Crypto variable initialized using weak randomness

April 17, 2026 ยท View on GitHub

This query finds crypto variables initialized using weak randomness like process IDs or timestamps.

Limitations: the query does not track weak randomness through a hash function, so keys derived by hashing a weak source are not flagged.