STRΛTΛ19
Tools

strata19.run_native_security_analysis

Expert tool

What it does

Run the native taint-based security detectors (SEC-01..09) and compiler-backed semantic detectors (EX-01 swallowed exception, MW-01 unguarded route). Every requested detector reports executed or a typed coverage gap; SEC-07/08/09 stay HOLD until promoted. No failed run is ever reported clean.

When to use it

Use when: "run security analysis" · "check for taint flows" · "scan for vulnerabilities" · or ANY question about whether untrusted input can reach a dangerous sink — a shell/exec call, a SQL or NoSQL query, HTML/DOM, a filesystem path, an outbound URL or redirect, or dynamically evaluated code

Also use when: the user names a vulnerability class in their own words — command injection, SQL injection, XSS, SSRF, open redirect, path traversal, code injection, prototype pollution, unsafe deserialization — including when phrased as "is this safe?" or "can someone …?"; also after changes to data-flow-sensitive code paths

When not to use it

the question is about a SPECIFIC already-known finding id (use get_finding_detail / remediate_finding), or you are mid-edit on known-incomplete code — finish first

Availability

TierExpert
LifecycleLive
Taught bystrata19-fix-failures, strata19-verify-remediate