pkg.soopen package index

brew / rank 4594

Install klee with Homebrew, Nix

Symbolic Execution Engine. Version 3.2 via Homebrew; verified 2026-07-31. Also installable with nix: nix profile install nixpkgs#klee.

install

Additional install commands

macOS

Homebrewverified · 100%
brew install klee

local Homebrew formula metadata

Linux

Nixverified · 92%
nix profile install nixpkgs#klee

nixpkgs package indexes · pkgs/by-name/kl/klee/package.nix · source: api.github.com

overview

Package summary

Symbolic Execution Engine

Commands and aliases

  • kleaver
  • klee
  • klee-exec-tree
  • klee-replay
  • klee-stats
  • klee-zesti
  • ktest-gen
  • ktest-randgen
  • ktest-tool

history

Project history and usage

KLEE is a dynamic symbolic execution engine for LLVM bitcode. It became influential because the 2008 OSDI paper demonstrated automatic test generation and bug finding on real Unix software at a scale that made symbolic execution feel practical rather than purely academic.

Project history

KLEE was initially developed at Stanford by Cristian Cadar, Daniel Dunbar, and Dawson Engler and presented at OSDI 2008. The project site describes it as a symbolic execution engine built on LLVM, and the repository describes the two central pieces: the core symbolic virtual machine and a POSIX/Linux emulation layer for running bitcode programs with symbolic operating-system inputs.

The OSDI evaluation is the historical anchor for KLEE: it ran on GNU Coreutils, BusyBox, MINIX utilities, and the HiStar kernel, using generated tests to expose crashes and correctness problems in heavily used systems code. That paper established the shape of KLEE's long-term identity: a research tool that is still packaged as a practical command-line engine.

Adoption history

KLEE has been adopted most visibly in research, program-analysis teaching, and systems-testing workflows. A 2020 journal article describes KLEE as a popular dynamic symbolic execution engine that began at Stanford and was later primarily developed and maintained by the Software Reliability Group at Imperial College London.

Package-manager adoption followed from that academic and systems-tooling footprint. The Homebrew formula ships the `klee`, `kleaver`, `ktest-tool`, replay, stats, and test-generation utilities, reflecting KLEE's role as a suite rather than a single binary.

How it is used

Users compile C or C++ programs to LLVM bitcode, mark inputs symbolic, and run KLEE to explore feasible paths and emit concrete test cases. The POSIX runtime lets KLEE model command-line arguments, files, environment variables, and other parts of a Unix process environment, making it especially attractive for testing command-line utilities.

Why package nerds care

KLEE matters to package nerds because it turns the package archive itself into test material: Coreutils, BusyBox, and MINIX utilities were not toy examples but ordinary low-level programs. It is also a good example of why some research artifacts become durable packages: the build may be specialized, but the command-line behavior is useful enough for distributions to preserve.

Timeline

  • 2008: OSDI paper presented KLEE as a symbolic execution tool for high-coverage tests on complex systems programs.
  • 2008: The OSDI evaluation reported KLEE runs over more than 452 programs and serious bugs in Coreutils, BusyBox, MINIX, and HiStar.
  • 2020: A journal article described KLEE's post-Stanford maintenance and its academic and industry community.
  • 2025-12-23: GitHub releases page listed KLEE 3.2.

Related projects

  • KLEE is related to LLVM, STP and other SMT-backed solver tooling, S2E, angr, CBMC, AFL-style testing workflows, and the POSIX utility suites used in its original evaluation.

security posture

Risk level: yellow

generalized runtime or code generation signal.

Risk classifier

yellow risk · medium confidence · runtime

Why

  • generalized runtime or code generation signal

Signals

  • text:repl

Install behavior

  • No Homebrew bottle metadata was recorded.

Recommended review

Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.

executables

Installed executables

CommandKindExposureNote
kleaverexecutableindexed executableDiscovered from the local executable index.
kleeexecutableindexed executableDiscovered from the local executable index.
klee-exec-treeexecutableindexed executableDiscovered from the local executable index.
klee-replayexecutableindexed executableDiscovered from the local executable index.
klee-statsexecutableindexed executableDiscovered from the local executable index.
klee-zestiexecutableindexed executableDiscovered from the local executable index.
ktest-genexecutableindexed executableDiscovered from the local executable index.
ktest-randgenexecutableindexed executableDiscovered from the local executable index.
ktest-toolexecutableindexed executableDiscovered from the local executable index.

freshness

Version and freshness

These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.

page generated2026-08-03
manager version3.2
manager updated2026-07-31
local dataunknown
upstreamnot available
latest detectednot detected
  • okNo freshness warnings were generated.

install metadata

Package metadata

Package keybrew:klee
Version3.2
Package managerHomebrew
Homepagehttps://klee-se.org
Repositoryhttps://github.com/klee/klee
Last updated2026-07-31T14:27:43Z
Pulseupdated
Bottlenot recorded
Servicenone declared

source database matches

Other package-manager records

Matches are pulled from external package-manager indexes and kept separate from local Automic Vault package links.

Nix95%

klee

nix profile install nixpkgs#klee
  • normalized package name match
  • Matched by: Klee
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/kl/klee/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1

source trail

Generated from repository data

This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.

Used sources

  • Geiger risk classifier
  • cross-ecosystem install command graph
  • curated package history
  • external package-manager database matches
  • pkg.so package database
  • pkgdb category and tag curation