Pyre has applications beyond type checking python code; it can also run static analysis to identify potential security issues. These security issues are identified with what is called a Taint Analysis. The #python Static Analyzer feature of Pyre is usually abbreviated to Pysa (pronounced like the Leaning tower of Pisa).
Pysa works by tracking flows of data from where they originate (sources) to where they terminate in a dangerous location (sinks). For example, we might use it to track flows where user-controllable request data flows into an eval call, leading to a remote code execution vulnerability. This analysis is made possible by user-created stubs which provide annotations on source code, as well as Rules that define which sources are dangerous for which sinks. Pysa comes with many pre-written stubs and rules for builtin and common python libraries.
https://pyre-check.org/docs/pysa-basics.html
Post #626
2.59K