5b Poc Validator
Compiles and runs all PoCs for zeroize-audit findings. Produces poc_validation_results.json consumed by the verification agent and the orchestrator.
- Type
- Subagent
- Repository
- trailofbits/skills
- GitHub stars
- 7.3k
- License
- CC-BY-SA-4.0
- Repo last updated
- Sep 25, 2026
- Source file
- plugins/zeroize-audit/agents/5b-poc-validator.md
- Model
- inherit
What 5b Poc Validator is
5b Poc Validator is a subagent published in the trailofbits/skills repository on GitHub, which has about 7.3k stars. The repository describes itself as: “Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows”
A subagent is a specialist assistant that Claude can hand part of a task to. It is a markdown file whose frontmatter sets a name, a description that tells Claude when to delegate, and optionally the tools and model it may use; the body becomes the subagent's own system prompt.
Because a subagent works in its own context, it keeps the main conversation focused: Claude can send a narrow job, such as a review or a specialised analysis, to 5b Poc Validator and get back a compact result.
It is set up to use these tools: Read, Write, Bash, Grep. Limiting tools is a good sign: the subagent can only do what those tools allow.
How to install 5b Poc Validator
Claude Code
- Download 5b-poc-validator.md from the repository.
- Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control.
- Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.
Claude Cowork
- Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent.
- Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.
New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.
Inside the source file
An excerpt from plugins/zeroize-audit/agents/5b-poc-validator.md, shared under the repository's CC-BY-SA-4.0 license. Read the full file on GitHub.
Compile and run all PoCs listed in the manifest. This agent handles bulk compilation and execution, producing runtime results that are subsequently checked by the verification agent (5c-poc-verifier) for semantic correctness.
Input
You receive these values from the orchestrator:
Process
Step 0 — Load Configuration
Read config_path to access PoC-related settings.
Step 1 — Read Manifest
Read {workdir}/poc/poc_manifest.json. Collect all PoC entries.
If no PoCs exist, write an empty results file and exit.
Step 2 — Compile and Run Each PoC
Dispatch on poc_entry.language:
C/C++ PoCs (language is absent or "c")
- Compile:
cd {workdir}/poc && make <makefile_target>- If compilation succeeds, run and record exit code:
cd {workdir}/poc && ./<makefile_target>
echo "Exit code: $?"- Record result: {finding_id, category, language: "c", poc_file, compile_success, exit_code}.
Rust PoCs (language == "rust")
Rust PoCs use cargo test. The exit code convention maps directly: a passing assert! → test passes → cargo exits 0 → exploitable; a failing assert! (panic) → test fails → cargo exits non-zero → not exploitable.
- Compile check (no run):
<poc_entry.compile_cmd>
# e.g. cargo test --manifest-path {workdir}/poc/Cargo.toml --no-run --test za_0001_missing_source_zeroize- If compilation succeeds, run the specific test and record exit code:
<poc_entry.run_cmd>
# e.g. cargo test --manifest-path {workdir}/poc/Cargo.toml --test za_0001_missing_source_zeroize -- --nocapture
echo "Exit code: $?"- Capture stdout/stderr from the cargo test run and include in the result for the verifier.
- Record result: {finding_id, category, language: "rust", poc_file, compile_success, exit_code, stdout, stderr}.
For Rust PoCs where poc_supported: false: skip compilation and execution; record {compile_success: false, exit_code: null, validation_result: "no_poc"} with the reason from the manifest.
Step 3 — Write Results
Write {workdir}/poc/poc_validation_results.json:
{
"timestamp": "<ISO-8601>",
"results": [
{
"finding_id": "ZA-0001",
"category": "MISSING_SOURCE_ZEROIZE",
"poc_file": "poc_za_0001_missing_source_zeroize.c",
"compile_success": true,
"exit_code": 0,
"validation_result": "exploitable"
}
]
}Validation result mapping (applies to both C/C++ and Rust PoCs):
- compile_success=true, exit_code=0 → "exploitable" (binary exited 0 or cargo test passed)
- compile_success=true, exit_code=1 → "not_exploitable" (C binary exited 1)
- compile_success=true, exit_code≠0 and ≠1 (Rust) → "not_exploitable" (cargo test failed due to assert panic)
- compile_success=false → "compile_failure"
- poc_supported=false → "no_poc"
Output
Write to {workdir}/poc/:
Error Handling
- Manifest missing: Fatal — write error and exit.
- Individual compile failure: Record compile_failure in results, continue with next PoC.
- Individual runtime failure: Record exit code, continue with next PoC.
- Always write poc_validation_results.json — even if empty ({"timestamp": "...", "results": []}).
Before you install
- Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
- Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
- Try it in a test project or a copy of your files before pointing it at real work.
- Pin the version you tested, and review changes before updating.
- Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.
FAQ
What is 5b Poc Validator?
5b Poc Validator is a subagent for Claude Code and Claude Cowork from the trailofbits/skills repository on GitHub. Compiles and runs all PoCs for zeroize-audit findings. Produces poc_validation_results.json consumed by the verification agent and the orchestrator.
How do I install 5b Poc Validator in Claude Code?
Download 5b-poc-validator.md from the repository. Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control. Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.
Can I use 5b Poc Validator in Claude Cowork?
Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent. Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.
Is 5b Poc Validator safe to install?
It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.
Similar resources
- Static Analysis Static analysis toolkit with CodeQL, Semgrep, and SARIF parsing for security vulnerability detection Plugin · trailofbits/skills
- Trailmark Builds source and binary code graphs for security analysis, context slicing, mutation testing, cryptographic protocol modeling, finding triage, and variant analysis. Plugin · trailofbits/skills
- Trailofbits:Ct Check Detects timing side-channels in cryptographic code Slash Command · trailofbits/skills
- Trailofbits:Audit Context Builds deep architectural context before vulnerability hunting Slash Command · trailofbits/skills
- 5c Poc Verifier Verifies that each zeroize-audit PoC actually proves the vulnerability it claims to demonstrate. Reads PoC source code, finding details, and original source to check alignment between the PoC and the finding. Produces poc_verification.json consumed by the orchestrator. Subagent · trailofbits/skills
- 5 Poc Generator Crafts bespoke proof-of-concept programs demonstrating that zeroize-audit findings are exploitable. Reads source code and finding details to generate tailored PoCs — each PoC is individually written, not templated. Each PoC exits 0 if the secret persists or 1 if wiped. Mandatory for every finding. Subagent · trailofbits/skills
- 6 Test Generator Generates runtime validation test harnesses (C tests, MSAN, Valgrind targets) for confirmed zeroize-audit findings. Produces a Makefile for automated test execution. Subagent · trailofbits/skills
- 4 Report Assembler Collects all findings from source and compiler analysis, applies supersessions and confidence gates, normalizes IDs, and produces a comprehensive markdown report with structured JSON for downstream tools. Supports dual-mode invocation: interim (findings.json only) and final (merge PoC results, produce final-report.md). Subagent · trailofbits/skills