{"repo":"nyx-sec/nyx","free":true,"listed":false,"github":"https://github.com/nyx-sec/nyx","clone":"git clone https://github.com/nyx-sec/nyx.git","description":"Multi-language static analysis with cross-file taint tracking. Scan your repo, triage findings in your browser, commit triage state with your code. No cloud, no account.","language":"Rust","stars":38,"topics":["ast-analysis","cli-tool","code-analysis","code-security","developer-tools","multi-language","rust","sast","security-scanner","security-tools"],"license":"GPL-3.0","category":"dev-tools","readme_excerpt":"A local-first security scanner with sandboxed dynamic verification and a browser UI. Scan your repo and triage in your browser, with no cloud and no account. English · 简体中文 --- Scan locally, browse locally Nyx runs cross-language taint analysis on your repository, then verifies Medium or higher confidence findings by running small sandboxed harnesses against the real code. Results are served to a React UI bound to 127.0.0.1 . You get severity, static evidence, dynamic verdicts, and a step-by-step flow visualiser that walks the dataflow from source → sanitizer → sink. Triage decisions persist to .nyx/triage.json , which commits alongside your code so the team shares one triage state. Everything stays on your machine: loopback-only bind, host-header enforcement, CSRF on every mutation, no remote telemetry, no login. --- What's in the UI Page What it shows --- --- Overview Dashboard: finding counts by severity, top offenders, engine profile summary Findings Browsable list with severity badges, triage status, rule filter, language filter Finding detail Flow-path visualiser with numbered steps (source → sanitizer → sink), dynamic verdicts, code snippets, evidence, cross-file markers, triage dropdown Triage Bulk update states (open, investigating, fixed, false positive, accepted risk, suppressed), audit trail, import/export JSON Explorer File tree with per-file symbol list and finding overlay Scans Run history, metrics, diff two scans to see what changed Rules Built-in and custom r","default_branch":null,"files":null,"tree":[],"storefront":"/r/nyx-sec","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/nyx-sec/nyx/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}