Snyk is an application security testing platform designed to identify and remediate vulnerabilities across source code, open-source dependencies, container images, and infrastructure-as-code configurations. It functions as a comprehensive security workflow automation tool, utilizing a static analysis engine and dependency graph mapping to detect security flaws and license compliance issues throughout the software development lifecycle. The platform distinguishes itself through agentic workflow orchestration and an automated remediation pipeline that generates and submits pull requests to patc
TscanPlus is an external attack surface management tool and security reconnaissance framework designed for discovering network assets, enumerating subdomains, and mapping internet-facing services. It functions as a vulnerability scanning framework and network asset discovery suite to identify security exposure and map active hosts. The platform distinguishes itself by integrating an intelligence layer that uses large language models to analyze raw scan results and identify security weaknesses within JavaScript code. It also includes a dedicated proxy management system that validates and rotat
PR Agent is an AI-powered code analysis tool and pull request reviewer that uses large language models to automate version control workflows. It functions as a programmatic agent that integrates with version control platforms to provide automated quality checks, explain code changes, and manage pull request documentation. The system distinguishes itself by enforcing organizational engineering standards through a customizable rule-based system. It leverages retrieval-augmented generation to inject repository context and organizational guidelines into its analysis, ensuring that feedback remain
SkillSpector is a security scanner designed to detect vulnerabilities and malicious patterns in AI agent plugins and extensions before they are installed. It functions as a runtime guardrail that calculates numeric risk scores and assigns severity labels to provide installation recommendations or block risky external extensions. The project distinguishes itself by using language models to perform semantic code analysis, evaluating code intent and context to reduce false positives. It also employs fingerprint-based issue suppression to track and ignore previously accepted risks across repeated
Acest proiect este un instrument de analiză statică bazat pe AI și un scaner automat de vulnerabilități conceput pentru a detecta defectele de securitate, cum ar fi injecția și ocolirea autentificării. Utilizează modele de limbaj mari pentru a efectua raționamente semantice în mai multe limbaje de programare, identificând vulnerabilitățile în cadrul modificărilor de cod.
Principalele funcționalități ale anthropics/claude-code-security-review sunt: LLM-Based Analysis, Vulnerability Scanners, AI-Powered Code Analysis Tools, Diff-Based Change Isolation, Vulnerability Reporting Integrations, Vulnerability Review Scanners, GitHub Actions Workflows, Security Linters.
Alternativele open-source pentru anthropics/claude-code-security-review includ: snyk/snyk — Snyk is an application security testing platform designed to identify and remediate vulnerabilities across source… tidesec/tscanplus — TscanPlus is an external attack surface management tool and security reconnaissance framework designed for discovering… qodo-ai/pr-agent — PR Agent is an AI-powered code analysis tool and pull request reviewer that uses large language models to automate… nvidia/skillspector — SkillSpector is a security scanner designed to detect vulnerabilities and malicious patterns in AI agent plugins and… aquasecurity/trivy — Trivy is a comprehensive security scanner designed to identify vulnerabilities and misconfigurations across container… anmol098/waka-readme-stats — waka-readme-stats is an automated profile README updater and developer statistics dashboard. It integrates with the…