Agent skill

Discover Attack Surface

by seqra in seqra/opentaint

Classify project-used dependency members and record taint sources as rule-authoring units.

Apache-2.0Auto-check passedSecurity

Install Discover Attack Surface

skills CLI
$ npx skills add seqra/opentaint --skill discover-attack-surface -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install seqra/opentaint discover-attack-surface --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/seqra/opentaint.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/discover-attack-surface .claude/skills/discover-attack-surface && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
discover-attack-surface
GitHub stars
162
Token cost
~1.7k tokens
SKILL.md length
823 words
Files
2 (incl. references)
Skills in repo
16
Repo updated
First seen
Licence
Apache-2.0

At a glance

Classify project-used dependency members and record taint sources as rule-authoring units.

  • Works in 4 steps: Inspect the plan's members → Classify the plan's members → Record verdicts and source units → …
  • The source-discovery depth pass
  • SKILL.md covers Inputs, Workflow, Output and Tracking, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Discover Attack Surface is an agent skill from seqra/opentaint. Classify project-used dependency members and record taint sources as rule-authoring units. Use for the source-discovery depth pass

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/java.md`).

It sits in Security, covering Threat modeling and Static analysis and SAST. The repository describes itself as: The open source taint analysis engine for the AI era. A formal dataflow analysis tool you can customize and self-host, built so AI agents drive your application security analysis… The licence is Apache-2.0.

When your agent uses it

  • The source-discovery depth pass
  • Tasks that involve Threat modeling
  • Tasks that involve Static analysis and SAST

Example prompts

  • “/discover-attack-surface”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Inspect the plan's members
  2. Classify the plan's members
  3. Record verdicts and source units
  4. Verify before returning

What it can do on your machine

Read from SKILL.md and the folder at commit f945f92. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are yaml).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Discover Attack Surface loads about 1.7k tokens when it runs, and up to ~1.9k if it reads all its reference files. Until then it costs about 39 tokens; SKILL.md has 823 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~39
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from seqra/opentaint at commit f945f92, republished under its Apache-2.0 licence (© seqra). 823 words, ~1,676 tokens.

Download SKILL.mdSave it as .claude/skills/discover-attack-surface/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
discover-attack-surface
description
Classify project-used dependency members and record taint sources as rule-authoring units. Use for the source-discovery depth pass
license
Apache-2.0
metadata.author
opentaint
metadata.version
0.3.0

Skill: Discover Attack Surface

Work one assignment of project-used dependency members and pick out the taint sources among them — the methods where untrusted data first enters. The assigned language reference defines the concrete inspection commands and identifier formats for the workflow below.

Inputs

Provided by the caller, fall back to the default value when omitted. Ask back only when a required input is missing and has no sensible default

  • project-root (optional) — root of the target project. Opentaint keeps all analysis artifacts under the fixed <project-root>/.opentaint/ directory, so every .opentaint/... path below resolves there. Default: current directory
  • language (required) — target language for this project and language-specific instructions
  • plan (required) — path to this agent's partition plan .opentaint/tracking/rules/plans/<id>.yaml: the project-used dependency members to classify

Workflow

Read references/<language>.md before starting. Its numbered steps provide the language-specific details for the workflow below.

1. Inspect the plan's members

The assigned plan's scopes contains the already-extracted project-used dependency members that still need a verdict. Inspect only those members. Confirm their dependency identity and exact signatures, then read application source, dependency source and API documentation, representative usages, and relevant framework configuration to understand how data enters the project.

2. Classify the plan's members

A source is the exact boundary where untrusted data first enters from a network, persistence, serialization, messaging, execution, or another external channel. For a callable member, decide whether it returns or otherwise exposes attacker-controlled data. A member that merely passes along data it was handed is a propagator, not a source.

Classify behavior rather than package or class names. For an individual member, prefer recording a borderline source with the uncertainty noted: later scan and triage can reject a false positive, while an omitted source becomes an unrecoverable false negative.

3. Record verdicts and source units

Complete the plan's source list in the form required by the language reference. Record every discovered source in its plan and write its source unit with tag: untrusted-data-source; resolving that unit to an existing or new rule happens later in create-rule. Non-sources create no unit. Mark an empty result explicitly so the reconcile join can distinguish it from a plan whose agent never returned. Where an owned unit already exists, merge new entries without rewriting its existing entries or stages.

4. Verify before returning

Re-check the full assigned scope against the classification. Re-read every rejected member and make sure it does not establish an external-input boundary. Confirm every source appears both in the completed plan and its source unit, no rejected member has a unit, and no pending/null verdict remains.

Output

Short and concise report of what was done

Artifacts:
  • .opentaint/tracking/rules/sources/<unit>.yaml — each source unit required by the completed plan
  • the assigned plan with the discovered sources recorded under source
Summary:
  • the source members found, one line each
  • anything blocked or left uncertain
Show full SKILL.md (360 more words)Show less

Tracking

.opentaint/tracking/rules/sources/<package-kebab>.yaml — one source unit per package (a dependency can span several packages), the file named for that package with . → -. tag is always the reusable untrusted-data-source group. dependencies names the dependency the package comes from, sources each an entry point { method, signature, note, rule_id } (method and signature use the exact language-specific identifiers from the plan), stages tracks the unit through rule authoring, and a blocker string is added under it when the unit can't be made to pass. Keep it clear from comments

yaml
dependencies:
  - <dependency-id>
tag: untrusted-data-source
sources:
  - { method: "<qualified-member>", signature: "<language-signature>", note: untrusted message payload, rule_id: null }
stages:
  test_project: pending
  tests_passing: pending

This skill sets tag: untrusted-data-source, fills dependencies, and adds one { method, signature, note, rule_id } entry per source. Copy method + signature from the plan, explain why the data is untrusted in note, and leave rule_id: null and the stages for rule authoring.

The plan .opentaint/tracking/rules/plans/<id>.yaml — read your members from its scopes map, record the sources you find under a top-level source list; the join then ledgers source + safe (members − source), keyed by the exact method and signature so distinct callable variants stay separate. It is regenerable and disposable, not durable state:

yaml
id: lib-001
scopes:
  <package-kebab>:
    - { method: "<qualified-member-a>", signature: "<language-signature-a>" }
    - { method: "<qualified-member-b>", signature: "<language-signature-b>" }
source:
  - { method: "<qualified-member-a>", signature: "<language-signature-a>" }

source: null is the generated plan's unprocessed sentinel. On completion, replace it with the exact sources found, or source: [] when there are none; mark-safe leaves a null plan for re-dispatch instead of incorrectly classifying all its members as safe. Every member listed as a source must also appear in its source unit.

Constraints

OpenTaint is a whole-program, interprocedural, field-sensitive alias analysis engine. It already propagates through visible application code, calls, aliases, and individual fields; custom rules and approximations model only the assigned source, sink, or opaque-method boundary. Compile-time constants and literals carry no taint, so a source or carrier whose output is only a constant introduces nothing.

  • This stage finds only sources — the boundaries where untrusted data enters, sinks are found later from the taint frontier
  • Work only your own plan and the source units it maps to — never another agent's plan or unit, shared coverage/classification state, or tags.yaml. Plans partition their write ownership according to the language reference
  • Stored / second-order injection (data persisted then read back) is modeled by the engine itself — don't record a source for the read-back or a propagator for the store→read path

© seqra, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/discover-attack-surface of seqra/opentaint.

  • SKILL.md
  • references/java.md

Open the folder on GitHubat commit f945f92

Compare with similar skills

Discover Attack Surface next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Discover Attack Surface compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Discover Attack Surface this skillseqra/opentaint162—~1.7kAutomated safety check: PassApache-2.0
Sast Businesslogicutkusen/sast-skills1.3k—~5.3kAutomated safety check: PassMIT
Trailmark Structuraltrailofbits/skills7.4k—~1.5kAutomated safety check: NotesCC-BY-SA-4.0
Audit Integritygithub/awesome-copilot40k—~1kAutomated safety check: PassMIT
Security Auditseb1n/awesome-ai-agent-skills206—~2.4kAutomated safety check: NotesMIT
CSO Security Auditgarrytan/gstack136k—~4.5kAutomated safety check: PassMIT

Similar skills

  • Sast Businesslogic

    utkusen/sast-skills

    Detect business logic vulnerabilities in a codebase using a three-phase approach: threat modeling (domain analysis and attack scenarios), batched verify (check exploitable gaps in parallel…

    1.3k GitHub stars~5.3k tokensUpdated 6 mo ago
    SecurityAuto-check passed
  • Trailmark Structural

    trailofbits/skills

    Official

    Runs full Trailmark structural analysis by building a graph, running preanalysis(), and reporting hotspots, taint, blast radius, privilege boundaries, attack surface, and version-gated Trailmark…

    7.4k GitHub stars~1.5k tokensUpdated 5 days ago
    SecurityAuto-check: notes
  • Audit Integrity

    github/awesome-copilot

    Official

    Enforce output quality, evidence verification, and quality gates across security audits.

    40k GitHub stars~1k tokensUpdated today
    SecurityAuto-check passed
  • Security Audit

    seb1n/awesome-ai-agent-skills

    Perform a broad, authorized security audit across application, infrastructure, identity, dependencies, and operations.

    206 GitHub stars~2.4k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • CSO Security Audit

    garrytan/gstack

    Runs an evidence-first security audit of a codebase through gstack's trusted launcher, with static findings by default and isolated reproduction when enabled.

    136k GitHub stars~4.5k tokensUpdated yesterday
    SecurityAuto-check passed
  • Trailmark Code Graphs

    trailofbits/skills

    Official

    Builds a code graph of functions, classes and calls across languages, then queries it for call paths, taint, blast radius, entry points and complexity hotspots.

    7.4k GitHub stars~4.3k tokensUpdated 5 days ago
    SecurityAuto-check passed

More from seqra/opentaint

All 16 skills in this repo
  • Analyze an OpenTaint scan's dropped external methods and decide which of them are propagators and optionally sinks.

    162 GitHub stars~3.2k tokensUpdated today
    Auto-check passed
  • Model a method's taint propagation as code-based dataflow approximation and refine it against a test project until the sample passes.

    162 GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Orchestrate Stage

    seqra/opentaint

    Run one stage of the OpenTaint pipeline by coordinating leaf subagents and deterministic joins.

    162 GitHub stars~806 tokensUpdated today
    Auto-check passed
  • Appsec Agent

    seqra/opentaint

    Run an end-to-end OpenTaint application-security analysis while owning the long project build and scans and delegating each other pipeline stage.

    162 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Build Project

    seqra/opentaint

    Build a target project into an opentaint project model. An agent skill from seqra/opentaint.

    162 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Model a method's taint propagation as a passThrough approximation.

    162 GitHub stars~1.7k tokensUpdated today
    Auto-check passed

Categories

Questions about Discover Attack Surface

What does Discover Attack Surface do?

Classify project-used dependency members and record taint sources as rule-authoring units. Discover Attack Surface is an agent skill from seqra/opentaint. Classify project-used dependency members and record taint sources as rule-authoring units.

When should I use Discover Attack Surface?

Discover Attack Surface fits situations like: the source-discovery depth pass; tasks that involve Threat modeling; tasks that involve Static analysis and SAST.

How do I install Discover Attack Surface in Claude Code?

Run `npx skills add seqra/opentaint --skill discover-attack-surface -a claude-code`. Or copy the skill folder (skills/discover-attack-surface in seqra/opentaint) into .claude/skills/discover-attack-surface in your project. Claude Code loads it when a task matches its description.

How do I install Discover Attack Surface in Codex?

Run `npx skills add seqra/opentaint --skill discover-attack-surface -a codex`. Or copy the skill folder (skills/discover-attack-surface in seqra/opentaint) into .agents/skills/discover-attack-surface in your project. Codex loads it when a task matches its description.

Can I use Discover Attack Surface in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add seqra/opentaint --skill discover-attack-surface -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/discover-attack-surface, .gemini/skills/discover-attack-surface, .github/skills/discover-attack-surface and .opencode/skills/discover-attack-surface in your project.

What does Discover Attack Surface need to run?

SKILL.md names no scripts, command-line tools or credentials: Discover Attack Surface is instructions for the agent only.

Does Discover Attack Surface access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Discover Attack Surface safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Discover Attack Surface use?

Discover Attack Surface is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Discover Attack Surface use?

About 1.7k tokens (SKILL.md is roughly 6.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 212 tokens, read only when the agent opens those files.

What are the alternatives to Discover Attack Surface?

Skills that share tags, products or a category with Discover Attack Surface: Sast Businesslogic (utkusen/sast-skills, 1.3k stars), Trailmark Structural (trailofbits/skills, 7.4k stars), Audit Integrity (github/awesome-copilot, 40k stars) and Security Audit (seb1n/awesome-ai-agent-skills, 206 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Discover Attack Surface?

seqra (a GitHub organization) maintains it in seqra/opentaint, which has 162 GitHub stars. The repository holds 16 skills in this directory. The repository was last updated on October 7, 2026.

Source: seqra/opentaint on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.