Agent skill

Reviewing Cryptography

by trilwu in trilwu/secskills

Review cryptographic implementations and protocol usage for misuse — weak primitives, nonce and IV handling, key management, authentication of ciphertext, randomness, timing side channels, TLS and…

MITAuto-check passedSecurity

Install Reviewing Cryptography

skills CLI
$ npx skills add trilwu/secskills --skill reviewing-cryptography -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trilwu/secskills reviewing-cryptography --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/secskills-core/skills/reviewing-cryptography .claude/skills/reviewing-cryptography && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
reviewing-cryptography
GitHub stars
157
Token cost
~2.7k tokens
SKILL.md length
1,183 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

Review cryptographic implementations and protocol usage for misuse — weak primitives, nonce and IV handling, key management, authentication of ciphertext, randomness, timing side channels, TLS and…

  • Works in 9 steps: Is the ciphertext authenticated? → Nonce and IV handling → Key management → …
  • Auditing code that encrypts
  • SKILL.md covers When to Use, When NOT to Use, The Misuse Checklist and Protocol-Level Questions, plus 4 more sections
  • Calls rg, gitleaks and curl; reaches defuddle.md

What it does

Reviewing Cryptography is an agent skill from trilwu/secskills. Review cryptographic implementations and protocol usage for misuse — weak primitives, nonce and IV handling, key management, authentication of ciphertext, randomness, timing side channels, TLS and JWT configuration, and password storage. Use when auditing code that encrypts, signs, hashes, or authenticates, or when assessing TLS and token configurations.

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Cryptography and Authentication. The repository describes itself as: Transform Claude Code into your personal security engineer. The licence is MIT.

When your agent uses it

  • Auditing code that encrypts
  • Assessing TLS and token configurations

Example prompts

  • “/reviewing-cryptography”

Workflow steps

9 steps, taken from the step headings in SKILL.md.

  1. Is the ciphertext authenticated?
  2. Nonce and IV handling
  3. Key management
  4. Password storage
  5. Randomness
  6. Timing side channels
  7. Signature verification
  8. TLS configuration
  9. Post-quantum posture

What it can do on your machine

Read from SKILL.md and the folder at commit ca53957. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • rg
    • gitleaks
    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • defuddle.md

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Reviewing Cryptography loads about 2.7k tokens when it runs. Until then it costs about 95 tokens; SKILL.md has 1,183 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~95
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from trilwu/secskills at commit ca53957, republished under its MIT licence (© trilwu). 1,183 words, ~2,676 tokens.

Download SKILL.mdSave it as .claude/skills/reviewing-cryptography/SKILL.md (or your agent's skills folder).
name
reviewing-cryptography
description
Review cryptographic implementations and protocol usage for misuse — weak primitives, nonce and IV handling, key management, authentication of ciphertext, randomness, timing side channels, TLS and JWT configuration, and password storage. Use when auditing code that encrypts, signs, hashes, or authenticates, or when assessing TLS and token configurations.
verified
2026-07-27

Reviewing Cryptography

Almost no real system is broken by cryptanalysis. They are broken by misuse: a reused nonce, unauthenticated ciphertext, a comparison that returns early, a key checked into git. Review for misuse, and leave primitive design to cryptographers.

When to Use

  • Auditing code that encrypts, decrypts, signs, verifies, or hashes
  • Reviewing key management, rotation, and storage
  • Assessing TLS/mTLS configuration and certificate validation
  • Reviewing JWT, session token, and API signature schemes
  • Checking password and secret storage
  • Evaluating randomness quality for security-relevant values

When NOT to Use

  • Designing a new primitive or protocol — that needs a cryptographer and formal review, not a code audit
  • Breaking cryptography in a CTF — different discipline; use solving-oriented offensive skills and known-attack tooling
  • General code review — use auditing-code-for-vulnerabilities
  • Password cracking — use cracking-passwords

The Misuse Checklist

Work through these in order. Each has caught real production breaks.

1. Is the ciphertext authenticated?

Encryption without authentication is the single most common serious finding. CBC or CTR without a MAC means an attacker can modify plaintext — and with a decryption oracle, recover it (padding oracle).

Good:  AES-GCM, ChaCha20-Poly1305, AES-CBC + HMAC (encrypt-then-MAC)
Bad:   AES-CBC alone, AES-ECB (ever), CTR without a MAC, MAC-then-encrypt
bash
rg -n 'AES/ECB|AES\.MODE_ECB|CipherMode\.ECB|"AES"\)' -i
rg -n 'AES/CBC/PKCS5Padding|MODE_CBC|createCipheriv\(.*cbc' -i

If you see CBC, find the MAC. If there is no MAC, that is a finding regardless of how the ciphertext is transported.

2. Nonce and IV handling
ModeRuleFailure
GCM / ChaCha20-Poly1305Never reuse a (key, nonce) pairCatastrophic: reveals the auth key, forgery becomes trivial
CBCIV must be unpredictable and random per messageChosen-plaintext attacks (BEAST-class)
CTRNever reuse a counter with the same keyKeystream reuse; XOR of plaintexts
bash
# The classic bug: a fixed or zero IV
rg -n 'iv\s*=\s*(b?["\x27]0|new byte\[\d+\]|bytes\(\d+\)|\[0\]\s*\*)' -i
rg -n 'IvParameterSpec\(new byte\[16\]\)|createCipheriv\([^,]+,[^,]+,\s*["\x27]'

Random 96-bit nonces for GCM are safe up to roughly 2^32 messages per key. A counter-based nonce is safer, but only if the counter state genuinely survives restarts and is not duplicated across instances. Ask where the counter is persisted; "in memory" plus horizontal scaling means reuse.

3. Key management
  • Where does the key come from? Hardcoded, env var, KMS/HSM, derived?
  • Hardcoded keys, keys in source, keys in config committed to the repo, keys in container images, keys in CI logs — check all of these.
  • Is a key used for exactly one purpose? Key reuse across encryption and signing, or across tenants, is a finding.
  • Is there a rotation path at all? A system that cannot rotate has no response to compromise.
  • Derived keys: is a proper KDF used (HKDF for key material, Argon2id/scrypt/ PBKDF2 for passwords)? A raw SHA-256 of a password is not a KDF.
bash
rg -n 'BEGIN (RSA |EC |OPENSSH )?PRIVATE KEY|-----BEGIN'
rg -n '(secret|api[_-]?key|password|token)\s*[:=]\s*["\x27][A-Za-z0-9/+=]{16,}' -i
gitleaks detect --source . --redact      # history matters more than the tree
4. Password storage
Correct:   Argon2id (preferred), scrypt, bcrypt, PBKDF2-HMAC-SHA256 with a
           high iteration count — each with a per-user random salt
Wrong:     MD5, SHA-1, SHA-256, SHA-512 (raw or salted), any unsalted hash,
           encryption instead of hashing, a "pepper" as the only defense

Check the work factor against current guidance, not the value that was adequate when the code was written. And check that the verification path uses the library's constant-time verify function rather than comparing strings.

5. Randomness

Security-relevant values — tokens, session IDs, nonces, salts, password reset codes, IVs — must come from a CSPRNG.

bash
rg -n 'math/rand|Math\.random\(\)|random\.random\(|rand\(\)|mt_rand|Random\(\)' 
# Correct: crypto/rand, secrets.token_bytes, window.crypto.getRandomValues,
#          SecureRandom, os.urandom, RandomNumberGenerator

Also check: seeding with a timestamp or PID, UUIDv1/v4-from-a-weak-source used as a secret, and predictable sequential IDs used where unguessability is assumed.

6. Timing side channels

Any comparison of a secret must be constant time: MACs, tokens, API signatures, password hashes, OTPs.

bash
rg -n 'hmac.*==|token\s*==|signature\s*==|\.equals\(.*(hmac|token|sig)' -i
# Correct: hmac.compare_digest, crypto.timingSafeEqual, subtle.ConstantTimeCompare,
#          MessageDigest.isEqual, hash_equals

Early-return string comparison of an HMAC is a practical remote attack, not a theoretical one.

7. Signature verification
  • Is the signature actually verified, or merely parsed?
  • Is the algorithm taken from the message? (JWT alg confusion: none, and RS256→HS256 where the public key becomes the HMAC key.)
  • Is the key selected by an identifier the attacker controls (kid, jku, x5u)? Those fields are attacker input; treat them as such.
  • Are claims validated after signature verification: exp, nbf, iss, aud, and — critically — the subject's current authorization?
bash
rg -n 'jwt\.decode\(|verify\s*[:=]\s*(False|false)|algorithms\s*=\s*\[?["\x27]?none' -i
rg -n 'InsecureSkipVerify|verify\s*=\s*False|CURLOPT_SSL_VERIFYPEER.*0|rejectUnauthorized:\s*false'
8. TLS configuration
bash
# Server side
testssl.sh --severity MEDIUM https://target
sslyze --regular target:443
nmap --script ssl-enum-ciphers -p 443 target

# Look for: TLS < 1.2, RC4/3DES/NULL/EXPORT ciphers, no forward secrecy,
# weak DH params, expired or misissued certs, missing HSTS

Client side is more often wrong than server side. Check that certificate verification is enabled, that hostname verification is on (it is separate from chain verification in several libraries), and that custom trust stores are not silently accepting everything. A custom TrustManager that returns without throwing is the Java idiom for "no TLS at all."

9. Post-quantum posture

For anything with a long confidentiality lifetime, note harvest-now-decrypt later exposure and whether a hybrid key exchange (e.g. X25519 + ML-KEM) is available in the stack. This is a roadmap finding, not usually an urgent one — but say so explicitly rather than omitting it.

Show full SKILL.md (501 more words)Show less

Protocol-Level Questions

Beyond primitives, ask:

  • Replay: is there a nonce, timestamp, or sequence number, and is it actually checked and stored?
  • Binding: is the signature bound to the whole message, including the recipient and context? Signature-stripping and cross-protocol reuse come from under-scoped signing.
  • Downgrade: can a client or server be negotiated to a weaker mode?
  • Oracles: does the error handling distinguish "bad padding" from "bad MAC", or decryption failure from authorization failure? Any observable difference — including timing and response size — is an oracle.
  • Canonicalization: if a signature covers a serialized structure, can the same structure serialize two ways? JSON and XML signature schemes break here routinely.

Rationalizations to Reject

  • "It's encrypted." Encrypted is not authenticated, and not authorized.
  • "We use AES-256, so it's strong." Key size is almost never the weak link.
  • "The IV is random enough." Show where it is generated and from what.
  • "Timing attacks aren't practical over a network." They are, and have been demonstrated repeatedly across the internet.
  • "We rolled our own because the library was awkward." Custom crypto is a finding on its own. Name the library that should be used instead.
  • "The key is in an environment variable, not the code." Better, but check where the env var is set, who can read the process environment, and whether it appears in logs, crash dumps, or the container image.
  • "Certificate pinning is too much hassle." Fine — but then say so as an accepted risk, do not disable verification instead.
  • "It's internal traffic." Internal networks are where lateral movement happens.

Deliverable

For each finding: the primitive or protocol involved, the specific misuse, the concrete attack it enables (not "weak crypto"), the affected data and its confidentiality lifetime, and the specific correct construction — named library, named mode, named parameters. Cryptography findings that recommend "use strong encryption" do not get fixed.

Reading External Sources

Fetch public advisories, specifications, and vendor reports as Markdown:

bash
curl -sL "https://defuddle.md/<url>"      # scheme in the path is optional

This strips page boilerplate — roughly 78% fewer tokens on a prose page — and returns the full text rather than a summary, so you can grep it and trust a negative result.

Three things it is not for. Fetch JSON and API responses raw, because readability extraction mangles structured data. Fetch authenticated or JavaScript-rendered pages directly, because it retrieves them anonymously. And never route adversary infrastructure (phishing links, C2, malware hosting), client-owned hosts, or engagement URLs through it — the request leaves your machine to a third party, and for live adversary infrastructure it also tips off the operator.

Some sites block the extractor and return an error blob rather than the page — {"error":"Failed to fetch: 418 I'm a teapot"} from freedesktop.org, for instance. That is the fetch being refused, not the source saying the thing does not exist. Re-fetch the URL directly before drawing any conclusion from it.

References

  • auditing-code-for-vulnerabilities — the surrounding code review
  • cracking-passwords — offensive side of weak password storage
  • testing-apis — token and signature handling at the API layer
  • Libraries to recommend: libsodium/NaCl, Google Tink, age, platform AEAD APIs
  • testssl.sh, sslyze, cryptography (Python) audit APIs, cargo-crev

© trilwu, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in secskills-core/skills/reviewing-cryptography of trilwu/secskills.

Open the folder on GitHubat commit ca53957

Compare with similar skills

Reviewing Cryptography next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Reviewing Cryptography compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Reviewing Cryptography this skilltrilwu/secskills157—~2.7kAutomated safety check: PassMIT
Implementing Mtls For Zero Trust Servicesmukul975/Anthropic-Cybersecurity-Skills34k—~650Automated safety check: PassApache-2.0
Implementing Zero Knowledge Proof For Authenticationmukul975/Anthropic-Cybersecurity-Skills34k—~858Automated safety check: PassApache-2.0
Add Eap Methodtalkincode/toughradius691—~802Automated safety check: PassMIT
Security ProtocolNoobyGains/godmode109—~2.4kAutomated safety check: NotesMIT
Static Vulnerability DetectorArabelaTso/Skills-4-SE253—~2kAutomated safety check: PassApache-2.0

Similar skills

  • Implementing Mtls For Zero Trust Services

    mukul975/Anthropic-Cybersecurity-Skills

    Configures mutual TLS (mTLS) authentication between microservices using Python cryptography library for certificate generation and ssl module for TLS verification.

    34k GitHub stars~650 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Implementing Zero Knowledge Proof For Authentication

    mukul975/Anthropic-Cybersecurity-Skills

    Implements the Schnorr identification protocol and a simplified Zero-Knowledge Password Proof (ZKPP) over the discrete logarithm problem, letting a prover authenticate by demonstrating knowledge of…

    34k GitHub stars~858 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Add Eap Method

    talkincode/toughradius

    Add an EAP authentication method (e.g. An agent skill from talkincode/toughradius.

    691 GitHub stars~802 tokensUpdated yesterday
    Frontend & DesignAuto-check passed
  • Security Protocol

    NoobyGains/godmode

    A skill your agent uses when writing code that processes user input, manages authentication or authorization, constructs database queries, handles file operations, interacts with external data…

    109 GitHub stars~2.4k tokensUpdated 7 mo ago
    Backend & APIsAuto-check: notes
  • Static Vulnerability Detector

    ArabelaTso/Skills-4-SE

    Statically analyze code to detect security vulnerabilities including buffer overflows, injection risks (SQL, command, XSS), insecure deserialization, improper authentication, hard-coded credentials…

    253 GitHub stars~2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Elasticsearch Authn

    aspectrr/deer

    Authenticate to Elasticsearch using native, file-based, LDAP/AD, SAML, OIDC, Kerberos, JWT, or certificate realms.

    405 GitHub stars~1.2k tokensUpdated 5 mo ago
    Backend & APIsAuto-check: notes

More from trilwu/secskills

All 50 skills in this repo
  • Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.

    157 GitHub stars~3.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.

    157 GitHub stars~3.1k tokensUpdated 1 mo ago
    Auto-check: notes
  • Securing AI Systems

    trilwu/secskills

    Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…

    157 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing Binaries

    trilwu/secskills

    Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.

    157 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing Go Binaries

    trilwu/secskills

    Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…

    157 GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing iOS Binaries

    trilwu/secskills

    Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…

    157 GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Reviewing Cryptography

What does Reviewing Cryptography do?

Review cryptographic implementations and protocol usage for misuse — weak primitives, nonce and IV handling, key management, authentication of ciphertext, randomness, timing side channels, TLS and…. Reviewing Cryptography is an agent skill from trilwu/secskills. Review cryptographic implementations and protocol usage for misuse — weak primitives, nonce and IV handling, key management, authentication of ciphertext, randomness, timing side channels, TLS and JWT configuration, and password storage.

When should I use Reviewing Cryptography?

Reviewing Cryptography fits situations like: auditing code that encrypts; assessing TLS and token configurations.

How do I install Reviewing Cryptography in Claude Code?

Run `npx skills add trilwu/secskills --skill reviewing-cryptography -a claude-code`. Or copy the skill folder (secskills-core/skills/reviewing-cryptography in trilwu/secskills) into .claude/skills/reviewing-cryptography in your project. Claude Code loads it when a task matches its description.

How do I install Reviewing Cryptography in Codex?

Run `npx skills add trilwu/secskills --skill reviewing-cryptography -a codex`. Or copy the skill folder (secskills-core/skills/reviewing-cryptography in trilwu/secskills) into .agents/skills/reviewing-cryptography in your project. Codex loads it when a task matches its description.

Can I use Reviewing Cryptography in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trilwu/secskills --skill reviewing-cryptography -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/reviewing-cryptography, .gemini/skills/reviewing-cryptography, .github/skills/reviewing-cryptography and .opencode/skills/reviewing-cryptography in your project.

What does Reviewing Cryptography need to run?

Going by SKILL.md and its folder, Reviewing Cryptography needs the command-line tools its instructions call (rg, gitleaks and curl).

Does Reviewing Cryptography access the network?

SKILL.md names 1 domain. In commands or code: defuddle.md; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Reviewing Cryptography safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Reviewing Cryptography use?

Reviewing Cryptography is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Reviewing Cryptography use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Reviewing Cryptography?

Skills that share tags, products or a category with Reviewing Cryptography: Implementing Mtls For Zero Trust Services (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Implementing Zero Knowledge Proof For Authentication (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Add Eap Method (talkincode/toughradius, 691 stars) and Security Protocol (NoobyGains/godmode, 109 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Reviewing Cryptography?

trilwu (a GitHub user) maintains it in trilwu/secskills, which has 157 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on September 4, 2026.

Source: trilwu/secskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.