awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
anthropics avatar

anthropics/claude-code-security-review

0
View on GitHub↗
5,316 stars·550 forks·Python·MIT·23 views

Claude Code Security Review

This project is an AI-powered static analysis tool and automated vulnerability scanner designed to detect security flaws such as injection and authentication bypasses. It uses large language models to perform semantic reasoning across multiple programming languages, identifying vulnerabilities within code changes.

The tool operates as a GitHub Action that integrates into continuous integration pipelines to analyze pull request diffs. It focuses on modified lines of code to target new risks and reports findings by posting automated comments directly to the pull request.

Analysis is directed by customizable security policies and external rule injection, allowing for project-specific instructions. These custom rules and filters are used to reduce noise and discard low-impact findings to prioritize high-confidence security risks.

Features

  • LLM-Based Analysis - Uses large language models to evaluate code intent and semantic context to identify security flaws.
  • Vulnerability Scanners - Provides an automated scanner that identifies security risks and insecure coding practices within source code using semantic reasoning.
  • AI-Powered Code Analysis Tools - Utilizes large language models to analyze source code for complex security vulnerabilities like injection attacks.
  • Diff-Based Change Isolation - Analyzes only modified code blocks within a diff to target new vulnerabilities for AI evaluation.
  • Vulnerability Reporting Integrations - Notifies developers of detected vulnerabilities by posting automated comments directly onto pull requests.
  • Vulnerability Review Scanners - Scans code changes in pull requests for security issues and displays results during the review process.
  • GitHub Actions Workflows - Operates as a managed workflow that triggers on pull requests and communicates via automated API comments.
  • Security Linters - Implements a customizable AI-driven security linter that applies project-specific instructions and filters to reduce noise during analysis.
  • Security Vulnerability Scanning - Scans source code differences in pull requests to detect common security flaws and vulnerabilities.
  • AI-Powered Code Auditing - Uses large language models to scan code for complex security vulnerabilities such as authentication bypasses.
  • Pull Request Vulnerability Scanning - Analyzes specific code changes in a diff to identify new security risks without scanning the entire codebase.
  • CI Pipeline Integration - Integrates automated vulnerability scanning directly into the continuous integration build process.
  • External Rule Management - Loads behavioral constraints and decision logic from external text files to steer the AI analysis process.
  • Security Scanning Rules - Directs the analysis process by adding project-specific security instructions and filtering rules through external files.
  • AI Scan Policies - Applies project-specific rules and filters to AI security scans to reduce false positives.
  • Security Scan Policy Enforcers - Applies project-specific rules and filters to AI scans to reduce false positives and prioritize critical findings.
  • False Positive Filtering - Applies custom constraints to discard low-impact findings and focus on high-confidence security risks.

Star history

Star history chart for anthropics/claude-code-security-reviewStar history chart for anthropics/claude-code-security-review

How this analysis was created: This summary and feature list were written by an AI model that read the project's README and public documentation pages. Each feature links to the documentation it came from; stars, license and language come straight from the GitHub API. The model does not read the source code, and the analysis is refreshed when the project is re-analysed. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Open-source alternatives to Claude Code Security Review

Similar open-source projects, ranked by how many features they share with Claude Code Security Review.
  • snyk/snyksnyk avatar

    snyk/snyk

    5,586View on GitHub↗

    Snyk is an application security testing platform designed to identify and remediate vulnerabilities across source code, open-source dependencies, container images, and infrastructure-as-code configurations. It functions as a comprehensive security workflow automation tool, utilizing a static analysis engine and dependency graph mapping to detect security flaws and license compliance issues throughout the software development lifecycle. The platform distinguishes itself through agentic workflow orchestration and an automated remediation pipeline that generates and submits pull requests to patc

    TypeScript
    View on GitHub↗5,586
  • tidesec/tscanplusTideSec avatar

    TideSec/TscanPlus

    3,753View on GitHub↗

    TscanPlus is an external attack surface management tool and security reconnaissance framework designed for discovering network assets, enumerating subdomains, and mapping internet-facing services. It functions as a vulnerability scanning framework and network asset discovery suite to identify security exposure and map active hosts. The platform distinguishes itself by integrating an intelligence layer that uses large language models to analyze raw scan results and identify security weaknesses within JavaScript code. It also includes a dedicated proxy management system that validates and rotat

    View on GitHub↗3,753
  • qodo-ai/pr-agentqodo-ai avatar

    qodo-ai/pr-agent

    11,630View on GitHub↗

    PR Agent is an AI-powered code analysis tool and pull request reviewer that uses large language models to automate version control workflows. It functions as a programmatic agent that integrates with version control platforms to provide automated quality checks, explain code changes, and manage pull request documentation. The system distinguishes itself by enforcing organizational engineering standards through a customizable rule-based system. It leverages retrieval-augmented generation to inject repository context and organizational guidelines into its analysis, ensuring that feedback remain

    Pythoncode-reviewcodereviewcoding-assistant
    View on GitHub↗11,630
  • nvidia/skillspectorNVIDIA avatar

    NVIDIA/SkillSpector

    10,778View on GitHub↗

    SkillSpector is a security scanner designed to detect vulnerabilities and malicious patterns in AI agent plugins and extensions before they are installed. It functions as a runtime guardrail that calculates numeric risk scores and assigns severity labels to provide installation recommendations or block risky external extensions. The project distinguishes itself by using language models to perform semantic code analysis, evaluating code intent and context to reduce false positives. It also employs fingerprint-based issue suppression to track and ignore previously accepted risks across repeated

    Python
    View on GitHub↗10,778
See all 30 alternatives to Claude Code Security Review→

Frequently asked questions

What does anthropics/claude-code-security-review do?

This project is an AI-powered static analysis tool and automated vulnerability scanner designed to detect security flaws such as injection and authentication bypasses. It uses large language models to perform semantic reasoning across multiple programming languages, identifying vulnerabilities within code changes.

What are the main features of anthropics/claude-code-security-review?

The main features of anthropics/claude-code-security-review are: LLM-Based Analysis, Vulnerability Scanners, AI-Powered Code Analysis Tools, Diff-Based Change Isolation, Vulnerability Reporting Integrations, Vulnerability Review Scanners, GitHub Actions Workflows, Security Linters.

What are some open-source alternatives to anthropics/claude-code-security-review?

Open-source alternatives to anthropics/claude-code-security-review include: snyk/snyk — Snyk is an application security testing platform designed to identify and remediate vulnerabilities across source… tidesec/tscanplus — TscanPlus is an external attack surface management tool and security reconnaissance framework designed for discovering… qodo-ai/pr-agent — PR Agent is an AI-powered code analysis tool and pull request reviewer that uses large language models to automate… nvidia/skillspector — SkillSpector is a security scanner designed to detect vulnerabilities and malicious patterns in AI agent plugins and… aquasecurity/trivy — Trivy is a comprehensive security scanner designed to identify vulnerabilities and misconfigurations across container… anmol098/waka-readme-stats — waka-readme-stats is an automated profile README updater and developer statistics dashboard. It integrates with the…

Curated searches featuring Claude Code Security Review

Hand-picked collections where Claude Code Security Review appears.
  • Infrastructure as Code Security Scanners
  • AI-powered automated code review tool
  • AI Code Review Bots