source-review-technique
Installation
SKILL.md
source-review-technique
Goal: Discover zero-day vulnerabilities in source code by combining deterministic structural search with LLM-assisted data flow analysis.
When this technique applies
- A target's source code is available (open source, leaked, or decompiled/decompressed).
- You need to track tainted inputs to sensitive sinks (SAST).
- Pure regex/search is too noisy, but full manual review is too slow.
The Hybrid Workflow
Modern SAST effectively bridges static tools with LLMs. The LLM acts as the triage and data-flow validator, while tools like semgrep or grep map the initial graph.