From a857f4c5a6f7899772a49c2a264c1bec1fa4f69a Mon Sep 17 00:00:00 2001 From: Parafee41 Date: Wed, 5 Aug 2026 16:15:32 +0800 Subject: [PATCH] docs(taint): document per-language model files (#2809) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit * docs(taint): document per-language model files * docs(taint): link language-specific model tests --------- Co-authored-by: Gergő Magyar --- .../gitnexus/gitnexus-taint-analysis/SKILL.md | 20 ++++++++++++------- .../skills/gitnexus-taint-analysis/SKILL.md | 20 ++++++++++++------- gitnexus/skills/gitnexus-taint-analysis.md | 20 ++++++++++++------- 3 files changed, 39 insertions(+), 21 deletions(-) diff --git a/.claude/skills/gitnexus/gitnexus-taint-analysis/SKILL.md b/.claude/skills/gitnexus/gitnexus-taint-analysis/SKILL.md index 9bffffdac..e4069f9a8 100644 --- a/.claude/skills/gitnexus/gitnexus-taint-analysis/SKILL.md +++ b/.claude/skills/gitnexus/gitnexus-taint-analysis/SKILL.md @@ -148,13 +148,19 @@ finding is NOT proof of safety. ## Adding a source / sink / sanitizer -Edit the language model in `taint/typescript-model.ts` (registered via the -explicit `registerBuiltinTaintModels` seam, keyed by `SupportedLanguages`). The -spec is hashable data (no functions). A sanitizer's `neutralizes` lists the -EXACT sink kinds it defends — never a blanket kill. Add a fixture + assert the -finding (or its absence) in `test/unit/taint/` (real-source harness: -`test/helpers/ts-cfg-harness.ts`); the end-to-end proof is -`test/integration/cfg/`. +Taint models cover four `SupportedLanguages` ids across three files: +TypeScript and JavaScript use `taint/typescript-model.ts`, Python uses +`taint/python-model.ts`, and Java uses `taint/java-model.ts`. Edit the model +for the language you are targeting. The explicit +`registerBuiltinTaintModels` seam in `typescript-model.ts` registers all four; +it is not an import side effect. + +The spec is hashable data (no functions). A sanitizer's `neutralizes` lists +the EXACT sink kinds it defends — never a blanket kill. Add a fixture + assert +the finding (or its absence) in `test/unit/taint/`. TypeScript and JavaScript +use the real-source harness `test/helpers/ts-cfg-harness.ts`; Python and Java +model matches are covered by `python-model-match.test.ts` and +`java-model-match.test.ts`. The end-to-end proof is `test/integration/cfg/`. ## Validation checklist for any `--pdg` change diff --git a/gitnexus-claude-plugin/skills/gitnexus-taint-analysis/SKILL.md b/gitnexus-claude-plugin/skills/gitnexus-taint-analysis/SKILL.md index 9bffffdac..e4069f9a8 100644 --- a/gitnexus-claude-plugin/skills/gitnexus-taint-analysis/SKILL.md +++ b/gitnexus-claude-plugin/skills/gitnexus-taint-analysis/SKILL.md @@ -148,13 +148,19 @@ finding is NOT proof of safety. ## Adding a source / sink / sanitizer -Edit the language model in `taint/typescript-model.ts` (registered via the -explicit `registerBuiltinTaintModels` seam, keyed by `SupportedLanguages`). The -spec is hashable data (no functions). A sanitizer's `neutralizes` lists the -EXACT sink kinds it defends — never a blanket kill. Add a fixture + assert the -finding (or its absence) in `test/unit/taint/` (real-source harness: -`test/helpers/ts-cfg-harness.ts`); the end-to-end proof is -`test/integration/cfg/`. +Taint models cover four `SupportedLanguages` ids across three files: +TypeScript and JavaScript use `taint/typescript-model.ts`, Python uses +`taint/python-model.ts`, and Java uses `taint/java-model.ts`. Edit the model +for the language you are targeting. The explicit +`registerBuiltinTaintModels` seam in `typescript-model.ts` registers all four; +it is not an import side effect. + +The spec is hashable data (no functions). A sanitizer's `neutralizes` lists +the EXACT sink kinds it defends — never a blanket kill. Add a fixture + assert +the finding (or its absence) in `test/unit/taint/`. TypeScript and JavaScript +use the real-source harness `test/helpers/ts-cfg-harness.ts`; Python and Java +model matches are covered by `python-model-match.test.ts` and +`java-model-match.test.ts`. The end-to-end proof is `test/integration/cfg/`. ## Validation checklist for any `--pdg` change diff --git a/gitnexus/skills/gitnexus-taint-analysis.md b/gitnexus/skills/gitnexus-taint-analysis.md index 9bffffdac..e4069f9a8 100644 --- a/gitnexus/skills/gitnexus-taint-analysis.md +++ b/gitnexus/skills/gitnexus-taint-analysis.md @@ -148,13 +148,19 @@ finding is NOT proof of safety. ## Adding a source / sink / sanitizer -Edit the language model in `taint/typescript-model.ts` (registered via the -explicit `registerBuiltinTaintModels` seam, keyed by `SupportedLanguages`). The -spec is hashable data (no functions). A sanitizer's `neutralizes` lists the -EXACT sink kinds it defends — never a blanket kill. Add a fixture + assert the -finding (or its absence) in `test/unit/taint/` (real-source harness: -`test/helpers/ts-cfg-harness.ts`); the end-to-end proof is -`test/integration/cfg/`. +Taint models cover four `SupportedLanguages` ids across three files: +TypeScript and JavaScript use `taint/typescript-model.ts`, Python uses +`taint/python-model.ts`, and Java uses `taint/java-model.ts`. Edit the model +for the language you are targeting. The explicit +`registerBuiltinTaintModels` seam in `typescript-model.ts` registers all four; +it is not an import side effect. + +The spec is hashable data (no functions). A sanitizer's `neutralizes` lists +the EXACT sink kinds it defends — never a blanket kill. Add a fixture + assert +the finding (or its absence) in `test/unit/taint/`. TypeScript and JavaScript +use the real-source harness `test/helpers/ts-cfg-harness.ts`; Python and Java +model matches are covered by `python-model-match.test.ts` and +`java-model-match.test.ts`. The end-to-end proof is `test/integration/cfg/`. ## Validation checklist for any `--pdg` change