Secure Code Review AI Agent (SeCoRA) - AI SAST
-
Updated
Jan 29, 2025 - Python
Secure Code Review AI Agent (SeCoRA) - AI SAST
A terminal interactive game designed to train yourself to identify insecure coding practices.
Defensive AI security audit skill for Claude and Codex. Reviews codebases and web apps for OWASP Top 10, auth and authorization flaws, business logic bugs, tenant isolation gaps, insecure defaults, secret leaks, and ORM or N+1 query issues, then produces clear remediation guidance.
Portable defensive application security and AI-agent security skill for Claude Code, Codex, Gemini, and ChatGPT. Covers OWASP, secure design, secure code review, MCP security, prompt injection, threat modeling, incident response, and hardening.
AppSec interview questions and study guides covering web, mobile, cloud, DevSecOps, and secure code review.
Developer behind VirtualSpace AppSec - a Windows secure code review tool by Verse (NL, KVK 88114171) that runs entirely on your own machine.
Windows secure code review tool by Verse. SAST + on-device AI analysis for C/C++, Python, JavaScript, and .NET source projects you own or are authorized to review - runs entirely on your own machine.
Local MCP server that helps coding agents run defensive, remediation-focused secure code review of source repositories.
Real-time code analysis that detects cross-file semantic errors, type inconsistencies, array bound violations, and function signature drift while you type, before files are saved, without external security APIs.
University job board reviewed as unfamiliar code: twelve findings including an authentication bypass via a client-supplied header, each fixed and held by a regression test.
CosmoGrepperAI is a highly polished, open-source application security scanner designed to dramatically outperform raw static analysis tools.
Online admission and seat-allocation system for the University of Kalamoon. ASP.NET Core MVC + EF Core + SQL Server graduation project (2022), with a 2026 security review.
Most AI security tools try to find more. SecHelix tries to prove itself wrong: every candidate finding goes to an independent verifier whose only job is to disprove it. Open-source AppSec agent for Claude Code, Codex and Copilot.
Easy-to-use, customizable, high-quality secure code review skills for AI agents.
VS Code extension prototype that uses adversarial LLM review to identify insecure code patterns, propose hardened alternatives, and apply approved local code changes.
One real vulnerability, one scary-looking false positive — can your scanner tell which is which? 10 AppSec cases, 3 of them decoys. A false positive costs exactly what a miss costs.
Beginner forensics mini-CTF — web log analysis, encoding vs encryption, secure code review of a vulnerable Flask endpoint, and classical ciphers, told as one continuous incident. Every flag independently verified.
Local defensive remediation lab using OpenAI Codex CLI, secure code review, patch validation and human-in-the-loop approval.
LabSite — AppSec triage trainer with 100+ hands-on tasks and challenges.
AI-powered code review agent with rule-based detection and RAG-enhanced security analysis
To associate your repository with the secure-code-review topic, visit your repo's landing page and select "manage topics."