SAST with Semgrep (Hypothesis Engine)
"Don't just grep. Trace the data."
1. Taint Mode (The "Proof" Engine)
Use Taint Mode to prove a hypothesis: "User input flows to this sink without sanitization."
rules:
- id: hypothesis-user-input-to-exec
mode: taint
pattern-sources:
- pattern: req.query.$KEY
- pattern: process.argv[...]
pattern-sinks:
- pattern: exec(...)
- pattern: eval(...)
pattern-sanitizers:
- pattern: escapeShell(...)
message: "Hypothesis Confirmed: User input reaches exec() without escaping."
severity: ERROR
2. Abstraction Patterns
When cve-researcher asks "Find all controllers that use this unsafe pattern", use structural matching.
- Hypothesis: "All controllers taking a
redirectparam are vulnerable." - Rule:
patterns: - pattern-inside: | class Controller { ... } - pattern: return redirect($URL) - pattern-not: return redirect("Safe Constant")
3. Workflow Integration
- Hypothesize:
cve-researchersuspects a logic bug type. - Draft Rule: Create a temporary rule file
rules/temp-hypothesis.yml. - Scan:
semgrep scan --config=rules/temp-hypothesis.yml . - Verify: If results > 0, the hypothesis is plausible.
4. Writing Tips
- Metavariables:
$Xmatches anything.$F(...)matches any function call. - Ellipsis:
...matches "any logic in between". - Focus: Don't try to find everything. Write a rule to find one specific logic flaw.