{"enrichment":{"faq":[{"a":"Crypto-analysis evaluates cryptographic posture across TLS/SSL/SSH configurations, public-key implementations, and token schemes. It detects cipher downgrades, weak key generation, nonce reuse, AEAD misuse, and JWT algorithm confusion using integrated tools like testssl.sh, openssl, and hashcat. Use it to identify cryptographic flaws before attackers do.","q":"What is crypto-analysis and what does it do?"},{"a":"Yes. Crypto-analysis audits TLS/PKI configurations and cipher suites for downgrade attacks and protocol flaws. It identifies weak ciphers, SSL/TLS version misconfigurations, and certificate chain issues to harden your cryptographic infrastructure against known weaknesses.","q":"Can crypto-analysis perform TLS PKI audit and detect protocol flaws?"},{"a":"Crypto-analysis recovers private keys from weak RSA and ECC implementations by detecting biased nonces and implementation flaws. It applies lattice-based attacks and nonce analysis to expose key material from systems with poor randomness or side-channel leakage.","q":"How does crypto-analysis help with RSA key attack and ECDSA nonce recovery?"},{"a":"Yes. Crypto-analysis forges JWT/JOSE tokens by exploiting algorithm confusion and signature bypass vulnerabilities. It tests for 'none' algorithm acceptance, key confusion between symmetric and asymmetric schemes, and other token validation weaknesses.","q":"Does crypto-analysis detect JWT token forgery via algorithm confusion?"},{"a":"Crypto-analysis exploits symmetric cipher misuse including CBC padding oracles, AES-GCM nonce reuse, and AEAD key commitment failures. It detects improper IV handling, deterministic encryption, and other patterns that leak plaintext or enable forgery.","q":"What symmetric encryption misuse can crypto-analysis identify?"},{"a":"Yes. Crypto-analysis assesses post-quantum cryptography migration readiness and identifies harvest-now-decrypt-later exposure. It evaluates your current reliance on quantum-vulnerable algorithms and guides transition planning to quantum-resistant schemes.","q":"Does crypto-analysis assess post-quantum migration readiness?"}],"shadow_tags":["key-recovery","tls-audit","signature-forgery","mode-oracle","nonce-reuse","weak-key-detection","token-manipulation","cipher-downgrade","offline-cracking","quantum-readiness"],"summary_rewrite":"Crypto-analysis evaluates cryptographic posture across TLS/SSL/SSH configurations, public-key implementations, and token schemes. It detects cipher downgrades, weak key generation, nonce reuse, AEAD misuse, and JWT algorithm confusion using integrated tools like testssl.sh, openssl, and hashcat. Use it to identify cryptographic flaws before attackers do."},"files":[{"bytes":8756,"path":"skills/crypto-analysis/SKILL.md","sha256":"4fdb7bfc9cc019169ed4eca753d8768a691e50859b4c1265d7aea759dcb9880d","url":"https://skillfed.io/files/hypnguyen1209/offensive-claude/crypto-analysis/8e73c35f/SKILL.md"}],"id":"hypnguyen1209/offensive-claude/crypto-analysis","links":{"html":"https://skillfed.io/hypnguyen1209/offensive-claude/crypto-analysis","md":"https://skillfed.io/hypnguyen1209/offensive-claude/crypto-analysis.md","repo":"https://github.com/hypnguyen1209/offensive-claude"},"meta":{"agents_supported":[],"first_seen":"2026-07-28","forks":58,"language":"Python","last_updated":"2026-07-03","license":"MIT","name":"crypto-analysis","publisher":"hypnguyen1209","stars":326},"relations":{"similar":[{"id":"ljagiello/ctf-skills/ctf-crypto"},{"id":"dpearson2699/swift-ios-skills/cryptokit"},{"id":"wshaddix/dotnet-skills/dotnet-cryptography"},{"id":"yaklang/hack-skills/lattice-crypto-attacks"},{"id":"RightNow-AI/openfang/crypto-expert"},{"id":"trailofbits/skills/wycheproof"},{"id":"PlamenTSV/plamen/signature-verification-audit"},{"id":"internet-court/internet-court-skill/near-ai-cloud"},{"id":"PlamenTSV/plamen/account-abstraction-security"},{"id":"pluginagentmarketplace/custom-plugin-blockchain/blockchain-basics"}]},"slug":{"owner":"hypnguyen1209","repo":"offensive-claude","skill":"crypto-analysis"},"version":"8e73c35f"}
