Skip to content
#

code-scanning

Here are 91 public repositories matching this topic...

agentic-semgrep-rules

Semgrep rules for AI agent code: static analysis for LLM applications in Python, TypeScript and JavaScript. Finds model output reaching exec, shells, SQL, URLs, files and HTML, user input in system prompts, over-broad tools, MCP servers without auth, leaked keys and unsafe model loading. 36 tested rules, CWE and OWASP mapping.

  • Updated Oct 5, 2026
  • Python

Does this code phone home? A privacy-focused static analyzer that traces system, user and hardware data to network sinks and flags telemetry sent without an opt-out check — including inverted DO_NOT_TRACK guards. Python, JS/TS, Go. SARIF + Privacy Nutrition Label.

  • Updated Sep 17, 2026
  • Python

GitHub Actions for AI agent and supply chain security checks: audit agent configs (Claude Code settings, MCP servers, Cursor rules, CLAUDE.md) for risky permissions and prompt injection, find secrets in prompt files and notebooks, diff SBOMs in PR comments, audit licences, validate llms.txt, ping IndexNow. SARIF output, no dependencies.

  • Updated Oct 5, 2026
  • Python

Add this topic to your repo

To associate your repository with the code-scanning topic, visit your repo's landing page and select "manage topics."

Learn more