Agent skill

Crypto Analysis

by hypnguyen1209 in hypnguyen1209/offensive-claude

A skill your agent uses when assessing cryptography — TLS/PKI auditing, RSA/ECC key attacks, ECDSA nonce lattice recovery, symmetric/AEAD misuse, JWT/JOSE forgery, hash cracking, post-quantum…

MITAuto-check passedSecurity

Install Crypto Analysis

skills CLI
$ npx skills add hypnguyen1209/offensive-claude --skill crypto-analysis -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install hypnguyen1209/offensive-claude crypto-analysis --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/hypnguyen1209/offensive-claude.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/crypto-analysis .claude/skills/crypto-analysis && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
crypto-analysis
GitHub stars
388
Token cost
~2.2k tokens
SKILL.md length
583 words
Files
14 (incl. scripts, references)
Skills in repo
9
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when assessing cryptography — TLS/PKI auditing, RSA/ECC key attacks, ECDSA nonce lattice recovery, symmetric/AEAD misuse, JWT/JOSE forgery, hash cracking, post-quantum…

  • Assessing cryptography — TLS/PKI auditing
  • SKILL.md covers When to Activate, Technique Map, Quick Start and OPSEC & Detection (summary), plus 1 more section
  • Runs Python scripts from its folder; calls python3
  • RSA/ECC key attacks

What it does

Crypto Analysis is an agent skill from hypnguyen1209/offensive-claude. Use when assessing cryptography — TLS/PKI auditing, RSA/ECC key attacks, ECDSA nonce lattice recovery, symmetric/AEAD misuse, JWT/JOSE forgery, hash cracking, post-quantum migration review

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 15 other files, including scripts and reference files (for example `references/ecc-nonce-attacks.md`, `references/hash-pq.md` and `references/jwt-jose.md`).

It sits in Security, covering Cryptography. The repository describes itself as: Offensive security toolkit for Claude Code covering red team, exploit dev, AD attacks, EDR bypass, mobile pentest. The licence is MIT.

When your agent uses it

  • Assessing cryptography — TLS/PKI auditing
  • RSA/ECC key attacks
  • ECDSA nonce lattice recovery
  • Symmetric/AEAD misuse

Example prompts

  • “/crypto-analysis”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit a506ad3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 7 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Crypto Analysis loads about 2.2k tokens when it runs, and up to ~13k if it reads all its reference files. Until then it costs about 51 tokens; SKILL.md has 583 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~51
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~13k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from hypnguyen1209/offensive-claude at commit a506ad3, republished under its MIT licence (© hypnguyen1209). 583 words, ~2,184 tokens.

Download SKILL.mdSave it as .claude/skills/crypto-analysis/SKILL.md (or your agent's skills folder). This skill also uses 13 other files; get the full folder from GitHub.
name
crypto-analysis
description
Use when assessing cryptography — TLS/PKI auditing, RSA/ECC key attacks, ECDSA nonce lattice recovery, symmetric/AEAD misuse, JWT/JOSE forgery, hash cracking, post-quantum migration review
metadata.type
offensive
metadata.phase
analysis
metadata.tools
testssl.sh, openssl, hashcat, john, RsaCtfTool, sagemath, jwt_tool, ecdsa-lattice
metadata.mitre
T1600, T1600.001, T1557, T1110.002, T1552.004, T1606.001, T1040
kill_chain.phase
recon, exploit
kill_chain.step
1, 4
kill_chain.attck_tactics
TA0043, TA0006, TA0009
kill_chain.attck_techniques
T1600, T1600.001, T1557, T1557.001, T1110.002, T1552.004, T1606.001, T1040
depends_on
recon-osint
feeds_into
exploit-development, web-pentest, network-attack

Cryptographic Analysis

When to Activate

  • Auditing TLS/SSL/SSH configurations and X.509 PKI (cipher suites, downgrade, protocol flaws)
  • Reviewing crypto implementations in source code or captured traffic
  • Attacking weak RSA/ECC keys (CTF and real-world weak-key hygiene)
  • Recovering ECDSA/DSA private keys from reused or biased nonces (lattice/HNP)
  • Exploiting symmetric/AEAD misuse: padding oracles, GCM nonce reuse, key-commitment
  • Forging JWT/JOSE tokens (algorithm confusion, none, jwk/jku/kid injection)
  • Cracking password hashes and grading KDF strength
  • Assessing post-quantum readiness ("harvest now, decrypt later" exposure)

Technique Map

TechniqueATT&CKCWEReferenceScript
TLS cipher/protocol downgrade auditT1600.001CWE-326references/tls-pki-audit.mdscripts/tls_audit.py
Terrapin SSH prefix truncation (CVE-2023-48795)T1557CWE-222references/tls-pki-audit.mdscripts/tls_audit.py
Marvin/Bleichenbacher RSA timing oracleT1600CWE-208references/tls-pki-audit.mdscripts/tls_audit.py
X.509 / CT-log shadow-asset discoveryT1589CWE-295references/tls-pki-audit.mdscripts/tls_audit.py
RSA weak-key factoring (Fermat/Wiener/common-modulus)T1600CWE-326references/rsa-attacks.mdscripts/rsa_attack.py
Coppersmith partial-key & ROCA (CVE-2017-15361)T1600CWE-310references/rsa-attacks.mdscripts/rsa_attack.py
Hastad broadcast / batch-GCDT1600CWE-326references/rsa-attacks.mdscripts/rsa_attack.py
ECDSA nonce reuse key recoveryT1552.004CWE-323references/ecc-nonce-attacks.mdscripts/ecdsa_lattice.py
Biased-nonce lattice/HNP (Minerva, PuTTY CVE-2024-31497)T1552.004CWE-1241references/ecc-nonce-attacks.mdscripts/ecdsa_lattice.py
Psychic signature (0,0) (CVE-2022-21449)T1606.001CWE-347references/ecc-nonce-attacks.mdscripts/ecdsa_lattice.py
CBC padding oracle (byte-by-byte decrypt)T1040CWE-209references/symmetric-aead.mdscripts/padding_oracle.py
AES-GCM nonce reuse "forbidden attack"T1040CWE-323references/symmetric-aead.mdscripts/gcm_nonce_reuse.py
AEAD key-commitment / invisible salamanders / partitioning oracleT1606CWE-347references/symmetric-aead.mdscripts/gcm_nonce_reuse.py
JWT algorithm confusion RS256→HS256 (CVE-2024-54150)T1606.001CWE-347references/jwt-jose.mdscripts/jwt_forge.py
JWT alg=none / jwk / jku / kid injectionT1606.001CWE-347references/jwt-jose.mdscripts/jwt_forge.py
Hash identification & GPU crackingT1110.002CWE-916references/hash-pq.mdscripts/hash_triage.py
Weak KDF / fast-hash password storageT1110.002CWE-916references/hash-pq.mdscripts/hash_triage.py
Post-quantum / HNDL exposure reviewT1600CWE-327references/hash-pq.mdscripts/tls_audit.py

Quick Start

bash
# 0. TLS/PKI posture in one shot (downgrade, ROBOT, SWEET32, Terrapin, cert/CT)
python3 scripts/tls_audit.py target.com:443 --ssh target.com:22 --ct --json out.json
testssl.sh --full --robot --sweet32 https://target.com   # cross-check with the canonical tool

# 1. RSA weak-key triage on a captured public key
python3 scripts/rsa_attack.py --pubkey server.pem --ct ciphertext.b64 --auto
#   tries Fermat (p~=q), Wiener (small d), batch-GCD/common-modulus, ROCA fingerprint

# 2. ECDSA key recovery from a signature corpus (reuse or bias)
python3 scripts/ecdsa_lattice.py recover sigs.json --curve secp256r1 --known-msb 4
#   reuse: needs 2 sigs w/ same r; bias: ~256-1200 sigs depending on leak

# 3. Symmetric/AEAD misuse
python3 scripts/padding_oracle.py --url https://t/dec --ct $CT --block 16   # CBC oracle
python3 scripts/gcm_nonce_reuse.py forbidden ct1.bin ct2.bin --nonce $N     # recover H + forge

# 4. JWT forgery chain
python3 scripts/jwt_forge.py confusion --pubkey jwt_pub.pem --claims '{"role":"admin"}'
python3 scripts/jwt_forge.py none      --claims '{"sub":"admin"}'

# 5. Hash triage + crack plan
python3 scripts/hash_triage.py hashes.txt            # identify + emit hashcat -m / john format
hashcat -m 22000 capture.hc22000 wl.txt -r rules/best64.rule

OPSEC & Detection (summary)

TechniqueTelemetry / IOCDetection (Sigma/EDR)OPSEC note
TLS scanning / testsslBurst of handshakes, many cipher renegotiations, malformed ClientHellosNIDS: high TLS alert rate from one src; Zeek ssl.log anomalous cipher offersRate-limit, spread across source IPs; passive cert/CT recon leaves no target-side trace
Marvin/ROBOT oracle probing~10^4–10^6 RSA decrypts, repeated malformed pre-master/CMSWAF/IDS: spike of TLS decrypt errors, identical-size payloadsExtremely loud; only against authorized hosts; use minimal query budgets
Terrapin MitMInjected SSH_MSG_IGNORE, sequence-number gap at NEWKEYSSSH server logs kex mismatch; netflow showing on-path deviceRequires active MitM; detectable by strict-kex peers; abort if kex-strict present
ECDSA nonce harvestingBulk signature collection (Git, TLS, SSH, blockchain)Mostly offline — no target telemetry once sigs capturedCollection is passive; recovery is offline; rotate-key advice in report
CBC padding oracleThousands of decrypt requests, alternating valid/invalid paddingWeb logs: ~256×blocks requests to one endpoint; Sigma on 4xx burstVery noisy (256×blocks×msgs); throttle, randomize timing
GCM nonce reuse / partitioningRepeated (nonce,key) pairs; multi-key ciphertext blobsApp crypto audit; flag reused IVs in logsForbidden-attack math is offline once two ciphertexts captured
JWT forgeryAnomalous alg, external jku/x5u fetch, all-zero ES signatureSigma: JWT with alg:none/HS after RS expected; egress to attacker JWKS URLEach forged token is a single request; minimal noise
Hash crackingNone on target (offline)N/A unless online spray (then T1110)Offline; protect loot at rest; never spray live without scope
Show full SKILL.md (109 more words)Show less

Deep Dives

  • references/tls-pki-audit.md — TLS/SSL/SSH posture: cipher/protocol downgrade, Terrapin (CVE-2023-48795), Marvin/Bleichenbacher (CVE-2022-4304, CVE-2024-2236), SWEET32/DROWN/Logjam/POODLE, X.509 and Certificate-Transparency analysis.
  • references/rsa-attacks.md — Weak-key factoring: Fermat, Wiener, common modulus, Hastad broadcast, Coppersmith partial-key, batch-GCD, ROCA (CVE-2017-15361); RsaCtfTool / cado-nfs / SageMath workflow.
  • references/ecc-nonce-attacks.md — ECDSA/DSA nonce reuse, biased-nonce lattice/HNP recovery (Minerva, PuTTY CVE-2024-31497), invalid-curve attacks, psychic signatures (CVE-2022-21449).
  • references/symmetric-aead.md — Block-cipher mode misuse: ECB detection, CBC padding oracle, CTR/GCM nonce reuse (forbidden attack), AEAD key-commitment / invisible salamanders / partitioning oracles.
  • references/jwt-jose.md — JWT/JOSE token forgery: algorithm confusion (CVE-2024-54150), alg=none, jwk/jku/x5u/kid injection, weak-secret cracking, library-level CVE landscape.
  • references/hash-pq.md — Hash identification, modern GPU cracking economics (RTX 40/50-series), KDF strength grading, and post-quantum migration / "harvest now, decrypt later" assessment (ML-KEM/ML-DSA, hybrid TLS, crypto-agility).

© hypnguyen1209, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 13 other files (scripts, references) in skills/crypto-analysis of hypnguyen1209/offensive-claude.

  • SKILL.md
  • references/ecc-nonce-attacks.md
  • references/hash-pq.md
  • references/jwt-jose.md
  • references/rsa-attacks.md
  • references/symmetric-aead.md
  • references/tls-pki-audit.md
  • scripts/ecdsa_lattice.py
  • scripts/gcm_nonce_reuse.py
  • scripts/hash_triage.py
  • scripts/jwt_forge.py
  • scripts/padding_oracle.py
  • scripts/rsa_attack.py
  • scripts/tls_audit.py

Open the folder on GitHubat commit a506ad3

Compare with similar skills

Crypto Analysis next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Crypto Analysis compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Crypto Analysis this skillhypnguyen1209/offensive-claude388—~2.2kAutomated safety check: PassMIT
Bom Explorecdxgen/cdxgen1.1k—~1.2kAutomated safety check: PassApache-2.0
Webcrypt MCPputervision/state-memory-mcp114—~847Automated safety check: PassMIT
Security Reviewvalory-xyz/open-autonomy129—~11kAutomated safety check: NotesApache-2.0
Hashcat Password Recovery WorkflowAgentSecOps/SecOpsAgentKit2201 repos~3.3kAutomated safety check: NotesCustom licence
Altllm Portal Authinternet-court/internet-court-skill6.5k1 repos~632Automated safety check: PassISC

Similar skills

  • Bom Explore

    cdxgen/cdxgen

    Explores and triages a CycloneDX BOM interactively with the cdxi REPL, using built-in commands for dependency trees, licenses, services, cryptographic assets, audit findings, evidence occurrences…

    1.1k GitHub stars~1.2k tokensUpdated yesterday
    SecurityAuto-check passed
  • Webcrypt MCP

    putervision/state-memory-mcp

    Teaches the agent to use the WebCrypt MCP server for AES-256-GCM symmetric encryption, RSA-4096 hybrid encryption, key generation, digital signatures, hashing, and post-quantum cryptography.

    114 GitHub stars~847 tokensUpdated 6 days ago
    SecurityAuto-check passed
  • Security Review

    valory-xyz/open-autonomy

    Security review of an open-autonomy agent service — cryptographic key handling, dynamic code execution, ABCI authentication and replay, secret exposure, dependency supply chain, and deployment…

    129 GitHub stars~11k tokensUpdated 25 days ago
    SecurityAuto-check: notes
  • Hashcat Password Recovery Workflow

    AgentSecOps/SecOpsAgentKit

    Guides authorized password-hash recovery with hashcat for security audits, forensic cases and policy testing, starting with an explicit authorization check before any cracking runs.

    220 GitHub starsUsed in 1 repo~3.3k tokens
    SecurityAuto-check: notes
  • Altllm Portal Auth

    internet-court/internet-court-skill

    A skill your agent uses when the user asks to log in or out with a wallet session, fetch a wallet sign-in challenge, verify an externally signed challenge, or troubleshoot AltLLM Portal wallet login…

    6.5k GitHub starsUsed in 1 repo~632 tokens
    SecurityAuto-check passed
  • Wycheproof

    trailofbits/skills

    Official

    Validates cryptographic implementations against Project Wycheproof's test vectors, which encode known attacks and edge cases across AES, RSA, ECDSA, ECDH, and more.

    7.4k GitHub stars~4.9k tokensUpdated 2 days ago
    SecurityAuto-check passed

More from hypnguyen1209/offensive-claude

All 9 skills in this repo
  • Incident Response

    hypnguyen1209/offensive-claude

    A skill your agent uses when responding to or forensically investigating an incident — triage acquisition (Velociraptor/KAPE), Volatility 3 memory forensics, Chainsaw/Hayabusa EVTX timelining…

    388 GitHub stars~2.5k tokensUpdated 12 days ago
    Auto-check passed
  • Malware Analysis

    hypnguyen1209/offensive-claude

    A skill your agent uses when reverse-engineering or detecting malware — static triage + capa/YARA-X, emulation/DBI/.NET unpacking, dynamic/fileless/Volatility 3 memory analysis, C2 config extraction…

    388 GitHub stars~2.3k tokensUpdated 12 days ago
    Auto-check passed
  • Recon Osint

    hypnguyen1209/offensive-claude

    A skill your agent uses when mapping a target's external attack surface or gathering OSINT — subdomain enumeration, attack-surface mapping (httpx/katana/JS secrets), subdomain takeover…

    388 GitHub stars~2.2k tokensUpdated 12 days ago
    Auto-check passed
  • Threat Hunting

    hypnguyen1209/offensive-claude

    A skill your agent uses when hunting threats or engineering detections — ATT&CK Detection-Strategies, Sigma + correlation with Detection-as-Code CI, Windows endpoint hunting…

    388 GitHub stars~2.4k tokensUpdated 12 days ago
    Auto-check passed
  • Threat Model Discipline

    hypnguyen1209/offensive-claude

    A skill your agent uses when starting an engagement, before exploitation, or whenever the attack surface changes — build/validate the threat model and detect drift (new unreviewed surface) before…

    388 GitHub stars~660 tokensUpdated 12 days ago
    Auto-check passed
  • Writing Offensive Skills

    hypnguyen1209/offensive-claude

    A skill your agent uses when creating or editing a skill in this offensive-claude repo — for the SKILL.md conventions (trigger descriptions, technique map, runnable scripts, OPSEC/detection…

    388 GitHub stars~826 tokensUpdated 12 days ago
    Auto-check passed

Categories

Questions about Crypto Analysis

What does Crypto Analysis do?

A skill your agent uses when assessing cryptography — TLS/PKI auditing, RSA/ECC key attacks, ECDSA nonce lattice recovery, symmetric/AEAD misuse, JWT/JOSE forgery, hash cracking, post-quantum…. Crypto Analysis is an agent skill from hypnguyen1209/offensive-claude.

When should I use Crypto Analysis?

Crypto Analysis fits situations like: assessing cryptography — TLS/PKI auditing; RSA/ECC key attacks; ECDSA nonce lattice recovery; symmetric/AEAD misuse.

How do I install Crypto Analysis in Claude Code?

Run `npx skills add hypnguyen1209/offensive-claude --skill crypto-analysis -a claude-code`. Or copy the skill folder (skills/crypto-analysis in hypnguyen1209/offensive-claude) into .claude/skills/crypto-analysis in your project. Claude Code loads it when a task matches its description.

How do I install Crypto Analysis in Codex?

Run `npx skills add hypnguyen1209/offensive-claude --skill crypto-analysis -a codex`. Or copy the skill folder (skills/crypto-analysis in hypnguyen1209/offensive-claude) into .agents/skills/crypto-analysis in your project. Codex loads it when a task matches its description.

Can I use Crypto Analysis in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hypnguyen1209/offensive-claude --skill crypto-analysis -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/crypto-analysis, .gemini/skills/crypto-analysis, .github/skills/crypto-analysis and .opencode/skills/crypto-analysis in your project.

What does Crypto Analysis need to run?

Going by SKILL.md and its folder, Crypto Analysis needs Python for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3.

Does Crypto Analysis access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Crypto Analysis safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Crypto Analysis use?

Crypto Analysis is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Crypto Analysis use?

About 2.2k tokens (SKILL.md is roughly 8.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 11k tokens, read only when the agent opens those files.

What are the alternatives to Crypto Analysis?

Skills that share tags, products or a category with Crypto Analysis: Bom Explore (cdxgen/cdxgen, 1.1k stars), Webcrypt MCP (putervision/state-memory-mcp, 114 stars), Security Review (valory-xyz/open-autonomy, 129 stars) and Hashcat Password Recovery Workflow (AgentSecOps/SecOpsAgentKit, 220 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Crypto Analysis?

hypnguyen1209 (a GitHub user) maintains it in hypnguyen1209/offensive-claude, which has 388 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on September 28, 2026.

Source: hypnguyen1209/offensive-claude on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.