CRYPTOGRAPHY
snoot
An offline cryptography inventory tool that helps teams locate classical public-key cryptography and plan post-quantum migration.
- Current state
- Experimental v0.1
- Discipline
- Cryptography
- Built with
- Rust / Tree-sitter / SARIF / CycloneDX CBOM / GitHub Actions
The idea
Locate classical public-key cryptography before a post-quantum migration, and preserve the resulting inventory in formats that teams can review and use in CI.
How it works
Four Rust detection engines examine source syntax, key material, dependency manifests and TLS configuration. Tree-sitter queries cover source languages; structured parsers support other evidence. Findings flow into portable baselines and machine-readable reports.
What’s implemented
- Inventories RSA, elliptic-curve, DSA and DH surfaces across source, keys, dependencies and configuration
- Exports SARIF, JSON and CycloneDX 1.6 cryptographic bills of materials
- Provides a GitHub Action, reviewed baselines and severity gates
- Maps findings to NIST post-quantum replacement families
PROJECT STATUS / EXPERIMENTAL V0.1
Where it stands
Experimental release · v0.1.0
- Detection is heuristic and recall is unmeasured
- No data-flow or transitive dependency analysis; source code only
- A clean scan does not establish quantum safety or complete coverage
Source & resources
Documentation behind this project page
Reviewed October 1, 2026. Project descriptions reflect a source review; repository validation claims were not independently reproduced.