mirror of
https://github.com/trailofbits/skills
synced 2026-06-21 14:12:00 +00:00
870955f1af
* init c review * lsp * agents -> prompts * wip * add windows, update judges * improve * upgrade * size update * rm toon format, improve workflow, cluster agents/prompts by issue type, improve prompt cache * improve general workflow, fix bugs * sarif via script, cluster manifest * fix bugs * fix workflow2 * workflow updates * more fixes * more fixes * improvements * update readme * update codeowners * update codeowners2 * fix small inconsistencies * Address review feedback on c-review plugin Critical: - Move SKILL.md into named skill subdirectory (plugins/c-review/skills/c-review/) so plugin discovery and the Codex validator find it; add .codex/skills/c-review symlink. - Convert allowed-tools in SKILL.md from YAML list to space-delimited string (spec compliance per #139). - Fix parse_scalar in generate_sarif.py to respect quoted strings when splitting inline lists; ["a,b", c] no longer corrupts to ['"a', 'b"', 'c']. - Fix location_parts trailing-colon handling so 'src/foo.c:' resolves to ('src/foo.c', 1) instead of keeping the colon in the filename. Important: - Convert agent tools: from YAML list to comma-separated string in worker, dedup-judge, fp-judge. - Refactor build_run_plan.py main() (131 → 77 lines) by extracting _validate_run_inputs / _render_workers / _print_summary helpers. - Fix ty possibly-missing-attribute warning by typing workers list explicitly. - Add PEP 723 inline metadata + plugins/c-review/scripts/pyproject.toml. - Rewrite SKILL.md description as scenario-based; add When to Use / When NOT to Use section headers. - Add Usage section to README. - Resolve Tier 2 contradiction in dedup-judge: unparseable/multi findings now skip Tier 2 and go straight to Tier 3. - Standardize placeholder convention in fp-judge ({var} not <var>). - Fix "Widthness Overflows" → "Width Truncation" in integer-overflow-finder. - Standardize "Bug Patterns to Find" heading in signal-handler and thread-safety finders. - Replace ls -1 glob in worker shard-write with find for shell portability. - Bump version 1.1.0 → 1.1.1 in plugin.json + marketplace.json. Verification: codex validator passes (73 plugin skills); ruff + ty clean; main() 77 lines (limit 100); SARIF generator runtime tests pass; end-to-end build_run_plan.py produces all 11 clusters with cache primer. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * Address claude[bot] review feedback on c-review - Phase 1 is_posix/is_windows probes in SKILL.md now include C++ extensions (.cpp, .cxx, .cc, .hpp, .hh) in their --include lists. A pure C++ POSIX daemon was silently dropping ~17 POSIX-gated passes plus all is_windows clusters because pthread.h / windows.h includes only in .cpp/.hpp files failed both --include='*.c' --include='*.h' filters. - generate_sarif.py informationUri points at trailofbits/skills (the actual repo) instead of trailofbits/tob-skills (404). - CODEOWNERS: add @dguido co-owner to /plugins/c-review/ and move it to the top of the c* alphabetical group (- < l < o < u under ASCII collation). - README.md: move c-review row after burpsuite-project-parser (b < c). - Bump version 1.1.1 → 1.1.2. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Dan Guido <dan@trailofbits.com> Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
1.4 KiB
1.4 KiB
name, description
| name | description |
|---|---|
| time-issues-finder | Identifies time-related bugs and timing attacks |
Finding ID Prefix: TIME (e.g., TIME-001, TIME-002)
Bug Patterns to Find:
-
Non-Monotonic Clocks
- Using wall clock for duration measurement
- Time going backward breaking logic
- Clock skew between systems
-
Time Zone Issues
- Local vs UTC confusion
- DST transitions breaking logic
- Midnight crossing issues
-
Leap Seconds
- Assuming 86400 seconds per day
- Time comparison across leap second
-
Time Representation
- 32-bit time_t (Y2038)
- Overflow in time calculations
- Loss of precision in conversion
-
Timing Assumptions
- Assuming operation completes in fixed time
- Timeout calculation errors
- Sleep duration assumptions
Common False Positives to Avoid:
- CLOCK_MONOTONIC used: Proper monotonic clock for duration measurement
- UTC throughout: Code consistently uses UTC without local time confusion
- 64-bit time_t: Modern systems with 64-bit time_t don't have Y2038 issue
- Non-security time usage: Logging timestamps, display purposes only
- Explicit tolerance: Code handles clock skew with explicit tolerance
Search Patterns:
time\s*\(|gettimeofday\s*\(|clock_gettime\s*\(
localtime\s*\(|gmtime\s*\(|strftime\s*\(
sleep\s*\(|usleep\s*\(|nanosleep\s*\(
difftime\s*\(|mktime\s*\(
CLOCK_MONOTONIC|CLOCK_REALTIME