hypnguyen1209/vulnerability-analysis
Use when auditing source code for vulnerabilities — drive CodeQL/Semgrep/Joern to taint untrusted data source-to-sink across injection, memory safety, deserialization/prototype-pollution, secrets/crypto/authz/race, and supply-chain risks
npx skills add https://github.com/hypnguyen1209/offensive-claude --skill vulnerability-analysis
Every vulnerability you miss is one an attacker finds first. Systematic source
auditing traces untrusted data from source to sink, evaluates every
sanitizer for bypass, and questions each trust-boundary assumption. This skill is
the router; depth lives in references/, and every technique cluster is backed
by a runnable tool in scripts/.
| Technique | ATT&CK | CWE | Reference | Script |
|-----------|--------|-----|-----------|--------|
| Taint analysis (source/sink/sanitizer modeling) | T1190 | CWE-20 | references/taint-engines-static-analysis.md | scripts/taint_trace.py |
| CodeQL/Semgrep/Joern engine orchestration + merge | T1190 | CWE-20 | references/taint-engines-static-analysis.md | scripts/sast_runner.py, scripts/joern_taint.sc |
| SQL injection (raw/ORM/identifier/2nd-order/NoSQL) | T1190 | CWE-89 | references/injection-source-patterns.md | scripts/taint_trace.py |
| OS command / argument injection | T1059 | CWE-78 / CWE-88 | references/injection-source-patterns.md | scripts/taint_trace.py |
| Server-side template injection | T1190 | CWE-1336 | references/injection-source-patterns.md | scripts/taint_trace.py |
| Path traversal | T1083 | CWE-22 | references/injection-source-patterns.md | scripts/taint_trace.py |
| SSRF (tainted server-side URL) | T1190 | CWE-918 | references/injection-source-patterns.md | scripts/taint_trace.py |
| Integer overflow -> heap/stack overflow | T1203 | CWE-190 / CWE-787 | references/memory-safety-c-cpp.md | scripts/joern_taint.sc |
| Use-after-free / double-free | T1203 | CWE-416 / CWE-415 | references/memory-safety-c-cpp.md | scripts/joern_taint.sc |
| Unbounded copy / NULL deref | T1203 | CWE-120 / CWE-476 | references/memory-safety-c-cpp.md | scripts/joern_taint.sc |
| Insecure deserialization + gadget preconditions | T1059 | CWE-502 | references/deserialization-prototype-pollution.md | scripts/deser_gadget_scan.py |
| Prototype pollution -> gadget -> RCE | T1059.007 | CWE-1321 | references/deserialization-prototype-pollution.md | scripts/deser_gadget_scan.py |
| Hardcoded secrets / high-entropy literals | T1552.001 | CWE-798 / CWE-321 | references/secrets-crypto-authz-concurrency.md | scripts/secret_crypto_audit.py |
| Weak / misused cryptography | T1600 | CWE-327 / CWE-328 / CWE-330 / CWE-347 | references/secrets-crypto-authz-concurrency.md | scripts/secret_crypto_audit.py |
| Broken authorization / IDOR / BOLA | T1190 | CWE-639 / CWE-862 | references/secrets-crypto-authz-concurrency.md | scripts/secret_crypto_audit.py |
| TOCTOU / race condition | T1190 | CWE-367 / CWE-362 | references/secrets-crypto-authz-concurrency.md | scripts/secret_crypto_audit.py |
| Known-CVE dependency (SCA) | T1195.001 | CWE-1395 / CWE-1104 | references/supply-chain-dependency-audit.md | scripts/dep_audit.py |
| Malicious package / install worm / typosquat | T1195.002 | CWE-506 / CWE-829 / CWE-1357 | references/supply-chain-dependency-audit.md | scripts/dep_audit.py |
| Variant hunting — one finding -> all siblings, root-cause clustered | T1190 | CWE-20 | references/variant-hunting.md | scripts/variant_hunt.py |
| Path feasibility — branch guards -> tri-state SAT/UNSAT (Z3 optional) | T1190 | CWE-20 | references/taint-engines-static-analysis.md | scripts/path_conditions.py |
| Evidence grounding + FP gate (structured proof, EVD citations) | T1190 | CWE-20 | references/finding-validation-runtime.md | scripts/validate_findings.py, scripts/evidence_kit.py |
| Runtime reachability confirmation (Frida sink-executed) | T1190 | CWE-20 | references/dynamic-instrumentation.md | scripts/merge_runtime_evidence.py |
# 0. Intake from recon-osint: languages, frameworks, trust boundaries, entry points.
# 1. Fast triage — rank files by unsanitized source->sink flows (heuristic, multi-lang)
python3 scripts/taint_trace.py trace ./src --lang py,js,php,java --json triage.json
python3 scripts/taint_trace.py config --lang py > seed.semgrep.yml # seed a real rule
# 2. Deep interprocedural — drive the real engines, then merge into one ranked list
python3 scripts/sast_runner.py semgrep --src ./src --config p/owasp-top-ten --pro --out sg.sarif
python3 scripts/sast_runner.py codeql --src ./src --lang python \
--suite codeql/python-queries:codeql-suites/python-security-extended.qls --out cq.sarif
python3 scripts/sast_runner.py joern --src ./src --script scripts/joern_taint.sc --out joern.json
python3 scripts/sast_runner.py merge sg.sarif cq.sarif joern.json --out merged.json --top 50
# 3. Class-specific deep passes
python3 scripts/deser_gadget_scan.py all ./src --json deser.json # deser sinks + gadget libs
python3 scripts/secret_crypto_audit.py all ./src --json sca.json # secrets+crypto+authz+TOCTOU
python3 scripts/dep_audit.py all ./repo --json dep.json # CVE SCA + worm/typosquat
trufflehog filesystem ./src --only-verified # confirm LIVE secrets
# 4. Exploitability gate (per finding): reachable? controllable? real impact? sanitizer real?
# -> write confirmed issues to templates/exploit/findings/ with
# severity, CWE, CVSS, taint path, PoC, evidence, ATT&CK ID, remediation.
python3 scripts/evidence_kit.py verify --store evidence.json # re-hash every artifact
python3 scripts/validate_findings.py --findings findings.json \
--evidence ./evidence --evidence-store evidence.json --strict # tier + EVD-citation gate
# 5. After a CONFIRMED finding: hunt every sibling, then prune false-positive paths
python3 scripts/variant_hunt.py ./src --seed-finding findings.json --lang py,js --json variants.json
python3 scripts/taint_trace.py trace ./src --lang py --json trace.json # trace carries branch guards
python3 scripts/path_conditions.py --trace trace.json --json feasibility.json # Z3 prune (tri-state)
python3 scripts/merge_runtime_evidence.py --events events.jsonl --findings findings.json --out merged.json
| Technique | Telemetry / IOC | Detection (Sigma/EDR) | OPSEC note |
|-----------|-----------------|------------------------|------------|
| SAST engine runs | codeql database create, semgrep --sarif, joern-parse process trees; large codeql-db//cpg.bin | CI process-creation Sigma (informational) | offline & silent; CodeQL --command runs target build -> sandbox hostile repos; purge DBs/SARIF on teardown |
| Injection (SQLi/cmdi/SSTI/SSRF) | SQL keywords/SLEEP, web svc spawning sh/curl, template engine errors, OOB DNS | webserver regex + EDR child-shell Sigma | source review is noiseless; validate with time-based/DNS-OOB, never --dump |
| Memory safety (C/C++) | SIGSEGV/SIGABRT, glibc corrupted/double free, ASan reports | auditd ANOM_ABEND Sigma; EDR RWX/W^X alerts | CPG review silent; fuzz a local copy in a container, purge cores (may hold secrets) |
| Deserialization / proto-pollution | Java rO0AB/.NET AAEAAAD///// in bodies; JVM->LDAP/RMI; POST / w/ Next-Action (CVE-2025-55182) | egress Sigma to 389/636/1099/1389; body-marker rules | prove gadget chain exists; id/DNS callback not reverse shell; proto-pollution is global -> revert |
| Secrets / crypto / authz / TOCTOU | AKIA*/ghp_* patterns; alg:none; sequential-id 200s; symlink-race auditd | secret-scanning push protection; symlink/PATH auditd | secret *verification* makes a logged provider API call -> only in scope; read one record for IDOR/TOCTOU evidence |
| Supply chain (SCA / worm) | install hook spawning shell/net; bundle.js/setup_bun.js; new public Shai-Hulud repo | install-script process-creation Sigma; agentless SBOM lookup | never npm install a suspect tree; --ignore-scripts in a disposable container; treat a compromised dep as full host compromise |
Semgrep (taint mode, Pro interfile, Opengrep), CodeQL modular dataflow API,
Joern CPG/reachableBy; engine orchestration + multi-tool merge; CPG+LLM (2025).
identifier/ORDER BY/2nd-order/NoSQL), OS command & argument injection, SSTI,
path traversal, SSRF; per-language safe/vuln pairs; Joern/Semgrep confirmation.
unbounded copy, NULL deref; the 2025 libxml2 CVE cluster; ASan/UBSan + fuzzing
confirmation; unsafe Rust surface.
preconditions (ysoserial/phpggc/ysoserial.net), JS prototype pollution->RCE;
React2Shell CVE-2025-55182, Tomcat CVE-2025-24813, lodash CVE-2025-13465, Silent
Spring.
trufflehog/Kingfisher), weak crypto, IDOR/BOLA, TOCTOU/race; LLM-augmented
secret detection (2025).
worm heuristics, typosquats; Shai-Hulud 1.0/2.0/Mini (CVE-2026-45321), the SLSA
provenance-bypass lesson.
sweep, same-function taint qualification, root-cause clustering (copy-paste/shared-util/
framework-misuse) to decide one-fix-or-many; backed by variant_hunt.py. Pairs with
evidence_kit.py (re-verifiable EVD evidence), path_conditions.py (Z3 path-prune, tri-state),
and merge_runtime_evidence.py (Frida runtime sink confirmation).
Take hypnguyen1209/vulnerability-analysis from the repository into ~/.claude/skills for personal
use, or into .claude/skills inside a project.
The agent identifies a skill by the name field in its header. Two skills with the
same name cannot sit side by side — one of them will be ignored.
The instructions reference npm.
Without those the skill loads but fails at the first command.