{"repo":"momenbasel/vulnhawk","free":true,"listed":false,"github":"https://github.com/momenbasel/vulnhawk","clone":"git clone https://github.com/momenbasel/vulnhawk.git","description":"AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.","language":"Python","stars":81,"topics":["ai","appsec","claude","code-security","llm","python","sast","security","vulnerability-scanner","code-review"],"license":null,"category":"security-tools","readme_excerpt":"AI-powered code security scanner that finds vulnerabilities Semgrep and CodeQL miss. &nbsp; &nbsp; &nbsp; Quick Start &bull; GitHub Action &bull; Comparison &bull; Languages &bull; FAQ --- The Problem Traditional SAST tools rely on pattern matching and AST rules. They excel at catching known vulnerability patterns, but they fundamentally cannot reason about intent . If your API has 20 endpoints and 19 of them verify authorization before acting on a resource, Semgrep has no way to flag the one that doesn't - because there is no pattern to match against. The vulnerability is the absence of a pattern. The Solution VulnHawk analyzes code with AI, and for every piece of code it examines, it includes related code from elsewhere in your codebase as context. This enrichment step lets the AI compare how similar components handle security - and spot the one that doesn't. --- Quick Start Choose a backend: No config files. No rules to write. No database to build. Claude Code and Codex backends are free for users with existing subscriptions. VulnHawk pipes prompts through your local CLI, so there are no additional API costs. --- VulnHawk vs Other SAST Tools Capability VulnHawk Semgrep CodeQL Snyk Code Checkmarx SonarQube :--- :---: :---: :---: :---: :---: :---: Detection method AI reasoning AST patterns QL data flow ML + rules Patterns + flow Patterns Business logic flaws Yes No Limited Limited Limited No Cross-file context Automatic Custom rules Custom queries Partial Paid tier Limited S","default_branch":null,"files":null,"tree":[],"storefront":"/r/momenbasel","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/momenbasel/vulnhawk/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}