Agent skill

Crypto Audit

by briiirussell in briiirussell/cybersecurity-skills

Audit cryptography implementation — algorithm choice, key sizes, KDF parameters, IV/nonce handling, signature verification, randomness, TLS configuration, and key rotation.

MITAuto-check: notesSecurity

Install Crypto Audit

skills CLI
$ npx skills add briiirussell/cybersecurity-skills --skill crypto-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install briiirussell/cybersecurity-skills crypto-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/briiirussell/cybersecurity-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/crypto-audit .claude/skills/crypto-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
crypto-audit
GitHub stars
413
Token cost
~2.8k tokens
SKILL.md length
1,273 words
Files
1
Skills in repo
25
Repo updated
First seen
Licence
MIT

At a glance

Audit cryptography implementation — algorithm choice, key sizes, KDF parameters, IV/nonce handling, signature verification, randomness, TLS configuration, and key rotation.

  • The user mentions crypto review
  • SKILL.md covers Don't roll your own, Audit Checklist, Verify Fixes at Runtime and Output Format, plus 2 more sections
  • Calls curl
  • Cryptography audit

What it does

Crypto Audit is an agent skill from briiirussell/cybersecurity-skills. Audit cryptography implementation — algorithm choice, key sizes, KDF parameters, IV/nonce handling, signature verification, randomness, TLS configuration, and key rotation. Deeper than owasp-audit A02. Use when the user mentions 'crypto review,' 'cryptography audit,' 'encryption review,' 'KDF,' 'PBKDF2,' 'Argon2,' 'bcrypt cost,' 'IV reuse,' 'nonce reuse,' 'AES mode,' 'AES-GCM,' 'AES-ECB,' 'signature verification,' 'TLS configuration,' 'cipher suites,' 'key rotation,' 'libsodium,' 'BoringSSL,' or 'is this crypto…

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Cryptography, Webhooks and Web application vulnerabilities. The repository describes itself as: Cybersecurity skills for AI coding agents (Claude Code, Cursor, Codex). The licence is MIT.

When your agent uses it

  • The user mentions crypto review
  • Cryptography audit
  • Encryption review
  • Signature verification

Example prompts

  • “crypto review,”
  • “cryptography audit,”
  • “encryption review,”
  • “/crypto-audit”

Requirements

  • Python 3
  • Pre-approved tools (allowed-tools): Read, Grep, Glob, Bash, WebSearch

What it can do on your machine

Read from SKILL.md and the folder at commit c9ade03. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep
    • Glob
    • Bash
    • WebSearch

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use curl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Crypto Audit loads about 2.8k tokens when it runs. Until then it costs about 134 tokens; SKILL.md has 1,273 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~134
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Grep, Glob, Bash, WebSearch

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from briiirussell/cybersecurity-skills at commit c9ade03, republished under its MIT licence (© briiirussell). 1,273 words, ~2,771 tokens.

Download SKILL.mdSave it as .claude/skills/crypto-audit/SKILL.md (or your agent's skills folder).
name
crypto-audit
description
Audit cryptography implementation — algorithm choice, key sizes, KDF parameters, IV/nonce handling, signature verification, randomness, TLS configuration, and key rotation. Deeper than owasp-audit A02. Use when the user mentions 'crypto review,' 'cryptography audit,' 'encryption review,' 'KDF,' 'PBKDF2,' 'Argon2,' 'bcrypt cost,' 'IV reuse,' 'nonce reuse,' 'AES mode,' 'AES-GCM,' 'AES-ECB,' 'signature verification,' 'TLS configuration,' 'cipher suites,' 'key rotation,' 'libsodium,' 'BoringSSL,' or 'is this crypto right.'
allowed-tools
Read, Grep, Glob, Bash, WebSearch

Crypto Audit — Cryptography Implementation Review

Audit how cryptography is implemented in an application — algorithm choices, parameters, modes, and the implementation patterns that turn good primitives into broken systems. Deeper than owasp-audit A02 (which catches the obvious "MD5 password" and "VERIFY_NONE" cases). This skill is for the subtler implementation review.

Most crypto failures are not "they used MD5." Most failures are: right primitive, wrong mode (ECB instead of GCM), right algorithm, wrong parameter (PBKDF2 with 1,000 iterations in 2026), right library, wrong call order (init the cipher after the data was loaded).

Cross-references: owasp-audit A02 (baseline) + A07 (timing-safe comparison), secrets-audit (key storage), iam-audit (KMS / HSM patterns).

Don't roll your own

The default audit verdict for any custom encryption scheme is "use libsodium / Tink / WebCrypto instead." There are < 50 people on Earth who can design new crypto safely, and they don't work at your company. Unless an explicit threat model says otherwise, custom crypto is a finding.

Audit Checklist

Algorithm and mode
  • Symmetric: AES-256-GCM or ChaCha20-Poly1305 (authenticated encryption — confidentiality + integrity in one primitive)
  • Reject: AES-ECB (block-pattern leak — identical plaintext → identical ciphertext), AES-CBC without HMAC (unauthenticated; padding oracle attacks), AES-CTR without HMAC (malleable; bit-flip = plaintext-flip), DES / 3DES, RC4, Blowfish (use Twofish or skip altogether)
  • Asymmetric: Ed25519 / X25519 for signatures and key exchange; RSA-OAEP / RSA-PSS at 3072+ bits if compatibility forces RSA; never RSA with PKCS#1 v1.5 padding for encryption (Bleichenbacher); never raw RSA
  • Hashing (general purpose): SHA-256, SHA-3, BLAKE2 / BLAKE3
  • Hashing (passwords) — categorically different problem: Argon2id, scrypt, bcrypt (with cost ≥ 12 for bcrypt; OWASP 2024 floor)
  • MAC: HMAC-SHA256 minimum; never CBC-MAC; never homemade hash(key + message)
  • Grep for: MD5, SHA1 (outside of HMAC-SHA1 in legacy compat), DES, RC4, Blowfish, AES.*ECB, pkcs1_v1_5 (Python), RSA.encrypt without OAEP
Key derivation
  • From a password: Argon2id (memory-hard) or PBKDF2-HMAC-SHA256 with ≥ 600,000 iterations (OWASP 2024) or scrypt with N=2^17, r=8, p=1
  • From a high-entropy secret: HKDF-SHA256 — the right primitive when you have key material and need to derive sub-keys
  • From a low-entropy secret to encryption key: PBKDF2 / Argon2 (treat it as a password)
  • Grep for: PBKDF2 (check iteration count), HKDF, Argon2, scrypt, pbkdf2_hmac (Python; check iterations arg)
IV / nonce handling

Wrong IV / nonce handling is one of the top three sources of "the crypto looks right but actually leaks plaintext."

  • AES-GCM: unique nonce per encryption under the same key. NEVER reuse. If you reuse a GCM nonce with the same key, you give the attacker the XOR of two plaintexts and the ability to forge messages. Use 96-bit random nonces (RFC 5116). For high-volume systems, switch to AES-GCM-SIV (nonce-misuse-resistant)
  • AES-CBC: IV must be unpredictable AND unique. Random 16-byte IV per encryption
  • AES-CTR: counter must never repeat for a (key, counter) pair within the lifetime of the key
  • ChaCha20-Poly1305: unique nonce per message; XChaCha20-Poly1305 has 192-bit nonce so random nonces are safe at scale
  • Grep for: hardcoded IVs (iv = "0000000000000000", iv = bytes(16)), zero-IV constructors, counter resets
  • Specifically grep for: Cipher.getInstance("AES") (Java default is ECB), AES.new(key) (PyCryptodome default is ECB), crypto.createCipher (Node, deprecated, derives IV from key — DON'T)
Authenticated encryption
  • Always use authenticated modes — AES-GCM, ChaCha20-Poly1305, or Encrypt-then-MAC (HMAC-SHA256 over ciphertext)
  • Never decrypt → check MAC; always check MAC → then decrypt (otherwise: padding oracle)
  • If using Encrypt-then-MAC, use separate keys for encryption and authentication (or HKDF-derive both from one master key)
  • Verify the MAC with a constant-time compare (crypto.timingSafeEqual in Node, hmac.compare_digest in Python, subtle.ConstantTimeCompare in Go) — see owasp-audit A07
Signature verification
  • The most common signature-verification bug isn't a broken algorithm — it's not checking the signature at all, or checking the algorithm from the message itself
  • JWT: verify alg is exactly what your code expects. Never call jwt.decode and use the claims without jwt.verify. Many libraries accept alg: none (un-signed) by default — verify the library version doesn't have this
  • Webhook signatures: verify the signature BEFORE doing anything else with the body. Many implementations parse-then-verify, leaving a JSON-parsing attack surface
  • Constant-time comparison for the signature byte string
  • Timestamp tolerance window — accept signatures from within ± 5 minutes (Stripe, GitHub, Slack all do this), not "forever" (replay attack)
  • See owasp-audit A02 type-coercion in signature paths (parseInt → NaN)
  • Grep for: jwt.decode (without subsequent verify), alg: 'none', verify.*sig without timingSafeEqual nearby
Randomness
  • Use: crypto.randomBytes (Node), secrets.token_bytes (Python ≥ 3.6), crypto/rand (Go), SecRandomCopyBytes (iOS), SecureRandom (Java)
  • Never use: Math.random() (Node — Mersenne Twister, predictable), random.random() (Python — same), rand() (C — terrible), arc4random_uniform for crypto (BSD — historical name only, but verify the runtime)
  • For UUIDs, prefer UUID v4 from a CSPRNG (most language stdlibs do this correctly; verify by reading the implementation if it matters)
  • Token / session ID minimum entropy — 128 bits (16 random bytes, base64 → 22 chars) is the floor; 256 bits is the sane default
  • Grep for: Math.random, random.random, rand(, mt_rand (PHP), Random.new (Ruby)
Show full SKILL.md (500 more words)Show less
TLS configuration
  • Versions: TLS 1.3 preferred, TLS 1.2 minimum, refuse TLS 1.0 / 1.1 / SSLv3 / SSLv2
  • Cipher suites (TLS 1.2): ECDHE only, AEAD ciphers only (AES-GCM, ChaCha20-Poly1305). Reject CBC, RC4, NULL, EXPORT, anonymous
  • Certificate validation: VERIFY_PEER, full chain, hostname check enabled (see owasp-audit A02 for managed-service caveat)
  • Certificate pinning: for high-trust connections (mobile apps to your backend, sensitive internal services); pair with backup pin (rotation)
  • HSTS preload: verified every subdomain serves HTTPS first; preload submission is sticky (months to remove)
  • OCSP stapling for performance and privacy
  • Test with: testssl.sh https://target or sslyze --regular target
Key lifecycle
  • Where keys live: HSM / cloud KMS (AWS KMS, GCP Cloud KMS, Azure Key Vault, HashiCorp Vault Transit) — applications request encrypt / decrypt without ever seeing the key material
  • Envelope encryption: per-record data key wrapped by a customer master key — limits blast radius if any single data key is exposed
  • Rotation: master keys annually (or per provider default); data keys per record (no rotation needed — re-encrypt only if compromise suspected). KMS providers handle this if configured
  • Key versioning: every ciphertext records the key ID that encrypted it, so decryption can find the right key after rotation
  • Revocation: how do you stop a compromised key from being used to decrypt? Plan exists, documented, tested
Specific framework patterns
  • Rails: MessageVerifier / MessageEncryptor use modern primitives by default; verify they're configured with a strong key (32 bytes / 256 bits)
  • Django: cryptography.fernet is AES-128-CBC + HMAC-SHA256 (acceptable but not GCM); django.core.signing for short signed values
  • Node/Express: prefer iron-session / cookie-signature over rolling your own
  • iOS: CryptoKit for modern Swift code; CommonCrypto works but has more footguns
  • Android: Tink (Google) is the recommended high-level library; raw JCA has historical AES-ECB defaults

Verify Fixes at Runtime

  • Test encryption / decryption round-trip after every change — silent data corruption is the failure mode of crypto changes
  • For algorithm changes (e.g., bcrypt → Argon2id): plan migration on next user login (rehash from plaintext during auth flow); old hashes need to remain readable until migrated
  • For TLS changes: verify with testssl.sh and curl --tlsv1.3 --tls-max 1.3 https://target (lower-bound TLS version enforcement)
  • For KMS changes: verify the IAM permissions cover both encrypt AND decrypt (common rollout bug: encrypted data, can't decrypt it back)

Output Format

markdown
# Cryptography Implementation Audit
## Project: [name]
## Scope: [components covered]
## Date: [date]

### Summary
[2-3 paragraphs]

### Findings
| ID | Severity | Component | Issue | CWE |
|----|----------|-----------|-------|-----|

### Per-finding detail
[Title, severity, file:line, description, vulnerable snippet, remediation, verification]

### TLS posture (if applicable)
[Output of testssl.sh / sslyze]

### Key inventory
| Key | Purpose | Location | Algorithm | Rotation |
|-----|---------|----------|-----------|----------|

### Recommendations
[Prioritized]

Disposition rule (Fixed / Deferred / Accepted Risk) per owasp-audit.

Boundaries

  • Audit code and configurations the user provides
  • Refuse to help break, weaken, or build backdoors into cryptography
  • For TLS testing — only test endpoints the user has authorization for
  • If the audit surfaces a fundamentally broken design (custom crypto, ROT13-as-protection), the recommendation is "replace, don't patch" — don't try to incrementally improve broken designs
  • Quantum-resistant migration: track NIST PQC standardization but don't recommend specific PQC primitives until they're standardized and library-supported; the field is changing

References

  • NIST SP 800-57 (Key Management)
  • NIST SP 800-131A (Algorithm Transitions)
  • NIST SP 800-175B (Cryptographic Standards Guidelines)
  • NIST FIPS 140-3 (Cryptographic Module Standards)
  • IETF RFC 7525 (TLS Recommendations)
  • OWASP Cryptographic Storage Cheat Sheet
  • OWASP Transport Layer Protection Cheat Sheet
  • "Cryptography Engineering" — Ferguson, Schneier, Kohno (the book to read)
  • "Real-World Cryptography" — David Wong
  • libsodium / Tink / BoringSSL documentation

© briiirussell, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/crypto-audit of briiirussell/cybersecurity-skills.

Open the folder on GitHubat commit c9ade03

Compare with similar skills

Crypto Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Crypto Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Crypto Audit this skillbriiirussell/cybersecurity-skills413—~2.8kAutomated safety check: NotesMIT
Security Reviewgetsentry/skills1k4 repos~2.9kAutomated safety check: NotesCC-BY-SA-4.0
Code Securitysemgrep/skills324—~1.2kAutomated safety check: PassCustom licence
Security Reviewgetsentry/warden418—~1.8kAutomated safety check: PassCustom licence
Security ConvexIgorWarzocha/Opencode-Workflows122—~3.1kAutomated safety check: PassNone
Security Auditjellydn/my-ai-tools123—~2.9kAutomated safety check: NotesMIT

Similar skills

  • Security Review

    getsentry/skills

    Official

    Security code review for vulnerabilities. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.9k tokens
    SecurityAuto-check: notes
  • Code Security

    semgrep/skills

    Official

    Security guidelines for writing secure code. An agent skill from semgrep/skills.

    324 GitHub stars~1.2k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Security Review

    getsentry/warden

    Official

    Finds exploitable application security vulnerabilities in code changes.

    418 GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check passed
  • Security Convex

    IgorWarzocha/Opencode-Workflows

    Review Convex security audit patterns for authentication and authorization.

    122 GitHub stars~3.1k tokensUpdated 8 mo ago
    SecurityAuto-check passed
  • Security Audit

    jellydn/my-ai-tools

    A skill your agent uses when reviewing code for security vulnerabilities, hardening an application, or deriving security requirements from OWASP/ASVS guidance.

    123 GitHub stars~2.9k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Security Review

    github/awesome-copilot

    Official

    AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching…

    40k GitHub starsUsed in 1 repo~2.3k tokens
    SecurityAuto-check: notes

More from briiirussell/cybersecurity-skills

All 25 skills in this repo
  • AI Risk Management

    briiirussell/cybersecurity-skills

    Apply the NIST AI Risk Management Framework (AI RMF 1.0) and adjacent guidance to AI / ML systems — model lifecycle governance, fairness and bias evaluation, robustness, transparency…

    413 GitHub stars~3.7k tokensUpdated 4 mo ago
    Auto-check: notes
  • API Audit

    briiirussell/cybersecurity-skills

    Audit REST, GraphQL, and RPC APIs against the OWASP API Security Top 10 (2023).

    413 GitHub stars~2.8k tokensUpdated 4 mo ago
    Auto-check: notes
  • Breach Patterns

    briiirussell/cybersecurity-skills

    Learn from public breach disclosures — extract the audit question each one implies and check your own stack.

    413 GitHub stars~3.5k tokensUpdated 4 mo ago
    Auto-check: notes
  • Cloud Audit

    briiirussell/cybersecurity-skills

    Audit cloud infrastructure (AWS, GCP, Azure) for misconfigurations, excessive permissions, and security gaps.

    413 GitHub stars~1.3k tokensUpdated 4 mo ago
    Auto-check: notes
  • Container Audit

    briiirussell/cybersecurity-skills

    Audit container images, Dockerfiles, and Kubernetes manifests for misconfigurations, excessive privileges, exposed secrets, and runtime risks.

    413 GitHub stars~2.5k tokensUpdated 4 mo ago
    Auto-check: notes
  • Csf Mapping

    briiirussell/cybersecurity-skills

    Map your security posture against the NIST Cybersecurity Framework 2.0 (Govern, Identify, Protect, Detect, Respond, Recover).

    413 GitHub stars~3k tokensUpdated 4 mo ago
    Auto-check: notes

Categories

Questions about Crypto Audit

What does Crypto Audit do?

Audit cryptography implementation — algorithm choice, key sizes, KDF parameters, IV/nonce handling, signature verification, randomness, TLS configuration, and key rotation. Crypto Audit is an agent skill from briiirussell/cybersecurity-skills. Audit cryptography implementation — algorithm choice, key sizes, KDF parameters, IV/nonce handling, signature verification, randomness, TLS configuration, and key rotation.

When should I use Crypto Audit?

Crypto Audit fits situations like: the user mentions crypto review; cryptography audit; encryption review; signature verification.

How do I install Crypto Audit in Claude Code?

Run `npx skills add briiirussell/cybersecurity-skills --skill crypto-audit -a claude-code`. Or copy the skill folder (skills/crypto-audit in briiirussell/cybersecurity-skills) into .claude/skills/crypto-audit in your project. Claude Code loads it when a task matches its description.

How do I install Crypto Audit in Codex?

Run `npx skills add briiirussell/cybersecurity-skills --skill crypto-audit -a codex`. Or copy the skill folder (skills/crypto-audit in briiirussell/cybersecurity-skills) into .agents/skills/crypto-audit in your project. Codex loads it when a task matches its description.

Can I use Crypto Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add briiirussell/cybersecurity-skills --skill crypto-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/crypto-audit, .gemini/skills/crypto-audit, .github/skills/crypto-audit and .opencode/skills/crypto-audit in your project.

What does Crypto Audit need to run?

Going by SKILL.md and its folder, Crypto Audit needs the command-line tools its instructions call (curl). Our summary lists: Python 3. Its frontmatter pre-approves these tools: Read, Grep, Glob, Bash, WebSearch.

Does Crypto Audit access the network?

SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Crypto Audit safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Crypto Audit use?

Crypto Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Crypto Audit use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Crypto Audit?

Skills that share tags, products or a category with Crypto Audit: Security Review (getsentry/skills, 1k stars), Code Security (semgrep/skills, 324 stars), Security Review (getsentry/warden, 418 stars) and Security Convex (IgorWarzocha/Opencode-Workflows, 122 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Crypto Audit?

briiirussell (a GitHub user) maintains it in briiirussell/cybersecurity-skills, which has 413 GitHub stars. The repository holds 25 skills in this directory. The repository was last updated on May 27, 2026.

Source: briiirussell/cybersecurity-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.