---
name: vulnerability-analysis
description: Use when auditing source code for vulnerabilities — drive CodeQL/Semgrep/Joern to taint untrusted data source-to-sink across injection, memory safety, deserialization/prototype-pollution, secrets/crypto/authz/race, and supply-chain risks
metadata:
  type: offensive
  phase: analysis
  tools: codeql, semgrep, joern, opengrep, trufflehog, gitleaks, kingfisher, osv-scanner, syft, grype, trivy, npm-audit, pip-audit, ysoserial, phpggc
  mitre: [T1190, T1059, T1552.001, T1195.001, T1213]
kill_chain:
  phase: [recon, exploit]
  step: [1, 4]
  attck_tactics: [TA0043, TA0002, TA0001]
  attck_techniques: [T1190, T1059, T1552.001, T1195.001, T1195.002]
depends_on: [recon-osint]
feeds_into: [exploit-development, web-pentest]
inputs: [attack_surface_map, source_code]
outputs: [vulnerability_list, taint_analysis_report, finding_record, sbom]
references:
  - references/taint-engines-static-analysis.md
  - references/injection-source-patterns.md
  - references/memory-safety-c-cpp.md
  - references/deserialization-prototype-pollution.md
  - references/secrets-crypto-authz-concurrency.md
  - references/supply-chain-dependency-audit.md
  - references/variant-hunting.md
scripts:
  - scripts/taint_trace.py
  - scripts/sast_runner.py
  - scripts/joern_taint.sc
  - scripts/deser_gadget_scan.py
  - scripts/secret_crypto_audit.py
  - scripts/dep_audit.py
  - scripts/validate_findings.py
  - scripts/evidence_kit.py
  - scripts/variant_hunt.py
  - scripts/path_conditions.py
  - scripts/merge_runtime_evidence.py
---

# Vulnerability Analysis

Every vulnerability you miss is one an attacker finds first. Systematic source
auditing traces untrusted data from **source** to **sink**, evaluates every
sanitizer for bypass, and questions each trust-boundary assumption. This skill is
the router; depth lives in `references/`, and every technique cluster is backed
by a runnable tool in `scripts/`.

## When to Activate

- Auditing any codebase (white/grey box) for security vulnerabilities
- Writing/driving CodeQL queries, Semgrep taint rules, or Joern CPGQL flows
- Tracing injection, deserialization, prototype-pollution, or memory-safety paths
- Reviewing auth/authorization (IDOR/BOLA), cryptography, or concurrency (TOCTOU)
- Triaging dependency CVEs and hunting malicious/compromised packages (SCA)
- Variant hunting — generalizing one finding into a codebase-wide pattern

## Technique Map

| Technique | ATT&CK | CWE | Reference | Script |
|-----------|--------|-----|-----------|--------|
| Taint analysis (source/sink/sanitizer modeling) | T1190 | CWE-20 | references/taint-engines-static-analysis.md | scripts/taint_trace.py |
| CodeQL/Semgrep/Joern engine orchestration + merge | T1190 | CWE-20 | references/taint-engines-static-analysis.md | scripts/sast_runner.py, scripts/joern_taint.sc |
| SQL injection (raw/ORM/identifier/2nd-order/NoSQL) | T1190 | CWE-89 | references/injection-source-patterns.md | scripts/taint_trace.py |
| OS command / argument injection | T1059 | CWE-78 / CWE-88 | references/injection-source-patterns.md | scripts/taint_trace.py |
| Server-side template injection | T1190 | CWE-1336 | references/injection-source-patterns.md | scripts/taint_trace.py |
| Path traversal | T1083 | CWE-22 | references/injection-source-patterns.md | scripts/taint_trace.py |
| SSRF (tainted server-side URL) | T1190 | CWE-918 | references/injection-source-patterns.md | scripts/taint_trace.py |
| Integer overflow -> heap/stack overflow | T1203 | CWE-190 / CWE-787 | references/memory-safety-c-cpp.md | scripts/joern_taint.sc |
| Use-after-free / double-free | T1203 | CWE-416 / CWE-415 | references/memory-safety-c-cpp.md | scripts/joern_taint.sc |
| Unbounded copy / NULL deref | T1203 | CWE-120 / CWE-476 | references/memory-safety-c-cpp.md | scripts/joern_taint.sc |
| Insecure deserialization + gadget preconditions | T1059 | CWE-502 | references/deserialization-prototype-pollution.md | scripts/deser_gadget_scan.py |
| Prototype pollution -> gadget -> RCE | T1059.007 | CWE-1321 | references/deserialization-prototype-pollution.md | scripts/deser_gadget_scan.py |
| Hardcoded secrets / high-entropy literals | T1552.001 | CWE-798 / CWE-321 | references/secrets-crypto-authz-concurrency.md | scripts/secret_crypto_audit.py |
| Weak / misused cryptography | T1600 | CWE-327 / CWE-328 / CWE-330 / CWE-347 | references/secrets-crypto-authz-concurrency.md | scripts/secret_crypto_audit.py |
| Broken authorization / IDOR / BOLA | T1190 | CWE-639 / CWE-862 | references/secrets-crypto-authz-concurrency.md | scripts/secret_crypto_audit.py |
| TOCTOU / race condition | T1190 | CWE-367 / CWE-362 | references/secrets-crypto-authz-concurrency.md | scripts/secret_crypto_audit.py |
| Known-CVE dependency (SCA) | T1195.001 | CWE-1395 / CWE-1104 | references/supply-chain-dependency-audit.md | scripts/dep_audit.py |
| Malicious package / install worm / typosquat | T1195.002 | CWE-506 / CWE-829 / CWE-1357 | references/supply-chain-dependency-audit.md | scripts/dep_audit.py |
| Variant hunting — one finding -> all siblings, root-cause clustered | T1190 | CWE-20 | references/variant-hunting.md | scripts/variant_hunt.py |
| Path feasibility — branch guards -> tri-state SAT/UNSAT (Z3 optional) | T1190 | CWE-20 | references/taint-engines-static-analysis.md | scripts/path_conditions.py |
| Evidence grounding + FP gate (structured proof, EVD citations) | T1190 | CWE-20 | references/finding-validation-runtime.md | scripts/validate_findings.py, scripts/evidence_kit.py |
| Runtime reachability confirmation (Frida sink-executed) | T1190 | CWE-20 | references/dynamic-instrumentation.md | scripts/merge_runtime_evidence.py |

## Quick Start

```bash
# 0. Intake from recon-osint: languages, frameworks, trust boundaries, entry points.

# 1. Fast triage — rank files by unsanitized source->sink flows (heuristic, multi-lang)
python3 scripts/taint_trace.py trace ./src --lang py,js,php,java --json triage.json
python3 scripts/taint_trace.py config --lang py > seed.semgrep.yml   # seed a real rule

# 2. Deep interprocedural — drive the real engines, then merge into one ranked list
python3 scripts/sast_runner.py semgrep --src ./src --config p/owasp-top-ten --pro --out sg.sarif
python3 scripts/sast_runner.py codeql  --src ./src --lang python \
    --suite codeql/python-queries:codeql-suites/python-security-extended.qls --out cq.sarif
python3 scripts/sast_runner.py joern   --src ./src --script scripts/joern_taint.sc --out joern.json
python3 scripts/sast_runner.py merge   sg.sarif cq.sarif joern.json --out merged.json --top 50

# 3. Class-specific deep passes
python3 scripts/deser_gadget_scan.py  all ./src --json deser.json     # deser sinks + gadget libs
python3 scripts/secret_crypto_audit.py all ./src --json sca.json      # secrets+crypto+authz+TOCTOU
python3 scripts/dep_audit.py          all ./repo --json dep.json      # CVE SCA + worm/typosquat
trufflehog filesystem ./src --only-verified                          # confirm LIVE secrets

# 4. Exploitability gate (per finding): reachable? controllable? real impact? sanitizer real?
#    -> write confirmed issues to templates/exploit/findings/ with
#       severity, CWE, CVSS, taint path, PoC, evidence, ATT&CK ID, remediation.
python3 scripts/evidence_kit.py verify --store evidence.json            # re-hash every artifact
python3 scripts/validate_findings.py --findings findings.json \
    --evidence ./evidence --evidence-store evidence.json --strict       # tier + EVD-citation gate

# 5. After a CONFIRMED finding: hunt every sibling, then prune false-positive paths
python3 scripts/variant_hunt.py ./src --seed-finding findings.json --lang py,js --json variants.json
python3 scripts/taint_trace.py trace ./src --lang py --json trace.json   # trace carries branch guards
python3 scripts/path_conditions.py --trace trace.json --json feasibility.json  # Z3 prune (tri-state)
python3 scripts/merge_runtime_evidence.py --events events.jsonl --findings findings.json --out merged.json
```

## OPSEC & Detection (summary)

| Technique | Telemetry / IOC | Detection (Sigma/EDR) | OPSEC note |
|-----------|-----------------|------------------------|------------|
| SAST engine runs | `codeql database create`, `semgrep --sarif`, `joern-parse` process trees; large `codeql-db/`/`cpg.bin` | CI process-creation Sigma (informational) | offline & silent; CodeQL `--command` runs target build -> sandbox hostile repos; purge DBs/SARIF on teardown |
| Injection (SQLi/cmdi/SSTI/SSRF) | SQL keywords/`SLEEP`, web svc spawning `sh/curl`, template engine errors, OOB DNS | webserver regex + EDR child-shell Sigma | source review is noiseless; validate with time-based/DNS-OOB, never `--dump` |
| Memory safety (C/C++) | SIGSEGV/SIGABRT, glibc `corrupted`/`double free`, ASan reports | auditd ANOM_ABEND Sigma; EDR RWX/W^X alerts | CPG review silent; fuzz a local copy in a container, purge cores (may hold secrets) |
| Deserialization / proto-pollution | Java `rO0AB`/.NET `AAEAAAD/////` in bodies; JVM->LDAP/RMI; `POST /` w/ `Next-Action` (CVE-2025-55182) | egress Sigma to 389/636/1099/1389; body-marker rules | prove gadget chain exists; `id`/DNS callback not reverse shell; proto-pollution is global -> revert |
| Secrets / crypto / authz / TOCTOU | `AKIA*`/`ghp_*` patterns; `alg:none`; sequential-id 200s; symlink-race auditd | secret-scanning push protection; symlink/PATH auditd | secret *verification* makes a logged provider API call -> only in scope; read one record for IDOR/TOCTOU evidence |
| Supply chain (SCA / worm) | install hook spawning shell/net; `bundle.js`/`setup_bun.js`; new public `Shai-Hulud` repo | install-script process-creation Sigma; agentless SBOM lookup | never `npm install` a suspect tree; `--ignore-scripts` in a disposable container; treat a compromised dep as full host compromise |

## Deep Dives

- references/taint-engines-static-analysis.md — taint theory + propagation rules;
  Semgrep (taint mode, Pro interfile, Opengrep), CodeQL modular dataflow API,
  Joern CPG/`reachableBy`; engine orchestration + multi-tool merge; CPG+LLM (2025).
- references/injection-source-patterns.md — source-code shapes of SQLi (incl.
  identifier/ORDER BY/2nd-order/NoSQL), OS command & argument injection, SSTI,
  path traversal, SSRF; per-language safe/vuln pairs; Joern/Semgrep confirmation.
- references/memory-safety-c-cpp.md — integer overflow->overflow, UAF/double-free,
  unbounded copy, NULL deref; the 2025 libxml2 CVE cluster; ASan/UBSan + fuzzing
  confirmation; `unsafe` Rust surface.
- references/deserialization-prototype-pollution.md — CWE-502 sinks + gadget
  preconditions (ysoserial/phpggc/ysoserial.net), JS prototype pollution->RCE;
  React2Shell CVE-2025-55182, Tomcat CVE-2025-24813, lodash CVE-2025-13465, Silent
  Spring.
- references/secrets-crypto-authz-concurrency.md — hardcoded secrets (gitleaks/
  trufflehog/Kingfisher), weak crypto, IDOR/BOLA, TOCTOU/race; LLM-augmented
  secret detection (2025).
- references/supply-chain-dependency-audit.md — OSV/SCA, malicious-package & install
  worm heuristics, typosquats; Shai-Hulud 1.0/2.0/Mini (CVE-2026-45321), the SLSA
  provenance-bypass lesson.
- references/variant-hunting.md — HUNT protocol: one confirmed finding -> tree-wide sibling
  sweep, same-function taint qualification, root-cause clustering (copy-paste/shared-util/
  framework-misuse) to decide one-fix-or-many; backed by `variant_hunt.py`. Pairs with
  `evidence_kit.py` (re-verifiable EVD evidence), `path_conditions.py` (Z3 path-prune, tri-state),
  and `merge_runtime_evidence.py` (Frida runtime sink confirmation).
