Skip to content
Back to skills

Hash Generator

ASecurity

Generate and verify cryptographic hashes with algorithm selection, salting, and integrity workflows.

  • 2 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 29, 2026
ai-agentspythonrustgoshellgitapisecurity

Works with

  • api

Security analysis

A100/100

Scanned September 29, 2026

npx -y skills add aicodedecode/awesome-muse-skills --skill hash-generator --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Hash Generator?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Hash Generator
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/aicodedecode-hash-generator/badge)](https://www.skillsdirectory.com/skills/aicodedecode-hash-generator)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: hash-generator
description: Generate and verify cryptographic hashes with algorithm selection, salting, and integrity workflows.
category: utilities
---

## Overview

Hashes are fingerprints for data: verifying downloads, deduplicating files, storing passwords
(properly), and building integrity checks. But not all hashes are equal — MD5 and SHA-1 are broken
for security, and password hashing needs specialized algorithms. This skill covers choosing the
right hash, generating and verifying checksums, and avoiding the classic mistakes.

## When to use

- Verifying file downloads against published checksums

- Choosing a hash algorithm for integrity or security

- Hashing passwords correctly (bcrypt/argon2, not SHA-256)

- Deduplicating files or detecting changes

- Understanding HMAC and digital signatures basics

## Core concepts

- - **Algorithm tiers.** Broken (MD5, SHA-1 — collisions practical; fine only for non-security
  checksums like quick dedup). Secure general-purpose (SHA-256, SHA-512, SHA-3, BLAKE2/3).
  Password-specific (bcrypt, scrypt, Argon2 — slow by design). Pick by threat model, not habit.
- - **Speed is a feature or a bug.** Fast hashes (SHA-256, BLAKE3) for file integrity — you want
  speed. Slow hashes (Argon2, bcrypt) for passwords — you want attackers slowed down. Using SHA-256
  for passwords is a vulnerability.
- - **Salts defeat rainbow tables.** Password hashing must use a unique random salt per password
  (bcrypt/Argon2 handle this internally). Unsalted hashes of common passwords are cracked instantly
  via precomputed tables.
- - **Checksums verify integrity, not authenticity.** A SHA-256 on the download page proves the file
  wasn't corrupted — but if the page was compromised, the hash was too. Authenticity needs
  signatures (GPG) or HTTPS from a trusted source.
- - **HMAC for message authentication.** Hash + secret key = proof the message came from someone
  with the key and wasn't altered. Used in API webhooks and tokens. Never roll your own MAC
  construction — use HMAC.
- - **Compare hashes safely.** Use constant-time comparison for security-sensitive hash checks
  (timing attacks can leak hash bytes). For file verification, normal string comparison is fine.

## Practical workflow

1. 1. **Choose the algorithm.** File integrity → SHA-256 (universal) or BLAKE3 (fastest). Passwords
   → Argon2id (modern best) or bcrypt (battle-tested). Checksums in legacy contexts → whatever's
   published, but verify the source.
2. **Generate checksums.** Shell:
   `sha256sum file.iso > file.iso.sha256`
   Verify: `sha256sum -c file.iso.sha256`
   Python: `hashlib.sha256(open("f","rb").read()).hexdigest()` (stream large files in chunks — don't
load multi-GB files into memory).
3. 3. **Verify downloads.** Compare against the publisher's published hash (fetched over HTTPS from
   the official site). Mismatch = do not use the file. Re-download or investigate — never override a
   failed check.
4. **Hash passwords properly.** Use a dedicated library (never raw SHA-256):
   Python example concept: `argon2.PasswordHasher().hash(password)` to store; `.verify(stored,
password)` to check. The library handles salt, cost factors, and format. Increase cost factors as
hardware improves.
5. 5. **Deduplicate with hashes.** Hash file contents (SHA-256) to find exact duplicates regardless
   of name. For near-duplicates (images), perceptual hashes (not cryptographic) are the tool.
6. 6. **Document the scheme.** In systems work: record which algorithm, how salts are
   generated/stored, and cost parameters. Future maintainers (and auditors) need this.

## Common pitfalls

- - **MD5/SHA-1 for security.** Collision attacks are practical. They're fine for non-adversarial
  checksums (cache keys, quick change detection) — never for signatures, certificates, or integrity
  against attackers.
- - **Fast hash for passwords.** SHA-256(password) falls to GPUs trying billions per second.
  Password hashing must be slow and salted — Argon2/bcrypt/scrypt only.
- - **No salt (or static salt).** Same password → same hash across users = rainbow-table
  vulnerability. Unique random salt per password, always.
- - **Trusting the hash source.** Verifying against a checksum posted on the same compromised page
  as the download. Get hashes from a separate trusted channel.
- - **Reading whole files into memory.** Hashing a 10GB file with `.read()` crashes. Stream in
  chunks (e.g., 64KB blocks).
- - **Rolling your own.** Custom hash constructions, homebrew KDFs, "double SHA-256 for extra
  security." Cryptography is a minefield — use standard, reviewed constructions.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…