Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Permit2 Patterns

ASecurity

Detect Permit2 / EIP-2612 lifecycle bugs — signature lifecycle, allowance transfer vs signature transfer confusion, nonce reuse, deadline manipulation, witness-data misuse. Activate on `permit`, `permitTransferFrom`, `IPermit2`, `SignatureTransfer`, `AllowanceTransfer`, `PermitWitnessTransferFrom`, `PermitBatchTransferFrom`.

36 stars
0 votes
0 copies
0 views
Added 10/4/2026
blockchainrustapi

Works with

api

Security Analysis

A100/100

Scanned 10/4/2026

$npx -y skills add iktok90-design/ai-smart-contract-auditor --skill permit2-patterns --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Permit2 Patterns?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Permit2 Patterns
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/iktok90-design-permit2-patterns/badge)](https://www.skillsdirectory.com/skills/iktok90-design-permit2-patterns)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: permit2-patterns
description: Detect Permit2 / EIP-2612 lifecycle bugs — signature lifecycle, allowance transfer vs signature transfer confusion, nonce reuse, deadline manipulation, witness-data misuse. Activate on `permit`, `permitTransferFrom`, `IPermit2`, `SignatureTransfer`, `AllowanceTransfer`, `PermitWitnessTransferFrom`, `PermitBatchTransferFrom`.
---

# Permit2 / EIP-2612 detection

## Background

EIP-2612 (`permit`) — token-native gasless approval, per-token nonce.
Permit2 (Uniswap) — canonical contract bridging legacy ERC20s into the permit world; two APIs:
- **SignatureTransfer** — one-shot, sig consumed atomically.
- **AllowanceTransfer** — persistent allowance with nonce + expiration.

## When this applies

- Routers, swap aggregators, vaults using Permit2 / EIP-2612 for gasless approve flows
- Custom permit implementations
- Apps calling `IPermit2.permitTransferFrom`, `permitWitnessTransferFrom`, `permit`

## Detection patterns

### Permit2 `permitTransferFrom` without amount check (CRITICAL)
```solidity
permit2.permitTransferFrom(permit, transferDetails, owner, signature);
// uses `transferDetails.requestedAmount` — caller-controlled
```
Caller can request `permit.permitted.amount` (the max), regardless of intent. App must enforce the actual transfer amount.

### Witness data ignored (HIGH)
`permitWitnessTransferFrom` includes a user-signed `witness` blob. App must validate it matches the intended action; otherwise sig can be reused with different context.

### SignatureTransfer vs AllowanceTransfer confusion (HIGH)
SignatureTransfer is one-shot. AllowanceTransfer is persistent with nonce + expiration. Mixing → over-approval or replay.

### Allowance not invalidated after one-shot use (HIGH)
Some implementations using AllowanceTransfer don't increment nonce after consumption.

### Missing deadline (HIGH)
Permit sigs without deadline are bearer instruments forever.

### EIP-2612 permit failure swallowed (MEDIUM)
```solidity
try IERC20Permit(token).permit(...) {} catch {}
token.transferFrom(...);   // ← if permit fails, falls back to stale allowance
```
Acceptable IFF the app then validates allowance is sufficient.

### Permit + transferFrom unbundled (MEDIUM — MEV)
Submitting `permit` in one tx then `transferFrom` in another lets a searcher front-run the permit and grief.

### Hardcoded chainId / DOMAIN_SEPARATOR cached (HIGH)
Some EIP-2612 impls cache DOMAIN_SEPARATOR in constructor. Post-chain-fork, this is wrong. Re-derive based on `block.chainid`. See [[signature-replay]].

### DAI-style permit (HIGH)
DAI uses a non-standard permit signature (allowed-bool, no amount). Apps that hit DAI with standard EIP-2612 ABI will revert.

### USDC EIP-3009 (different from EIP-2612) (MEDIUM)
USDC uses `transferWithAuthorization` / `receiveWithAuthorization` instead of permit on most chains. Apps assuming permit-on-USDC break.

### Nonce reuse across signers (HIGH)
Custom permit impls that use a global nonce instead of per-signer nonce → cross-signer collision.

### Bitmap nonce model assumed but not used (HIGH)
Permit2 uses a bitmap for nonces (word index + bit). Custom forks sometimes simplify this and break.

## Severity rubric

| Pattern | Severity |
|---|---|
| `permitTransferFrom` with caller-controlled requestedAmount | **Critical** |
| AllowanceTransfer not invalidating nonce on one-shot use | **High** |
| Sig without deadline | **High** |
| Cached DOMAIN_SEPARATOR not fork-aware | **High** |
| Witness ignored in permitWitnessTransferFrom | **High** |
| Failed permit swallowed, allowance not re-checked | **Medium** |
| Permit + tx unbundled (MEV grief) | **Medium** |
| DAI/USDC-specific sig variant mishandled | **High** |
| Global nonce instead of per-signer | **High** |

## Remediation patterns

- App-side: validate `transferDetails.requestedAmount <= permit.permitted.amount` AND matches intent.
- Bundle `permit` + consuming op in one tx.
- Use Permit2's canonical contracts via OZ / Uniswap reference impls.
- For DAI / USDC: dispatch on token type, use appropriate sig variant.
- For chain forks: re-derive `DOMAIN_SEPARATOR` when chainId changes.

## False-positive notes

- Apps that just call `IERC20Permit.permit(...)` directly and don't trust the result are typically fine.
- Uniswap V4 / Universal Router use Permit2 canonically — audit how they pass requestedAmount.

## Related

- [[signature-replay]]
- [[approval-issues]]
- [[mev-frontrunning]]

Attribution

iktok90-designiktok90-design
View sourceSee grades on GitHubMore from iktok90-design →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Nft Standards

Implement NFT standards (ERC-721, ERC-1155) with proper metadata handling, minting strategies, and marketplace integration. Use when creating NFT contracts, building NFT marketplaces, or implementing digital asset systems.

458250 votes

Nft Standards

Implement NFT standards (ERC-721, ERC-1155) with proper metadata handling, minting strategies, and marketplace integration. Use when creating NFT contracts, building NFT marketplaces, or implementing digital asset systems.

401990 votes

vyper-compiler

Vyper smart contract compiler internals. Use when working on the Vyper compiler codebase — compilation pipeline, Venom IR, semantic analysis, code generation, testing, or contributing. Triggers on vyper compiler development, Venom passes, AST/semantics changes, codegen work, or test writing.

51840 votes

Flash Loan Simulator

Simulate flash loan arbitrage strategies and profitability across DeFi protocols. Use when performing crypto analysis. Trigger with phrases like "analyze crypto", "check blockchain", or "monitor market".

27190 votes

On Chain Analytics

Perform on-chain analysis including whale tracking, token flows, and network activity. Use when performing crypto analysis. Trigger with phrases like "analyze crypto", "check blockchain", or "monitor market".

27190 votes
View all in blockchain →