Sign In

cryptoserve

Package Overview
Dependencies
Maintainers
1
Versions
13
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

cryptoserve

CryptoServe CLI - Cryptographic scanning, PQC analysis, encryption, and local key management

Source
npmnpm
Version
0.1.3
Version published
Weekly downloads
231
16.08%
Maintainers
1
Weekly downloads
 
Created
Source

CryptoServe CLI (Node.js)

Zero-dependency CLI for cryptographic scanning, post-quantum readiness analysis, encryption, and local key management.

npx cryptoserve pqc

Installation

# Run without installing
npx cryptoserve help

# Or install globally
npm install -g cryptoserve

Requires Node.js 18 or later. No dependencies — uses only Node.js built-in modules (node:crypto, node:fs, node:https).

Commands

CommandDescription
scan [path]Scan project for crypto libraries, hardcoded secrets, and weak patterns
pqcPost-quantum readiness analysis with SNDL risk assessment
encrypt / decryptPassword-based encryption (strings and files)
context list / showList and inspect context-aware algorithm presets
hash-passwordscrypt / PBKDF2 password hashing
vaultEncrypted local secret storage with env injection
initSet up master key + AI tool protection
login / statusConnect to a CryptoServe server

Scan

Detect crypto libraries, algorithm usage, hardcoded secrets, and certificate files in JavaScript/TypeScript projects.

cryptoserve scan .
cryptoserve scan ./src --format json

Detects 20+ crypto packages (jsonwebtoken, node-forge, @noble/curves, etc.), node:crypto API usage, algorithm string literals, weak patterns (MD5, DES, ECB, createCipher), and hardcoded API keys (AWS, OpenAI, Anthropic, GitHub, Stripe, and more).

PQC Analysis

Offline post-quantum readiness assessment. Evaluates your project's cryptographic posture against quantum threat timelines.

cryptoserve pqc
cryptoserve pqc --profile healthcare
cryptoserve pqc --profile national_security --verbose
cryptoserve pqc --format json

Profiles: general, national_security, healthcare, financial, intellectual_property, legal, authentication, session_tokens, ephemeral

Output includes quantum readiness score (0-100), SNDL risk assessment, KEM/signature recommendations (ML-KEM, ML-DSA, SLH-DSA), migration plan, and compliance references (CNSA 2.0, NIST SP 800-208, BSI, ANSSI).

Encrypt / Decrypt

AES-256-GCM, AES-128-GCM, and ChaCha20-Poly1305 encryption with password-based key derivation (scrypt).

# Text
cryptoserve encrypt "sensitive data" --password mypassword
cryptoserve decrypt "<base64 output>" --password mypassword

# Files
cryptoserve encrypt --file report.pdf --output report.enc --password mypassword
cryptoserve decrypt --file report.enc --output report.pdf --password mypassword

# Choose algorithm
cryptoserve encrypt "data" --algorithm ChaCha20-Poly1305 --password mypassword

# Context-aware (auto-selects algorithm based on data sensitivity)
cryptoserve encrypt "SSN: 123-45-6789" --context user-pii --password mypassword

Cross-SDK Compatibility

The encrypted blob format is byte-identical between the Python and Node.js SDKs. Data encrypted by one can be decrypted by the other:

[header_len: 2 bytes][JSON header][ciphertext + auth tag]

Context-Aware Encryption

A 5-layer algorithm resolver selects the optimal encryption algorithm based on data sensitivity, compliance requirements, threat model, and access patterns.

# List available contexts
cryptoserve context list

# Show full resolution rationale
cryptoserve context show user-pii --verbose

# Encrypt with automatic algorithm selection
cryptoserve encrypt "patient diagnosis" --context health-data --password mypassword

Built-in Contexts

ContextSensitivityAlgorithmCompliance
user-piiHighAES-256-GCMGDPR
payment-dataCriticalAES-256-GCMPCI-DSS
session-tokensMediumAES-128-GCMOWASP
health-dataCriticalAES-256-GCMHIPAA
generalMediumAES-128-GCM

Custom Contexts

Add project-specific contexts in .cryptoserve.json:

{
  "contexts": {
    "audit-logs": {
      "displayName": "Audit Logs",
      "sensitivity": "high",
      "compliance": ["SOX"],
      "adversaries": ["insider"],
      "protectionYears": 7,
      "usage": "at_rest",
      "frequency": "high"
    }
  }
}

Password Hashing

cryptoserve hash-password
cryptoserve hash-password --algorithm pbkdf2

Outputs $scrypt$... or $pbkdf2-sha256$... format strings.

Vault

Encrypted local secret storage using AES-256-GCM. Secrets are stored at ~/.cryptoserve/vault.enc.

cryptoserve vault init
cryptoserve vault set DATABASE_URL "postgres://..."
cryptoserve vault set API_KEY "sk-..."
cryptoserve vault get DATABASE_URL
cryptoserve vault list

# Run a command with secrets injected as environment variables
cryptoserve vault run -- node server.js

# Import from .env file
cryptoserve vault import .env

Init

Set up master key storage and AI tool protection in one command.

cryptoserve init

This generates a master key (stored in OS keychain on macOS/Linux, encrypted file fallback), detects AI coding tools (Claude Code, Cursor, Copilot, Windsurf, Cline, Aider), and configures deny rules to prevent them from reading .env, .pem, .key, and other sensitive files.

Programmatic Usage

All modules are importable as ES modules:

import { encrypt, decrypt, encryptString, decryptString } from 'cryptoserve/lib/local-crypto.mjs';
import { analyzeOffline } from 'cryptoserve/lib/pqc-engine.mjs';
import { scanProject } from 'cryptoserve/lib/scanner.mjs';
import { resolveContext } from 'cryptoserve/lib/context-resolver.mjs';

License

Apache-2.0

Keywords

cryptography

FAQs

Package last updated on 10 Feb 2026

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts