Agent skill

Constant Time Analysis

by sickn33 in sickn33/agentic-awesome-skills

Analyze cryptographic code to detect operations that leak secret data through execution timing variations.

MITAuto-check passedMobile

Install Constant Time Analysis

skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill constant-time-analysis -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sickn33/agentic-awesome-skills constant-time-analysis --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/constant-time-analysis .claude/skills/constant-time-analysis && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
constant-time-analysis
GitHub stars
47k
Used in
2 other repos
Token cost
~2.4k tokens
SKILL.md length
625 words
Files
1
Skills in repo
1,354
Repo updated
First seen
Licence
MIT

At a glance

Analyze cryptographic code to detect operations that leak secret data through execution timing variations.

  • Works in 4 steps: Identify the secret inputs to the… → Trace data flow from the flagged… → Common false positive patterns → …
  • Tasks that involve Cryptography
  • SKILL.md covers When to Use, When NOT to Use, Language Selection and Quick Start, plus 6 more sections
  • Calls uv and dotnet

What it does

Constant Time Analysis is an agent skill from sickn33/agentic-awesome-skills. Analyze cryptographic code to detect operations that leak secret data through execution timing variations.

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Mobile, covering Cryptography. It works with Java, Kotlin, C++ and C#. The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.

When your agent uses it

  • Tasks that involve Cryptography

Example prompts

  • “/constant-time-analysis”

Requirements

  • Python 3
  • Node.js

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Identify the secret inputs to the function (private keys, plaintext, signatures, tokens)
  2. Trace data flow from the flagged instruction back to inputs
  3. Common false positive patterns
  4. Document your analysis for each flagged item

What it can do on your machine

Read from SKILL.md and the folder at commit ec02547. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • uv
    • dotnet

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com
    • kyberslash.cr.yp.to
    • bearssl.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Constant Time Analysis loads about 2.4k tokens when it runs. Until then it costs about 32 tokens; SKILL.md has 625 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~32
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sickn33/agentic-awesome-skills at commit ec02547, republished under its MIT licence (© sickn33). 625 words, ~2,359 tokens.

Download SKILL.mdSave it as .claude/skills/constant-time-analysis/SKILL.md (or your agent's skills folder).
name
constant-time-analysis
description
Analyze cryptographic code to detect operations that leak secret data through execution timing variations.
risk
critical
source
community
date_added
2026-09-04

Constant-Time Analysis

Analyze cryptographic code to detect operations that leak secret data through execution timing variations.

When to Use

text
User writing crypto code? ──yes──> Use this skill
         │
         no
         │
         v
User asking about timing attacks? ──yes──> Use this skill
         │
         no
         │
         v
Code handles secret keys/tokens? ──yes──> Use this skill
         │
         no
         │
         v
Skip this skill

Concrete triggers:

  • User implements signature, encryption, or key derivation
  • Code contains / or % operators on secret-derived values
  • User mentions "constant-time", "timing attack", "side-channel", "KyberSlash"
  • Reviewing functions named sign, verify, encrypt, decrypt, derive_key

When NOT to Use

  • Non-cryptographic code (business logic, UI, etc.)
  • Public data processing where timing leaks don't matter
  • Code that doesn't handle secrets, keys, or authentication tokens
  • High-level API usage where timing is handled by the library

Language Selection

Based on the file extension or language context, refer to the appropriate guide:

LanguageFile ExtensionsGuide
C, C++.c, .h, .cpp, .cc, .hppreferences/compiled.md
Go.goreferences/compiled.md
Rust.rsreferences/compiled.md
Swift.swiftreferences/swift.md
Java.javareferences/vm-compiled.md
Kotlin.kt, .ktsreferences/kotlin.md
C#.csreferences/vm-compiled.md
PHP.phpreferences/php.md
JavaScript.js, .mjs, .cjsreferences/javascript.md
TypeScript.ts, .tsxreferences/javascript.md
Python.pyreferences/python.md
Ruby.rbreferences/ruby.md

Quick Start

bash
# Analyze any supported file type
uv run {baseDir}/ct_analyzer/analyzer.py <source_file>

# Include conditional branch warnings
uv run {baseDir}/ct_analyzer/analyzer.py --warnings <source_file>

# Filter to specific functions
uv run {baseDir}/ct_analyzer/analyzer.py --func 'sign|verify' <source_file>

# JSON output for CI
uv run {baseDir}/ct_analyzer/analyzer.py --json <source_file>
Native Compiled Languages Only (C, C++, Go, Rust)
bash
# Cross-architecture testing (RECOMMENDED)
uv run {baseDir}/ct_analyzer/analyzer.py --arch x86_64 crypto.c
uv run {baseDir}/ct_analyzer/analyzer.py --arch arm64 crypto.c

# Multiple optimization levels
uv run {baseDir}/ct_analyzer/analyzer.py --opt-level O0 crypto.c
uv run {baseDir}/ct_analyzer/analyzer.py --opt-level O3 crypto.c
VM-Compiled Languages (Java, Kotlin, C#)
bash
# Analyze Java bytecode
uv run {baseDir}/ct_analyzer/analyzer.py CryptoUtils.java

# Analyze Kotlin bytecode (Android/JVM)
uv run {baseDir}/ct_analyzer/analyzer.py CryptoUtils.kt

# Analyze C# IL
uv run {baseDir}/ct_analyzer/analyzer.py CryptoUtils.cs

Note: Java, Kotlin, and C# compile to bytecode (JVM/CIL) that runs on a virtual machine with JIT compilation. The analyzer examines the bytecode directly, not the JIT-compiled native code. The --arch and --opt-level flags do not apply to these languages.

Swift (iOS/macOS)
bash
# Analyze Swift for native architecture
uv run {baseDir}/ct_analyzer/analyzer.py crypto.swift

# Analyze for specific architecture (iOS devices)
uv run {baseDir}/ct_analyzer/analyzer.py --arch arm64 crypto.swift

# Analyze with different optimization levels
uv run {baseDir}/ct_analyzer/analyzer.py --opt-level O0 crypto.swift

Note: Swift compiles to native code like C/C++/Go/Rust, so it uses assembly-level analysis and supports --arch and --opt-level flags.

Prerequisites
LanguageRequirements
C, C++, Go, RustCompiler in PATH (gcc/clang, go, rustc)
SwiftXcode or Swift toolchain (swiftc in PATH)
JavaJDK with javac and javap in PATH
KotlinKotlin compiler (kotlinc) + JDK (javap) in PATH
C#.NET SDK + ilspycmd (dotnet tool install -g ilspycmd)
PHPPHP with VLD extension or OPcache
JavaScript/TypeScriptNode.js in PATH
PythonPython 3.x in PATH
RubyRuby with --dump=insns support

macOS users: Homebrew installs Java and .NET as "keg-only". You must add them to your PATH:

bash
# For Java (add to ~/.zshrc)
export PATH="/opt/homebrew/opt/openjdk@21/bin:$PATH"

# For .NET tools (add to ~/.zshrc)
export PATH="$HOME/.dotnet/tools:$PATH"

See references/vm-compiled.md for detailed setup instructions and troubleshooting.

Quick Reference

ProblemDetectionFix
Division on secretsDIV, IDIV, SDIV, UDIVBarrett reduction or multiply-by-inverse
Branch on secretsJE, JNE, BEQ, BNEConstant-time selection (cmov, bit masking)
Secret comparisonEarly-exit memcmpUse crypto/subtle or constant-time compare
Weak RNGrand(), mt_rand, Math.randomUse crypto-secure RNG
Table lookup by secretArray subscript on secret indexBit-sliced lookups

Interpreting Results

PASSED - No variable-time operations detected.

FAILED - Dangerous instructions found. Example:

text
[ERROR] SDIV
  Function: decompose_vulnerable
  Reason: SDIV has early termination optimization; execution time depends on operand values
Show full SKILL.md (271 more words)Show less

Verifying Results (Avoiding False Positives)

CRITICAL: Not every flagged operation is a vulnerability. The tool has no data flow analysis - it flags ALL potentially dangerous operations regardless of whether they involve secrets.

For each flagged violation, ask: Does this operation's input depend on secret data?

  1. Identify the secret inputs to the function (private keys, plaintext, signatures, tokens)

  2. Trace data flow from the flagged instruction back to inputs

  3. Common false positive patterns:

    c
    // FALSE POSITIVE: Division uses public constant, not secret
    int num_blocks = data_len / 16;  // data_len is length, not content
    
    // TRUE POSITIVE: Division involves secret-derived value
    int32_t q = secret_coef / GAMMA2;  // secret_coef from private key
  4. Document your analysis for each flagged item

Quick Triage Questions
QuestionIf YesIf No
Is the operand a compile-time constant?Likely false positiveContinue
Is the operand a public parameter (length, count)?Likely false positiveContinue
Is the operand derived from key/plaintext/secret?TRUE POSITIVELikely false positive
Can an attacker influence the operand value?TRUE POSITIVELikely false positive

Limitations

  1. Static Analysis Only: Analyzes assembly/bytecode, not runtime behavior. Cannot detect cache timing or microarchitectural side-channels.

  2. No Data Flow Analysis: Flags all dangerous operations regardless of whether they process secrets. Manual review required.

  3. Compiler/Runtime Variations: Different compilers, optimization levels, and runtime versions may produce different output.

Real-World Impact

  • KyberSlash (2023): Division instructions in post-quantum ML-KEM implementations allowed key recovery
  • Lucky Thirteen (2013): Timing differences in CBC padding validation enabled plaintext recovery
  • RSA Timing Attacks: Early implementations leaked private key bits through division timing

References

© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/constant-time-analysis of sickn33/agentic-awesome-skills.

Open the folder on GitHubat commit ec02547

Used in 2 other repositories

We found 11 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Constant Time Analysis next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Constant Time Analysis compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Constant Time Analysis this skillsickn33/agentic-awesome-skills47k2 repos~2.4kAutomated safety check: PassMIT
Code Audit3stoneBrother/code-audit8931 repos~2.7kAutomated safety check: PassNone
Crap Analyzerswingerman/engineer154—~1.2kAutomated safety check: PassMIT
Constant-Time Analysistrailofbits/skills7.4k—~3.3kAutomated safety check: NotesCC-BY-SA-4.0
Code Revieweralirezarezvani/claude-skills28k1 repos~1.6kAutomated safety check: PassMIT
Fory Performance Optimizationapache/fory4.6k—~2.2kAutomated safety check: PassApache-2.0

Similar skills

  • Code Audit

    3stoneBrother/code-audit

    Professional code security audit skill covering 55+ vulnerability types.

    893 GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed
  • Crap Analyzer

    swingerman/engineer

    A skill your agent uses to produce a risk-based refactor + test plan for recently-changed code on a diff/branch/PR by computing CRAP (complexity × untested) on changed methods.

    154 GitHub stars~1.2k tokensUpdated 15 days ago
    Testing & QAAuto-check passed
  • Constant-Time Analysis

    trailofbits/skills

    Official

    Compiles cryptographic code and inspects the assembly or bytecode for variable-time instructions, then triages which flagged operations actually touch secrets.

    7.4k GitHub stars~3.3k tokensUpdated today
    SecurityAuto-check: notes
  • Code Reviewer

    alirezarezvani/claude-skills

    Code review automation for TypeScript, JavaScript, Python, Go, Swift, Kotlin, C, .NET, Java, C, C++, Rust, Ruby, PHP, and Dart/Flutter.

    28k GitHub starsUsed in 1 repo~1.6k tokens
    DevelopmentAuto-check passed
  • Run profile-driven bottleneck optimization across Apache Fory implementations (Java, C++, Python/Cython, Go, Rust, Swift, C, JavaScript/TypeScript, Dart, Kotlin, Scala).

    4.6k GitHub stars~2.2k tokensUpdated yesterday
    MobileAuto-check passed
  • Official

    Audits existing tests in any language using formal, research-backed test smell names and the testsmells.org 19-smell academic taxonomy.

    5.6k GitHub starsUsed in 1 repo~2.5k tokens
    MobileAuto-check passed

More from sickn33/agentic-awesome-skills

All 1,354 skills in this repo
  • Liuguang Banlan UI

    sickn33/agentic-awesome-skills

    Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • User Thoughts Memory

    sickn33/agentic-awesome-skills

    Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Using LWC Memory and Graphs

    sickn33/agentic-awesome-skills

    Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.

    47k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Find Complementary Founders

    sickn33/agentic-awesome-skills

    Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.

    47k GitHub starsUsed in 1 repo~4.8k tokens
    Auto-check passed
  • Cline Pilot

    sickn33/agentic-awesome-skills

    Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.

    47k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed
  • Content Creator

    sickn33/agentic-awesome-skills

    Drafts and reviews audience-specific content from supplied brand examples, with local scripts for brand voice and SEO diagnostics, channel templates and a content calendar.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed

Categories

Questions about Constant Time Analysis

What does Constant Time Analysis do?

Analyze cryptographic code to detect operations that leak secret data through execution timing variations. Constant Time Analysis is an agent skill from sickn33/agentic-awesome-skills. Analyze cryptographic code to detect operations that leak secret data through execution timing variations.

When should I use Constant Time Analysis?

Constant Time Analysis fits situations like: tasks that involve Cryptography.

How do I install Constant Time Analysis in Claude Code?

Run `npx skills add sickn33/agentic-awesome-skills --skill constant-time-analysis -a claude-code`. Or copy the skill folder (skills/constant-time-analysis in sickn33/agentic-awesome-skills) into .claude/skills/constant-time-analysis in your project. Claude Code loads it when a task matches its description.

How do I install Constant Time Analysis in Codex?

Run `npx skills add sickn33/agentic-awesome-skills --skill constant-time-analysis -a codex`. Or copy the skill folder (skills/constant-time-analysis in sickn33/agentic-awesome-skills) into .agents/skills/constant-time-analysis in your project. Codex loads it when a task matches its description.

Can I use Constant Time Analysis in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill constant-time-analysis -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/constant-time-analysis, .gemini/skills/constant-time-analysis, .github/skills/constant-time-analysis and .opencode/skills/constant-time-analysis in your project.

What does Constant Time Analysis need to run?

Going by SKILL.md and its folder, Constant Time Analysis needs the command-line tools its instructions call (uv and dotnet). Our summary lists: Python 3; Node.js.

Does Constant Time Analysis access the network?

SKILL.md names 3 domains. As links in the text: github.com, kyberslash.cr.yp.to and bearssl.org. This is read from the text; nothing was executed.

Is Constant Time Analysis safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Constant Time Analysis use?

Constant Time Analysis is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Constant Time Analysis use?

About 2.4k tokens (SKILL.md is roughly 9.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Constant Time Analysis?

Skills that share tags, products or a category with Constant Time Analysis: Code Audit (3stoneBrother/code-audit, 893 stars), Crap Analyzer (swingerman/engineer, 154 stars), Constant-Time Analysis (trailofbits/skills, 7.4k stars) and Code Reviewer (alirezarezvani/claude-skills, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Constant Time Analysis?

sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,343 GitHub stars. The repository holds 1,354 skills in this directory. The repository was last updated on October 7, 2026.

Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.