Agent skill

Detecting Weak Cryptography

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Scan a source tree for weak cryptographic primitives: MD5 / SHA-1 used for security purposes, DES / 3DES / RC4 ciphers, ECB block mode, custom-built crypto (XOR loops, hand-rolled HMAC), hardcoded…

MITAuto-check passedSecurity

Install Detecting Weak Cryptography

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill detecting-weak-cryptography -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace detecting-weak-cryptography --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/detecting-weak-cryptography .claude/skills/detecting-weak-cryptography && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
detecting-weak-cryptography
GitHub stars
2.8k
Token cost
~1.3k tokens
SKILL.md length
400 words
Files
4 (incl. scripts, references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Scan a source tree for weak cryptographic primitives: MD5 / SHA-1 used for security purposes, DES / 3DES / RC4 ciphers, ECB block mode, custom-built crypto (XOR loops, hand-rolled HMAC), hardcoded…

  • : pre-merge gate on crypto-touching code
  • SKILL.md covers Overview, When the skill produces findings, Prerequisites and Instructions, plus 4 more sections
  • Runs Python scripts from its folder; calls python3 and git
  • Audit before SOC2 / PCI assessment

What it does

Detecting Weak Cryptography is an agent skill from jeremylongshore/tons-of-skills-marketplace. Scan a source tree for weak cryptographic primitives: MD5 / SHA-1 used for security purposes, DES / 3DES / RC4 ciphers, ECB block mode, custom-built crypto (XOR loops, hand-rolled HMAC), hardcoded IVs, predictable random (Math.random / java.util.Random for crypto seeds), missing certificate verification (verify=False, rejectUnauthorized: false). Use when: pre-merge gate on crypto-touching code, audit before SOC2 / PCI assessment, post-incident review when "we found a weakness in our token signing." Threshold: any…

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/PLAYBOOK.md`, `references/THEORY.md` and `scripts/scan_weak_crypto.py`). Compatibility notes: Designed for Claude Code

It sits in Security, covering Cryptography. It works with Java. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • : pre-merge gate on crypto-touching code
  • Audit before SOC2 / PCI assessment
  • Post-incident review when we found a weakness in our token signing. Threshold: any call to a known-weak algorithm with non-test context
  • Cert verification explicitly disabled

Example prompts

  • “we found a weakness in our token signing.”
  • “scan weak crypto”
  • “find MD5 usage”
  • “/detecting-weak-cryptography”

Requirements

  • Python 3
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Bash(python3:*), Glob, Grep

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Bash(python3:*)
    • Glob
    • Grep

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Detecting Weak Cryptography loads about 1.3k tokens when it runs, and up to ~5.8k if it reads all its reference files. Until then it costs about 195 tokens; SKILL.md has 400 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~195
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 400 words, ~1,314 tokens.

Download SKILL.mdSave it as .claude/skills/detecting-weak-cryptography/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
detecting-weak-cryptography
description
Scan a source tree for weak cryptographic primitives: MD5 / SHA-1 used for security purposes, DES / 3DES / RC4 ciphers, ECB block mode, custom-built crypto (XOR loops, hand-rolled HMAC), hardcoded IVs, predictable random (Math.random / java.util.Random for crypto seeds), missing certificate verification (verify=False, rejectUnauthorized: false). Use when: pre-merge gate on crypto-touching code, audit before SOC2 / PCI assessment, post-incident review when "we found a weakness in our token signing." Threshold: any call to a known-weak algorithm with non-test context, OR cert verification explicitly disabled, OR a custom crypto loop pattern. Trigger with: "scan weak crypto", "find MD5 usage", "check ECB mode", "audit ssl verify", "weak random".
allowed-tools
Read, Bash(python3:*), Glob, Grep
compatibility
Designed for Claude Code
disallowed-tools
Bash(rm:*), Bash(curl:*)
version
3.30.0
author
Jeremy Longshore <jeremy@intentsolutions.io>
license
MIT
tags
security, static-analysis, cryptography, pentest

Detecting Weak Cryptography

Overview

Weak cryptography (CWE-327 Use of a Broken or Risky Cryptographic Algorithm, CWE-330 Use of Insufficiently Random Values) shows up when engineers use the convenient API instead of the cryptographic one. hashlib.md5(password) is faster to type than the correct bcrypt/argon2 invocation; Math.random() returns a number quickly without needing to know about crypto.randomBytes().

The fix is universal: use the modern primitive. SHA-256 for general hashing, bcrypt/argon2/scrypt for passwords, AES-GCM for encryption, HMAC-SHA256 for signing, secrets / crypto.randomBytes / SecureRandom for randomness.

When the skill produces findings

FindingSeverityThresholdAffected control
MD5 used in security contextHIGHhashlib.md5, MessageDigest.MD5, CryptoJS.MD5CWE-327
SHA-1 used in security contextHIGHhashlib.sha1, etc.CWE-327
DES / 3DES cipherCRITICALDESCrypto, "DES/CBC", "DESede"CWE-327
RC4 cipherCRITICAL"ARC4", "RC4"CWE-327
AES ECB modeCRITICAL"AES/ECB" or MODE_ECBCWE-327
Hardcoded IV (initialization vector)CRITICALIV literal in sourceCWE-329
Custom XOR-based "encryption"CRITICALXOR loop over bytesCWE-327
Predictable random for crypto seedCRITICALMath.random / java.util.Random / random.random for keysCWE-330
TLS cert verification disabledCRITICALverify=False, rejectUnauthorized:false, ServerCertificateValidationCallback returning trueCWE-295
Hardcoded HMAC secretHIGHLong literal in HMAC constructorCWE-321
Insecure password hashing (no salt, no KDF)CRITICALhashlib.sha256(password) without bcrypt/argon2CWE-916

Prerequisites

  • Python 3.9+
  • Source tree on local filesystem

Instructions

Run
bash
python3 ${CLAUDE_PLUGIN_ROOT}/skills/detecting-weak-cryptography/scripts/scan_weak_crypto.py /path/to/repo

Options: --output, --format, --min-severity, --include-tests, --languages, --allow-md5-checksums (excludes MD5 used in non-security contexts like content-addressable storage).

Show full SKILL.md (178 more words)Show less
Interpret

CRITICAL = direct cryptographic break available against the algorithm. CVEs, public attack tools, sometimes pre-computed tables (rainbow tables for MD5/SHA-1).

HIGH = algorithm collision-broken (MD5, SHA-1) but the specific use case may tolerate the weakness (file-deduplication checksums, non-security HMAC). Verify the usage context.

Remediation

See references/PLAYBOOK.md for per-primitive migration. Modern defaults: SHA-256/SHA-3 for hashing, AES-256-GCM for encryption, HMAC-SHA-256 for signing, secrets-grade random for keys, bcrypt / argon2id for password storage.

Examples

Pre-merge gate
bash
python3 ${CLAUDE_PLUGIN_ROOT}/skills/detecting-weak-cryptography/scripts/scan_weak_crypto.py \
    --min-severity high $(git diff --name-only main...HEAD | tr '\n' ' ')
CI
yaml
- name: Weak-crypto scan
  run: |
    python3 plugins/security/penetration-tester/skills/detecting-weak-cryptography/scripts/scan_weak_crypto.py \
        . --min-severity high

Output

JSON / JSONL / Markdown. Exit codes: 0 / 1 / 2.

Error Handling

False positives common on:

  • MD5 used for content-addressable storage (caches, content hashes) where collision resistance against ATTACKERS isn't needed — use --allow-md5-checksums.
  • HMAC-MD5 — broken against adversaries but acceptable as an integrity check inside a TLS session where the channel is already authenticated.

Verify each finding by reading whether the algorithm's failure mode (collision, preimage, etc.) is actually exploitable in context.

Resources

  • references/THEORY.md — Per-primitive attack model (why MD5 / SHA-1 are collision-broken, why ECB leaks structure, why Math.random is non-crypto-grade)
  • references/PLAYBOOK.md — Per-language modern-crypto recipes (Python cryptography library, Node crypto, Java JCA with modern algorithms, Go crypto/rand + crypto/cipher AEAD)

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/.curated/detecting-weak-cryptography of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/PLAYBOOK.md
  • references/THEORY.md
  • scripts/scan_weak_crypto.py

Open the folder on GitHubat commit cfae287

Compare with similar skills

Detecting Weak Cryptography next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Detecting Weak Cryptography compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Detecting Weak Cryptography this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1.3kAutomated safety check: PassMIT
Crypto Bomcdxgen/cdxgen1.1k—~1.4kAutomated safety check: PassApache-2.0
Constant-Time Analysistrailofbits/skills7.5k—~3.3kAutomated safety check: NotesCC-BY-SA-4.0
Azure Security Keyvault Keys Javamicrosoft/skills3.1k5 repos~2.9kAutomated safety check: PassMIT
Security Reviewgithub/awesome-copilot40k1 repos~2.3kAutomated safety check: NotesMIT
124 Java Secure Codingjabrena/plinth447—~885Automated safety check: PassApache-2.0

Similar skills

  • Crypto Bom

    cdxgen/cdxgen

    Generates a CycloneDX Cryptographic Bill of Materials (CBOM) with the cdxgen cbom command, inventorying cryptographic algorithms, certificates, keys, and protocol usage from source code and hosts…

    1.1k GitHub stars~1.4k tokensUpdated yesterday
    SecurityAuto-check passed
  • Constant-Time Analysis

    trailofbits/skills

    Official

    Compiles cryptographic code and inspects the assembly or bytecode for variable-time instructions, then triages which flagged operations actually touch secrets.

    7.5k GitHub stars~3.3k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Official

    Azure Key Vault Keys Java SDK for cryptographic key management.

    3.1k GitHub starsUsed in 5 repos~2.9k tokens
    SecurityAuto-check passed
  • Security Review

    github/awesome-copilot

    Official

    AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching…

    40k GitHub starsUsed in 1 repo~2.3k tokens
    SecurityAuto-check: notes
  • A skill your agent uses when you need to apply Java secure coding best practices — including validating untrusted inputs, defending against injection attacks with parameterized queries, minimizing…

    447 GitHub stars~885 tokensUpdated 3 days ago
    SecurityAuto-check passed
  • Constant Time Analysis

    sickn33/agentic-awesome-skills

    Analyze cryptographic code to detect operations that leak secret data through execution timing variations.

    47k GitHub starsUsed in 2 repos~2.4k tokens
    MobileAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Detecting Weak Cryptography

What does Detecting Weak Cryptography do?

Scan a source tree for weak cryptographic primitives: MD5 / SHA-1 used for security purposes, DES / 3DES / RC4 ciphers, ECB block mode, custom-built crypto (XOR loops, hand-rolled HMAC), hardcoded…. Detecting Weak Cryptography is an agent skill from jeremylongshore/tons-of-skills-marketplace.Random for crypto seeds), missing certificate verification (verify=False, rejectUnauthorized: false).

When should I use Detecting Weak Cryptography?

Detecting Weak Cryptography fits situations like: : pre-merge gate on crypto-touching code; audit before SOC2 / PCI assessment; post-incident review when we found a weakness in our token signing. Threshold: any call to a known-weak algorithm with non-test context; cert verification explicitly disabled.

How do I install Detecting Weak Cryptography in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill detecting-weak-cryptography -a claude-code`. Or copy the skill folder (skills/.curated/detecting-weak-cryptography in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/detecting-weak-cryptography in your project. Claude Code loads it when a task matches its description.

How do I install Detecting Weak Cryptography in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill detecting-weak-cryptography -a codex`. Or copy the skill folder (skills/.curated/detecting-weak-cryptography in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/detecting-weak-cryptography in your project. Codex loads it when a task matches its description.

Can I use Detecting Weak Cryptography in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill detecting-weak-cryptography -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/detecting-weak-cryptography, .gemini/skills/detecting-weak-cryptography, .github/skills/detecting-weak-cryptography and .opencode/skills/detecting-weak-cryptography in your project.

What does Detecting Weak Cryptography need to run?

Going by SKILL.md and its folder, Detecting Weak Cryptography needs Python for the scripts in its folder and the command-line tools its instructions call (python3 and git). Our summary lists: Python 3. Its frontmatter pre-approves these tools: Read, Bash(python3:*), Glob, Grep. Compatibility (from SKILL.md): Designed for Claude Code.

Does Detecting Weak Cryptography access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Detecting Weak Cryptography safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Detecting Weak Cryptography use?

Detecting Weak Cryptography is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Detecting Weak Cryptography use?

About 1.3k tokens (SKILL.md is roughly 5.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.5k tokens, read only when the agent opens those files.

What are the alternatives to Detecting Weak Cryptography?

Skills that share tags, products or a category with Detecting Weak Cryptography: Crypto Bom (cdxgen/cdxgen, 1.1k stars), Constant-Time Analysis (trailofbits/skills, 7.5k stars), Azure Security Keyvault Keys Java (microsoft/skills, 3.1k stars) and Security Review (github/awesome-copilot, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Detecting Weak Cryptography?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.