The Master AI Taint Path Analysis skill provides developers with the capability to verify if identified whitebox leads represent actual bugs by tracing taint from an untrusted data source to a potentially vulnerable sink. The analysis covers forward and reverse taint, witness paths, and sanitizer evaluation, enabling users to differentiate between real findings and false positives based on live source code verification.
What this skill does
Identifies potential vulnerabilities by examining taint paths from untrusted sources to dangerous sinks such as SQL execution, system calls, file operations, deserialization, template rendering, redirect targets, and memory copy functions.
Performs adjudication to determine whether a taint path constitutes a real, reachable bug within the current source code.
Confirms each hop of the taint path against live source code to substantiate or dismiss identified leads.
Assists developers in documenting the decision-making process to prevent redundant analysis in future assessments.
Who it is for
This skill is designed for developers and teams utilizing AI coding agents such as Claude Code, Cursor, and Codex, specifically those involved in security testing, defensive research, or educational projects.
Use cases
Validating security concerns flagged by source code scanners or hand-spotted vulnerable sinks.
Deciding the validity of potential security vulnerabilities during a code review process.
Providing evidence-based decisions to confirm or refute the presence of vulnerabilities in open source software (OSS), or during capture the flag (CTF) challenges and in-scope engagements.
Technical details
Utilizes capabilities like agent-skills, aiapplication, and adjudicating-taint-paths for effective taint path analysis.
Supports integration with AI coding agents such as Claude Code, Cursor, and Codex, without implying affiliation.
For authorised security testing, defensive research and educational use only.
Source & Licence
This package is built on open-source work published by UnboundCompute (UnboundCompute/security-agent-skills) and distributed under MIT. The original licence text and copyright notice are included in your download.
Personal and commercial use, modification and redistribution are permitted, provided the original copyright and licence notice are retained.
Your purchase covers curation, licence verification, packaging, documentation and instant delivery. It does not grant exclusive rights to the underlying open-source code, which remains available under its original licence.
Delivery & Support
Delivery: instant — a secure download link is emailed to you as soon as payment is confirmed.
Format: ZIP archive containing the skill files, documentation and the original licence.
Updates: updates are included only where stated on this page.
Refunds
This is a digital product delivered immediately after purchase. By completing your order you request immediate delivery and acknowledge that, once the download has been accessed, the statutory right to cancel no longer applies to the extent permitted by law. Refund requests are handled in accordance with our published Refund Policy.
Claude, Codex, Gemini and Cursor are trademarks of their respective owners. MCP Cart is an independent marketplace and is not affiliated with, endorsed by, or sponsored by any of them. Compatibility references describe interoperability only.