Install
$ agentstack add skill-yue-zhou1-zkcrypto-audit-crypto-audit-router ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
crypto-audit-router
Top-level orchestrator for the crypto audit framework.
When to Use
- Starting a new audit and deciding the execution order
- Choosing between
ecc-pairing-auditor,zk-circuit-auditor,dkg-threshold-auditor,rust-crypto-safety, orspec-delta-checker - Moving a suspected issue from domain review to verification, reporting, and indexing
- Coordinating multi-skill audits without losing handoff artifacts
When NOT to Use
- Replacing the domain auditors themselves
- Writing final findings without
crypto-fp-check - Querying or writing prior art directly without deciding whether the finding is verified and citable
Rationalizations to Reject
| Rationalization | Why it is wrong | |---|---| | "No ZK code, skip zk-circuit-auditor" | Fiat-Shamir transcripts appear outside ZK circuits too | | "It's just Rust safety, no crypto-specific review needed" | rust-crypto-safety covers timing, zeroize, and unsafe, which are crypto-specific | | "We already ran spec-delta-checker, skip domain audit" | spec-delta-checker finds drift; domain auditors find implementation bugs unrelated to the spec |
Workflow
- Load machine-readable route metadata from
../../../_meta/router-matrix.yaml - Load machine-readable skill trigger metadata from
../../../_meta/codex-skill-registry.yaml - Read
references/routing-matrix.mdas the human-readable mirror of registry policy - Execute
workflows/full-audit-flow.mdto keep the end-to-end sequence consistent - Preserve the output contract from each skill before routing to the next one
Routing Authority
- Auto-routing eligibility is determined by
trigger_modein
../../../_meta/codex-skill-registry.yaml.
trigger_mode: router_autoskills are eligible when predicates match.trigger_mode: user_triggered_onlyskills must never be auto-selected.agents/openai.yamlprovides UI/discovery metadata only and does not override
routing policy.
Session State Enforcement
- Every handoff must preserve schema validity against
zk-findings/sessions/session-state-schema.json.
- Use
references/state-machine.mdto enforce legal phase transitions and
mutation boundaries (open_findings -> verified_findings, next_steps refresh, closeout checks).
- If any required session-state field is missing, route back to the earliest
phase that can repair the state before progressing.
Routing Scope
This router is responsible for sequencing crypto-audit-context, spec-delta-checker, the domain auditors, crypto-fp-check, crypto-report-writer, and zkbugs-index.
Output Contract
Produce an audit routing plan that includes:
- The chosen skill sequence and why each skill was selected
- The current artifact handed from one phase to the next
- The stop condition for each phase
- The next unresolved branch or escalation point
Reference Index
- [references/routing-matrix.md](references/routing-matrix.md)
- [references/state-machine.md](references/state-machine.md)
- [workflows/full-audit-flow.md](workflows/full-audit-flow.md)
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: Yue-Zhou1
- Source: Yue-Zhou1/zkcrypto-audit
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.