reentrancy-analysis && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "reentrancy-analysis" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/aptos/reentrancy-analysis into .claude/skills/reentrancy-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "reentrancy-analysis", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/PlamenTSV/plamen/tree/main/agents/skills/aptos/reentrancy-analysisType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add PlamenTSV/plamen --skill reentrancy-analysis -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install PlamenTSV/plamen reentrancy-analysis --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .agents/skills && cp -r skills-src/agents/skills/aptos/reentrancy-analysis .agents/skills/reentrancy-analysis && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "reentrancy-analysis" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/aptos/reentrancy-analysis into .agents/skills/reentrancy-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "reentrancy-analysis", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add PlamenTSV/plamen --skill reentrancy-analysis -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install PlamenTSV/plamen reentrancy-analysis --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/agents/skills/aptos/reentrancy-analysis .cursor/skills/reentrancy-analysis && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "reentrancy-analysis" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/aptos/reentrancy-analysis into .cursor/skills/reentrancy-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "reentrancy-analysis", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/PlamenTSV/plamen.git --path agents/skills/aptos/reentrancy-analysis--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add PlamenTSV/plamen --skill reentrancy-analysis -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install PlamenTSV/plamen reentrancy-analysis --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/agents/skills/aptos/reentrancy-analysis .gemini/skills/reentrancy-analysis && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "reentrancy-analysis" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/aptos/reentrancy-analysis into .gemini/skills/reentrancy-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "reentrancy-analysis", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install PlamenTSV/plamen reentrancy-analysisInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add PlamenTSV/plamen --skill reentrancy-analysis -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .github/skills && cp -r skills-src/agents/skills/aptos/reentrancy-analysis .github/skills/reentrancy-analysis && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "reentrancy-analysis" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/aptos/reentrancy-analysis into .github/skills/reentrancy-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "reentrancy-analysis", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add PlamenTSV/plamen --skill reentrancy-analysis -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install PlamenTSV/plamen reentrancy-analysis --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/agents/skills/aptos/reentrancy-analysis .opencode/skills/reentrancy-analysis && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "reentrancy-analysis" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/aptos/reentrancy-analysis into .opencode/skills/reentrancy-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "reentrancy-analysis", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
reentrancy-analysisTrigger REENTRANCY flag detected (dynamic dispatch, closures, dispatchable FA, function values) - Used by Breadth agents, depth-state-trace
Reentrancy Analysis is an agent skill from PlamenTSV/plamen. Trigger REENTRANCY flag detected (dynamic dispatch, closures, dispatchable FA, function values) - Used by Breadth agents, depth-state-trace
Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Smart contract auditing. The repository describes itself as: Autonomous Web3 security audit agent for Claude Code. The licence is MIT.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 795962b. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are move and markdown).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Reentrancy Analysis loads about 2.9k tokens when it runs. Until then it costs about 40 tokens; SKILL.md has 1,110 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from PlamenTSV/plamen at commit 795962b, republished under its MIT licence (© PlamenTSV). 1,110 words, ~2,927 tokens.
.claude/skills/reentrancy-analysis/SKILL.md (or your agent's skills folder).Trigger: REENTRANCY flag detected (dynamic dispatch, closures, dispatchable FA, function values) Used by: Breadth agents, depth-state-trace Covers: Cross-module reentrancy via closures, dispatchable FA hook reentrancy, direct/indirect reentrancy, resource lock gaps
Audit reentrancy vectors in Aptos Move. Historically, Move's linear type system and static dispatch prevented reentrancy. Post Move 2.2, function values (closures) and dispatchable FungibleAsset hooks introduce dynamic dispatch, creating reentrancy surfaces analogous to EVM callbacks but with different mechanics and mitigations.
Pre Move 2.2: No dynamic dispatch. All function calls are statically resolved at compile time. Reentrancy was architecturally impossible (no callbacks, no external calls to untrusted code).
Post Move 2.2: Two reentrancy vectors exist:
|arg| { body } syntax allows passing executable code as parameters. A module calling a user-supplied closure can be reentered.withdraw, deposit, and derived_balance hooks execute external module code during FA operations. This is framework-level dynamic dispatch.#[module_lock]: Prevents INDIRECT reentrancy (cross-module reentry into the locked module). Does NOT prevent DIRECT reentrancy (closure calling back into the same module's function within the same execution frame).
Find ALL uses of dynamic dispatch in the audited modules:
MANDATORY SEARCH: Grep all .move files for:
| followed by parameter patterns (closure syntax: |x| { ... }, |x, y| { ... })callback: |u64| -> u64, FunctionValue)move | (move closures that capture variables)| # | Module | Function | Dynamic Dispatch Type | Caller-Controlled? | Reentrancy Risk |
|---|---|---|---|---|---|
| 1 | {module} | {func} | Closure parameter | YES/NO | {assess} |
| 2 | {module} | {func} | Stored function value | YES/NO | {assess} |
MANDATORY SEARCH: Grep for:
dispatchable_fungible_asset module usageregister_dispatch_functions or equivalent hook registrationwithdraw_with_*, deposit_with_* function patternsderived_balance implementations| # | Module | Hook Type | Registered Function | External Code Executed? |
|---|---|---|---|---|
| 1 | {module} | withdraw | {module::withdraw_hook} | YES - at every withdrawal |
| 2 | {module} | deposit | {module::deposit_hook} | YES - at every deposit |
| 3 | {module} | derived_balance | {module::balance_hook} | YES - at every balance query |
For each module containing dynamic dispatch points:
| Module | Has #[module_lock]? | Public Entry Points | Protected by Lock? | Direct Reentry Possible? |
|---|---|---|---|---|
| {module} | YES/NO | {list entry/public functions} | YES/NO | {YES if lock present - lock prevents indirect but not direct} |
CRITICAL DISTINCTION:
#[module_lock] = YES: Indirect reentrancy blocked (Module A -> closure -> Module A's function). Direct reentrancy still possible (within same function frame, closure calls same module's public function via friend or inline).#[module_lock] = NO: Both direct and indirect reentrancy possible.Check: For each module WITHOUT #[module_lock]:
If the audited module stores data in a third-party resource abstraction:
| Data Structure | Provided By Module | Our Module Uses | Third-Party Lock Protects Us? |
|---|---|---|---|
| SmartTable | aptos_std | YES/NO | NO - their lock protects THEIR invariants, not ours |
| Table | aptos_std | YES/NO | NO |
| {custom_struct} | {third_party} | YES/NO | NO |
Pattern: Module A stores its accounting data in a SmartTable (from aptos_std). aptos_std may have #[module_lock]. But this lock only prevents reentry into aptos_std - it does NOT prevent reentry into Module A. An attacker can reenter Module A while Module A's SmartTable operation is in progress.
Check: Does the protocol rely on a third-party module's lock for its own reentrancy protection? If YES -> FINDING.
For each dynamic dispatch point identified in Step 1:
| Dispatch Point | State READ Before Dispatch | State MODIFIED Before Dispatch | State Modified AFTER Dispatch |
|---|---|---|---|
| {func:line} | {variables/resources read} | {variables/resources written} | {variables/resources written} |
For each dispatch point where state is modified before dispatch:
1. Function entry: Read state S1 (e.g., user_balance = 100)
2. Modify state: S1 partially updated (e.g., user_balance -= 50, but total_supply not yet updated)
3. Dynamic dispatch: closure/hook executes
4. REENTRY: Attacker calls back into same module
5. Reentrant call reads: S1 (modified) - sees user_balance = 50
6. Reentrant call reads: S2 (NOT yet modified) - sees stale total_supply = 1000 (should be 950)
7. Inconsistency: S1 and S2 are out of sync
8. Original execution resumes: modifies S2 (total_supply = 950)
9. Impact: [describe what the attacker gained]Key question for each dispatch point: Is there ANY pair of state variables (S1, S2) where S1 is updated before dispatch but S2 is updated after? If YES, the reentrant call sees an inconsistent state.
If the protocol uses dispatchable FungibleAsset:
// Framework calls this DURING withdrawal:
fun withdraw_hook(store: Object<FungibleStore>, amount: u64, ...) {
// This code runs AFTER the framework has decided to withdraw
// but potentially BEFORE the calling module's post-withdrawal logic
// Can this hook call back into the protocol?
// What state has been partially modified at this point?
}Trace: What is the call stack at the point the withdraw hook fires?
redeem())fungible_asset::withdraw()module::withdraw_hook()Can a deposit hook selectively revert to block specific operations?
If derived_balance hook is registered:
fungible_asset::balance() trigger external code?balance() called within a state modification sequence? (read-modify-write pattern where read triggers hook)For each reentrancy vector found, categorize the recommended fix:
| Vector | Recommended Fix | Implementation |
|---|---|---|
| Cross-module via closure | Add #[module_lock] | Module-level attribute |
| Direct reentrancy | Check-Effect-Interaction pattern | Reorder operations: all state writes before dispatch |
| Dispatchable FA hook | Complete all state updates before FA operations | Move all borrow_global_mut before withdraw/deposit |
| Third-party resource bypass | Module-level boolean guard | assert!(!is_executing, E_REENTRANCY) pattern |
#[module_lock] applied? What does it cover vs not cover?borrow_global_mut, no state writes), reentrancy cannot cause inconsistency#[module_lock] is present AND the closure does not call the same module's functions, reentrancy is fully blocked## Finding [RE-N]: Title
**Verdict**: CONFIRMED / PARTIAL / REFUTED / CONTESTED
**Step Execution**: ✓1,2,3,4,5,6 | ✗N(reason) | ?N(uncertain)
**Rules Applied**: [R4:✓/✗, R10:✓/✗, R12:✓/✗]
**Severity**: Critical/High/Medium/Low/Info
**Location**: module_name.move:LineN
**Reentrancy Type**: DIRECT / INDIRECT / HOOK_BASED / THIRD_PARTY_BYPASS
**Dispatch Point**: {function:line where dynamic dispatch occurs}
**Inconsistent State**: {which state variables are out of sync during callback}
**Description**: What's wrong
**Impact**: What can happen (double-spend, state corruption, fund theft)
**Evidence**: Code showing the dispatch point and state ordering
### Attack Sequence
1. [Attacker calls function X]
2. [State S1 is modified]
3. [Dynamic dispatch triggers callback]
4. [Callback reenters function Y which reads stale S2]
5. [Impact: ...]
### Precondition Analysis (if PARTIAL/REFUTED)
**Missing Precondition**: [What blocks exploitation]
**Precondition Type**: STATE / ACCESS / TIMING / EXTERNAL / BALANCE
### Postcondition Analysis (if CONFIRMED/PARTIAL)
**Postconditions Created**: [What conditions this creates]
**Postcondition Types**: [List applicable types]
**Who Benefits**: [Who can use these]| Step | Required | Completed? | Notes |
|---|---|---|---|
| 1. Dynamic Dispatch Point Inventory | YES | ✓/✗/? | Both closures (1a) and FA hooks (1b) |
| 2. Module Lock Analysis | YES | ✓/✗/? | Direct vs indirect distinction |
| 3. Third-Party Resource Lock Bypass | IF third-party data structures used | ✓/✗(N/A)/? | |
| 4. State Consistency Analysis | FOR EACH dispatch point | ✓/✗/? | Pre/post dispatch state traced |
| 5. Dispatchable FA Specific | IF dispatchable FA used | ✓/✗(N/A)/? | 5a, 5b, 5c sub-steps |
| 6. Mitigation Recommendations | FOR EACH finding | ✓/✗/? |
If any step skipped, document valid reason (N/A, no dynamic dispatch, no dispatchable FA, module lock covers all paths).
© PlamenTSV, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in agents/skills/aptos/reentrancy-analysis of PlamenTSV/plamen.
Open the folder on GitHubat commit 795962b
Reentrancy Analysis next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Reentrancy Analysis this skillPlamenTSV/plamen | 303 | — | ~2.9k | Automated safety check: Pass | MIT | |
| Web3 Smart Contract Auditawarexone/Agentic-Bug-Hunter | 5.3k | 3 repos | ~4.5k | Automated safety check: Pass | MIT | |
| Fizzpashov/skills | 1.2k | 2 repos | ~11k | Automated safety check: Pass | MIT | |
| Web3 Smart Contract Grep Arsenaltradecatlabs/vibe-coding-cn | 17k | 2 repos | ~3.3k | Automated safety check: Pass | MIT | |
| X Raypashov/skills | 1.2k | 1 repos | ~10k | Automated safety check: Pass | MIT | |
| Web3 Bug Bounty AI Toolstradecatlabs/vibe-coding-cn | 17k | 2 repos | ~3.9k | Automated safety check: Warn | MIT |
awarexone/Agentic-Bug-Hunter
Guides smart contract audits and bounty target selection with ten DeFi bug classes, kill signals, a Foundry PoC template and grep patterns.
pashov/skills
Generate Echidna/Medusa-compatible Solidity fuzz suites from Foundry or Hardhat projects.
tradecatlabs/vibe-coding-cn
A master set of ten grep command blocks that surface likely vulnerability classes in Solidity source within the first 30 minutes of auditing a new protocol.
pashov/skills
Generates an x-ray.md pre-audit report covering overview, enhanced threat model (protocol-type profiling, git-weighted attack surfaces, temporal risk analysis, composability dependency mapping)…
tradecatlabs/vibe-coding-cn
A selection guide to AI-driven tools for Web3 bug bounty work, from autonomous web pentesters to smart contract bug finders, with notes on authorization.
pashov/skills
Reconcile an existing Fizz harness with a changed source tree.
PlamenTSV/plamen
Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project…
PlamenTSV/plamen
Trigger Pattern Always (used by all verifier agents) - Inject Into security-verifier agents (Phase 5)
PlamenTSV/plamen
Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth agents, depth agents
PlamenTSV/plamen
Trigger Pattern Always (Sui Move) -- foundational security check - Inject Into Breadth agents, depth agents
PlamenTSV/plamen
Trigger Pattern ACCOUNTCLOSING flag detected (close/CloseAccount usage) - Inject Into Breadth agents, depth agents
PlamenTSV/plamen
Trigger Pattern Always required for Solana audits - Inject Into Breadth agents, depth agents
Categories
Trigger REENTRANCY flag detected (dynamic dispatch, closures, dispatchable FA, function values) - Used by Breadth agents, depth-state-trace. Reentrancy Analysis is an agent skill from PlamenTSV/plamen.
Reentrancy Analysis fits situations like: REENTRANCY flag detected (dynamic dispatch; dispatchable FA; function values) - Used by Breadth agents; depth-state-trace.
Run `npx skills add PlamenTSV/plamen --skill reentrancy-analysis -a claude-code`. Or copy the skill folder (agents/skills/aptos/reentrancy-analysis in PlamenTSV/plamen) into .claude/skills/reentrancy-analysis in your project. Claude Code loads it when a task matches its description.
Run `npx skills add PlamenTSV/plamen --skill reentrancy-analysis -a codex`. Or copy the skill folder (agents/skills/aptos/reentrancy-analysis in PlamenTSV/plamen) into .agents/skills/reentrancy-analysis in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PlamenTSV/plamen --skill reentrancy-analysis -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/reentrancy-analysis, .gemini/skills/reentrancy-analysis, .github/skills/reentrancy-analysis and .opencode/skills/reentrancy-analysis in your project.
SKILL.md names no scripts, command-line tools or credentials: Reentrancy Analysis is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Reentrancy Analysis is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Reentrancy Analysis: Web3 Smart Contract Audit (awarexone/Agentic-Bug-Hunter, 5.3k stars), Fizz (pashov/skills, 1.2k stars), Web3 Smart Contract Grep Arsenal (tradecatlabs/vibe-coding-cn, 17k stars) and X Ray (pashov/skills, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
PlamenTSV (a GitHub user) maintains it in PlamenTSV/plamen, which has 303 GitHub stars. The repository holds 87 skills in this directory. The repository was last updated on September 26, 2026.
Source: PlamenTSV/plamen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.