Agent skill

Zero State Return

by PlamenTSV in PlamenTSV/plamen

Trigger Pattern Vault/pool/first-depositor pattern detected - Inject Into Depth-edge-case

MITAuto-check passed

Install Zero State Return

skills CLI
$ npx skills add PlamenTSV/plamen --skill zero-state-return -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install PlamenTSV/plamen zero-state-return --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agents/skills/aptos/zero-state-return .claude/skills/zero-state-return && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
zero-state-return
GitHub stars
303
Token cost
~2.9k tokens
SKILL.md length
1,147 words
Files
1
Skills in repo
87
Repo updated
First seen
Licence
MIT

At a glance

Trigger Pattern Vault/pool/first-depositor pattern detected - Inject Into Depth-edge-case

  • Works in 7 steps: Identify Zero-State Transitions → First Depositor Analysis → Return to Zero Analysis → …
  • Pattern Vault/pool/first-depositor pattern detected - Inject Into Depth-edge-case
  • SKILL.md covers Overview, 1. Identify Zero-State…, 2. First Depositor Analysis and 3. Return to Zero Analysis, plus 9 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Zero State Return is an agent skill from PlamenTSV/plamen. Trigger Pattern Vault/pool/first-depositor pattern detected - Inject Into Depth-edge-case

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: Autonomous Web3 security audit agent for Claude Code. The licence is MIT.

When your agent uses it

  • Pattern Vault/pool/first-depositor pattern detected - Inject Into Depth-edge-case

Example prompts

  • “/zero-state-return”

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Identify Zero-State Transitions
  2. First Depositor Analysis
  3. Return to Zero Analysis
  4. Residual Asset Check
  5. Re-Entry Vulnerability Analysis
  6. Empty Pool Edge Cases
  7. Protocol Reset Functions

What it can do on your machine

Read from SKILL.md and the folder at commit 795962b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Zero State Return loads about 2.9k tokens when it runs. Until then it costs about 27 tokens; SKILL.md has 1,147 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~27
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from PlamenTSV/plamen at commit 795962b, republished under its MIT licence (© PlamenTSV). 1,147 words, ~2,890 tokens.

Download SKILL.mdSave it as .claude/skills/zero-state-return/SKILL.md (or your agent's skills folder).
name
zero-state-return
description
Trigger Pattern Vault/pool/first-depositor pattern detected - Inject Into Depth-edge-case

ZERO_STATE_RETURN Skill

Trigger Pattern: Vault/pool/first-depositor pattern detected Inject Into: Depth-edge-case Purpose: Analyze zero-state transitions in Aptos Move protocols -- initial zero state, return to zero after operations, residual assets, and re-entry vulnerabilities

Overview

This skill covers BOTH initial zero state AND return-to-zero-state analysis:

  • Protocol initialization and first deposit conditions
  • Protocol returning to zero after normal operations
  • Residual assets when supply returns to zero
  • Re-entry vulnerabilities after full exit

1. Identify Zero-State Transitions

Find all vault/pool/staking mechanisms and their zero-state boundaries:

StateResource / VariableZero ConditionTriggerCode Location
Total shares{resource.total_supply}== 0All users withdrew/burned{module:line}
Total assets{resource.total_assets}== 0No funds deposited{module:line}
Pool liquidity{resource.reserves}Both reserves == 0All LP withdrawn{module:line}
Staking pool{resource.total_staked}== 0All unstaked{module:line}

For each state: what is the protocol behavior when this condition is true?

2. First Depositor Analysis

Can the first depositor manipulate share price?

2a. Share Minting Formula at Zero State
ProtocolFormulaWhen totalShares == 0First Deposit Behavior
{name}shares = amount * totalShares / totalAssets{special case?}{describe}

Classic first depositor attack on Aptos:

  1. First depositor deposits minimal amount (e.g., 1 unit)
  2. Attacker directly deposits tokens to the protocol's FungibleStore (unsolicited -- bypasses accounting)
  3. Exchange rate inflates: totalAssets increases but totalShares stays at 1
  4. Next depositor receives 0 shares due to rounding (their deposit amount < inflated share price)
  5. First depositor withdraws, capturing the second depositor's funds

Checks:

  • Is there a minimum first deposit requirement?
  • Does the protocol use virtual shares/assets (e.g., add 1 to both numerator and denominator)?
  • Is there a dead shares mechanism (burn initial shares to zero address)?
  • Can unsolicited deposits to the protocol's store inflate totalAssets?
  • Does the protocol use internal accounting (resistant) or direct balance queries (vulnerable)?
2b. First Deposit Protection Mechanisms
ProtectionPresent?ImplementationBypass Possible?
Minimum first depositYES/NO{code ref}{analysis}
Virtual shares/assets offsetYES/NO{code ref}{analysis}
Dead shares (initial mint to zero)YES/NO{code ref}{analysis}
Internal accounting (not balance-based)YES/NO{code ref}{analysis}
Decimal offset in share calculationYES/NO{code ref}{analysis}

3. Return to Zero Analysis

After normal operations, can the protocol return to zero state?

3a. Return-to-Zero Scenarios
ScenarioTriggerResidual State AfterRe-entry Safe?
All shares redeemedLast user withdraws{what remains?}YES/NO
Emergency withdrawAdmin drains{what remains?}YES/NO
All stakers unstakeLast unstake{what remains?}YES/NO
Pool fully drainedAll LP removed{what remains?}YES/NO
3b. Can Total Shares Reach Exactly Zero?

Trace the withdrawal/burn path:

  • Can the last user withdraw ALL their shares? (no minimum balance lock?)
  • Does the protocol enforce a minimum share amount that prevents reaching zero?
  • If dead shares exist, totalShares never reaches 0 -- is this protection consistent?

4. Residual Asset Check

When supply returns to zero, check for stranded value:

4a. Accrued Rewards
Reward SourcePersists When totalShares = 0?Claimable By Next Depositor?Amount Bounded?
{reward_source}YES/NOYES/NO{max amount or UNBOUNDED}

If rewards persist AND next depositor can claim -> FINDING (severity based on amount).

4b. Unclaimed Fees
Fee TypePersists When totalShares = 0?Captured By Next Depositor?Reconciliation Mechanism?
{fee_type}YES/NOYES/NO{mechanism or NONE}
4c. Dust Balances
  • Can dust (sub-unit amounts) remain in FungibleStore after all withdrawals?
  • Does dust affect exchange rate calculations on re-entry? (e.g., totalAssets = 1 wei, totalShares = 0)
  • Does the protocol handle totalAssets > 0 AND totalShares == 0 explicitly?
4d. Pending Operations
  • Are there pending withdrawals/claims that persist after zero state?
  • What happens to in-flight multi-step operations when supply hits zero?
  • Are there resources or objects that reference the pool/vault state that become orphaned?

5. Re-Entry Vulnerability Analysis

Does re-entering zero state recreate first-depositor attack conditions?

ScenarioInitial StateReturn-to-Zero StateSame Vulnerability?
First depositor attacktotalSupply=0, totalAssets=0totalSupply=0, totalAssets=X (residual)WORSE if residual > 0
Exchange rate manipulationNo shares existNo shares, but balance existsYES + amplified
Donation attackClean stateDirty stateYES + pre-seeded

Key question: Is the first-deposit protection (from Section 2b) applied ONLY on initial deployment, or does it also trigger when totalShares returns to 0?

Trace the share minting code:

// Pattern: Protection covers initial AND return-to-zero
if (total_shares == 0) {
    // First deposit logic with protection
}

// vs Pattern: Protection only on first-ever deposit
if (!initialized) {
    // Protection here
} else if (total_shares == 0) {
    // NO protection -- vulnerable on return-to-zero
}
Show full SKILL.md (485 more words)Show less

5b. Default/Uninitialized State Values

For each state field used in arithmetic or control flow, check its initial value before any user interaction:

  • Default zero: Move initializes struct fields to their declared defaults (typically 0 for integers, @0x0 for addresses). If a function uses last_timestamp, start_time, or last_update in subtraction or division BEFORE it has ever been set, the result may be unexpected (e.g., timestamp::now_seconds() - 0 = enormous elapsed time, or division by a value derived from 0).
  • First-call path: Trace the FIRST invocation of each state-modifying function. Does it assume a prior call already initialized dependent fields?
  • Check: For each field read in a function, is there a code path where that field still holds its default value (0, @0x0, false)? If yes, does the function behave correctly with that default?

6. Empty Pool Edge Cases

6a. Division by Zero
ExpressionWhen totalShares = 0BehaviorImpact
amount * totalShares / totalAssets0 / totalAssetsReturns 0{impact}
amount * totalAssets / totalSharesamount * X / 0ABORT{DoS, broken withdrawal}
rewards / totalSharesrewards / 0ABORT{reward distribution broken}

For each division: is there a zero-check guard? If not, what transaction aborts?

6b. Zero-Amount Operations at Zero State
OperationAt Zero StateResultExpected?
deposit(0) at totalShares=0{behavior}{shares issued?}{analysis}
withdraw(0) at totalShares=0{behavior}{aborts?}{analysis}
claim_rewards() at totalShares=0{behavior}{rewards distributed?}{analysis}

7. Protocol Reset Functions

Check for admin functions that can force zero state:

FunctionAccess ControlClears All State?Residual After Reset
{emergency_withdraw_fn}{who}YES/NO{what remains}
{rescue_tokens_fn}{who}YES/NO{what remains}
{pause + drain_fn}{who}YES/NO{what remains}
{migrate_fn}{who}YES/NO{what remains in old module}

For each: what state persists after the "reset"? Can it be exploited?

Instantiation Parameters

{CONTRACTS}              -- Move modules containing vault/pool logic
{SHARE_VARIABLES}        -- Variables tracking total shares/supply
{ASSET_VARIABLES}        -- Variables tracking total assets/deposits
{SHARE_MINT_FORMULA}     -- Share calculation formula at deposit
{FIRST_DEPOSIT_GUARDS}   -- Existing first-deposit protections

Finding Template

markdown
**ID**: [ZS-N]
**Severity**: [typically HIGH if funds extractable, MEDIUM if DoS]
**Step Execution**: checkmark1,2,3,4,5,6,7 | x(reasons) | ?(uncertain)
**Rules Applied**: [R4:Y, R10:Y, R11:Y]
**Location**: module::function:LineN
**Title**: [Zero-state type] allows [attack] due to [residual state / missing protection]
**Description**:
- Protocol can reach totalShares=0 via [mechanism]
- When this happens, [state variable] retains value of [amount]
- A new depositor can [exploit path]
**Impact**: [Fund extraction / exchange rate manipulation / DoS]

Output Schema

FieldRequiredDescription
zero_state_transitionsyesAll paths to zero state
first_depositor_analysisyesFirst deposit attack assessment
residual_assetsyesWhat persists after zero state
re_entry_vulnerabilityyesWhether return-to-zero recreates first-depositor conditions
edge_casesyesDivision by zero and zero-amount operations
findingyesCONFIRMED / REFUTED / CONTESTED
evidenceyesCode locations with line numbers
step_executionyesStatus for each step

Step Execution Checklist (MANDATORY)

SectionRequiredCompleted?Notes
1. Identify Zero-State TransitionsYESY/x/?
2. First Depositor AnalysisYESY/x/?Including 2a formula + 2b protections
3. Return to Zero AnalysisYESY/x/?Including 3a scenarios + 3b exact zero trace
4. Residual Asset CheckYESY/x/?All sub-checks: 4a rewards, 4b fees, 4c dust, 4d pending
5. Re-Entry Vulnerability AnalysisYESY/x/?Compare initial vs return-to-zero protections
6. Empty Pool Edge CasesYESY/x/?Division by zero + zero-amount ops
7. Protocol Reset FunctionsIF admin reset existsY/x(N/A)/?
Cross-Reference Markers

After Section 2 (First Depositor): Cross-reference with TOKEN_FLOW_TRACING.md Section 5 for unsolicited deposit vectors that amplify first-depositor attacks.

After Section 4 (Residual Assets): If residual rewards/fees found, cross-reference with ECONOMIC_DESIGN_AUDIT.md for whether fee/reward accumulation is bounded.

After Section 5 (Re-Entry): If return-to-zero is possible AND first-deposit protection is initial-only -> FINDING (minimum Medium, upgrade to High if unsolicited deposits can amplify).

© PlamenTSV, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in agents/skills/aptos/zero-state-return of PlamenTSV/plamen.

Open the folder on GitHubat commit 795962b

Compare with similar skills

Zero State Return next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Zero State Return compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Zero State Return this skillPlamenTSV/plamen303—~2.9kAutomated safety check: PassMIT
Detecting Anomalous Authentication Patternsmukul975/Anthropic-Cybersecurity-Skills34k—~7.5kAutomated safety check: PassApache-2.0
Detecting Indirect Prompt Injectionmukul975/Anthropic-Cybersecurity-Skills34k—~2.8kAutomated safety check: WarnApache-2.0
Detecting AI Model Prompt Injection Attacksmukul975/Anthropic-Cybersecurity-Skills34k—~1.9kAutomated safety check: WarnApache-2.0
Detecting SQL Injection Patternsjeremylongshore/tons-of-skills-marketplace2.8k—~1.5kAutomated safety check: PassMIT
Detecting Command Injection Patternsjeremylongshore/tons-of-skills-marketplace2.8k—~1.3kAutomated safety check: PassMIT

Similar skills

  • Detecting Anomalous Authentication Patterns

    mukul975/Anthropic-Cybersecurity-Skills

    Detects anomalous authentication patterns using UEBA analytics, statistical baselines, and machine learning models to identify impossible travel, credential stuffing, brute force, password spraying…

    34k GitHub stars~7.5k tokensUpdated 1 mo ago
    Data & AnalyticsAuto-check passed
  • Detecting Indirect Prompt Injection

    mukul975/Anthropic-Cybersecurity-Skills

    Detect and defend against indirect prompt injection hidden in web pages, documents, and images consumed by an agent, via content extraction (HTML/PDF/OCR), normalization, and scanning with LLM…

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    SecurityAuto-check: warnings
  • Detecting AI Model Prompt Injection Attacks

    mukul975/Anthropic-Cybersecurity-Skills

    Detects prompt injection using regex signature matching, heuristic scoring for structural anomalies, and DeBERTa-based transformer classification, flagging direct injections (system-prompt…

    34k GitHub stars~1.9k tokensUpdated 1 mo ago
    SecurityAuto-check: warnings
  • Detecting SQL Injection Patterns

    jeremylongshore/tons-of-skills-marketplace

    Scan a source tree for SQL-injection vulnerable patterns: string concatenation into queries, f-string interpolation in SQL, string-format substitution into raw queries, deprecated cursor methods…

    2.8k GitHub stars~1.5k tokensUpdated today
    SecurityAuto-check passed
  • Detecting Command Injection Patterns

    jeremylongshore/tons-of-skills-marketplace

    Scan a source tree for command-injection vulnerable patterns: shell=True calls in Python subprocess, os.system / os.popen with interpolated strings, Node childprocess.exec with template literals…

    2.8k GitHub stars~1.3k tokensUpdated today
    Testing & QAAuto-check passed
  • Detecting Process Injection Techniques

    mukul975/Anthropic-Cybersecurity-Skills

    Detects and analyzes process injection techniques used by malware including classic DLL injection, process hollowing, APC injection, thread hijacking, and reflective loading.

    34k GitHub stars~3.5k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from PlamenTSV/plamen

All 87 skills in this repo
  • Audit Prep

    PlamenTSV/plamen

    Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project…

    303 GitHub stars~3.7k tokensUpdated 11 days ago
    Auto-check passed
  • Verification Protocol

    PlamenTSV/plamen

    Trigger Pattern Always (used by all verifier agents) - Inject Into security-verifier agents (Phase 5)

    303 GitHub stars~3.5k tokensUpdated 11 days ago
    Auto-check passed
  • Ability Analysis

    PlamenTSV/plamen

    Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth agents, depth agents

    303 GitHub stars~3.3k tokensUpdated 11 days ago
    Auto-check passed
  • Ability Analysis

    PlamenTSV/plamen

    Trigger Pattern Always (Sui Move) -- foundational security check - Inject Into Breadth agents, depth agents

    303 GitHub stars~3.2k tokensUpdated 11 days ago
    Auto-check passed
  • Account Lifecycle

    PlamenTSV/plamen

    Trigger Pattern ACCOUNTCLOSING flag detected (close/CloseAccount usage) - Inject Into Breadth agents, depth agents

    303 GitHub stars~1.2k tokensUpdated 11 days ago
    Auto-check passed
  • Account Validation

    PlamenTSV/plamen

    Trigger Pattern Always required for Solana audits - Inject Into Breadth agents, depth agents

    303 GitHub stars~1.7k tokensUpdated 11 days ago
    Auto-check passed

Questions about Zero State Return

What does Zero State Return do?

Trigger Pattern Vault/pool/first-depositor pattern detected - Inject Into Depth-edge-case. Zero State Return is an agent skill from PlamenTSV/plamen.

When should I use Zero State Return?

Zero State Return fits situations like: pattern Vault/pool/first-depositor pattern detected - Inject Into Depth-edge-case.

How do I install Zero State Return in Claude Code?

Run `npx skills add PlamenTSV/plamen --skill zero-state-return -a claude-code`. Or copy the skill folder (agents/skills/aptos/zero-state-return in PlamenTSV/plamen) into .claude/skills/zero-state-return in your project. Claude Code loads it when a task matches its description.

How do I install Zero State Return in Codex?

Run `npx skills add PlamenTSV/plamen --skill zero-state-return -a codex`. Or copy the skill folder (agents/skills/aptos/zero-state-return in PlamenTSV/plamen) into .agents/skills/zero-state-return in your project. Codex loads it when a task matches its description.

Can I use Zero State Return in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PlamenTSV/plamen --skill zero-state-return -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/zero-state-return, .gemini/skills/zero-state-return, .github/skills/zero-state-return and .opencode/skills/zero-state-return in your project.

What does Zero State Return need to run?

SKILL.md names no scripts, command-line tools or credentials: Zero State Return is instructions for the agent only.

Does Zero State Return access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Zero State Return safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Zero State Return use?

Zero State Return is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Zero State Return use?

About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Zero State Return?

Skills that share tags, products or a category with Zero State Return: Detecting Anomalous Authentication Patterns (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Detecting Indirect Prompt Injection (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Detecting AI Model Prompt Injection Attacks (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Detecting SQL Injection Patterns (jeremylongshore/tons-of-skills-marketplace, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Zero State Return?

PlamenTSV (a GitHub user) maintains it in PlamenTSV/plamen, which has 303 GitHub stars. The repository holds 87 skills in this directory. The repository was last updated on September 26, 2026.

Source: PlamenTSV/plamen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.