# Merkle Tree Auditor

> >

- **Type:** Skill
- **Install:** `agentstack add skill-yue-zhou1-zkcrypto-audit-merkle-tree-auditor`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [Yue-Zhou1](https://agentstack.voostack.com/s/yue-zhou1)
- **Installs:** 0
- **Category:** [Agent Skills](https://agentstack.voostack.com/c/agent-skills)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [Yue-Zhou1](https://github.com/Yue-Zhou1)
- **Source:** https://github.com/Yue-Zhou1/zkcrypto-audit/tree/main/plugins/crypto-primitive-auditors/skills/merkle-tree-auditor

## Install

```sh
agentstack add skill-yue-zhou1-zkcrypto-audit-merkle-tree-auditor
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# merkle-tree-auditor

Domain auditor for Merkle tree construction and proof verification logic.

## When to Use

- Reviewing Merkle inclusion/exclusion proof verification code
- Auditing leaf/internal hashing separation and root construction
- Checking sparse Merkle defaults and update semantics
- Reviewing multi-proof batching and path validation logic

## When NOT to Use

- Hash primitive parameter tuning without Merkle tree usage context
- Commitment opening systems not based on Merkle authentication paths
- Marking suspected Merkle issues as confirmed without verification gates

## Core Review Areas

1. Second-preimage resistance through strict node typing
2. Leaf-node domain separation and canonical encoding
3. Sparse tree default values and edge-case handling
4. Proof length/path validation and index binding
5. Root update safety and state transition checks

## Workflow

### Phase 1: Tree model and encoding inventory

- Read `references/merkle-checklist.md`
- Identify leaf format, node format, and hash domain tags
- Map index-bit ordering and path-direction handling

### Phase 2: Proof verification review

- Execute `workflows/proof-review.md`
- Verify path length/depth checks, left-right ordering, and root comparison
- Check sparse defaults and empty-path handling are fail-closed

### Phase 3: Pattern hunt

- Read `references/finding-patterns.md`
- Prioritize domain-separation gaps, empty-path acceptance, and unbound multiproof reuse

### Phase 4: Handoff

- Send surviving findings to `crypto-fp-check`
- Use `zkbugs-index` only after verification succeeds

## Output Contract

Produce a Merkle-audit handoff that includes:

- The tree variant and proof path under review
- The exact node-typing, path-validation, or root-binding gap
- Whether the issue affects soundness, replay/update integrity, or completeness
- The next verification or reporting route

## Reference Index

- [references/merkle-checklist.md](references/merkle-checklist.md)
- [references/finding-patterns.md](references/finding-patterns.md)
- [workflows/proof-review.md](workflows/proof-review.md)

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [Yue-Zhou1](https://github.com/Yue-Zhou1)
- **Source:** [Yue-Zhou1/zkcrypto-audit](https://github.com/Yue-Zhou1/zkcrypto-audit)
- **License:** MIT

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-yue-zhou1-zkcrypto-audit-merkle-tree-auditor
- Seller: https://agentstack.voostack.com/s/yue-zhou1
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
