sast

GitHub

SAST技能用于源码漏洞挖掘,通过分解为映射入口、危险操作、流追踪等阶段,结合静态分析与对抗验证,精准发现并生成PoC。

providers/codex/.agents/skills/sast/SKILL.md H-mmer/pentest-agents

Trigger Scenarios

用户请求进行源代码安全审计或漏洞扫描 需要深入分析特定仓库的安全风险

Install

npx skills add H-mmer/pentest-agents --skill sast -g -y
More Options

Non-standard path

npx skills add https://github.com/H-mmer/pentest-agents/tree/main/providers/codex/.agents/skills/sast -g -y

Use without installing

npx skills use H-mmer/pentest-agents@sast

指定 Agent (Claude Code)

npx skills add H-mmer/pentest-agents --skill sast -a claude-code -g -y

安装 repo 全部 skill

npx skills add H-mmer/pentest-agents --all -g -y

预览 repo 内 skill

npx skills add H-mmer/pentest-agents --list

SKILL.md

Frontmatter
{
    "name": "sast",
    "description": "Source code vulnerability hunting (SAST). Decomposes analysis into specialized passes: map entry points, map dangerous ops, trace flows, find gaps, adversarial validation, exploit. Usage: \/sast <repo_path> [--lang c|cpp|rust|java|python|go|php] [--min-score 4] [--max-files 30] [--skip-static] [--best-of N]"
}

Source code hunt on: $ARGUMENTS

ALL agents dispatched by this command MUST use in the subagent dispatch tool call, EXCEPT sast-flow-tracer and sast-gap-analyzer which MUST use model: "opus" (these require cross-file reasoning that benefits from maximum reasoning depth regardless of what the orchestrator inherits).

Read rules/hunting.md FIRST. Rules 0, 2, 9, 14 apply to SAST. Read skills/sast-methodology/SKILL.md for reference.

Why This Pipeline Exists

A single agent asked to "find vulnerabilities" will hallucinate plausible-looking bugs. This pipeline decomposes the task into focused steps:

  1. Reading code and listing entry points → comprehension task
  2. Listing dangerous operations → pattern matching task
  3. Connecting entry points to dangerous ops → cross-file reasoning (pinned opus)
  4. Finding validation gaps in those connections → focused analysis (pinned opus)
  5. Disproving each candidate → adversarial checking
  6. Building PoC for survivors → targeted coding

The synthesis happens through the PIPELINE, not inside one agent's head.

Phase 0: Setup

  1. Parse args: <repo_path>, --lang (auto-detect), --min-score (default 4), --max-files (default 30), --skip-static (skip CodeQL/Semgrep), --best-of N (run N independent hunters on top files, default 1)
  2. ls <repo_path>/
  3. Auto-detect language:
    find <repo_path> \( -name '*.c' -o -name '*.cpp' -o -name '*.h' -o -name '*.rs' -o -name '*.java' -o -name '*.py' -o -name '*.go' -o -name '*.php' -o -name '*.phtml' -o -name '*.inc' \) | head -20
    
  4. Check build: ls <repo_path>/{Makefile,CMakeLists.txt,Cargo.toml,pom.xml,go.mod,composer.json} 2>/dev/null
  5. Brain: uv run python3 ../../tools/brain.py brief sast-<repo_name>
  6. Create output dirs: mkdir -p findings/sast poc/sast/exploits sast-work/

Phase 1: Build + Static Analysis

1a: Build with sanitizers (best-effort, C/C++/Rust/Go only)

cd <repo_path>
export CC="gcc" CFLAGS="-fsanitize=address,undefined -g -O1 -fno-omit-frame-pointer"
export CXX="g++" CXXFLAGS="$CFLAGS"

If build fails → log and continue. Code review still works.

Skip 1a for PHP/Python/Java — no native sanitizers. For PHP, ensure php --version works and, if composer.json exists, run composer install --no-dev best-effort for autoload/deps.

1b: Static analysis (unless --skip-static)

Run available tools and collect warnings:

# C/C++
cppcheck --enable=all --xml <repo_path> 2> sast-work/cppcheck.xml
# Universal
semgrep --config auto <repo_path> -o sast-work/semgrep.json --json
# PHP (run these when --lang php or .php files detected)
semgrep --config p/php --config p/security-audit <repo_path> -o sast-work/semgrep-php.json --json
psalm --taint-analysis --output-format=json <repo_path> > sast-work/psalm.json 2>/dev/null || true
phpstan analyse --level=max --error-format=json <repo_path> > sast-work/phpstan.json 2>/dev/null || true

Parse into sast-work/static-warnings.json. These feed into Phase 3d as additional candidates.

Phase 2: File Ranking

Dispatch sast-file-ranker agent (model: inherit):

  • Input: repo path, language, build info
  • Output: sast-rankings.json

Phase 3: Decomposed Analysis (per scored file)

For each file scoring >= --min-score, starting from highest:

3a: Entry Point Mapping

Dispatch sast-entry-mapper agent (model: inherit):

  • Output: sast-work/<file_hash>-entries.json

3b: Dangerous Operation Mapping

Dispatch sast-danger-mapper agent (model: inherit):

  • Output: sast-work/<file_hash>-dangers.json

3c: Data Flow Tracing

Dispatch sast-flow-tracer agent (model: opus):

  • Input: entries + dangers + source + headers
  • Output: sast-work/<file_hash>-flows.json

3d: Gap Analysis

Dispatch sast-gap-analyzer agent (model: opus):

  • Input: flows + static-warnings (if relevant)
  • Output: sast-work/<file_hash>-candidates.json

3e: Brain update

uv run python3 ../../tools/brain.py record sast-<repo_name> analyzed "<file>" "entries: N, dangers: N, flows: N, candidates: N"

Phase 4: Adversarial Validation

For each candidate: Dispatch sast-devils-advocate agent (model: inherit):

  • Verdict: SURVIVES / KILLED (with reason)

Phase 5: PoC Confirmation

For each survivor: Dispatch sast-hunter agent (model: inherit) in focused mode:

  • Receives the specific candidate with full context
  • Writes PoC, runs with ASan (C/C++/Rust/Go) OR PHP runtime/HTTP request (PHP) OR interpreter (Python/Java)
  • Verdict: CONFIRMED / REJECTED

Best-of-N (if --best-of > 1)

For score-5 files, run N independent instances. Finding in 2+ runs = real. Finding in 1 run = flag for review.

Phase 6: Exploit Development (confirmed, severity >= medium)

Dispatch sast-exploit-builder agent (model: inherit):

  • Tier 1-5 exploitation ladder
  • Output: poc/sast/exploits/

Phase 7: Document

Record to brain, write to findings/sast/, print summary.

Output

SAST HUNT: <repo_name> (decomposed pipeline)
══════════════════════════════════════════════

Static warnings: N | Files ranked: N (huntable: N)
Entry points: N | Dangerous ops: N | Reachable flows: N | Candidates: N
Devil's advocate: N survived / N killed
ASan confirmed: N | Exploit tiers: ...

CONFIRMED:
1. [CRITICAL] <title> — <file>:<line>
   Flow: <entry> → <gap> → <dangerous op>

HALLUCINATIONS CAUGHT (saved by devil's advocate):
- <candidate> — killed: <reason>

Cost: $X.XX | Agents: N

Cost Awareness

4-6 agents per file, two using Opus. Budget ~$0.50-2.00/file. 30 files ≈ $15-60. Adjust --min-score and --max-files accordingly.

Top-Tier SAST Operator Addendum

Make source review adversarial and evidence-bound.

  1. Rank by exploit reachability, not scary APIs. Entry point plus attacker control plus missing guard plus dangerous sink beats isolated exec, eval, or deserializer references.
  2. For every candidate, require a concrete flow: source, transformations, authorization checks, validation gaps, sink, and trigger conditions.
  3. Read tests and recent security patches. Regression tests often show the intended invariant; patch diffs show the bug shape.
  4. Use static tools as lead generators only. A finding survives when the repo can be built or minimally exercised and the PoC hits the vulnerable path.
  5. Maintain a killed-candidate list with reasons: unreachable, sanitized, auth required, type impossible, dead code, framework guard, version mismatch.
  6. For memory-unsafe code, prefer sanitizer-confirmed crashes with minimized inputs. For web code, prefer request-level PoCs. For supply-chain or CI, prove the workflow trigger and trust boundary.
  7. Stop when marginal files are low-value. Raise --min-score rather than spending Opus on glue code.

Version History

  • 41d49b6 Current 2026-07-24 11:58

Same Skill Collection

.claude/skills/analyze/SKILL.md
.claude/skills/autopilot/SKILL.md
.claude/skills/brain/SKILL.md
.claude/skills/chain/SKILL.md
.claude/skills/correlate/SKILL.md
.claude/skills/dupcheck/SKILL.md
.claude/skills/fullscan/SKILL.md
.claude/skills/hunt/SKILL.md
.claude/skills/learn/SKILL.md
.claude/skills/mindmap/SKILL.md
.claude/skills/monitor/SKILL.md
.claude/skills/new/SKILL.md
.claude/skills/pipeline/SKILL.md
.claude/skills/quality/SKILL.md
.claude/skills/quickscan/SKILL.md
.claude/skills/remember/SKILL.md
.claude/skills/report/SKILL.md
.claude/skills/resume/SKILL.md
.claude/skills/sast/SKILL.md
.claude/skills/status/SKILL.md
.claude/skills/submit/SKILL.md
.claude/skills/surface/SKILL.md
.claude/skills/sync/SKILL.md
.claude/skills/triage/SKILL.md
.claude/skills/validate/SKILL.md
providers/codex/.agents/skills/analyze/SKILL.md
providers/codex/.agents/skills/autopilot/SKILL.md
providers/codex/.agents/skills/brain/SKILL.md
providers/codex/.agents/skills/chain/SKILL.md
providers/codex/.agents/skills/correlate/SKILL.md
providers/codex/.agents/skills/dupcheck/SKILL.md
providers/codex/.agents/skills/fullscan/SKILL.md
providers/codex/.agents/skills/hunt/SKILL.md
providers/codex/.agents/skills/learn/SKILL.md
providers/codex/.agents/skills/mindmap/SKILL.md
providers/codex/.agents/skills/monitor/SKILL.md
providers/codex/.agents/skills/new/SKILL.md
providers/codex/.agents/skills/pipeline/SKILL.md
providers/codex/.agents/skills/quality/SKILL.md
providers/codex/.agents/skills/quickscan/SKILL.md
providers/codex/.agents/skills/remember/SKILL.md
providers/codex/.agents/skills/report/SKILL.md
providers/codex/.agents/skills/resume/SKILL.md
providers/codex/.agents/skills/status/SKILL.md
providers/codex/.agents/skills/submit/SKILL.md
providers/codex/.agents/skills/surface/SKILL.md
providers/codex/.agents/skills/sync/SKILL.md
providers/codex/.agents/skills/triage/SKILL.md
providers/codex/.agents/skills/validate/SKILL.md

Metadata

Files
0
Version
41d49b6
Hash
d1295114
Indexed
2026-07-24 11:58

- 위키
Copyright © 2011-2026 iteam. Current version is 2.155.2. UTC+08:00, 2026-08-06 19:37
浙ICP备14020137号-1 $방문자$