awesome-repositories.com
Blog
awesome-repositories.com

Descoperă cele mai bune repository-uri open source cu căutare AI.

ExploreazăCăutări recomandateAlternative open-sourceSoftware self-hostedBlogHartă site
ProiectDespreCum realizăm clasamentulPresăServer MCP
LegalConfidențialitateTermeni
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
anthropics avatar

anthropics/claude-code-security-review

0
View on GitHub↗
5,316 stele·550 fork-uri·Python·MIT·9 vizualizări

Claude Code Security Review

Acest proiect este un instrument de analiză statică bazat pe AI și un scaner automat de vulnerabilități conceput pentru a detecta defectele de securitate, cum ar fi injecția și ocolirea autentificării. Utilizează modele de limbaj mari pentru a efectua raționamente semantice în mai multe limbaje de programare, identificând vulnerabilitățile în cadrul modificărilor de cod.

Instrumentul operează ca un GitHub Action care se integrează în pipeline-urile de integrare continuă pentru a analiza diff-urile pull request-urilor. Se concentrează pe liniile de cod modificate pentru a viza riscurile noi și raportează constatările prin postarea de comentarii automate direct în pull request.

Analiza este direcționată de politici de securitate personalizabile și injecția de reguli externe, permițând instrucțiuni specifice proiectului. Aceste reguli și filtre personalizate sunt utilizate pentru a reduce zgomotul și a elimina constatările cu impact redus pentru a prioritiza riscurile de securitate cu încredere ridicată.

Features

  • LLM-Based Analysis - Uses large language models to evaluate code intent and semantic context to identify security flaws.
  • Vulnerability Scanners - Provides an automated scanner that identifies security risks and insecure coding practices within source code using semantic reasoning.
  • AI-Powered Code Analysis Tools - Utilizes large language models to analyze source code for complex security vulnerabilities like injection attacks.
  • Diff-Based Change Isolation - Analyzes only modified code blocks within a diff to target new vulnerabilities for AI evaluation.
  • Vulnerability Reporting Integrations - Notifies developers of detected vulnerabilities by posting automated comments directly onto pull requests.
  • Vulnerability Review Scanners - Scans code changes in pull requests for security issues and displays results during the review process.
  • GitHub Actions Workflows - Operates as a managed workflow that triggers on pull requests and communicates via automated API comments.
  • Security Linters - Implements a customizable AI-driven security linter that applies project-specific instructions and filters to reduce noise during analysis.
  • Security Vulnerability Scanning - Scans source code differences in pull requests to detect common security flaws and vulnerabilities.
  • AI-Powered Code Auditing - Uses large language models to scan code for complex security vulnerabilities such as authentication bypasses.
  • Pull Request Vulnerability Scanning - Analyzes specific code changes in a diff to identify new security risks without scanning the entire codebase.
  • CI Pipeline Integration - Integrates automated vulnerability scanning directly into the continuous integration build process.
  • External Rule Management - Loads behavioral constraints and decision logic from external text files to steer the AI analysis process.
  • Security Scanning Rules - Directs the analysis process by adding project-specific security instructions and filtering rules through external files.
  • AI Scan Policies - Applies project-specific rules and filters to AI security scans to reduce false positives.
  • Security Scan Policy Enforcers - Applies project-specific rules and filters to AI scans to reduce false positives and prioritize critical findings.
  • False Positive Filtering - Applies custom constraints to discard low-impact findings and focus on high-confidence security risks.

Istoric stele

Graficul istoricului de stele pentru anthropics/claude-code-security-reviewGraficul istoricului de stele pentru anthropics/claude-code-security-review

Căutare AI

Explorează mai multe repository-uri excelente

Descrie ce ai nevoie în limbaj simplu — AI-ul sortează mii de proiecte open source selectate în funcție de relevanță.

Start searching with AI

Colecții curatoriate care includ Claude Code Security Review

Colecții selectate manual în care apare Claude Code Security Review.
  • Scanere de securitate pentru Infrastructure as Code
  • Instrument automatizat de code review bazat pe AI
  • Boți AI pentru code review

Alternative open-source pentru Claude Code Security Review

Proiecte open-source similare, clasificate după numărul de funcționalități comune cu Claude Code Security Review.
  • snyk/snykAvatar snyk

    snyk/snyk

    5,586Vezi pe GitHub↗

    Snyk is an application security testing platform designed to identify and remediate vulnerabilities across source code, open-source dependencies, container images, and infrastructure-as-code configurations. It functions as a comprehensive security workflow automation tool, utilizing a static analysis engine and dependency graph mapping to detect security flaws and license compliance issues throughout the software development lifecycle. The platform distinguishes itself through agentic workflow orchestration and an automated remediation pipeline that generates and submits pull requests to patc

    TypeScript
    Vezi pe GitHub↗5,586
  • tidesec/tscanplusAvatar TideSec

    TideSec/TscanPlus

    3,753Vezi pe GitHub↗

    TscanPlus is an external attack surface management tool and security reconnaissance framework designed for discovering network assets, enumerating subdomains, and mapping internet-facing services. It functions as a vulnerability scanning framework and network asset discovery suite to identify security exposure and map active hosts. The platform distinguishes itself by integrating an intelligence layer that uses large language models to analyze raw scan results and identify security weaknesses within JavaScript code. It also includes a dedicated proxy management system that validates and rotat

    Vezi pe GitHub↗3,753
  • qodo-ai/pr-agentAvatar qodo-ai

    qodo-ai/pr-agent

    11,630Vezi pe GitHub↗

    PR Agent is an AI-powered code analysis tool and pull request reviewer that uses large language models to automate version control workflows. It functions as a programmatic agent that integrates with version control platforms to provide automated quality checks, explain code changes, and manage pull request documentation. The system distinguishes itself by enforcing organizational engineering standards through a customizable rule-based system. It leverages retrieval-augmented generation to inject repository context and organizational guidelines into its analysis, ensuring that feedback remain

    Pythoncode-reviewcodereviewcoding-assistant
    Vezi pe GitHub↗11,630
  • nvidia/skillspectorAvatar NVIDIA

    NVIDIA/SkillSpector

    10,778Vezi pe GitHub↗

    SkillSpector is a security scanner designed to detect vulnerabilities and malicious patterns in AI agent plugins and extensions before they are installed. It functions as a runtime guardrail that calculates numeric risk scores and assigns severity labels to provide installation recommendations or block risky external extensions. The project distinguishes itself by using language models to perform semantic code analysis, evaluating code intent and context to reduce false positives. It also employs fingerprint-based issue suppression to track and ignore previously accepted risks across repeated

    Python
    Vezi pe GitHub↗10,778
Vezi toate cele 30 alternative pentru Claude Code Security Review→

Întrebări frecvente

Ce face anthropics/claude-code-security-review?

Acest proiect este un instrument de analiză statică bazat pe AI și un scaner automat de vulnerabilități conceput pentru a detecta defectele de securitate, cum ar fi injecția și ocolirea autentificării. Utilizează modele de limbaj mari pentru a efectua raționamente semantice în mai multe limbaje de programare, identificând vulnerabilitățile în cadrul modificărilor de cod.

Care sunt principalele funcționalități ale anthropics/claude-code-security-review?

Principalele funcționalități ale anthropics/claude-code-security-review sunt: LLM-Based Analysis, Vulnerability Scanners, AI-Powered Code Analysis Tools, Diff-Based Change Isolation, Vulnerability Reporting Integrations, Vulnerability Review Scanners, GitHub Actions Workflows, Security Linters.

Care sunt câteva alternative open-source pentru anthropics/claude-code-security-review?

Alternativele open-source pentru anthropics/claude-code-security-review includ: snyk/snyk — Snyk is an application security testing platform designed to identify and remediate vulnerabilities across source… tidesec/tscanplus — TscanPlus is an external attack surface management tool and security reconnaissance framework designed for discovering… qodo-ai/pr-agent — PR Agent is an AI-powered code analysis tool and pull request reviewer that uses large language models to automate… nvidia/skillspector — SkillSpector is a security scanner designed to detect vulnerabilities and malicious patterns in AI agent plugins and… aquasecurity/trivy — Trivy is a comprehensive security scanner designed to identify vulnerabilities and misconfigurations across container… anmol098/waka-readme-stats — waka-readme-stats is an automated profile README updater and developer statistics dashboard. It integrates with the…