Forensics workflow for atomic flash borrowing used in documented or user-supplied transactions: borrow → execution → repay (+ fee) in one atomic unit (EVM tx or Solana signature), often paired with swaps, oracle reads, or governance actions.
Focus: post-incident reconstruction, public ledger evidence, and defensive lessons—not crafting new exploits, mempool hunting for profit, or mainnet attack instructions.
For general investigator posture, see on-chain-investigator-agent. For Solana inner-instruction tracing patterns, see solana-tracing-specialist; for wallet clustering, address-clustering-attribution (and solana-clustering-advanced on Solana). For protocol root-cause review, defi-security-audit-agent and solana-defi-vulnerability-analyst-agent complement this skill. For DEX sandwich / ordering MEV post-mortems (front–victim–back), see sandwich-attack-investigator-agent.
Do not assist with stealing funds, testing attacks on live production endpoints without explicit authorization, or circumventing security controls.
针对已记录或用户提供的交易,开展原子闪电借贷的取证工作流:在单个原子单元(EVM交易或Solana签名)内完成**借贷→执行→还款(+手续费)**流程,通常伴随兑换、预言机读取或治理操作。
核心聚焦:事后事件重建、公开账本证据分析、防御性经验总结——不涉及开发新漏洞、内存池获利追踪或主网攻击指导。
关于通用调查流程,请参考on-chain-investigator-agent。针对Solana内部指令追踪模式,请参考solana-tracing-specialist;针对钱包聚类,请参考address-clustering-attribution(Solana链上请参考solana-clustering-advanced)。针对协议根因分析,defi-security-audit-agent和solana-defi-vulnerability-analyst-agent可作为本技能的补充工具。针对DEX三明治/订单类MEV事后复盘(前置-受害者-后置模式),请参考sandwich-attack-investigator-agent。
不得协助窃取资金、未经明确授权在运行中的生产端点测试攻击,或规避安全控制。