strata19.run_native_security_analysis
Expert tool
What it does
Run the native taint-based security detectors (SEC-01..09) and compiler-backed semantic detectors (EX-01 swallowed exception, MW-01 unguarded route). Every requested detector reports executed or a typed coverage gap; SEC-07/08/09 stay HOLD until promoted. No failed run is ever reported clean.
When to use it
Use when: "run security analysis" · "check for taint flows" · "scan for vulnerabilities" · or ANY question about whether untrusted input can reach a dangerous sink — a shell/exec call, a SQL or NoSQL query, HTML/DOM, a filesystem path, an outbound URL or redirect, or dynamically evaluated code
Also use when: the user names a vulnerability class in their own words — command injection, SQL injection, XSS, SSRF, open redirect, path traversal, code injection, prototype pollution, unsafe deserialization — including when phrased as "is this safe?" or "can someone …?"; also after changes to data-flow-sensitive code paths
When not to use it
the question is about a SPECIFIC already-known finding id (use get_finding_detail / remediate_finding), or you are mid-edit on known-incomplete code — finish first
Availability
| Tier | Expert |
| Lifecycle | Live |
| Taught by | strata19-fix-failures, strata19-verify-remediate |