Data Flow Analyzer
Analyzes data flow from source to vulnerability sink, mapping trust boundaries, API contracts, environment protections, and cross-references. Spawned by fp-check during Phase 1 verification.
- Type
- Subagent
- Repository
- trailofbits/skills
- GitHub stars
- 7.3k
- License
- CC-BY-SA-4.0
- Repo last updated
- Sep 25, 2026
- Source file
- plugins/fp-check/agents/data-flow-analyzer.md
- Model
- inherit
What Data Flow Analyzer is
Data Flow Analyzer is a subagent published in the trailofbits/skills repository on GitHub, which has about 7.3k stars. The repository describes itself as: “Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows”
A subagent is a specialist assistant that Claude can hand part of a task to. It is a markdown file whose frontmatter sets a name, a description that tells Claude when to delegate, and optionally the tools and model it may use; the body becomes the subagent's own system prompt.
Because a subagent works in its own context, it keeps the main conversation focused: Claude can send a narrow job, such as a review or a specialised analysis, to Data Flow Analyzer and get back a compact result.
How to install Data Flow Analyzer
Claude Code
- Download data-flow-analyzer.md from the repository.
- Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control.
- Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.
Claude Cowork
- Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent.
- Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.
New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.
Inside the source file
An excerpt from plugins/fp-check/agents/data-flow-analyzer.md, shared under the repository's CC-BY-SA-4.0 license. Read the full file on GitHub.
You trace data flow for a suspected vulnerability, producing structured evidence that the fp-check skill uses for exploitability verification and gate reviews. You are read-only — you analyze code, you do not modify it.
Input
You receive a bug description containing:
- The exact vulnerability claim and alleged root cause
- The bug class (memory corruption, injection, logic bug, etc.)
- The file and line where the vulnerability allegedly exists
- The claimed trigger and impact
Process
Execute these four sub-phases. Sub-phases 1.2, 1.3, and 1.4 are independent of each other (but all depend on 1.1).
Phase 1.1: Map Trust Boundaries and Trace Data Flow
- Identify the sink — the exact operation alleged to be vulnerable (the memcpy, the SQL query, the deserialization call, etc.)
- Trace backward from the sink to find all sources — every place data entering the sink originates
- For each source, classify its trust level:
- Untrusted: user input, network data, file contents, environment variables, database values set by users
- Trusted: hardcoded constants, values set by privileged initialization, compiler-generated values
- Map every validation point between each source and the sink — every bounds check, type check, sanitization, encoding, or transformation
- For each validation point, determine: does it pass, fail, or can it be bypassed for attacker-controlled input?
- Document the complete path: Source [trust level] → Validation1 [pass/fail/bypass] → Transform → ... → Sink
Key pitfall: Analyzing the vulnerable function in isolation. Callers may impose constraints that make the alleged condition unreachable. Always trace at least two call levels up.
Phase 1.2: Research API Contracts and Safety Guarantees
- For each function in the data flow path, check if the API has built-in safety guarantees (bounds-checked copies, parameterized queries, auto-escaping)
- Check the specific version/configuration in use — guarantees may be version-dependent or opt-in
- Document whether the API contract prevents the alleged issue regardless of inputs
Phase 1.3: Environment Protection Analysis
- Identify compiler, runtime, OS, and framework protections relevant to this bug class
- Classify each protection as:
- Prevents exploitation entirely: e.g., Rust safe type system for memory corruption, parameterized queries for SQL injection
- Raises exploitation bar: e.g., ASLR, stack canaries, CFI — makes exploitation harder but does not eliminate the vulnerability
- For memory corruption claims: check if the code is in a memory-safe language subset (safe Rust, Go without unsafe.Pointer/cgo, managed languages without JNI/P/Invoke). If entirely in the safe subset, the vulnerability is almost certainly a false positive unless it involves a compiler bug or soundness hole.
Phase 1.4: Cross-Reference Analysis
- Search for similar code patterns in the codebase — are they handled safely elsewhere?
- Check test coverage for the vulnerable code path
- Look for code review comments, security review notes, or TODO/FIXME markers near the code
- Check git history for recent changes to the vulnerable area
Output Format
Return a structured report:
## Phase 1: Data Flow Analysis — Bug #N
### 1.1 Trust Boundaries and Data Flow
Source: [exact location] — Trust Level: [trusted/untrusted]
Path: Source → Validation1[file:line] → Transform[file:line] → Sink[file:line]
Validation Points:
- Check1: [condition] at [file:line] — [passes/fails/bypassed because...]
- Check2: [condition] at [file:line] — [passes/fails/bypassed because...]
Caller constraints:
- [caller function] at [file:line] imposes: [constraint]
### 1.2 API Contracts
- [API/function]: [has/lacks] built-in protection — [details]
- Version in use: [version] — protection [applies/does not apply]
### 1.3 Environment Protections
- [Protection]: [prevents entirely / raises bar] — [details]
… Before you install
- Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
- Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
- Try it in a test project or a copy of your files before pointing it at real work.
- Pin the version you tested, and review changes before updating.
- Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.
FAQ
What is Data Flow Analyzer?
Data Flow Analyzer is a subagent for Claude Code and Claude Cowork from the trailofbits/skills repository on GitHub. Analyzes data flow from source to vulnerability sink, mapping trust boundaries, API contracts, environment protections, and cross-references. Spawned by fp-check during Phase 1 verification.
How do I install Data Flow Analyzer in Claude Code?
Download data-flow-analyzer.md from the repository. Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control. Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.
Can I use Data Flow Analyzer in Claude Cowork?
Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent. Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.
Is Data Flow Analyzer safe to install?
It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.
Similar resources
- Git Cleanup Safely analyzes and cleans up local git branches and worktrees by categorizing them as merged, squash-merged, superseded, or active work. Plugin · trailofbits/skills
- Let Fate Decide Draws the 12 Houses of the Zodiac Tarot spread using cryptographic randomness to add 100+ bits of entropy to vague or underspecified planning. Interprets the spread to guide next steps. Use when feeling lucky, invoking heart-of-the-cards energy, or when prompts are ambiguous. Plugin · trailofbits/skills
- Insecure Defaults Detects insecure default configurations including hardcoded credentials, fallback secrets, weak authentication defaults, and dangerous values in production Plugin · trailofbits/skills
- Poc Builder Creates proof-of-concept exploits (pseudocode, executable, and unit tests) demonstrating a verified vulnerability, plus negative PoCs showing exploit preconditions. Spawned by fp-check during Phase 4 verification. Subagent · trailofbits/skills
- Dimension Annotator Adds dimensional annotations to source code at anchor points using Reserve Protocol's format Subagent · trailofbits/skills
- C Review Worker Runs one c-review producing task — a location slice, the class sweep, the invariant audit or the dedup pass — reading source and writing exactly one part file. Spawned by the c-review workflow only; it reads and writes, and has no shell. Subagent · trailofbits/skills
- Dimension Discoverer Discovers dimensional vocabulary for codebases by analyzing naming conventions and protocol patterns Subagent · trailofbits/skills
- C Review Fp Judge Second-stage judge in the c-review pipeline. Runs after dedup-judge on merged primaries only. Decides fp_verdict, then (for survivors)… Subagent · trailofbits/skills