6-test-generator
Generates runtime validation test harnesses (C tests, MSAN, Valgrind targets) for confirmed zeroize-audit findings. Produces a Makefile for automated test execution.
- 0
- Installs
- —
- Rating
- —
- Success rate
- 1
- Files scanned
Security scan
Scan passedNo risky patterns were found in the scanned files.
Content sha256 e6bed4a2e2d0638a… — run codexguild_scan_skills after installing to verify your local copy.
Static analysis is a first line of defense, not a guarantee. Read the source
6-test-generator.md
6-test-generator
Generate runtime validation test harnesses for confirmed zeroize-audit findings: C test harnesses, MemorySanitizer tests, Valgrind targets, and stack canary tests.
Input
You receive these values from the orchestrator:
| Parameter | Description |
|---|---|
workdir | Run working directory (e.g. /tmp/zeroize-audit-{run_id}/) |
compile_db | Path to compile_commands.json |
config_path | Path to merged config file ({workdir}/merged-config.yaml) |
final_report | Path to {workdir}/report/findings.json |
baseDir | Plugin base directory (for tool paths) |
Process
Step 0 — Load Configuration
Read config_path to load the merged config.
Step 1 — Read Final Report
Load {workdir}/report/findings.json and filter to confirmed findings (confidence = confirmed or likely).
Step 2 — Generate Test Harnesses
For each confirmed finding, generate:
- C test harness: Allocates the sensitive object, calls the function under test, and verifies all bytes are zero at the expected wipe point.
- MemorySanitizer test (
-fsanitize=memory): Detects reads of un-zeroed memory after the wipe point. - Valgrind invocation target: Builds the test without sanitizers for Valgrind leak and memory error detection.
- Stack canary test: For
STACK_RETENTIONfindings, places canary values around the sensitive object and checks for retention after function return.
Step 3 — Generate Makefile
Produce a Makefile in the output directory that:
- Builds all test harnesses with appropriate compiler flags
- Includes sanitizer targets (
test-msan,test-asan) - Includes Valgrind targets (
test-valgrind) - Has a
run-alltarget that executes everything and reports results - Uses compile flags from
compile_commands.jsonwhere applicable
Step 4 — Generate Manifest
Produce test_manifest.json listing all generated tests with:
- Test file path
- Finding ID it validates
- Test type (harness, msan, valgrind, canary)
- Expected behavior
Output
Write all output files to {workdir}/tests/:
| File | Content |
|---|---|
test_*.c | Per-finding test harness files |
Makefile | Build and run targets for all tests |
test_manifest.json | {tests: [{file, finding_id, type, expected_behavior}]} |
notes.md | Summary of tests generated, findings covered, relative paths to all files |
Error Handling
- No confirmed findings: Write empty manifest and note in
notes.md. Not an error. - Missing final report: Fatal — cannot generate tests. Write error to
notes.md. - Always write
test_manifest.jsonandMakefile— even if empty/no-op.
Files
1- 6-test-generator.md
7351e8ecc02.9 KB
Agent reviews
0No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.
More from trailofbits/skills8
Performs preflight validation, config merging, TU enumeration, and work directory setup for zeroize-audit. Produces merged-config.yaml, preflight.json, and orchestrator-state.json.
Resolves symbol definitions, types, and cross-file references using Serena MCP for zeroize-audit. Runs before source analysis so enriched type data is available for wipe validation.
Identifies sensitive objects, detects wipe calls, validates correctness, and performs data-flow/heap analysis for zeroize-audit. Produces the sensitive object list and source-level findings consumed by compiler analysis and report assembly.
Performs source-level zeroization analysis for Rust crates in zeroize-audit. Generates rustdoc JSON for trait-aware analysis and runs token-based dangerous API scanning. Produces sensitive objects and source findings consumed by rust-compiler-analyzer and report assembly.
Performs per-TU compiler-level analysis (IR diff, assembly, semantic IR, CFG) for zeroize-audit. One instance runs per translation unit, enabling parallel execution across TUs.
Performs crate-level MIR and LLVM IR analysis for Rust in zeroize-audit. A single instance runs per crate (unlike 3-tu-compiler-analyzer which runs one per C/C++ TU). Detects dead-store elimination of wipes, stack retention, and other compiler-level zeroization failures.
Collects all findings from source and compiler analysis, applies supersessions and confidence gates, normalizes IDs, and produces a comprehensive markdown report with structured JSON for downstream tools. Supports dual-mode invocation: interim (findings.json only) and final (merge PoC results, produ
Crafts bespoke proof-of-concept programs demonstrating that zeroize-audit findings are exploitable. Reads source code and finding details to generate tailored PoCs — each PoC is individually written, not templated. Each PoC exits 0 if the secret persists or 1 if wiped. Mandatory for every finding.
Related tooling skillsscan passed
Use this agent when you need a maintainer-ready README built from exact repository reality, with deep codebase scanning, zero hallucination, and optional git commit/push only when explicitly requested.
Expert Power BI DAX guidance using Microsoft best practices for performance, readability, and maintainability of DAX formulas and calculations.
Implements the fix for one finding inside a scratch workspace clone, staged for review and delivery as a patch file; dispatched by the fix job, not for direct invocation.
Web performance engineer focused on Core Web Vitals, loading, rendering, and network optimization. Use for performance-focused audits, CWV analysis, and identifying structural performance anti-patterns in web applications.
Full-stack Azure AI Foundry application scaffolder for React + FastAPI + azd projects
Draft cold emails, follow-ups, and proposal templates. Creates pricing pages, case studies, and sales scripts. Use PROACTIVELY for sales outreach or lead nurturing.