Credential Fixture Review
python scripts/_credentials.py is review material for the CryptoLint -- Cryptography Misuse & Weak Algorithm Detector skill. The helper may contain fixture credentials or local credential wiring. Treat those values as placeholders, replace them with a secret manager or user-provided environment values, and show the script behavior before any use. Do not contact external services with embedded sample credentials.
CryptoLint -- Cryptography Misuse & Weak Algorithm Detector
CryptoLint scans codebases for cryptographic anti-patterns, deprecated algorithms (MD5, SHA-1, DES, RC4), hardcoded keys and IVs, insecure encryption modes (ECB), weak random number generation, timing-vulnerable comparisons, and insecure TLS/SSL configuration. It uses regex-based pattern matching against 90 cryptography-specific patterns across 6 categories, lefthook for git hook integration, and produces markdown reports with actionable remediation guidance. 100% local. Zero telemetry.
Commands
Free Tier (No license required)
cryptolint scan [file|directory]
One-shot cryptography quality scan of files or directories.
How to execute:
bash "<SKILL_DIR>/scripts/dispatcher.sh" --path [target]
What it does:
- Accepts a file path or directory (defaults to current directory)
- Discovers all source files (skips .git, node_modules, binaries, images, .min.js)
- Runs 30 cryptography patterns against each file (free tier limit)
- Calculates a crypto quality score (0-100) per file and overall
- Grades: A (90-100), B (80-89), C (70-79), D (60-69), F (<60)
- Outputs findings with: file, line number, check ID, severity, description, recommendation
- Exit code 0 if score >= 70, exit code 1 if crypto quality is poor
- Free tier limited to first 30 patterns (WA + KM categories)
Example usage scenarios:
- "Scan my code for crypto issues" -> runs
cryptolint scan .
- "Check this file for weak algorithms" -> runs
cryptolint scan src/crypto.ts
- "Find hardcoded encryption keys" -> runs
cryptolint scan src/
- "Audit cryptography usage in my project" -> runs
cryptolint scan .
- "Check for MD5 or SHA1 usage" -> runs
cryptolint scan .
Pro Tier ($19/user/month -- requires CRYPTOLINT_LICENSE_KEY)
cryptolint scan --tier pro [file|directory]
Extended scan with 60 patterns covering weak algorithms, key management, encryption modes, and random number generation.
How to execute:
bash "<SKILL_DIR>/scripts/dispatcher.sh" --path [target] --tier pro
What it does:
- Validates Pro+ license
- Runs 60 cryptography patterns (WA, KM, EM, RN categories)
- Detects insecure encryption modes (ECB, CBC without auth)
- Identifies weak random number generation for crypto
- Full category breakdown reporting
cryptolint scan --format json [directory]
Generate JSON output for CI/CD integration.
bash "<SKILL_DIR>/scripts/dispatcher.sh" --path [directory] --format json
cryptolint scan --format html [directory]
Generate HTML report for browser viewing.
bash "<SKILL_DIR>/scripts/dispatcher.sh" --path [directory] --format html
cryptolint scan --category WA [directory]
Filter scan to a specific check category (WA, KM, EM, RN, TC, CP).
bash "<SKILL_DIR>/scripts/dispatcher.sh" --path [directory] --category WA
Team Tier ($39/user/month -- requires CRYPTOLINT_LICENSE_KEY with team tier)
cryptolint scan --tier team [directory]
Full scan with all 90 patterns across all 6 categories including timing attacks and certificate/protocol checks.
How to execute:
bash "<SKILL_DIR>/scripts/dispatcher.sh" --path [directory] --tier team
What it does:
- Validates Team+ license
- Runs all 90 patterns across 6 categories
- Includes timing & comparison checks (timing side-channels, non-constant-time comparison)
- Includes certificate & protocol checks (TLS verification disabled, insecure protocols)
- Full category breakdown with per-file results
cryptolint scan --verbose [directory]
Verbose output showing every matched line and pattern details.
bash "<SKILL_DIR>/scripts/dispatcher.sh" --path [directory] --verbose
cryptolint status
Show license and configuration information.
bash "<SKILL_DIR>/scripts/dispatcher.sh" status
Check Categories
CryptoLint detects 90 cryptographic anti-patterns across 6 categories:
| Category |
Code |
Patterns |
Description |
Severity Range |
| Weak Algorithms |
WA |
15 |
MD5, SHA-1, DES, 3DES, RC4, Blowfish, weak PBKDF2 iterations, deprecated TLS versions |
high -- critical |
| Key Management |
KM |
15 |
Hardcoded encryption keys, static IVs/salts, short keys, keys in source code, zero IVs |
high -- critical |
| Encryption Modes |
EM |
15 |
ECB mode, CBC without authentication, raw RSA without padding, deprecated createCipher |
medium -- critical |
| Random Number Generation |
RN |
15 |
Math.random() for security, java.util.Random for crypto, time-seeded RNG, predictable seeds |
high -- critical |
| Timing & Comparison |
TC |
15 |
String equality for hashes, == for HMAC, non-constant-time comparisons, early-return timing leaks |
medium -- high |
| Certificate & Protocol |
CP |
15 |
SSL/TLS verification disabled, hostname check bypassed, insecure protocol versions, HTTP in auth |
high -- critical |
Tier-Based Pattern Access
| Tier |
Patterns |
Categories |
| Free |
30 |
WA, KM |
| Pro |
60 |
WA, KM, EM, RN |
| Team |
90 |
WA, KM, EM, RN, TC, CP |
| Enterprise |
90 |
WA, KM, EM, RN, TC, CP + priority support |
Scoring
CryptoLint uses a deductive scoring system starting at 100 (perfect):
| Severity |
Point Deduction |
Description |
| Critical |
-25 per finding |
Broken algorithm or direct cryptographic vulnerability |
| High |
-15 per finding |
Significant cryptographic weakness (deprecated algo, weak key) |
| Medium |
-8 per finding |
Suboptimal practice (CBC without auth, weak mode choice) |
| Low |
-3 per finding |
Informational / best practice suggestion |
Grading Scale
| Grade |
Score Range |
Meaning |
| A |
90-100 |
Excellent cryptography practices |
| B |
80-89 |
Good crypto with minor issues |
| C |
70-79 |
Acceptable but needs improvement |
| D |
60-69 |
Poor cryptography quality |
| F |
Below 60 |
Critical cryptography problems |
- Pass threshold: 70 (Grade C or better)
- Exit code 0 = pass (score >= 70)
- Exit code 1 = fail (score < 70)
Configuration
Users can configure CryptoLint in ~/.openclaw/openclaw.json:
{
"skills": {
"entries": {
"cryptolint": {
"enabled": true,
"apiKey": "YOUR_LICENSE_KEY_HERE",
"config": {
"severityThreshold": "medium",
"ignorePatterns": ["**/test/**", "**/fixtures/**", "**/*.test.*"],
"ignoreChecks": [],
"reportFormat": "text"
}
}
}
}
}
Important Notes
- Free tier works immediately with no configuration
- All scanning happens locally -- no code is sent to external servers
- License validation is offline -- no phone-home or network calls
- Pattern matching only -- no AST parsing, no external dependencies beyond bash
- Supports scanning all file types in a single pass
- Git hooks use lefthook which must be installed (see install metadata above)
- Exit codes: 0 = pass (score >= 70), 1 = fail (for CI/CD integration)
- Output formats: text (default), json, html
Error Handling
- If lefthook is not installed and user tries hooks, prompt to install it
- If license key is invalid or expired, show clear message with link to https://cryptolint.pages.dev/renew
- If a file is binary, skip it automatically with no warning
- If no scannable files found in target, report clean scan with info message
- If an invalid category is specified with --category, show available categories
When to Use CryptoLint
The user might say things like:
- "Scan my code for crypto issues"
- "Check my cryptography usage"
- "Find weak algorithms in my code"
- "Detect hardcoded encryption keys"
- "Are there any MD5 or SHA1 uses?"
- "Check for insecure encryption modes"
- "Audit my TLS configuration"
- "Find ECB mode usage"
- "Check for timing attack vulnerabilities"
- "Scan for weak random number generation"
- "Run a cryptography audit"
- "Generate a crypto quality report"
- "Check if Math.random is used for security"
- "Find hardcoded IVs and salts"
- "Check my code for crypto anti-patterns"
1---2name: cryptolint-33description: Cryptography misuse & weak algorithm detector -- detects deprecated algorithms, hardcoded keys/IVs, ECB mode, weak random number generation, timing-vulnerable comparisons, and insecure TLS configuration4---56789### Credential Fixture Review1011`python scripts/_credentials.py` is review material for the `CryptoLint -- Cryptography Misuse & Weak Algorithm Detector` skill. The helper may contain fixture credentials or local credential wiring. Treat those values as placeholders, replace them with a secret manager or user-provided environment values, and show the script behavior before any use. Do not contact external services with embedded sample credentials.1213# CryptoLint -- Cryptography Misuse & Weak Algorithm Detector1415CryptoLint scans codebases for cryptographic anti-patterns, deprecated algorithms (MD5, SHA-1, DES, RC4), hardcoded keys and IVs, insecure encryption modes (ECB), weak random number generation, timing-vulnerable comparisons, and insecure TLS/SSL configuration. It uses regex-based pattern matching against 90 cryptography-specific patterns across 6 categories, lefthook for git hook integration, and produces markdown reports with actionable remediation guidance. 100% local. Zero telemetry.1617## Commands1819### Free Tier (No license required)2021#### `cryptolint scan [file|directory]`22One-shot cryptography quality scan of files or directories.2324**How to execute:**25```bash26bash "<SKILL_DIR>/scripts/dispatcher.sh" --path [target]27```2829**What it does:**301. Accepts a file path or directory (defaults to current directory)312. Discovers all source files (skips .git, node_modules, binaries, images, .min.js)323. Runs 30 cryptography patterns against each file (free tier limit)334. Calculates a crypto quality score (0-100) per file and overall345. Grades: A (90-100), B (80-89), C (70-79), D (60-69), F (<60)356. Outputs findings with: file, line number, check ID, severity, description, recommendation367. Exit code 0 if score >= 70, exit code 1 if crypto quality is poor378. Free tier limited to first 30 patterns (WA + KM categories)3839**Example usage scenarios:**40- "Scan my code for crypto issues" -> runs `cryptolint scan .`41- "Check this file for weak algorithms" -> runs `cryptolint scan src/crypto.ts`42- "Find hardcoded encryption keys" -> runs `cryptolint scan src/`43- "Audit cryptography usage in my project" -> runs `cryptolint scan .`44- "Check for MD5 or SHA1 usage" -> runs `cryptolint scan .`4546### Pro Tier ($19/user/month -- requires CRYPTOLINT_LICENSE_KEY)4748#### `cryptolint scan --tier pro [file|directory]`49Extended scan with 60 patterns covering weak algorithms, key management, encryption modes, and random number generation.5051**How to execute:**52```bash53bash "<SKILL_DIR>/scripts/dispatcher.sh" --path [target] --tier pro54```5556**What it does:**571. Validates Pro+ license582. Runs 60 cryptography patterns (WA, KM, EM, RN categories)593. Detects insecure encryption modes (ECB, CBC without auth)604. Identifies weak random number generation for crypto615. Full category breakdown reporting6263#### `cryptolint scan --format json [directory]`64Generate JSON output for CI/CD integration.6566```bash67bash "<SKILL_DIR>/scripts/dispatcher.sh" --path [directory] --format json68```6970#### `cryptolint scan --format html [directory]`71Generate HTML report for browser viewing.7273```bash74bash "<SKILL_DIR>/scripts/dispatcher.sh" --path [directory] --format html75```7677#### `cryptolint scan --category WA [directory]`78Filter scan to a specific check category (WA, KM, EM, RN, TC, CP).7980```bash81bash "<SKILL_DIR>/scripts/dispatcher.sh" --path [directory] --category WA82```8384### Team Tier ($39/user/month -- requires CRYPTOLINT_LICENSE_KEY with team tier)8586#### `cryptolint scan --tier team [directory]`87Full scan with all 90 patterns across all 6 categories including timing attacks and certificate/protocol checks.8889**How to execute:**90```bash91bash "<SKILL_DIR>/scripts/dispatcher.sh" --path [directory] --tier team92```9394**What it does:**951. Validates Team+ license962. Runs all 90 patterns across 6 categories973. Includes timing & comparison checks (timing side-channels, non-constant-time comparison)984. Includes certificate & protocol checks (TLS verification disabled, insecure protocols)995. Full category breakdown with per-file results100101#### `cryptolint scan --verbose [directory]`102Verbose output showing every matched line and pattern details.103104```bash105bash "<SKILL_DIR>/scripts/dispatcher.sh" --path [directory] --verbose106```107108#### `cryptolint status`109Show license and configuration information.110111```bash112bash "<SKILL_DIR>/scripts/dispatcher.sh" status113```114115## Check Categories116117CryptoLint detects 90 cryptographic anti-patterns across 6 categories:118119| Category | Code | Patterns | Description | Severity Range |120|----------|------|----------|-------------|----------------|121| **Weak Algorithms** | WA | 15 | MD5, SHA-1, DES, 3DES, RC4, Blowfish, weak PBKDF2 iterations, deprecated TLS versions | high -- critical |122| **Key Management** | KM | 15 | Hardcoded encryption keys, static IVs/salts, short keys, keys in source code, zero IVs | high -- critical |123| **Encryption Modes** | EM | 15 | ECB mode, CBC without authentication, raw RSA without padding, deprecated createCipher | medium -- critical |124| **Random Number Generation** | RN | 15 | Math.random() for security, java.util.Random for crypto, time-seeded RNG, predictable seeds | high -- critical |125| **Timing & Comparison** | TC | 15 | String equality for hashes, == for HMAC, non-constant-time comparisons, early-return timing leaks | medium -- high |126| **Certificate & Protocol** | CP | 15 | SSL/TLS verification disabled, hostname check bypassed, insecure protocol versions, HTTP in auth | high -- critical |127128## Tier-Based Pattern Access129130| Tier | Patterns | Categories |131|------|----------|------------|132| **Free** | 30 | WA, KM |133| **Pro** | 60 | WA, KM, EM, RN |134| **Team** | 90 | WA, KM, EM, RN, TC, CP |135| **Enterprise** | 90 | WA, KM, EM, RN, TC, CP + priority support |136137## Scoring138139CryptoLint uses a deductive scoring system starting at 100 (perfect):140141| Severity | Point Deduction | Description |142|----------|-----------------|-------------|143| **Critical** | -25 per finding | Broken algorithm or direct cryptographic vulnerability |144| **High** | -15 per finding | Significant cryptographic weakness (deprecated algo, weak key) |145| **Medium** | -8 per finding | Suboptimal practice (CBC without auth, weak mode choice) |146| **Low** | -3 per finding | Informational / best practice suggestion |147148### Grading Scale149150| Grade | Score Range | Meaning |151|-------|-------------|---------|152| **A** | 90-100 | Excellent cryptography practices |153| **B** | 80-89 | Good crypto with minor issues |154| **C** | 70-79 | Acceptable but needs improvement |155| **D** | 60-69 | Poor cryptography quality |156| **F** | Below 60 | Critical cryptography problems |157158- **Pass threshold:** 70 (Grade C or better)159- Exit code 0 = pass (score >= 70)160- Exit code 1 = fail (score < 70)161162## Configuration163164Users can configure CryptoLint in `~/.openclaw/openclaw.json`:165166```json167{168 "skills": {169 "entries": {170 "cryptolint": {171 "enabled": true,172 "apiKey": "YOUR_LICENSE_KEY_HERE",173 "config": {174 "severityThreshold": "medium",175 "ignorePatterns": ["**/test/**", "**/fixtures/**", "**/*.test.*"],176 "ignoreChecks": [],177 "reportFormat": "text"178 }179 }180 }181 }182}183```184185## Important Notes186187- **Free tier** works immediately with no configuration188- **All scanning happens locally** -- no code is sent to external servers189- **License validation is offline** -- no phone-home or network calls190- Pattern matching only -- no AST parsing, no external dependencies beyond bash191- Supports scanning all file types in a single pass192- Git hooks use **lefthook** which must be installed (see install metadata above)193- Exit codes: 0 = pass (score >= 70), 1 = fail (for CI/CD integration)194- Output formats: text (default), json, html195196## Error Handling197198- If lefthook is not installed and user tries hooks, prompt to install it199- If license key is invalid or expired, show clear message with link to https://cryptolint.pages.dev/renew200- If a file is binary, skip it automatically with no warning201- If no scannable files found in target, report clean scan with info message202- If an invalid category is specified with --category, show available categories203204## When to Use CryptoLint205206The user might say things like:207- "Scan my code for crypto issues"208- "Check my cryptography usage"209- "Find weak algorithms in my code"210- "Detect hardcoded encryption keys"211- "Are there any MD5 or SHA1 uses?"212- "Check for insecure encryption modes"213- "Audit my TLS configuration"214- "Find ECB mode usage"215- "Check for timing attack vulnerabilities"216- "Scan for weak random number generation"217- "Run a cryptography audit"218- "Generate a crypto quality report"219- "Check if Math.random is used for security"220- "Find hardcoded IVs and salts"221- "Check my code for crypto anti-patterns"