Agent skill

Zero State Return

by PlamenTSV in PlamenTSV/plamen

Trigger Always inject into Arithmetic agent (extends existing ZEROSTATEECONOMICS) - Purpose Check protocol return-to-zero state, not just initial zero state

MITAuto-check passedBackend & APIs

Install Zero State Return

skills CLI
$ npx skills add PlamenTSV/plamen --skill zero-state-return -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install PlamenTSV/plamen zero-state-return --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agents/skills/evm/zero-state-return .claude/skills/zero-state-return && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
zero-state-return
GitHub stars
303
Token cost
~1.5k tokens
SKILL.md length
491 words
Files
1
Skills in repo
87
Repo updated
First seen
Licence
MIT

At a glance

Trigger Always inject into Arithmetic agent (extends existing ZEROSTATEECONOMICS) - Purpose Check protocol return-to-zero state, not just initial zero state

  • Works in 8 steps: Return-to-Zero Scenarios → Residual Asset Check → Re-Entry Vulnerability Analysis → …
  • Always inject into Arithmetic agent (extends existing ZEROSTATEECONOMICS) - Purpose Check protocol return-to-zero state
  • SKILL.md covers Overview, 1. Return-to-Zero Scenarios, 2. Residual Asset Check and 3. Re-Entry Vulnerability…, plus 6 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Zero State Return is an agent skill from PlamenTSV/plamen. Trigger Always inject into Arithmetic agent (extends existing ZEROSTATEECONOMICS) - Purpose Check protocol return-to-zero state, not just initial zero state

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Smart contracts. The repository describes itself as: Autonomous Web3 security audit agent for Claude Code. The licence is MIT.

When your agent uses it

  • Always inject into Arithmetic agent (extends existing ZEROSTATEECONOMICS) - Purpose Check protocol return-to-zero state
  • Not just initial zero state

Example prompts

  • “/zero-state-return”

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Return-to-Zero Scenarios
  2. Residual Asset Check
  3. Re-Entry Vulnerability Analysis
  4. Protocol Reset Functions
  5. Zero-State Return Checklist
  6. Code Patterns to Check
  7. Finding Template
  8. Integration with ZERO_STATE_ECONOMICS

What it can do on your machine

Read from SKILL.md and the folder at commit 795962b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown and solidity).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Zero State Return loads about 1.5k tokens when it runs. Until then it costs about 44 tokens; SKILL.md has 491 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~44
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from PlamenTSV/plamen at commit 795962b, republished under its MIT licence (© PlamenTSV). 491 words, ~1,533 tokens.

Download SKILL.mdSave it as .claude/skills/zero-state-return/SKILL.md (or your agent's skills folder).
name
zero-state-return
description
Trigger Always inject into Arithmetic agent (extends existing ZERO_STATE_ECONOMICS) - Purpose Check protocol return-to-zero state, not just initial zero state

ZERO_STATE_RETURN Skill

Trigger: Always inject into Arithmetic agent (extends existing ZERO_STATE_ECONOMICS) Purpose: Check protocol return-to-zero state, not just initial zero state

Overview

ZERO_STATE_ECONOMICS checks initial zero state. This skill EXTENDS it to cover:

  • Protocol returning to zero after normal operations
  • Residual assets when supply returns to zero
  • Re-entry vulnerabilities after full exit

1. Return-to-Zero Scenarios

After normal operations, can the protocol return to:

StateTriggerCheck
totalSupply == 0All users withdrew/burnedDoes this recreate first-depositor conditions?
totalPooledAmount == 0No funds stakedAre there residual rewards?
Empty validator setAll validators removedCan protocol still function?
Zero liquidityAll LP withdrawnWhat happens to accumulated fees?

2. Residual Asset Check

When supply returns to zero, check for:

2a. Accrued Rewards
  • Do rewards persist when totalSupply = 0?
  • If yes → inflates exchange rate for next depositor
  • Example: Protocol accrues 100 ETH rewards, last user exits, totalSupply = 0, next deposit of 1 wei receives claim to 100 ETH
2b. Unclaimed Fees
  • Are there fee balances that persist?
  • Can first new depositor capture accumulated fees?
  • Example: Protocol fees = 10 ETH, users exit, new depositor claims all fees
2c. Dust Balances
  • Can dust (tiny amounts) affect exchange rate calculations?
  • Example: totalSupply = 0, dust balance = 1 wei, exchange rate undefined or manipulable
2d. Pending Operations
  • Are there pending withdrawals/claims that persist?
  • What happens to in-flight operations when supply hits zero?

3. Re-Entry Vulnerability Analysis

Does re-entering zero state recreate first-depositor attack conditions?

ScenarioInitial StateReturn-to-Zero StateSame Vulnerability?
First depositor attacktotalSupply=0, totalAssets=0totalSupply=0, totalAssets=X (residual)WORSE if residual > 0
Exchange rate manipulationNo shares existNo shares, but balance existsYES + amplified
Donation attackClean stateDirty stateYES + pre-seeded
Show full SKILL.md (216 more words)Show less

4. Protocol Reset Functions

Check for admin functions that can force zero state:

  • emergencyWithdraw() - does it clear ALL state?
  • rescueTokens() - can it create accounting mismatch?
  • pause() + drain() - what state remains after?
  • migrate() - does old contract have residuals?

For each: what state persists after the "reset"?

5. Zero-State Return Checklist

markdown
## Zero-State Return Analysis for [ContractName]

### Can protocol return to zero state?
- [ ] All users can withdraw (no locked funds)
- [ ] All shares can be burned
- [ ] Supply can reach exactly zero

### What persists when supply = 0?
- [ ] Accrued rewards: [amount/none]
- [ ] Protocol fees: [amount/none]
- [ ] Dust balances: [yes/no]
- [ ] Pending operations: [list/none]

### Re-entry vulnerability?
- [ ] Initial zero state protected: [yes/no/how]
- [ ] Return-to-zero state protected: [yes/no/how]
- [ ] Same protection mechanism: [yes/no]

### Exchange rate at return-to-zero:
- [ ] Formula: [show calculation]
- [ ] With residual X: [show calculation]
- [ ] Can attacker inflate rate before re-entry: [yes/no]

5b. Default/Uninitialized State Values

For each state variable used in arithmetic or control flow, check its initial value before any user interaction:

  • Default zero: Solidity initializes to 0. If a function uses lastTimestamp, startTime, or lastUpdate in subtraction or division BEFORE it has ever been set, the result may be unexpected (e.g., block.timestamp - 0 = enormous elapsed time, or division by a value derived from 0).
  • First-call path: Trace the FIRST invocation of each state-modifying function. Does it assume a prior call already initialized dependent variables?
  • Check: For each variable read in a function, is there a code path where that variable still holds its default value (0, address(0), false)? If yes, does the function behave correctly with that default?

6. Code Patterns to Check

solidity
// Pattern 1: Check covers initial zero only
if (totalSupply == 0) {
    return 1e18; // 1:1 rate
}
// QUESTION: What if totalSupply returns to 0 with balance > 0?

// Pattern 2: Exchange rate with balance
uint256 rate = totalAssets / totalSupply;
// QUESTION: What if totalAssets > 0 and totalSupply = 0 (division by zero)
// QUESTION: What if both return to 0 but at different times?

// Pattern 3: First deposit protection
require(totalSupply > 0 || msg.value >= MIN_FIRST_DEPOSIT);
// QUESTION: Does this check exist for RE-deposits after full exit?

7. Finding Template

markdown
**ID**: [AR-N]
**Severity**: [typically HIGH if funds extractable]
**Location**: Contract.sol:LineN
**Title**: Return-to-zero state allows [attack] due to [residual state]
**Description**:
- Protocol can return to totalSupply=0 via [mechanism]
- When this happens, [state variable] retains value of [amount]
- A new depositor can [exploit path]
**Impact**: [Fund extraction / exchange rate manipulation / unfair distribution]
**PoC Scenario**:
1. Users deposit and earn rewards
2. All users withdraw, totalSupply = 0
3. Rewards remain: totalRewards = X
4. Attacker deposits 1 wei
5. Attacker claims X rewards

8. Integration with ZERO_STATE_ECONOMICS

This skill does NOT replace ZERO_STATE_ECONOMICS. It EXTENDS it:

CheckZERO_STATE_ECONOMICSZERO_STATE_RETURN
Initial zero stateYES-
First depositor attackYES-
Return to zero-YES
Residual assets-YES
Re-entry vulnerability-YES

When applying ZERO_STATE_ECONOMICS, ALSO apply ZERO_STATE_RETURN.

© PlamenTSV, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in agents/skills/evm/zero-state-return of PlamenTSV/plamen.

Open the folder on GitHubat commit 795962b

Compare with similar skills

Zero State Return next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Zero State Return compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Zero State Return this skillPlamenTSV/plamen303—~1.5kAutomated safety check: PassMIT
Fizz Convertpashov/skills1.2k2 repos~3.7kAutomated safety check: PassMIT
Solana Devsolana-foundation/solana-dev-skill574—~3.8kAutomated safety check: PassMIT
Feynman Auditor0xiehnnkta/nemesis-auditor2431 repos~11kAutomated safety check: PassMIT
Smart Contract Auditgreatpie/smart-contract-audit-skill101—~1.1kAutomated safety check: PassNone
RadarAuditware/radar154—~2.1kAutomated safety check: PassGPL-3.0

Similar skills

  • Fizz Convert

    pashov/skills

    Convert English-language properties in PROPERTIES.md (produced by the Fizz skill) into Solidity assertions inside the existing fuzz harness, then flip their checkboxes.

    1.2k GitHub starsUsed in 2 repos~3.7k tokens
    Backend & APIsAuto-check passed
  • Solana Dev

    solana-foundation/solana-dev-skill

    A skill your agent uses when user asks to "build a Solana dapp", "write an Anchor program", "create a token", "debug Solana errors", "set up wallet connection", "test my Solana program", "fuzz my…

    574 GitHub stars~3.8k tokensUpdated today
    Backend & APIsAuto-check passed
  • Feynman Auditor

    0xiehnnkta/nemesis-auditor

    Deep business logic bug finder using the Feynman technique. An agent skill from 0xiehnnkta/nemesis-auditor.

    243 GitHub starsUsed in 1 repo~11k tokens
    Backend & APIsAuto-check passed
  • Smart Contract Audit

    greatpie/smart-contract-audit-skill

    Script-backed, out-of-box auditing workflow for Solidity/EVM repositories based on EVMbench detect/patch/exploit methodology.

    101 GitHub stars~1.1k tokensUpdated 7 mo ago
    Backend & APIsAuto-check passed
  • Radar

    Auditware/radar

    Use radar for smart contract security analysis, AST generation, and detection template development.

    154 GitHub stars~2.1k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Solidity Auditor

    Gabson0x/bountyforge

    Security audit of Solidity code while you develop. An agent skill from Gabson0x/bountyforge.

    443 GitHub stars~3.7k tokensUpdated 21 days ago
    Backend & APIsAuto-check passed

More from PlamenTSV/plamen

All 87 skills in this repo
  • Audit Prep

    PlamenTSV/plamen

    Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project…

    303 GitHub stars~3.7k tokensUpdated 11 days ago
    Auto-check passed
  • Verification Protocol

    PlamenTSV/plamen

    Trigger Pattern Always (used by all verifier agents) - Inject Into security-verifier agents (Phase 5)

    303 GitHub stars~3.5k tokensUpdated 11 days ago
    Auto-check passed
  • Ability Analysis

    PlamenTSV/plamen

    Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth agents, depth agents

    303 GitHub stars~3.3k tokensUpdated 11 days ago
    Auto-check passed
  • Ability Analysis

    PlamenTSV/plamen

    Trigger Pattern Always (Sui Move) -- foundational security check - Inject Into Breadth agents, depth agents

    303 GitHub stars~3.2k tokensUpdated 11 days ago
    Auto-check passed
  • Account Lifecycle

    PlamenTSV/plamen

    Trigger Pattern ACCOUNTCLOSING flag detected (close/CloseAccount usage) - Inject Into Breadth agents, depth agents

    303 GitHub stars~1.2k tokensUpdated 11 days ago
    Auto-check passed
  • Account Validation

    PlamenTSV/plamen

    Trigger Pattern Always required for Solana audits - Inject Into Breadth agents, depth agents

    303 GitHub stars~1.7k tokensUpdated 11 days ago
    Auto-check passed

Categories

Questions about Zero State Return

What does Zero State Return do?

Trigger Always inject into Arithmetic agent (extends existing ZEROSTATEECONOMICS) - Purpose Check protocol return-to-zero state, not just initial zero state. Zero State Return is an agent skill from PlamenTSV/plamen.

When should I use Zero State Return?

Zero State Return fits situations like: always inject into Arithmetic agent (extends existing ZEROSTATEECONOMICS) - Purpose Check protocol return-to-zero state; not just initial zero state.

How do I install Zero State Return in Claude Code?

Run `npx skills add PlamenTSV/plamen --skill zero-state-return -a claude-code`. Or copy the skill folder (agents/skills/evm/zero-state-return in PlamenTSV/plamen) into .claude/skills/zero-state-return in your project. Claude Code loads it when a task matches its description.

How do I install Zero State Return in Codex?

Run `npx skills add PlamenTSV/plamen --skill zero-state-return -a codex`. Or copy the skill folder (agents/skills/evm/zero-state-return in PlamenTSV/plamen) into .agents/skills/zero-state-return in your project. Codex loads it when a task matches its description.

Can I use Zero State Return in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PlamenTSV/plamen --skill zero-state-return -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/zero-state-return, .gemini/skills/zero-state-return, .github/skills/zero-state-return and .opencode/skills/zero-state-return in your project.

What does Zero State Return need to run?

SKILL.md names no scripts, command-line tools or credentials: Zero State Return is instructions for the agent only.

Does Zero State Return access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Zero State Return safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Zero State Return use?

Zero State Return is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Zero State Return use?

About 1.5k tokens (SKILL.md is roughly 6.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Zero State Return?

Skills that share tags, products or a category with Zero State Return: Fizz Convert (pashov/skills, 1.2k stars), Solana Dev (solana-foundation/solana-dev-skill, 574 stars), Feynman Auditor (0xiehnnkta/nemesis-auditor, 243 stars) and Smart Contract Audit (greatpie/smart-contract-audit-skill, 101 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Zero State Return?

PlamenTSV (a GitHub user) maintains it in PlamenTSV/plamen, which has 303 GitHub stars. The repository holds 87 skills in this directory. The repository was last updated on September 26, 2026.

Source: PlamenTSV/plamen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.