Dangerous sinks by language (grep catalog)
SkillAI & modelsGrep-ready dangerous function/sink catalog per language for fast code review. Load when reviewing source in PHP, Python, JavaScript/Node, Java, Ruby, Go, .NET/C# and you need the exact functions that cause RCE/SQLi/SSRF/traversal/deserialization. Signals: "dangerous functions", "sinks", grepping a codebase.
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the Dangerous sinks by language (grep catalog) skill
What this skill tells your AI
The instructions your AI receives, as published by noorqureshi/sploitagent in skills/code-review/code-review-dangerous-sinks/SKILL.md and read by ahel’s review.
When it applies
You're reading source and want the fastest path to bugs: grep every dangerous sink, then trace each hit's argument back to user input.
Why it works
A small set of functions cause most severe bugs (command/code exec, SQL, deserialization, file access, SSRF). Enumerating them turns review into "find the sink → prove the source".
Sinks to grep (trace the argument to a user source)
- Command exec (RCE, CWE-78): PHP
system exec shell_exec passthru proc_open· Pythonos.system subprocess.*(shell=True) os.popen· Nodechild_process.exec execSync· JavaRuntime.exec ProcessBuilder· Rubysystem exec `backticks` %x()· Goexec.Command. - Code eval (CWE-94):
eval(all), Pythonexec pickle.loads, NodeFunction() vm, PHPeval assert create_function preg_replace/e, Rubyeval send. - SQL (CWE-89): string-built queries / concatenation into
query execute(all ORMs have a raw path — grepraw,.query(,String.formatnear SQL). - Deserialization (CWE-502): Python
pickle yaml.load(!safe) marshal, JavareadObject XMLDecoder, PHPunserialize, RubyMarshal.load YAML.load, .NETBinaryFormatter. - File/path (CWE-22):
open read include require fopen readFile sendFilewith user paths; archive extractors (zip-slip). - SSRF (CWE-918): URL fetchers —
requests.get urllib curl file_get_contents http.get HttpClienttaking a user URL. - Template (SSTI):
render_template_string, Twig/Freemarker string templates. - Secrets:
password= api_key= secret token=literals; private keys.
Method
rg -n "os\.system|subprocess|shell_exec|eval\(|unserialize|pickle\.loads|readObject|render_template_string"
then for each hit trace the argument. Pair with semgrep --config auto for dataflow.
Gotchas
- Parameterized queries / allowlisted args = safe; confirm the source, don't report the grep hit.
yaml.safe_loadand framework-escaped ORMs are the safe variants — note which one is used.
References
OWASP Code Review Guide; GTFOBins (for the exec side); Semgrep registry.
Signals
- GitHub stars
- 20
- Forks
- 7
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
code-review-dangerous-sinks- Source
- github.com/noorqureshi/sploitagent
github.com/noorqureshi/sploitagent
Related picks
Skill · akiojin
The pick for C#tia-csharp-common
Skill · czarnak
The pick for C#golang-code-style
Skill · samber
The pick for Gocc-go-dev
Skill · doccker
The pick for Go110-java-maven-best-practices
Skill · jabrena
The pick for Javajava-api-consistency-validator
Skill · arabelatso
The pick for Java