Summary
The security audit skill covers web authentication, AI/LLM security, cloud deployment, supply chain, memory safety, and protocol security, but it does not have a dedicated guide for cryptographic implementation reviews.
Adding a CRYPTOGRAPHY-AND-KEY-MANAGEMENT.md guide would make cryptography a first class audit category and give reviewers a consistent checklist for identifying common implementation flaws.
Proposed scope
Create skills/security-audit/CRYPTOGRAPHY-AND-KEY-MANAGEMENT.md covering:
- Weak or deprecated algorithms (MD5, SHA-1, DES, RC4).
- Insecure randomness and predictable token generation.
- Nonce and IV reuse.
- JWT signing and verification mistakes (
alg=none, algorithm confusion).
- Password hashing pitfalls (bcrypt, Argon2, PBKDF2 guidance).
- TLS and certificate validation mistakes.
- Secret and key management practices (rotation, storage, KMS/HSM usage).
- Common vulnerable vs. secure code examples.
Integration
- Add the new guide to
SKILL.md.
- Include it in the coverage ledger so audit validation remains complete.
- Keep the format consistent with the existing domain guides.
Why this belongs here
Cryptographic mistakes are a recurring source of security vulnerabilities, but they currently fall between existing categories like Web Protocol and Auth and Cloud and Deployment. A dedicated guide would improve audit consistency without overlapping heavily with the current documentation structure.
Summary
The security audit skill covers web authentication, AI/LLM security, cloud deployment, supply chain, memory safety, and protocol security, but it does not have a dedicated guide for cryptographic implementation reviews.
Adding a
CRYPTOGRAPHY-AND-KEY-MANAGEMENT.mdguide would make cryptography a first class audit category and give reviewers a consistent checklist for identifying common implementation flaws.Proposed scope
Create
skills/security-audit/CRYPTOGRAPHY-AND-KEY-MANAGEMENT.mdcovering:alg=none, algorithm confusion).Integration
SKILL.md.Why this belongs here
Cryptographic mistakes are a recurring source of security vulnerabilities, but they currently fall between existing categories like Web Protocol and Auth and Cloud and Deployment. A dedicated guide would improve audit consistency without overlapping heavily with the current documentation structure.