Golang Patterns
affaan-m/ECC
Go-specific design patterns and best practices including functional options, small interfaces, dependency injection, concurrency patterns, error handling, and package organization.
Type Thought-template (instantiate before use) - Trigger Pattern Always (Aptos Move) -- ConstructorRef/TransferRef/MintRef/BurnRef lifecycle
$ npx skills add PlamenTSV/plamen --skill ref-lifecycle -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install PlamenTSV/plamen ref-lifecycle --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agents/skills/aptos/ref-lifecycle .claude/skills/ref-lifecycle && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "ref-lifecycle" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/aptos/ref-lifecycle into .claude/skills/ref-lifecycle/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ref-lifecycle", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/PlamenTSV/plamen/tree/main/agents/skills/aptos/ref-lifecycleType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add PlamenTSV/plamen --skill ref-lifecycle -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install PlamenTSV/plamen ref-lifecycle --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .agents/skills && cp -r skills-src/agents/skills/aptos/ref-lifecycle .agents/skills/ref-lifecycle && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "ref-lifecycle" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/aptos/ref-lifecycle into .agents/skills/ref-lifecycle/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ref-lifecycle", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add PlamenTSV/plamen --skill ref-lifecycle -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install PlamenTSV/plamen ref-lifecycle --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/agents/skills/aptos/ref-lifecycle .cursor/skills/ref-lifecycle && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "ref-lifecycle" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/aptos/ref-lifecycle into .cursor/skills/ref-lifecycle/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ref-lifecycle", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/PlamenTSV/plamen.git --path agents/skills/aptos/ref-lifecycle--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add PlamenTSV/plamen --skill ref-lifecycle -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install PlamenTSV/plamen ref-lifecycle --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/agents/skills/aptos/ref-lifecycle .gemini/skills/ref-lifecycle && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "ref-lifecycle" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/aptos/ref-lifecycle into .gemini/skills/ref-lifecycle/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ref-lifecycle", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install PlamenTSV/plamen ref-lifecycleInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add PlamenTSV/plamen --skill ref-lifecycle -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .github/skills && cp -r skills-src/agents/skills/aptos/ref-lifecycle .github/skills/ref-lifecycle && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "ref-lifecycle" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/aptos/ref-lifecycle into .github/skills/ref-lifecycle/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ref-lifecycle", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add PlamenTSV/plamen --skill ref-lifecycle -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install PlamenTSV/plamen ref-lifecycle --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/agents/skills/aptos/ref-lifecycle .opencode/skills/ref-lifecycle && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "ref-lifecycle" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/aptos/ref-lifecycle into .opencode/skills/ref-lifecycle/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ref-lifecycle", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
ref-lifecycleType Thought-template (instantiate before use) - Trigger Pattern Always (Aptos Move) -- ConstructorRef/TransferRef/MintRef/BurnRef lifecycle
Ref Lifecycle is an agent skill from PlamenTSV/plamen. Type Thought-template (instantiate before use) - Trigger Pattern Always (Aptos Move) -- ConstructorRef/TransferRef/MintRef/BurnRef lifecycle
Its SKILL.md is about 3.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
The repository describes itself as: Autonomous Web3 security audit agent for Claude Code. The licence is MIT.
8 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 795962b. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Ref Lifecycle loads about 3.4k tokens when it runs. Until then it costs about 39 tokens; SKILL.md has 1,494 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from PlamenTSV/plamen at commit 795962b, republished under its MIT licence (© PlamenTSV). 1,494 words, ~3,414 tokens.
.claude/skills/ref-lifecycle/SKILL.md (or your agent's skills folder).Type: Thought-template (instantiate before use) Trigger Pattern: Always (Aptos Move) -- ConstructorRef/TransferRef/MintRef/BurnRef lifecycle Inject Into: Breadth agents, depth-state-trace, depth-token-flow Research basis: Aptos Object model capability-based access control, permanent reference semantics
In Aptos Move, object capabilities (Refs) are unforgeable tokens that grant specific permissions over objects. Unlike role-based access control in EVM, Refs are permanent once created -- they CANNOT be revoked. A leaked or improperly stored Ref grants permanent capability to its holder.
Key Ref types:
object::create_*. Parent of all other Refs. Grants ability to generate TransferRef, MintRef, BurnRef, DeleteRef, and ExtendRef.TransferRef is frozen. Bypasses ungated_transfer restrictions.ConstructorRef|TransferRef|MintRef|BurnRef|DeleteRef|ExtendRef|
object::create_named_object|object::create_sticky_object|object::create_object|
fungible_asset::generate_mint_ref|fungible_asset::generate_burn_ref|
fungible_asset::generate_transfer_ref|object::generate_delete_ref|
object::generate_extend_ref|object::generate_transfer_refEnumerate ALL Ref types found in the codebase. For each:
| Ref Type | Created In (module::function) | Stored Location | Access Control | Capability Granted |
|---|---|---|---|---|
| ConstructorRef | {module}::{init_fn} | {consumed / stored in resource} | {who can access} | Generate all other Refs |
| MintRef | {module}::{init_fn} | {global resource at @addr} | {who can access} | Unlimited minting of {asset} |
| BurnRef | {module}::{init_fn} | {global resource at @addr} | {who can access} | Burn {asset} from any store |
| TransferRef | {module}::{init_fn} | {global resource at @addr} | {who can access} | Transfer {asset} bypassing freeze |
| DeleteRef | {module}::{init_fn} | {global resource at @addr} | {who can access} | Delete {object} |
| ExtendRef | {module}::{init_fn} | {global resource at @addr} | {who can access} | Generate signer for {object} |
Completeness check: Search for ALL generate_*_ref calls and object::create_* calls. Every Ref created MUST appear in the table.
The ConstructorRef is the root capability. It exists only during the init_module or object creation call.
Check 2a: Is ConstructorRef stored?
ConstructorRef -- this type has drop but NOT store, so it CANNOT be stored in global storage directly.object::generate_signer(&constructor_ref) and stores the signer reference indirectly, trace what that signer can do.Check 2b: What Refs are generated from it?
generate_*_ref call that uses this ConstructorRefpublic visibility or weak access control -> unlimited minting capability leak.Check 2c: ExtendRef derived signer
object::generate_extend_ref is called, the resulting ExtendRef can later produce a signer via object::generate_signer_for_extendingmove_to/move_fromCheck 3a: Storage access control
acquires and signer requirements)public fun that exposes MintRef via return value or mutable reference?public fun returning &MintRef or &mut MintRef = capability leak to any module.Check 3b: Mint amount validation
fungible_asset::supply check before mint)Check 3c: BurnRef scope
fungible_asset::burn_from with a BurnRef can burn tokens from ANY FungibleStoreCheck 3d: Mint/Burn symmetry
Check 4a: Freeze bypass
fungible_asset::transfer_with_ref bypasses frozen store checksfungible_asset::set_frozen_flag for compliance/security: does a stored TransferRef undermine the freeze?Check 4b: Transfer direction
fungible_asset::transfer_with_ref takes from: Object<FungibleStore> and to: Object<FungibleStore> -- the holder controls BOTH endsCheck 4c: Who holds TransferRef?
public entry fun to the transfer_with_ref invocation.Check 5a: Resource cleanup before deletion
object::delete(delete_ref) is called, what happens to resources stored at the object address?move_from of all resources = stranded assets (Rule 9: minimum MEDIUM).Check 5b: Deletion authorization
Check 6a: Public function returns
public fun or public(friend) fun that returns a Ref type&MintRef (immutable reference) leak is dangerous because it can be passed to fungible_asset::mint within the same transactionpublic fun returning Ref = Critical leak (any module can use). public(friend) fun returning Ref = Medium leak (friend modules can use -- check friend list).Check 6b: Friend module exposure
friend declarations in modules that store Refspublic fun that uses the Ref without additional access control?public fun that calls Module A's mint function = any module can mint via Module B.Check 6c: Store ability check
store ability can be placed in arbitrary global storage locationsstore? (standard Aptos Refs: ConstructorRef has drop only; MintRef/BurnRef/TransferRef/DeleteRef/ExtendRef have drop and store)store ability placed in a resource with weak access control = Ref can migrate to uncontrolled storage.Critical fact: Aptos Refs CANNOT be revoked once created. There is no revoke_mint_ref function in the framework.
Check 7a: Maximum blast radius
Check 7b: Compensating controls
Check 7c: Module upgrade path
compatible or immutable policy?): can an upgrade change who accesses the Ref?Check 8a: Ref combination attacks
Check 8b: Ref holder alignment
## Finding [{PREFIX}-N]: {Title}
**Verdict**: CONFIRMED / PARTIAL / REFUTED / CONTESTED
**Step Execution**: {see checklist below}
**Ref Type**: {ConstructorRef / MintRef / BurnRef / TransferRef / DeleteRef / ExtendRef}
**Severity**: {Critical/High/Medium/Low/Info}
**Location**: {SourceFile:LineN}
**Description**: {What capability is exposed and how}
**Impact**: {What an attacker/compromised entity can do with the Ref}
**Evidence**: {Code showing Ref creation, storage, and access path}
### Blast Radius
- **If compromised**: {Maximum damage description}
- **Revocable**: NO (Aptos Refs are permanent)
- **Compensating controls**: {pause/multisig/rate-limit or NONE}| Step | Required | Completed? | Notes |
|---|---|---|---|
| 1. Reference Inventory | YES | Y/N/? | Must enumerate ALL Refs |
| 2. ConstructorRef Analysis | YES | Y/N/? | |
| 3. MintRef/BurnRef Analysis | IF present | Y/N(none)/? | |
| 4. TransferRef Analysis | IF present | Y/N(none)/? | |
| 5. DeleteRef Analysis | IF present | Y/N(none)/? | |
| 6. Ref Leakage Path Analysis | YES | Y/N/? | Check public returns + friends |
| 7. Ref Revocation Assessment | YES | Y/N/? | Always: Refs are permanent |
| 8. Cross-Ref Interaction | IF 2+ Ref types | Y/N(single)/? |
**Step Execution**: check1,2,3,4,6,7,8 | x5(no DeleteRef)OR if incomplete:
**Step Execution**: check1,2,3 | ?4,6,7(TransferRef not fully traced)
**FLAG**: Incomplete analysis -- requires depth review (leakage paths not exhausted){CONTRACTS} -- Move modules to analyze
{ASSET_NAME} -- Primary fungible asset name
{REF_STORAGE} -- Where Refs are stored (resource name and address)
{ACCESS_CONTROL} -- Who can access stored Refs (signer requirements)
{FRIEND_MODULES} -- Modules declared as friends
{FREEZE_USED} -- Whether protocol uses freeze functionality (YES/NO)
{UPGRADE_POLICY} -- Module upgrade policy (compatible/immutable)| Field | Required | Description |
|---|---|---|
| ref_inventory | yes | Complete table of all Refs in codebase |
| constructor_ref_analysis | yes | ConstructorRef lifecycle and consumption |
| mint_burn_analysis | if present | MintRef/BurnRef storage and access control |
| transfer_ref_analysis | if present | TransferRef and freeze bypass potential |
| delete_ref_analysis | if present | DeleteRef and resource cleanup |
| leakage_paths | yes | Public/friend exposure of Refs |
| revocation_assessment | yes | Blast radius and compensating controls |
| cross_ref_interactions | if 2+ types | Combined Ref attack scenarios |
| finding | yes | CONFIRMED / REFUTED / CONTESTED / NEEDS_DEPTH |
| evidence | yes | Code locations with line numbers |
| step_execution | yes | Status for each step |
© PlamenTSV, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in agents/skills/aptos/ref-lifecycle of PlamenTSV/plamen.
Open the folder on GitHubat commit 795962b
Ref Lifecycle next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Ref Lifecycle this skillPlamenTSV/plamen | 303 | — | ~3.4k | Automated safety check: Pass | MIT | |
| Golang Patternsaffaan-m/ECC | 274k | — | ~1.1k | Automated safety check: Pass | MIT | |
| Kotlin Exposed Patternsaffaan-m/ECC | 274k | 4 repos | ~5.5k | Automated safety check: Pass | MIT | |
| Dotnet Patternsaffaan-m/ECC | 274k | 1 repos | ~2.3k | Automated safety check: Pass | MIT | |
| Fastapi Patternsaffaan-m/ECC | 274k | — | ~2.3k | Automated safety check: Pass | MIT | |
| Python Patternsaffaan-m/ECC | 274k | — | ~2.3k | Automated safety check: Pass | MIT |
affaan-m/ECC
Go-specific design patterns and best practices including functional options, small interfaces, dependency injection, concurrency patterns, error handling, and package organization.
affaan-m/ECC
JetBrains Exposed ORM patterns including DSL queries, DAO pattern, transactions, HikariCP connection pooling, Flyway migrations, and repository pattern.
affaan-m/ECC
Idiomatic C and .NET patterns, conventions, dependency injection, async/await, and best practices for building robust, maintainable .NET applications.
affaan-m/ECC
FastAPI patterns for async APIs, dependency injection, Pydantic request and response models, OpenAPI docs, tests, security, and production readiness.
affaan-m/ECC
Python-specific design patterns and best practices including protocols, dataclasses, context managers, decorators, async/await, type hints, and package organization.
sickn33/agentic-awesome-skills
Reference document for monopoly patterns. An agent skill from sickn33/agentic-awesome-skills.
PlamenTSV/plamen
Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project…
PlamenTSV/plamen
Trigger Pattern Always (used by all verifier agents) - Inject Into security-verifier agents (Phase 5)
PlamenTSV/plamen
Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth agents, depth agents
PlamenTSV/plamen
Trigger Pattern Always (Sui Move) -- foundational security check - Inject Into Breadth agents, depth agents
PlamenTSV/plamen
Trigger Pattern ACCOUNTCLOSING flag detected (close/CloseAccount usage) - Inject Into Breadth agents, depth agents
PlamenTSV/plamen
Trigger Pattern Always required for Solana audits - Inject Into Breadth agents, depth agents
Type Thought-template (instantiate before use) - Trigger Pattern Always (Aptos Move) -- ConstructorRef/TransferRef/MintRef/BurnRef lifecycle. Ref Lifecycle is an agent skill from PlamenTSV/plamen.
Ref Lifecycle fits situations like: pattern Always (Aptos Move) -- ConstructorRef/TransferRef/MintRef/BurnRef lifecycle.
Run `npx skills add PlamenTSV/plamen --skill ref-lifecycle -a claude-code`. Or copy the skill folder (agents/skills/aptos/ref-lifecycle in PlamenTSV/plamen) into .claude/skills/ref-lifecycle in your project. Claude Code loads it when a task matches its description.
Run `npx skills add PlamenTSV/plamen --skill ref-lifecycle -a codex`. Or copy the skill folder (agents/skills/aptos/ref-lifecycle in PlamenTSV/plamen) into .agents/skills/ref-lifecycle in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PlamenTSV/plamen --skill ref-lifecycle -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ref-lifecycle, .gemini/skills/ref-lifecycle, .github/skills/ref-lifecycle and .opencode/skills/ref-lifecycle in your project.
SKILL.md names no scripts, command-line tools or credentials: Ref Lifecycle is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Ref Lifecycle is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.4k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Ref Lifecycle: Golang Patterns (affaan-m/ECC, 274k stars), Kotlin Exposed Patterns (affaan-m/ECC, 274k stars), Dotnet Patterns (affaan-m/ECC, 274k stars) and Fastapi Patterns (affaan-m/ECC, 274k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
PlamenTSV (a GitHub user) maintains it in PlamenTSV/plamen, which has 303 GitHub stars. The repository holds 87 skills in this directory. The repository was last updated on September 26, 2026.
Source: PlamenTSV/plamen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.