| name | detecting-weak-cryptography |
| description | Scan a source tree for weak cryptographic primitives: MD5 / SHA-1
used for security purposes, DES / 3DES / RC4 ciphers, ECB block
mode, custom-built crypto (XOR loops, hand-rolled HMAC),
hardcoded IVs, predictable random (Math.random / java.util.Random
for crypto seeds), missing certificate verification
(verify=False, rejectUnauthorized: false).
Use when: pre-merge gate on crypto-touching code, audit before
SOC2 / PCI assessment, post-incident review when "we found a
weakness in our token signing."
Threshold: any call to a known-weak algorithm with non-test
context, OR cert verification explicitly disabled, OR a custom
crypto loop pattern.
Trigger with: "scan weak crypto", "find MD5 usage", "check ECB
mode", "audit ssl verify", "weak random".
|
| allowed-tools | ["Read","Bash(python3:*)","Glob","Grep"] |
| disallowed-tools | ["Bash(rm:*)","Bash(curl:*)"] |
| version | 3.30.0 |
| author | Jeremy Longshore <jeremy@intentsolutions.io> |
| license | MIT |
| compatibility | Designed for Claude Code |
| tags | ["security","static-analysis","cryptography","pentest"] |
Detecting Weak Cryptography
Overview
Weak cryptography (CWE-327 Use of a Broken or Risky Cryptographic
Algorithm, CWE-330 Use of Insufficiently Random Values) shows up
when engineers use the convenient API instead of the cryptographic
one. hashlib.md5(password) is faster to type than the correct
bcrypt/argon2 invocation; Math.random() returns a number quickly
without needing to know about crypto.randomBytes().
The fix is universal: use the modern primitive. SHA-256 for general
hashing, bcrypt/argon2/scrypt for passwords, AES-GCM for encryption,
HMAC-SHA256 for signing, secrets / crypto.randomBytes /
SecureRandom for randomness.
When the skill produces findings
| Finding | Severity | Threshold | Affected control |
|---|
| MD5 used in security context | HIGH | hashlib.md5, MessageDigest.MD5, CryptoJS.MD5 | CWE-327 |
| SHA-1 used in security context | HIGH | hashlib.sha1, etc. | CWE-327 |
| DES / 3DES cipher | CRITICAL | DESCrypto, "DES/CBC", "DESede" | CWE-327 |
| RC4 cipher | CRITICAL | "ARC4", "RC4" | CWE-327 |
| AES ECB mode | CRITICAL | "AES/ECB" or MODE_ECB | CWE-327 |
| Hardcoded IV (initialization vector) | CRITICAL | IV literal in source | CWE-329 |
| Custom XOR-based "encryption" | CRITICAL | XOR loop over bytes | CWE-327 |
| Predictable random for crypto seed | CRITICAL | Math.random / java.util.Random / random.random for keys | CWE-330 |
| TLS cert verification disabled | CRITICAL | verify=False, rejectUnauthorized:false, ServerCertificateValidationCallback returning true | CWE-295 |
| Hardcoded HMAC secret | HIGH | Long literal in HMAC constructor | CWE-321 |