# Crypto Audit Context

> >

- **Type:** Skill
- **Install:** `agentstack add skill-yue-zhou1-zkcrypto-audit-crypto-audit-context`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [Yue-Zhou1](https://agentstack.voostack.com/s/yue-zhou1)
- **Installs:** 0
- **Category:** [Finance & Payments](https://agentstack.voostack.com/c/finance-and-payments)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [Yue-Zhou1](https://github.com/Yue-Zhou1)
- **Source:** https://github.com/Yue-Zhou1/zkcrypto-audit/tree/main/plugins/core-audit-flow/skills/crypto-audit-context

## Install

```sh
agentstack add skill-yue-zhou1-zkcrypto-audit-crypto-audit-context
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# crypto-audit-context

Start here before claiming vulnerabilities.

**Core principle:** verify what the code actually enforces, not what the docs
claim.

## When to Use

- Beginning a ZK or cryptographic audit
- Reading unfamiliar verifier, prover, signature, DKG, or serialization code
- Building a threat model before bug hunting
- Prioritizing which files and functions deserve the deepest review first

## When NOT to Use

- Verifying whether a specific suspected finding is a true positive
- Writing final severity decisions or report-ready findings
- Querying prior-art or disclosure state

## Audit Priority

Review highest-risk code first:

1. **Critical path** — `verify`, `batch_verify`, `deserialize`, `from_bytes`, transcript/challenge generation, `keygen`, `sign`, `prove`
2. **Trust boundary** — `unsafe` blocks, FFI modules, unchecked constructors, parameter loading
3. **Supporting** — caches, zeroization, type conversions, error conversion, optimized backends

## Rationalizations to Reject

| Rationalization | Why it is wrong |
|---|---|
| "The README explains the architecture" | READMEs describe intent, not enforcement |
| "I'll map trust boundaries later during domain review" | Domain skills assume the dimension map is already built |
| "The codebase is small, I can hold the context in my head" | Small codebases have the same attack-surface density |

## Workflow

### Phase 1: Map the critical path

- Identify verifier, transcript, parsing, and randomness entrypoints
- Mark code that handles attacker-controlled or externally supplied values

### Phase 2: Build the dimension map

- Read `references/dimensional-analysis.md`
- Assign dimensions to values that cross trust boundaries
- Treat every unknown or inherited dimension as suspicious until proven safe

### Phase 3: Build the protocol threat model

- Read `references/threat-model-checklist.md`
- Record replay surfaces, authentication roots, downgrade surfaces, and corruption model assumptions

### Phase 4: Produce the audit handoff

- Summarize the highest-risk paths
- Name unresolved assumptions
- Hand off to a domain auditor or verification skill
- Initialize or update session state in `zk-findings/sessions/.json`
  using `zk-findings/sessions/session-state-schema.json`
- Persist trust boundaries, open findings, and next-step routes so follow-on
  conversations continue from the same state

## Output Contract

Produce a context handoff that includes:

- Critical paths and trust boundaries that deserve deepest review
- Dimension-map anomalies and unresolved assumptions
- Threat-model notes that the next skill must preserve
- Recommended next skills, with a brief reason for each route
- Session state path updated in `zk-findings/sessions/` for downstream handoffs

## Reference Index

- [references/dimensional-analysis.md](references/dimensional-analysis.md)
- [references/threat-model-checklist.md](references/threat-model-checklist.md)

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [Yue-Zhou1](https://github.com/Yue-Zhou1)
- **Source:** [Yue-Zhou1/zkcrypto-audit](https://github.com/Yue-Zhou1/zkcrypto-audit)
- **License:** MIT

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-yue-zhou1-zkcrypto-audit-crypto-audit-context
- Seller: https://agentstack.voostack.com/s/yue-zhou1
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
