Setup & Installation
What This Skill Does
Variant analysis skill for finding similar vulnerabilities across a codebase after an initial bug is identified. It guides systematic pattern generalization using ripgrep, Semgrep, and CodeQL, moving from exact matches to broader search patterns while tracking false positive rates. Covers interprocedural analysis, taint tracking, and structured triage of results.
Manual variant hunting typically stops at the original file or uses one-off grep patterns that miss semantically related constructs across languages, while this skill enforces incremental generalization with false positive tracking so you cover the full vulnerability class without drowning in noise.
When to use it
- Searching the entire codebase for null equality bypasses after finding one in an auth handler
- Building a Semgrep rule from a known XSS pattern and iterating until it covers related sinks
- Triaging 30 ripgrep matches from a single root cause into high/medium/low confidence findings
- Expanding a CodeQL query from a Python injection bug to cover Java and Go variants in the same repo
- Running a five-step variant hunt after a CVE patch to find missed instances in forked code paths