False positive filtering for Weasel static analysis results. Triggers on weasel filter, weasel triage, or weasel clean report.
Expert in filtering false positives from Weasel static analysis output.
Context: This skill filters WEASEL's output. For validating your own attack ideas, see weasel-validate.
āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā
ā HIGH SEVERITY (typically 0-5 issues) ā
ā ā Verify ALL - these are critical ā
āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā¤
ā MEDIUM SEVERITY (typically 2-10) ā
ā ā Verify ALL - these matter ā
āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā¤
ā LOW SEVERITY (can be many) ā
ā ā Sample check if >10 issues ā
ā ā Check all if ā¤10 issues ā
āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā¤
ā GAS / NC ā
ā ā Skip verification (not security) ā
āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā
When user just ran weasel_analyze via MCP:
When report file already exists (user ran weasel with output flag):
weasel_analyze MCP (small)## [H-01] Reentrancy...)## [ or endWhy Workflow B is efficient:
For each finding to verify:
Keep output minimal - one line per finding:
Filtered 5 findings ā 2 confirmed, 3 false positives
ā [H-01] Reentrancy in withdraw() - confirmed
ā [M-03] Access control missing - confirmed
ā [H-02] Reentrancy in deposit() - has nonReentrant
ā [M-01] Unchecked return - uses SafeERC20
ā [M-02] Integer overflow - in unchecked{} intentionally
Removed 3 sections from report.md
No verbose evidence blocks - user can ask for details on specific findings if needed.
Ask user:
| Rationalization | Why It's Wrong |
|---|---|
| "This detector usually has false positives" | Check THIS instance. Each case is different. |
| "The code looks safe" | READ the code. Don't judge by appearance. |
| "I'll mark as FP without reading" | ALWAYS read source code before verdict. |
| "SafeERC20 is used, so all transfer issues are FP" | Verify SafeERC20 is actually used at THAT location. |
| "This is a known pattern, must be fine" | Known patterns can still have implementation bugs. |
| "I'll confirm all High severity to be safe" | False positives waste developer time. Verify properly. |