Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Scan a source tree for weak cryptographic primitives: MD5 / SHA-1 used for security purposes, DES / 3DES / RC4 ciphers, ECB block mode, custom-built crypto (XOR loops, hand-rolled HMAC), hardcoded IVs, predictable random (Math.random / java.util.Random for crypto seeds), missing certificate verification (verify=False, rejectUnauthorized: false). Use when: pre-merge gate on crypto-touching code, audit before SOC2 / PCI assessment, post-incident review when "we found a weakness in our token signin
| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-04 | ✗→✓ | ▲ Improved | -39% | 0% |
| case-11 | ✗→✓ | ▲ Improved | 15% | 0% |
| case-12 | ✗→✓ | ▲ Improved | -8% | 0% |
| case-15 | ✗→✓ | ▲ Improved | -7% | 0% |
| case-16 | ✗→✓ | ▲ Improved | -8% | 0% |
Weak cryptography (CWE-327 Use of a Broken or Risky Cryptographic Algorithm, CWE-330 Use of Insufficiently Random Values) shows up when engineers use the convenient API instead of the cryptographic one. hashlib.md5(password) is faster to type than the correct bcrypt/argon2 invocation; Math.random() returns a number quickly without needing to know about crypto.randomBytes().
The fix is universal: use the modern primitive. SHA-256 for general hashing, bcrypt/argon2/scrypt for passwords, AES-GCM for encryption, HMAC-SHA256 for signing, secrets / crypto.randomBytes / SecureRandom for randomness.
| Finding | Severity | Threshold | Affected control | |---|---|---|---| | MD5 used in security context | HIGH | hashlib.md5, MessageDigest.MD5, CryptoJS.MD5 | CWE-327 | | SHA-1 used in security context | HIGH | hashlib.sha1, etc. | CWE-327 | | DES / 3DES cipher | CRITICAL | DESCrypto, "DES/CBC", "DESede" | CWE-327 | | RC4 cipher | CRITICAL | "ARC4", "RC4" | CWE-327 | | AES ECB mode | CRITICAL | "AES/ECB" or MODE_ECB | CWE-327 | | Hardcoded IV (initialization vector) | CRITICAL | IV literal in source | CWE-329 | | Custom XOR-based "encryption" | CRITICAL | XOR loop over bytes | CWE-327 | | Predictable random for crypto seed | CRITICAL | Math.random / java.util.Random / random.random for keys | CWE-330 | | TLS cert verification disabled | CRITICAL | verify=False, rejectUnauthorized:false, ServerCertificateValidationCallback returning true | CWE-295 | | Hardcoded HMAC secret | HIGH | Long literal in HMAC constructor | CWE-321 | | Insecure password hashing (no salt, no KDF) | CRITICAL | hashlib.sha256(password) without bcrypt/argon2 | CWE-916 |
bashpython3 ${CLAUDE_PLUGIN_ROOT}/skills/detecting-weak-cryptography/scripts/scan_weak_crypto.py /path/to/repo
Options: --output, --format, --min-severity, --include-tests, --languages, --allow-md5-checksums (excludes MD5 used in non-security contexts like content-addressable storage).
CRITICAL = direct cryptographic break available against the algorithm. CVEs, public attack tools, sometimes pre-computed tables (rainbow tables for MD5/SHA-1).
HIGH = algorithm collision-broken (MD5, SHA-1) but the specific use case may tolerate the weakness (file-deduplication checksums, non-security HMAC). Verify the usage context.
See references/PLAYBOOK.md for per-primitive migration. Modern defaults: SHA-256/SHA-3 for hashing, AES-256-GCM for encryption, HMAC-SHA-256 for signing, secrets-grade random for keys, bcrypt / argon2id for password storage.
bashpython3 ${CLAUDE_PLUGIN_ROOT}/skills/detecting-weak-cryptography/scripts/scan_weak_crypto.py \ --min-severity high $(git diff --name-only main...HEAD | tr '\n' ' ')
yaml- name: Weak-crypto scan run: | python3 plugins/security/penetration-tester/skills/detecting-weak-cryptography/scripts/scan_weak_crypto.py \ . --min-severity high
JSON / JSONL / Markdown. Exit codes: 0 / 1 / 2.
False positives common on:
where collision resistance against ATTACKERS isn't needed — use --allow-md5-checksums.
integrity check inside a TLS session where the channel is already authenticated.
Verify each finding by reading whether the algorithm's failure mode (collision, preimage, etc.) is actually exploitable in context.
references/THEORY.md — Per-primitive attack model (why MD5 /SHA-1 are collision-broken, why ECB leaks structure, why Math.random is non-crypto-grade)
references/PLAYBOOK.md — Per-language modern-crypto recipes(Python cryptography library, Node crypto, Java JCA with modern algorithms, Go crypto/rand + crypto/cipher AEAD)
Other measured skills in the registry, with their headline benchmark lift.