Encryption scheme auditor
Skill Yue-Zhou1/zkcrypto-audit/plugins/crypto-primitive-auditors/skills/encryption-scheme-auditor
Audit encryption implementations for AEAD nonce handling, decrypt oracle behavior, associated-data binding, key-derivation misuse, and decrypt-error side effects.From its SKILL.md
npx -y skills add Yue-Zhou1/zkcrypto-audit --skill encryption-scheme-auditorAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 2 stars2 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
SKILL.md
2.5 KB, 469 tokens by cl100k_base, as published. Nobody here has run it
encryption-scheme-auditor
Domain auditor for symmetric encryption and authenticated decryption safety.
When to Use
- Reviewing AEAD mode integrations and nonce lifecycle handling
- Auditing decrypt error behavior for oracle side effects
- Checking associated-data binding and tag verification ordering
- Reviewing key-derivation context separation across protocol roles
- Validating key rotation and algorithm agility controls
When NOT to Use
- Asymmetric key-exchange and signature protocol audits outside encryption modes
- Side-channel-focused constant-time analysis without encryption semantics
- Marking suspected encryption flaws as confirmed without verification gates
Core Review Areas
- Nonce generation, uniqueness, and reuse prevention under the same key
- AEAD tag verification-before-plaintext discipline
- Associated-data binding and domain separation
- Padding/MAC oracle surfaces in decrypt error paths
- KDF parameter/context separation and key lifecycle management
Workflow
Phase 1: Encrypt/decrypt path intake
- Read
references/encryption-checklist.md - Execute
workflows/decrypt-error-review.md - Map encrypt and decrypt entrypoints, including all error branches
Phase 2: Nonce and tag review
- Verify nonce creation, persistence, and replay safeguards
- Confirm tag checks complete before any plaintext is released
- Ensure associated-data inputs match protocol intent in both directions
Phase 3: Pattern hunt
- Read
references/finding-patterns.md - Prioritize nonce reuse, decrypt oracle behavior, and KDF context collisions
Phase 4: Handoff
- Send surviving findings to
crypto-fp-check - Use
zkbugs-indexonly after the finding survives verification
Output Contract
Produce an encryption-specific handoff that includes:
- The mode/implementation path and nonce lifecycle involved
- The decrypt error behavior and oracle risk surface
- Whether the issue is nonce, tag-ordering, AD-binding, KDF, or key-lifecycle related
- The next verification or reporting route
Reference Index
What ships with it: 4 files
3.6 KB alongside SKILL.md
agents/
- openai.yaml454 B
references/
- encryption-checklist.md1.3 KB
- finding-patterns.md751 B
workflows/
- decrypt-error-review.md1.2 KB