Setup & Installation
What This Skill Does
Detects timing side-channel vulnerabilities in cryptographic code across 12 languages. It analyzes assembly and bytecode for variable-time operations like secret-dependent branches, divisions, and table lookups that can leak private key material through execution timing. Developed by Trail of Bits.
Manual code review misses timing vulnerabilities because the dangerous patterns look like normal arithmetic — this tool flags the exact instructions (DIV, IDIV, conditional jumps) that create exploitable timing differences, across languages from C to Python.
When to use it
- Checking a post-quantum KEM implementation for division on secret coefficients
- Auditing a custom HMAC verify function for early-exit comparison paths
- Scanning a JWT signing library before shipping to production
- Running cross-architecture timing checks on the same crypto routine for x86_64 and arm64
- Adding constant-time violation checks to a CI pipeline for a cryptography library