LOCAL REVIEW AID · V4.2.0 · PROFESSIONAL + AGENCY
Turn AI-generated changes into an explicit Scanner → Firewall decision.
CodeRiskTools combines a 176-rule Secret Scanner Engine with intent-aware AI Change Firewall policy. Provide declared intent and a unified diff—or a supported agent event—and receive redacted Scanner evidence, integrity binding, and a final ALLOW or BLOCKED decision for human review.
One local, evidence-first workflow
- Declare allowed scope and operations in an intent manifest.
- Provide the corresponding unified diff or invoke a supported Claude Code, Codex, Cursor, or Aider entrypoint.
- Run the bundled Secret Scanner Engine and produce redacted Scanner evidence.
- Bind the exact report and diff with SHA-256 for integrity and consistency—not authenticity.
- Evaluate scope, dependency, CI, security-control, and infrastructure policy, then return ALLOW or BLOCKED.
PROFESSIONAL · $19 · AVAILABLE
For one-project workflows
The complete Scanner → Firewall workflow, local agent entrypoints, optional Repository Guard, browser-extension policy pack, source, tests, checksums, and edition attestation.
Fresh-extract gate: Firewall 240 tests / 379 subtests; Scanner 383 tests / 523 subtests / 1 expected no-Git skip.
AGENCY · $30 · AVAILABLE
For authorized multi-project/client operations
The same detection and policy core plus bounded multi-project/client manifests, orchestration, evidence aggregation, and additional operational tests. The higher price reflects licensing and operational scope—not stronger detection.
Fresh-extract gate: Firewall 259 tests / 379 subtests; Scanner 385 tests / 523 subtests / 1 expected no-Git skip.
Included capabilities
- Complete 176-rule Secret Scanner Engine with explicit bounded Git-history mode.
- Signed rulepack verification and supported credential-verification paths.
- Provider-neutral agent workflow for Claude Code, Codex, Cursor, and Aider.
- Optional Repository Guard and browser-extension policy pack.
- Redacted evidence and report–diff integrity binding.
- Deterministic buyer wrapper with product ZIP, SHA-256 sidecar, and edition attestation.
Publicly inspectable evidence
On the published deterministic synthetic corpus, CodeRiskTools correctly classified 120/120 eligible shared detection cases, matched 80/80 intent-policy cases, and matched 40/40 Agent E2E cases. Gitleaks tied CodeRiskTools on the shared 120-case synthetic detection track.
Review methodology, raw results, exact versions, hashes, and reproducibility pack
Important boundaries
This is a focused local review aid, not full SAST, SCA, container security, a complete enterprise AppSec platform, or a security guarantee. It can produce false positives and false negatives. Continue using broader controls where appropriate.
The benchmark is deterministic and synthetic. It is not production efficacy and does not establish broad product superiority. Scanner detection, Firewall policy, and Agent E2E remain separate evidence tracks; no combined-accuracy claim is made. SHA-256 binding is an integrity check, not a signature, MAC, or authenticity proof.
Compare the focused workflow with broader security platforms
The paid workflow advantage
Stop over-scoped AI changes—not just exposed secrets.
CodeRiskTools tied Gitleaks at 120/120 on the shared synthetic secret-detection track. The paid differentiation is the next gate: bind a declared task to a quantitative change budget, run Scanner evidence, and return an auditable ALLOW or BLOCKED decision before the agent’s change is accepted.
Choose low, medium, or high scope. Each profile limits changed files, added lines, deleted lines, and dependency-file touches.
The same deterministic evaluator runs in the CLI, Scanner → Firewall workflow, supported agent hooks, Repository Guard, and Agency batch.
Observed counters, approved limits, exceeded dimensions, stable Rule IDs, and redacted evidence make the decision reviewable.
This is workflow and policy-enforcement differentiation—not a claim of better secret-detection accuracy, production efficacy, or broad competitive superiority. Competitors were not scored on this CodeRiskTools-only budget capability, and its result must not be combined with the 120-point shared track.