JavaSinkTracerSAFE
基于函数级污点分析的 Java 源代码漏洞审计工具JavaSinkTracer,通过 Model Context Protocol (MCP) 为 AI 助手提供安全分析能力。
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
基于函数级污点分析的 Java 源代码漏洞审计工具JavaSinkTracer,通过 Model Context Protocol (MCP) 为 AI 助手提供安全分析能力。
快速开始
1. 安装依赖
pip install -r requirements.txt
2. 配置 Claude Desktop
编辑配置文件并添加 MCP 服务器配置:
macOS: ~/Library/Application Support/Claude/claude_desktop_config.json Windows: %APPDATA%/Claude/claude_desktop_config.json
{
"mcpServers": {
"javasinktracer": {
"command": "python",
"args": [
"/path/to/JavaSinkTracer/mcp_server.py"
],
"description": "Java源代码漏洞审计工具 - 基于函数级污点分析"
}
}
}注意:将 /path/to/JavaSinkTracer 替换为实际的项目路径。
3. 重启 Claude Desktop
配置完成后重启 Claude Desktop,MCP 工具将自动加载。
视频演示
https://www.bilibili.com/video/BV1XrxDz1EvF
核心功能
漏洞扫描
从危险函数(Sink)反向追踪到外部入口(Source),自动发现潜在的安全漏洞链路。
调用图分析
构建完整的 Java 项目函数调用关系图,支持跨文件、跨类的调用追踪。
智能分析
基于函数级污点分析,有效规避变量级追踪在复杂场景(线程、反射、回调)下的断链问题。
代码提取
自动提取漏洞链路上每个函数的完整源代码,便于人工或 AI 深入分析。
可用工具
使用示例
示例 1:全面漏洞扫描
请帮我扫描 /path/to/java-project 项目的安全漏洞
AI 会自动:
- 构建调用关系图
- 扫描所有类型的漏洞
- 分析并报告发现的问题
示例 2:针对性检测
检查项目中是否存在 SQL 注入和命令执行漏洞
AI 会扫描特定类型的漏洞(SQLI、RCE)。
示例 3:深入分析
这个漏洞链路是真实漏洞吗?请分析调用链的源代码
AI 会提取完整的调用链代码并进行分析。
支持的漏洞类型
- RCE - 远程代码执行 (CWE-78)
- SQLI - SQL 注入 (CWE-89)
- XXE - XML 外部实体注入 (CWE-611)
- SSRF - 服务端请求伪造 (CWE-918)
- PATH_TRAVERSAL - 路径穿越 (CWE-22)
- DESERIALIZE - 反序列化漏洞 (CWE-502)
- XPATH_INJECTION - XPath 注入 (CWE-643)
- TEMPLATE_INJECTION - 模板注入 (CWE-94)
- JNDI_INJECTION - JNDI 注入 (CWE-74)
- REFLECTION_INJECTION - 反射注入 (CWE-470)
- LOG_INJECTION - 日志注入 (CWE-117)
- CRYPTO_WEAKNESS - 加密算法弱点 (CWE-327)
支持的框架
- Spring Boot / Spring MVC
- MyBatis / Hiber
dbf16a4f9ba1OBSERVED · 2026-10-07Exposed tools (6)
6 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
analyze_vulnerability_chain | read | 详细分析特定的漏洞调用链,提取每个函数的源代码。 |
build_callgraph | read | 构建Java项目的函数调用关系图(Call Graph)。分析项目中所有类和方法的调用关系。 |
extract_method_code | read | 从Java项目中提取指定类的方法源代码。 |
find_vulnerabilities | read | 扫描Java项目,寻找从Sink到Source的污点传播链路,识别潜在安全漏洞。 |
get_project_statistics | read | 获取Java项目的统计信息,包括类数量、方法数量、调用关系数量等。 |
list_sink_rules | read | 列出所有配置的Sink规则(漏洞危险函数)。 |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (2)
javalang, colorama, mcp, markdown, bs4
Gates applied: no_behavioural_pass, no_license.
dbf16a4f9ba1full audit observations/trust-audit/mcp-server/zacarx__javasinktracer.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | dbf16a4f9ba1 | SAFE | B | 89 | first audit |
Questions
What is the JavaSinkTracer MCP server?
基于函数级污点分析的 Java 源代码漏洞审计工具JavaSinkTracer,通过 Model Context Protocol (MCP) 为 AI 助手提供安全分析能力。
What tools does JavaSinkTracer expose?
6 in total: 6 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is JavaSinkTracer safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does JavaSinkTracer need?
No credential environment variables were found in its source, so it appears to need none.
How does JavaSinkTracer run?
It speaks stdio, so it runs as a local process your client starts.
How current is this page?
The grade is for one exact copy of the source (dbf16a4f9ba1), read on 2026-10-07. The repository is watched and re-audited when it changes.