Agent skill

Semantic Gap Investigator

by PlamenTSV in PlamenTSV/plamen

Trigger Semantic Invariant Agent (Phase 4a.5) reports syncgaps = 1 OR accumulationexposures = 1 OR conditionalwrites = 1 OR clustergaps = 1 in its return message - Agent Typ...

MITAuto-check passed

Install Semantic Gap Investigator

skills CLI
$ npx skills add PlamenTSV/plamen --skill semantic-gap-investigator -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install PlamenTSV/plamen semantic-gap-investigator --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agents/skills/niche/semantic-gap-investigator .claude/skills/semantic-gap-investigator && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
semantic-gap-investigator
GitHub stars
303
Token cost
~2.7k tokens
SKILL.md length
306 words
Files
1
Skills in repo
87
Repo updated
First seen
Licence
MIT

At a glance

Trigger Semantic Invariant Agent (Phase 4a.5) reports syncgaps = 1 OR accumulationexposures = 1 OR conditionalwrites = 1 OR clustergaps = 1 in its return message - Agent Typ...

  • Semantic Invariant Agent (Phase 4a.
  • SKILL.md covers When This Agent Spawns, Agent Prompt Template and Why Niche Agent (Not Scanner…
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Reports syncgaps = 1 OR accumulationexposures = 1 OR conditionalwrites = 1 OR clustergaps = 1 in its return message - Agent Typ..

What it does

Semantic Gap Investigator is an agent skill from PlamenTSV/plamen. Trigger Semantic Invariant Agent (Phase 4a.5) reports syncgaps = 1 OR accumulationexposures = 1 OR conditionalwrites = 1 OR clustergaps = 1 in its return message - Agent Typ...

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: Autonomous Web3 security audit agent for Claude Code. The licence is MIT.

When your agent uses it

  • Semantic Invariant Agent (Phase 4a.
  • Reports syncgaps = 1 OR accumulationexposures = 1 OR conditionalwrites = 1 OR clustergaps = 1 in its return message - Agent Typ..

Example prompts

  • “/semantic-gap-investigator”

What it can do on your machine

Read from SKILL.md and the folder at commit 795962b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Semantic Gap Investigator loads about 2.7k tokens when it runs. Until then it costs about 52 tokens; SKILL.md has 306 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~52
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from PlamenTSV/plamen at commit 795962b, republished under its MIT licence (© PlamenTSV). 306 words, ~2,720 tokens.

Download SKILL.mdSave it as .claude/skills/semantic-gap-investigator/SKILL.md (or your agent's skills folder).
name
semantic-gap-investigator
description
Trigger Semantic Invariant Agent (Phase 4a.5) reports sync_gaps = 1 OR accumulation_exposures = 1 OR conditional_writes = 1 OR cluster_gaps = 1 in its return message - Agent Typ...

Niche Agent: Semantic Gap Investigator

Trigger: Semantic Invariant Agent (Phase 4a.5) reports sync_gaps >= 1 OR accumulation_exposures >= 1 OR conditional_writes >= 1 OR cluster_gaps >= 1 in its return message Agent Type: general-purpose (standalone niche agent, NOT injected into another agent) Budget: 1 depth budget slot in Phase 4b iteration 1 Finding prefix: [SGI-N]

When This Agent Spawns

The Semantic Invariant Agent (Phase 4a.5) Pass 2 returns a summary: 'DONE: {G} cluster_gaps, {T} consequence traces ({D} deep_propagation), {W} missed_write_sites, {B} branch_asymmetries'. Pass 1 returns: 'DONE: {N} variables, {M} gaps, {C} conditional, {S} sync_gaps, {A} accumulation, {K} clusters'. If S >= 1 OR A >= 1 OR C >= 1 OR G >= 1, the orchestrator spawns this agent.

CONDITIONAL writes on accumulator/snapshot/tracking variables are now in-scope. The semantic invariant agent pre-filters - it only annotates CONDITIONALs on state-tracking variables (not every if in the codebase), so the investigation set is bounded. Depth agents do not systematically trace conditional skip-path consequences through consumer functions; this agent does.

Agent Prompt Template

Task(subagent_type="general-purpose", prompt="
You are the Semantic Gap Investigator. You take pre-flagged SYNC_GAP, ACCUMULATION_EXPOSURE, and CONDITIONAL annotations from the Semantic Invariant Agent and investigate each one to a definitive conclusion (exploitable or benign).

## Your Inputs
Read:
- {SCRATCHPAD}/semantic_invariants.md (the Main Table CONDITIONAL annotations, Mirror Variable Pairs, and Time-Weighted Accumulators tables, plus any Potential Gaps column entries tagged SYNC_GAP, ACCUMULATION_EXPOSURE, or CONDITIONAL)
- {SCRATCHPAD}/state_variables.md (variable definitions)
- {SCRATCHPAD}/function_list.md (all functions)
- Source files referenced in the gap annotations

## Processing Protocol (MANDATORY)

For each analysis step below, execute in order:
1. **ENUMERATE targets**: List every entity the step applies to (gaps, variables, functions) as a numbered list before analysis begins.
2. **PROCESS exhaustively**: Analyze each numbered entity. Mark each "DONE" or "N/A (reason)" before moving to the next.
3. **COVERAGE GATE**: Count enumerated vs processed. If any entity lacks a marker, process it before proceeding to the next step.

## Your Task

### STEP 1: Extract Investigation Targets

From semantic_invariants.md, collect every entry tagged:
- **SYNC_GAP(other_var, function)**: A function writes one mirror variable but not the other
- **ACCUMULATION_EXPOSURE(input, time_source)**: A time-weighted calculation with externally controllable input and unbounded time delta
- **CONDITIONAL(condition_expression)**: A write to an accumulator/snapshot/tracking variable that only executes when a condition is true - callers that trigger the enclosing function when the condition is false leave this variable stale

### STEP 2: Investigate Each SYNC_GAP

For each SYNC_GAP:
1. Read the function that creates the gap (writes variable A but not variable B)
2. Identify ALL consumers that read the stale variable B after the gap-creating function executes
3. For each consumer: trace the execution with concrete values showing the stale read produces a wrong result
4. Check: is the gap self-correcting? If yes, how long can the window last? What functions trigger correction?
5. Check: can any action during the gap window cause permanent damage (e.g., setting a checkpoint to a stale value)?

Verdict per gap:
- **EXPLOITABLE**: Consumer produces materially wrong result during window, AND window can last > 1 block, AND either (a) window is unbounded or (b) permanent damage is possible during window. **After EXPLOITABLE verdict**: The confirmed mechanism requires precondition P. Using the Main Table write sites (including constructor), verify no other code path also establishes P. If found: investigate and create a separate finding.
- **BENIGN**: Gap exists but all consumers are overridden/unused, OR gap self-corrects within same transaction, OR stale value direction is always conservative (undercharges, not overcharges)

### STEP 3: Investigate Each ACCUMULATION_EXPOSURE

For each ACCUMULATION_EXPOSURE:
1. Read the accumulation formula and identify the controllable input and time source
2. Model the attack: Can an actor (permissionless OR semi-trusted) manipulate the controllable input, wait for time to pass, then trigger the accumulation to snapshot the manipulated state?
3. Quantify: What is the maximum excess accumulation from a single manipulation? Use concrete values (e.g., 1000 ETH deposit, 7-day stale period, 10% annual fee rate)
4. Check mitigations: Does the protocol snapshot BEFORE or AFTER the manipulation? Does it use min(old, new) or time-weighted averages? Are there caps?
5. Check composition: Can multiple exposures be combined (e.g., inflate supply AND extend time delta in the same attack)?

Verdict per exposure:
- **EXPLOITABLE**: Manipulation produces > 1% excess accumulation with realistic parameters, AND no mitigation fully prevents it, AND attacker can profit (or protocol loses funds). **After EXPLOITABLE verdict**: The confirmed mechanism requires precondition P. Using the Main Table write sites (including constructor), verify no other code path also establishes P. If found: investigate and create a separate finding.
- **BENIGN**: Mitigations prevent meaningful manipulation, OR the exposure is bounded below materiality, OR the controllable input requires fully-trusted actor access

### STEP 4: Investigate Each CONDITIONAL Write

For each CONDITIONAL annotation on an accumulator/snapshot/tracking variable:
1. Identify the function containing the conditional write and the condition expression
2. Identify ALL callers of that function (direct and indirect via call chain)
3. For each caller: determine if the caller can trigger the function when the condition is FALSE (the skip path). What concrete state causes the skip? (e.g., `vestingGains == 0` after full vest (vesting vaults), `pendingRewards == 0` after claim (staking), `timeElapsed == 0` in same block, `totalSupply == 0` after last exit (share-based pools))
4. When the write is skipped, identify ALL consumer functions that READ the stale variable afterward - within the same caller's execution AND in subsequent external calls
5. For each consumer: trace execution with the stale value using concrete numbers. Does the stale read produce a materially wrong result?
6. Check temporal scope: how long can the stale value persist? Until the next call that satisfies the condition? Unbounded?

Verdict per conditional:
- **EXPLOITABLE**: Consumer produces materially wrong result with stale value, AND the skip path is reachable under normal operation (not just error/revert paths), AND the staleness window can last > 1 block. **After EXPLOITABLE verdict**: The confirmed mechanism requires precondition P. Using the Main Table write sites (including constructor), verify no other code path also establishes P. If found: investigate and create a separate finding.
- **BENIGN**: Skip path is unreachable under normal operation, OR all consumers handle the stale value correctly, OR staleness self-corrects within the same transaction

### STEP 5: Trace Conditional Skip Paths for SYNC_GAP functions

For each function identified in STEP 2 as creating a sync gap:
- Does ANY caller of this function assume the gap does NOT exist?
- Specifically: if function F creates a sync gap when condition C is false, does any caller of F (e.g., `distributeYield`/`recordLoss` (vesting vaults), `reportProfit`/`reportLoss` (Yearn-style), `notifyRewardAmount`/`getReward` (staking)) rely on the variable being updated regardless of C?
- If yes: trace the caller's subsequent logic with the stale value to find the impact

**Coverage assertion**: Before returning, verify every entity enumerated under each step has been processed. Report enumerated vs analyzed counts in your return message.

## Output Format

### Flag Disposition Table (MANDATORY - write FIRST, update per flag)

Write this skeleton table to {SCRATCHPAD}/niche_semantic_gap_findings.md BEFORE starting investigation.
Update each row's Disposition as you investigate. PENDING rows at completion = workflow violation.

| # | Flag Type | Variable | Location | Disposition | If BENIGN: Defense (file:line) | If EXPLOITABLE: Finding ID |
|---|-----------|----------|----------|-------------|-------------------------------|---------------------------|

Every SYNC_GAP, ACCUMULATION_EXPOSURE, CONDITIONAL, and CLUSTER_GAP flag from semantic_invariants.md
MUST appear as a row. The orchestrator verifies: count(rows) == count(flags).

### Findings

Use standard finding format with [SGI-N] IDs.

For each finding, include:
- **Gap Type**: SYNC_GAP, ACCUMULATION_EXPOSURE, CONDITIONAL_SKIP, or CLUSTER_GAP
- **Source Annotation**: Quote the exact annotation from semantic_invariants.md
- **Investigation Result**: EXPLOITABLE or BENIGN with full reasoning
- **Concrete Values**: Numeric trace showing the wrong result (for EXPLOITABLE)

## Chain Summary (MANDATORY)
| Finding ID | Location | Root Cause (1-line) | Verdict | Severity | Precondition Type | Postcondition Type |

Write to {SCRATCHPAD}/niche_semantic_gap_findings.md

Return: 'DONE: {S} sync gaps, {A} accumulation exposures, {C} conditional writes, {G} cluster gaps - {T} total flags dispositioned, {E} exploitable'
")

Why Niche Agent (Not Scanner Sub-Check or Injectable)

  • Not a scanner sub-check: Investigating gaps requires reading multiple source files, tracing consumers through call chains, and modeling concrete value flows. This exceeds a scanner's 2-minute time budget per check.
  • Not an injectable: This is not protocol-type-specific. SYNC_GAPs, ACCUMULATION_EXPOSUREs, and CONDITIONAL writes on tracking variables can appear in any protocol with stateful accumulators (vaults, staking, lending, DEXes).
  • Flag-triggered isolation: Only spawns when the Semantic Invariant Agent detects high-signal flags. Zero context cost for protocols without these patterns.
  • Why CONDITIONAL writes are in-scope: Depth agents and CHECK 8 scan for branch asymmetry from code, but do not systematically consume the pre-computed CONDITIONAL annotations from semantic_invariants.md. The niche agent already has the consumer-tracing infrastructure (Steps 2-3); extending it to CONDITIONAL writes is a natural fit. The semantic invariant agent pre-filters to tracking variables only, keeping the investigation set bounded.

© PlamenTSV, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in agents/skills/niche/semantic-gap-investigator of PlamenTSV/plamen.

Open the folder on GitHubat commit 795962b

Compare with similar skills

Semantic Gap Investigator next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Semantic Gap Investigator compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Semantic Gap Investigator this skillPlamenTSV/plamen303—~2.7kAutomated safety check: PassMIT
Sync State Invariantsopenchamber/openchamber11k—~2.7kAutomated safety check: PassMIT
Root Cause Investigationgarrytan/gstack136k—~13kAutomated safety check: NotesMIT
Investigate Dropbox Sync Issueblotcms/blot2k—~4.7kAutomated safety check: PassAGPL-3.0
Osint Investigationaffaan-m/ECC276k—~5.7kAutomated safety check: PassCC-BY-SA-4.0
Investigate Macserver Sync Issueblotcms/blot2k—~4.2kAutomated safety check: WarnAGPL-3.0

Similar skills

  • Sync State Invariants

    openchamber/openchamber

    A skill your agent uses when changing session synchronization, bootstrap or reconnect state, event reducers, polling, optimistic updates, message queues, live activity, ordering/reconciliation…

    11k GitHub stars~2.7k tokensUpdated today
    Business, Finance & HRAuto-check passed
  • Debugs in four phases (investigate, analyze, hypothesize, implement) under one rule: no fix is made until the root cause is found.

    136k GitHub stars~13k tokensUpdated today
    DevelopmentAuto-check: notes
  • Investigate a "Dropbox sync issue" alert email from Blot's hourly Dropbox sync validation (each flagged blog lists unsynced changes, Fix() repairs, errors and/or a stuck folder lock; the changes…

    2k GitHub stars~4.7k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Sparse-clue OSINT investigation methodology for extracting overlooked leads, connecting fragmented evidence, and testing explanations across sources.

    276k GitHub stars~5.7k tokensUpdated yesterday
    SecurityAuto-check passed
  • Investigate an "iCloud resync found changes" admin email (the ICLOUDRESYNCISSUE email a macserver-requested resync sends when it found changes, Fix() repairs or errors, with the macserver's reason)…

    2k GitHub stars~4.2k tokensUpdated yesterday
    Auto-check: warnings
  • React Sync

    vercel/next.js

    Official

    Build local React changes in the bundle variants consumed by Next.js, sync them into a local Next.js checkout, and test the resulting integration.

    143k GitHub stars~486 tokensUpdated today
    Auto-check passed

More from PlamenTSV/plamen

All 87 skills in this repo
  • Audit Prep

    PlamenTSV/plamen

    Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project…

    303 GitHub stars~3.7k tokensUpdated 14 days ago
    Auto-check passed
  • Verification Protocol

    PlamenTSV/plamen

    Trigger Pattern Always (used by all verifier agents) - Inject Into security-verifier agents (Phase 5)

    303 GitHub stars~3.5k tokensUpdated 14 days ago
    Auto-check passed
  • Ability Analysis

    PlamenTSV/plamen

    Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth agents, depth agents

    303 GitHub stars~3.3k tokensUpdated 14 days ago
    Auto-check passed
  • Ability Analysis

    PlamenTSV/plamen

    Trigger Pattern Always (Sui Move) -- foundational security check - Inject Into Breadth agents, depth agents

    303 GitHub stars~3.2k tokensUpdated 14 days ago
    Auto-check passed
  • Account Lifecycle

    PlamenTSV/plamen

    Trigger Pattern ACCOUNTCLOSING flag detected (close/CloseAccount usage) - Inject Into Breadth agents, depth agents

    303 GitHub stars~1.2k tokensUpdated 14 days ago
    Auto-check passed
  • Account Validation

    PlamenTSV/plamen

    Trigger Pattern Always required for Solana audits - Inject Into Breadth agents, depth agents

    303 GitHub stars~1.7k tokensUpdated 14 days ago
    Auto-check passed

Questions about Semantic Gap Investigator

What does Semantic Gap Investigator do?

Trigger Semantic Invariant Agent (Phase 4a.5) reports syncgaps = 1 OR accumulationexposures = 1 OR conditionalwrites = 1 OR clustergaps = 1 in its return message - Agent Typ... Semantic Gap Investigator is an agent skill from PlamenTSV/plamen.5) reports syncgaps = 1 OR accumulationexposures = 1 OR conditionalwrites = 1 OR clustergaps = 1 in its return message - Agent Typ...

When should I use Semantic Gap Investigator?

Semantic Gap Investigator fits situations like: semantic Invariant Agent (Phase 4a; reports syncgaps = 1 OR accumulationexposures = 1 OR conditionalwrites = 1 OR clustergaps = 1 in its return message - Agent Typ..

How do I install Semantic Gap Investigator in Claude Code?

Run `npx skills add PlamenTSV/plamen --skill semantic-gap-investigator -a claude-code`. Or copy the skill folder (agents/skills/niche/semantic-gap-investigator in PlamenTSV/plamen) into .claude/skills/semantic-gap-investigator in your project. Claude Code loads it when a task matches its description.

How do I install Semantic Gap Investigator in Codex?

Run `npx skills add PlamenTSV/plamen --skill semantic-gap-investigator -a codex`. Or copy the skill folder (agents/skills/niche/semantic-gap-investigator in PlamenTSV/plamen) into .agents/skills/semantic-gap-investigator in your project. Codex loads it when a task matches its description.

Can I use Semantic Gap Investigator in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PlamenTSV/plamen --skill semantic-gap-investigator -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/semantic-gap-investigator, .gemini/skills/semantic-gap-investigator, .github/skills/semantic-gap-investigator and .opencode/skills/semantic-gap-investigator in your project.

What does Semantic Gap Investigator need to run?

SKILL.md names no scripts, command-line tools or credentials: Semantic Gap Investigator is instructions for the agent only.

Does Semantic Gap Investigator access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Semantic Gap Investigator safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Semantic Gap Investigator use?

Semantic Gap Investigator is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Semantic Gap Investigator use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Semantic Gap Investigator?

Skills that share tags, products or a category with Semantic Gap Investigator: Sync State Invariants (openchamber/openchamber, 11k stars), Root Cause Investigation (garrytan/gstack, 136k stars), Investigate Dropbox Sync Issue (blotcms/blot, 2k stars) and Osint Investigation (affaan-m/ECC, 276k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Semantic Gap Investigator?

PlamenTSV (a GitHub user) maintains it in PlamenTSV/plamen, which has 303 GitHub stars. The repository holds 87 skills in this directory. The repository was last updated on September 26, 2026.

Source: PlamenTSV/plamen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.