advisory-mining
Mine GitHub Security Advisories and CVE databases for incomplete fixes, finding variant vulnerabilities in patched code or similar patterns in related packages.
Detect code injection vulnerabilities in packages that dynamically generate or evaluate code via new Function(), eval(), vm.run*, or template literal interpolation.
$ npx -y skills add ByamB4/find-cve-agent --skill code-injection-codegen --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/code-injection-codegenContext preview
The summary Claude sees to decide when to auto-load this skill.
Detect code injection vulnerabilities in packages that dynamically generate or evaluate code via new Function(), eval(), vm.run*, or template literal interpolation.
name: code-injection-codegen
description: "Detect code injection vulnerabilities in packages that dynamically generate or evaluate code via new Function(), eval(), vm.run*, or template literal interpolation."
metadata:
filePattern:
- "**/*.js"
- "**/*.ts"
- "**/*.mjs"
bashPattern:
- "semgrep.*codegen"
- "grep.*(eval|Function|vm\\.run)"
priority: 95Audit any package that dynamically generates or evaluates code — schema validators, template engines, expression evaluators, serializers with code generation, JIT compilers, query builders that emit JavaScript.
This is the highest-yield vulnerability class for CVE hunting. ~90% acceptance rate when confirmed.
Code generation packages often interpolate user-controlled values directly into generated code strings. Unlike template injection (where user input goes INTO a template), here user input becomes PART of the generated code itself.
Search for all dynamic code execution:
# JavaScript/TypeScript
grep -rn "new Function\(" .
grep -rn "eval(" .
grep -rn "vm\.run" .
grep -rn "vm\.compileFunction" .
grep -rn "setTimeout(" . | grep -v "setTimeout(function"
grep -rn "setInterval(" . | grep -v "setInterval(function"
grep -rn "new AsyncFunction" .
grep -rn "script\.runIn" .
# Python
grep -rn "eval(" .
grep -rn "exec(" .
grep -rn "compile(" . | grep -v "re.compile"
# Ruby
grep -rn "\.eval\b" .
grep -rn "instance_eval" .
grep -rn "class_eval" .
# PHP
grep -rn "eval(" .
grep -rn "assert(" .
grep -rn "create_function" .
grep -rn "preg_replace.*\/e" .For each sink found:
1. Identify what string is being evaluated 2. Trace backwards — is any part of that string derived from user input? 3. Check for template literals: `` new Function(`return ${userInput}`) `` 4. Check for string concatenation: `new Function("return " + userInput)` 5. Check for variable interpolation in generated code
JSON.stringify does NOT escape `*/`. If generated code wraps values in block comments:
// VULNERABLE PATTERN:
let code = `/* ${JSON.stringify(userValue)} */ actual_code_here`;
// Attacker input: */ malicious_code /*
// Result: /* */ malicious_code /* */ actual_code_hereSearch for this pattern:
grep -rn "\/\*.*JSON\.stringify" .
grep -rn "\/\*.*\$\{" .Common mistakes:
1. Can the attacker control the interpolated value? 2. Does the generated code get executed (not just constructed)? 3. What is the execution context? (Node.js process = RCE, browser = XSS) 4. Is there any sandboxing? (node:vm is NOT security — see sandbox-escape skill)
// Schema validator generating validation function
function createValidator(schema) {
const code = `return function(value) {
if (typeof value !== "${schema.type}") throw new Error("invalid");
}`;
return new Function(code)();
}
// Exploit: schema.type = '"; }); process.mainModule.require("child_process").execSync("id"); //'// Expression evaluator
function evaluate(expr) {
return eval("(" + expr + ")");
}// Serializer generating accessor code
function createGetter(path) {
return new Function("obj", `return obj.${path}`);
}
// Exploit: path = "x; process.mainModule.require('child_process').execSync('id'); //"// Code generator with "safe" comments
function generateModule(config) {
return `
/* Config: ${JSON.stringify(config.name)} */
module.exports = { value: ${JSON.stringify(config.value)} };
`;
}
// Exploit: config.name = "*/ require('child_process').execSync('id'); /*"// Debug source mapping
const code = `${generatedCode}\n//# sourceURL=${filename}`;
new Function(code)();
// Exploit: filename contains newline + malicious codeOpen Source CVE Hunting Harness for Claude Code A Claude Code plugin that systematically finds real CVEs in open source packages through coordinated multi-agent security research.
Repo: ByamB4/find-cve-agent
Mine GitHub Security Advisories and CVE databases for incomplete fixes, finding variant vulnerabilities in patched code or similar patterns in related packages.
Detect authentication and authorization bypass vulnerabilities including missing auth middleware, JWT algorithm confusion, IDOR, and session fixation.
Detect OS command injection via shell execution sinks where user-controlled input reaches system commands without proper sanitization.
Cross-pollination multiplier technique: find a vulnerability in one package, then search for the same pattern across all similar packages to multiply findings.
Detect decompression bomb vulnerabilities where compressed input can expand to exhaust memory, targeting buffer-based decompression without size limits.
Detect XML/SVG/YAML entity expansion (Billion Laughs) vulnerabilities in parsers that allow unbounded entity definitions.