Install the "zero-state-return" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/sui/zero-state-return into .claude/skills/zero-state-return/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "zero-state-return", then confirm the skill loads.
Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
skills CLI
$ npx skills add PlamenTSV/plamen --skill zero-state-return -a codex
Project install goes to .agents/skills/; add -g for ~/.codex/skills/.
Install the "zero-state-return" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/sui/zero-state-return into .agents/skills/zero-state-return/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "zero-state-return", then confirm the skill loads.
Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add PlamenTSV/plamen --skill zero-state-return -a cursor
Project install goes to .agents/skills/; add -g for ~/.cursor/skills/.
Install the "zero-state-return" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/sui/zero-state-return into .cursor/skills/zero-state-return/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "zero-state-return", then confirm the skill loads.
Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
skills CLI
$ npx skills add PlamenTSV/plamen --skill zero-state-return -a gemini-cli
Project install goes to .agents/skills/; add -g for ~/.gemini/skills/.
Install the "zero-state-return" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/sui/zero-state-return into .gemini/skills/zero-state-return/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "zero-state-return", then confirm the skill loads.
Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
skills CLI
$ npx skills add PlamenTSV/plamen --skill zero-state-return -a github-copilot
Project install goes to .agents/skills/; add -g for ~/.copilot/skills/.
Install the "zero-state-return" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/sui/zero-state-return into .github/skills/zero-state-return/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "zero-state-return", then confirm the skill loads.
GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add PlamenTSV/plamen --skill zero-state-return -a opencode
OpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
Install the "zero-state-return" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/sui/zero-state-return into .opencode/skills/zero-state-return/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "zero-state-return", then confirm the skill loads.
OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
SKILL.md covers Overview, 1. Identify Zero-State…, 2. First Depositor Analysis and 3. Return-to-Zero Scenarios, plus 9 more sections
Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
What it does
Zero State Return is an agent skill from PlamenTSV/plamen. Trigger Vault/first-depositor pattern detected - Inject Into Depth-edge-case agent (extends existing ZEROSTATEECONOMICS)
Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
The repository describes itself as: Autonomous Web3 security audit agent for Claude Code. The licence is MIT.
Read from SKILL.md and the folder at commit 795962b. It shows what the files ask for, not the result of running them.
Tool permissions
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Runs code
No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).
From the folder's file list and the shell code blocks in SKILL.md.
Network
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Credentials
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Context cost
Zero State Return loads about 2.7k tokens when it runs. Until then it costs about 35 tokens; SKILL.md has 1,108 words of instructions outside code blocks.
Always· name and description, kept in context so the agent knows when to use it
~35
When it runs· the whole SKILL.md, loaded when a task matches
~2.7k
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
Safety
Auto-check passed
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Trigger: Vault/first-depositor pattern detected
Inject Into: Depth-edge-case agent (extends existing ZERO_STATE_ECONOMICS)
Purpose: Check protocol return-to-zero state in Sui shared objects, not just initial zero state. Covers first depositor manipulation, residual assets, and re-entry after full exit.
Overview
ZERO_STATE_ECONOMICS checks initial zero state. This skill EXTENDS it to cover:
Protocol returning to zero after normal operations
Residual assets in shared objects when supply returns to zero
Re-entry vulnerabilities after full exit
Sui-specific: shared objects persist even when economically empty
1. Identify Zero-State Transitions
State
Trigger
Shared Object Behavior
Check
total_supply == 0
All users withdrew/burned shares
Shared pool object persists
Does this recreate first-depositor conditions?
balance::value(&pool.balance) == 0
No funds deposited
Balance<T> field is zero but exists
Are there residual rewards?
Empty participant set
All participants removed
Shared object fields still allocated
Can protocol still function?
Zero liquidity
All LP withdrawn
Pool shared object persists
What happens to accumulated fees?
Sui-specific: Unlike EVM contracts (which always exist at their address), Sui shared objects CANNOT be deleted -- they persist forever once created. This means a pool/vault that reaches zero state ALWAYS allows re-entry, and its state fields retain their last values.
2. First Depositor Analysis
Can the first depositor manipulate the share price?
2a. Classic First-Depositor Attack (adapted for PTBs)
PTB Attack Sequence:
1. Deposit minimum amount (1 unit) -> receive 1 share
2. Donate large amount to inflate balance (if donation vector exists -- see TOKEN_FLOW_TRACING Section 5)
3. Next depositor's shares are calculated against inflated balance
4. Shares round to 0 or near-0, value captured by attacker
Sui-specific considerations:
Steps 1-2 can happen in the SAME PTB (atomic) if donation is possible
balance::join to the shared pool balance may or may not be accessible
Check: does the protocol enforce a minimum first deposit? (assert!(amount >= MIN_FIRST_DEPOSIT))
Check: does the protocol use virtual shares/offset (e.g., mint initial phantom shares)?
2b. Share Price Calculation
State
Formula
With Residual
Division by Zero?
total_supply = 0, balance = 0
{show formula}
N/A
{YES/NO -- how handled?}
total_supply = 0, balance > 0
{show formula}
{inflated rate?}
{YES/NO}
total_supply > 0, balance = 0
{show formula}
N/A
{YES/NO}
Check: What constant is returned when total_supply = 0? Is it 1:1? Is it configurable? Can it be manipulated?
3. Return-to-Zero Scenarios
After normal operations, can the protocol return to zero?
3a. Full Exit Path
Can ALL users withdraw their full balance? Or do rounding/dust prevent complete exit?
After all withdrawals, what is the state of the shared pool object?
Are there any pending operations (unlocking, vesting) that prevent zero state?
3b. What Persists at Zero State
Persistent State
Value After Full Exit
Impact on Next Depositor
Accumulated rewards
{amount or 0}
{inflates rate for next depositor?}
Protocol fees
{amount or 0}
{captured by next depositor?}
Dust balances
{0 or nonzero}
{affects exchange rate?}
Epoch/timestamp state
{last epoch value}
{stale values used?}
Configuration parameters
{unchanged}
{potentially stale?}
3c. Pending Operations at Zero
Are there pending withdrawal requests that persist?
Are there unclaimed rewards allocated to zero-address or burned shares?
What happens to in-flight operations (epoch transitions, rebalances) when supply hits zero?
4. Residual Asset Check
When supply returns to zero:
4a. Accrued Rewards
Do rewards persist when total_supply = 0?
If yes -> inflates exchange rate for next depositor
Example: Protocol accrues 100 SUI rewards, last user exits, total_supply = 0, next deposit of 1 MIST receives claim to 100 SUI
4b. Unclaimed Fees
Are there fee balances stored in the shared object that persist?
Can first new depositor capture accumulated fees?
Example: Protocol fees = 10 SUI in Balance<SUI>, users exit, new depositor's shares priced against total balance including fees
4c. Dust Balances
Can dust (tiny amounts) remain in the shared object's Balance<T>?
Does balance::split leave remainder when amount cannot be evenly divided?
Do dynamic fields persist that affect calculations?
Are there objects stored in Table, Bag, ObjectTable, ObjectBag that survive full exit?
Can orphaned dynamic field entries affect the next epoch of deposits?
5. Re-Entry Vulnerability Analysis
Does re-entering zero state recreate first-depositor attack conditions?
Scenario
Initial State
Return-to-Zero State
Same Vulnerability?
First depositor attack
total_supply=0, balance=0
total_supply=0, balance=X (residual)
WORSE if residual > 0
Exchange rate manipulation
No shares exist
No shares, but balance exists
YES + amplified
Donation attack
Clean shared object
Dirty shared object
YES + pre-seeded
Key insight: On Sui, shared objects persist indefinitely. A pool that was active, drained, and re-entered has DIFFERENT state than a freshly created pool -- even if both have total_supply = 0.
Show full SKILL.md (412 more words)Show less
5b. Default/Uninitialized State Values
For each state field used in arithmetic or control flow, check its initial value before any user interaction:
Default zero: Move initializes struct fields to their declared defaults (typically 0 for integers, @0x0 for addresses). If a function uses last_timestamp, start_time, or last_update in subtraction or division BEFORE it has ever been set, the result may be unexpected (e.g., clock::timestamp_ms(clock) - 0 = enormous elapsed time, or division by a value derived from 0).
First-call path: Trace the FIRST invocation of each state-modifying function. Does it assume a prior call already initialized dependent fields?
Check: For each field read in a function, is there a code path where that field still holds its default value (0, @0x0, false)? If yes, does the function behave correctly with that default?
6. Protocol Reset Functions
Check for admin functions that can force zero state:
Reset Function
Requires Cap?
Clears ALL State?
Residual After Reset
emergency_withdraw()
{AdminCap/OwnerCap}
{YES/NO -- which fields?}
{list remaining state}
rescue_tokens()
{cap type}
{NO -- only moves tokens}
{accounting mismatch?}
pause()
{cap type}
{NO -- just sets flag}
{all state preserved}
migrate()
{cap type}
{NO -- copies to new object}
{old object residual?}
For each: what state persists in the shared object after the "reset"? Can the shared object be re-entered after reset?
7. Finding Template
markdown
**ID**: [ZS-N]
**Severity**: [typically HIGH if funds extractable]
**Step Execution**: check1,2,3,4,5,6 | x(reasons) | ?(uncertain)
**Rules Applied**: [R10:check, R4:check]
**Location**: module::function:LineN
**Title**: Return-to-zero state allows [attack] due to [residual state]
**Description**:
- Protocol can return to total_supply=0 via [mechanism]
- When this happens, [state variable] retains value of [amount]
- A new depositor can [exploit path]
**Impact**: [Fund extraction / exchange rate manipulation / unfair distribution]
**PoC Scenario**:
1. Users deposit and earn rewards
2. All users withdraw, total_supply = 0
3. Rewards remain in shared object: balance::value = X
4. Attacker deposits 1 MIST
5. Attacker claims X rewards
8. Integration with ZERO_STATE_ECONOMICS
This skill does NOT replace ZERO_STATE_ECONOMICS. It EXTENDS it:
Check
ZERO_STATE_ECONOMICS
ZERO_STATE_RETURN
Initial zero state
YES
-
First depositor attack
YES
-
Return to zero
-
YES
Residual assets
-
YES
Re-entry vulnerability
-
YES
Shared object persistence
-
YES (Sui-specific)
When applying ZERO_STATE_ECONOMICS, ALSO apply ZERO_STATE_RETURN.
Zero State Return next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
Detect and defend against indirect prompt injection hidden in web pages, documents, and images consumed by an agent, via content extraction (HTML/PDF/OCR), normalization, and scanning with LLM…
Detects prompt injection using regex signature matching, heuristic scoring for structural anomalies, and DeBERTa-based transformer classification, flagging direct injections (system-prompt…
Detects and analyzes process injection techniques used by malware including classic DLL injection, process hollowing, APC injection, thread hijacking, and reflective loading.
Detect process injection techniques (T1055) - including DLL injection, process hollowing, and APC injection - by analyzing Sysmon Event IDs 1, 7, 8, 10, and 25 for cross-process memory operations…
Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project…
Trigger Pattern Always required for Solana audits - Inject Into Breadth agents, depth agents
303 GitHub stars~1.7k tokensUpdated 11 days ago
Auto-check passed
Questions about Zero State Return
What does Zero State Return do?
Trigger Vault/first-depositor pattern detected - Inject Into Depth-edge-case agent (extends existing ZEROSTATEECONOMICS). Zero State Return is an agent skill from PlamenTSV/plamen.
When should I use Zero State Return?
Zero State Return fits situations like: vault/first-depositor pattern detected - Inject Into Depth-edge-case agent (extends existing ZEROSTATEECONOMICS).
How do I install Zero State Return in Claude Code?
Run `npx skills add PlamenTSV/plamen --skill zero-state-return -a claude-code`. Or copy the skill folder (agents/skills/sui/zero-state-return in PlamenTSV/plamen) into .claude/skills/zero-state-return in your project. Claude Code loads it when a task matches its description.
How do I install Zero State Return in Codex?
Run `npx skills add PlamenTSV/plamen --skill zero-state-return -a codex`. Or copy the skill folder (agents/skills/sui/zero-state-return in PlamenTSV/plamen) into .agents/skills/zero-state-return in your project. Codex loads it when a task matches its description.
Can I use Zero State Return in Cursor, Gemini CLI or GitHub Copilot?
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PlamenTSV/plamen --skill zero-state-return -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/zero-state-return, .gemini/skills/zero-state-return, .github/skills/zero-state-return and .opencode/skills/zero-state-return in your project.
What does Zero State Return need to run?
SKILL.md names no scripts, command-line tools or credentials: Zero State Return is instructions for the agent only.
Does Zero State Return access the network?
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Is Zero State Return safe to install?
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
What licence does Zero State Return use?
Zero State Return is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
How many tokens does Zero State Return use?
About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
What are the alternatives to Zero State Return?
Skills that share tags, products or a category with Zero State Return: Detecting Anomalous Authentication Patterns (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Detecting Indirect Prompt Injection (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Detecting AI Model Prompt Injection Attacks (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Detecting Process Injection Techniques (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Who maintains Zero State Return?
PlamenTSV (a GitHub user) maintains it in PlamenTSV/plamen, which has 303 GitHub stars. The repository holds 87 skills in this directory. The repository was last updated on September 26, 2026.
Source: PlamenTSV/plamen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.