Skip to content

Add CRYPTOGRAPHY-AND-KEY-MANAGEMENT.md security audit guide #39

Description

@RohanOnKeys

Summary

The security audit skill covers web authentication, AI/LLM security, cloud deployment, supply chain, memory safety, and protocol security, but it does not have a dedicated guide for cryptographic implementation reviews.

Adding a CRYPTOGRAPHY-AND-KEY-MANAGEMENT.md guide would make cryptography a first class audit category and give reviewers a consistent checklist for identifying common implementation flaws.

Proposed scope

Create skills/security-audit/CRYPTOGRAPHY-AND-KEY-MANAGEMENT.md covering:

  • Weak or deprecated algorithms (MD5, SHA-1, DES, RC4).
  • Insecure randomness and predictable token generation.
  • Nonce and IV reuse.
  • JWT signing and verification mistakes (alg=none, algorithm confusion).
  • Password hashing pitfalls (bcrypt, Argon2, PBKDF2 guidance).
  • TLS and certificate validation mistakes.
  • Secret and key management practices (rotation, storage, KMS/HSM usage).
  • Common vulnerable vs. secure code examples.

Integration

  • Add the new guide to SKILL.md.
  • Include it in the coverage ledger so audit validation remains complete.
  • Keep the format consistent with the existing domain guides.

Why this belongs here

Cryptographic mistakes are a recurring source of security vulnerabilities, but they currently fall between existing categories like Web Protocol and Auth and Cloud and Deployment. A dedicated guide would improve audit consistency without overlapping heavily with the current documentation structure.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions