Agent skill

Semi Trusted Roles

by PlamenTSV in PlamenTSV/plamen

Trigger Pattern operator/keeper/crank requireauth checks, authority-gated functions - Inject Into Breadth agents, depth-state-trace

MITAuto-check passedSecurity

Install Semi Trusted Roles

skills CLI
$ npx skills add PlamenTSV/plamen --skill semi-trusted-roles -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install PlamenTSV/plamen semi-trusted-roles --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agents/skills/soroban/semi-trusted-roles .claude/skills/semi-trusted-roles && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
semi-trusted-roles
GitHub stars
303
Token cost
~2.1k tokens
SKILL.md length
640 words
Files
1
Skills in repo
87
Repo updated
First seen
Licence
MIT

At a glance

Trigger Pattern operator/keeper/crank requireauth checks, authority-gated functions - Inject Into Breadth agents, depth-state-trace

  • Works in 6 steps: Inventory Role Permissions → Analyze Within-Scope Abuse → Model Attack Scenarios → …
  • Pattern operator/keeper/crank requireauth checks
  • SKILL.md covers Step 1: Inventory Role…, Step 2: Analyze Within-Scope…, Step 3: Model Attack Scenarios and Step 4: Assess Mitigations, plus 6 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Semi Trusted Roles is an agent skill from PlamenTSV/plamen. Trigger Pattern operator/keeper/crank requireauth checks, authority-gated functions - Inject Into Breadth agents, depth-state-trace

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Smart contract auditing. It works with Stellar. The repository describes itself as: Autonomous Web3 security audit agent for Claude Code. The licence is MIT.

When your agent uses it

  • Pattern operator/keeper/crank requireauth checks
  • Authority-gated functions - Inject Into Breadth agents
  • Depth-state-trace

Example prompts

  • “/semi-trusted-roles”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Inventory Role Permissions
  2. Analyze Within-Scope Abuse
  3. Model Attack Scenarios
  4. Assess Mitigations
  5. Model User-Side Exploitation (Direction 2 — MANDATORY)
  6. Precondition Griefability Check

What it can do on your machine

Read from SKILL.md and the folder at commit 795962b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Semi Trusted Roles loads about 2.1k tokens when it runs. Until then it costs about 38 tokens; SKILL.md has 640 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~38
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from PlamenTSV/plamen at commit 795962b, republished under its MIT licence (© PlamenTSV). 640 words, ~2,077 tokens.

Download SKILL.mdSave it as .claude/skills/semi-trusted-roles/SKILL.md (or your agent's skills folder).
name
semi-trusted-roles
description
Trigger Pattern operator/keeper/crank require_auth checks, authority-gated functions - Inject Into Breadth agents, depth-state-trace

SEMI_TRUSTED_ROLES Skill (Soroban)

Trigger Pattern: operator/keeper/crank require_auth checks, authority-gated functions, admin actions beyond pure parameter-setting Inject Into: Breadth agents, depth-state-trace Finding prefix: [STR-N] Rules referenced: R2, R6, R10, R13

operator|keeper|crank|authority|admin|require_auth|guardian|relayer|updater|manager

Soroban role context: No role-based modifiers. Access control is custom: stored Address from Instance/Persistent storage + .require_auth(). Address is opaque — may be keypair, Stellar multisig, or contract.


Step 1: Inventory Role Permissions

In {CONTRACTS}, find all functions callable by {ROLE_NAME}. For each at {ROLE_FUNCTIONS}:

  • Storage keys read/written (Instance/Persistent/Temporary)?
  • Cross-contract calls (invoke_contract / TokenClient)?
  • Parameters accepted from caller?
  • Auth validation method? (stored Address + require_auth() vs inline vs direct check)
FunctionAuth CheckStorage MutationsCross-Contract CallsParameters

Auth patterns: stored Address + require_auth(), e.current_contract_address().require_auth() (sub-invocation), NO auth on privileged state mutation (missing auth bug).


Step 2: Analyze Within-Scope Abuse

For each permitted action, ask:

Timing Abuse (~5s ledger close, no mempool):

  • Execute at harmful times? (front-running limited to validator/fee-bump ordering)
  • Delay execution to harm users? (skip oracle updates, withhold cranks)
  • Maximum harm window?

Parameter Abuse:

  • Pass harmful values? (inflated amounts, wrong recipient, max slippage)
  • Parameters validated on-chain or accepted implicitly?
  • Supply attacker-controlled contract address?

Sequence Abuse:

  • Execute functions out of order? (claim before distribute, settle before finalize)
  • Skip required functions? (skip epoch advancement, skip price update)

Omission Abuse:

  • Harm users by NOT executing? (skip reward distribution, delay settlement)
  • Protocol degradation timeline if role stops?

Step 3: Model Attack Scenarios

Scenario A: Timing Attack (Transaction Ordering)
1. {ROLE_NAME} observes pending user transaction
2. {ROLE_NAME} submits role_function() in same or prior ledger
3. State changes before user transaction executes
4. Impact: {TIMING_IMPACT}
Note: No public mempool. Requires role to be validator or fee-bumper.

Scenario B: Parameter Attack
1. {ROLE_NAME} calls {ROLE_FUNCTION} with {MALICIOUS_PARAMS}
2. Parameters not validated against {EXPECTED_CONSTRAINTS}
3. Impact: {PARAM_IMPACT}

Scenario C: Key Compromise
1. {ROLE_NAME} Address keypair compromised (or: Address is a contract that gets compromised)
2. Attacker can call: {ROLE_FUNCTIONS}
3. Maximum extractable value: {MAX_DAMAGE}
4. Recovery: {RECOVERY_PATH} — rotation function exists? If Address is upgradeable contract, who holds upgrade key?

Step 4: Assess Mitigations

  • Timelock on {ROLE_NAME} actions? (multi-ledger proposal+execute)
  • {ROLE_NAME} a Stellar multisig (M-of-N) or governance contract?
  • Does a rotation/removal function EXIST? If NO → FINDING: authority irrevocable. Min Medium if role modifies user state.
  • Can admin rotate authority quickly for compromise response?
  • Rate limits (per-ledger caps, cooldowns)?
  • If immutable (no update_current_contract_wasm): can compromised role be replaced?

Soroban patterns: Two-step transfer (propose_new_admin + accept_admin), multisig Address. Role in Instance/Persistent storage takes effect immediately (no built-in delay).


Step 5: Model User-Side Exploitation (Direction 2 — MANDATORY)

Predictability Analysis:

  • Is the role's behavior predictable? (schedule, price triggers, queue length)
  • Can users observe when the role will act? (on-chain state)
  • Can users front-run/back-run via higher-fee transactions?
Scenario D: User Exploits Role Timing
1. User observes {ROLE_NAME} executes {ROLE_FUNCTION} when {CONDITION} met
2. User submits higher-fee tx to land before role in same ledger
3. User benefits from known state change. Impact: {USER_EXPLOIT_IMPACT}

Scenario E: User Griefs Role Preconditions
1. {ROLE_FUNCTION} requires state: {PRECONDITION}
2. User manipulates state to violate {PRECONDITION}
3. Role tx panics; protocol enters degraded state. Impact: {GRIEF_IMPACT}

Scenario F: User Forces Suboptimal Role Action
1. User manipulates on-chain state to make worst option appear best
2. {ROLE_NAME} (honest policy) chooses suboptimal path. Impact: {SUBOPTIMAL_IMPACT}

Scenario G: Stale Rate via Discrete Updates
1. Exchange rate only updates when {ROLE_NAME} calls {UPDATE_FUNCTION}
2. User enters at stale rate, role updates, user exits. Impact: {RATE_ARBIT_IMPACT}

Step 6: Precondition Griefability Check

For each function callable by {ROLE_NAME}:

FunctionPreconditionsUser Can Manipulate?Grief Impact

Soroban griefing: Persistent storage record proliferation exceeding resource budget during role iteration? TTL expiry on user entries causing unwrap() panics in role functions?


Show full SKILL.md (264 more words)Show less

Step 6b: Admin/Privileged Function Griefability (EXHAUSTIVE)

Enumerate ALL authority-gated functions:

FunctionAuthority TypePreconditionsUser Can Manipulate?Grief Impact

Completeness check: Total authority-gated: {N}, analyzed: {M}. If M < N → analyze missing.

Soroban-specific checks:

  • Can users create Persistent entries that block admin cleanup/migration? (N entries = N resource units)
  • Can in-flight multi-ledger operations (pending withdrawal, partial unstake) block admin actions?
  • Can users revoke allowances just before contract transfer_from, causing admin crank to fail?
  • Can unsolicited token transfer to contract bloat tracked balance beyond admin's expected range?

Common False Positives

  • Read-only functions: no abuse vector
  • Idempotent functions: timing abuse limited
  • User-initiated dependency: role requires user to initiate first — front-running may not apply
  • Economic alignment: staked collateral / fee-funded role has cost for malicious action
  • Immutable address: hardcoded Address — rotation N/A, but compromise risk permanent

Finding Template

markdown
**ID**: [STR-N]
**Severity**: Critical/High/Medium/Low/Info
**Step Execution**: (see below)
**Rules Applied**: [R2:___, R6:___, R10:___, R13:___]
**Location**: src/{file}.rs:LineN
**Title**: {what role can do / what user can exploit}
**Description**: {specific abuse vector with code reference}
**Impact**: {quantified damage at worst-state parameters}

Step Execution Checklist (MANDATORY)

StepRequiredCompleted?Notes
1. Inventory Role PermissionsYES
2. Analyze Within-Scope AbuseYES
3. Model Attack Scenarios (A, B, C)YES
4. Assess MitigationsYES
5. Model User-Side Exploitation (D, E, F, G)YESMANDATORY — never skip
6. Precondition Griefability CheckYESMANDATORY — never skip
6b. Admin Instruction GriefabilityYESMANDATORY — never skip
Cross-Reference Markers

After Step 4: DO NOT STOP HERE — Steps 5-6 analyze the reverse direction. After Step 5: Cross-reference with TOKEN_FLOW_TRACING for token-related griefing vectors. IF role actions are time-predictable → document ledger-ordering (fee-bump) vectors. After Step 6: IF any precondition is user-griefable → severity >= MEDIUM. Document protocol degradation timeline if role is blocked indefinitely. After Step 6b: IF admin iterates over user-created Persistent entries → check for unbounded iteration / resource exhaustion.

Output Format for Step Execution
markdown
**Step Execution**: check1,2,3,4,5,6,6b | (no skips for this skill)

© PlamenTSV, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in agents/skills/soroban/semi-trusted-roles of PlamenTSV/plamen.

Open the folder on GitHubat commit 795962b

Compare with similar skills

Semi Trusted Roles next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Semi Trusted Roles compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Semi Trusted Roles this skillPlamenTSV/plamen303—~2.1kAutomated safety check: PassMIT
Soroban Contract Auditsickn33/agentic-awesome-skills47k1 repos~1.4kAutomated safety check: PassMIT
Soroban Liquidity Poolsickn33/agentic-awesome-skills47k1 repos~1.3kAutomated safety check: PassMIT
Soroban Storage Ttl Lifecyclesickn33/agentic-awesome-skills47k1 repos~1.3kAutomated safety check: PassMIT
Soroban Token Mintersickn33/agentic-awesome-skills47k1 repos~1.3kAutomated safety check: PassMIT
Stellar DevVelaPayments/vela-payments131—~1.8kAutomated safety check: PassMIT

Similar skills

  • Soroban Contract Audit

    sickn33/agentic-awesome-skills

    Soroban smart contract security audit register: authorization checks, panic pathways, integer overflows, and storage footprint verification for Stellar.

    47k GitHub starsUsed in 1 repo~1.4k tokens
    SecurityAuto-check passed
  • Soroban Liquidity Pool

    sickn33/agentic-awesome-skills

    Automated market maker liquidity pool register: constant-product invariant curves, swap fee tiers, and LP token shares for Soroban DeFi.

    47k GitHub starsUsed in 1 repo~1.3k tokens
    SecurityAuto-check passed
  • Soroban Storage Ttl Lifecycle

    sickn33/agentic-awesome-skills

    Soroban ledger state rent and TTL extension register: live state tracking, bump thresholds, rent fee reserves, and archive boundaries.

    47k GitHub starsUsed in 1 repo~1.3k tokens
    SecurityAuto-check passed
  • Soroban Token Minter

    sickn33/agentic-awesome-skills

    Soroban SEP-41 token contract architecture register: admin control, supply caps, metadata standard, and transfer event emissions on Stellar.

    47k GitHub starsUsed in 1 repo~1.3k tokens
    SecurityAuto-check passed
  • Stellar Dev

    VelaPayments/vela-payments

    End-to-end Stellar development playbook. An agent skill from VelaPayments/vela-payments.

    131 GitHub stars~1.8k tokensUpdated 4 days ago
    Backend & APIsAuto-check passed
  • Stellar iOS Mac SDK

    Soneso/stellar-ios-mac-sdk

    Guides Stellar blockchain development in Swift using stellar-ios-mac-sdk.

    132 GitHub stars~4.3k tokensUpdated yesterday
    Backend & APIsAuto-check passed

More from PlamenTSV/plamen

All 87 skills in this repo
  • Audit Prep

    PlamenTSV/plamen

    Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project…

    303 GitHub stars~3.7k tokensUpdated 14 days ago
    Auto-check passed
  • Verification Protocol

    PlamenTSV/plamen

    Trigger Pattern Always (used by all verifier agents) - Inject Into security-verifier agents (Phase 5)

    303 GitHub stars~3.5k tokensUpdated 14 days ago
    Auto-check passed
  • Ability Analysis

    PlamenTSV/plamen

    Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth agents, depth agents

    303 GitHub stars~3.3k tokensUpdated 14 days ago
    Auto-check passed
  • Ability Analysis

    PlamenTSV/plamen

    Trigger Pattern Always (Sui Move) -- foundational security check - Inject Into Breadth agents, depth agents

    303 GitHub stars~3.2k tokensUpdated 14 days ago
    Auto-check passed
  • Account Lifecycle

    PlamenTSV/plamen

    Trigger Pattern ACCOUNTCLOSING flag detected (close/CloseAccount usage) - Inject Into Breadth agents, depth agents

    303 GitHub stars~1.2k tokensUpdated 14 days ago
    Auto-check passed
  • Account Validation

    PlamenTSV/plamen

    Trigger Pattern Always required for Solana audits - Inject Into Breadth agents, depth agents

    303 GitHub stars~1.7k tokensUpdated 14 days ago
    Auto-check passed

Works with

Categories

Questions about Semi Trusted Roles

What does Semi Trusted Roles do?

Trigger Pattern operator/keeper/crank requireauth checks, authority-gated functions - Inject Into Breadth agents, depth-state-trace. Semi Trusted Roles is an agent skill from PlamenTSV/plamen.

When should I use Semi Trusted Roles?

Semi Trusted Roles fits situations like: pattern operator/keeper/crank requireauth checks; authority-gated functions - Inject Into Breadth agents; depth-state-trace.

How do I install Semi Trusted Roles in Claude Code?

Run `npx skills add PlamenTSV/plamen --skill semi-trusted-roles -a claude-code`. Or copy the skill folder (agents/skills/soroban/semi-trusted-roles in PlamenTSV/plamen) into .claude/skills/semi-trusted-roles in your project. Claude Code loads it when a task matches its description.

How do I install Semi Trusted Roles in Codex?

Run `npx skills add PlamenTSV/plamen --skill semi-trusted-roles -a codex`. Or copy the skill folder (agents/skills/soroban/semi-trusted-roles in PlamenTSV/plamen) into .agents/skills/semi-trusted-roles in your project. Codex loads it when a task matches its description.

Can I use Semi Trusted Roles in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PlamenTSV/plamen --skill semi-trusted-roles -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/semi-trusted-roles, .gemini/skills/semi-trusted-roles, .github/skills/semi-trusted-roles and .opencode/skills/semi-trusted-roles in your project.

What does Semi Trusted Roles need to run?

SKILL.md names no scripts, command-line tools or credentials: Semi Trusted Roles is instructions for the agent only.

Does Semi Trusted Roles access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Semi Trusted Roles safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Semi Trusted Roles use?

Semi Trusted Roles is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Semi Trusted Roles use?

About 2.1k tokens (SKILL.md is roughly 8.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Semi Trusted Roles?

Skills that share tags, products or a category with Semi Trusted Roles: Soroban Contract Audit (sickn33/agentic-awesome-skills, 47k stars), Soroban Liquidity Pool (sickn33/agentic-awesome-skills, 47k stars), Soroban Storage Ttl Lifecycle (sickn33/agentic-awesome-skills, 47k stars) and Soroban Token Minter (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Semi Trusted Roles?

PlamenTSV (a GitHub user) maintains it in PlamenTSV/plamen, which has 303 GitHub stars. The repository holds 87 skills in this directory. The repository was last updated on September 26, 2026.

Source: PlamenTSV/plamen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.