Implementing Mtls For Zero Trust Services
mukul975/Anthropic-Cybersecurity-Skills
Configures mutual TLS (mTLS) authentication between microservices using Python cryptography library for certificate generation and ssl module for TLS verification.
Review cryptographic implementations and protocol usage for misuse — weak primitives, nonce and IV handling, key management, authentication of ciphertext, randomness, timing side channels, TLS and…
$ npx skills add trilwu/secskills --skill reviewing-cryptography -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install trilwu/secskills reviewing-cryptography --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/secskills-core/skills/reviewing-cryptography .claude/skills/reviewing-cryptography && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "reviewing-cryptography" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-core/skills/reviewing-cryptography into .claude/skills/reviewing-cryptography/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "reviewing-cryptography", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/trilwu/secskills/tree/main/secskills-core/skills/reviewing-cryptographyType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add trilwu/secskills --skill reviewing-cryptography -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install trilwu/secskills reviewing-cryptography --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/secskills-core/skills/reviewing-cryptography .agents/skills/reviewing-cryptography && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "reviewing-cryptography" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-core/skills/reviewing-cryptography into .agents/skills/reviewing-cryptography/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "reviewing-cryptography", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trilwu/secskills --skill reviewing-cryptography -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install trilwu/secskills reviewing-cryptography --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/secskills-core/skills/reviewing-cryptography .cursor/skills/reviewing-cryptography && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "reviewing-cryptography" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-core/skills/reviewing-cryptography into .cursor/skills/reviewing-cryptography/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "reviewing-cryptography", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/trilwu/secskills.git --path secskills-core/skills/reviewing-cryptography--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add trilwu/secskills --skill reviewing-cryptography -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install trilwu/secskills reviewing-cryptography --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/secskills-core/skills/reviewing-cryptography .gemini/skills/reviewing-cryptography && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "reviewing-cryptography" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-core/skills/reviewing-cryptography into .gemini/skills/reviewing-cryptography/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "reviewing-cryptography", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install trilwu/secskills reviewing-cryptographyInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add trilwu/secskills --skill reviewing-cryptography -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .github/skills && cp -r skills-src/secskills-core/skills/reviewing-cryptography .github/skills/reviewing-cryptography && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "reviewing-cryptography" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-core/skills/reviewing-cryptography into .github/skills/reviewing-cryptography/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "reviewing-cryptography", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trilwu/secskills --skill reviewing-cryptography -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install trilwu/secskills reviewing-cryptography --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/secskills-core/skills/reviewing-cryptography .opencode/skills/reviewing-cryptography && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "reviewing-cryptography" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-core/skills/reviewing-cryptography into .opencode/skills/reviewing-cryptography/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "reviewing-cryptography", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
reviewing-cryptographyReview cryptographic implementations and protocol usage for misuse — weak primitives, nonce and IV handling, key management, authentication of ciphertext, randomness, timing side channels, TLS and…
Reviewing Cryptography is an agent skill from trilwu/secskills. Review cryptographic implementations and protocol usage for misuse — weak primitives, nonce and IV handling, key management, authentication of ciphertext, randomness, timing side channels, TLS and JWT configuration, and password storage. Use when auditing code that encrypts, signs, hashes, or authenticates, or when assessing TLS and token configurations.
Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Cryptography and Authentication. The repository describes itself as: Transform Claude Code into your personal security engineer. The licence is MIT.
9 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit ca53957. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
rggitleakscurlFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
defuddle.mdFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Reviewing Cryptography loads about 2.7k tokens when it runs. Until then it costs about 95 tokens; SKILL.md has 1,183 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from trilwu/secskills at commit ca53957, republished under its MIT licence (© trilwu). 1,183 words, ~2,676 tokens.
.claude/skills/reviewing-cryptography/SKILL.md (or your agent's skills folder).Almost no real system is broken by cryptanalysis. They are broken by misuse: a reused nonce, unauthenticated ciphertext, a comparison that returns early, a key checked into git. Review for misuse, and leave primitive design to cryptographers.
solving-oriented offensive skills and known-attack toolingauditing-code-for-vulnerabilitiescracking-passwordsWork through these in order. Each has caught real production breaks.
Encryption without authentication is the single most common serious finding. CBC or CTR without a MAC means an attacker can modify plaintext — and with a decryption oracle, recover it (padding oracle).
Good: AES-GCM, ChaCha20-Poly1305, AES-CBC + HMAC (encrypt-then-MAC)
Bad: AES-CBC alone, AES-ECB (ever), CTR without a MAC, MAC-then-encryptrg -n 'AES/ECB|AES\.MODE_ECB|CipherMode\.ECB|"AES"\)' -i
rg -n 'AES/CBC/PKCS5Padding|MODE_CBC|createCipheriv\(.*cbc' -iIf you see CBC, find the MAC. If there is no MAC, that is a finding regardless of how the ciphertext is transported.
| Mode | Rule | Failure |
|---|---|---|
| GCM / ChaCha20-Poly1305 | Never reuse a (key, nonce) pair | Catastrophic: reveals the auth key, forgery becomes trivial |
| CBC | IV must be unpredictable and random per message | Chosen-plaintext attacks (BEAST-class) |
| CTR | Never reuse a counter with the same key | Keystream reuse; XOR of plaintexts |
# The classic bug: a fixed or zero IV
rg -n 'iv\s*=\s*(b?["\x27]0|new byte\[\d+\]|bytes\(\d+\)|\[0\]\s*\*)' -i
rg -n 'IvParameterSpec\(new byte\[16\]\)|createCipheriv\([^,]+,[^,]+,\s*["\x27]'Random 96-bit nonces for GCM are safe up to roughly 2^32 messages per key. A counter-based nonce is safer, but only if the counter state genuinely survives restarts and is not duplicated across instances. Ask where the counter is persisted; "in memory" plus horizontal scaling means reuse.
rg -n 'BEGIN (RSA |EC |OPENSSH )?PRIVATE KEY|-----BEGIN'
rg -n '(secret|api[_-]?key|password|token)\s*[:=]\s*["\x27][A-Za-z0-9/+=]{16,}' -i
gitleaks detect --source . --redact # history matters more than the treeCorrect: Argon2id (preferred), scrypt, bcrypt, PBKDF2-HMAC-SHA256 with a
high iteration count — each with a per-user random salt
Wrong: MD5, SHA-1, SHA-256, SHA-512 (raw or salted), any unsalted hash,
encryption instead of hashing, a "pepper" as the only defenseCheck the work factor against current guidance, not the value that was adequate when the code was written. And check that the verification path uses the library's constant-time verify function rather than comparing strings.
Security-relevant values — tokens, session IDs, nonces, salts, password reset codes, IVs — must come from a CSPRNG.
rg -n 'math/rand|Math\.random\(\)|random\.random\(|rand\(\)|mt_rand|Random\(\)'
# Correct: crypto/rand, secrets.token_bytes, window.crypto.getRandomValues,
# SecureRandom, os.urandom, RandomNumberGeneratorAlso check: seeding with a timestamp or PID, UUIDv1/v4-from-a-weak-source used as a secret, and predictable sequential IDs used where unguessability is assumed.
Any comparison of a secret must be constant time: MACs, tokens, API signatures, password hashes, OTPs.
rg -n 'hmac.*==|token\s*==|signature\s*==|\.equals\(.*(hmac|token|sig)' -i
# Correct: hmac.compare_digest, crypto.timingSafeEqual, subtle.ConstantTimeCompare,
# MessageDigest.isEqual, hash_equalsEarly-return string comparison of an HMAC is a practical remote attack, not a theoretical one.
alg confusion: none, and
RS256→HS256 where the public key becomes the HMAC key.)kid, jku,
x5u)? Those fields are attacker input; treat them as such.exp, nbf, iss,
aud, and — critically — the subject's current authorization?rg -n 'jwt\.decode\(|verify\s*[:=]\s*(False|false)|algorithms\s*=\s*\[?["\x27]?none' -i
rg -n 'InsecureSkipVerify|verify\s*=\s*False|CURLOPT_SSL_VERIFYPEER.*0|rejectUnauthorized:\s*false'# Server side
testssl.sh --severity MEDIUM https://target
sslyze --regular target:443
nmap --script ssl-enum-ciphers -p 443 target
# Look for: TLS < 1.2, RC4/3DES/NULL/EXPORT ciphers, no forward secrecy,
# weak DH params, expired or misissued certs, missing HSTSClient side is more often wrong than server side. Check that certificate
verification is enabled, that hostname verification is on (it is separate
from chain verification in several libraries), and that custom trust stores
are not silently accepting everything. A custom TrustManager that returns
without throwing is the Java idiom for "no TLS at all."
For anything with a long confidentiality lifetime, note harvest-now-decrypt later exposure and whether a hybrid key exchange (e.g. X25519 + ML-KEM) is available in the stack. This is a roadmap finding, not usually an urgent one — but say so explicitly rather than omitting it.
Beyond primitives, ask:
For each finding: the primitive or protocol involved, the specific misuse, the concrete attack it enables (not "weak crypto"), the affected data and its confidentiality lifetime, and the specific correct construction — named library, named mode, named parameters. Cryptography findings that recommend "use strong encryption" do not get fixed.
Fetch public advisories, specifications, and vendor reports as Markdown:
curl -sL "https://defuddle.md/<url>" # scheme in the path is optionalThis strips page boilerplate — roughly 78% fewer tokens on a prose page — and returns the full text rather than a summary, so you can grep it and trust a negative result.
Three things it is not for. Fetch JSON and API responses raw, because readability extraction mangles structured data. Fetch authenticated or JavaScript-rendered pages directly, because it retrieves them anonymously. And never route adversary infrastructure (phishing links, C2, malware hosting), client-owned hosts, or engagement URLs through it — the request leaves your machine to a third party, and for live adversary infrastructure it also tips off the operator.
Some sites block the extractor and return an error blob rather than the page —
{"error":"Failed to fetch: 418 I'm a teapot"} from freedesktop.org, for
instance. That is the fetch being refused, not the source saying the thing
does not exist. Re-fetch the URL directly before drawing any conclusion from
it.
auditing-code-for-vulnerabilities — the surrounding code reviewcracking-passwords — offensive side of weak password storagetesting-apis — token and signature handling at the API layerage, platform AEAD APIstestssl.sh, sslyze, cryptography (Python) audit APIs, cargo-crev© trilwu, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in secskills-core/skills/reviewing-cryptography of trilwu/secskills.
Open the folder on GitHubat commit ca53957
Reviewing Cryptography next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Reviewing Cryptography this skilltrilwu/secskills | 157 | — | ~2.7k | Automated safety check: Pass | MIT | |
| Implementing Mtls For Zero Trust Servicesmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~650 | Automated safety check: Pass | Apache-2.0 | |
| Implementing Zero Knowledge Proof For Authenticationmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~858 | Automated safety check: Pass | Apache-2.0 | |
| Add Eap Methodtalkincode/toughradius | 691 | — | ~802 | Automated safety check: Pass | MIT | |
| Security ProtocolNoobyGains/godmode | 109 | — | ~2.4k | Automated safety check: Notes | MIT | |
| Static Vulnerability DetectorArabelaTso/Skills-4-SE | 253 | — | ~2k | Automated safety check: Pass | Apache-2.0 |
mukul975/Anthropic-Cybersecurity-Skills
Configures mutual TLS (mTLS) authentication between microservices using Python cryptography library for certificate generation and ssl module for TLS verification.
mukul975/Anthropic-Cybersecurity-Skills
Implements the Schnorr identification protocol and a simplified Zero-Knowledge Password Proof (ZKPP) over the discrete logarithm problem, letting a prover authenticate by demonstrating knowledge of…
talkincode/toughradius
Add an EAP authentication method (e.g. An agent skill from talkincode/toughradius.
NoobyGains/godmode
A skill your agent uses when writing code that processes user input, manages authentication or authorization, constructs database queries, handles file operations, interacts with external data…
ArabelaTso/Skills-4-SE
Statically analyze code to detect security vulnerabilities including buffer overflows, injection risks (SQL, command, XSS), insecure deserialization, improper authentication, hard-coded credentials…
aspectrr/deer
Authenticate to Elasticsearch using native, file-based, LDAP/AD, SAML, OIDC, Kerberos, JWT, or certificate realms.
trilwu/secskills
Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.
trilwu/secskills
Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.
trilwu/secskills
Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…
trilwu/secskills
Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.
trilwu/secskills
Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…
trilwu/secskills
Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…
Categories
Review cryptographic implementations and protocol usage for misuse — weak primitives, nonce and IV handling, key management, authentication of ciphertext, randomness, timing side channels, TLS and…. Reviewing Cryptography is an agent skill from trilwu/secskills. Review cryptographic implementations and protocol usage for misuse — weak primitives, nonce and IV handling, key management, authentication of ciphertext, randomness, timing side channels, TLS and JWT configuration, and password storage.
Reviewing Cryptography fits situations like: auditing code that encrypts; assessing TLS and token configurations.
Run `npx skills add trilwu/secskills --skill reviewing-cryptography -a claude-code`. Or copy the skill folder (secskills-core/skills/reviewing-cryptography in trilwu/secskills) into .claude/skills/reviewing-cryptography in your project. Claude Code loads it when a task matches its description.
Run `npx skills add trilwu/secskills --skill reviewing-cryptography -a codex`. Or copy the skill folder (secskills-core/skills/reviewing-cryptography in trilwu/secskills) into .agents/skills/reviewing-cryptography in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trilwu/secskills --skill reviewing-cryptography -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/reviewing-cryptography, .gemini/skills/reviewing-cryptography, .github/skills/reviewing-cryptography and .opencode/skills/reviewing-cryptography in your project.
Going by SKILL.md and its folder, Reviewing Cryptography needs the command-line tools its instructions call (rg, gitleaks and curl).
SKILL.md names 1 domain. In commands or code: defuddle.md; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Reviewing Cryptography is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Reviewing Cryptography: Implementing Mtls For Zero Trust Services (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Implementing Zero Knowledge Proof For Authentication (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Add Eap Method (talkincode/toughradius, 691 stars) and Security Protocol (NoobyGains/godmode, 109 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
trilwu (a GitHub user) maintains it in trilwu/secskills, which has 157 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on September 4, 2026.
Source: trilwu/secskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.