Review agent · Secrets & crypto
Cryptography
Checks that cryptographic primitives fit their purpose and keys, IVs and randomness are handled correctly.
Illustrative example of how this agent reviews a finding.
Why this agent matters
Weak crypto fails silently: everything works until someone cracks the passwords or forges the tokens. OWASP ranks it A02 (Cryptographic Failures).
Scanners flag every MD5 and every random() call, but MD5 for a cache key is fine and random() for a UI shuffle is fine. This agent judges purpose, so you fix the password hashing, not the ETag.
What it checks
- Broken primitives used for security: MD5, SHA-1, DES, RC4, ECB mode
- Hard-coded or predictable keys, IVs and salts; nonce reuse
- Non-cryptographic randomness used for tokens or secrets
- Unsalted or low-cost password hashing
When it marks a finding as a likely false positive
- The primitive is used for a non-security purpose such as a checksum or cache key
The fix it suggests
- AES-GCM and SHA-256 or better
- Argon2 or bcrypt for passwords
- A CSPRNG and proper key management
Scope and limits
This agent validates findings reported by Semgrep, Gitleaks and Trivy; it doesn't hunt for new bugs on its own. A finding reaches it when its CWE or rule/path keywords match this vulnerability class. It sees only the minimal code around the finding, with secrets redacted, and returns a verdict with a confidence score, a plain-English explanation and a suggested patch.
Common questions
Will it make me remove every MD5?
No. It marks non-security uses such as checksums as likely false positives and explains why.
Related agents
- Secrets & data exposure — Judges whether a flagged value is really a secret and whether sensitive data leaks through logs or errors.
See all 20 review agents → · Agent setup reviewer · How the pipeline works
Run the Cryptography agent on your repository
100 free credits, no credit card. Every finding comes with a verdict and a fix.
Get started free