一键导入
cryptography-entropy
Use when working on entropy, DRBG, cryptography; provides the FinnOS-specific cryptography and entropy workflow and evidence gates.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
菜单
Use when working on entropy, DRBG, cryptography; provides the FinnOS-specific cryptography and entropy workflow and evidence gates.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
基于 SOC 职业分类
Use when working on arm64, aarch64, AAVMF; provides the FinnOS-specific arm64 platform development workflow and evidence gates.
Use when working on toolchain, OVMF, AAVMF; provides the FinnOS-specific build environment management workflow and evidence gates.
Use when working on build script, target profile, image; provides the FinnOS-specific build orchestration workflow and evidence gates.
Use when working on CI, GitHub Actions, required check; provides the FinnOS-specific ci maintenance workflow and evidence gates.
Use when working on architecture abstraction, platform interface, parity; provides the FinnOS-specific cross-architecture design workflow and evidence gates.
Use when working on status, completion percentage, verified; provides the FinnOS-specific evidence and status reporting workflow and evidence gates.
| name | cryptography-entropy |
| title | Cryptography and Entropy |
| version | 1 |
| status | active |
| owners | [] |
| triggers | ["entropy","DRBG","cryptography","signing","key storage"] |
| prerequisites | ["threat-modelling","driver-architecture","unsafe-rust-low-level-safety"] |
| related_docs | ["SECURITY.md","RELEASING.md"] |
| category | Security |
| conditional_skills | [] |
| implementation_gates | ["Implementation waits for platform entropy devices and userspace isolation; never create custom cryptography."] |
| related_milestones | ["M6 Developer Preview","M7 Beta"] |
| last_verified | {"base_commit":"d21a477","date":"2026-07-16","worktree_dirty":true,"context":"base commit plus uncommitted audit and agent-system worktree"} |
| description | Use when working on entropy, DRBG, cryptography; provides the FinnOS-specific cryptography and entropy workflow and evidence gates. |
cryptography-entropy (Security; skill maturity: planning-gated).
Define trustworthy entropy, DRBG, reviewed crypto APIs, key storage, signing, and TLS prerequisites.
Use for requests mentioning entropy, DRBG, cryptography, signing, key storage, or when a dependency points to this skill. Load only after repository entry and before design or implementation.
Implementation waits for platform entropy devices and userspace isolation; never create custom cryptography. Do not load it only because a future FinnOS document mentions the subsystem.
threat-modellingdriver-architectureunsafe-rust-low-level-safetyRead the full prerequisite closure in topological dependency order. If one cannot be satisfied, move the task to Blocked or Deferred; do not omit the dependency.
Conditional skills:
Implementation gates are roadmap/runtime conditions, not additional documents to load automatically:
SECURITY.mdRELEASING.mdRe-read implementation and tests referenced by those documents. The documents establish intent/status boundaries, not runtime proof.
No entropy source, RNG, crypto API, key store, signatures, or TLS exists.
Registry verification used base commit d21a477 plus the dirty worktree context "base commit plus uncommitted audit and agent-system worktree" on 2026-07-16. This is not an integrated-revision claim. Reverify after HEAD, active PRs, or relevant source changes.
git status, recent history, active related issue/PR, and selected roadmap item.An evidence-backed cryptography and entropy result with scoped artifacts, tests, documentation, and handoff. Include acceptance evidence, residual limitations, and next dependency rather than only code.
./tools/finn check
Run commands from the repository root. A command listed here is a baseline/gate, not evidence that absent future functionality has a runnable target.
State shared semantics explicitly; isolate x86-64 and ARM64 mechanisms.
State guest architecture separately from host architecture and emulator model. Maintain a parity row for changed semantics and document intentional differences.
Preserve the boundary described by the current state: No entropy source, RNG, crypto API, key store, signatures, or TLS exists. Apply .agents/checklists/pre-change.md; for kernel, driver, security, architecture, or UI work also apply the matching checklist.
Make Test known vectors, failure-to-seed, fork/process separation, and platform variance observable with a negative case, then run the narrow and aggregate gates. Do not permanently hard-code test counts; counts belong to dated evidence reports.
Update the canonical behavior/status document, relevant architecture/reference material, test/build instructions, limitations, and this skill registry if any command, gate, or current-context statement changes.
Threat-model boot/platform entropy before relying on downstream assumptions.Use .agents/templates/handoff-template.md. Include objective, starting/final Git state, task state, skills used, files, exact commands/results, evidence classification, docs/status changes, unknowns, blockers, risks, next action, and next skills. Distinguish locally verified worktree changes from integrated behavior.
Request: "Work on entropy." Correct response: begin by threat-model boot/platform entropy, then use reviewed standard primitives/libraries only, and require evidence for test known vectors, failure-to-seed, fork/process separation, and platform variance before changing status. Incorrect response: create a plausible subsystem scaffold and mark the roadmap item complete because it compiles.
Canonical source: .agents/scripts/skill_registry.py. Increment version for material policy/workflow/gate changes, update last_verified only after reinspection, run python3 .agents/scripts/render_skills.py, review generated diffs, then run python3 .agents/scripts/validate.py --all. Follow .agents/GOVERNANCE.md; never hand-edit generated skills.