Skip to content
SkillsBundleby SANTACONCHA
ES EN

Individual AI skill · AI for Inteligencia e Investigación

zeroize-audit

Detects missing zeroization of sensitive data in source code and identifies zeroization removed by compiler optimizations, with assembly-level analysis, and control-flow verification. Use for auditing C/C++/Rust code handling secrets, keys, passwords, or other sensitive data.

Source content · review pending Source language: EN

Choose how you use AI

Agent format only: this skill needs tools or scripts that web projects cannot execute.

Free ZIP · One canonical method · Usage example · Installation guide · Licence notices

From file to useful result

How to ask with this skill installed

Installing the skill gives your AI a method. Your request still has to provide the case-specific facts, constraints and expected output.

1Name the real task

Describe the decision or deliverable, not just the topic.

2Provide the evidence

Add source material, audience, limits and known facts.

3Define done

Set format, quality criteria and checks.

Adaptable starting prompt Replace the brackets with your case

When to use it

  • Auditing cryptographic implementations (keys, seeds, nonces, secrets)
  • Reviewing authentication systems (passwords, tokens, session data)
  • Analyzing code that handles PII or sensitive credentials
  • Verifying secure cleanup in security-critical codebases
  • Investigating memory safety of sensitive data handling

When not to use it

  • General code review without security focus
  • Performance optimization (unless related to secure wiping)
  • Refactoring tasks not related to sensitive data
  • Code without identifiable secrets or sensitive values

---

What you need first

Before running, verify the following. Each has a defined failure mode.

C/C++ prerequisites:

| Prerequisite | Failure mode if missing | |---|---| | compile_commands.json at compile_db path | Fail fast — do not proceed | | clang on PATH | Fail fast — IR/ASM analysis impossible | | uvx on PATH (for Serena) | If mcp_mode=require: fail. If mcp_mode=prefer: continue without MCP; downgrade affected findings per Confidence Gating rules. | | {baseDir}/tools/extract_compile_flags.py | Fail fast — cannot extract per-TU flags | | {baseDir}/tools/emit_ir.sh | Fail fast — IR analysis impossible | | {baseDir}/tools/emit_asm.sh | Warn and skip assembly findings (STACK_RETENTION, REGISTER_SPILL) | | {baseDir}/tools/mcp/check_mcp.sh | Warn and treat as MCP unavailable | | {baseDir}/tools/mcp/normalize_mcp_evidence.py | Warn and use raw MCP output |

Rust prerequisites:

| Prerequisite | Failure mode if missing | |---|---| | Cargo.toml at cargo_manifest path | Fail fast — do not proceed | | cargo check passes | Fail fast — crate must be buildable | | cargo +nightly on PATH | Fail fast — nightly required for MIR and LLVM IR emission | | uv on PATH | Fail fast — required to run Python analysis scripts | | {baseDir}/tools/validate_rust_toolchain.sh | Warn — run preflight manually. Checks all tools, scripts, nightly, and optionally cargo check. Use --json for machine-readable output, --manifest to also validate the crate builds. | | {baseDir}/tools/emit_rust_mir.sh | Fail fast — MIR analysis impossible (--opt, --crate, --bin/--lib supported; --out can be file or directory) | | {baseDir}/tools/emit_rust_ir.sh | Fail fast — LLVM IR analysis impossible (--opt required; --crate, --bin/--lib supported; --out must be .ll) | | {baseDir}/tools/emit_rust_asm.sh | Warn and skip assembly findings (STACK_RETENTION, REGISTER_SPILL). Supports --opt, --crate, --bin/--lib, --target, --intel-syntax; --out can be .s file or directory. | | {baseDir}/tools/diff_rust_mir.sh | Warn and skip MIR-level optimization comparison. Accepts 2+ MIR files, normalizes, diffs pairwise, and reports first opt level where zeroize/drop-glue patterns disappear. | | {baseDir}/tools/scripts/semantic_audit.py | Warn and skip semantic source analysis | | {baseDir}/tools/scripts/find_dangerous_apis.py | Warn and skip dangerous API scan | | {baseDir}/tools/scripts/check_mir_patterns.py | Warn and skip MIR analysis | | {baseDir}/tools/scripts/check_llvm_patterns.py | Warn and skip LLVM IR analysis | | {baseDir}/tools/scripts/check_rust_asm.py | Warn and skip Rust assembly analysis (STACK_RETENTION, REGISTER_SPILL, drop-glue checks). Dispatches to check_rust_asm_x86.py (production) or check_rust_asm_aarch64.py (EXPERIMENTAL — AArch64 findings require manual verification). | | {baseDir}/tools/scripts/check_rust_asm_x86.py | Required by check_rust_asm.py for x86-64 analysis; warn and skip if missing | | {baseDir}/tools/scripts/check_rust_asm_aarch64.py | Required by check_rust_asm.py for AArch64 analysis (EXPERIMENTAL); warn and skip if missing |

Common prerequisite:

| Prerequisite | Failure mode if missing | |---|---| | {baseDir}/tools/generate_poc.py | Fail fast — PoC generation is mandatory |

---

Choose the right scope

Packs that include this skill

Download only this method or take it together with the rest of its professional area.

This page

Individual skill

The smallest useful download, prepared for a web project or an agent.

Choose format →
Professional pack

AI for Inteligencia e Investigación

This skill plus the other methods selected for this professional area.

Same method, different setup

Where will you use it?

We do not duplicate the skill for every platform. We keep one canonical method and explain the correct installation route.

Traceable by design

Source and licence travel with the file.

SkillsBundle catalogues material of its own and from third parties. Inclusion does not claim original authorship. The individual ZIP preserves the canonical catalogue path and includes the applicable licence notices.

Catalogue path
skills/transversal/knowledge/trailofbits-skills/plugins/zeroize-audit/skills/zeroize-audit
Ficha origin
Extracted from SKILL.md
Read terms and licence policy →

Start with one real task

Install the method. Keep your judgement.

Choose format