Augments Trailmark code graphs with external audit findings from SARIF static analysis results and weAudit annotation files. Maps findings to graph nodes by file and line overlap, creates severity-based subgraphs, and enables cross-referencing findings with pre-analysis data (blast radius, taint, etc.). Use when projecting SARIF results onto a code graph, overlaying weAudit annotations, cross-referencing Semgrep or CodeQL findings with call graph data, or visualizing audit findings in the contex
Detected risks:
A security-tooling skill that projects external audit findings onto Trailmark code graphs. It maps SARIF static analysis results and weAudit annotation files to graph nodes by file path and line-range overlap, creates severity-based subgraphs, and enables cross-referencing those findings with pre-analysis data such as blast radius and taint. It applies when importing Semgrep, CodeQL, or other SARIF-producing tool results into a graph, overlaying weAudit annotations, querying which functions carry high-severity findings, or visualizing audit coverage alongside code structure.
The recommended workflow builds the graph and runs `engine.preanalysis()` first so that findings can be related to blast radius and taint context, then locates the input files (SARIF typically emitted by tools like `semgrep --sarif -o results.sarif` or CodeQL, and weAudit stored at `.vscode/<username>.weaudit`), runs augmentation, inspects results, and cross-references with pre-analysis subgraphs. Both a CLI (`uv run trailmark augment {targetDir} --sarif ... --weaudit ...`) and a programmatic QueryEngine API (`augment_sarif`, `augment_weaudit`, `findings`, `subgraph`, `annotations_of`) are provided. Augmentation results report matched and unmatched finding counts plus the subgraphs created; unmatched findings are flagged for investigation because they may indicate parsing gaps or out-of-scope files.
Findings are stored as standard Trailmark annotations with kinds `finding` (tool-generated) or `audit_note` (human notes) and sources like `sarif:<tool>` or `weaudit:<author>`. The skill creates severity- and tool-scoped subgraphs such as `sarif:error`, `sarif:warning`, `sarif:note`, per-tool subgraphs, and weAudit subgraphs by severity and entry type. Matching normalizes finding paths against the graph root, selects nodes whose line ranges overlap, and prefers the tightest span; SARIF relative, absolute, and file:// URIs are handled and weAudit 0-indexed lines are converted to 1-indexed automatically. It is explicitly not for running static analysis tools or building the graph itself (use the trailmark skill), and a SARIF 2.1.0 and weAudit format reference lives in references/formats.md.
It accepts SARIF static analysis results (e.g., from Semgrep or CodeQL) and weAudit annotation files, which are typically stored at `.vscode/<username>.weaudit` within the workspace.
Yes. The skill requires running `engine.preanalysis()` before augmenting so findings can be cross-referenced with blast radius and taint data; skipping it removes that context.
Unmatched findings are those whose file/line locations did not overlap any parsed code unit. The skill says to report the unmatched count and investigate when high, since it may signal parsing gaps or out-of-scope files.
It creates severity-based SARIF subgraphs (`sarif:error`, `sarif:warning`, `sarif:note`), per-tool subgraphs like `sarif:<tool>`, and weAudit subgraphs by severity (`weaudit:high/medium/low`) and entry type (`weaudit:findings`, `weaudit:notes`).
Findings are matched by normalizing the file path against the graph's root, selecting nodes whose line ranges overlap, and preferring the tightest match; SARIF relative/absolute/file:// paths are handled and weAudit 0-indexed lines are converted to 1-indexed.
Quick Setup:
.claude/skills/Repository
trailofbits/skills