New to Claude Skills? Learn how to install them →

sickn33 on GitHub

Constant-Time Analysis

Free

Detect timing leaks in cryptographic code execution.

Get this skill

Free · Opens the source repo

What Constant-Time Analysis does

Constant-Time Analysis is a specialized tool designed for developers working with cryptographic code. It focuses on identifying potential vulnerabilities that could arise from timing variations during execution. Such vulnerabilities can lead to secret data leakage, making this skill essential for anyone implementing cryptographic functions like encryption, signing, or key derivation. The skill analyzes the code for operations that may inadvertently expose sensitive information through timing attacks, which are a common side-channel attack vector.

This skill is particularly useful when your code involves secret keys or tokens, as it can detect operations that could be exploited by an attacker. By analyzing the code for specific patterns, such as the use of division or modulus operations on secret-derived values, it helps ensure that your cryptographic implementations are robust against timing attacks. The tool is designed to be easy to integrate into your development workflow, allowing you to run analyses quickly and efficiently.

When using Constant-Time Analysis, you can expect to receive detailed feedback on your code, including warnings about potential timing leaks and recommendations for secure coding practices. The skill supports a variety of programming languages, including C, C++, Go, Rust, Java, Kotlin, C#, Swift, PHP, JavaScript, TypeScript, Python, and Ruby, making it versatile for different development environments. This broad support ensures that developers across various platforms can benefit from enhanced security in their cryptographic implementations.

In summary, Constant-Time Analysis is a critical tool for developers focused on security in cryptographic applications. By identifying and mitigating timing leaks, it helps safeguard sensitive data and strengthens the overall security posture of your applications.

When to use it

Use this skill when writing cryptographic code or when analyzing code that handles sensitive keys or tokens.

When not to use it

Avoid this skill for non-cryptographic code or high-level APIs where timing is managed internally and does not expose secrets.

What you can build with it

Analyzing Encryption Functions

When implementing encryption algorithms, use this skill to ensure that no timing leaks could expose sensitive data.

Reviewing Cryptographic Libraries

If you're reviewing a library that handles cryptographic operations, run this skill to check for potential timing vulnerabilities.

Auditing Secret Key Management Code

Use this skill to analyze code that manages secret keys or tokens, ensuring it does not leak information through timing variations.

How to install Constant-Time Analysis

View source

1. Install with the skills CLI

npx skills add sickn33/agentic-awesome-skills/constant-time-analysis --agent claude-code

2. Or install it manually

Download the skill folder and drop it into ~/.claude/skills/ for all projects, or .claude/skills/ to scope it to one repo. Restart Claude Code so it picks up the new skill.

Anthropic's agentic coding CLI, and the reference implementation of Agent Skills. Drop a skill folder into ~/.claude/skills and Claude Code loads it automatically whenever a task matches the skill's description. Claude Code docs

Inside SKILL.md

Written by sickn33

Constant-Time Analysis

Analyze cryptographic code to detect operations that leak secret data through execution timing variations.

When to Use

User writing crypto code? ──yes──> Use this skill
         │
         no
         │
         v
User asking about timing attacks? ──yes──> Use this skill
         │
         no
         │
         v
Code handles secret keys/tokens? ──yes──> Use this skill
         │
         no
         │
         v
Skip this skill

Concrete triggers:

  • User implements signature, encryption, or key derivation
  • Code contains / or % operators on secret-derived values
  • User mentions "constant-time", "timing attack", "side-channel", "KyberSlash"
  • Reviewing functions named sign, verify, encrypt, decrypt, derive_key

When NOT to Use

  • Non-cryptographic code (business logic, UI, etc.)
  • Public data processing where timing leaks don't matter
  • Code that doesn't handle secrets, keys, or authentication tokens
  • High-level API usage where timing is handled by the library

Language Selection

Based on the file extension or language context, refer to the appropriate guide:

LanguageFile ExtensionsGuide
C, C++.c, .h, .cpp, .cc, .hppreferences/compiled.md
Go.goreferences/compiled.md
Rust.rsreferences/compiled.md
Swift.swiftreferences/swift.md
Java.javareferences/vm-compiled.md
Kotlin.kt, .ktsreferences/kotlin.md
C#.csreferences/vm-compiled.md
PHP.phpreferences/php.md
JavaScript.js, .mjs, .cjsreferences/javascript.md
TypeScript.ts, .tsxreferences/javascript.md
Python.pyreferences/python.md
Ruby.rbreferences/ruby.md

Quick Start

# Analyze any supported file type
uv run {baseDir}/ct_analyzer/analyzer.py <source_file>

# Include conditional branch warnings
uv run {baseDir}/ct_analyzer/analyzer.py --warnings <source_file>

# Filter to specific functions
uv run {baseDir}/ct_analyzer/analyzer.py --func 'sign|verify' <source_file>

# JSON output for CI
uv run {baseDir}/ct_analyzer/analyzer.py --json <source_file>

Native Compiled Languages Only (C, C++, Go, Rust)

# Cross-architecture testing (RECOMMENDED)
uv run {baseDir}/ct_analyzer/analyzer.py --arch x86_64 crypto.c
uv run {baseDir}/ct_analyzer/analyzer.py --arch arm64 crypto.c

# Multiple optimization levels
uv run {baseDir}/ct_analyzer/analyzer.py --opt-level O0 crypto.c
uv run {baseDir}/ct_analyzer/analyzer.py --opt-level O3 crypto.c

VM-Compiled Languages (Java, Kotlin, C#)

# Analyze Java bytecode
uv run {baseDir}/ct_analyzer/analyzer.py CryptoUtils.java

# Analyze Kotlin bytecode (Android/JVM)
uv run {baseDir}/ct_analyzer/analyzer.py CryptoUtils.kt

# Analyze C# IL
uv run {baseDir}/ct_analyzer/analyzer.py CryptoUtils.cs

Note: Java, Kotlin, and C# compile to bytecode (JVM/CIL) that runs on a virtual machine with JIT compilation. The analyzer examines the bytecode directly, not the JIT-compiled native code. The --arch and --opt-level flags do not apply to these languages.

Swift (iOS/macOS)

# Analyze Swift for native architecture
uv run {baseDir}/ct_analyzer/analyzer.py crypto.swift

# Analyze for specific architecture (iOS devices)
uv run {baseDir}/ct_analyzer/analyzer.py --arch arm64 crypto.swift

# Analyze with different optimization levels
uv run {baseDir}/ct_analyzer/analyzer.py --opt-level O0 crypto.swift

Note: Swift compiles to native code like C/C++/Go/Rust, so it uses assembly-level analysis and supports --arch and --opt-level flags.

Prerequisites

LanguageRequirements
C, C++, Go, RustCompiler in PATH (gcc/clang, go, rustc)
SwiftXcode or Swift toolchain (swiftc in PATH)
JavaJDK with javac and javap in PATH
KotlinKotlin compiler (kotlinc) + JDK (javap) in PATH
C#.NET SDK + ilspycmd (dotnet tool install -g ilspycmd)
PHPPHP with VLD extension or OPcache
JavaScript/TypeScriptNode.js in PATH
PythonPython 3.x in PATH
RubyRuby with --dump=insns support

macOS users: Homebrew installs Java and .NET as "keg-only". You must add them to your PATH:

# For Java (add to ~/.zshrc)
export PATH="/opt/homebrew/opt/openjdk@21/bin:$PATH"

# For .NET tools (add to ~/.zshrc)
export PATH="$HOME/.dotnet/tools:$PATH"

See references/vm-compiled.md for detailed setup instructions and troubleshooting.

Quick Reference

ProblemDetectionFix
Division on secretsDIV, IDIV, SDIV, UDIVBarrett reduction or multiply-by-inverse
Branch on secretsJE, JNE, BEQ, BNEConstant-time selection (cmov, bit masking)
Secret comparisonEarly-exit memcmpUse crypto/subtle or constant-time compare
Weak RNGrand(), mt_rand, Math.randomUse crypto-secure RNG
Table lookup by secretArray subscript on secret indexBit-sliced lookups

Interpreting Results

PASSED - No variable-time operations detected.

FAILED - Dangerous instructions found. Example:

[ERROR] SDIV
  Function: decompose_vulnerable
  Reason: SDIV has early termination optimization; execution time depends on operand values

Verifying Results (Avoiding False Positives)

CRITICAL: Not every flagged operation is a vulnerability. The tool has no data flow analysis - it flags ALL potentially dangerous operations regardless of whether they involve secrets.

For each flagged violation, ask: Does this operation's input depend on secret data?

  1. Identify the secret inputs to the function (private keys, plaintext, signatures, tokens)

  2. Trace data flow from the flagged instruction back to inputs

  3. Common false positive patterns:

    // FALSE POSITIVE: Division uses public constant, not secret
    int num_blocks = data_len / 16;  // data_len is length, not content
    
    // TRUE POSITIVE: Division involves secret-derived value
    int32_t q = secret_coef / GAMMA2;  // secret_coef from private key
    
  4. Document your analysis for each flagged item

Quick Triage Questions

QuestionIf YesIf No
Is the operand a compile-time constant?Likely false positiveContinue
Is the operand a public parameter (length, count)?Likely false positiveContinue
Is the operand derived from key/plaintext/secret?TRUE POSITIVELikely false positive
Can an attacker influence the operand value?TRUE POSITIVELikely false positive

Limitations

  1. Static Analysis Only: Analyzes assembly/bytecode, not runtime behavior. Cannot detect cache timing or microarchitectural side-channels.

  2. No Data Flow Analysis: Flags all dangerous operations regardless of whether they process secrets. Manual review required.

  3. Compiler/Runtime Variations: Different compilers, optimization levels, and runtime versions may produce different output.

Real-World Impact

  • KyberSlash (2023): Division instructions in post-quantum ML-KEM implementations allowed key recovery
  • Lucky Thirteen (2013): Timing differences in CBC padding validation enabled plaintext recovery
  • RSA Timing Attacks: Early implementations leaked private key bits through division timing

References

Frequently asked questions about Constant-Time Analysis

Similar skills