Numeric Trust Boundary

Detects untrusted numeric input that flows through a conversion, cast, or parser into a length, size, index, or authorization comparison without bounds-checking the post-conversion value. Use when writing or modifying code that calls atoi/strtol/parseInt/strconv.Atoi on user-supplied or network-supplied input, casts between signed and unsigned integer types, narrows an integer width before a bounds check, or uses an untrusted integer as an allocation size, array index, file offset, length argument to memcpy, or comparison gate for authorization or permission decisions.

thejefflarson Updated

File contents

thejefflarson/soundcheck/tree/main/.claude/skills/numeric-trust-boundary commit e467a5ba6e

Frequently asked questions

npx skillmds@latest add thejefflarson/numeric-trust-boundary