Agent skill

Semi Trusted Roles

by PlamenTSV in PlamenTSV/plamen

Trigger Pattern operator/admin/manager parties listed as signatory or controller, authority-gated choices - Inject Into Breadth agents, depth-state-trace

MITAuto-check passed

Install Semi Trusted Roles

skills CLI
$ npx skills add PlamenTSV/plamen --skill semi-trusted-roles -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install PlamenTSV/plamen semi-trusted-roles --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agents/skills/daml/semi-trusted-roles .claude/skills/semi-trusted-roles && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
semi-trusted-roles
GitHub stars
303
Token cost
~2.7k tokens
SKILL.md length
926 words
Files
1
Skills in repo
87
Repo updated
First seen
Licence
MIT

At a glance

Trigger Pattern operator/admin/manager parties listed as signatory or controller, authority-gated choices - Inject Into Breadth agents, depth-state-trace

  • Works in 6 steps: Inventory Role Permissions → Analyze Within-Scope Abuse (Direction 1… → Model Attack Scenarios → …
  • Pattern operator/admin/manager parties listed as signatory
  • SKILL.md covers Step 1: Inventory Role…, Step 2: Analyze Within-Scope…, Step 3: Model Attack Scenarios and Step 4: Assess Mitigations, plus 6 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Semi Trusted Roles is an agent skill from PlamenTSV/plamen. Trigger Pattern operator/admin/manager parties listed as signatory or controller, authority-gated choices - Inject Into Breadth agents, depth-state-trace

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: Autonomous Web3 security audit agent for Claude Code. The licence is MIT.

When your agent uses it

  • Pattern operator/admin/manager parties listed as signatory
  • Authority-gated choices - Inject Into Breadth agents
  • Depth-state-trace

Example prompts

  • “/semi-trusted-roles”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Inventory Role Permissions
  2. Analyze Within-Scope Abuse (Direction 1 — role harms users)
  3. Model Attack Scenarios
  4. Assess Mitigations
  5. Model User-Side Exploitation (Direction 2 — R6, MANDATORY)
  6. Precondition Griefability Check

What it can do on your machine

Read from SKILL.md and the folder at commit 795962b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Semi Trusted Roles loads about 2.7k tokens when it runs. Until then it costs about 43 tokens; SKILL.md has 926 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~43
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from PlamenTSV/plamen at commit 795962b, republished under its MIT licence (© PlamenTSV). 926 words, ~2,705 tokens.

Download SKILL.mdSave it as .claude/skills/semi-trusted-roles/SKILL.md (or your agent's skills folder).
name
semi-trusted-roles
description
Trigger Pattern operator/admin/manager parties listed as signatory or controller, authority-gated choices - Inject Into Breadth agents, depth-state-trace

SEMI_TRUSTED_ROLES Skill (DAML)

Trigger Pattern: operator/admin/manager/registrar party as signatory or controller, authority-gated choices beyond pure parameter-setting Inject Into: Breadth agents, depth-state-trace Finding prefix: [DML-STR-N] Rules referenced: R2, R6, R10, R13

operator|admin|manager|registrar|issuer|guardian|custodian|controller|signatory|authority

DAML role context: there are no role modifiers. A "role" is a Party that appears as a signatory and/or as a controller of privileged choices. Authority is held by holding that party's submission rights; a choice's required authorizers are its controller parties (AND-joined), a create/archive requires the contract's signatory parties. An operator/admin party is therefore SEMI_TRUSTED: trusted to act within its choices, but its key may be compromised and its actions must be analyzed bidirectionally (R6) — what it can do TO users, and what users can do to exploit/grief it.


Step 1: Inventory Role Permissions

In {TEMPLATES}, find every choice whose controller includes {ROLE_PARTY} (operator/admin/etc.), and every template where {ROLE_PARTY} is a signatory. For each:

  • Which (Template, field) does the choice's consequence create/archive (i.e. what state does it write)?
  • Does the choice exercise another template's choice (one-hop authority propagation)?
  • Parameters accepted from the caller (especially a caller-supplied ContractId or party)?
  • Consume-mode (consuming/nonconsuming/pre/postconsuming)?
Choice (Template.Choice)ControllerConsume-Mode(Template,field) WrittenExercises Other TemplatesCaller Params

Auth patterns: controller operator, controller issuer, operator (joint), signatory operator (operator co-signs every successor), choice that re-fetches a contract and branches on a field the operator controls.


Step 2: Analyze Within-Scope Abuse (Direction 1 — role harms users)

For each permitted action, ask:

Timing Abuse (ledger-time ordered, no public mempool):

  • Can the role exercise a choice at a harmful time (before a user's query-driven action, just before a deadline)?
  • Can the role DELAY a choice (skip a settlement/registration crank) to harm users?

Parameter Abuse:

  • Can the role pass a harmful value (inflated amount, wrong newOwner, attacker-controlled ContractId)?
  • Are caller parameters validated in the choice body (assertMsg, ensure on the successor), or trusted implicitly?
  • Can the role supply a forged config/whitelist ContractId the choice does not bind to a trusted issuer?

Sequence / Omission Abuse:

  • Can the role exercise choices out of order (accept before propose, settle before finalize)?
  • Can the role harm users by NOT exercising (never registering, never unlocking, never distributing)? Is there a recovery path if the role stops?

Step 3: Model Attack Scenarios

Scenario A: Authority-Timing Attack
1. {ROLE_PARTY} observes a user's pending action via on-chain ACS state
2. {ROLE_PARTY} submits role_choice() to land in a prior/same ledger
3. ACS changes before the user's transaction commits
4. Impact: {TIMING_IMPACT}
Note: no public mempool; ordering is ledger-time / submission based.

Scenario B: Parameter / Forged-CID Attack
1. {ROLE_PARTY} exercises {ROLE_CHOICE} with {MALICIOUS_PARAMS} (amount, recipient, or a lookalike ContractId)
2. Choice body does not validate against {EXPECTED_CONSTRAINTS} / does not bind the CID to the trusted issuer
3. Impact: {PARAM_IMPACT}

Scenario C: Key Compromise
1. {ROLE_PARTY}'s submission key is compromised
2. Attacker can exercise: {ROLE_CHOICES} and co-sign as signatory on: {SIGNATORY_TEMPLATES}
3. Maximum extractable / corruptible state: {MAX_DAMAGE}
4. Recovery: is there a choice to rotate/replace {ROLE_PARTY}? If the role is a hardcoded signatory, rotation may be impossible.

Step 4: Assess Mitigations

  • Is the role action gated by a propose/accept two-step (multi-transaction) flow rather than a single unilateral choice?
  • Is {ROLE_PARTY} a single party or a joint controller (AND of multiple parties, the DAML analog of multisig)?
  • Does a rotation/replacement choice EXIST? If the role is a signatory baked into live contracts, replacing it may require re-creating every contract. If NO rotation path → FINDING: authority irrevocable. Min Medium if the role can mutate user-held contracts.
  • Rate limits / caps tracked across transactions (accumulator template)?
  • If the role is also a maintainer of a key, note: maintainers MUST be signatories — compromise of the maintainer party affects key uniqueness too.

DAML patterns: Propose→Accept (OperatorProposal create + Accept choice), joint controller a, b, an Admin contract whose signatory is a governance party.


Step 5: Model User-Side Exploitation (Direction 2 — R6, MANDATORY)

Predictability Analysis:

  • Is the role's behavior predictable (a published schedule, a state-triggered crank, a queue)?
  • Can users observe via the ACS when the role will act?
  • Can users submit to land before the role in ledger order?
Scenario D: User Exploits Role Timing
1. User observes {ROLE_PARTY} exercises {ROLE_CHOICE} when {CONDITION} holds in the ACS
2. User submits a transaction to land before the role's
3. User benefits from the known impending state change. Impact: {USER_EXPLOIT_IMPACT}

Scenario E: User Griefs Role Preconditions
1. {ROLE_CHOICE} requires ACS state: {PRECONDITION} (a contract present, a key resolvable, an ensure satisfiable)
2. User archives/alters a contract the role's choice fetches, or creates a key-collision the role's lookupByKey trips on
3. Role's choice aborts (CONTRACT_NOT_FOUND / PreconditionFailed); protocol enters a degraded state. Impact: {GRIEF_IMPACT}

Scenario F: User Forces Suboptimal Role Action
1. User shapes ACS state so the honest role's policy chooses a harmful branch
2. Impact: {SUBOPTIMAL_IMPACT}

Scenario G: Stale State via Discrete Role Updates
1. A rate/config contract is only re-created when {ROLE_PARTY} exercises {UPDATE_CHOICE}
2. User acts at the stale rate, role updates, user exits. Impact: {RATE_ARBIT_IMPACT}

Show full SKILL.md (384 more words)Show less

Step 6: Precondition Griefability Check

For each choice controlled by {ROLE_PARTY}:

ChoicePreconditions (fetched contract / resolvable key / ensure)User Can Manipulate?Grief Impact

DAML griefing: Can a user archive a contract the role's choice fetches (CONTRACT_NOT_FOUND abort)? Can a user create a contract whose key collides / makes the role's lookupByKey return a stale or false-None result? Can a user inflate an accumulator/queue contract so the role's iterating choice aborts?


Step 6b: Privileged-Choice Griefability (EXHAUSTIVE)

Enumerate ALL authority-gated choices:

ChoiceAuthority (controller/signatory)PreconditionsUser Can Manipulate?Grief Impact

Completeness check: Total authority-gated choices: {N}, analyzed: {M}. If M < N → analyze the missing ones.

DAML-specific checks:

  • Can users create contracts that block a role's bulk cleanup/migration (one archive per contract → unbounded)?
  • Can in-flight Propose/Accept contracts block a role action (a pending proposal the role must resolve)?
  • Can a user archive a precondition contract just before the role's exercise, causing CONTRACT_NOT_FOUND?
  • Can an unsolicited contract created with the role as observer/signatory bloat the role's view or force consent?

Common False Positives

  • Pure read / nonconsuming view choices: no abuse vector
  • Idempotent choices: timing abuse limited
  • User-initiated dependency: role acts only after the user proposes first — front-running may not apply
  • Joint controller already present: a choice already controller a, b is not single-where-joint
  • Fully-trusted governance party: if the project's trust table marks the party FULLY_TRUSTED, apply the −1 trusted-actor tier modifier (do NOT apply it to semi-trusted operator/admin)

Finding Template

markdown
**ID**: [DML-STR-N]
**Verdict**: CONFIRMED / PARTIAL / REFUTED / CONTESTED
**Step Execution**: (see below)
**Rules Applied**: [R2:___, R6:___, R10:___, R13:___]
**Severity**: Critical/High/Medium/Low/Info
**Location**: {Module}.daml:LineN (template X, choice Y)
**Title**: {what the role party can do to users / what users can exploit or grief}
**Description**: {specific abuse vector with code reference — which controller/signatory, which unvalidated parameter}
**Impact**: {quantified damage at worst-state parameters — Rule 10}
**PoC steer**: `submit roleParty (exerciseCmd ...)` succeeds with harmful state (Direction 1), or user `submit`/archive griefs the role's precondition so its choice aborts (Direction 2); `submitMustFail` proves a guard holds.

Step Execution Checklist (MANDATORY)

StepRequiredCompleted?Notes
1. Inventory Role PermissionsYESController + signatory choices
2. Analyze Within-Scope AbuseYES
3. Model Attack Scenarios (A, B, C)YES
4. Assess MitigationsYESRotation/replacement choice exists?
5. Model User-Side Exploitation (D, E, F, G)YESMANDATORY (R6) — never skip
6. Precondition Griefability CheckYESMANDATORY — never skip
6b. Privileged-Choice GriefabilityYESMANDATORY — never skip
Cross-Reference Markers

After Step 4: DO NOT STOP HERE — Steps 5-6 analyze the reverse (R6) direction. After Step 5: Cross-reference with CHOICE_SEMANTICS for value-bearing role choices and CID_CAPABILITY_SAFETY for role choices accepting a caller-supplied ContractId. IF the role's actions are time-predictable → document ledger-ordering vectors. After Step 6: IF any precondition is user-griefable → severity >= MEDIUM. Document the protocol degradation timeline if the role is blocked indefinitely. After Step 6b: IF the role iterates over user-creatable contracts → check for unbounded iteration / abort.

Output Format for Step Execution
markdown
**Step Execution**: ✓1,2,3,4,5,6,6b | (no skips for this skill)

© PlamenTSV, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in agents/skills/daml/semi-trusted-roles of PlamenTSV/plamen.

Open the folder on GitHubat commit 795962b

Compare with similar skills

Semi Trusted Roles next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Semi Trusted Roles compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Semi Trusted Roles this skillPlamenTSV/plamen303—~2.7kAutomated safety check: PassMIT
Golang Patternsaffaan-m/ECC276k—~1.1kAutomated safety check: PassMIT
Kotlin Exposed Patternsaffaan-m/ECC276k4 repos~5.5kAutomated safety check: PassMIT
Dotnet Patternsaffaan-m/ECC276k1 repos~2.3kAutomated safety check: PassMIT
Fastapi Patternsaffaan-m/ECC276k—~2.3kAutomated safety check: PassMIT
Python Patternsaffaan-m/ECC276k—~2.3kAutomated safety check: PassMIT

Similar skills

  • Golang Patterns

    affaan-m/ECC

    Go-specific design patterns and best practices including functional options, small interfaces, dependency injection, concurrency patterns, error handling, and package organization.

    276k GitHub stars~1.1k tokensUpdated today
    DevelopmentAuto-check passed
  • JetBrains Exposed ORM patterns including DSL queries, DAO pattern, transactions, HikariCP connection pooling, Flyway migrations, and repository pattern.

    276k GitHub starsUsed in 4 repos~5.5k tokens
    DatabasesAuto-check passed
  • Dotnet Patterns

    affaan-m/ECC

    Idiomatic C and .NET patterns, conventions, dependency injection, async/await, and best practices for building robust, maintainable .NET applications.

    276k GitHub starsUsed in 1 repo~2.3k tokens
    DevelopmentAuto-check passed
  • Fastapi Patterns

    affaan-m/ECC

    FastAPI patterns for async APIs, dependency injection, Pydantic request and response models, OpenAPI docs, tests, security, and production readiness.

    276k GitHub stars~2.3k tokensUpdated today
    Backend & APIsAuto-check passed
  • Python Patterns

    affaan-m/ECC

    Python-specific design patterns and best practices including protocols, dataclasses, context managers, decorators, async/await, type hints, and package organization.

    276k GitHub stars~2.3k tokensUpdated today
    DevelopmentAuto-check passed
  • Admin

    yc-software/qm

    Act for an org admin — the admin API (scope directory, per-scope config & SOUL, any scope's memory, transcripts & captured prompts, files, user roster & external users, audit/errors/metrics/egress)…

    15k GitHub stars~3.1k tokensUpdated today
    Auto-check passed

More from PlamenTSV/plamen

All 87 skills in this repo
  • Audit Prep

    PlamenTSV/plamen

    Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project…

    303 GitHub stars~3.7k tokensUpdated 14 days ago
    Auto-check passed
  • Verification Protocol

    PlamenTSV/plamen

    Trigger Pattern Always (used by all verifier agents) - Inject Into security-verifier agents (Phase 5)

    303 GitHub stars~3.5k tokensUpdated 14 days ago
    Auto-check passed
  • Ability Analysis

    PlamenTSV/plamen

    Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth agents, depth agents

    303 GitHub stars~3.3k tokensUpdated 14 days ago
    Auto-check passed
  • Ability Analysis

    PlamenTSV/plamen

    Trigger Pattern Always (Sui Move) -- foundational security check - Inject Into Breadth agents, depth agents

    303 GitHub stars~3.2k tokensUpdated 14 days ago
    Auto-check passed
  • Account Lifecycle

    PlamenTSV/plamen

    Trigger Pattern ACCOUNTCLOSING flag detected (close/CloseAccount usage) - Inject Into Breadth agents, depth agents

    303 GitHub stars~1.2k tokensUpdated 14 days ago
    Auto-check passed
  • Account Validation

    PlamenTSV/plamen

    Trigger Pattern Always required for Solana audits - Inject Into Breadth agents, depth agents

    303 GitHub stars~1.7k tokensUpdated 14 days ago
    Auto-check passed

Questions about Semi Trusted Roles

What does Semi Trusted Roles do?

Trigger Pattern operator/admin/manager parties listed as signatory or controller, authority-gated choices - Inject Into Breadth agents, depth-state-trace. Semi Trusted Roles is an agent skill from PlamenTSV/plamen.

When should I use Semi Trusted Roles?

Semi Trusted Roles fits situations like: pattern operator/admin/manager parties listed as signatory; authority-gated choices - Inject Into Breadth agents; depth-state-trace.

How do I install Semi Trusted Roles in Claude Code?

Run `npx skills add PlamenTSV/plamen --skill semi-trusted-roles -a claude-code`. Or copy the skill folder (agents/skills/daml/semi-trusted-roles in PlamenTSV/plamen) into .claude/skills/semi-trusted-roles in your project. Claude Code loads it when a task matches its description.

How do I install Semi Trusted Roles in Codex?

Run `npx skills add PlamenTSV/plamen --skill semi-trusted-roles -a codex`. Or copy the skill folder (agents/skills/daml/semi-trusted-roles in PlamenTSV/plamen) into .agents/skills/semi-trusted-roles in your project. Codex loads it when a task matches its description.

Can I use Semi Trusted Roles in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PlamenTSV/plamen --skill semi-trusted-roles -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/semi-trusted-roles, .gemini/skills/semi-trusted-roles, .github/skills/semi-trusted-roles and .opencode/skills/semi-trusted-roles in your project.

What does Semi Trusted Roles need to run?

SKILL.md names no scripts, command-line tools or credentials: Semi Trusted Roles is instructions for the agent only.

Does Semi Trusted Roles access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Semi Trusted Roles safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Semi Trusted Roles use?

Semi Trusted Roles is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Semi Trusted Roles use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Semi Trusted Roles?

Skills that share tags, products or a category with Semi Trusted Roles: Golang Patterns (affaan-m/ECC, 276k stars), Kotlin Exposed Patterns (affaan-m/ECC, 276k stars), Dotnet Patterns (affaan-m/ECC, 276k stars) and Fastapi Patterns (affaan-m/ECC, 276k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Semi Trusted Roles?

PlamenTSV (a GitHub user) maintains it in PlamenTSV/plamen, which has 303 GitHub stars. The repository holds 87 skills in this directory. The repository was last updated on September 26, 2026.

Source: PlamenTSV/plamen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.