5 Poc Generator
Crafts bespoke proof-of-concept programs demonstrating that zeroize-audit findings are exploitable. Reads source code and finding details to generate tailored PoCs — each PoC is individually written, not templated. Each PoC exits 0 if the secret persists or 1 if wiped. Mandatory for every finding.
- Type
- Subagent
- Repository
- trailofbits/skills
- GitHub stars
- 7.3k
- License
- CC-BY-SA-4.0
- Repo last updated
- Sep 25, 2026
- Source file
- plugins/zeroize-audit/agents/5-poc-generator.md
- Model
- inherit
What 5 Poc Generator is
5 Poc Generator is a subagent published in the trailofbits/skills repository on GitHub, which has about 7.3k stars. The repository describes itself as: “Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows”
A subagent is a specialist assistant that Claude can hand part of a task to. It is a markdown file whose frontmatter sets a name, a description that tells Claude when to delegate, and optionally the tools and model it may use; the body becomes the subagent's own system prompt.
Because a subagent works in its own context, it keeps the main conversation focused: Claude can send a narrow job, such as a review or a specialised analysis, to 5 Poc Generator and get back a compact result.
It is set up to use these tools: Read, Write, Bash, Grep, Glob. Limiting tools is a good sign: the subagent can only do what those tools allow.
How to install 5 Poc Generator
Claude Code
- Download 5-poc-generator.md from the repository.
- Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control.
- Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.
Claude Cowork
- Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent.
- Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.
New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.
Inside the source file
An excerpt from plugins/zeroize-audit/agents/5-poc-generator.md, shared under the repository's CC-BY-SA-4.0 license. Read the full file on GitHub.
Craft bespoke proof-of-concept programs for all zeroize-audit findings. Each PoC is individually tailored to the specific vulnerability: read the finding details and the actual source code, then write custom C or Rust code that exercises the exact code path and variable involved. Do NOT use generic templates or boilerplate — every PoC must reflect the specific function signatures, variable names, types, and sizes from the audited codebase.
Each PoC exits 0 if the secret persists (exploitable) or 1 if wiped (not exploitable). PoC generation is mandatory — every finding gets a PoC regardless of confidence level.
Input
You receive these values from the orchestrator:
Process
Step 0 — Load Configuration and Findings
- Read config_path to load the merged config. Extract PoC-relevant settings:
- secret_fill_byte (default: 0xAA)
- stack_probe_max (default: 4096)
- source_inclusion_threshold (default: 5000 lines)
- Read final_report to load all findings. Filter to findings in poc_categories.
Step 1 — Write Shared PoC Infrastructure
Write {poc_output_dir}/poc_common.h with these helpers:
- POC_PASS() macro — prints "EXPLOITABLE: secret persists" and exits 0
- POC_FAIL() macro — prints "NOT EXPLOITABLE: secret wiped" and exits 1
- volatile_read_nonzero(ptr, len) — reads len bytes through a volatile pointer, returns 1 if any byte is non-zero
- volatile_read_pattern(ptr, len, pattern) — reads len bytes through a volatile pointer, returns 1 if ≥ len/4 bytes match pattern
- stack_probe(frame_size) — noinline/noclone function that reads frame_size bytes of uninitialized stack locals, checks for SECRET_FILL_BYTE pattern
- heap_residue_check(alloc_size) — malloc/fill/free/re-malloc/check cycle to detect heap residue
Set SECRET_FILL_BYTE and STACK_PROBE_MAX from config values. Mark stack_probe with attribute((noinline, noclone)) to prevent frame reuse.
Step 2 — Craft Each PoC
For each finding, follow this process:
2a — Read and Understand the Source
- Use Read to examine the function at finding.location.file:finding.location.line. Read at least 50 lines of context around the finding location.
- Identify:
- Function signature: name, parameters, return type
- Sensitive variable: exact name, type, size (from finding.object)
- Wipe presence: does the source contain an approved wipe call for this variable? Where?
- Error paths: for error-path findings, identify what inputs trigger the error return
- Control flow: for path-coverage findings, identify which paths lack the wipe
- Use Grep to find:
- Callers of the target function (to understand valid argument patterns)
- Type definitions for the sensitive object (structs, typedefs)
- Include dependencies needed by the target function
2b — Determine Inclusion Strategy
- If the target function is static or the source file is ≤ source_inclusion_threshold lines: use #include to include the source file directly
- If the target function is extern and the file is large: compile the target source to an object file and link via the Makefile
2c — Write the PoC
Write {poc_output_dir}/poc_za_NNNN_category.c (or .rs for Rust). The PoC must:
- Include poc_common.h for shared helpers
- Set up required context: include necessary headers, define structs/types used by the target function, declare external symbols if linking
- Initialize the sensitive buffer: fill with SECRET_FILL_BYTE using memset() before calling the target function. This establishes the "secret" content that should be wiped.
- Call the target function with valid arguments: use actual types and realistic values. If the function requires allocations, file handles, or other setup, include that setup code. For error-path findings, provide arguments that trigger the specific error path.
Before you install
- Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
- Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
- Try it in a test project or a copy of your files before pointing it at real work.
- Pin the version you tested, and review changes before updating.
- Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.
FAQ
What is 5 Poc Generator?
5 Poc Generator is a subagent for Claude Code and Claude Cowork from the trailofbits/skills repository on GitHub. Crafts bespoke proof-of-concept programs demonstrating that zeroize-audit findings are exploitable. Reads source code and finding details to generate tailored PoCs — each PoC is individually written, not templated. Each PoC exits 0 if the secret persists or 1 if wiped. Mandatory for every finding.
How do I install 5 Poc Generator in Claude Code?
Download 5-poc-generator.md from the repository. Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control. Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.
Can I use 5 Poc Generator in Claude Cowork?
Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent. Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.
Is 5 Poc Generator safe to install?
It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.
Similar resources
- 2 Source Analyzer Identifies sensitive objects, detects wipe calls, validates correctness, and performs data-flow/heap analysis for zeroize-audit. Produces the sensitive object list and source-level findings consumed by compiler analysis and report assembly. Subagent · trailofbits/skills
- 4 Report Assembler Collects all findings from source and compiler analysis, applies supersessions and confidence gates, normalizes IDs, and produces a comprehensive markdown report with structured JSON for downstream tools. Supports dual-mode invocation: interim (findings.json only) and final (merge PoC results, produce final-report.md). Subagent · trailofbits/skills
- 3b Rust Compiler Analyzer Performs crate-level MIR and LLVM IR analysis for Rust in zeroize-audit. A single instance runs per crate (unlike 3-tu-compiler-analyzer which runs one per C/C++ TU). Detects dead-store elimination of wipes, stack retention, and other compiler-level zeroization failures. Subagent · trailofbits/skills
- 5b Poc Validator Compiles and runs all PoCs for zeroize-audit findings. Produces poc_validation_results.json consumed by the verification agent and the orchestrator. Subagent · trailofbits/skills
- 5c Poc Verifier Verifies that each zeroize-audit PoC actually proves the vulnerability it claims to demonstrate. Reads PoC source code, finding details, and original source to check alignment between the PoC and the finding. Produces poc_verification.json consumed by the orchestrator. Subagent · trailofbits/skills
- 6 Test Generator Generates runtime validation test harnesses (C tests, MSAN, Valgrind targets) for confirmed zeroize-audit findings. Produces a Makefile for automated test execution. Subagent · trailofbits/skills
- 3 Tu Compiler Analyzer Performs per-TU compiler-level analysis (IR diff, assembly, semantic IR, CFG) for zeroize-audit. One instance runs per translation unit, enabling parallel execution across TUs. Subagent · trailofbits/skills
- Adversarial Modeler Models attacker perspectives and builds exploit scenarios for HIGH RISK code changes. Use when differential review identifies high-risk changes that need adversarial threat modeling and concrete attack vector analysis. Subagent · trailofbits/skills