SKILLS/performing-cryptographic-audit-of-application/SKILL.md
A cryptographic audit systematically reviews an application's use of cryptographic primitives, protocols, and key management to identify vulnerabilities such as weak algorithms, insecure modes, hardco
npx skillsauth add pinkpixel-dev/skills-collection-2 performing-cryptographic-audit-of-applicationInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
A cryptographic audit systematically reviews an application's use of cryptographic primitives, protocols, and key management to identify vulnerabilities such as weak algorithms, insecure modes, hardcoded keys, insufficient entropy, and protocol misconfigurations. This skill covers building an automated crypto audit tool that scans Python and configuration files for common cryptographic weaknesses.
| Category | Examples | Risk Level | |----------|----------|------------| | Weak Hashing | MD5, SHA-1 for integrity/signatures | High | | Insecure Encryption | DES, 3DES, RC4, Blowfish | High | | Bad Cipher Mode | ECB mode for any block cipher | High | | Insufficient Key Size | RSA < 2048, AES-128 for long-term | Medium | | Hardcoded Secrets | Keys/passwords in source code | Critical | | Weak KDF | Low iteration PBKDF2, plain MD5 | High | | Poor Entropy | time-based seeds, predictable IVs | High | | Deprecated Protocols | SSLv3, TLS 1.0, TLS 1.1 | High |
tools
Extract stored credentials from compromised endpoints using the LaZagne post-exploitation tool to recover passwords from browsers, databases, system vaults, and applications during authorized red team operations.
testing
Analyze and bypass Content Security Policy implementations to achieve cross-site scripting by exploiting misconfigurations, JSONP endpoints, unsafe directives, and policy injection techniques.
testing
Scan container images, filesystems, and Kubernetes manifests for vulnerabilities, misconfigurations, exposed secrets, and license compliance issues using Aqua Security Trivy with SBOM generation and CI/CD integration.
development
This skill covers hardening container images by minimizing attack surface, removing unnecessary packages, implementing multi-stage builds, configuring non-root users, and applying CIS Docker Benchmark recommendations to produce secure production-ready images.