zeroize-audit - Audit sensitive-data zeroization in C/C++/Rust
Audits C, C++, and Rust code for missing or compiler-removed zeroization of sensitive data using source, IR, assembly, and control-flow analysis.
Tags
Updated: 2026-10-08Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Detect missing zeroization
- Compare optimized IR
- Analyze emitted assembly
- Track secret data copies
- Check heap allocator usage
- Verify control-flow coverage
- Generate runtime validation tests
- Generate finding PoCs
- Produce structured JSON reports
Inputs
- Repository root
- compile_commands.json
- Cargo.toml
- Heuristics configuration
- Optimization levels
- Target languages
- Translation-unit limit
- MCP settings
- PoC categories
- PoC output directory
- Analysis feature flags
Outputs
- Structured JSON audit report
- Persistent finding files
- Temporary analysis artifacts
- Generated proof-of-concept files
Requirements
- Valid C/C++ or Rust build context
- Compilable translation units
- Clang for C/C++ analysis
- Cargo nightly toolchain for Rust
- Required analysis scripts
- PoC generation tool
- Python and uv tooling
- Optional Serena MCP access
