# strata19.run_native_security_analysis
URL: /documentation/reference/tools/run_native_security_analysis



{/* GENERATED FILE — do not edit. Sources: src/mcp/facade/tool-projection-registry.ts (availability) + describe() in src/mcp/facade/facade-tools.ts (prose). Regenerate: pnpm exec tsx scripts/docs/site/generate-tool-reference.ts */}

## What it does [#what-it-does]

Run the native taint-based security detectors (SEC-01..09) and compiler-backed semantic detectors (EX-01 swallowed exception, MW-01 unguarded route). Every requested detector reports executed or a typed coverage gap; SEC-07/08/09 stay HOLD until promoted. No failed run is ever reported clean.

## When to use it [#when-to-use-it]

**Use when:** "run security analysis" · "check for taint flows" · "scan for vulnerabilities" · or ANY question about whether untrusted input can reach a dangerous sink — a shell/exec call, a SQL or NoSQL query, HTML/DOM, a filesystem path, an outbound URL or redirect, or dynamically evaluated code

**Also use when:** the user names a vulnerability class in their own words — command injection, SQL injection, XSS, SSRF, open redirect, path traversal, code injection, prototype pollution, unsafe deserialization — including when phrased as "is this safe?" or "can someone …?"; also after changes to data-flow-sensitive code paths

## When not to use it [#when-not-to-use-it]

the question is about a SPECIFIC already-known finding id (use get\_finding\_detail / remediate\_finding), or you are mid-edit on known-incomplete code — finish first

## Availability [#availability]

|           |                                                      |
| --------- | ---------------------------------------------------- |
| Tier      | Expert                                               |
| Lifecycle | Live                                                 |
| Taught by | `strata19-fix-failures`, `strata19-verify-remediate` |
