スキル一覧に戻る
bentefay

crypto

by bentefay

A web app to help you understand where your money is going.

2🍴 0📅 2026年1月10日
GitHubで見るManusで実行

SKILL.md


name: crypto description: Client-side cryptography with libsodium. Use when working on files in src/lib/crypto/.

Crypto Guidelines

All crypto happens client-side. Server NEVER sees plaintext.

Architecture

  • Seed phrase (128-bit) → Ed25519 keypair (signing) → X25519 keypair (encryption)
  • Vault key (random 256-bit) wrapped with user's X25519 public key
  • Data encrypted with XChaCha20-Poly1305

Critical Rules

  1. Never log keys or sensitive data - not even in development
  2. Use libsodium - don't implement crypto primitives
  3. Async everywhere - all functions async (libsodium-wrappers)
  4. Constant-time comparisons - sodium.compare for secrets
  5. Zeroize secrets - sodium.memzero when done
  6. Type-safe keys - use branded types (VaultKey, SigningKey)

Common Pitfalls

  • Don't use crypto.randomBytes → use sodium.randombytes_buf
  • Don't concatenate key material → use proper KDFs
  • Don't store keys in localStorage without encryption
  • Don't forget await sodium.ready before operations

Testing

Use property-based tests for roundtrip verification with fast-check.

スコア

総合スコア

50/100

リポジトリの品質指標に基づく評価

SKILL.md

SKILL.mdファイルが含まれている

+20
LICENSE

ライセンスが設定されている

0/10
説明文

100文字以上の説明がある

0/10
人気

GitHub Stars 100以上

0/15
最近の活動

3ヶ月以内に更新がある

0/10
フォーク

10回以上フォークされている

0/5
Issue管理

オープンIssueが50未満

+5
言語

プログラミング言語が設定されている

+5
タグ

1つ以上のタグが設定されている

0/5

レビュー

💬

レビュー機能は近日公開予定です