Hash function auditor
Skill Yue-Zhou1/zkcrypto-audit/plugins/crypto-primitive-auditors/skills/hash-function-auditor
Audit ZK-friendly hash functions (Poseidon, Rescue, MiMC, Pedersen) for parameter selection, sponge construction, domain separation, and algebraic attack resistance.From its SKILL.md
npx -y skills add Yue-Zhou1/zkcrypto-audit --skill hash-function-auditorAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 2 stars2 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
SKILL.md
2.3 KB, 443 tokens by cl100k_base, as published. Nobody here has run it
hash-function-auditor
Domain auditor for ZK-friendly hash primitive security and usage correctness.
When to Use
- Auditing Poseidon, Rescue, MiMC, Pedersen, or related ZK hash implementations
- Reviewing sponge absorption/squeezing APIs and parameterization
- Verifying domain separation tags across hash call sites
- Checking round count and matrix choices against claimed security margins
When NOT to Use
- Generic transcript review not focused on hash primitive internals
- Commitment opening verification without hash primitive concerns
- Marking hash findings as confirmed without verification gates
Core Review Areas
- Parameter selection and provenance
- Sponge construction and capacity/rate safety
- Domain separation and call-site context binding
- Algebraic attack resistance for chosen rounds and constants
- Matrix and S-box structural properties
Workflow
Phase 1: Parameter provenance review
- Read
references/hash-checklist.md - Verify round constants and MDS matrices are derived with clear provenance
- Confirm claimed security level matches round configuration
Phase 2: Sponge and API review
- Execute
workflows/sponge-review.md - Validate absorption/squeezing behavior, padding, and capacity boundaries
- Review call sites for unsafe reuse across protocol domains
Phase 3: Pattern hunt
- Read
references/finding-patterns.md - Prioritize weak constants, missing domain separation, and capacity misuse
Phase 4: Handoff
- Send surviving findings to
crypto-fp-check - Use
zkbugs-indexonly after verification succeeds
Output Contract
Produce a hash-audit handoff that includes:
- The primitive, parameter set, and call sites under review
- The exact security-property gap (capacity, rounds, separation, algebraic margin)
- The exploitability conditions and expected impact
- The next verification or reporting route
Reference Index
What ships with it: 4 files
3.5 KB alongside SKILL.md
agents/
- openai.yaml452 B
references/
- finding-patterns.md914 B
- hash-checklist.md1.1 KB
workflows/
- sponge-review.md1.0 KB