Ethereum crypto auditor
Skill Yue-Zhou1/zkcrypto-audit/plugins/crypto-primitive-auditors/skills/ethereum-crypto-auditor
Audit Rust application code that uses Ethereum cryptography. Use when reviewing secp256k1/ECDSA usage, keccak/EIP-712 hashing, BN254/BLS12-381 precompile interaction, KZG/EIP-4844 patterns, or alloy/ethers-rs API usage.From its SKILL.md
npx -y skills add Yue-Zhou1/zkcrypto-audit --skill ethereum-crypto-auditorAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 2 stars2 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
SKILL.md
3.3 KB, 742 tokens by cl100k_base, as published. Nobody here has run it
ethereum-crypto-auditor
Domain auditor for Ethereum cryptography usage in Rust application code.
When to Use
- Auditing Rust code that calls secp256k1 signing, ecrecover, or ECDSA verification
- Reviewing keccak256 / EIP-712 / EIP-191 hashing in application logic
- Checking BN254 or BLS12-381 precompile input encoding and output decoding
- Auditing KZG blob commitment and opening proof handling (EIP-4844)
- Reviewing alloy / ethers-rs / web3 API usage for type confusion or encoding bugs
When NOT to Use
- Auditing curve arithmetic internals or pairing math (use
ecc-pairing-auditor) - Reviewing ZK circuit constraints or transcript construction
- Declaring findings confirmed without
crypto-fp-check
Core Review Areas
- secp256k1 / ECDSA usage — k-reuse, malleability (high/low-s), recovery ID, ecrecover input encoding
- Ethereum hash functions — keccak256 vs SHA3-256, EIP-712 / EIP-191 domain separation, prefix handling
- BN254 / BLS12-381 application usage — precompile input encoding (EIP-196/197, EIP-2537), subgroup membership checks, field element range validation
- KZG / EIP-4844 usage — trusted setup assumptions, blob commitment encoding, opening proof verification
- alloy / ethers-rs API misuse — type confusion, encoding errors, signature deserialization, address derivation from wrong public key form
- EVM precompile interaction — input padding/encoding, output decoding, error handling on failure
Workflow
Phase 1: Checklist pass
- Read
references/ethereum-crypto-checklist.md - Identify all crypto entry points and classify by area
- Enumerate every ECDSA call, hash invocation, precompile interaction, and KZG operation
Phase 2: ECDSA and hash review
- Execute
workflows/secp256k1-ecdsa-review.md - Treat every signature, ecrecover call, and hash-to-address path as hostile until validated
- Verify low-s normalization, recovery ID range, and EIP-712 domain separator construction
Phase 3: Precompile and KZG review
- Execute
workflows/evm-precompile-review.md - Verify input encoding, subgroup membership, field range, and output decoding for every precompile call and KZG operation
- Check error handling on precompile failure and return data length validation
Phase 4: Handoff
- Send surviving findings to
crypto-fp-check - Use
zkbugs-indexonly after verification succeeds
Output Contract
Produce an Ethereum-crypto handoff that includes:
- The crypto entry points, API calls, and encoding paths involved
- The exact malleability, encoding, domain-separation, or type-confusion issue
- Whether the issue is ECDSA, hash, precompile, KZG, or API-layer
- The next verification or reporting route
Reference Index
What ships with it: 5 files
9.0 KB alongside SKILL.md
agents/
- openai.yaml566 B
references/
- ethereum-crypto-checklist.md2.2 KB
- finding-patterns.md1.9 KB