CodeRiskTools

Developer tools for safer AI-assisted coding

Local security tools for developers

Security tools for code, CI and MCP servers.

Vulnerability database

Version 3.1.1 runs local repository and SBOM vulnerability scans against a real, signed OSV starter database with 243,381 CVE/OSV records available from the first scan. After updates, the database can grow toward the full OSV source count, currently 813,101 records. Coverage is explicitly partial: absence of a match is not proof of safety.

CodeRiskTools Observatory now bridges this Scanner 3.1.1 SBOM vulnerability output into reproducible, exact-SHA, review-gated repository risk evidence without executing the target repository.

Use the free Secret Scanner Engine to catch exposed credentials before merge. For authorized MCP reviews, MCPwatch Scanner + Report Pack v0.5.2 analyzes local exports and produces clear HTML, CSV and JSON evidence without uploading source code.

Evidence

Release-scoped checks

574 tests passed and 1 skipped, CI succeeded on Python 3.10-3.13, and the release records SHA-256 wheel provenance.

Limits

Evidence, not guarantees

The scanner is a bounded developer tool with redacted outputs and strict diff/Git handling. It does not claim security guarantees or production efficacy.

Choose the right security workflow

Start free, then add the workflow your review requires.

1. Public MIT core

CodeRiskTools Secret Scanner Engine 3.1.1 is public and available at the GitHub repository and release link.

2. MCPwatch Scanner + Report Pack

Available now for authorized local MCP surface reviews on GNU/Linux x86_64. Professional ($99) covers one organization; Agency ($249) covers authorized client engagements.

View MCPwatch Scanner

3. AI Change Firewall

AI Change Firewall is a separate paid proprietary product. Professional is available for $19 and Agency for $30 as one-time purchases. The public MIT Secret Scanner Engine remains separately available.

View AI Change Firewall

Responsible disclosure

Use GitHub Private Vulnerability Reporting for vulnerabilities.

For public bugs, use GitHub Issues without sensitive data. For vulnerabilities, use GitHub Private Vulnerability Reporting from the scanner repository Security tab. Do not send secrets, private code, or customer data.

Loading, please wait…
BACK TO TOP