Agent skill

Crypto Best Practices

by Hack23 in Hack23/cia

Implement strong encryption, secure hashing, and proper key management following NIST and OWASP cryptography guidelines

Apache-2.0Auto-check passedSecurity

Install Crypto Best Practices

skills CLI
$ npx skills add Hack23/cia --skill crypto-best-practices -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Hack23/cia crypto-best-practices --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/crypto-best-practices .claude/skills/crypto-best-practices && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
crypto-best-practices
GitHub stars
239
Token cost
~4.9k tokens
SKILL.md length
420 words
Files
1
Skills in repo
78
Repo updated
First seen
Licence
Apache-2.0

At a glance

Implement strong encryption, secure hashing, and proper key management following NIST and OWASP cryptography guidelines

  • Tasks that involve Cryptography
  • SKILL.md covers Purpose, When to Use This Skill, Golden Rules of Cryptography and Password Hashing, plus 9 more sections
  • Calls openssl; needs ENCRYPTION_KEY and AES_ENCRYPTION_KEY

What it does

Crypto Best Practices is an agent skill from Hack23/cia. Implement strong encryption, secure hashing, and proper key management following NIST and OWASP cryptography guidelines

Its SKILL.md is about 4.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Cryptography. The repository describes itself as: Citizen Intelligence Agency. Open-source intelligence platform analyzing Swedish political activities using AI and data visualization. Tracks politicians, government… The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Cryptography

Example prompts

  • “/crypto-best-practices”

Requirements

  • A credential in ENCRYPTION_KEY
  • A credential in AES_ENCRYPTION_KEY

What it can do on your machine

Read from SKILL.md and the folder at commit 6a9797b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • openssl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com
    • csrc.nist.gov
    • cheatsheetseries.owasp.org
    • docs.spring.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • ENCRYPTION_KEY
    • AES_ENCRYPTION_KEY
    • SSL_KEYSTORE_PASSWORD

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Crypto Best Practices loads about 4.9k tokens when it runs. Until then it costs about 35 tokens; SKILL.md has 420 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~35
When it runs · the whole SKILL.md, loaded when a task matches
~4.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Hack23/cia at commit 6a9797b, republished under its Apache-2.0 licence (© Hack23). 420 words, ~4,887 tokens.

Download SKILL.mdSave it as .claude/skills/crypto-best-practices/SKILL.md (or your agent's skills folder).
name
crypto-best-practices
description
Implement strong encryption, secure hashing, and proper key management following NIST and OWASP cryptography guidelines
license
Apache-2.0

Cryptography Best Practices Skill

Purpose

This skill provides guidance on implementing cryptography correctly in the CIA platform, covering encryption, hashing, digital signatures, and key management. It ensures compliance with NIST, OWASP, and Hack23 ISMS cryptography policies.

When to Use This Skill

Apply this skill when:

  • ✅ Encrypting sensitive data at rest (database, files)
  • ✅ Implementing user authentication (password hashing)
  • ✅ Securing data in transit (TLS configuration)
  • ✅ Generating secure tokens or session IDs
  • ✅ Implementing digital signatures
  • ✅ Creating API authentication mechanisms
  • ✅ Managing encryption keys

Golden Rules of Cryptography

Rule #1: Never Roll Your Own Crypto

❌ NEVER IMPLEMENT YOUR OWN:

  • Encryption algorithms
  • Hashing functions
  • Random number generators
  • Cryptographic protocols

✅ ALWAYS USE ESTABLISHED LIBRARIES:

  • Java Cryptography Architecture (JCA)
  • Bouncy Castle (when JCA insufficient)
  • Spring Security Crypto
  • Apache Commons Crypto
Rule #2: Use Strong, Modern Algorithms

APPROVED ALGORITHMS (2024):

Encryption:

  • ✅ AES-256-GCM (preferred for symmetric encryption)
  • ✅ ChaCha20-Poly1305 (alternative to AES)
  • ✅ RSA-4096 (for asymmetric encryption)
  • ❌ DES, 3DES, RC4 (deprecated, insecure)
  • ❌ AES-ECB mode (vulnerable to patterns)

Hashing:

  • ✅ SHA-256, SHA-384, SHA-512 (for general hashing)
  • ✅ bcrypt (cost factor 12+) for passwords
  • ✅ Argon2id (preferred for new implementations)
  • ❌ MD5, SHA-1 (cryptographically broken)

Key Derivation:

  • ✅ PBKDF2 with SHA-256 (100,000+ iterations)
  • ✅ Argon2id (memory-hard, resistant to GPU attacks)
  • ❌ Simple hashing without salt

Password Hashing

Implementation with BCrypt
java
@Configuration
public class PasswordConfig {
    
    @Bean
    public PasswordEncoder passwordEncoder() {
        // BCrypt with strength 12 (2^12 = 4096 rounds)
        return new BCryptPasswordEncoder(12);
    }
}

@Service
public class UserService {
    
    @Autowired
    private PasswordEncoder passwordEncoder;
    
    @Autowired
    private UserRepository userRepository;
    
    public void createUser(String username, String plainPassword) {
        // Hash password before storing
        String hashedPassword = passwordEncoder.encode(plainPassword);
        
        User user = new User();
        user.setUsername(username);
        user.setPassword(hashedPassword);  // Never store plain text!
        
        userRepository.save(user);
    }
    
    public boolean authenticate(String username, String plainPassword) {
        User user = userRepository.findByUsername(username)
            .orElseThrow(() -> new UsernameNotFoundException("User not found"));
        
        // Verify password
        return passwordEncoder.matches(plainPassword, user.getPassword());
    }
    
    public void changePassword(String username, String oldPassword, String newPassword) {
        User user = userRepository.findByUsername(username)
            .orElseThrow(() -> new UsernameNotFoundException("User not found"));
        
        // Verify old password
        if (!passwordEncoder.matches(oldPassword, user.getPassword())) {
            throw new BadCredentialsException("Current password is incorrect");
        }
        
        // Hash and store new password
        user.setPassword(passwordEncoder.encode(newPassword));
        userRepository.save(user);
    }
}
Password Strength Requirements
java
@Component
public class PasswordValidator {
    
    private static final int MIN_LENGTH = 12;
    private static final Pattern UPPERCASE = Pattern.compile("[A-Z]");
    private static final Pattern LOWERCASE = Pattern.compile("[a-z]");
    private static final Pattern DIGIT = Pattern.compile("[0-9]");
    private static final Pattern SPECIAL = Pattern.compile("[!@#$%^&*(),.?\":{}|<>]");
    
    public void validatePassword(String password) throws ValidationException {
        List<String> errors = new ArrayList<>();
        
        if (password == null || password.length() < MIN_LENGTH) {
            errors.add("Password must be at least " + MIN_LENGTH + " characters");
        }
        
        if (!UPPERCASE.matcher(password).find()) {
            errors.add("Password must contain at least one uppercase letter");
        }
        
        if (!LOWERCASE.matcher(password).find()) {
            errors.add("Password must contain at least one lowercase letter");
        }
        
        if (!DIGIT.matcher(password).find()) {
            errors.add("Password must contain at least one digit");
        }
        
        if (!SPECIAL.matcher(password).find()) {
            errors.add("Password must contain at least one special character");
        }
        
        // Check against common passwords
        if (isCommonPassword(password)) {
            errors.add("Password is too common, choose a stronger password");
        }
        
        if (!errors.isEmpty()) {
            throw new ValidationException("Password validation failed: " + 
                String.join(", ", errors));
        }
    }
    
    private boolean isCommonPassword(String password) {
        // Check against list of 10,000 most common passwords
        Set<String> commonPasswords = loadCommonPasswords();
        return commonPasswords.contains(password.toLowerCase());
    }
}

Data Encryption at Rest

AES-256-GCM Encryption
java
@Configuration
public class EncryptionConfig {
    
    @Bean
    public TextEncryptor textEncryptor() {
        String encryptionKey = System.getenv("ENCRYPTION_KEY");
        String salt = System.getenv("ENCRYPTION_SALT");
        
        return Encryptors.text(encryptionKey, salt);
    }
    
    @Bean
    public BytesEncryptor bytesEncryptor() {
        String encryptionKey = System.getenv("ENCRYPTION_KEY");
        String salt = System.getenv("ENCRYPTION_SALT");
        
        return Encryptors.stronger(encryptionKey, salt);
    }
}

@Service
public class DataEncryptionService {
    
    @Autowired
    private BytesEncryptor encryptor;
    
    /**
     * Encrypt sensitive data before storing in database
     */
    public byte[] encrypt(String plaintext) {
        if (plaintext == null) return null;
        return encryptor.encrypt(plaintext.getBytes(StandardCharsets.UTF_8));
    }
    
    /**
     * Decrypt data retrieved from database
     */
    public String decrypt(byte[] ciphertext) {
        if (ciphertext == null) return null;
        byte[] decrypted = encryptor.decrypt(ciphertext);
        return new String(decrypted, StandardCharsets.UTF_8);
    }
}

// Entity with encrypted fields
@Entity
@Table(name = "politician")
public class Politician {
    
    @Id
    private String id;
    
    private String firstName;  // Public data - not encrypted
    
    private String lastName;   // Public data - not encrypted
    
    // Sensitive field - encrypted in database
    @Column(name = "personal_id_encrypted")
    private byte[] personalIdEncrypted;
    
    @Column(name = "email_encrypted")
    private byte[] emailEncrypted;
    
    @Transient
    private transient DataEncryptionService encryptionService;
    
    // Getter/Setter for encrypted field
    public String getPersonalId() {
        return encryptionService.decrypt(personalIdEncrypted);
    }
    
    public void setPersonalId(String personalId) {
        this.personalIdEncrypted = encryptionService.encrypt(personalId);
    }
    
    public String getEmail() {
        return encryptionService.decrypt(emailEncrypted);
    }
    
    public void setEmail(String email) {
        this.emailEncrypted = encryptionService.encrypt(email);
    }
}
Custom AES-GCM Implementation (Advanced)
java
@Service
public class AesGcmEncryption {
    
    private static final String ALGORITHM = "AES/GCM/NoPadding";
    private static final int GCM_TAG_LENGTH = 128;
    private static final int GCM_IV_LENGTH = 12;
    private static final int AES_KEY_SIZE = 256;
    
    private final SecretKey secretKey;
    
    public AesGcmEncryption() throws Exception {
        // Load key from secure key management system
        this.secretKey = loadKey();
    }
    
    public byte[] encrypt(byte[] plaintext) throws Exception {
        // Generate random IV (nonce)
        byte[] iv = generateIV();
        
        Cipher cipher = Cipher.getInstance(ALGORITHM);
        GCMParameterSpec spec = new GCMParameterSpec(GCM_TAG_LENGTH, iv);
        cipher.init(Cipher.ENCRYPT_MODE, secretKey, spec);
        
        byte[] ciphertext = cipher.doFinal(plaintext);
        
        // Prepend IV to ciphertext (IV doesn't need to be secret)
        byte[] result = new byte[iv.length + ciphertext.length];
        System.arraycopy(iv, 0, result, 0, iv.length);
        System.arraycopy(ciphertext, 0, result, iv.length, ciphertext.length);
        
        return result;
    }
    
    public byte[] decrypt(byte[] encrypted) throws Exception {
        // Extract IV from beginning
        byte[] iv = new byte[GCM_IV_LENGTH];
        System.arraycopy(encrypted, 0, iv, 0, GCM_IV_LENGTH);
        
        // Extract ciphertext
        byte[] ciphertext = new byte[encrypted.length - GCM_IV_LENGTH];
        System.arraycopy(encrypted, GCM_IV_LENGTH, ciphertext, 0, ciphertext.length);
        
        Cipher cipher = Cipher.getInstance(ALGORITHM);
        GCMParameterSpec spec = new GCMParameterSpec(GCM_TAG_LENGTH, iv);
        cipher.init(Cipher.DECRYPT_MODE, secretKey, spec);
        
        return cipher.doFinal(ciphertext);
    }
    
    private byte[] generateIV() {
        byte[] iv = new byte[GCM_IV_LENGTH];
        SecureRandom random = new SecureRandom();
        random.nextBytes(iv);
        return iv;
    }
    
    private SecretKey loadKey() throws Exception {
        // Load from AWS Secrets Manager, Vault, or secure keystore
        // NEVER hardcode encryption keys!
        String base64Key = System.getenv("AES_ENCRYPTION_KEY");
        byte[] decodedKey = Base64.getDecoder().decode(base64Key);
        return new SecretKeySpec(decodedKey, "AES");
    }
}

TLS/SSL Configuration

Container/Server TLS Configuration

For production deployments, configure TLS at the container or reverse proxy level:

Tomcat server.xml (if using embedded Tomcat):

xml
<Connector port="8443" protocol="org.apache.coyote.http11.Http11NioProtocol"
           maxThreads="150" SSLEnabled="true" scheme="https" secure="true"
           clientAuth="false" sslProtocol="TLS"
           sslEnabledProtocols="TLSv1.3,TLSv1.2"
           ciphers="TLS_AES_256_GCM_SHA384,TLS_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256"
           keystoreFile="${SSL_KEYSTORE_PATH}"
           keystorePass="${SSL_KEYSTORE_PASSWORD}"
           keystoreType="PKCS12"
           keyAlias="cia-server"/>

Or use Spring Security for HTTPS redirect and headers:

java
@Configuration
public class SecurityConfig extends WebSecurityConfigurerAdapter {
    
    @Override
    protected void configure(HttpSecurity http) throws Exception {
        http
            .requiresChannel()
                .anyRequest().requiresSecure()
                .and()
            .headers()
                .httpStrictTransportSecurity()
                    .includeSubDomains(true)
                    .maxAgeInSeconds(31536000)
                    .and()
                .contentSecurityPolicy("default-src 'self'; script-src 'self'; style-src 'self'");
    }
}
Nginx/Apache Reverse Proxy TLS

For most production deployments, configure TLS at the reverse proxy:

nginx
# nginx.conf
server {
    listen 443 ssl http2;
    
    ssl_certificate /path/to/cert.pem;
    ssl_certificate_key /path/to/key.pem;
    
    ssl_protocols TLSv1.3 TLSv1.2;
    ssl_ciphers 'TLS_AES_256_GCM_SHA384:TLS_AES_128_GCM_SHA256:TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384';
    ssl_prefer_server_ciphers on;
    
    add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
    
    location / {
        proxy_pass http://localhost:8080;
        proxy_set_header X-Forwarded-Proto https;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
    }
}
Show full SKILL.md (162 more words)Show less

JWT Token Security

RS256 (RSA Signature)
java
@Service
public class JwtTokenService {
    
    private final PrivateKey privateKey;
    private final PublicKey publicKey;
    private final long expirationMs = 86400000; // 24 hours
    
    public JwtTokenService() throws Exception {
        // Load keys from secure storage (not hardcoded!)
        this.privateKey = loadPrivateKey();
        this.publicKey = loadPublicKey();
    }
    
    public String generateToken(UserDetails user) {
        Date now = new Date();
        Date expiration = new Date(now.getTime() + expirationMs);
        
        return Jwts.builder()
            .setSubject(user.getUsername())
            .claim("authorities", user.getAuthorities().stream()
                .map(GrantedAuthority::getAuthority)
                .collect(Collectors.toList()))
            .setIssuedAt(now)
            .setExpiration(expiration)
            .signWith(privateKey, SignatureAlgorithm.RS256)
            .compact();
    }
    
    public Claims validateToken(String token) {
        try {
            return Jwts.parserBuilder()
                .setSigningKey(publicKey)
                .build()
                .parseClaimsJws(token)
                .getBody();
        } catch (ExpiredJwtException e) {
            throw new TokenExpiredException("Token has expired");
        } catch (JwtException e) {
            throw new InvalidTokenException("Invalid token signature");
        }
    }
    
    private PrivateKey loadPrivateKey() throws Exception {
        // Load from AWS Secrets Manager or similar
        // NEVER commit private keys to git!
        return null;  // Placeholder
    }
    
    private PublicKey loadPublicKey() throws Exception {
        // Public key can be in application resources
        InputStream is = getClass().getResourceAsStream("/jwt-public-key.pem");
        // Parse and return public key
        return null;  // Placeholder
    }
}

Secure Random Number Generation

java
@Component
public class SecureRandomGenerator {
    
    private final SecureRandom secureRandom;
    
    public SecureRandomGenerator() {
        // Use strong random number generator
        this.secureRandom = new SecureRandom();
    }
    
    /**
     * Generate cryptographically secure random bytes
     */
    public byte[] generateRandomBytes(int length) {
        byte[] bytes = new byte[length];
        secureRandom.nextBytes(bytes);
        return bytes;
    }
    
    /**
     * Generate secure random token for session IDs, CSRF tokens, etc.
     */
    public String generateSecureToken(int byteLength) {
        byte[] randomBytes = generateRandomBytes(byteLength);
        return Base64.getUrlEncoder().withoutPadding().encodeToString(randomBytes);
    }
    
    /**
     * Generate random API key
     */
    public String generateApiKey() {
        // 32 bytes = 256 bits of entropy
        return "sk_" + generateSecureToken(32);
    }
    
    /**
     * Generate CSRF token
     */
    public String generateCsrfToken() {
        // 24 bytes = 192 bits of entropy
        return generateSecureToken(24);
    }
}

Key Management

Key Generation
bash
# Generate AES-256 key
openssl rand -base64 32 > aes-256-key.txt

# Generate RSA-4096 key pair
openssl genrsa -out private-key.pem 4096
openssl rsa -in private-key.pem -pubout -out public-key.pem

# Generate self-signed certificate for TLS
openssl req -x509 -newkey rsa:4096 -keyout server-key.pem -out server-cert.pem -days 365 -nodes
Key Rotation Strategy
java
@Service
public class KeyRotationService {
    
    @Autowired
    private SecretsManager secretsManager;
    
    @Scheduled(cron = "0 0 0 1 */3 *")  // Every 3 months
    public void rotateEncryptionKey() {
        log.info("Starting encryption key rotation");
        
        // 1. Generate new key
        byte[] newKey = generateNewKey();
        
        // 2. Store new key with version number
        secretsManager.createSecret("encryption-key-v2", newKey);
        
        // 3. Re-encrypt data with new key
        reEncryptAllData("encryption-key-v1", "encryption-key-v2");
        
        // 4. Mark old key for deletion (keep for 30 days)
        secretsManager.scheduleKeyDeletion("encryption-key-v1", 30);
        
        log.info("Encryption key rotation completed");
    }
    
    private byte[] generateNewKey() {
        SecureRandom random = new SecureRandom();
        byte[] key = new byte[32];  // 256 bits
        random.nextBytes(key);
        return key;
    }
    
    private void reEncryptAllData(String oldKeyName, String newKeyName) {
        // Re-encrypt all encrypted data in database
        // This is a complex operation that should be done carefully
    }
}

ISMS Compliance Mapping

ISO 27001:2022 Controls
  • A.8.24 - Use of Cryptography: Implementation of crypto policy
  • A.8.11 - Data Masking: Encryption of sensitive data
  • A.5.17 - Authentication Information: Secure password hashing
NIST Cybersecurity Framework
  • PR.DS-1: Data-at-rest protected
  • PR.DS-2: Data-in-transit protected
  • PR.DS-5: Protections against data leaks
CIS Controls v8
  • Control 3.11: Encrypt sensitive data at rest
  • Control 3.10: Encrypt sensitive data in transit

Hack23 ISMS Policy References

Cryptographic Controls Framework:

All Hack23 ISMS Policies: https://github.com/Hack23/ISMS-PUBLIC

CIA Platform Architecture References

References

Standards & Guidelines

© Hack23, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/crypto-best-practices of Hack23/cia.

Open the folder on GitHubat commit 6a9797b

Compare with similar skills

Crypto Best Practices next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Crypto Best Practices compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Crypto Best Practices this skillHack23/cia239—~4.9kAutomated safety check: PassApache-2.0
Bom Explorecdxgen/cdxgen1.1k—~1.2kAutomated safety check: PassApache-2.0
Webcrypt MCPputervision/state-memory-mcp111—~847Automated safety check: PassMIT
Crypto Analysishypnguyen1209/offensive-claude386—~2.2kAutomated safety check: PassMIT
Security Reviewvalory-xyz/open-autonomy129—~11kAutomated safety check: NotesApache-2.0
Hashcat Password Recovery WorkflowAgentSecOps/SecOpsAgentKit2191 repos~3.3kAutomated safety check: NotesCustom licence

Similar skills

  • Bom Explore

    cdxgen/cdxgen

    Explores and triages a CycloneDX BOM interactively with the cdxi REPL, using built-in commands for dependency trees, licenses, services, cryptographic assets, audit findings, evidence occurrences…

    1.1k GitHub stars~1.2k tokensUpdated yesterday
    SecurityAuto-check passed
  • Webcrypt MCP

    putervision/state-memory-mcp

    Teaches the agent to use the WebCrypt MCP server for AES-256-GCM symmetric encryption, RSA-4096 hybrid encryption, key generation, digital signatures, hashing, and post-quantum cryptography.

    111 GitHub stars~847 tokensUpdated 4 days ago
    SecurityAuto-check passed
  • Crypto Analysis

    hypnguyen1209/offensive-claude

    A skill your agent uses when assessing cryptography — TLS/PKI auditing, RSA/ECC key attacks, ECDSA nonce lattice recovery, symmetric/AEAD misuse, JWT/JOSE forgery, hash cracking, post-quantum…

    386 GitHub stars~2.2k tokensUpdated 9 days ago
    SecurityAuto-check passed
  • Security Review

    valory-xyz/open-autonomy

    Security review of an open-autonomy agent service — cryptographic key handling, dynamic code execution, ABCI authentication and replay, secret exposure, dependency supply chain, and deployment…

    129 GitHub stars~11k tokensUpdated 23 days ago
    SecurityAuto-check: notes
  • Hashcat Password Recovery Workflow

    AgentSecOps/SecOpsAgentKit

    Guides authorized password-hash recovery with hashcat for security audits, forensic cases and policy testing, starting with an explicit authorization check before any cracking runs.

    219 GitHub starsUsed in 1 repo~3.3k tokens
    SecurityAuto-check: notes
  • Altllm Portal Auth

    internet-court/internet-court-skill

    A skill your agent uses when the user asks to log in or out with a wallet session, fetch a wallet sign-in challenge, verify an externally signed challenge, or troubleshoot AltLLM Portal wallet login…

    6.4k GitHub starsUsed in 1 repo~632 tokens
    SecurityAuto-check passed

More from Hack23/cia

All 78 skills in this repo
  • WCAG 2.1 AA compliance, ARIA attributes, keyboard navigation, screen reader optimization for accessible political data platforms

    239 GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Advanced chart types, D3.js/Vaadin Charts patterns, political data visualization, time series analysis

    239 GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • AI Governance

    Hack23/cia

    AI governance, EU AI Act compliance, OWASP LLM security, responsible AI practices for GitHub Copilot agents

    239 GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • API Integration

    Hack23/cia

    External API integration patterns, retry logic, circuit breakers, caching, rate limiting for government data APIs

    239 GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • AWS CloudWatch metrics, alarms, dashboards, log insights, and application monitoring for the CIA platform

    239 GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • AWS security best practices, VPC security, IAM, KMS, CloudTrail, GuardDuty for CIA platform deployment

    239 GitHub stars~2.3k tokensUpdated today
    Auto-check passed

Categories

Questions about Crypto Best Practices

What does Crypto Best Practices do?

Implement strong encryption, secure hashing, and proper key management following NIST and OWASP cryptography guidelines. Crypto Best Practices is an agent skill from Hack23/cia.

When should I use Crypto Best Practices?

Crypto Best Practices fits situations like: tasks that involve Cryptography.

How do I install Crypto Best Practices in Claude Code?

Run `npx skills add Hack23/cia --skill crypto-best-practices -a claude-code`. Or copy the skill folder (.github/skills/crypto-best-practices in Hack23/cia) into .claude/skills/crypto-best-practices in your project. Claude Code loads it when a task matches its description.

How do I install Crypto Best Practices in Codex?

Run `npx skills add Hack23/cia --skill crypto-best-practices -a codex`. Or copy the skill folder (.github/skills/crypto-best-practices in Hack23/cia) into .agents/skills/crypto-best-practices in your project. Codex loads it when a task matches its description.

Can I use Crypto Best Practices in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Hack23/cia --skill crypto-best-practices -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/crypto-best-practices, .gemini/skills/crypto-best-practices, .github/skills/crypto-best-practices and .opencode/skills/crypto-best-practices in your project.

What does Crypto Best Practices need to run?

Going by SKILL.md and its folder, Crypto Best Practices needs the command-line tools its instructions call (openssl) and credentials named ENCRYPTION_KEY, AES_ENCRYPTION_KEY and SSL_KEYSTORE_PASSWORD. Our summary lists: A credential in ENCRYPTION_KEY; A credential in AES_ENCRYPTION_KEY.

Does Crypto Best Practices access the network?

SKILL.md names 4 domains. As links in the text: github.com, csrc.nist.gov, cheatsheetseries.owasp.org and docs.spring.io. This is read from the text; nothing was executed.

Is Crypto Best Practices safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Crypto Best Practices use?

Crypto Best Practices is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Crypto Best Practices use?

About 4.9k tokens (SKILL.md is roughly 20k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Crypto Best Practices?

Skills that share tags, products or a category with Crypto Best Practices: Bom Explore (cdxgen/cdxgen, 1.1k stars), Webcrypt MCP (putervision/state-memory-mcp, 111 stars), Crypto Analysis (hypnguyen1209/offensive-claude, 386 stars) and Security Review (valory-xyz/open-autonomy, 129 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Crypto Best Practices?

Hack23 (a GitHub organization) maintains it in Hack23/cia, which has 239 GitHub stars. The repository holds 78 skills in this directory. The repository was last updated on October 6, 2026.

Source: Hack23/cia on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.