zeroize-audit - Audit zeroization of sensitive data
Audits C/C++ and Rust code for missing or weakened zeroization, including compiler optimization effects, with IR, assembly, and control-flow evidence.
Tags
Updated: 2026-10-08Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Detect missing zeroization
- Compare compiler IR
- Analyze assembly retention
- Track secret copies
- Analyze control-flow paths
- Check heap allocation
- Generate proof-of-concepts
- Generate runtime tests
Inputs
- Repository root
- compile_commands.json path
- Cargo.toml path
- Heuristics configuration
- Optimization levels
- Target languages
- Translation unit limit
- MCP settings
- PoC categories
- PoC output directory
- Analysis feature flags
Outputs
- Structured JSON audit report
- Zeroization findings
- IR and assembly evidence
- Generated proof-of-concept files
- Temporary analysis artifacts
Requirements
- Readable target codebase
- Writable temporary directory
- Valid compile_commands.json or Cargo.toml
- Compilable C/C++ translation units or passing cargo check
- clang
- Required analysis scripts
- uvx for Serena MCP
- uv for Rust analysis
- Rust nightly toolchain
- Cargo build context
