1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
Runnable `.klr` files live in [`examples/`](../examples/) and the built-in
suites in [`suites/`](../suites/). This page annotates a few.
[`examples/auth_security.klr`](../examples/auth_security.klr)
```klr
project "MyApplication"
attack authentication {
}
```
```sh
killer test examples/auth_security.klr --url http://localhost:8080
```
```klr
suite "API" {
}
```
```sh
killer test api.klr --url http://localhost:8080 --parallel
```
[`examples/database_rules.klr`](../examples/database_rules.klr)
```klr
rule "unsafe database query"
when function contains "query"
and input reaches query
without sanitization
severity high
report: "User input reaches database directly"
```
```sh
killer test examples/database_rules.klr --project .
```
```sh
killer test --suite web --url http://localhost:8080
killer test --suite api --url http://localhost:8080 --parallel
killer test --suite authentication --url http://localhost:8080
```
```sh
killer ci --base origin/main # scan + rules + review; non-zero exit on findings
killer github enable # generate .github/workflows/killer.yml
```