A static taint analysis tool that tracks untrusted user input through your program — catching SQL injection, XSS, and command injection without running it.
TaintTrace statically propagates taint labels through your program's AST, merging branches with sound over-approximation and reaching a fixed point over loops.
Any value entering from input, get_param, request.args etc. is marked tainted.
Assignments, binary ops, if/else branches, and while loops — taint flows through all of them. Fixed-point iteration handles loops.
If a tainted value reaches a dangerous operation like sql_exec or eval without being sanitized, a warning is emitted.
Calls to escape, parameterize, or your custom sanitizers remove the taint label — no false alarm.
Choose your platform. OCaml required for .imp files; Python 3.8+ for native .py analysis.
# 1. Install OCaml and Dune (if you don't have them) brew install opam # macOS sudo apt install opam build-essential -y # Ubuntu/Debian opam init -y && eval $(opam env) opam install dune -y # 2. Clone and build git clone https://github.com/yourusername/taint_analysis cd taint_analysis dune build # 3. Run on any .imp file dune exec src/main.exe -- tests/test1_sqli.imp # 4. Or supply a custom policy dune exec src/main.exe -- --policy policies/webapp.json tests/test1_sqli.imp
# Open WSL (Windows Subsystem for Linux) wsl # Install dependencies sudo apt install opam build-essential -y opam init -y && eval $(opam env) && opam install dune -y # Build and run cd ~/taint_analysis dune build dune exec src/main.exe -- tests/test1_sqli.imp
# No installation needed beyond Python 3.8+ python3 --version # must be 3.8 or newer # Run directly on any .py file python3 python_frontend/taint_py.py tests/test_sqli.py # With a custom policy file python3 python_frontend/taint_py.py --policy policies/webapp.json tests/test_sqli.py
Six representative programs — from raw injection to properly sanitized code. Click any card to explore.
Complete reference for every bundled test — what it checks and what output to expect.
Pass any JSON policy file with --policy to override the built-in rules.
Mix and match to fit your tech stack — three bundled policies included.
Functions or constructs that introduce untrusted data into the program.
input, get_param, request.args.get …
Dangerous operations that must never receive tainted data without sanitization.
sql_exec, eval, os.system, innerHTML …
Functions that clean tainted data — calling them removes the taint label.
escape, parameterize, html_escape …
{ "sources": [ "input", "get_param", "post_param", "cookie" ], "sinks": [ "sql_exec", "html_output", "eval" ], "sanitizers": [ "my_custom_escape", "validate_input" ] }
Bundled policies: policies/default.json · policies/webapp.json · policies/cmdinject.json
python_frontend/taint_py.py uses Python's built-in ast module to analyze real .py files — no OCaml needed. It detects SQLi, XSS, and command injection in Flask, Django, and plain Python.