Agent skill

Semi Trusted Roles

by PlamenTSV in PlamenTSV/plamen

Trigger Pattern Crank/bot/operator signer checks, authority-gated instructions - Inject Into Breadth agents, depth-state-trace

MITAuto-check passed

Install Semi Trusted Roles

skills CLI
$ npx skills add PlamenTSV/plamen --skill semi-trusted-roles -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install PlamenTSV/plamen semi-trusted-roles --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agents/skills/solana/semi-trusted-roles .claude/skills/semi-trusted-roles && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
semi-trusted-roles
GitHub stars
303
Token cost
~2.3k tokens
SKILL.md length
746 words
Files
1
Skills in repo
87
Repo updated
First seen
Licence
MIT

At a glance

Trigger Pattern Crank/bot/operator signer checks, authority-gated instructions - Inject Into Breadth agents, depth-state-trace

  • Works in 6 steps: Inventory Role Permissions → Analyze Within-Scope Abuse → Model Attack Scenarios → …
  • Pattern Crank/bot/operator signer checks
  • SKILL.md covers Reasoning Template, Common False Positives, Finding Template and Step Execution Checklist…
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Semi Trusted Roles is an agent skill from PlamenTSV/plamen. Trigger Pattern Crank/bot/operator signer checks, authority-gated instructions - Inject Into Breadth agents, depth-state-trace

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with Solana. The repository describes itself as: Autonomous Web3 security audit agent for Claude Code. The licence is MIT.

When your agent uses it

  • Pattern Crank/bot/operator signer checks
  • Authority-gated instructions - Inject Into Breadth agents
  • Depth-state-trace

Example prompts

  • “/semi-trusted-roles”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Inventory Role Permissions
  2. Analyze Within-Scope Abuse
  3. Model Attack Scenarios
  4. Assess Mitigations
  5. Model User-Side Exploitation (Direction 2 - MANDATORY)
  6. Precondition Griefability Check

What it can do on your machine

Read from SKILL.md and the folder at commit 795962b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Semi Trusted Roles loads about 2.3k tokens when it runs. Until then it costs about 36 tokens; SKILL.md has 746 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~36
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from PlamenTSV/plamen at commit 795962b, republished under its MIT licence (© PlamenTSV). 746 words, ~2,286 tokens.

Download SKILL.mdSave it as .claude/skills/semi-trusted-roles/SKILL.md (or your agent's skills folder).
name
semi-trusted-roles
description
Trigger Pattern Crank/bot/operator signer checks, authority-gated instructions - Inject Into Breadth agents, depth-state-trace

Skill: Semi-Trusted Role Analysis (Solana)

Trigger Pattern: Crank/bot/operator signer checks, authority-gated instructions Inject Into: Breadth agents, depth-state-trace Finding prefix: [STR-N] Rules referenced: S1, S3, S9, R2, R6, R10, R13

crank|bot|operator|keeper|authority|admin|has_one\s*=\s*authority|
constraint\s*=\s*.*signer|role|guardian|relayer

Reasoning Template

Step 1: Inventory Role Permissions
  • In {CONTRACTS}, find all instructions callable by {ROLE_NAME}
  • For each instruction at {ROLE_FUNCTIONS}:
    • What accounts does it modify (mutable accounts)?
    • What CPI calls does it make?
    • What instruction data parameters does it accept?
    • Is the signer validated via has_one, Signer type, or custom constraint?
InstructionSigner CheckMutable AccountsCPI CallsParameters
Step 2: Analyze Within-Scope Abuse

For each permitted action, ask:

Timing Abuse (400ms slots):

  • Can {ROLE_NAME} execute at harmful times? (front-run users via MEV bundles or priority fee ordering, during epoch transitions)
  • Can {ROLE_NAME} delay execution to harm users? (skip slots, withhold cranking)
  • With 400ms slot times, timing windows are ~30x tighter than EVM - but MEV bundles enable precise ordering

Parameter Abuse:

  • Can {ROLE_NAME} pass harmful instruction data? (max slippage, wrong recipient pubkey, inflated amounts)
  • Are instruction parameters validated via Anchor constraints, or trusted implicitly?
  • Can {ROLE_NAME} supply attacker-controlled accounts in remaining_accounts?

Sequence Abuse:

  • Can {ROLE_NAME} execute instructions out of order? (claim before distribute, settle before finalize)
  • Can {ROLE_NAME} skip required instructions? (skip epoch advancement, skip oracle update)

Omission Abuse:

  • Can {ROLE_NAME} harm users by NOT cranking? (skip reward distribution, delay settlement)
  • What is the protocol degradation timeline if crank stops? (1 slot? 1 epoch? indefinite?)
Step 3: Model Attack Scenarios
Scenario A: Timing Attack (MEV Bundle)
1. {ROLE_NAME} monitors pending transactions in mempool
2. {ROLE_NAME} creates MEV bundle: [role_instruction, user_instruction]
3. Role instruction executes first within same slot, changing state
4. User instruction executes with worse conditions
5. Impact: {TIMING_IMPACT}

Scenario B: Parameter Attack
1. {ROLE_NAME} calls {ROLE_INSTRUCTION} with {MALICIOUS_PARAMS}
2. Instruction data is not validated against {EXPECTED_CONSTRAINTS}
3. Impact: {PARAM_IMPACT}

Scenario C: Key Compromise
1. {ROLE_NAME} keypair is compromised
2. Attacker can call: {ROLE_FUNCTIONS}
3. Maximum extractable value: {MAX_DAMAGE}
4. Recovery: {RECOVERY_PATH} - can authority be rotated? Timelock?
Step 4: Assess Mitigations
  • Is there a timelock on {ROLE_NAME} actions? (multi-instruction sequence with delay)
  • Is {ROLE_NAME} a multisig (Squads, Snowflake)?
  • Does a removal/rotation function for {ROLE_NAME} EXIST? If NO -> FINDING: authority is irrevocable without program upgrade. Severity: minimum Medium if role can modify user-facing state.
  • Can admin rotate {ROLE_NAME} authority quickly?
  • Are there rate limits, cooldowns, or per-slot caps?
  • Is the program immutable (upgrade authority revoked)? If so, can a compromised role be replaced at all?
Step 5: Model User-Side Exploitation (Direction 2 - MANDATORY)

Predictability Analysis:

  • Is the crank's behavior predictable? (epoch boundaries, price movements, queue-processing cadence)
  • Can users observe when the crank will act? (monitoring on-chain state, slot timing)
  • Can users front-run or back-run the crank via MEV bundles or priority fees?

Scenario D: User Exploits Crank Timing

1. User observes that {ROLE_NAME} executes {ROLE_INSTRUCTION} at predictable times
2. User submits transaction with high priority fee to land BEFORE crank in same slot
3. {ROLE_INSTRUCTION} executes, changing state (e.g., reward distribution, rate update)
4. User benefits from known state change
5. Impact: {USER_EXPLOIT_IMPACT}

Scenario E: User Griefs Crank Preconditions

1. {ROLE_INSTRUCTION} requires account state: {PRECONDITION}
2. User manipulates account state to violate {PRECONDITION}
3. {ROLE_NAME} sends transaction, instruction fails
4. Protocol enters degraded state (no crank actions possible)
5. Impact: {GRIEF_IMPACT}

Scenario F: User Forces Suboptimal Crank Action

1. {ROLE_NAME} must choose between options based on on-chain state
2. User manipulates state (deposits/withdrawals) to make worst option appear best
3. {ROLE_NAME} (following honest behavior) chooses suboptimal path
4. User profits from forced suboptimal execution
5. Impact: {SUBOPTIMAL_IMPACT}

Scenario G: Same-Chain Rate Staleness via Discrete Updates

1. Protocol's exchange rate only updates when {ROLE_NAME} cranks (discrete updates)
2. Between crank calls, rate is stale (does not reflect accumulated value)
3. User monitors for {ROLE_NAME} pending transaction
4. User enters at stale rate (favorable), crank executes, rate updates
5. User exits at updated rate (or holds appreciating position)
6. Impact: {RATE_ARBIT_IMPACT}
Step 6: Precondition Griefability Check

For each instruction callable by {ROLE_NAME}:

InstructionPreconditionsUser Can Manipulate?Grief Impact
{ix}account balance > 0YES - withdraw allCrank stuck
{ix}Clock timestamp > last_crank + intervalNO - time-basedN/A
{ix}threshold metYES - partial withdrawDelayed execution

CU budget griefing: Can a user submit CU-heavy transactions to fill the leader's block and delay crank execution? Priority fee escalation can push crank costs above economic viability.

Show full SKILL.md (285 more words)Show less
Step 6b: Admin/Privileged Instruction Griefability (EXHAUSTIVE)

Enumerate ALL authority-gated instructions across the program:

InstructionAuthority TypePreconditionsUser Can Manipulate?Grief Impact
{admin_ix}{owner/admin/operator}{preconditions}YES/NO{impact}

Enumeration completeness check:

  • Total authority-gated instructions in program: {N}
  • Instructions analyzed in this table: {M}
  • If M < N -> INCOMPLETE - analyze missing instructions before proceeding

Solana-specific checks:

  • Can users create PDA accounts that block admin operations? (unexpected PDA state preventing closure/migration)
  • Can users create token accounts owned by the protocol PDA that block operations? (non-zero balances preventing account closure)
  • Can users initiate multi-instruction operations (partial unstake, pending withdrawal) whose in-flight state blocks admin actions?
  • Can a user create so many accounts that iterating over them exceeds CU limits for admin instructions?

Common False Positives

  • View-only / read instructions: If role only reads state, no abuse vector
  • Idempotent instructions: If calling twice has same effect as once, timing abuse is limited
  • User-initiated dependency: If role action requires user to initiate first, front-running may not apply
  • Economic alignment: If crank is economically aligned (staked collateral, tip-funded), malicious action has cost

Finding Template

markdown
**ID**: [STR-N]
**Severity**: Critical/High/Medium/Low/Info
**Step Execution**: (see below)
**Rules Applied**: [S1:___, S3:___, S9:___, R2:___, R6:___, R10:___, R13:___]
**Location**: programs/{program}/src/instructions/{file}.rs:LineN
**Title**: {what role can do / what user can exploit}
**Description**: {specific abuse vector with code reference}
**Impact**: {quantified damage at worst-state parameters}

Step Execution Checklist (MANDATORY)

StepRequiredCompleted?Notes
1. Inventory Role PermissionsYES
2. Analyze Within-Scope AbuseYES
3. Model Attack Scenarios (A,B,C)YES
4. Assess MitigationsYES
5. Model User-Side Exploitation (D,E,F,G)YESMANDATORY -- never skip
6. Precondition Griefability CheckYESMANDATORY -- never skip
6b. Admin Instruction GriefabilityYESMANDATORY -- never skip
Cross-Reference Markers

After Step 4: DO NOT STOP HERE -- Steps 5-6 analyze the reverse direction. After Step 5: Cross-reference with TOKEN_FLOW_TRACING for token-related griefing vectors. IF crank actions are predictable -> document Jito MEV vectors. After Step 6: IF any precondition is user-griefable -> severity >= MEDIUM. Document protocol degradation timeline if crank is blocked.

Output Format for Step Execution
markdown
**Step Execution**: check1,2,3,4,5,6,6b | (no skips for this skill)

© PlamenTSV, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in agents/skills/solana/semi-trusted-roles of PlamenTSV/plamen.

Open the folder on GitHubat commit 795962b

Compare with similar skills

Semi Trusted Roles next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Semi Trusted Roles compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Semi Trusted Roles this skillPlamenTSV/plamen303—~2.3kAutomated safety check: PassMIT
Solana Devsolana-foundation/solana-dev-skill573—~3.8kAutomated safety check: PassMIT
Meme Coin Security Auditawarexone/Agentic-Bug-Hunter5.3k1 repos~2.4kAutomated safety check: PassMIT
Swapper Depositswapperfinance/swapper-toolkit852—~1.8kAutomated safety check: PassMIT
PNP Prediction Markets on Solanainternet-court/internet-court-skill6.6k—~7.5kAutomated safety check: NotesMIT
Minara Crypto Trading and WalletMinara-AI/minara-skills362—~5.7kAutomated safety check: PassNone

Similar skills

  • Solana Dev

    solana-foundation/solana-dev-skill

    A skill your agent uses when user asks to "build a Solana dapp", "write an Anchor program", "create a token", "debug Solana errors", "set up wallet connection", "test my Solana program", "fuzz my…

    573 GitHub stars~3.8k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Meme Coin Security Audit

    awarexone/Agentic-Bug-Hunter

    Screens EVM and Solana meme coins for rug pull signs such as hidden mint, honeypot logic and fee tricks, starting with fast kill signals before any code review.

    5.3k GitHub starsUsed in 1 repo~2.4k tokens
    SecurityAuto-check passed
  • Swapper Deposit

    swapperfinance/swapper-toolkit

    Deposit and bridge funds into a wallet or protocol using Swapper Finance.

    852 GitHub stars~1.8k tokensUpdated 6 mo ago
    Business, Finance & HRAuto-check passed
  • PNP Prediction Markets on Solana

    internet-court/internet-court-skill

    Creates, trades and settles permissionless prediction markets on Solana with any SPL token as collateral, including social-media and custom-oracle markets.

    6.6k GitHub stars~7.5k tokensUpdated 1 mo ago
    Business, Finance & HRAuto-check: notes
  • Minara Crypto Trading and Wallet

    Minara-AI/minara-skills

    Drives the Minara CLI for crypto swaps, perps, limit orders, wallet transfers, deposits and withdrawals, plus AI market analysis.

    362 GitHub stars~5.7k tokensUpdated 24 days ago
    Business, Finance & HRAuto-check passed
  • Manifest

    Bonasa-Tech/manifest

    A skill your agent uses when building, debugging, or integrating with the Manifest DEX on Solana, especially for TypeScript SDK usage, transaction construction with ManifestClient, market state…

    158 GitHub stars~478 tokensUpdated yesterday
    DevelopmentAuto-check passed

More from PlamenTSV/plamen

All 87 skills in this repo
  • Audit Prep

    PlamenTSV/plamen

    Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project…

    303 GitHub stars~3.7k tokensUpdated 14 days ago
    Auto-check passed
  • Verification Protocol

    PlamenTSV/plamen

    Trigger Pattern Always (used by all verifier agents) - Inject Into security-verifier agents (Phase 5)

    303 GitHub stars~3.5k tokensUpdated 14 days ago
    Auto-check passed
  • Ability Analysis

    PlamenTSV/plamen

    Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth agents, depth agents

    303 GitHub stars~3.3k tokensUpdated 14 days ago
    Auto-check passed
  • Ability Analysis

    PlamenTSV/plamen

    Trigger Pattern Always (Sui Move) -- foundational security check - Inject Into Breadth agents, depth agents

    303 GitHub stars~3.2k tokensUpdated 14 days ago
    Auto-check passed
  • Account Lifecycle

    PlamenTSV/plamen

    Trigger Pattern ACCOUNTCLOSING flag detected (close/CloseAccount usage) - Inject Into Breadth agents, depth agents

    303 GitHub stars~1.2k tokensUpdated 14 days ago
    Auto-check passed
  • Account Validation

    PlamenTSV/plamen

    Trigger Pattern Always required for Solana audits - Inject Into Breadth agents, depth agents

    303 GitHub stars~1.7k tokensUpdated 14 days ago
    Auto-check passed

Works with

Questions about Semi Trusted Roles

What does Semi Trusted Roles do?

Trigger Pattern Crank/bot/operator signer checks, authority-gated instructions - Inject Into Breadth agents, depth-state-trace. Semi Trusted Roles is an agent skill from PlamenTSV/plamen.

When should I use Semi Trusted Roles?

Semi Trusted Roles fits situations like: pattern Crank/bot/operator signer checks; authority-gated instructions - Inject Into Breadth agents; depth-state-trace.

How do I install Semi Trusted Roles in Claude Code?

Run `npx skills add PlamenTSV/plamen --skill semi-trusted-roles -a claude-code`. Or copy the skill folder (agents/skills/solana/semi-trusted-roles in PlamenTSV/plamen) into .claude/skills/semi-trusted-roles in your project. Claude Code loads it when a task matches its description.

How do I install Semi Trusted Roles in Codex?

Run `npx skills add PlamenTSV/plamen --skill semi-trusted-roles -a codex`. Or copy the skill folder (agents/skills/solana/semi-trusted-roles in PlamenTSV/plamen) into .agents/skills/semi-trusted-roles in your project. Codex loads it when a task matches its description.

Can I use Semi Trusted Roles in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PlamenTSV/plamen --skill semi-trusted-roles -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/semi-trusted-roles, .gemini/skills/semi-trusted-roles, .github/skills/semi-trusted-roles and .opencode/skills/semi-trusted-roles in your project.

What does Semi Trusted Roles need to run?

SKILL.md names no scripts, command-line tools or credentials: Semi Trusted Roles is instructions for the agent only.

Does Semi Trusted Roles access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Semi Trusted Roles safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Semi Trusted Roles use?

Semi Trusted Roles is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Semi Trusted Roles use?

About 2.3k tokens (SKILL.md is roughly 9.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Semi Trusted Roles?

Skills that share tags, products or a category with Semi Trusted Roles: Solana Dev (solana-foundation/solana-dev-skill, 573 stars), Meme Coin Security Audit (awarexone/Agentic-Bug-Hunter, 5.3k stars), Swapper Deposit (swapperfinance/swapper-toolkit, 852 stars) and PNP Prediction Markets on Solana (internet-court/internet-court-skill, 6.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Semi Trusted Roles?

PlamenTSV (a GitHub user) maintains it in PlamenTSV/plamen, which has 303 GitHub stars. The repository holds 87 skills in this directory. The repository was last updated on September 26, 2026.

Source: PlamenTSV/plamen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.