Install the "zero-state-return" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/aptos/zero-state-return into .claude/skills/zero-state-return/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "zero-state-return", then confirm the skill loads.
Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
skills CLI
$ npx skills add PlamenTSV/plamen --skill zero-state-return -a codex
Project install goes to .agents/skills/; add -g for ~/.codex/skills/.
Install the "zero-state-return" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/aptos/zero-state-return into .agents/skills/zero-state-return/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "zero-state-return", then confirm the skill loads.
Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add PlamenTSV/plamen --skill zero-state-return -a cursor
Project install goes to .agents/skills/; add -g for ~/.cursor/skills/.
Install the "zero-state-return" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/aptos/zero-state-return into .cursor/skills/zero-state-return/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "zero-state-return", then confirm the skill loads.
Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
skills CLI
$ npx skills add PlamenTSV/plamen --skill zero-state-return -a gemini-cli
Project install goes to .agents/skills/; add -g for ~/.gemini/skills/.
Install the "zero-state-return" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/aptos/zero-state-return into .gemini/skills/zero-state-return/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "zero-state-return", then confirm the skill loads.
Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
skills CLI
$ npx skills add PlamenTSV/plamen --skill zero-state-return -a github-copilot
Project install goes to .agents/skills/; add -g for ~/.copilot/skills/.
Install the "zero-state-return" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/aptos/zero-state-return into .github/skills/zero-state-return/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "zero-state-return", then confirm the skill loads.
GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add PlamenTSV/plamen --skill zero-state-return -a opencode
OpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
Install the "zero-state-return" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/aptos/zero-state-return into .opencode/skills/zero-state-return/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "zero-state-return", then confirm the skill loads.
OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Facts
Skill name
zero-state-return
GitHub stars
303
Token cost
~2.9k tokens
SKILL.md length
1,147 words
Files
1
Skills in repo
87
Repo updated
First seen
Licence
MIT
At a glance
Trigger Pattern Vault/pool/first-depositor pattern detected - Inject Into Depth-edge-case
Works in 7 steps: Identify Zero-State Transitions → First Depositor Analysis → Return to Zero Analysis → …
Pattern Vault/pool/first-depositor pattern detected - Inject Into Depth-edge-case
SKILL.md covers Overview, 1. Identify Zero-State…, 2. First Depositor Analysis and 3. Return to Zero Analysis, plus 9 more sections
Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
What it does
Zero State Return is an agent skill from PlamenTSV/plamen. Trigger Pattern Vault/pool/first-depositor pattern detected - Inject Into Depth-edge-case
Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
The repository describes itself as: Autonomous Web3 security audit agent for Claude Code. The licence is MIT.
When your agent uses it
Pattern Vault/pool/first-depositor pattern detected - Inject Into Depth-edge-case
Example prompts
“/zero-state-return”
Workflow steps
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 795962b. It shows what the files ask for, not the result of running them.
Tool permissions
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Runs code
No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).
From the folder's file list and the shell code blocks in SKILL.md.
Network
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Credentials
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Context cost
Zero State Return loads about 2.9k tokens when it runs. Until then it costs about 27 tokens; SKILL.md has 1,147 words of instructions outside code blocks.
Always· name and description, kept in context so the agent knows when to use it
~27
When it runs· the whole SKILL.md, loaded when a task matches
~2.9k
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
Safety
Auto-check passed
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Download SKILL.mdSave it as .claude/skills/zero-state-return/SKILL.md (or your agent's skills folder).
name
zero-state-return
description
Trigger Pattern Vault/pool/first-depositor pattern detected - Inject Into Depth-edge-case
ZERO_STATE_RETURN Skill
Trigger Pattern: Vault/pool/first-depositor pattern detected
Inject Into: Depth-edge-case
Purpose: Analyze zero-state transitions in Aptos Move protocols -- initial zero state, return to zero after operations, residual assets, and re-entry vulnerabilities
Overview
This skill covers BOTH initial zero state AND return-to-zero-state analysis:
Protocol initialization and first deposit conditions
Protocol returning to zero after normal operations
Residual assets when supply returns to zero
Re-entry vulnerabilities after full exit
1. Identify Zero-State Transitions
Find all vault/pool/staking mechanisms and their zero-state boundaries:
State
Resource / Variable
Zero Condition
Trigger
Code Location
Total shares
{resource.total_supply}
== 0
All users withdrew/burned
{module:line}
Total assets
{resource.total_assets}
== 0
No funds deposited
{module:line}
Pool liquidity
{resource.reserves}
Both reserves == 0
All LP withdrawn
{module:line}
Staking pool
{resource.total_staked}
== 0
All unstaked
{module:line}
For each state: what is the protocol behavior when this condition is true?
2. First Depositor Analysis
Can the first depositor manipulate share price?
2a. Share Minting Formula at Zero State
Protocol
Formula
When totalShares == 0
First Deposit Behavior
{name}
shares = amount * totalShares / totalAssets
{special case?}
{describe}
Classic first depositor attack on Aptos:
First depositor deposits minimal amount (e.g., 1 unit)
Attacker directly deposits tokens to the protocol's FungibleStore (unsolicited -- bypasses accounting)
Exchange rate inflates: totalAssets increases but totalShares stays at 1
Next depositor receives 0 shares due to rounding (their deposit amount < inflated share price)
First depositor withdraws, capturing the second depositor's funds
Checks:
Is there a minimum first deposit requirement?
Does the protocol use virtual shares/assets (e.g., add 1 to both numerator and denominator)?
Is there a dead shares mechanism (burn initial shares to zero address)?
Can unsolicited deposits to the protocol's store inflate totalAssets?
Does the protocol use internal accounting (resistant) or direct balance queries (vulnerable)?
2b. First Deposit Protection Mechanisms
Protection
Present?
Implementation
Bypass Possible?
Minimum first deposit
YES/NO
{code ref}
{analysis}
Virtual shares/assets offset
YES/NO
{code ref}
{analysis}
Dead shares (initial mint to zero)
YES/NO
{code ref}
{analysis}
Internal accounting (not balance-based)
YES/NO
{code ref}
{analysis}
Decimal offset in share calculation
YES/NO
{code ref}
{analysis}
3. Return to Zero Analysis
After normal operations, can the protocol return to zero state?
3a. Return-to-Zero Scenarios
Scenario
Trigger
Residual State After
Re-entry Safe?
All shares redeemed
Last user withdraws
{what remains?}
YES/NO
Emergency withdraw
Admin drains
{what remains?}
YES/NO
All stakers unstake
Last unstake
{what remains?}
YES/NO
Pool fully drained
All LP removed
{what remains?}
YES/NO
3b. Can Total Shares Reach Exactly Zero?
Trace the withdrawal/burn path:
Can the last user withdraw ALL their shares? (no minimum balance lock?)
Does the protocol enforce a minimum share amount that prevents reaching zero?
If dead shares exist, totalShares never reaches 0 -- is this protection consistent?
4. Residual Asset Check
When supply returns to zero, check for stranded value:
4a. Accrued Rewards
Reward Source
Persists When totalShares = 0?
Claimable By Next Depositor?
Amount Bounded?
{reward_source}
YES/NO
YES/NO
{max amount or UNBOUNDED}
If rewards persist AND next depositor can claim -> FINDING (severity based on amount).
4b. Unclaimed Fees
Fee Type
Persists When totalShares = 0?
Captured By Next Depositor?
Reconciliation Mechanism?
{fee_type}
YES/NO
YES/NO
{mechanism or NONE}
4c. Dust Balances
Can dust (sub-unit amounts) remain in FungibleStore after all withdrawals?
Does dust affect exchange rate calculations on re-entry? (e.g., totalAssets = 1 wei, totalShares = 0)
Does the protocol handle totalAssets > 0 AND totalShares == 0 explicitly?
4d. Pending Operations
Are there pending withdrawals/claims that persist after zero state?
What happens to in-flight multi-step operations when supply hits zero?
Are there resources or objects that reference the pool/vault state that become orphaned?
5. Re-Entry Vulnerability Analysis
Does re-entering zero state recreate first-depositor attack conditions?
Scenario
Initial State
Return-to-Zero State
Same Vulnerability?
First depositor attack
totalSupply=0, totalAssets=0
totalSupply=0, totalAssets=X (residual)
WORSE if residual > 0
Exchange rate manipulation
No shares exist
No shares, but balance exists
YES + amplified
Donation attack
Clean state
Dirty state
YES + pre-seeded
Key question: Is the first-deposit protection (from Section 2b) applied ONLY on initial deployment, or does it also trigger when totalShares returns to 0?
Trace the share minting code:
// Pattern: Protection covers initial AND return-to-zero
if (total_shares == 0) {
// First deposit logic with protection
}
// vs Pattern: Protection only on first-ever deposit
if (!initialized) {
// Protection here
} else if (total_shares == 0) {
// NO protection -- vulnerable on return-to-zero
}
Show full SKILL.md (485 more words)Show less
5b. Default/Uninitialized State Values
For each state field used in arithmetic or control flow, check its initial value before any user interaction:
Default zero: Move initializes struct fields to their declared defaults (typically 0 for integers, @0x0 for addresses). If a function uses last_timestamp, start_time, or last_update in subtraction or division BEFORE it has ever been set, the result may be unexpected (e.g., timestamp::now_seconds() - 0 = enormous elapsed time, or division by a value derived from 0).
First-call path: Trace the FIRST invocation of each state-modifying function. Does it assume a prior call already initialized dependent fields?
Check: For each field read in a function, is there a code path where that field still holds its default value (0, @0x0, false)? If yes, does the function behave correctly with that default?
6. Empty Pool Edge Cases
6a. Division by Zero
Expression
When totalShares = 0
Behavior
Impact
amount * totalShares / totalAssets
0 / totalAssets
Returns 0
{impact}
amount * totalAssets / totalShares
amount * X / 0
ABORT
{DoS, broken withdrawal}
rewards / totalShares
rewards / 0
ABORT
{reward distribution broken}
For each division: is there a zero-check guard? If not, what transaction aborts?
6b. Zero-Amount Operations at Zero State
Operation
At Zero State
Result
Expected?
deposit(0) at totalShares=0
{behavior}
{shares issued?}
{analysis}
withdraw(0) at totalShares=0
{behavior}
{aborts?}
{analysis}
claim_rewards() at totalShares=0
{behavior}
{rewards distributed?}
{analysis}
7. Protocol Reset Functions
Check for admin functions that can force zero state:
Function
Access Control
Clears All State?
Residual After Reset
{emergency_withdraw_fn}
{who}
YES/NO
{what remains}
{rescue_tokens_fn}
{who}
YES/NO
{what remains}
{pause + drain_fn}
{who}
YES/NO
{what remains}
{migrate_fn}
{who}
YES/NO
{what remains in old module}
For each: what state persists after the "reset"? Can it be exploited?
Instantiation Parameters
{CONTRACTS} -- Move modules containing vault/pool logic
{SHARE_VARIABLES} -- Variables tracking total shares/supply
{ASSET_VARIABLES} -- Variables tracking total assets/deposits
{SHARE_MINT_FORMULA} -- Share calculation formula at deposit
{FIRST_DEPOSIT_GUARDS} -- Existing first-deposit protections
Finding Template
markdown
**ID**: [ZS-N]
**Severity**: [typically HIGH if funds extractable, MEDIUM if DoS]
**Step Execution**: checkmark1,2,3,4,5,6,7 | x(reasons) | ?(uncertain)
**Rules Applied**: [R4:Y, R10:Y, R11:Y]
**Location**: module::function:LineN
**Title**: [Zero-state type] allows [attack] due to [residual state / missing protection]
**Description**:
- Protocol can reach totalShares=0 via [mechanism]
- When this happens, [state variable] retains value of [amount]
- A new depositor can [exploit path]
**Impact**: [Fund extraction / exchange rate manipulation / DoS]
All sub-checks: 4a rewards, 4b fees, 4c dust, 4d pending
5. Re-Entry Vulnerability Analysis
YES
Y/x/?
Compare initial vs return-to-zero protections
6. Empty Pool Edge Cases
YES
Y/x/?
Division by zero + zero-amount ops
7. Protocol Reset Functions
IF admin reset exists
Y/x(N/A)/?
Cross-Reference Markers
After Section 2 (First Depositor): Cross-reference with TOKEN_FLOW_TRACING.md Section 5 for unsolicited deposit vectors that amplify first-depositor attacks.
After Section 4 (Residual Assets): If residual rewards/fees found, cross-reference with ECONOMIC_DESIGN_AUDIT.md for whether fee/reward accumulation is bounded.
After Section 5 (Re-Entry): If return-to-zero is possible AND first-deposit protection is initial-only -> FINDING (minimum Medium, upgrade to High if unsolicited deposits can amplify).
Zero State Return next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
Detect and defend against indirect prompt injection hidden in web pages, documents, and images consumed by an agent, via content extraction (HTML/PDF/OCR), normalization, and scanning with LLM…
Detects prompt injection using regex signature matching, heuristic scoring for structural anomalies, and DeBERTa-based transformer classification, flagging direct injections (system-prompt…
Scan a source tree for SQL-injection vulnerable patterns: string concatenation into queries, f-string interpolation in SQL, string-format substitution into raw queries, deprecated cursor methods…
Scan a source tree for command-injection vulnerable patterns: shell=True calls in Python subprocess, os.system / os.popen with interpolated strings, Node childprocess.exec with template literals…
Detects and analyzes process injection techniques used by malware including classic DLL injection, process hollowing, APC injection, thread hijacking, and reflective loading.
Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project…
Trigger Pattern Always required for Solana audits - Inject Into Breadth agents, depth agents
303 GitHub stars~1.7k tokensUpdated 11 days ago
Auto-check passed
Questions about Zero State Return
What does Zero State Return do?
Trigger Pattern Vault/pool/first-depositor pattern detected - Inject Into Depth-edge-case. Zero State Return is an agent skill from PlamenTSV/plamen.
When should I use Zero State Return?
Zero State Return fits situations like: pattern Vault/pool/first-depositor pattern detected - Inject Into Depth-edge-case.
How do I install Zero State Return in Claude Code?
Run `npx skills add PlamenTSV/plamen --skill zero-state-return -a claude-code`. Or copy the skill folder (agents/skills/aptos/zero-state-return in PlamenTSV/plamen) into .claude/skills/zero-state-return in your project. Claude Code loads it when a task matches its description.
How do I install Zero State Return in Codex?
Run `npx skills add PlamenTSV/plamen --skill zero-state-return -a codex`. Or copy the skill folder (agents/skills/aptos/zero-state-return in PlamenTSV/plamen) into .agents/skills/zero-state-return in your project. Codex loads it when a task matches its description.
Can I use Zero State Return in Cursor, Gemini CLI or GitHub Copilot?
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PlamenTSV/plamen --skill zero-state-return -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/zero-state-return, .gemini/skills/zero-state-return, .github/skills/zero-state-return and .opencode/skills/zero-state-return in your project.
What does Zero State Return need to run?
SKILL.md names no scripts, command-line tools or credentials: Zero State Return is instructions for the agent only.
Does Zero State Return access the network?
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Is Zero State Return safe to install?
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
What licence does Zero State Return use?
Zero State Return is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
How many tokens does Zero State Return use?
About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
What are the alternatives to Zero State Return?
Skills that share tags, products or a category with Zero State Return: Detecting Anomalous Authentication Patterns (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Detecting Indirect Prompt Injection (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Detecting AI Model Prompt Injection Attacks (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Detecting SQL Injection Patterns (jeremylongshore/tons-of-skills-marketplace, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Who maintains Zero State Return?
PlamenTSV (a GitHub user) maintains it in PlamenTSV/plamen, which has 303 GitHub stars. The repository holds 87 skills in this directory. The repository was last updated on September 26, 2026.
Source: PlamenTSV/plamen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.