Lua code: security overview and practical approaches to static analysis [pdf]
spw17.langsec.org
spw17.langsec.org
This is basically the only thing about their detection method, which is pretty disappointing, even more so comparing to exciting things like 'inter- and intra-procedural data flow analysis' in related work section.
> Alternatively, one could use the parsers from the existing tools, such as LuaCheck [17] or lua-checker [19]. Unfortunately the parsers in those tools are tailored to particular versions of Lua specifications and adapting them to all or latest Lua specifications may be untrivial or may introduce bugs and unnecessary complexity.
Wrong, at least for Luacheck parser: it supports all Lua syntax starting from 5.1.
And they are welcoming towards patches, though they don't copy them all in verbatim: https://www.lua.org/faq.html#1.9
> 1.9 – Do you accept patches?
> We encourage discussions based on tested code solutions for problems and enhancements, but we never incorporate third-party code verbatim. We always try to understand the issue and the proposed solution and then, if we choose to address the issue, we provide our own code. All code in Lua is written by us. See also the previous question [On the lack of a public, official VCS].
Few large projects accept all outside contribution. And Lua would not be as versatile, as portable, or as small as it is if it did.