Flags
vercel/next.js
How to add or modify Next.js experimental feature flags end-to-end.
Trigger STABLESWAPFORK flag (fork-ancestry detects Curve/StableSwap parent via getd/gety/rampa/StableSwap patterns) - Agent Type general-purpose (standalone niche agent, 1 budget slot)
$ npx skills add PlamenTSV/plamen --skill stableswap-compliance -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install PlamenTSV/plamen stableswap-compliance --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agents/skills/niche/stableswap-compliance .claude/skills/stableswap-compliance && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "stableswap-compliance" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/niche/stableswap-compliance into .claude/skills/stableswap-compliance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "stableswap-compliance", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/PlamenTSV/plamen/tree/main/agents/skills/niche/stableswap-complianceType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add PlamenTSV/plamen --skill stableswap-compliance -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install PlamenTSV/plamen stableswap-compliance --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .agents/skills && cp -r skills-src/agents/skills/niche/stableswap-compliance .agents/skills/stableswap-compliance && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "stableswap-compliance" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/niche/stableswap-compliance into .agents/skills/stableswap-compliance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "stableswap-compliance", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add PlamenTSV/plamen --skill stableswap-compliance -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install PlamenTSV/plamen stableswap-compliance --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/agents/skills/niche/stableswap-compliance .cursor/skills/stableswap-compliance && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "stableswap-compliance" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/niche/stableswap-compliance into .cursor/skills/stableswap-compliance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "stableswap-compliance", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/PlamenTSV/plamen.git --path agents/skills/niche/stableswap-compliance--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add PlamenTSV/plamen --skill stableswap-compliance -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install PlamenTSV/plamen stableswap-compliance --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/agents/skills/niche/stableswap-compliance .gemini/skills/stableswap-compliance && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "stableswap-compliance" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/niche/stableswap-compliance into .gemini/skills/stableswap-compliance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "stableswap-compliance", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install PlamenTSV/plamen stableswap-complianceInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add PlamenTSV/plamen --skill stableswap-compliance -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .github/skills && cp -r skills-src/agents/skills/niche/stableswap-compliance .github/skills/stableswap-compliance && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "stableswap-compliance" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/niche/stableswap-compliance into .github/skills/stableswap-compliance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "stableswap-compliance", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add PlamenTSV/plamen --skill stableswap-compliance -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install PlamenTSV/plamen stableswap-compliance --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/agents/skills/niche/stableswap-compliance .opencode/skills/stableswap-compliance && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "stableswap-compliance" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/niche/stableswap-compliance into .opencode/skills/stableswap-compliance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "stableswap-compliance", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
stableswap-complianceTrigger STABLESWAPFORK flag (fork-ancestry detects Curve/StableSwap parent via getd/gety/rampa/StableSwap patterns) - Agent Type general-purpose (standalone niche agent, 1 budget slot)
Stableswap Compliance is an agent skill from PlamenTSV/plamen. Trigger STABLESWAPFORK flag (fork-ancestry detects Curve/StableSwap parent via getd/gety/rampa/StableSwap patterns) - Agent Type general-purpose (standalone niche agent, 1 budget slot)
Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
The repository describes itself as: Autonomous Web3 security audit agent for Claude Code. The licence is MIT.
Read from SKILL.md and the folder at commit 795962b. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Stableswap Compliance loads about 1.9k tokens when it runs. Until then it costs about 53 tokens; SKILL.md has 97 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from PlamenTSV/plamen at commit 795962b, republished under its MIT licence (© PlamenTSV). 97 words, ~1,922 tokens.
.claude/skills/stableswap-compliance/SKILL.md (or your agent's skills folder).Trigger:
STABLESWAP_FORKflag intemplate_recommendations.md(fork-ancestry detects Curve/StableSwap as parent) Agent Type:general-purpose(standalone niche agent, NOT injected into another agent) Budget: 1 depth budget slot in Phase 4b iteration 1 Finding prefix:[SSC-N]Added in: v1.1.6 Language: All (Curve forks exist across EVM, Soroban, Solana, Move)
Recon Agent 1B (Fork Ancestry) detects Curve/StableSwap as a parent protocol via patterns: get_d|get_y|get_y_d|ramp_a|stop_ramp_a|StableSwap|stableswap|A_PRECISION|RATE_MULTIPLIER|admin_fee|get_virtual_price|calc_withdraw_one_coin|remove_liquidity_imbalance.
If detected with confidence MEDIUM or HIGH, recon sets STABLESWAP_FORK flag. The orchestrator spawns this agent in Phase 4b iteration 1 alongside standard agents.
Task(subagent_type="general-purpose", prompt="
You are the StableSwap Compliance Agent. You audit Curve/StableSwap fork correctness against the reference implementation.
## Your Inputs
Read:
- {SCRATCHPAD}/meta_buffer.md (fork ancestry analysis)
- {SCRATCHPAD}/findings_inventory.md (existing findings to avoid duplicates)
- {SCRATCHPAD}/function_list.md
- Source files containing get_d, get_y, get_y_d, ramp_a, deposit, withdraw
## Processing Protocol (MANDATORY)
For each CHECK, execute three steps in order:
1. **ENUMERATE targets**: List every entity as a numbered list.
2. **PROCESS exhaustively**: Analyze each. Mark DONE or N/A(reason).
3. **COVERAGE GATE**: Count enumerated vs processed. Complete all before next CHECK.
## CHECK 1: Iterative Solver Convergence
For EACH function using Newton-Raphson or iterative root-finding (get_d, get_y, get_y_d, or similar):
| Function | Location | Max Iterations | Convergence Check? | Reverts on Non-Convergence? | Finding? |
|----------|----------|---------------|-------------------|---------------------------|---------|
**What to check**:
- Does the function verify the solution converged (difference < threshold)?
- If iteration limit exhausted without convergence, does it REVERT/PANIC or silently return the last (potentially incorrect) approximation?
- Curve reference: `assert converged` after the loop. Many forks drop this assertion.
- **Impact**: A non-converged result produces incorrect D/y values, leading to mispriced swaps, incorrect LP share calculations, or exploitable deposit/withdraw amounts.
Tag: `[BOUNDARY:iterations=MAX → d_prev-d={value}]` to prove non-convergence at specific inputs.
## CHECK 2: Amplification Parameter Encoding
Read the function that computes `ann` or the effective amplification:
| Location | Formula Used | Curve Reference Formula | Match? | Finding? |
|----------|-------------|------------------------|--------|---------|
**What to check**:
- Curve reference: `ann = A * N_COINS` where `A` is stored as `A * A_PRECISION` (i.e., `A * N_COINS^(N_COINS-1)`)
- Common fork bug: storing `A` as the raw amplification factor, then computing `ann = A * N_COINS` which produces a value `N_COINS^(N_COINS-1)` times too small
- Check `initialize()`: how is the `a` parameter stored? Raw value or pre-multiplied?
- Check `A()` / `get_a()`: does it return the stored value directly or divide by `A_PRECISION`?
- Check `ramp_a`: does the ramp target use the same encoding as `initialize`?
- **Impact**: Incorrect A encoding degrades capital efficiency. For N=2, the error is 2x. For N=3, the error is 9x. For N=4, the error is 64x.
Tag: `[VARIATION:A_encoding=raw vs A*N^(N-1) → pricing error={magnitude}]`
## CHECK 3: Reserve Decimal Normalization
For EACH multi-token pool that computes invariants (D, y):
| Pool | Tokens | Decimals per Token | Normalization Applied? | Curve Reference | Finding? |
|------|--------|-------------------|----------------------|----------------|---------|
**What to check**:
- Curve reference: `RATE_MULTIPLIER` or `PRECISION_MUL` normalizes all reserves to a common precision (typically 18 decimals) before invariant calculation
- Common fork bug: assuming all tokens have the same decimals (e.g., 7 on Stellar, 18 on EVM)
- Read the deposit/swap/withdraw functions: are raw token amounts passed to `get_d`/`get_y`, or are they normalized first?
- If no normalization: check if the pool creation validates that all tokens have identical decimals
- **Impact**: Without normalization, a pool with tokens of different decimals computes incorrect invariants. A 7-decimal token paired with an 18-decimal token would treat 1 unit of the 7-decimal token as equivalent to 1 unit of the 18-decimal token — a 10^11 pricing error.
Tag: `[VARIATION:decimals=7,18 → price_error={ratio}]`
## CHECK 4: Fee Application Consistency
For EACH fee-related computation in the StableSwap:
| Operation | Fee Formula | Curve Reference Formula | Match? | Rounding Direction | Finding? |
|-----------|-----------|------------------------|--------|-------------------|---------|
**What to check**:
- `admin_fee` encoding: does it match Curve's definition (fraction of the trading fee, not an absolute percentage)?
- Fee deduction in deposit: applied to the imbalance component, not the entire deposit?
- Fee deduction in withdrawal: symmetric with deposit fee application?
- `withdraw_admin_fees`: computed as `balance - reserves` (Curve pattern) or via internal tracking?
- `donate_admin_fees`: if present, can it be used to manipulate the exchange rate?
## CHECK 5: Known StableSwap-Family Footguns
StableSwap-invariant pools (the Newton-Raphson `D`/`y` design popularized by
Curve and now forked across many chains/languages) share a set of
historically exploited failure classes because they share the same
underlying math and lifecycle. Verify the fork addresses each class against
the canonical StableSwap invariant design, the same way you'd check
conformance against a written standard (e.g. ERC-20):
| Known Issue Class | Canonical Mitigation | Fork Has It? | Finding? |
|------------|---------------------|-------------|---------|
| Read-only reentrancy via a virtual-price / share-price view during an unfinished external call | view function guard or no callback re-entry into the price view | Check |
| Imbalanced-withdrawal fee bypass (`remove_liquidity`-style exits skipping the imbalance fee) | fee charged on deviation from a balanced withdrawal | Check |
| Amplification-ramp manipulation (A changed while positions are open, to move the invariant's price curve) | minimum ramp duration, maximum A change per ramp | Check |
| Admin/protocol fee accumulation causing exchange-rate drift between accounting and real reserves | periodic fee sweep or auto-donation reconciling accounting to reserves | Check |
| First-depositor share inflation via direct token transfer before any deposit | minimum liquidity lock or internal (non-balance-derived) accounting | Check |
## Output
- Maximum 8 findings [SSC-1] through [SSC-8]
- Use standard finding format from ~/.claude/rules/finding-output-format.md
## Chain Summary (MANDATORY)
| Finding ID | Location | Root Cause (1-line) | Verdict | Severity | Precondition Type | Postcondition Type |
Write to {SCRATCHPAD}/niche_stableswap_compliance_findings.md
Return: 'DONE: {N} stableswap compliance findings - Check1: {A} convergence, Check2: {B} A-encoding, Check3: {C} decimals, Check4: {D} fees, Check5: {E} known vulns'
")© PlamenTSV, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in agents/skills/niche/stableswap-compliance of PlamenTSV/plamen.
Open the folder on GitHubat commit 795962b
Stableswap Compliance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Stableswap Compliance this skillPlamenTSV/plamen | 303 | — | ~1.9k | Automated safety check: Pass | MIT | |
| Flagsvercel/next.js | 143k | — | ~746 | Automated safety check: Pass | MIT | |
| Pii Detectruvnet/ruflo | 74k | — | ~350 | Automated safety check: Notes | MIT | |
| Threat Detectionalirezarezvani/claude-skills | 28k | — | ~3.5k | Automated safety check: Pass | MIT | |
| Detecting Arp Poisoning In Network Trafficmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3.8k | Automated safety check: Notes | Apache-2.0 | |
| Detecting Anomalies In Industrial Control Systemsmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3.2k | Automated safety check: Pass | Apache-2.0 |
vercel/next.js
How to add or modify Next.js experimental feature flags end-to-end.
ruvnet/ruflo
Detect and flag personally identifiable information (PII) in text, code, and configurations.
alirezarezvani/claude-skills
A skill your agent uses when hunting for threats in an environment, analyzing IOCs, or detecting behavioral anomalies in telemetry.
mukul975/Anthropic-Cybersecurity-Skills
Detect Layer 2 ARP poisoning/spoofing by deploying ARPWatch, Dynamic ARP Inspection (DAI), Wireshark packet analysis, and custom Python monitoring scripts that flag gratuitous ARP floods, IP-to-MAC…
mukul975/Anthropic-Cybersecurity-Skills
Deploys anomaly detection for OT/ICS environments using machine learning on OT network baselines, physics-based process models, and Modbus/DNP3/OPC UA traffic analysis to flag deviations, rogue…
github/awesome-copilot
Deepfake detection and media safety — detect AI-generated audio, images, video, and text, trace synthesis sources, apply watermarks, verify speaker identity, and analyze media intelligence using…
PlamenTSV/plamen
Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project…
PlamenTSV/plamen
Trigger Pattern Always (used by all verifier agents) - Inject Into security-verifier agents (Phase 5)
PlamenTSV/plamen
Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth agents, depth agents
PlamenTSV/plamen
Trigger Pattern Always (Sui Move) -- foundational security check - Inject Into Breadth agents, depth agents
PlamenTSV/plamen
Trigger Pattern ACCOUNTCLOSING flag detected (close/CloseAccount usage) - Inject Into Breadth agents, depth agents
PlamenTSV/plamen
Trigger Pattern Always required for Solana audits - Inject Into Breadth agents, depth agents
Trigger STABLESWAPFORK flag (fork-ancestry detects Curve/StableSwap parent via getd/gety/rampa/StableSwap patterns) - Agent Type general-purpose (standalone niche agent, 1 budget slot). Stableswap Compliance is an agent skill from PlamenTSV/plamen.
Run `npx skills add PlamenTSV/plamen --skill stableswap-compliance -a claude-code`. Or copy the skill folder (agents/skills/niche/stableswap-compliance in PlamenTSV/plamen) into .claude/skills/stableswap-compliance in your project. Claude Code loads it when a task matches its description.
Run `npx skills add PlamenTSV/plamen --skill stableswap-compliance -a codex`. Or copy the skill folder (agents/skills/niche/stableswap-compliance in PlamenTSV/plamen) into .agents/skills/stableswap-compliance in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PlamenTSV/plamen --skill stableswap-compliance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/stableswap-compliance, .gemini/skills/stableswap-compliance, .github/skills/stableswap-compliance and .opencode/skills/stableswap-compliance in your project.
SKILL.md names no scripts, command-line tools or credentials: Stableswap Compliance is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Stableswap Compliance is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.9k tokens (SKILL.md is roughly 7.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Stableswap Compliance: Flags (vercel/next.js, 143k stars), Pii Detect (ruvnet/ruflo, 74k stars), Threat Detection (alirezarezvani/claude-skills, 28k stars) and Detecting Arp Poisoning In Network Traffic (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
PlamenTSV (a GitHub user) maintains it in PlamenTSV/plamen, which has 303 GitHub stars. The repository holds 87 skills in this directory. The repository was last updated on September 26, 2026.
Source: PlamenTSV/plamen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.