AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Hash Function Auditor

skill-yue-zhou1-zkcrypto-audit-hash-function-auditor · by Yue-Zhou1

>

No reviews yet
0 installs
20 views
0.0% view→install

Install

$ agentstack add skill-yue-zhou1-zkcrypto-audit-hash-function-auditor

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-yue-zhou1-zkcrypto-audit-hash-function-auditor)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
1mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Hash Function Auditor? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

hash-function-auditor

Domain auditor for ZK-friendly hash primitive security and usage correctness.

When to Use

  • Auditing Poseidon, Rescue, MiMC, Pedersen, or related ZK hash implementations
  • Reviewing sponge absorption/squeezing APIs and parameterization
  • Verifying domain separation tags across hash call sites
  • Checking round count and matrix choices against claimed security margins

When NOT to Use

  • Generic transcript review not focused on hash primitive internals
  • Commitment opening verification without hash primitive concerns
  • Marking hash findings as confirmed without verification gates

Core Review Areas

  1. Parameter selection and provenance
  2. Sponge construction and capacity/rate safety
  3. Domain separation and call-site context binding
  4. Algebraic attack resistance for chosen rounds and constants
  5. Matrix and S-box structural properties

Workflow

Phase 1: Parameter provenance review

  • Read references/hash-checklist.md
  • Verify round constants and MDS matrices are derived with clear provenance
  • Confirm claimed security level matches round configuration

Phase 2: Sponge and API review

  • Execute workflows/sponge-review.md
  • Validate absorption/squeezing behavior, padding, and capacity boundaries
  • Review call sites for unsafe reuse across protocol domains

Phase 3: Pattern hunt

  • Read references/finding-patterns.md
  • Prioritize weak constants, missing domain separation, and capacity misuse

Phase 4: Handoff

  • Send surviving findings to crypto-fp-check
  • Use zkbugs-index only after verification succeeds

Output Contract

Produce a hash-audit handoff that includes:

  • The primitive, parameter set, and call sites under review
  • The exact security-property gap (capacity, rounds, separation, algebraic margin)
  • The exploitability conditions and expected impact
  • The next verification or reporting route

Reference Index

  • [references/hash-checklist.md](references/hash-checklist.md)
  • [references/finding-patterns.md](references/finding-patterns.md)
  • [workflows/sponge-review.md](workflows/sponge-review.md)

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.