What we still need to verify : 1 point in this profile is not yet confirmed against vendor documentation.
- Current signature database list: confirm against the repository
Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.
What it does
Graudit is deliberately simple: a shell script wrapped around grep, plus a
set of signature databases, one per language or technology. Each database is
a list of regular expressions matching functions and constructs that deserve
a human look, such as eval, system, exec, unserialize, direct
superglobal access, string-concatenated queries, and insecure API calls. You
point it at a directory, choose a database, and it prints matches with file,
line number and surrounding context.
There is no parsing, no type resolution and no data flow. That is the design, not a shortcoming to be apologized for. The tool exists to answer a specific question during manual review: where in these one hundred thousand lines should I start reading? A reviewer who knows the language can scan a few hundred grep hits far faster than they can read the codebase, and the signature databases encode the accumulated instinct about which calls are worth checking. Databases are plain text files, so adding a signature for an internal helper function takes one line.
Where it fits
This is a reviewer's tool, run on a workstation during a penetration test, code audit or bug bounty triage of an open-source target. It is not a CI tool and should not be treated as one: there is no severity model, no deduplication and no notion of a baseline. It works on any checkout with no build, no dependency install and no network, which makes it convenient on an isolated assessment machine.
Strengths
- Zero setup and zero dependencies beyond a shell and grep, which matters on locked-down or air-gapped review environments.
- Signature databases are plain text and trivially extensible, so organization-specific dangerous functions are easy to add.
- Language agnostic in practice: if you can write a regex for a pattern, you can hunt for it, including in languages no scanner supports.
- Fast on large trees and completely transparent about why each hit fired.
Limitations
- Purely lexical. Every match is a candidate, not a finding, and the false positive rate is by design very high.
- No understanding of whether a dangerous call is reachable or whether its input is attacker-controlled, so it cannot tell exploitable from inert.
- No structured output, state tracking or integration story, which rules it out as an automated control.
Who it suits
Well suited to penetration testers, auditors and researchers who read code for a living and want a fast index into unfamiliar source. It is the wrong tool for a development team looking for an automated gate, where a real static analyzer with a severity model belongs instead.
Used Graudit? Recommend it under your own name and title.
Recommend this tool