CRYPTOGRAPHY

snoot

An offline cryptography inventory tool that helps teams locate classical public-key cryptography and plan post-quantum migration.

Current state
Experimental v0.1
Discipline
Cryptography
Built with
Rust / Tree-sitter / SARIF / CycloneDX CBOM / GitHub Actions

The idea

Locate classical public-key cryptography before a post-quantum migration, and preserve the resulting inventory in formats that teams can review and use in CI.

How it works

Four Rust detection engines examine source syntax, key material, dependency manifests and TLS configuration. Tree-sitter queries cover source languages; structured parsers support other evidence. Findings flow into portable baselines and machine-readable reports.

What’s implemented

  • Inventories RSA, elliptic-curve, DSA and DH surfaces across source, keys, dependencies and configuration
  • Exports SARIF, JSON and CycloneDX 1.6 cryptographic bills of materials
  • Provides a GitHub Action, reviewed baselines and severity gates
  • Maps findings to NIST post-quantum replacement families

PROJECT STATUS / EXPERIMENTAL V0.1

Where it stands

Experimental release · v0.1.0

  • Detection is heuristic and recall is unmeasured
  • No data-flow or transitive dependency analysis; source code only
  • A clean scan does not establish quantum safety or complete coverage

Source & resources

Documentation behind this project page

Reviewed October 1, 2026. Project descriptions reflect a source review; repository validation claims were not independently reproduced.