From asi
Audits Python applications and configs for cryptographic vulnerabilities including weak algorithms like MD5/SHA-1, ECB mode, hardcoded secrets, and poor entropy. Builds automated scanner for security reviews.
How this skill is triggered — by the user, by Claude, or both
Slash command
/asi:performing-cryptographic-audit-of-applicationThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
A cryptographic audit systematically reviews an application's use of cryptographic primitives, protocols, and key management to identify vulnerabilities such as weak algorithms, insecure modes, hardcoded keys, insufficient entropy, and protocol misconfigurations. This skill covers building an automated crypto audit tool that scans Python and configuration files for common cryptographic weaknesses.
A cryptographic audit systematically reviews an application's use of cryptographic primitives, protocols, and key management to identify vulnerabilities such as weak algorithms, insecure modes, hardcoded keys, insufficient entropy, and protocol misconfigurations. This skill covers building an automated crypto audit tool that scans Python and configuration files for common cryptographic weaknesses.
| Category | Examples | Risk Level |
|---|---|---|
| Weak Hashing | MD5, SHA-1 for integrity/signatures | High |
| Insecure Encryption | DES, 3DES, RC4, Blowfish | High |
| Bad Cipher Mode | ECB mode for any block cipher | High |
| Insufficient Key Size | RSA < 2048, AES-128 for long-term | Medium |
| Hardcoded Secrets | Keys/passwords in source code | Critical |
| Weak KDF | Low iteration PBKDF2, plain MD5 | High |
| Poor Entropy | time-based seeds, predictable IVs | High |
| Deprecated Protocols | SSLv3, TLS 1.0, TLS 1.1 | High |
npx claudepluginhub plurigrid/asi --plugin asiScans Python and config files for cryptographic weaknesses: weak algorithms, insecure modes, hardcoded keys, bad entropy, TLS misconfigurations.
Scans Python and configuration files for cryptographic weaknesses: deprecated algorithms, insecure modes, hardcoded keys, weak entropy, and TLS misconfigurations. Use during security assessments or compliance reviews.
Audits Python apps and configs for crypto vulnerabilities like weak algorithms (MD5/SHA-1), insecure modes (ECB), hard-coded keys, entropy issues, and TLS configs; generates reports with fixes.