ciphertext

A specialized workflow for recovering the algorithm or key-related process behind a target ciphertext from an ARM64 execution trace.

In plain words
What is it for?
Use it to bind an ARM64 trace, search for encryption-related operations, inspect round functions and key schedules, and verify a recovery.
Why use it?
It imposes a structured investigation of data flow and candidate algorithms so early trace matches are not mistaken for proof.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/icloudza/algokiller-plugin/ciphertext
Any agent
npx skills add icloudza/algokiller-plugin --skill ciphertext
Clone the repo
git clone --depth 1 https://github.com/icloudza/algokiller-plugin

Made for: Claude Code, Codex.

Per session 40 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 466 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00040 $0.00466
Opus 5 $0.00020 $0.00233
Sonnet 5 $0.00008 $0.00093
Haiku 4.5 $0.00004 $0.00047

Measured 2d ago against content hash ae55dc1d548c, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

ciphertext scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/ciphertext/SKILL.md · 33 lines

What it actually says

You are now entering AlgoKiller ciphertext-recovery mode. High-discipline analysis; drift = hallucination.

MANDATORY FIRST STEPS — execute in order:

  1. Load the full methodology from the ak:ciphertext-recovery skill. Read it completely before any tool call. This is not optional — the skill contains candidate-family enumeration, key-schedule extraction, round-function extraction, modification detection, table-lookup evidence, and closed-loop verification methodology.

  2. Parse the user input below. The first whitespace-separated token is the absolute path to the ARM64 trace log; the rest is the task description (target ciphertext + any optional context).

  3. Call MCP tool ak.bind_trace with that path and mode="ciphertext". Do not proceed if bind fails.

  4. Proceed with the methodology from the skill. Every trace_search / trace_context return will include a discipline_reminder field — read it and respect it.

NON-NEGOTIABLE RULES (skill expands each):

  • Earliest hit = candidate, not conclusion. Verify it sits on the upstream data-flow of the target ciphertext.
  • Classify every notable hit: origin / generation / copy / encode / consume / stale / conflict.
  • Exhaust candidate families (block / stream / hash / CRC / compression / XOR-add-rotate / Feistel-SPN-ARX) with match-or-conflict evidence before naming a standard algorithm.
  • Backward chain-chasing: hard limit 3 hops.
  • Input contract: only target ciphertext is guaranteed. Do NOT ask the user for missing field names / encoding / request context / samples — search and infer.
  • Sufficient evidence → write_artifact recovered Python (.py) + analysis report (.md).
  • Partial evidence → deliver confirmed + high-confidence + open gaps. Don't stall.

User input:

$ARGUMENTS

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 33 lines · 40 tokens per session scan A ae55dc1d548c

Subscribe to this mod's changes

ciphertext is a skill published in the GitHub repository icloudza/algokiller-plugin (77 stars, last pushed 3mo ago), licensed MIT. It adds 40 tokens to every session and 466 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

hexwitness

Investigate authorized binaries and runtime behavior with HexWitness's durable evidence MCP and optional Binary Ninja or IDA live tools. Use for function or class discovery, UUID and field mapping, protocol reconstruction, capture comparison, contradiction analysis, evidence-gap planning, and promotion of live…

siaginw/HexWitness · 64 tokens

liveagent-code-review

Review an open GitHub pull request or the current local branch and working tree with parallel, independent reviewers and evidence-based validation. Use when the user asks for code review, invokes the Code Review action from Git Review, or explicitly mentions this skill.

Stack-Cairn/LiveAgent · 54 tokens

deploy

Trigger the claude-desktop-extra Build & Release GitHub Actions pipeline (build-and-release.yml). With no argument the skill inspects the changes since the last release and decides forcerebuild itself; "/deploy force" / "/deploy no-force" override.

patrickjaja/claude-desktop-extra · 54 tokens

sessions

Search and ask questions about coding agent session history across Claude Code, Codex, and Cursor. Use when asking what was worked on, what was tried before, how a problem was investigated across sessions, what happened recently, or any question about past agent sessions. Also use when the user references prior…

slopus/happy · 78 tokens

discover-interview-synthesis

Synthesizes user research interviews into actionable insights, patterns, and recommendations. Use after conducting user interviews, customer calls, or usability sessions to extract and communicate findings across participants. Distinct from foundation-meeting-recap, which summarizes one internal meeting for its…

product-on-purpose/pm-skills · 69 tokens

define-jtbd-canvas

Creates a Jobs to be Done canvas capturing the functional, emotional, and social dimensions of a customer job. Use when deeply understanding customer motivations, designing for jobs, or reframing product positioning.

product-on-purpose/pm-skills · 45 tokens