Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

订阅源联系隐私© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
semgrep-rules — 用于静态代码分析、检测安全漏洞以及跨多种语言实施安全编码实践的 Semgrep 规则集合。 | Kitploit
工具/GitHubGitHub/trailofbits/semgrep-rules
静态分析漏洞分析代码分析DevSecOps错误配置
GitHubtrailofbits/semgrep-rules

semgrep-rules

用于静态代码分析、检测安全漏洞以及跨多种语言实施安全编码实践的 Semgrep 规则集合。

查看仓库
531591054个月前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

Trail of Bits 公开 Semgrep 规则

此仓库包含由 Trail of Bits 开发并向公众提供的 Semgrep 规则。它们是我们持续开发工作的一部分,并用于我们的安全审计、漏洞研究和内部项目。随着我们发现新技术,它们将不断演变。

如需 Semgrep 指导,请访问 Testing Handbook。

使用 Semgrep

运行这些规则最简单的方式是从 Semgrep 注册表 运行它们。为此,请导航到项目的根目录并运行以下命令:```shell $ semgrep --config "p/trailofbits"

或者,您可以克隆此仓库,导航到项目的根文件夹,并使用以下命令单独运行规则:```shell
$ semgrep --config /path/to/semgrep-rules/semgreprule.yml

要从克隆的仓库运行所有规则:```shell $ semgrep --config /path/to/semgrep-rules/ .

## 实用标志

Semgrep 将针对所有受支持的代码文件运行,但 `.gitignore` 文件中指定的文件除外。如果你希望对包括 `.gitignore` 中列出的文件和目录在内的所有文件和目录运行规则,请添加 `--no-git-ignore` 标志。```shell
$ semgrep --config /path/to/semgrep-rules/ . --no-git-ignore

你也可以让 Semgrep 忽略匹配任何模式的文件和目录。例如,如果你想告诉 Semgrep 忽略所有 Go 测试文件,可以运行以下命令:```shell $ semgrep --config /path/to/semgrep-rules/ . --exclude='*_test.go'

使用 `-o` 将结果输出到文件:```shell
$ semgrep --config /path/to/semgrep-rules/hanging-goroutine.yml -o leaks.txt'

规则

go

IDPlaygroundImpactConfidence描述
eth-rpc-tracetransaction🛝🔗🟥🌕检测从 EVM 交易或区块中提取跟踪信息的尝试。在交易所或桥接应用中,必须实现额外的逻辑来封装这些端点,以防止回滚调用帧期间转移的值被计入。
eth-txreceipt-status🛝🔗🟥🌕检测读取交易回执状态的情况
hanging-goroutine🛝🔗🟩🌗Goroutine 泄漏
invalid-usage-of-modified-variable🛝🔗🟧🌘发生错误时可能出现非预期的赋值
iterate-over-empty-map🛝🔗🟩🌗可能是在对空 map 进行冗余迭代
missing-runlock-on-rwmutex🛝🔗🟧🌗在函数返回前缺少对 RWMutex 锁的 RUnlock 操作
missing-unlock-before-return🛝🔗🟧🌗在函数返回前缺少 mutex 解锁操作
nil-check-after-call🛝🔗🟧🌗可能的空指针解引用
racy-append-to-slice🛝🔗🟧🌗多个 goroutine 并发调用 append
racy-write-to-map🛝🔗🟧🌗多个 goroutine 并发写入同一个 map
servercodec-readrequestbody-unhandled-nil🛝🔗🟩🌘ServerCodec 接口实现可能不正确
string-to-int-signedness-cast🛝🔗🟧🌘整数下溢
sync-mutex-value-copied🛝🔗🟩🌘通过值接收器复制 sync.Mutex
unmarshal-tag-is-dash🛝🔗🟧🌘
unmarshal-tag-is-omitempty🛝🔗🟩🌘
unsafe-dll-loading🛝🔗🟥🌘使用了易受 DLL 劫持攻击的函数
waitgroup-add-called-inside-goroutine🛝🔗🟧🌗在匿名 goroutine 中调用 sync.WaitGroup.Add
waitgroup-wait-inside-loop🛝🔗🟧🌗在循环中调用 sync.WaitGroup.Wait

python

下载工具