An LLVM-based instrumentation tool for universal taint tracking, dataflow analysis, and tracing.
-
Updated
Jun 10, 2026 - C++
An LLVM-based instrumentation tool for universal taint tracking, dataflow analysis, and tracing.
libdft for Intel Pin 3.x and 64 bit platform. (Dynamic taint tracking, taint analysis)
Cyclops 是一款具有 XSS 检测功能的浏览器
Defense-in-depth security toolkit for LLM agents — taint tracking, proxy secret guard, policy engine, and red-team benchmarking
a taint tracer based on DynamoRIO, currently ARM only
a dataflow analysis framework implemented in Go, like soot
A suite of experiments for evaluating open-source binary taint trackers.
FLOWMATRIX: GPU-Assisted Information-Flow Analysis through Matrix-Based Representation, USENIX Security'22
WhiteRabbitTracker: Analyzing malware evasions with information flow tracking
A closed-loop security runtime preventing "The Great Exfiltration" and Indirect Prompt Injection in Autonomous AI Agents.
JSFlow is a security-enhanced JavaScript interpreter for fine-grained tracking of information flow.
A prototype of an Interactive Application Security Testing System
Stop uncertain data becoming confident-looking results. plumb-line carries provenance, confidence and mock-taint with values through JavaScript and Python, and its review-time checks and GitHub Action catch uncertainty laundered into a claim in AI-assisted code.
The EyalSec browser for security testing. Browse the web app you are testing and it reports DOM-XSS flows that really happened in the page: the source (URL, postMessage, storage, cookies), the sink, and the attacker-controlled characters. Linux x86_64.
Ricerca's PolyTracker (Forked from https://github.com/trailofbits/polytracker )
Signed provenance labels and taint-tracking policy for LLM agent security. The core library behind AgentMesh.
Blocks AI agent tool calls acting on untrusted data before they cause damage.
The Security Kernel for AI Agents — MCP/A2A gateway with policy enforcement, taint tracking, sandboxed execution, deterministic envelopes, and Sigstore audit. OWASP ASI 2026 compliant.
Dynamic Taint Analysis for Web Storage
The EyalSec Python runtime. Run your existing Python app through it unchanged and it reports or blocks attacker-controlled data reaching SQL queries, shell commands, deserializers, file paths and dynamic imports. Django, Flask, FastAPI. Linux, Python 3.9 to 3.14.
To associate your repository with the taint-tracking topic, visit your repo's landing page and select "manage topics."