agentsclimarketplace

Hash function auditor

Skill Yue-Zhou1/zkcrypto-audit/plugins/crypto-primitive-auditors/skills/hash-function-auditor

Audit ZK-friendly hash functions (Poseidon, Rescue, MiMC, Pedersen) for parameter selection, sponge construction, domain separation, and algebraic attack resistance.From its SKILL.md

Install
npx -y skills add Yue-Zhou1/zkcrypto-audit --skill hash-function-auditor

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 2 stars2 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

SKILL.md

2.3 KB, 443 tokens by cl100k_base, as published. Nobody here has run it

hash-function-auditor

Domain auditor for ZK-friendly hash primitive security and usage correctness.

When to Use

  • Auditing Poseidon, Rescue, MiMC, Pedersen, or related ZK hash implementations
  • Reviewing sponge absorption/squeezing APIs and parameterization
  • Verifying domain separation tags across hash call sites
  • Checking round count and matrix choices against claimed security margins

When NOT to Use

  • Generic transcript review not focused on hash primitive internals
  • Commitment opening verification without hash primitive concerns
  • Marking hash findings as confirmed without verification gates

Core Review Areas

  1. Parameter selection and provenance
  2. Sponge construction and capacity/rate safety
  3. Domain separation and call-site context binding
  4. Algebraic attack resistance for chosen rounds and constants
  5. Matrix and S-box structural properties

Workflow

Phase 1: Parameter provenance review

  • Read references/hash-checklist.md
  • Verify round constants and MDS matrices are derived with clear provenance
  • Confirm claimed security level matches round configuration

Phase 2: Sponge and API review

  • Execute workflows/sponge-review.md
  • Validate absorption/squeezing behavior, padding, and capacity boundaries
  • Review call sites for unsafe reuse across protocol domains

Phase 3: Pattern hunt

  • Read references/finding-patterns.md
  • Prioritize weak constants, missing domain separation, and capacity misuse

Phase 4: Handoff

  • Send surviving findings to crypto-fp-check
  • Use zkbugs-index only after verification succeeds

Output Contract

Produce a hash-audit handoff that includes:

  • The primitive, parameter set, and call sites under review
  • The exact security-property gap (capacity, rounds, separation, algebraic margin)
  • The exploitability conditions and expected impact
  • The next verification or reporting route

Reference Index

What ships with it: 4 files

3.5 KB alongside SKILL.md

agents/

workflows/

Keep looking

Skills are one crate of 326,852. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.