Skip to content
KitploitKITPLOIT
OutilsExploitsBlog
Log in
Soumettre
OutilsExploitsBlog
Soumettre

Outils de Hacking, PenTest et Cybersécurité pour votre Arsenal de Sécurité !

Kitploit est un répertoire d'outils de hacking, de cybersécurité et de pentesting. Découvrez les dernières mises à jour des projets pour trouver des vulnérabilités, analyser des systèmes, automatiser les tests et renforcer votre sécurité.

FluxContactConfidentialité© 2026 Kitploit

Répertoire d'outils

Catégories

Voir toutes les catégories
Loading categories
qlcoder — Agentic Framework for Synthesizing CodeQL Queries | Kitploit
Outils/GitHubGitHub/neuralprogram/qlcoder
Static AnalysisVulnerability ScannersVulnerability AnalysisCode AnalysisPapers & ResearchAI-Assisted Reversing
GitHubneuralprogram/qlcoder

qlcoder

Agentic Framework for Synthesizing CodeQL Queries

Voir le dépôt
287103il y a 1 moisVérifié par Kitploit

Populaires

Voir tout →

Découvrez les outils les plus utilisés par notre communauté.

Explorer tous les outils

Parcourez notre collection d'outils

Voir tous les outils →
Partager
Contenu non disponible dans la langue demandée. Affichage de la version anglaise.

QLCoder

Agentic Framework for Synthesizing CodeQL Queries

Table of Contents

  • Overview
  • Installation
    • Docker (Recommended)
    • Native (Linux)
  • Usage
  • Quick Start
  • Development Tooling
  • Examples
  • Paper Environment
  • Contributions
  • Team
  • Citation
  • Affiliated Projects

Overview

QLCoder Iterative Refinement

QLCoder is a framework for using LLMs to synthesize end-to-end CodeQL queries for vulnerability detection. Given an existing CVE's metadata, LLM, and coding agent, QLCoder iteratively synthesizes a CodeQL query to detect the existing CVE. The starting query is a CodeQL path query template populated by an extracted AST of the diff. While synthesizing the query, the coding agent has access to tools to interface with a RAG database and the CodeQL language server. Afterwards, the query can be used for multivariant analysis, regression testing, or guidance for writing CodeQL queries.

Installation

Docker (Recommended)

Step 1: Install CodeQL

Note - In the paper, CodeQL version 2.22.2 was used. However, any version (and language) can be used. QLCoder stores the local CodeQL version's QL packs in the vector database. Paths are configured in .env.

Download an appropriate version of the CodeQL Action bundle from the CodeQL Action releases page.

  • For the latest version: Visit the latest release and download the appropriate bundle for your OS:

    • codeql-bundle-osx64.tar.gz for macOS
    • codeql-bundle-linux64.tar.gz for Linux
  • For a specific version (e.g., 2.22.2): Go to the CodeQL Action releases page, find the release tagged codeql-bundle-v2.22.2, and download the appropriate bundle for your platform.

Extract to ~/codeql (or another path — update CODEQL_HOME in .env accordingly):

tar -xzf codeql-bundle-<platform>.tar.gz -C ~/

Step 2: Install the CodeQL LSP MCP server

Clone the CodeQL LSP MCP server and build it.

git clone https://github.com/neuralprogram/codeql-lsp-mcp ~/codeql-lsp-mcp
cd ~/codeql-lsp-mcp
npm install
npm run build

Step 3: Configure and start services

cp .env.example .env
echo "APP_UID=$(id -u)" >> .env
echo "APP_GID=$(id -g)" >> .env

Fill in your API key and CodeQL paths in .env:

ANTHROPIC_API_KEY=...

# QL pack paths depend on your CodeQL version.
# Find the version numbers with:
#   ls ~/codeql/qlpacks/codeql/java-queries/   → use for SECURITY_QLPACK_PATH
#   ls ~/codeql/qlpacks/codeql/java-all/        → use for LIBRARY_QLPACK_PATH
SECURITY_QLPACK_PATH=~/codeql/qlpacks/codeql/java-queries/<version>/Security/CWE
LIBRARY_QLPACK_PATH=~/codeql/qlpacks/codeql/java-all/<version>/semmle/code/java

Then start the QLCoder app and ChromaDB:

docker compose up -d

Step 4: Retrieve CVE repositories

The CVE must be listed in data/project_info.csv. This clones the repository at the buggy commit and generates the fix diff.

docker compose run --rm app python3 scripts/get_cve_repos.py --cve CVE-2025-27818
# or multiple at once:
docker compose run --rm app python3 scripts/get_cve_repos.py --cves CVE-2025-27818,CVE-2025-0851
# process CVEs from a file (one CVE ID per line)
docker compose run --rm app python3 scripts/get_cve_repos.py --cve-file cves.txt
# process all CVEs
docker compose run --rm app python3 scripts/get_cve_repos.py --all
# force regenerate existing diffs
docker compose run --rm app python3 scripts/get_cve_repos.py --cve CVE-2018-9159 --force

Step 5: Create CodeQL databases

Databases are created with --build-mode=none — no build toolchain required.

# to build a specific CVE's CodeQL databases
docker compose run --rm app python3 scripts/build_codeql_dbs.py --cve-id CVE-2025-27818

This creates cves/CVE-2025-27818/CVE-2025-27818-vul and cves/CVE-2025-27818/CVE-2025-27818-fix.

# to build all of the fetched CVE repos' CodeQL databases
docker compose run --rm app python3 scripts/build_codeql_dbs.py

Step 6: Populate RAG database

Run these scripts to populate the vector database. codeql_docs_fetcher.py and cwe_fetcher.py are one-time setup; cves_fetcher.py should be re-run after adding new CVEs.

docker compose run --rm app python3 scripts/codeql_docs_fetcher.py
docker compose run --rm app python3 scripts/cwe_fetcher.py
docker compose run --rm app python3 scripts/cves_fetcher.py

Native (Linux)

Step 1: Install CodeQL

Note - In the paper, CodeQL version 2.22.2 was used. However, any version (and language) can be used. QLCoder stores the local CodeQL version's QL packs in the vector database. Paths are configured in .env.

Download an appropriate version of the CodeQL Action bundle from the CodeQL Action releases page.

  • For the latest version: Visit the latest release and download the appropriate bundle for your OS:

    • codeql-bundle-linux64.tar.gz for Linux
  • For a specific version (e.g., 2.22.2): Go to the CodeQL Action releases page, find the release tagged codeql-bundle-v2.22.2, and download the appropriate bundle for your platform.

After downloading, extract the archive in the project root directory:

tar -xzf codeql-bundle-<platform>.tar.gz

This should create a sub-directory codeql/ with the executable codeql inside.

Add the path of this executable to your PATH environment variable:

export PATH="$PWD/codeql:$PATH"

Step 2: Install the CodeQL LSP MCP server

Clone the CodeQL LSP MCP server and build it.

git clone https://github.com/neuralprogram/codeql-lsp-mcp
cd codeql-lsp-mcp
npm install
npm run build

Step 3: Setup Conda environment

conda env create -f environment.yml
conda activate qlcoder

Step 4: Configure .env

cp .env.example .env

Fill in your API key and CodeQL paths in .env:

ANTHROPIC_API_KEY=...
CODEQL_HOME=~/codeql
CODEQL_LSP_MCP_HOME=~/codeql-lsp-mcp

# QL pack paths depend on your CodeQL version.
# Find the version numbers with:
#   ls ~/codeql/qlpacks/codeql/java-queries/   → use for SECURITY_QLPACK_PATH
#   ls ~/codeql/qlpacks/codeql/java-all/        → use for LIBRARY_QLPACK_PATH
SECURITY_QLPACK_PATH=~/codeql/qlpacks/codeql/java-queries/<version>/Security/CWE
LIBRARY_QLPACK_PATH=~/codeql/qlpacks/codeql/java-all/<version>/semmle/code/java

Step 5: Retrieve CVE repositories

The CVE must be listed in data/project_info.csv. This clones the repository at the buggy commit and generates the fix diff.

python3 scripts/get_cve_repos.py --cve CVE-2025-27818
# or multiple at once:
python3 scripts/get_cve_repos.py --cves CVE-2025-27818,CVE-2025-0851
# process CVEs from a file (one CVE ID per line)
python3 scripts/get_cve_repos.py --cve-file cves.txt
# process all CVEs
python3 scripts/get_cve_repos.py --all
# force regenerate existing diffs
python3 scripts/get_cve_repos.py --cve CVE-2018-9159 --force

Step 6: Create CodeQL databases

Databases are created with --build-mode=none — no build toolchain required.

# to build a specific CVE's CodeQL databases
python3 scripts/build_codeql_dbs.py --cve-id CVE-2025-27818
Télécharger l’outil