Agent skill

Sep41 Token Safety

by PlamenTSV in PlamenTSV/plamen

Trigger Pattern SEP-41 token patterns detected (approve/transfer/transferfrom/allowance/balance) - Inject Into Breadth agents, depth-token-flow, depth-edge-case

MITAuto-check passedSecurity

Install Sep41 Token Safety

skills CLI
$ npx skills add PlamenTSV/plamen --skill sep41-token-safety -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install PlamenTSV/plamen sep41-token-safety --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agents/skills/soroban/sep41-token-safety .claude/skills/sep41-token-safety && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sep41-token-safety
GitHub stars
303
Token cost
~2.5k tokens
SKILL.md length
1,045 words
Files
1
Skills in repo
87
Repo updated
First seen
Licence
MIT

At a glance

Trigger Pattern SEP-41 token patterns detected (approve/transfer/transferfrom/allowance/balance) - Inject Into Breadth agents, depth-token-flow, depth-edge-case

  • Works in 6 steps: Approve Race Condition → Allowance Expiry → Transfer Auth Propagation → …
  • Pattern SEP-41 token patterns detected (approve/transfer/transferfrom/allowance/balance) - Inject Into Breadth agents
  • SKILL.md covers 1. Approve Race Condition, 2. Allowance Expiry, 3. Transfer Auth Propagation and 4. SAC Interaction, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Sep41 Token Safety is an agent skill from PlamenTSV/plamen. Trigger Pattern SEP-41 token patterns detected (approve/transfer/transferfrom/allowance/balance) - Inject Into Breadth agents, depth-token-flow, depth-edge-case

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Smart contract auditing. It works with Stellar and Ethereum. The repository describes itself as: Autonomous Web3 security audit agent for Claude Code. The licence is MIT.

When your agent uses it

  • Pattern SEP-41 token patterns detected (approve/transfer/transferfrom/allowance/balance) - Inject Into Breadth agents
  • Depth-token-flow
  • Depth-edge-case

Example prompts

  • “/sep41-token-safety”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Approve Race Condition
  2. Allowance Expiry
  3. Transfer Auth Propagation
  4. SAC Interaction
  5. Balance Verification
  6. Burn Authorization

What it can do on your machine

Read from SKILL.md and the folder at commit 795962b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are rust and markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sep41 Token Safety loads about 2.5k tokens when it runs. Until then it costs about 45 tokens; SKILL.md has 1,045 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~45
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from PlamenTSV/plamen at commit 795962b, republished under its MIT licence (© PlamenTSV). 1,045 words, ~2,479 tokens.

Download SKILL.mdSave it as .claude/skills/sep41-token-safety/SKILL.md (or your agent's skills folder).
name
sep41-token-safety
description
Trigger Pattern SEP-41 token patterns detected (approve/transfer/transfer_from/allowance/balance) - Inject Into Breadth agents, depth-token-flow, depth-edge-case

SEP41_TOKEN_SAFETY Skill (Soroban)

Trigger Pattern: SEP-41 token patterns detected (approve/transfer/transfer_from/allowance/balance) Inject Into: Breadth agents, depth-token-flow, depth-edge-case Finding prefix: [ST-N] Rules referenced: R4, R5, R10, R11, R13, R15

SEP-41 is Soroban's token interface standard, analogous to ERC-20. It introduces Soroban-specific behaviors that differ from ERC-20: allowances use Temporary storage with expiration_ledger, the approve function can be front-run similarly to ERC-20, and the Stellar Asset Contract (SAC) bridges Stellar classic assets into Soroban with additional accounting complexity.

1. Approve Race Condition

The approve(from, spender, amount, expiration_ledger) function overwrites the current allowance without checking the existing value. This is the ERC-20 approve race condition, present identically in SEP-41:

Token Contractapprove Guarded?Guard TypeEffective?
{contract}YES/NOrequire!(current == 0) / noneYES/NO

Attack sequence:

  1. Owner approves spender for 100 tokens
  2. Owner submits new approval for 50 tokens
  3. Spender front-runs the new approval and spends the 100-token allowance
  4. New 50-token approval is set
  5. Spender spends 50 more tokens — net: 150 tokens spent, 50 intended

Soroban-specific note: Soroban does not have a traditional mempool — transaction ordering is determined by validators, not fee-based priority. However, multi-operation transactions and DEX routing can create ordering dependencies. The race condition is lower likelihood than on EVM but the vulnerability exists.

Check for:

  • Does approve allow setting non-zero over non-zero without an intermediate zero-set step?
  • Does the protocol documentation warn users about the race condition?
  • Are there any off-chain tools (like increaseAllowance / decreaseAllowance equivalents) to safely adjust allowances?

2. Allowance Expiry

SEP-41 allowances include an expiration_ledger parameter stored alongside the allowance amount. When the ledger passes expiration_ledger, the allowance is treated as zero. Verify expiry is handled correctly:

ContractAllowance Expiry Checked Before Use?Expired Allowance Returns 0 or Panics?Protocol Communicates Expiry to Users?
{contract}YES/NO{behavior}YES/NO

Allowance storage: SEP-41 standard stores allowances in Temporary storage with TTL linked to expiration_ledger. When expiration_ledger passes, the Temporary entry may be pruned, and the allowance() call returns zero automatically.

Checks:

  • Does the calling contract handle the case where a previously valid allowance has expired and transfer_from now fails?
  • Is expiration_ledger validated to be in the future when approve is called? Setting expiration_ledger in the past silently creates an already-expired allowance
  • For protocol-controlled allowances (e.g., a contract that approves tokens on behalf of users): does the contract re-approve if the allowance has expired?

Edge case: expiration_ledger = 0 behavior — verify whether the token contract treats 0 as "no expiry" or "expired at ledger 0" (already expired). Inconsistency here could cause silent allowance failures.

3. Transfer Auth Propagation

SEP-41 transfer(from, to, amount) requires from.require_auth(). transfer_from(spender, from, to, amount) requires spender.require_auth() and checks the allowance. Trace auth through the contract's transfer chains:

Calling FunctionTransfer TypeAuth Addressrequire_auth Called?Correct Subject?
{fn}transfer / transfer_from{from or spender}YES/NOYES/NO

Patterns to check:

  • A contract calling token.transfer(user, contract, amount) on behalf of a user — does it call user.require_auth() first, or does it rely on the token contract to enforce it?
  • Sub-invocation auth propagation: if a function calls token.transfer inside a invoke_contract chain, is the AuthorizedInvocation tree constructed to include the token transfer?
  • transfer_from where the spender is the calling contract itself (valid for vault patterns) — is the allowance actually set, or does the contract assume it already is?
Show full SKILL.md (507 more words)Show less

4. SAC Interaction

The Stellar Asset Contract (SAC) wraps Stellar classic XLM and issued assets as SEP-41 tokens. Contracts that interact with SAC face unique considerations:

ConcernAddressed?Evidence
SAC balance includes trust line state (frozen/unauthorized)YES/NO{fn:line or NONE}
Classic Stellar operations affecting SAC balance not reflected in Soroban stateYES/NO{fn:line or NONE}
Clawback feature of issued assets handledYES/NO{fn:line or NONE}
Issuer authorization revocation handledYES/NO{fn:line or NONE}
Token address permanence (classic re-issuance / migration)YES/NO{fn:line or NONE}

SAC-specific risks:

  • Trust line authorization: A classic Stellar account can have its trust line for an asset revoked by the issuer. After revocation, transfer to that account fails silently or panics. Contracts that assume all transfers succeed need to handle this.
  • Clawback: Some Stellar assets have clawback enabled. An issuer can call clawback to reduce a Soroban contract's balance without any Soroban transaction. This means a contract's balance() can decrease between two Soroban transactions with no on-Soroban event.
  • Balance source of truth: SAC reads balances from the underlying Stellar ledger state. If a classic operation changes the balance, the Soroban contract sees the new balance immediately — this can break invariants if the contract caches balances.
  • Token address permanence: On Stellar, classic assets can be re-issued or migrated, changing their effective on-chain identity. Contracts that derive storage keys, registry lookups, or deployment salts from token addresses may become unreachable if a token's address changes. Verify whether token address references can be updated or if the protocol documents this as a known limitation.

5. Balance Verification

When a contract accepts token deposits, it should verify the actual balance received rather than trusting the amount parameter:

FunctionReads Balance After Transfer?Trusts Amount Parameter?Fee-on-Transfer Risk?
{fn}YES/NOYES/NOYES/NO

Note: Standard Soroban tokens (non-SAC) do not support fee-on-transfer. However:

  • SAC-wrapped assets with clawback can reduce effective received amount
  • Custom token implementations may deviate from the standard
  • Protocols that accept arbitrary SEP-41 tokens should always read balance before and after transfer

Safe pattern:

rust
let balance_before = token.balance(env.current_contract_address());
token.transfer_from(&spender, &from, &env.current_contract_address(), &amount);
let balance_after = token.balance(env.current_contract_address());
let received = balance_after - balance_before;
// Use `received` not `amount` for accounting

6. Burn Authorization

burn(from, amount) and burn_from(spender, from, amount) must enforce proper authorization:

FunctionAuth CheckAuth SubjectCorrect?
burn call at {file:line}from.require_auth()fromYES/NO
burn_from call at {file:line}spender.require_auth() + allowance checkspenderYES/NO

Checks:

  • burn without require_auth on from → anyone can burn any user's tokens
  • burn_from without allowance check → bypasses the approval mechanism
  • Protocol contracts that call burn to destroy tokens: verify they call from.require_auth() or that from is the calling contract itself (self-burn is always permitted)
  • burn combined with minting: verify the net supply change is intentional and correctly accounted

Finding Template

markdown
**ID**: [ST-N]
**Severity**: [Critical if token theft, High if allowance bypass or burn exploit, Medium if expiry/SAC risk, Low if approve race]
**Step Execution**: ✓1,2,3,4,5,6 | ✗(reasons) | ?(uncertain)
**Rules Applied**: [R4:✓/✗, R5:✓/✗, R10:✓/✗, R11:✓/✗, R13:✓/✗, R15:✓/✗]
**Location**: src/{contract}.rs:LineN
**Title**: {Approve race / Expired allowance / Auth bypass / SAC risk / Burn exploit} in `{fn_name}`
**Description**: [Specific SEP-41 interaction flaw with code reference]
**Impact**: [Token theft / silent transfer failure / incorrect accounting / unauthorized burn]

Step Execution Checklist (MANDATORY)

SectionRequiredCompleted?Notes
1. Approve Race ConditionYES✓/✗/?All approve call sites
2. Allowance ExpiryYES✓/✗/?All transfer_from paths and approve expiration_ledger handling
3. Transfer Auth PropagationYES✓/✗/?All transfer and transfer_from invocations
4. SAC InteractionIF SAC tokens are involved✓/✗(N/A)/?Trust line, clawback, balance caching
5. Balance VerificationIF contract accepts deposits✓/✗(N/A)/?Balance-before vs balance-after pattern
6. Burn AuthorizationIF burn or burn_from present✓/✗(N/A)/?Auth on all burn call sites

© PlamenTSV, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in agents/skills/soroban/sep41-token-safety of PlamenTSV/plamen.

Open the folder on GitHubat commit 795962b

Compare with similar skills

Sep41 Token Safety next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sep41 Token Safety compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sep41 Token Safety this skillPlamenTSV/plamen303—~2.5kAutomated safety check: PassMIT
Ethereum Smart Contract Vulnerability Analysistradecatlabs/vibe-coding-cn17k1 repos~738Automated safety check: PassApache-2.0
Soroban Contract Auditsickn33/agentic-awesome-skills47k1 repos~1.4kAutomated safety check: PassMIT
Soroban Liquidity Poolsickn33/agentic-awesome-skills47k1 repos~1.3kAutomated safety check: PassMIT
Soroban Storage Ttl Lifecyclesickn33/agentic-awesome-skills47k1 repos~1.3kAutomated safety check: PassMIT
Soroban Token Mintersickn33/agentic-awesome-skills47k1 repos~1.3kAutomated safety check: PassMIT

Similar skills

  • Runs Slither and Mythril against Solidity contracts to find reentrancy, overflow and access-control bugs before mainnet deployment, then triages and reports findings.

    17k GitHub starsUsed in 1 repo~738 tokens
    SecurityAuto-check passed
  • Soroban Contract Audit

    sickn33/agentic-awesome-skills

    Soroban smart contract security audit register: authorization checks, panic pathways, integer overflows, and storage footprint verification for Stellar.

    47k GitHub starsUsed in 1 repo~1.4k tokens
    SecurityAuto-check passed
  • Soroban Liquidity Pool

    sickn33/agentic-awesome-skills

    Automated market maker liquidity pool register: constant-product invariant curves, swap fee tiers, and LP token shares for Soroban DeFi.

    47k GitHub starsUsed in 1 repo~1.3k tokens
    SecurityAuto-check passed
  • Soroban Storage Ttl Lifecycle

    sickn33/agentic-awesome-skills

    Soroban ledger state rent and TTL extension register: live state tracking, bump thresholds, rent fee reserves, and archive boundaries.

    47k GitHub starsUsed in 1 repo~1.3k tokens
    SecurityAuto-check passed
  • Soroban Token Minter

    sickn33/agentic-awesome-skills

    Soroban SEP-41 token contract architecture register: admin control, supply caps, metadata standard, and transfer event emissions on Stellar.

    47k GitHub starsUsed in 1 repo~1.3k tokens
    SecurityAuto-check passed
  • Smart Contract Audit

    forefy/.context

    Comprehensive smart contract security audit framework with multi-expert analysis.

    152 GitHub starsUsed in 1 repo~5.1k tokens
    SecurityAuto-check passed

More from PlamenTSV/plamen

All 87 skills in this repo
  • Audit Prep

    PlamenTSV/plamen

    Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project…

    303 GitHub stars~3.7k tokensUpdated 14 days ago
    Auto-check passed
  • Verification Protocol

    PlamenTSV/plamen

    Trigger Pattern Always (used by all verifier agents) - Inject Into security-verifier agents (Phase 5)

    303 GitHub stars~3.5k tokensUpdated 14 days ago
    Auto-check passed
  • Ability Analysis

    PlamenTSV/plamen

    Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth agents, depth agents

    303 GitHub stars~3.3k tokensUpdated 14 days ago
    Auto-check passed
  • Ability Analysis

    PlamenTSV/plamen

    Trigger Pattern Always (Sui Move) -- foundational security check - Inject Into Breadth agents, depth agents

    303 GitHub stars~3.2k tokensUpdated 14 days ago
    Auto-check passed
  • Account Lifecycle

    PlamenTSV/plamen

    Trigger Pattern ACCOUNTCLOSING flag detected (close/CloseAccount usage) - Inject Into Breadth agents, depth agents

    303 GitHub stars~1.2k tokensUpdated 14 days ago
    Auto-check passed
  • Account Validation

    PlamenTSV/plamen

    Trigger Pattern Always required for Solana audits - Inject Into Breadth agents, depth agents

    303 GitHub stars~1.7k tokensUpdated 14 days ago
    Auto-check passed

Works with

Categories

Questions about Sep41 Token Safety

What does Sep41 Token Safety do?

Trigger Pattern SEP-41 token patterns detected (approve/transfer/transferfrom/allowance/balance) - Inject Into Breadth agents, depth-token-flow, depth-edge-case. Sep41 Token Safety is an agent skill from PlamenTSV/plamen.

When should I use Sep41 Token Safety?

Sep41 Token Safety fits situations like: pattern SEP-41 token patterns detected (approve/transfer/transferfrom/allowance/balance) - Inject Into Breadth agents; depth-token-flow; depth-edge-case.

How do I install Sep41 Token Safety in Claude Code?

Run `npx skills add PlamenTSV/plamen --skill sep41-token-safety -a claude-code`. Or copy the skill folder (agents/skills/soroban/sep41-token-safety in PlamenTSV/plamen) into .claude/skills/sep41-token-safety in your project. Claude Code loads it when a task matches its description.

How do I install Sep41 Token Safety in Codex?

Run `npx skills add PlamenTSV/plamen --skill sep41-token-safety -a codex`. Or copy the skill folder (agents/skills/soroban/sep41-token-safety in PlamenTSV/plamen) into .agents/skills/sep41-token-safety in your project. Codex loads it when a task matches its description.

Can I use Sep41 Token Safety in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PlamenTSV/plamen --skill sep41-token-safety -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sep41-token-safety, .gemini/skills/sep41-token-safety, .github/skills/sep41-token-safety and .opencode/skills/sep41-token-safety in your project.

What does Sep41 Token Safety need to run?

SKILL.md names no scripts, command-line tools or credentials: Sep41 Token Safety is instructions for the agent only.

Does Sep41 Token Safety access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Sep41 Token Safety safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Sep41 Token Safety use?

Sep41 Token Safety is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sep41 Token Safety use?

About 2.5k tokens (SKILL.md is roughly 9.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Sep41 Token Safety?

Skills that share tags, products or a category with Sep41 Token Safety: Ethereum Smart Contract Vulnerability Analysis (tradecatlabs/vibe-coding-cn, 17k stars), Soroban Contract Audit (sickn33/agentic-awesome-skills, 47k stars), Soroban Liquidity Pool (sickn33/agentic-awesome-skills, 47k stars) and Soroban Storage Ttl Lifecycle (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sep41 Token Safety?

PlamenTSV (a GitHub user) maintains it in PlamenTSV/plamen, which has 303 GitHub stars. The repository holds 87 skills in this directory. The repository was last updated on September 26, 2026.

Source: PlamenTSV/plamen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.