What tools are necessary for static-analysis taint-based vulnerability detection? For example, being able to find/search source-sink paths through a tainted variable, flexibility to choose flow sensitive/insensitive analysis, etc.
I realize there is no definitive answer, but that doesn't mean your answers are merely opinions; they are informed answers gleaned through application and practice.