跳到主要内容
知仓学习社ZHICANG

trailmark-variant-neighborhood

Expands one confirmed or suspected vulnerability into a Trailmark graph neighborhood of variant candidates by finding sibling functions, shared call…

不碰外部(只输出文字)无严重或高危命中trailofbits/skills

它会碰到什么

扫了多少5 个文本文件,10 KB
它会碰到什么不碰外部(只输出文字)
命中总数0 处
命中统计严重 0 · 高 0 · 中 0 · 低 0

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

Trailmark Variant Neighborhood

Expand one seed issue into graph-derived variant candidates. This skill

generates review targets, not confirmed findings.

When to Use

  • A finding is confirmed or plausible and variants may exist
  • The vulnerable pattern depends on call context
  • The issue involves a shared sink, source, validator, interface, override,

trait, hook, handler, adapter, or critical type

  • The next step is to seed variant-analysis, semgrep-rule-creator,

static-analysis, or manual review

When NOT to Use

  • No seed issue exists. Use discovery or triage first.
  • The pattern is purely syntactic and already obvious. Use

semgrep-rule-creator directly.

  • The question is exploit-chain composition across multiple findings. Use a

composition workflow.

  • The goal is remediation verification. Use a remediation-review workflow.
  • The seed cannot be bound to a graph node.

Rationalizations to Reject

| Rationalization | Why It Is Wrong | Required Action |

|---|---|---|

| "Nearby code means variant" | Proximity is only a candidate reason | Rank it as a review target |

| "Only exact same names matter" | Variants often share sinks or preconditions, not names | Expand across callers, callees, interfaces, and types |

| "Every candidate is a finding" | This skill outputs candidates for review | Avoid vulnerability claims |

| "Unreachable candidates can be ignored completely" | They may become reachable after refactors | Rank lower or list as deferred |

| "Graph candidates replace semantic pattern work" | Graph structure finds locations, not root-cause semantics | Hand off to variant-analysis, Semgrep, CodeQL, or manual review |

Workflow

Variant Neighborhood Progress:
- [ ] Step 1: Normalize and bind the seed
- [ ] Step 2: Expand graph neighborhoods
- [ ] Step 3: Rank candidates
- [ ] Step 4: Extract variant pattern guidance
- [ ] Step 5: Emit handoff packet

Step 1: Normalize And Bind The Seed

Accept finding text, file/line, function name, or output from

trailmark-finding-triage. Bind the seed to a Trailmark node and record the

root cause in plain language.

If the seed has no concrete graph binding, stop before inventing variants.

Step 2: Expand Neighborhoods

Use the dimensions in

[references/neighborhood-patterns.md](references/neighborhood-patterns.md):

  • shared callers
  • shared callees and sinks
  • entrypoint path neighbors
  • interface, override, trait, and implementation siblings
  • file or module cluster neighbors
  • taint or privilege-boundary peers
  • type and state-reference neighbors

Bound expansion to avoid candidate floods.

Step 3: Rank Candidates

Rank with [references/ranking.md](references/ranking.md). Prioritize

entrypoint-reachable, tainted, boundary-adjacent, high-blast-radius, shared

sink, same-interface, and close-distance candidates. Penalize test, mock,

generated, vendor, unreachable, and trusted-internal-only candidates.

Step 4: Extract Pattern Guidance

Summarize what should be searched for syntactically and what requires semantic

review. Identify whether follow-up belongs in:

  • variant-analysis
  • semgrep-rule-creator
  • static-analysis with CodeQL or SARIF-producing tools
  • manual review

Step 5: Emit Handoff Packet

Use [references/output-format.md](references/output-format.md). Include

ranked candidates, inclusion reasons, exclusions, limitations, and the

variant-analysis handoff.

Stop Conditions

  • No graph binding exists
  • Candidate count is too high and the root cause is underspecified
  • Trailmark cannot analyze the target language
  • The seed is only in test, generated, or vendor code and the user did not say

that code is in scope

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。