Agent skill

Variant Analysis

by vibeeval in vibeeval/vibecosystem

Find similar vulnerabilities across a codebase after discovering one instance.

MITAuto-check passedSecurity

Install Variant Analysis

skills CLI
$ npx skills add vibeeval/vibecosystem --skill variant-analysis -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vibeeval/vibecosystem variant-analysis --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vibeeval/vibecosystem.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/variant-analysis .claude/skills/variant-analysis && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
variant-analysis
GitHub stars
531
Token cost
~1.5k tokens
SKILL.md length
379 words
Files
1
Skills in repo
144
Repo updated
First seen
Licence
MIT

At a glance

Find similar vulnerabilities across a codebase after discovering one instance.

  • Works in 4 steps: Characterize the Original Bug → Generate Search Queries → Triage Results → …
  • Tasks that involve Static analysis and SAST
  • SKILL.md covers Process, Common Variant Patterns, Automation Integration and Rationalizations to Reject
  • Calls rg

What it does

Variant Analysis is an agent skill from vibeeval/vibecosystem. Find similar vulnerabilities across a codebase after discovering one instance. Uses pattern matching, AST search, Semgrep/CodeQL queries, and manual tracing to propagate findings. Adapted from Trail of Bits. Use after finding a bug to check if the same pattern exists elsewhere.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Static analysis and SAST. It works with Semgrep. The repository describes itself as: AI software team for Claude Code - 138 agents, 295 skills, 73 hooks. Self-learning, multi-agent swarm, autonomous skill evolution. The licence is MIT.

When your agent uses it

  • Tasks that involve Static analysis and SAST

Example prompts

  • “/variant-analysis”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Characterize the Original Bug
  2. Generate Search Queries
  3. Triage Results
  4. Report

What it can do on your machine

Read from SKILL.md and the folder at commit 3b763b1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • rg

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Variant Analysis loads about 1.5k tokens when it runs. Until then it costs about 74 tokens; SKILL.md has 379 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~74
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vibeeval/vibecosystem at commit 3b763b1, republished under its MIT licence (© vibeeval). 379 words, ~1,494 tokens.

Download SKILL.mdSave it as .claude/skills/variant-analysis/SKILL.md (or your agent's skills folder).
name
variant-analysis
description
Find similar vulnerabilities across a codebase after discovering one instance. Uses pattern matching, AST search, Semgrep/CodeQL queries, and manual tracing to propagate findings. Adapted from Trail of Bits. Use after finding a bug to check if the same pattern exists elsewhere.

Variant Analysis

When you find a bug, the same mistake almost certainly exists elsewhere. Variant analysis systematically hunts for siblings of a known vulnerability.

Process

Step 1: Characterize the Original Bug

Before searching, understand what makes this bug a bug:

ORIGINAL BUG:
  File: src/api/users.ts:42
  Type: Missing input validation
  Pattern: req.params.id used directly in DB query without sanitization
  Root cause: Developer assumed framework sanitizes params
  Trigger: Untrusted input reaches database query

Extract the abstract pattern -- not the specific code, but the class of mistake:

  • Missing validation at a trust boundary
  • Incorrect error handling in auth path
  • Race condition between check and use
  • Hardcoded secret in source
  • SQL injection via string concatenation
Step 2: Generate Search Queries

For each bug class, create multiple search strategies:

Grep/Ripgrep (Fast, broad)
bash
# Example: SQL injection via concatenation
rg "query\(.*\+.*\)" --type ts
rg "execute\(.*\$\{" --type ts
rg "\.raw\(.*\+" --type ts

# Example: Missing auth middleware
rg "router\.(get|post|put|delete)\(" --type ts -l | \
  xargs rg -L "authenticate|authorize|requireAuth"

# Example: Hardcoded secrets
rg "(password|secret|key|token)\s*[=:]\s*['\"][^'\"]{8,}" --type ts
Semgrep (AST-aware, precise)
yaml
# Example: SQL injection
rules:
  - id: sql-injection-concatenation
    patterns:
      - pattern: $DB.query($X + ...)
      - pattern-not: $DB.query($X, [...])
    message: "Potential SQL injection via string concatenation"
    severity: ERROR

# Example: Missing null check before use
rules:
  - id: null-deref-after-find
    patterns:
      - pattern: |
          const $X = await $DB.findOne(...)
          ...
          $X.$PROP
      - pattern-not: |
          const $X = await $DB.findOne(...)
          ...
          if ($X) { ... }
    message: "Using findOne result without null check"
    severity: WARNING
CodeQL (Deep analysis)
ql
// Example: Tainted data reaching SQL
import javascript

from CallExpr call, DataFlow::Node source, DataFlow::Node sink
where
  source = DataFlow::parameterNode(any(Function f).getAParameter()) and
  sink = call.getArgument(0) and
  call.getCalleeName() = "query" and
  DataFlow::localFlow(source, sink)
select sink, "Untrusted input flows to SQL query"
Step 3: Triage Results

For each match:

StatusMeaningAction
CONFIRMEDSame bug pattern, exploitableFile as finding
LIKELYSame pattern, needs deeper analysisInvestigate further
MITIGATEDPattern present but other controls prevent exploitationDocument as defense-in-depth gap
FALSE POSITIVEPattern matches but context makes it safeDocument why it's safe
Step 4: Report
## Variant Analysis Report

**Original Finding**: [reference to original bug]
**Pattern**: [abstract description of the vulnerability class]
**Search Method**: [grep/semgrep/codeql/manual]

### Confirmed Variants

1. **[SEVERITY]** file.ts:42 -- [description]
2. **[SEVERITY]** other.ts:88 -- [description]

### Likely Variants (Need Investigation)

3. file2.ts:15 -- [why it might be vulnerable]

### Mitigated Instances

4. safe.ts:30 -- Same pattern but [mitigation] prevents exploitation

### Statistics

- Files scanned: X
- Matches found: Y
- Confirmed: Z
- False positives: W

Common Variant Patterns

Input Validation Variants

If one endpoint lacks validation, check ALL endpoints:

bash
# Find all route handlers
rg "router\.(get|post|put|delete|patch)\(" --type ts -n

# Check each for validation middleware
# Missing validation = variant
Auth/Authz Variants

If one route lacks auth, check all routes:

bash
# Find routes without auth middleware
rg "app\.(get|post)\(['\"]" --type ts | grep -v "auth\|protect\|require"
Error Handling Variants

If one catch block leaks info, check all catch blocks:

bash
rg "catch.*\{" -A 3 --type ts | grep -E "res\.(send|json).*err"
Crypto Variants

If one place uses weak crypto, check all crypto usage:

bash
rg "createHash\(|createCipher\(|randomBytes\(" --type ts
rg "MD5\|SHA1\|DES\|RC4" --type ts
Race Condition Variants

If one TOCTOU exists, check similar check-then-act patterns:

bash
rg "if.*await.*find" -A 5 --type ts | grep -E "await.*(update|delete|create)"

Automation Integration

Show full SKILL.md (161 more words)Show less
With coroner agent (post-mortem)

After fixing a bug, coroner should:

  1. Call variant-analysis with the bug pattern
  2. Check all confirmed variants
  3. Create tasks for each variant fix
With security-reviewer agent

During review, if a finding is discovered:

  1. Pause the linear review
  2. Run variant analysis for the finding class
  3. Include all variants in the review report
With code-reviewer agent

When a fix is reviewed:

  1. Check if the fix addresses all known variants
  2. Verify the fix pattern is applied consistently

Rationalizations to Reject

RationalizationWhy It's WrongRequired Action
"It's just one instance"Bugs travel in packsRun variant analysis
"The other code is different"Same pattern, different syntaxAbstract the pattern
"We already fixed this area"Fix might be incompleteVerify with search
"Semgrep didn't find anything"Rules might be too specificTry multiple search methods
"It's too many results"Volume doesn't mean false positiveTriage each result

Inspired by Trail of Bits variant-analysis plugin.

© vibeeval, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/variant-analysis of vibeeval/vibecosystem.

Open the folder on GitHubat commit 3b763b1

Compare with similar skills

Variant Analysis next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Variant Analysis compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Variant Analysis this skillvibeeval/vibecosystem531—~1.5kAutomated safety check: PassMIT
Semgrepvigolium/piolium1381 repos~2.4kAutomated safety check: NotesMIT
Semgrep Security Scantrailofbits/skills7.4k—~3.7kAutomated safety check: NotesCC-BY-SA-4.0
Sast SemgrepAgentSecOps/SecOpsAgentKit2192 repos~2.4kAutomated safety check: PassCustom licence
Semgrep Rule Creatortrailofbits/skills7.4k6 repos~1.8kAutomated safety check: NotesCC-BY-SA-4.0
Semgrep Rule Variant Creatortrailofbits/skills7.4k5 repos~3.4kAutomated safety check: NotesCC-BY-SA-4.0

Similar skills

  • Semgrep

    vigolium/piolium

    Run Semgrep static analysis scan on a codebase using parallel subagents.

    138 GitHub starsUsed in 1 repo~2.4k tokens
    SecurityAuto-check: notes
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.4k GitHub stars~3.7k tokensUpdated 5 days ago
    SecurityAuto-check: notes
  • Sast Semgrep

    AgentSecOps/SecOpsAgentKit

    Static application security testing (SAST) using Semgrep for vulnerability detection, security code review, and secure coding guidance with OWASP and CWE framework mapping.

    219 GitHub starsUsed in 2 repos~2.4k tokens
    SecurityAuto-check passed
  • Semgrep Rule Creator

    trailofbits/skills

    Official

    Creates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns.

    7.4k GitHub starsUsed in 6 repos~1.8k tokens
    SecurityAuto-check: notes
  • Official

    Creates language variants of existing Semgrep rules. An agent skill from trailofbits/skills.

    7.4k GitHub starsUsed in 5 repos~3.4k tokens
    SecurityAuto-check: notes
  • Semgrep

    waybarrios/opencode-power-pack

    Run Semgrep static analysis across a codebase, optionally using Semgrep Pro for cross-file taint analysis.

    533 GitHub stars~2.4k tokensUpdated yesterday
    SecurityAuto-check passed

More from vibeeval/vibecosystem

All 144 skills in this repo
  • Agent Benchmark

    vibeeval/vibecosystem

    Framework for measuring and tracking agent response quality over time.

    531 GitHub stars~2.9k tokensUpdated 2 mo ago
    Auto-check passed
  • Differential Review

    vibeeval/vibecosystem

    Security-focused differential code review with blast radius analysis, risk-adaptive depth (DEEP/FOCUSED/SURGICAL), git history correlation, and structured finding format.

    531 GitHub stars~1.6k tokensUpdated 2 mo ago
    Auto-check passed
  • Factcheck Guard

    vibeeval/vibecosystem

    A skill your agent uses when making any factual claim about the codebase — existence, absence, or behavior.

    531 GitHub stars~2.2k tokensUpdated 2 mo ago
    Auto-check passed
  • Fp Check

    vibeeval/vibecosystem

    Systematic false positive verification for security findings.

    531 GitHub stars~1.6k tokensUpdated 2 mo ago
    Auto-check passed
  • N8n Workflows

    vibeeval/vibecosystem

    n8n otomasyon workflow'lari. An agent skill from vibeeval/vibecosystem.

    531 GitHub stars~3.3k tokensUpdated 2 mo ago
    Auto-check passed
  • Notepad System

    vibeeval/vibecosystem

    A skill your agent uses when context compression is imminent, when resuming a session, or when preserving critical decisions across long tasks.

    531 GitHub stars~1.7k tokensUpdated 2 mo ago
    Auto-check passed

Works with

Categories

Questions about Variant Analysis

What does Variant Analysis do?

Find similar vulnerabilities across a codebase after discovering one instance. Variant Analysis is an agent skill from vibeeval/vibecosystem. Find similar vulnerabilities across a codebase after discovering one instance.

When should I use Variant Analysis?

Variant Analysis fits situations like: tasks that involve Static analysis and SAST.

How do I install Variant Analysis in Claude Code?

Run `npx skills add vibeeval/vibecosystem --skill variant-analysis -a claude-code`. Or copy the skill folder (skills/variant-analysis in vibeeval/vibecosystem) into .claude/skills/variant-analysis in your project. Claude Code loads it when a task matches its description.

How do I install Variant Analysis in Codex?

Run `npx skills add vibeeval/vibecosystem --skill variant-analysis -a codex`. Or copy the skill folder (skills/variant-analysis in vibeeval/vibecosystem) into .agents/skills/variant-analysis in your project. Codex loads it when a task matches its description.

Can I use Variant Analysis in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vibeeval/vibecosystem --skill variant-analysis -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/variant-analysis, .gemini/skills/variant-analysis, .github/skills/variant-analysis and .opencode/skills/variant-analysis in your project.

What does Variant Analysis need to run?

Going by SKILL.md and its folder, Variant Analysis needs the command-line tools its instructions call (rg).

Does Variant Analysis access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Variant Analysis safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Variant Analysis use?

Variant Analysis is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Variant Analysis use?

About 1.5k tokens (SKILL.md is roughly 6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Variant Analysis?

Skills that share tags, products or a category with Variant Analysis: Semgrep (vigolium/piolium, 138 stars), Semgrep Security Scan (trailofbits/skills, 7.4k stars), Sast Semgrep (AgentSecOps/SecOpsAgentKit, 219 stars) and Semgrep Rule Creator (trailofbits/skills, 7.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Variant Analysis?

vibeeval (a GitHub user) maintains it in vibeeval/vibecosystem, which has 531 GitHub stars. The repository holds 144 skills in this directory. The repository was last updated on August 8, 2026.

Source: vibeeval/vibecosystem on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.