Get instant AI generated feedback to your PRs. It scans the changes you made and looks for potential bugs, security concerns and provides recommnedations on the spot.
-
Updated
Jul 26, 2025 - TypeScript
Get instant AI generated feedback to your PRs. It scans the changes you made and looks for potential bugs, security concerns and provides recommnedations on the spot.
GitHub Action to export GitHub security alerts
Snapcube is a powerful CLI tool that allows you to save your project structure to JSON and recreate it anywhere. Perfect for project templates, backups, or sharing project scaffolds with your team.
Audit MCP servers for security risks and config leaks; generate Markdown + SARIF reports and optionally fail CI via policy gates (stdio/HTTP JSON-RPC, profile-based scoring).
GitHub Action for VulnHunter security scanning. SARIF output, PR annotations, CI/CD gating.
Static analyzer that tracks resource lifecycles across all code paths to find locks, connections, and handles that leak on error paths. Inspired by the 57-year-old bug found in Apollo 11 guidance code.
MCP server that detects accidentally committed secrets, API keys, tokens, and credentials using pattern matching and entropy analysis
Diagnose env-var bugs in JS/TS repos with framework-aware CI, SARIF, and GitHub annotations.
🔒 Real-time secret detection for VS Code - Scan code for AWS, GitHub, Stripe, Slack credentials and 40+ more patterns. Privacy-first, local processing.
Free security scanner for AI-generated code. 5 rules for secrets, eval, SQL injection, .env exposure. Full version: 35+ rules.
🛡️ Agent Security Scanner — 364 patterns, 35 threat categories, 27 runtime checks. Zero-Trust policy layer for MCP/A2A agents.
Local preflight and audit tool for AI coding agents: scan repo risk, enforce tool-call policy, and record tamper-evident audit logs. Local-first, zero telemetry.
mcp-scan is a free, open-source security scanner for MCP (Model Context Protocol) servers. It scans your MCP server's source code for critical security issues: hardcoded API keys, servers binding to all network interfaces, missing authentication on remote transports, dangerously broad tool permissions, and vulnerable dependencies.
Is your AI-built store secure & production-ready? A deterministic scanner for AI-generated commerce codebases (secrets, injection, commerce-logic, deps). Built by MnT.
Static analyzer for least-privilege GitHub Actions GITHUB_TOKEN permissions.
Security scanner for AI-assisted repositories.
A security scanner for HarmonyOS NEXT — finds, validates, and fixes vulnerabilities in ArkTS / ArkBytecode apps. CLI + TypeScript SDK, SARIF output.
Accelerating new GitHub Actions workflows
Dependabot for LLM models — scans code for outdated AI model strings, opens upgrade PRs automatically
Static security scanner for JavaScript/TypeScript MCP servers. Detect risky shell, secret, filesystem, and network behavior via CLI or GitHub Actions.
To associate your repository with the code-scanning topic, visit your repo's landing page and select "manage topics."