Agent skill

Token Flow Tracing

by PlamenTSV in PlamenTSV/plamen

Trigger Pattern BALANCEDEPENDENT flag (required) - Inject Into Depth-token-flow, breadth agents

MITAuto-check passedBusiness, Finance & HR

Install Token Flow Tracing

skills CLI
$ npx skills add PlamenTSV/plamen --skill token-flow-tracing -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install PlamenTSV/plamen token-flow-tracing --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agents/skills/sui/token-flow-tracing .claude/skills/token-flow-tracing && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
token-flow-tracing
GitHub stars
303
Token cost
~3.4k tokens
SKILL.md length
1,412 words
Files
1
Skills in repo
87
Repo updated
First seen
Licence
MIT

At a glance

Trigger Pattern BALANCEDEPENDENT flag (required) - Inject Into Depth-token-flow, breadth agents

  • Works in 9 steps: Asset Inventory → Token Entry Points → Token Exit Points → …
  • Pattern BALANCEDEPENDENT flag (required) - Inject Into Depth-token-flow
  • SKILL.md covers 1. Asset Inventory, 2. Token Entry Points, 3. Token Exit Points and 4. Balance Tracking and Desync…, plus 9 more sections
  • Needs ATTACKER_TOKEN

What it does

Token Flow Tracing is an agent skill from PlamenTSV/plamen. Trigger Pattern BALANCEDEPENDENT flag (required) - Inject Into Depth-token-flow, breadth agents

Its SKILL.md is about 3.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Business, Finance & HR. The repository describes itself as: Autonomous Web3 security audit agent for Claude Code. The licence is MIT.

When your agent uses it

  • Pattern BALANCEDEPENDENT flag (required) - Inject Into Depth-token-flow

Example prompts

  • “/token-flow-tracing”

Requirements

  • A credential in ATTACKER_TOKEN

Workflow steps

9 steps, taken from the step headings in SKILL.md.

  1. Asset Inventory
  2. Token Entry Points
  3. Token Exit Points
  4. Balance Tracking and Desync Analysis
  5. Unsolicited Deposit Analysis
  6. Token Type Confusion
  7. Coin Splitting and Merging
  8. Zero-Value Operations
  9. Cross-Token Interactions

What it can do on your machine

Read from SKILL.md and the folder at commit 795962b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • ATTACKER_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Token Flow Tracing loads about 3.4k tokens when it runs. Until then it costs about 29 tokens; SKILL.md has 1,412 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~29
When it runs · the whole SKILL.md, loaded when a task matches
~3.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from PlamenTSV/plamen at commit 795962b, republished under its MIT licence (© PlamenTSV). 1,412 words, ~3,423 tokens.

Download SKILL.mdSave it as .claude/skills/token-flow-tracing/SKILL.md (or your agent's skills folder).
name
token-flow-tracing
description
Trigger Pattern BALANCE_DEPENDENT flag (required) - Inject Into Depth-token-flow, breadth agents

TOKEN_FLOW_TRACING Skill (Sui)

Trigger Pattern: BALANCE_DEPENDENT flag (required) Inject Into: Depth-token-flow, breadth agents Purpose: Trace all Coin<T> and Balance<T> flows through Sui Move protocols to identify accounting desync, unsolicited deposit vectors, type confusion, and token lifecycle issues

For every token the protocol handles:

1. Asset Inventory

Enumerate ALL Coin<T> and Balance<T> types the protocol handles:

Token TypeRepresentationLocation (module::struct field)Owned or Shared?Entry FunctionsExit Functions
{e.g., SUI}Balance<SUI>pool::Pool.balanceShared objectdeposit()withdraw()
{e.g., USDC}Coin<USDC>(function parameter)Owned (user)swap_in()swap_out()

Sui-specific representations:

  • Coin<T>: Owned object with id: UID and balance: Balance<T>. Has key + store abilities -- freely transferable to any address via transfer::public_transfer. This is the primary unsolicited transfer vector on Sui.
  • Balance<T>: Value type with store ability only (no key). Stored inside other objects. Cannot exist as a standalone on-chain object. Must live inside a struct with key.
  • TreasuryCap<T>: Capability to mint/burn. Must be tracked.
  • Dynamic fields storing Balance<T>: Hidden balance storage -- check dynamic_field::add/borrow/remove.

2. Token Entry Points

Where can tokens enter the protocol?

Entry PathFunctionToken FormAccounting UpdateValidated?
Standard deposit{module::deposit}Coin<T> parameter{state variable updated}YES/NO
PTB coin splitting(PTB splits user coin)Coin<T> from split{same as above?}N/A
Direct transfertransfer::public_transferCoin<T> to addressNONE -- creates new owned objectNO
Balance mergebalance::joinBalance<T>{state variable updated?}YES/NO
Mintcoin::from_balance / coin::mintTreasuryCap{supply tracking}YES/NO
Side-effect receipt{external call returns coin}Coin<T>{handled?}YES/NO

Sui-specific entry analysis:

  • coin::into_balance(coin) converts Coin<T> to Balance<T> -- does the protocol track this conversion?
  • coin::split(&mut coin, amount, ctx) creates a new Coin<T> -- does the protocol validate the split amount?
  • Can users pass zero-value coins? (coin::zero<T>(ctx))

3. Token Exit Points

Where can tokens leave the protocol?

Exit PathFunctionToken FormAccounting UpdateAuthorized?
Standard withdraw{module::withdraw}Coin<T> returned{state variable decremented}{access check}
Transfer outtransfer::public_transferCoin<T>{accounting updated?}{access check}
Balance extractionbalance::splitBalance<T>{state variable decremented?}{access check}
Burncoin::burn / balance::decrease_supplyTreasuryCap{supply tracking}{cap holder}
Fee distribution{fee function}Coin<T> or Balance<T>{fee accounting}{access check}
Emergency withdraw{emergency function}Coin<T>{does it clear ALL state?}{admin cap?}

For each exit: does the tracked balance decrease BEFORE or AFTER the actual balance extraction? For each transfer/withdrawal: can the source be underfunded at execution time? (funds deployed externally, locked, or lent out → transfer aborts) Check for:

  • balance::split before state update -> can the function abort between split and update?
  • State update before balance::split -> can state be inconsistent if split aborts?
3b. Self-Transfer Accounting

For each transfer function: can the sender and recipient be the same address/object? If YES: does a self-transfer update accounting state (fees credited, rewards claimed, snapshots updated, share ratios changed) without net token movement? Flag as FINDING.

4. Balance Tracking and Desync Analysis

For each token in the protocol:

TokenInternal Tracking VariableActual Balance SourceCan They Desync?Desync Vector
{token}{e.g., pool.total_deposited}balance::value(&pool.balance)YES/NO{how}

Red flags:

  • Exchange rate calculations using balance::value() directly instead of tracked internal variable
  • No reconciliation mechanism between tracked and actual balance
  • Accounting variables updated in a different function than the balance transfer
  • balance::join(&mut pool.balance, deposit_balance) without incrementing tracked counter

Sui-specific desync vectors:

  • balance::join into a shared object's Balance<T> without updating the tracking variable
  • Dynamic field operations that add/remove Balance<T> without pool-level accounting
  • Multiple shared objects holding the same token type with aggregate accounting errors

5. Unsolicited Deposit Analysis

Can tokens be added to the protocol's balance without going through deposit logic?

Sui object model considerations:

  • Owned objects: Only the owner can access. Sending Coin<T> via transfer::public_transfer to a shared object's address creates a NEW owned object at that address -- it does NOT add to the shared object's Balance<T>. The protocol would need to explicitly receive and merge it.
  • Shared objects: Anyone can call functions on shared objects, but cannot directly modify their Balance<T> fields without going through the module's public API.
  • However: If the module exposes a public function that accepts Coin<T> and calls balance::join without proper accounting, this IS a donation vector.
Donation PathPossible?Changes Protocol Balance?Breaks Accounting?Impact
transfer::public_transfer to pool addressYES (creates owned obj)NO (not auto-merged)NO (unless protocol sweeps){analysis}
Public function accepting Coin<T> without accounting{YES/NO}YESYES{analysis}
Dynamic field injection{YES/NO -- needs module API}{YES/NO}{YES/NO}{analysis}
Reward/fee distribution to protocol address{YES/NO}{YES/NO}{YES/NO}{analysis}
5b. Unsolicited Transfer Matrix (All Token Types)

For EVERY external token type the protocol holds, queries, or receives as side effects -- not just the protocol's primary token:

Token TypeCan Be Sent to Protocol?Changes Protocol Accounting?Blocks Operations?Triggers Side Effects?
{token_a}YES/NOYES/NOYES/NOYES/NO

RULE: If ANY token type can enter the protocol's balance AND affects state -> analyze each consequence:

  • Accounting impact: Does tracked vs actual balance diverge?
  • Iteration impact: Does the protocol iterate over sources of this token? (gas DoS vector via object count)
  • Operation blocking: Does non-zero balance of this token prevent admin operations?
  • Side effect chain: Does receiving this token trigger further side effects?
Show full SKILL.md (588 more words)Show less

6. Token Type Confusion

Can the wrong Coin<T> type be passed to protocol functions?

FunctionExpected Type ParameterValidated?What if Wrong Type?
{function}Coin<USDC>{by Move type system / runtime check}{impact}

Sui Move type safety: Move's type system provides strong static guarantees -- Coin<USDC> and Coin<SUI> are different types at compile time. However:

  • Generic functions fun deposit<T>(coin: Coin<T>) accept ANY Coin<T> -- is T validated?
  • Does the protocol check T against an allowed list? (e.g., assert!(type_name::get<T>() == allowed_type))
  • Can an attacker create a custom token type and pass Coin<ATTACKER_TOKEN> to a generic function?
  • For pools with multiple token types: can the type parameters be swapped? (e.g., Pool<A, B> called with Coin<B> where Coin<A> expected)

7. Coin Splitting and Merging

Analyze coin::split() and coin::join() / balance::split() and balance::join() operations:

OperationLocationAmount SourceValidated?Edge Cases
coin::split(&mut coin, amount, ctx){location}{user input / computed}{amount <= coin.value?}{amount = 0? amount = full value?}
coin::join(&mut coin_a, coin_b){location}{coin_b.value}{overflow check?}{coin_b is zero?}
balance::split(&mut bal, amount){location}{computed}{amount <= bal.value?}{amount = 0?}
balance::join(&mut bal_a, bal_b){location}{bal_b.value}{overflow check?}{bal_b is zero?}

Check:

  • Off-by-one errors in split amounts
  • Dust remaining after splits (tiny amounts that cannot be withdrawn)
  • Zero-value splits: coin::split(&mut coin, 0, ctx) creates a zero-value coin -- does the protocol handle this?
  • Full-value splits: splitting the entire balance leaves a zero-value coin/balance in place

8. Zero-Value Operations

What happens with zero-value tokens?

OperationZero Input BehaviorImpact
deposit(coin::zero<T>()){aborts / succeeds / mints zero shares}{accounting impact}
withdraw(0){aborts / succeeds / burns zero shares}{accounting impact}
swap(coin::zero<T>()){aborts / succeeds}{state change without value?}
claim_rewards() when rewards = 0{aborts / succeeds}{side effects?}

Check: Can zero-value operations be used to:

  • Trigger state changes without economic commitment?
  • Reset cooldown timers?
  • Increment counters or advance epochs?
  • Create empty objects that consume storage?

9. Cross-Token Interactions

For protocols with multiple token types:

InteractionToken AToken BDependencyImpact
Exchange rate{A type}{B type}{A balance affects B's rate?}{if A manipulated, B price changes?}
Collateral/debt{collateral type}{debt type}{collateral value gates borrowing}{if collateral inflated, excess borrowing}
LP composition{A type}{B type}{ratio determines share value}{imbalance vector}
  • Can operations on Token A affect Token B's accounting?
  • Are there exchange rate dependencies between tokens?
  • Can withdrawing Token A affect availability of Token B?

Finding Template

markdown
**ID**: [TF-N]
**Severity**: [based on fund impact]
**Step Execution**: check1,2,3,4,5,6,7,8,9 | x(reasons) | ?(uncertain)
**Rules Applied**: [R1:check, R11:check, R4:check, R10:check]
**Location**: module::function:LineN
**Title**: [Token type] can enter/exit via [path] without [expected accounting update]
**Description**: [Trace the token flow and where it diverges from expected]
**Impact**: [What breaks: exchange rates, user balances, protocol insolvency]

Instantiation Parameters

{CONTRACTS}           -- Move modules to analyze
{TOKEN_TYPES}         -- Coin<T>/Balance<T> types handled
{SHARED_OBJECTS}      -- Shared objects holding balances
{ENTRY_FUNCTIONS}     -- Token deposit/entry functions
{EXIT_FUNCTIONS}      -- Token withdraw/exit functions
{GENERIC_FUNCTIONS}   -- Functions with type parameter <T>

Output Schema

FieldRequiredDescription
asset_inventoryyesAll Coin<T> and Balance<T> types
entry_pointsyesAll token entry paths
exit_pointsyesAll token exit paths
balance_trackingyesInternal vs actual balance analysis
unsolicited_analysisyesDonation/unsolicited deposit vectors
type_confusionyesType parameter validation
findingyesCONFIRMED / REFUTED / CONTESTED
evidenceyesCode locations with line numbers
step_executionyesStatus for each step

Step Execution Checklist (MANDATORY)

SectionRequiredCompleted?Notes
1. Asset InventoryYEScheck/x/?
2. Token Entry PointsYEScheck/x/?
3. Token Exit PointsYEScheck/x/?
4. Balance Tracking and DesyncYEScheck/x/?
5. Unsolicited Deposit AnalysisYEScheck/x/?
5b. Unsolicited Transfer Matrix (All Types)YEScheck/x/?MANDATORY -- never skip
6. Token Type ConfusionYEScheck/x/?
7. Coin Splitting and MergingYEScheck/x/?
8. Zero-Value OperationsYEScheck/x/?
9. Cross-Token InteractionsIF multi-tokencheck/x(N/A)/?
Cross-Reference Markers

After Section 5 (Unsolicited Deposit Analysis):

  • IF donation vectors found -> MUST check impact on exchange rates in Section 4
  • IF protocol has generic functions -> MUST complete Section 6

After Section 7 (Coin Splitting and Merging):

  • IF dust amounts possible -> MUST check zero-value impact in Section 8
  • Cross-reference with ZERO_STATE_RETURN for residual balance implications

After Section 8 (Zero-Value Operations):

  • IF zero-value operations cause state changes -> FINDING (minimum Low)
  • Document: "Zero-value [operation] triggers [state change] without economic commitment"

© PlamenTSV, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in agents/skills/sui/token-flow-tracing of PlamenTSV/plamen.

Open the folder on GitHubat commit 795962b

Compare with similar skills

Token Flow Tracing next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Token Flow Tracing compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Token Flow Tracing this skillPlamenTSV/plamen303—~3.4kAutomated safety check: PassMIT
Technical Analysttradermonty/claude-trading-skills3k5 repos~4.6kAutomated safety check: PassMIT
Creating Financial ModelsChen-zexi/open-ptc-agent7294 repos~1.3kAutomated safety check: PassMIT
Stock APIzhangxiangliang/stock-api2k—~507Automated safety check: PassMIT
Theme Detectortradermonty/claude-trading-skills3k2 repos~4.9kAutomated safety check: PassMIT
Itr Walakaranb192/itr-wala871—~3.6kAutomated safety check: PassMIT

Similar skills

  • Technical Analyst

    tradermonty/claude-trading-skills

    This skill should be used when analyzing weekly price charts for stocks, stock indices, cryptocurrencies, or forex pairs.

    3k GitHub starsUsed in 5 repos~4.6k tokens
    Business, Finance & HRAuto-check passed
  • Creating Financial Models

    Chen-zexi/open-ptc-agent

    This skill provides an advanced financial modeling suite with DCF analysis, sensitivity testing, Monte Carlo simulations, and scenario planning for investment decisions

    729 GitHub starsUsed in 4 repos~1.3k tokens
    Business, Finance & HRAuto-check passed
  • Stock API

    zhangxiangliang/stock-api

    Fetch real-time stock quotes, K-line (candlestick) history, and search symbols for China A-shares, Hong Kong, and US markets.

    2k GitHub stars~507 tokensUpdated yesterday
    Business, Finance & HRAuto-check passed
  • Theme Detector

    tradermonty/claude-trading-skills

    Detect and analyze trending market themes across sectors. An agent skill from tradermonty/claude-trading-skills.

    3k GitHub starsUsed in 2 repos~4.9k tokens
    Business, Finance & HRAuto-check passed
  • Itr Wala

    karanb192/itr-wala

    File Indian income tax returns (ITR) for FY 2025-26 / AY 2026-27.

    871 GitHub stars~3.6k tokensUpdated 4 days ago
    Business, Finance & HRAuto-check passed
  • Tushare Data

    zillionare/zillionare

    面向中文自然语言的 Tushare 数据研究技能。用于把“看看这只股票最近怎么样”“帮我查财报趋势”“最近哪个板块最强”“北向资金在买什么”“给我导出一份行情数据”这类请求,转成可执行的数据获取、清洗、对比、筛选、导出与简要分析流程。适用于 A 股、指数、ETF/基金、财务、估值、资金流、公告新闻、板块概念与宏观数据等研究场景。

    319 GitHub starsUsed in 2 repos~2.3k tokens
    Business, Finance & HRAuto-check passed

More from PlamenTSV/plamen

All 87 skills in this repo
  • Audit Prep

    PlamenTSV/plamen

    Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project…

    303 GitHub stars~3.7k tokensUpdated 12 days ago
    Auto-check passed
  • Verification Protocol

    PlamenTSV/plamen

    Trigger Pattern Always (used by all verifier agents) - Inject Into security-verifier agents (Phase 5)

    303 GitHub stars~3.5k tokensUpdated 12 days ago
    Auto-check passed
  • Ability Analysis

    PlamenTSV/plamen

    Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth agents, depth agents

    303 GitHub stars~3.3k tokensUpdated 12 days ago
    Auto-check passed
  • Ability Analysis

    PlamenTSV/plamen

    Trigger Pattern Always (Sui Move) -- foundational security check - Inject Into Breadth agents, depth agents

    303 GitHub stars~3.2k tokensUpdated 12 days ago
    Auto-check passed
  • Account Lifecycle

    PlamenTSV/plamen

    Trigger Pattern ACCOUNTCLOSING flag detected (close/CloseAccount usage) - Inject Into Breadth agents, depth agents

    303 GitHub stars~1.2k tokensUpdated 12 days ago
    Auto-check passed
  • Account Validation

    PlamenTSV/plamen

    Trigger Pattern Always required for Solana audits - Inject Into Breadth agents, depth agents

    303 GitHub stars~1.7k tokensUpdated 12 days ago
    Auto-check passed

Questions about Token Flow Tracing

What does Token Flow Tracing do?

Trigger Pattern BALANCEDEPENDENT flag (required) - Inject Into Depth-token-flow, breadth agents. Token Flow Tracing is an agent skill from PlamenTSV/plamen.

When should I use Token Flow Tracing?

Token Flow Tracing fits situations like: pattern BALANCEDEPENDENT flag (required) - Inject Into Depth-token-flow.

How do I install Token Flow Tracing in Claude Code?

Run `npx skills add PlamenTSV/plamen --skill token-flow-tracing -a claude-code`. Or copy the skill folder (agents/skills/sui/token-flow-tracing in PlamenTSV/plamen) into .claude/skills/token-flow-tracing in your project. Claude Code loads it when a task matches its description.

How do I install Token Flow Tracing in Codex?

Run `npx skills add PlamenTSV/plamen --skill token-flow-tracing -a codex`. Or copy the skill folder (agents/skills/sui/token-flow-tracing in PlamenTSV/plamen) into .agents/skills/token-flow-tracing in your project. Codex loads it when a task matches its description.

Can I use Token Flow Tracing in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PlamenTSV/plamen --skill token-flow-tracing -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/token-flow-tracing, .gemini/skills/token-flow-tracing, .github/skills/token-flow-tracing and .opencode/skills/token-flow-tracing in your project.

What does Token Flow Tracing need to run?

Going by SKILL.md and its folder, Token Flow Tracing needs credentials named ATTACKER_TOKEN. Our summary lists: A credential in ATTACKER_TOKEN.

Does Token Flow Tracing access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Token Flow Tracing safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Token Flow Tracing use?

Token Flow Tracing is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Token Flow Tracing use?

About 3.4k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Token Flow Tracing?

Skills that share tags, products or a category with Token Flow Tracing: Technical Analyst (tradermonty/claude-trading-skills, 3k stars), Creating Financial Models (Chen-zexi/open-ptc-agent, 729 stars), Stock API (zhangxiangliang/stock-api, 2k stars) and Theme Detector (tradermonty/claude-trading-skills, 3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Token Flow Tracing?

PlamenTSV (a GitHub user) maintains it in PlamenTSV/plamen, which has 303 GitHub stars. The repository holds 87 skills in this directory. The repository was last updated on September 26, 2026.

Source: PlamenTSV/plamen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.