# Fiat Shamir Auditor

> >

- **Type:** Skill
- **Install:** `agentstack add skill-yue-zhou1-zkcrypto-audit-fiat-shamir-auditor`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [Yue-Zhou1](https://agentstack.voostack.com/s/yue-zhou1)
- **Installs:** 0
- **Category:** [Agent Skills](https://agentstack.voostack.com/c/agent-skills)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [Yue-Zhou1](https://github.com/Yue-Zhou1)
- **Source:** https://github.com/Yue-Zhou1/zkcrypto-audit/tree/main/plugins/crypto-primitive-auditors/skills/fiat-shamir-auditor

## Install

```sh
agentstack add skill-yue-zhou1-zkcrypto-audit-fiat-shamir-auditor
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# fiat-shamir-auditor

Domain auditor for transcript-binding and challenge-derivation correctness.

## When to Use

- Reviewing Fiat-Shamir transforms in proof systems and signature schemes
- Auditing transcript absorb order and challenge derivation timing
- Checking public input and domain separation binding to transcript state
- Reviewing multi-round challenge dependencies in non-interactive protocols

## When NOT to Use

- Hash primitive internals when transcript behavior is not under review
- Generic circuit checks with no transcript/challenge path
- Marking suspected transcript flaws as confirmed without verification gates

## Core Review Areas

1. Transcript completeness for all prover and context messages
2. Domain separation across protocol rounds and contexts
3. Challenge derivation order and dependency correctness
4. Public input and statement binding to challenges
5. Multi-round transcript consistency and reset safety
6. Hash primitive suitability for challenge derivation

## Workflow

### Phase 1: Transcript inventory

- Read `references/fiat-shamir-checklist.md`
- Identify all absorb/squeeze operations and transcript states
- Enumerate every statement element expected to influence challenges

### Phase 2: Binding review

- Execute `workflows/transcript-binding-review.md`
- Verify commitments are absorbed before challenge derivation
- Ensure public inputs and domain labels are bound at correct points

### Phase 3: Pattern hunt

- Read `references/finding-patterns.md`
- Prioritize frozen-heart style independence, missing absorbs, and reset bugs

### Phase 4: Handoff

- Send surviving findings to `crypto-fp-check`
- Use `zkbugs-index` only after verification succeeds

## Output Contract

Produce a transcript-audit handoff that includes:

- The transcript states, labels, and challenge points involved
- The exact missing binding, absorb-order, or reset-safety issue
- Whether the issue affects soundness, replay resistance, or protocol context separation
- The next verification or reporting route

## Reference Index

- [references/fiat-shamir-checklist.md](references/fiat-shamir-checklist.md)
- [references/finding-patterns.md](references/finding-patterns.md)
- [workflows/transcript-binding-review.md](workflows/transcript-binding-review.md)

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [Yue-Zhou1](https://github.com/Yue-Zhou1)
- **Source:** [Yue-Zhou1/zkcrypto-audit](https://github.com/Yue-Zhou1/zkcrypto-audit)
- **License:** MIT

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-yue-zhou1-zkcrypto-audit-fiat-shamir-auditor
- Seller: https://agentstack.voostack.com/s/yue-zhou1
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
