Local security tools for developers
Security tools for code, CI and MCP servers.
Vulnerability database
Version 3.1.1 runs local repository and SBOM vulnerability scans against a real, signed OSV starter database with 243,381 CVE/OSV records available from the first scan. After updates, the database can grow toward the full OSV source count, currently 813,101 records. Coverage is explicitly partial: absence of a match is not proof of safety.
CodeRiskTools Observatory now bridges this Scanner 3.1.1 SBOM vulnerability output into reproducible, exact-SHA, review-gated repository risk evidence without executing the target repository.
Use the free Secret Scanner Engine to catch exposed credentials before merge. For authorized MCP reviews, MCPwatch Scanner + Report Pack v0.5.2 analyzes local exports and produces clear HTML, CSV and JSON evidence without uploading source code.
Available now
Secret Scanner Engine 3.1.1
Public MIT source, release tag, README documentation in the repository, pre-commit support, and a composite GitHub Action for local or CI checks.
Evidence
Release-scoped checks
574 tests passed and 1 skipped, CI succeeded on Python 3.10-3.13, and the release records SHA-256 wheel provenance.
Limits
Evidence, not guarantees
The scanner is a bounded developer tool with redacted outputs and strict diff/Git handling. It does not claim security guarantees or production efficacy.
Choose the right security workflow
Start free, then add the workflow your review requires.
1. Public MIT core
CodeRiskTools Secret Scanner Engine 3.1.1 is public and available at the GitHub repository and release link.
2. MCPwatch Scanner + Report Pack
Available now for authorized local MCP surface reviews on GNU/Linux x86_64. Professional ($99) covers one organization; Agency ($249) covers authorized client engagements.
3. AI Change Firewall
AI Change Firewall is a separate paid proprietary product. Professional is available for $19 and Agency for $30 as one-time purchases. The public MIT Secret Scanner Engine remains separately available.
Responsible disclosure
Use GitHub Private Vulnerability Reporting for vulnerabilities.
For public bugs, use GitHub Issues without sensitive data. For vulnerabilities, use GitHub Private Vulnerability Reporting from the scanner repository Security tab. Do not send secrets, private code, or customer data.