Agent skill

Oracle Flashloan Analysis

by quillai-network in quillai-network/quillshield_skills

Detects price oracle manipulation and flash loan attack vectors in DeFi smart contracts.

MITAuto-check passedBusiness, Finance & HR

Install Oracle Flashloan Analysis

skills CLI
$ npx skills add quillai-network/quillshield_skills --skill oracle-flashloan-analysis -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install quillai-network/quillshield_skills oracle-flashloan-analysis --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/quillai-network/quillshield_skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/oracle-flashloan-analysis/skills/oracle-flashloan-analysis .claude/skills/oracle-flashloan-analysis && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
oracle-flashloan-analysis
GitHub stars
130
Token cost
~2.8k tokens
SKILL.md length
617 words
Files
3 (incl. references)
Skills in repo
11
Repo updated
First seen
Licence
MIT

At a glance

Detects price oracle manipulation and flash loan attack vectors in DeFi smart contracts.

  • Works in 4 steps: Oracle Source Identification → Oracle Validation Verification → Flash Loan Attack Surface Analysis → …
  • Auditing DeFi protocols that depend on price data
  • SKILL.md covers When to Use, When NOT to Use, Core Concept: The Oracle Trust… and The Four-Phase Detection…, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Oracle Flashloan Analysis is an agent skill from quillai-network/quillshield_skills. Detects price oracle manipulation and flash loan attack vectors in DeFi smart contracts. Classifies oracle trust models (Chainlink, TWAP, spot price, custom), identifies stale price risks, circular price dependencies, and flash loan atomicity exploitation patterns. Use when auditing DeFi protocols that depend on price data, oracle integrations, lending protocols, DEXs, derivatives, or any contract where flash loans could manipulate state within a single transaction.

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/flash-loan-vectors.md` and `references/oracle-types.md`).

It sits in Business, Finance & HR, covering Crypto and DeFi analysis, Banking and insurance and Penetration testing. It works with Uniswap. The repository describes itself as: Structured skills for smart contract security audits. Infers state invariants, detects semantic guard gaps, models flash loan + oracle attack chains, simulates adversarial… The licence is MIT.

When your agent uses it

  • Auditing DeFi protocols that depend on price data
  • Oracle integrations
  • Lending protocols
  • Any contract where flash loans could manipulate state within a single transaction

Example prompts

  • “Use the oracle-flashloan-analysis skill to detect price oracle manipulation and flash loan attack vectors in DeFi smart contracts”
  • “/oracle-flashloan-analysis”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Oracle Source Identification
  2. Oracle Validation Verification
  3. Flash Loan Attack Surface Analysis
  4. Circular Dependency Detection

What it can do on your machine

Read from SKILL.md and the folder at commit 8bdd3c0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are solidity and markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Oracle Flashloan Analysis loads about 2.8k tokens when it runs, and up to ~6.5k if it reads all its reference files. Until then it costs about 124 tokens; SKILL.md has 617 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~124
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from quillai-network/quillshield_skills at commit 8bdd3c0, republished under its MIT licence (© quillai-network). 617 words, ~2,817 tokens.

Download SKILL.mdSave it as .claude/skills/oracle-flashloan-analysis/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
oracle-flashloan-analysis
description
Detects price oracle manipulation and flash loan attack vectors in DeFi smart contracts. Classifies oracle trust models (Chainlink, TWAP, spot price, custom), identifies stale price risks, circular price dependencies, and flash loan atomicity exploitation patterns. Use when auditing DeFi protocols that depend on price data, oracle integrations, lending protocols, DEXs, derivatives, or any contract where flash loans could manipulate state within a single transaction.

Oracle & Flash Loan Analysis

Detect vulnerabilities where external price data can be manipulated or flash loans can exploit protocol logic within a single transaction. These two attack vectors are often combined and represent the most common DeFi attack pattern.

When to Use

  • Auditing any DeFi protocol that reads external price data (lending, DEX, derivatives, yield aggregators)
  • Reviewing Chainlink, Uniswap TWAP, Band Protocol, or custom oracle integrations
  • Analyzing protocols that interact with or are accessible via flash loans
  • Threat modeling for MEV, sandwich attacks, and price manipulation
  • When a protocol uses balanceOf(), pool reserves, or spot prices for critical calculations

When NOT to Use

  • Contracts with no price dependencies or external data feeds
  • Pure access control analysis (use semantic-guard-analysis)
  • State-to-state invariant checking (use state-invariant-detection)

Core Concept: The Oracle Trust Hierarchy

Not all price sources are equally secure. Oracle vulnerabilities stem from the gap between assumed trust and actual manipulation resistance.

Trust Level (highest to lowest):
┌─────────────────────────────────────────────┐
│ Level 5: Multi-oracle consensus + circuit    │
│          breakers + TWAP + staleness checks  │
├─────────────────────────────────────────────┤
│ Level 4: Chainlink with full validation      │
│          (staleness, sequencer, min answers)  │
├─────────────────────────────────────────────┤
│ Level 3: Uniswap V3 TWAP (long window)      │
│          Multi-block manipulation cost        │
├─────────────────────────────────────────────┤
│ Level 2: Uniswap V2 TWAP (short window)     │
│          or Chainlink WITHOUT staleness check │
├─────────────────────────────────────────────┤
│ Level 1: Spot price from single pool         │ ← Manipulable via flash loan
│          or balanceOf() for pricing           │
└─────────────────────────────────────────────┘

The Four-Phase Detection Architecture

Phase 1: Oracle Source Identification

Locate every point where the contract reads external price/value data.

Search for these patterns:

PatternOracle TypeRisk Level
latestRoundData()ChainlinkMedium (depends on validation)
latestAnswer()Chainlink (deprecated)HIGH (no round validation)
observe() / consult()Uniswap TWAPMedium (depends on window)
getReserves()AMM spot priceCRITICAL (flash-loan manipulable)
balanceOf(address(this))Self-balanceCRITICAL (donation attack)
slot0() / sqrtPriceX96Uniswap V3 spotCRITICAL (single-block manipulable)
Custom getPrice()UnknownRequires investigation

Build an Oracle Dependency Map:

Contract: LendingPool
├── borrowLimit() → uses getCollateralPrice()
│   └── getCollateralPrice() → calls chainlinkOracle.latestRoundData()
├── liquidate() → uses getDebtPrice()
│   └── getDebtPrice() → calls uniswapPool.slot0() ← SPOT PRICE!
└── calculateInterest() → uses getUtilizationRate()
    └── getUtilizationRate() → reads internal state (safe)
Phase 2: Oracle Validation Verification

For each oracle source, verify that proper safety checks are in place.

Chainlink Validation Checklist:

solidity
// COMPLETE Chainlink integration
(uint80 roundId, int256 price, , uint256 updatedAt, uint80 answeredInRound) =
    priceFeed.latestRoundData();

require(price > 0, "Invalid price");                    // Check 1: Non-negative
require(updatedAt > 0, "Round not complete");            // Check 2: Round complete
require(answeredInRound >= roundId, "Stale price");      // Check 3: Not stale
require(block.timestamp - updatedAt < HEARTBEAT,         // Check 4: Fresh
        "Price too old");

// L2-specific
require(!sequencerFeed.isDown(), "Sequencer down");      // Check 5: L2 sequencer
require(block.timestamp - sequencerUptime > GRACE,       // Check 6: Grace period
        "Grace period");

Missing Check Severity:

Missing CheckSeverityImpact
price > 0HIGHZero/negative price → infinite borrowing or free liquidations
updatedAt > 0MEDIUMIncomplete round data used
answeredInRound >= roundIdHIGHStale price from previous round
Heartbeat/freshnessHIGHHours-old price during volatile markets
L2 sequencer checkHIGHStale price during L2 outage → unfair liquidations
Price deviation boundsMEDIUMExtreme outlier not filtered

TWAP Validation:

Window length analysis:
  - < 10 minutes: HIGH RISK — manipulable with moderate capital
  - 10-30 minutes: MEDIUM RISK — expensive but feasible multi-block manipulation
  - 30+ minutes: LOWER RISK — requires sustained pool manipulation
  - Check: Is the TWAP window configurable? Can governance reduce it?
Phase 3: Flash Loan Attack Surface Analysis

Identify operations that can be exploited via flash loan atomicity.

Flash Loan Attack Model:

Single Transaction:
  1. Borrow N tokens via flash loan (Aave, dYdX, Balancer)
  2. Manipulate price source (swap in pool, donate to contract)
  3. Exploit protocol at manipulated price (borrow, liquidate, swap)
  4. Reverse manipulation (swap back)
  5. Repay flash loan + fee
  6. Profit = exploited_value - flash_loan_fee - gas

Detection Algorithm:

For each function F that reads price/value data:
  1. Identify the price source S
  2. Can S be manipulated within a single transaction?
     - Spot price from AMM → YES (swap in same tx)
     - balanceOf(address(this)) → YES (donate tokens)
     - Chainlink feed → NO (off-chain updates)
     - TWAP → DEPENDS (short window = risky)
  3. What does F do with the price?
     - Determines borrowing limit → CRITICAL
     - Triggers liquidation → CRITICAL
     - Sets exchange rate → HIGH
     - Informational only → LOW
  4. Is the manipulation profitable?
     - value_extracted - (flash_loan_fee + slippage + gas) > 0 → EXPLOIT VIABLE

Common Flash Loan Attack Patterns:

PatternTargetMethod
Oracle manipulationLending protocolFlash swap in pool → inflate collateral price → over-borrow
Governance attackDAO/votingFlash borrow governance tokens → vote → execute → return
Liquidation manipulationLending protocolFlash swap to crash price → liquidate at discount
Share price inflationVault/ERC4626Flash loan → donate to vault → inflate share price → front-run deposit
Arbitrage amplificationAMM/DEXFlash loan amplifies existing price discrepancy
Show full SKILL.md (221 more words)Show less
Phase 4: Circular Dependency Detection

Find cases where a protocol's pricing depends on its own state, creating exploitable feedback loops.

Circular Dependency Pattern:

Protocol A uses Token X price → from Pool P
Pool P contains Token X + Token Y
Protocol A issues Token X (or affects its supply)

→ CIRCULAR: Protocol A's actions change Token X supply
            → changes Pool P reserves
            → changes Token X price
            → changes Protocol A's valuations

Detection:

For each price oracle call in the contract:
  1. What token/asset is being priced?
  2. Does THIS contract mint, burn, or distribute that token?
  3. Does THIS contract add/remove liquidity from the pricing pool?
  4. Does any action in THIS contract affect the reserves of the pricing pool?

  If YES to any → CIRCULAR DEPENDENCY
  Severity: CRITICAL if the circular path can be exploited atomically

Workflow

Task Progress:
- [ ] Step 1: Identify all oracle/price data sources in the contract
- [ ] Step 2: Classify each source by trust level (Chainlink, TWAP, spot, custom)
- [ ] Step 3: Verify validation checks for each oracle source
- [ ] Step 4: Map flash loan attack surfaces (which operations use manipulable prices?)
- [ ] Step 5: Detect circular price dependencies
- [ ] Step 6: Estimate manipulation cost vs profit (feasibility analysis)
- [ ] Step 7: Score findings and generate report

Output Format

markdown
## Oracle & Flash Loan Analysis Report

### Finding: [Title]

**Function:** `functionName()` at `Contract.sol:L42`
**Category:** [Oracle Manipulation | Stale Price | Flash Loan | Circular Dependency]
**Severity:** [CRITICAL | HIGH | MEDIUM]

**Oracle Source:** `[oracle contract/function]`
**Trust Level:** [1-5 from hierarchy]

**Vulnerability:**
[Description of how the price source can be manipulated or is insufficiently validated]

**Attack Scenario:**
1. Attacker obtains flash loan of [X tokens] from [source]
2. Swaps [amount] in [pool] to manipulate price of [token]
3. Calls `functionName()` which reads manipulated price
4. Extracts [value] from protocol at wrong price
5. Reverses manipulation and repays flash loan
6. Net profit: [amount]

**Missing Validations:**
- [ ] Price > 0 check
- [ ] Staleness check (heartbeat)
- [ ] Round completeness check
- [ ] L2 sequencer check
- [ ] Price deviation bounds

**Recommendation:**
[Specific fix — add TWAP, add Chainlink validation, implement circuit breaker]

Quick Detection Checklist

  • Does any function use getReserves(), slot0(), or balanceOf() for pricing? (Flash-loan manipulable)
  • Does Chainlink integration check for price > 0, staleness, and round completeness?
  • Is the TWAP window long enough to resist multi-block manipulation (> 30 min)?
  • Does the protocol's own token appear in its pricing oracle's pool? (Circular dependency)
  • Can any critical operation (borrow, liquidate, swap) be called in the same transaction as a flash loan?
  • Are there price deviation circuit breakers for extreme moves?
  • On L2: Is the sequencer uptime checked before using price data?

For oracle type details, see {baseDir}/references/oracle-types.md. For flash loan attack patterns, see {baseDir}/references/flash-loan-vectors.md.

Rationalizations to Reject

  • "We use Chainlink, so it's safe" → Only if ALL validation checks are implemented; partial integration is common
  • "Flash loans can't affect our protocol" → Any protocol using manipulable price sources is affected
  • "The TWAP window is 10 minutes" → Multi-block manipulation is feasible for well-funded attackers
  • "Our oracle is a trusted admin feed" → Admin key compromise → arbitrary price → instant drain
  • "The pool is too large to manipulate" → Flash loans provide unlimited capital for single-transaction manipulation
  • "We check if price is non-zero" → Non-zero is necessary but not sufficient; stale/manipulated non-zero prices are dangerous

© quillai-network, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in plugins/oracle-flashloan-analysis/skills/oracle-flashloan-analysis of quillai-network/quillshield_skills.

  • SKILL.md
  • references/flash-loan-vectors.md
  • references/oracle-types.md

Open the folder on GitHubat commit 8bdd3c0

Compare with similar skills

Oracle Flashloan Analysis next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Oracle Flashloan Analysis compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Oracle Flashloan Analysis this skillquillai-network/quillshield_skills130—~2.8kAutomated safety check: PassMIT
Aomi Transactjeremylongshore/tons-of-skills-marketplace2.8k—~2.3kAutomated safety check: PassMIT
Okx Cex Earnokx/agent-skills1872 repos~3.3kAutomated safety check: PassMIT
Aomi Transactsickn33/agentic-awesome-skills47k1 repos~2.3kAutomated safety check: PassMIT
Okx Defi Investnirholas/three.ws229—~4.4kAutomated safety check: PassMIT
Systematic Attackingmtarcure/claude-vibe-squad165—~3.6kAutomated safety check: PassMIT

Similar skills

  • Aomi Transact

    jeremylongshore/tons-of-skills-marketplace

    Build natural-language crypto agents, web3 assistants, and trading bots that read and write EVM chain state.

    2.8k GitHub stars~2.3k tokensUpdated today
    Business, Finance & HRAuto-check passed
  • Okx Cex Earn

    okx/agent-skills

    Manages OKX Simple Earn (flexible savings/lending), Flash Earn, On-chain Earn (staking/DeFi), Dual Investment (DCD/双币赢), and AutoEarn (自动赚币) via the okx CLI.

    187 GitHub starsUsed in 2 repos~3.3k tokens
    Business, Finance & HRAuto-check passed
  • Aomi Transact

    sickn33/agentic-awesome-skills

    Build natural-language crypto/DeFi agents and EVM MCP plugins (Claude Code, Cursor, Codex, Gemini).

    47k GitHub starsUsed in 1 repo~2.3k tokens
    Business, Finance & HRAuto-check passed
  • Okx Defi Invest

    nirholas/three.ws

    OKX-aggregated DeFi discovery and execution — for users who want OKX to find and route to the best protocol WITHOUT naming a specific DApp.

    229 GitHub stars~4.4k tokensUpdated today
    Business, Finance & HRAuto-check passed
  • Systematic Attacking

    mtarcure/claude-vibe-squad

    A skill your agent uses for ALL authorized offensive-security / bug-bounty work — the single method to find, chain, prove, dedup, and package the highest-value (High/Critical) findings across every…

    165 GitHub stars~3.6k tokensUpdated 19 days ago
    SecurityAuto-check passed
  • Defi Amm Security

    affaan-m/ECC

    Security checklist for Solidity AMM contracts, liquidity pools, and swap flows.

    276k GitHub starsUsed in 1 repo~1.3k tokens
    Business, Finance & HRAuto-check passed

More from quillai-network/quillshield_skills

All 11 skills in this repo
  • Behavioral State Analysis

    quillai-network/quillshield_skills

    Token-efficient smart contract security auditing via Behavioral State Analysis (BSA).

    130 GitHub stars~1.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dos Griefing Analysis

    quillai-network/quillshield_skills

    Detects Denial of Service and griefing vulnerabilities in smart contracts.

    130 GitHub stars~3.3k tokensUpdated 6 mo ago
    Auto-check passed
  • External Call Safety

    quillai-network/quillshield_skills

    Detects unsafe external call patterns and token integration vulnerabilities in smart contracts.

    130 GitHub stars~3.1k tokensUpdated 6 mo ago
    Auto-check passed
  • Input Arithmetic Safety

    quillai-network/quillshield_skills

    Detects input validation failures and arithmetic vulnerabilities in smart contracts.

    130 GitHub stars~3.1k tokensUpdated 6 mo ago
    Auto-check passed
  • Proxy Upgrade Safety

    quillai-network/quillshield_skills

    Detects vulnerabilities in upgradeable proxy smart contracts including storage layout collisions, uninitialized implementations, function selector clashing, delegatecall context issues, and upgrade…

    130 GitHub stars~3.2k tokensUpdated 6 mo ago
    Auto-check passed
  • Reentrancy Pattern Analysis

    quillai-network/quillshield_skills

    Systematically detects all reentrancy vulnerability variants in smart contracts — classic, cross-function, cross-contract, and read-only reentrancy.

    130 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed

Works with

Questions about Oracle Flashloan Analysis

What does Oracle Flashloan Analysis do?

Detects price oracle manipulation and flash loan attack vectors in DeFi smart contracts. Oracle Flashloan Analysis is an agent skill from quillai-network/quillshield_skills. Detects price oracle manipulation and flash loan attack vectors in DeFi smart contracts.

When should I use Oracle Flashloan Analysis?

Oracle Flashloan Analysis fits situations like: auditing DeFi protocols that depend on price data; oracle integrations; lending protocols; any contract where flash loans could manipulate state within a single transaction.

How do I install Oracle Flashloan Analysis in Claude Code?

Run `npx skills add quillai-network/quillshield_skills --skill oracle-flashloan-analysis -a claude-code`. Or copy the skill folder (plugins/oracle-flashloan-analysis/skills/oracle-flashloan-analysis in quillai-network/quillshield_skills) into .claude/skills/oracle-flashloan-analysis in your project. Claude Code loads it when a task matches its description.

How do I install Oracle Flashloan Analysis in Codex?

Run `npx skills add quillai-network/quillshield_skills --skill oracle-flashloan-analysis -a codex`. Or copy the skill folder (plugins/oracle-flashloan-analysis/skills/oracle-flashloan-analysis in quillai-network/quillshield_skills) into .agents/skills/oracle-flashloan-analysis in your project. Codex loads it when a task matches its description.

Can I use Oracle Flashloan Analysis in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add quillai-network/quillshield_skills --skill oracle-flashloan-analysis -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/oracle-flashloan-analysis, .gemini/skills/oracle-flashloan-analysis, .github/skills/oracle-flashloan-analysis and .opencode/skills/oracle-flashloan-analysis in your project.

What does Oracle Flashloan Analysis need to run?

SKILL.md names no scripts, command-line tools or credentials: Oracle Flashloan Analysis is instructions for the agent only.

Does Oracle Flashloan Analysis access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Oracle Flashloan Analysis safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Oracle Flashloan Analysis use?

Oracle Flashloan Analysis is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Oracle Flashloan Analysis use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.7k tokens, read only when the agent opens those files.

What are the alternatives to Oracle Flashloan Analysis?

Skills that share tags, products or a category with Oracle Flashloan Analysis: Aomi Transact (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Okx Cex Earn (okx/agent-skills, 187 stars), Aomi Transact (sickn33/agentic-awesome-skills, 47k stars) and Okx Defi Invest (nirholas/three.ws, 229 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Oracle Flashloan Analysis?

quillai-network (a GitHub organization) maintains it in quillai-network/quillshield_skills, which has 130 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on March 30, 2026.

Source: quillai-network/quillshield_skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.