CodeRiskTools AI Change Firewall — powered by Secret Scanner Engine

LOCAL REVIEW AID · V4.2.0 · PROFESSIONAL + AGENCY

Turn AI-generated changes into an explicit Scanner → Firewall decision.

CodeRiskTools combines a 176-rule Secret Scanner Engine with intent-aware AI Change Firewall policy. Provide declared intent and a unified diff—or a supported agent event—and receive redacted Scanner evidence, integrity binding, and a final ALLOW or BLOCKED decision for human review.

One local, evidence-first workflow

  1. Declare allowed scope and operations in an intent manifest.
  2. Provide the corresponding unified diff or invoke a supported Claude Code, Codex, Cursor, or Aider entrypoint.
  3. Run the bundled Secret Scanner Engine and produce redacted Scanner evidence.
  4. Bind the exact report and diff with SHA-256 for integrity and consistency—not authenticity.
  5. Evaluate scope, dependency, CI, security-control, and infrastructure policy, then return ALLOW or BLOCKED.

PROFESSIONAL · $19 · AVAILABLE

For one-project workflows

The complete Scanner → Firewall workflow, local agent entrypoints, optional Repository Guard, browser-extension policy pack, source, tests, checksums, and edition attestation.

Fresh-extract gate: Firewall 240 tests / 379 subtests; Scanner 383 tests / 523 subtests / 1 expected no-Git skip.

Buy Professional — $19

AGENCY · $30 · AVAILABLE

For authorized multi-project/client operations

The same detection and policy core plus bounded multi-project/client manifests, orchestration, evidence aggregation, and additional operational tests. The higher price reflects licensing and operational scope—not stronger detection.

Fresh-extract gate: Firewall 259 tests / 379 subtests; Scanner 385 tests / 523 subtests / 1 expected no-Git skip.

Buy Agency — $30

Included capabilities

  • Complete 176-rule Secret Scanner Engine with explicit bounded Git-history mode.
  • Signed rulepack verification and supported credential-verification paths.
  • Provider-neutral agent workflow for Claude Code, Codex, Cursor, and Aider.
  • Optional Repository Guard and browser-extension policy pack.
  • Redacted evidence and report–diff integrity binding.
  • Deterministic buyer wrapper with product ZIP, SHA-256 sidecar, and edition attestation.

Publicly inspectable evidence

On the published deterministic synthetic corpus, CodeRiskTools correctly classified 120/120 eligible shared detection cases, matched 80/80 intent-policy cases, and matched 40/40 Agent E2E cases. Gitleaks tied CodeRiskTools on the shared 120-case synthetic detection track.

Review methodology, raw results, exact versions, hashes, and reproducibility pack

Important boundaries

This is a focused local review aid, not full SAST, SCA, container security, a complete enterprise AppSec platform, or a security guarantee. It can produce false positives and false negatives. Continue using broader controls where appropriate.

The benchmark is deterministic and synthetic. It is not production efficacy and does not establish broad product superiority. Scanner detection, Firewall policy, and Agent E2E remain separate evidence tracks; no combined-accuracy claim is made. SHA-256 binding is an integrity check, not a signature, MAC, or authenticity proof.

Compare the focused workflow with broader security platforms

The paid workflow advantage

Stop over-scoped AI changes—not just exposed secrets.

CodeRiskTools tied Gitleaks at 120/120 on the shared synthetic secret-detection track. The paid differentiation is the next gate: bind a declared task to a quantitative change budget, run Scanner evidence, and return an auditable ALLOW or BLOCKED decision before the agent’s change is accepted.

Declare the authorization budget

Choose low, medium, or high scope. Each profile limits changed files, added lines, deleted lines, and dependency-file touches.

Enforce it locally

The same deterministic evaluator runs in the CLI, Scanner → Firewall workflow, supported agent hooks, Repository Guard, and Agency batch.

Keep a machine-readable receipt

Observed counters, approved limits, exceeded dimensions, stable Rule IDs, and redacted evidence make the decision reviewable.

Release evidence: v4.2.0 · Professional Firewall 240 tests / 379 subtests · Agency Firewall 259 tests / 379 subtests · deterministic A/B build and fail-closed buyer-wrapper verification passed.

This is workflow and policy-enforcement differentiation—not a claim of better secret-detection accuracy, production efficacy, or broad competitive superiority. Competitors were not scored on this CodeRiskTools-only budget capability, and its result must not be combined with the 120-point shared track.

Loading, please wait…
BACK TO TOP