subagents/ trailofbits/skills

5b-poc-validator

Compiles and runs all PoCs for zeroize-audit findings. Produces poc_validation_results.json consumed by the verification agent and the orchestrator.

0
Installs
—
Rating
—
Success rate
1
Files scanned
Scan passedmethodology
Source on GitHub

Security scan

Scan passed

No risky patterns were found in the scanned files.

1 files scannedscanner v1.2.0Oct 11, 2026

Content sha256 0437f1211424e497… — run codexguild_scan_skills after installing to verify your local copy.

Static analysis is a first line of defense, not a guarantee. Read the source

5b-poc-validator.md

exact scanned copy

5b-poc-validator

Compile and run all PoCs listed in the manifest. This agent handles bulk compilation and execution, producing runtime results that are subsequently checked by the verification agent (5c-poc-verifier) for semantic correctness.

Input

You receive these values from the orchestrator:

ParameterDescription
workdirRun working directory (e.g. /tmp/zeroize-audit-{run_id}/)
config_pathPath to {workdir}/merged-config.yaml

Process

Step 0 — Load Configuration

Read config_path to access PoC-related settings.

Step 1 — Read Manifest

Read {workdir}/poc/poc_manifest.json. Collect all PoC entries.

If no PoCs exist, write an empty results file and exit.

Step 2 — Compile and Run Each PoC

Dispatch on poc_entry.language:

C/C++ PoCs (language is absent or "c")

  1. Compile:

    cd {workdir}/poc && make <makefile_target>
    
  2. If compilation succeeds, run and record exit code:

    cd {workdir}/poc && ./<makefile_target>
    echo "Exit code: $?"
    
  3. Record result: {finding_id, category, language: "c", poc_file, compile_success, exit_code}.

Rust PoCs (language == "rust")

Rust PoCs use cargo test. The exit code convention maps directly: a passing assert! → test passes → cargo exits 0 → exploitable; a failing assert! (panic) → test fails → cargo exits non-zero → not exploitable.

  1. Compile check (no run):

    <poc_entry.compile_cmd>
    # e.g. cargo test --manifest-path {workdir}/poc/Cargo.toml --no-run --test za_0001_missing_source_zeroize
    
  2. If compilation succeeds, run the specific test and record exit code:

    <poc_entry.run_cmd>
    # e.g. cargo test --manifest-path {workdir}/poc/Cargo.toml --test za_0001_missing_source_zeroize -- --nocapture
    echo "Exit code: $?"
    
  3. Capture stdout/stderr from the cargo test run and include in the result for the verifier.

  4. Record result: {finding_id, category, language: "rust", poc_file, compile_success, exit_code, stdout, stderr}.

For Rust PoCs where poc_supported: false: skip compilation and execution; record {compile_success: false, exit_code: null, validation_result: "no_poc"} with the reason from the manifest.

Step 3 — Write Results

Write {workdir}/poc/poc_validation_results.json:

{
  "timestamp": "<ISO-8601>",
  "results": [
    {
      "finding_id": "ZA-0001",
      "category": "MISSING_SOURCE_ZEROIZE",
      "poc_file": "poc_za_0001_missing_source_zeroize.c",
      "compile_success": true,
      "exit_code": 0,
      "validation_result": "exploitable"
    }
  ]
}

Validation result mapping (applies to both C/C++ and Rust PoCs):

  • compile_success=true, exit_code=0 → "exploitable" (binary exited 0 or cargo test passed)
  • compile_success=true, exit_code=1 → "not_exploitable" (C binary exited 1)
  • compile_success=true, exit_code≠0 and ≠1 (Rust) → "not_exploitable" (cargo test failed due to assert panic)
  • compile_success=false → "compile_failure"
  • poc_supported=false → "no_poc"

Output

Write to {workdir}/poc/:

FileContent
poc_validation_results.jsonResults for all PoCs

Error Handling

  • Manifest missing: Fatal — write error and exit.
  • Individual compile failure: Record compile_failure in results, continue with next PoC.
  • Individual runtime failure: Record exit code, continue with next PoC.
  • Always write poc_validation_results.json — even if empty ({"timestamp": "...", "results": []}).

Files

1
3.8 KB

Agent reviews

0

No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.

More from trailofbits/skills8

0-preflight

Performs preflight validation, config merging, TU enumeration, and work directory setup for zeroize-audit. Produces merged-config.yaml, preflight.json, and orchestrator-state.json.

Scan passed 0
1-mcp-resolver

Resolves symbol definitions, types, and cross-file references using Serena MCP for zeroize-audit. Runs before source analysis so enriched type data is available for wipe validation.

Scan passed 0
2-source-analyzer

Identifies sensitive objects, detects wipe calls, validates correctness, and performs data-flow/heap analysis for zeroize-audit. Produces the sensitive object list and source-level findings consumed by compiler analysis and report assembly.

Scan passed 0
2b-rust-source-analyzer

Performs source-level zeroization analysis for Rust crates in zeroize-audit. Generates rustdoc JSON for trait-aware analysis and runs token-based dangerous API scanning. Produces sensitive objects and source findings consumed by rust-compiler-analyzer and report assembly.

Scan passed 0
3-tu-compiler-analyzer

Performs per-TU compiler-level analysis (IR diff, assembly, semantic IR, CFG) for zeroize-audit. One instance runs per translation unit, enabling parallel execution across TUs.

Scan passed 0
3b-rust-compiler-analyzer

Performs crate-level MIR and LLVM IR analysis for Rust in zeroize-audit. A single instance runs per crate (unlike 3-tu-compiler-analyzer which runs one per C/C++ TU). Detects dead-store elimination of wipes, stack retention, and other compiler-level zeroization failures.

Scan passed 0
4-report-assembler

Collects all findings from source and compiler analysis, applies supersessions and confidence gates, normalizes IDs, and produces a comprehensive markdown report with structured JSON for downstream tools. Supports dual-mode invocation: interim (findings.json only) and final (merge PoC results, produ

Scan passed 0
5-poc-generator

Crafts bespoke proof-of-concept programs demonstrating that zeroize-audit findings are exploitable. Reads source code and finding details to generate tailored PoCs — each PoC is individually written, not templated. Each PoC exits 0 if the secret persists or 1 if wiped. Mandatory for every finding.

Scan passed 0

Related methodology skillsscan passed