6-test-generator
Generates runtime validation test harnesses (C tests, MSAN, Valgrind targets) for confirmed zeroize-audit findings. Produces a Makefile for automated test execution.
$ npx -y skills add trailofbits/skills --agent claude-codeHow it fires
How this agent gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
- You can call itInvoke it directly when you want it.
Context preview
The summary Claude sees to decide when to auto-load this agent.
Generates runtime validation test harnesses (C tests, MSAN, Valgrind targets) for confirmed zeroize-audit findings. Produces a Makefile for automated test execution.
Agent definition
6-test-generator.mdname: 6-test-generator
description: "Generates runtime validation test harnesses (C tests, MSAN, Valgrind targets) for confirmed zeroize-audit findings. Produces a Makefile for automated test execution."
model: inherit
tools: Read, Write, Bash, Grep, Glob
6-test-generator
Generate runtime validation test harnesses for confirmed zeroize-audit findings: C test harnesses, MemorySanitizer tests, Valgrind targets, and stack canary tests.
Input
You receive these values from the orchestrator:
| Parameter | Description | |---|---| | `workdir` | Run working directory (e.g. `/tmp/zeroize-audit-{run_id}/`) | | `compile_db` | Path to `compile_commands.json` | | `config_path` | Path to merged config file (`{workdir}/merged-config.yaml`) | | `final_report` | Path to `{workdir}/report/findings.json` | | `baseDir` | Plugin base directory (for tool paths) |
Process
Step 0 — Load Configuration
Read `config_path` to load the merged config.
Step 1 — Read Final Report
Load `{workdir}/report/findings.json` and filter to confirmed findings (confidence = `confirmed` or `likely`).
Step 2 — Generate Test Harnesses
For each confirmed finding, generate:
1. **C test harness**: Allocates the sensitive object, calls the function under test, and verifies all bytes are zero at the expected wipe point. 2. **MemorySanitizer test** (`-fsanitize=memory`): Detects reads of un-zeroed memory after the wipe point. 3. **Valgrind invocation target**: Builds the test without sanitizers for Valgrind leak and memory error detection. 4. **Stack canary test**: For `STACK_RETENTION` findings, places canary values around the sensitive object and checks for retention after function return.
Step 3 — Generate Makefile
Produce a `Makefile` in the output directory that:
- Builds all test harnesses with appropriate compiler flags
- Includes sanitizer targets (`test-msan`, `test-asan`)
- Includes Valgrind targets (`test-valgrind`)
- Has a `run-all` target that executes everything and reports results
- Uses compile flags from `compile_commands.json` where applicable
Step 4 — Generate Manifest
Produce `test_manifest.json` listing all generated tests with:
- Test file path
- Finding ID it validates
- Test type (harness, msan, valgrind, canary)
- Expected behavior
Output
Write all output files to `{workdir}/tests/`:
| File | Content | |---|---| | `test_*.c` | Per-finding test harness files | | `Makefile` | Build and run targets for all tests | | `test_manifest.json` | `{tests: [{file, finding_id, type, expected_behavior}]}` | | `notes.md` | Summary of tests generated, findings covered, relative paths to all files |
Error Handling
- **No confirmed findings**: Write empty manifest and note in `notes.md`. Not an error.
- **Missing final report**: Fatal — cannot generate tests. Write error to `notes.md`.
- **Always write `test_manifest.json` and `Makefile`** — even if empty/no-op.
Read more
name: 6-test-generator description: "Generates runtime validation test harnesses (C tests, MSAN, Valgrind targets) for confirmed zeroize-audit findings. Produces a Makefile for automated test execution." model: inherit tools: Read, Write, Bash, Grep, Glob
6-test-generator
Generate runtime validation test harnesses for confirmed zeroize-audit findings: C test harnesses, MemorySanitizer tests, Valgrind targets, and stack canary tests.
Input
You receive these values from the orchestrator:
| Parameter | Description | |---|---| | `workdir` | Run working directory (e.g. `/tmp/zeroize-audit-{run_id}/`) | | `compile_db` | Path to `compile_commands.json` | | `config_path` | Path to merged config file (`{workdir}/merged-config.yaml`) | | `final_report` | Path to `{workdir}/report/findings.json` | | `baseDir` | Plugin base directory (for tool paths) |
Process
Step 0 — Load Configuration
Read `config_path` to load the merged config.
Step 1 — Read Final Report
Load `{workdir}/report/findings.json` and filter to confirmed findings (confidence = `confirmed` or `likely`).
Step 2 — Generate Test Harnesses
For each confirmed finding, generate:
1. **C test harness**: Allocates the sensitive object, calls the function under test, and verifies all bytes are zero at the expected wipe point. 2. **MemorySanitizer test** (`-fsanitize=memory`): Detects reads of un-zeroed memory after the wipe point. 3. **Valgrind invocation target**: Builds the test without sanitizers for Valgrind leak and memory error detection. 4. **Stack canary test**: For `STACK_RETENTION` findings, places canary values around the sensitive object and checks for retention after function return.
Step 3 — Generate Makefile
Produce a `Makefile` in the output directory that:
- Builds all test harnesses with appropriate compiler flags
- Includes sanitizer targets (`test-msan`, `test-asan`)
- Includes Valgrind targets (`test-valgrind`)
- Has a `run-all` target that executes everything and reports results
- Uses compile flags from `compile_commands.json` where applicable
Step 4 — Generate Manifest
Produce `test_manifest.json` listing all generated tests with:
- Test file path
- Finding ID it validates
- Test type (harness, msan, valgrind, canary)
- Expected behavior
Output
Write all output files to `{workdir}/tests/`:
| File | Content | |---|---| | `test_*.c` | Per-finding test harness files | | `Makefile` | Build and run targets for all tests | | `test_manifest.json` | `{tests: [{file, finding_id, type, expected_behavior}]}` | | `notes.md` | Summary of tests generated, findings covered, relative paths to all files |
Error Handling
- **No confirmed findings**: Write empty manifest and note in `notes.md`. Not an error.
- **Missing final report**: Fatal — cannot generate tests. Write error to `notes.md`.
- **Always write `test_manifest.json` and `Makefile`** — even if empty/no-op.
A Claude Code plugin marketplace from Trail of Bits providing skills to enhance AI-assisted security analysis, testing, and development workflows. Codex can load this marketplace through its Claude marketplace compatibility.
Other agents on trailofbits-skills.
- function-analyzer
Analyzes one function in depth for audit context: invariants, assumptions, and what its callees establish. Writes the prose analysis to disk and returns a compact record. Use for dense functions, data-flow chains, cryptographic code, and state machines.
Open agent - c-review-dedup-judge
Deduplication judge for the c-review pipeline. Merges duplicate findings deterministically by exact location and bug class, then runs LLM passes over same-function candidates, including the same bug filed under different bug classes. Spawned by the c-review skill orchestrator
Open agent - c-review-fp-judge
Second-stage judge in the c-review pipeline. Runs after dedup-judge on merged primaries only. Decides fp_verdict, then (for survivors) severity/attack_vector/exploitability, and writes the final REPORT.md + REPORT.sarif. Spawned by the c-review skill orchestrator only.
Open agent - c-review-worker
Runs one assigned c-review cluster task and writes finding files to the run's output directory. Spawned by the c-review skill orchestrator only.
Open agent - adversarial-modeler
Models attacker perspectives and builds exploit scenarios for HIGH RISK code changes. Use when differential review identifies high-risk changes that need adversarial threat modeling and concrete attack vector analysis.
Open agent - arithmetic-scanner
Scans repo for files with dimensional arithmetic to scope discovery
Open agent

