1-mcp-resolver
Resolves symbol definitions, types, and cross-file references using Serena MCP for zeroize-audit. Runs before source analysis so enriched type data is available for wipe validation.
- 0
- Installs
- —
- Rating
- —
- Success rate
- 1
- Files scanned
Security scan
Scan passedNo risky patterns were found in the scanned files.
Content sha256 daa9deb0d8346c80… — run codexguild_scan_skills after installing to verify your local copy.
Static analysis is a first line of defense, not a guarantee. Read the source
1-mcp-resolver.md
1-mcp-resolver
Resolve symbol definitions, types, and cross-file references via Serena MCP before source analysis begins.
Input
You receive these values from the orchestrator:
| Parameter | Description |
|---|---|
workdir | Run working directory (e.g. /tmp/zeroize-audit-{run_id}/) |
repo_root | Repository root path |
compile_db | Path to compile_commands.json |
config_path | Path to merged config file ({workdir}/merged-config.yaml) |
input_file | Path to {workdir}/agent-inputs/mcp-resolver.json containing sensitive_candidates |
mcp_timeout_ms | Timeout budget for all MCP queries |
Process
Step 0 — Load Configuration and Inputs
Read config_path to load the merged config (sensitive patterns, approved wipes). Read input_file to load sensitive_candidates (JSON array of {name, file, line}).
Step 1 — Activate Project
Call activate_project with repo_root. This must succeed before any other Serena tool.
Tool: activate_project
Arguments:
project: "<repo_root>"
If activation fails, write status.json with "status": "failed" and stop.
Step 2 — Resolve Symbols
For each candidate in sensitive_candidates:
- Resolve definition and type:
find_symbolwithsymbol_nameandinclude_body: true. Record file, line, kind, type info, array sizes, and struct layout. - Collect use sites:
find_referencing_symbolswithsymbol_name. Record all cross-file references. - Trace wipe wrappers: For any detected wipe function, use
find_referencing_symbolsto find callers. Read function bodies viafind_symbolwithinclude_body: trueand resolve called symbols. - Survey unfamiliar TUs: Use
get_symbols_overviewwhen needed.
Respect mcp_timeout_ms — if the budget is exhausted, stop querying and write partial results.
Step 3 — Build Reference Graph
From the collected results, build:
- A symbol-keyed map of definitions with resolved types
- A cross-file reference graph (caller -> callee relationships)
- Wipe wrapper chains (function A calls B which calls explicit_bzero)
Step 4 — Normalize Evidence
Pipe all raw MCP output through the normalizer:
uv run --no-project {baseDir}/tools/mcp/normalize_mcp_evidence.py \
--input <raw_results> \
--output <workdir>/mcp-evidence/symbols.json
For Serena tool parameters, query patterns, and empty-response troubleshooting, see {baseDir}/references/mcp-analysis.md.
Output
Write all output files to {workdir}/mcp-evidence/:
| File | Content |
|---|---|
status.json | `{"status": "success |
symbols.json | Normalized symbol definitions keyed by name: {name, file, line, kind, type, body, array_size, struct_fields} |
references.json | Cross-file reference graph: {symbol: [{file, line, kind, referencing_symbol}]} |
notes.md | Human-readable observations, unresolved symbols, and relative paths to JSON files |
Error Handling
- Activation failure: Write
status.jsonwith"status": "failed", exit. The orchestrator will setmcp_available=false. - Timeout: Write partial results. Set
status.jsonto"status": "partial"with the count of resolved vs. total candidates. - Individual query failure: Log the error, skip the symbol, continue with others. Record skipped symbols in
status.json.errors. - Always write
status.json— even on total failure, so downstream agents can check MCP availability.
Cross-Reference Convention
This agent does not assign finding IDs. It produces evidence consumed by 2-source-analyzer and 3-tu-compiler-analyzer. Evidence files use relative paths from {workdir} (e.g., mcp-evidence/symbols.json).
Files
1- 1-mcp-resolver.md
52904c58ca4.1 KB
Agent reviews
0No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.
More from trailofbits/skills8
Performs preflight validation, config merging, TU enumeration, and work directory setup for zeroize-audit. Produces merged-config.yaml, preflight.json, and orchestrator-state.json.
Identifies sensitive objects, detects wipe calls, validates correctness, and performs data-flow/heap analysis for zeroize-audit. Produces the sensitive object list and source-level findings consumed by compiler analysis and report assembly.
Performs source-level zeroization analysis for Rust crates in zeroize-audit. Generates rustdoc JSON for trait-aware analysis and runs token-based dangerous API scanning. Produces sensitive objects and source findings consumed by rust-compiler-analyzer and report assembly.
Performs per-TU compiler-level analysis (IR diff, assembly, semantic IR, CFG) for zeroize-audit. One instance runs per translation unit, enabling parallel execution across TUs.
Performs crate-level MIR and LLVM IR analysis for Rust in zeroize-audit. A single instance runs per crate (unlike 3-tu-compiler-analyzer which runs one per C/C++ TU). Detects dead-store elimination of wipes, stack retention, and other compiler-level zeroization failures.
Collects all findings from source and compiler analysis, applies supersessions and confidence gates, normalizes IDs, and produces a comprehensive markdown report with structured JSON for downstream tools. Supports dual-mode invocation: interim (findings.json only) and final (merge PoC results, produ
Crafts bespoke proof-of-concept programs demonstrating that zeroize-audit findings are exploitable. Reads source code and finding details to generate tailored PoCs — each PoC is individually written, not templated. Each PoC exits 0 if the secret persists or 1 if wiped. Mandatory for every finding.
Compiles and runs all PoCs for zeroize-audit findings. Produces poc_validation_results.json consumed by the verification agent and the orchestrator.
Related knowledge skillsscan passed
Produces clean reusable raster assets from approved Impeccable mock references without redesigning the direction.
Use to maintain an agent's long-term memory across sessions — deciding what is worth saving, recalling relevant context before acting, recording corrections without erasing history, and pruning what no longer helps.
|
QA engineer specialized in test strategy, test writing, and coverage analysis. Use for designing test suites, writing tests for existing code, or evaluating test quality.
Specialist for CoreAI DIY presenter mode features, including presentation view, navigation, and teleprompter functionality
Build financial models, backtest trading strategies, and analyze market data. Implements risk metrics, portfolio optimization, and statistical arbitrage. Use PROACTIVELY for quantitative finance, trading algorithms, or risk analysis.