mirror of
https://github.com/trailofbits/skills
synced 2026-06-21 14:12:00 +00:00
870955f1af
* init c review * lsp * agents -> prompts * wip * add windows, update judges * improve * upgrade * size update * rm toon format, improve workflow, cluster agents/prompts by issue type, improve prompt cache * improve general workflow, fix bugs * sarif via script, cluster manifest * fix bugs * fix workflow2 * workflow updates * more fixes * more fixes * improvements * update readme * update codeowners * update codeowners2 * fix small inconsistencies * Address review feedback on c-review plugin Critical: - Move SKILL.md into named skill subdirectory (plugins/c-review/skills/c-review/) so plugin discovery and the Codex validator find it; add .codex/skills/c-review symlink. - Convert allowed-tools in SKILL.md from YAML list to space-delimited string (spec compliance per #139). - Fix parse_scalar in generate_sarif.py to respect quoted strings when splitting inline lists; ["a,b", c] no longer corrupts to ['"a', 'b"', 'c']. - Fix location_parts trailing-colon handling so 'src/foo.c:' resolves to ('src/foo.c', 1) instead of keeping the colon in the filename. Important: - Convert agent tools: from YAML list to comma-separated string in worker, dedup-judge, fp-judge. - Refactor build_run_plan.py main() (131 → 77 lines) by extracting _validate_run_inputs / _render_workers / _print_summary helpers. - Fix ty possibly-missing-attribute warning by typing workers list explicitly. - Add PEP 723 inline metadata + plugins/c-review/scripts/pyproject.toml. - Rewrite SKILL.md description as scenario-based; add When to Use / When NOT to Use section headers. - Add Usage section to README. - Resolve Tier 2 contradiction in dedup-judge: unparseable/multi findings now skip Tier 2 and go straight to Tier 3. - Standardize placeholder convention in fp-judge ({var} not <var>). - Fix "Widthness Overflows" → "Width Truncation" in integer-overflow-finder. - Standardize "Bug Patterns to Find" heading in signal-handler and thread-safety finders. - Replace ls -1 glob in worker shard-write with find for shell portability. - Bump version 1.1.0 → 1.1.1 in plugin.json + marketplace.json. Verification: codex validator passes (73 plugin skills); ruff + ty clean; main() 77 lines (limit 100); SARIF generator runtime tests pass; end-to-end build_run_plan.py produces all 11 clusters with cache primer. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * Address claude[bot] review feedback on c-review - Phase 1 is_posix/is_windows probes in SKILL.md now include C++ extensions (.cpp, .cxx, .cc, .hpp, .hh) in their --include lists. A pure C++ POSIX daemon was silently dropping ~17 POSIX-gated passes plus all is_windows clusters because pthread.h / windows.h includes only in .cpp/.hpp files failed both --include='*.c' --include='*.h' filters. - generate_sarif.py informationUri points at trailofbits/skills (the actual repo) instead of trailofbits/tob-skills (404). - CODEOWNERS: add @dguido co-owner to /plugins/c-review/ and move it to the top of the c* alphabetical group (- < l < o < u under ASCII collation). - README.md: move c-review row after burpsuite-project-parser (b < c). - Bump version 1.1.1 → 1.1.2. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Dan Guido <dan@trailofbits.com> Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
1.6 KiB
1.6 KiB
name, description
| name | description |
|---|---|
| createprocess-finder | Identifies CreateProcess security issues |
Finding ID Prefix: CREATEPROC (e.g., CREATEPROC-001, CREATEPROC-002)
Bug Patterns to Find:
-
Unquoted Paths with Spaces
lpApplicationNameis NULL andlpCommandLinehas unquoted path with spacesC:\Program Files\App\run.exetriesC:\Program.exefirst- Subdirectory spaces also vulnerable:
C:\App\Some Dir\run.exe
-
Handle Inheritance Leaks
bInheritHandlesis TRUE when creating lower-privilege process- Sensitive handles (files, tokens, pipes) leak to child
-
Console Sharing
- Missing
DETACHED_PROCESSorCREATE_NEW_CONSOLE - Lower-privilege child shares stdin/stdout/stderr with parent
- Missing
-
Dangerous Flags
CREATE_PRESERVE_CODE_AUTHZ_LEVELbypasses AppLocker/SRPCREATE_BREAKAWAY_FROM_JOBescapes job sandbox
-
Batch File Execution
.cmd/.batwithout full path to cmd.exe- Vulnerable to cmd.exe planting on old systems
Common False Positives to Avoid:
- Quoted paths:
"C:\Program Files\App\run.exe"is safe - lpApplicationName specified: Full path in first parameter
- Same privilege level: Handle inheritance between same-privilege processes
- No sensitive handles: Process has no inheritable sensitive handles
Search Patterns:
CreateProcess[AW]?\s*\(|CreateProcessAsUser[AW]?\s*\(
ShellExecute[AW]?\s*\(|ShellExecuteEx[AW]?\s*\(
SHCreateProcessAsUser[AW]?\s*\(
bInheritHandles|CREATE_BREAKAWAY_FROM_JOB
CREATE_PRESERVE_CODE_AUTHZ_LEVEL|DETACHED_PROCESS