Taint Flow Tracker
Traces how external input flows to detected memory bugs - answers “Can an attacker actually trigger this bug?”
Usage
# After scanning
memguard taint <scan-id>
memguard taint <scan-id> --source ./src/
# Via GUI: click any issue → Taint Flow button
Expected Output
CRITICAL: 2 bugs reachable from network input.
Remote exploitation possible.
recv() network → 'buf'
→param parse_request() 'raw'
→return log_request() 'req'
→ USE_AFTER_FREE at server_sim.c:92
Confidence: 90%
6-Phase Pipeline
Parse source - tree-sitter (regex fallback) extracts functions with params, assignments, struct writes, globals, returns, function pointer calls
Find taint sources - 30+ input functions across 6 categories (network, file, stdin, argv, env, IPC)
Build data-flow graph - 5 edge types: PARAM, RETURN, ASSIGN, GLOBAL, STRUCT
Propagate taint - iterative fixpoint at variable level through assignments, parameters, returns, struct fields, globals
Trace to bugs - BFS with data-flow awareness, prefers tainted paths
Risk assessment - edge-type weighted confidence scoring with contextual narrative