Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsCommunityBlog
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Sh Kb Crypto

ASecurity

Knowledge base for finding cryptographic failures - weak hashing/encryption, insecure randomness, hardcoded/static keys and IVs, ECB mode, missing integrity, and predictable tokens. Use when hunting crypto misuse. CWE-327/328/330/326/916, OWASP A02:2021-Cryptographic Failures.

14 stars
0 votes
0 copies
0 views
Added 9/28/2026
securitypythonrustgojavasqlnodesecurity

Security Analysis

A100/100

Scanned 9/28/2026

Install to Claude Code

$npx -y skills add dmdhrumilmistry/security-harness --skill sh-kb-crypto --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Sh Kb Crypto?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Sh Kb Crypto
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/dmdhrumilmistry-sh-kb-crypto/badge)](https://www.skillsdirectory.com/skills/dmdhrumilmistry-sh-kb-crypto)

More formats (shields.io, HTML) on the badges page.

Files
SKILL.md
---
name: sh-kb-crypto
description: "Knowledge base for finding cryptographic failures - weak hashing/encryption, insecure randomness, hardcoded/static keys and IVs, ECB mode, missing integrity, and predictable tokens. Use when hunting crypto misuse. CWE-327/328/330/326/916, OWASP A02:2021-Cryptographic Failures."
---

# Cryptographic Failures - Hunter Knowledge Base

Broken or misused cryptography: weak algorithms, predictable randomness, static keys/IVs, missing
integrity, or protecting nothing (plaintext). Impact depends on what the crypto was meant to protect.

## What to hunt
- **Weak/broken algorithms** (CWE-327/328): `MD5`/`SHA1` for passwords or signatures, `DES`/`3DES`/`RC4`,
  fast hashes for password storage (should be argon2/bcrypt/scrypt/PBKDF2).
- **Insecure randomness** (CWE-330/338): `Math.random()`, `random.random()`/`random.randint`, `rand()`,
  `java.util.Random`, time-seeded RNG used for tokens/session ids/password-reset/OTP/nonces/keys.
- **Static/hardcoded key or IV** (CWE-321/329): fixed AES key/IV in source; reused nonce; predictable salt.
- **ECB mode** (CWE-327): `AES/ECB` leaks plaintext patterns.
- **Missing integrity / unauthenticated encryption**: CBC without a MAC (padding-oracle risk); encrypt
  without authenticate; not using AEAD (AES-GCM/ChaCha20-Poly1305).
- **Bad TLS/cert handling**: disabled verification (`verify=False`, `rejectUnauthorized:false`,
  `InsecureSkipVerify:true`, trust-all TrustManager/HostnameVerifier).
- **Weak KDF params**: low PBKDF2 iterations, no salt.

## Sinks (grep targets)
`md5(|sha1(|MD5|SHA1|DES|RC4|Math.random|random\.(random|randint|choice)|util.Random|AES/ECB|ECB|
verify=False|rejectUnauthorized|InsecureSkipVerify|createCipher\(|PBKDF2.*iterations|IV\s*=`.
Look near "password", "token", "key", "encrypt", "sign", "session".

## Detection recipe
1. Grep the patterns above; for each, determine **what is being protected** and the **threat model**.
2. Password storage: which hash + salt + params? Token generation: which RNG? Encryption: algorithm, mode,
   key/IV source, integrity?
3. Confirm the weakness is used on security-relevant data (a non-security CRC/`md5` for a cache key is fine).

## PoC / evidence
- The code using the weak primitive at `file:line`. For randomness: show tokens derive from a predictable
  RNG (attacker can predict/brute future values). For static key: show the literal key/IV.
- Padding oracle / ECB: describe the exploit conditions; a full oracle PoC is usually `needs-runtime`.

## False-positive filters
- MD5/SHA1 used for **non-security** purposes (ETags, cache keys, dedup checksums) - not a finding.
- CSPRNG in use: `secrets`/`os.urandom` (Python), `crypto.randomBytes` (Node), `SecureRandom` (Java),
  `crypto/rand` (Go). Password hashing via argon2/bcrypt/scrypt with salt.
- AEAD (AES-GCM/ChaCha20-Poly1305) or encrypt-then-MAC; per-message random IV/nonce; keys from a KMS/secret
  manager. TLS verification enabled (the insecure flags are dev-only and not shipped).

## CWE / OWASP / severity
CWE-327/328/330/338/321/326/916, CWE-295 (cert validation). OWASP A02:2021. Forgeable tokens / broken auth
crypto / disabled TLS verification -> **high/critical**; weak-but-limited -> medium.

## Chaining hints
Predictable reset/session tokens -> `auth` account takeover; static JWT/HMAC key -> forge tokens; disabled
TLS verification -> MITM -> credential capture; weak password hash + a `secrets`/`sqli` DB dump -> mass
credential cracking.

## Mitigation
Use argon2/bcrypt/scrypt (salted) for passwords; CSPRNG for all tokens/keys/IVs; AES-GCM or
ChaCha20-Poly1305 (AEAD) with per-message nonces; keys from a KMS/secret manager, never hardcoded; enforce
TLS certificate verification; drop MD5/SHA1/DES/RC4/ECB for security purposes.

Attribution

dmdhrumilmistrydmdhrumilmistry
View sourceMore from dmdhrumilmistry →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Springboot Security

Java Spring Boot 服务中关于身份验证/授权、验证、CSRF、密钥、标头、速率限制和依赖安全的 Spring Security 最佳实践。

2456590 votes

Security Review

Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.

2456590 votes

Paperclip Evals

Choose, inspect, validate, and report Paperclip Runner or Product E2E evaluations while preserving evidence, provenance, cost, and failure classification.

813270 votes

Paperclip Task Bridge

Create, comment on, update, and list Paperclip tasks from Hermes using scoped Paperclip API credentials.

813270 votes

Summarize Status

Write a short, colloquial summary for a Paperclip summary slot: open with the 1–3 specific, concrete actions the reader needs to take right now to unblock the work, then a brief plain-language status, streaming progress as it works.

813270 votes
View all in security →