source-analysis
12 resources across 4 kinds
Tools
- Open ↗is-maliciouscloud costpassive
MIT-licensed Node CLI that sends a project's selected source, config, build, and CI files to TypeSafe Jev and reports suspicious files and line ranges with probabilities; needs a TypeSafe API key and spends paid input tokens.
- Open ↗Jev Security Scancloud costhostedopt-inpassive
MIT-licensed Python CLI and Claude Code/Codex skill that reviews Agent Skills, MCP config and source code for suspicious behavior before installation: offline by default, or nine-category Jev triage with a TypeSafe API key.
Frameworks & agents
- Open ↗
Vul-RAG, a knowledge-level retrieval-augmented-generation framework for LLM-based vulnerability detection: it extracts vulnerability knowledge from CVEs into a knowledge base and uses it to judge whether given code is vulnerable. Ships the LinuxVul benchmark (4,667 vulnerable/patched function pairs from 2,174 Linux-kernel CVEs across the top-10 CWEs); the authors report finding 10 previously-unknown kernel bugs, 6 receiving CVE assignments.
- Open ↗AppSec (florianbuetow)passive
MIT Claude Code plugin bundling 62 slash-command skills across OWASP, STRIDE, PASTA, LINDDUN, MITRE ATT&CK and CWE Top 25, plus six red-team persona agents, for reviewing a codebase and generating fixes.
- Open ↗Claude Security (plugin)cloud costlicencepassive
Claude Code plugin that runs a team of agents to scan a repository or diff for vulnerabilities, independently verifies each finding, and writes Markdown, JSONL and SARIF reports plus optional patch files left for review.
- Open ↗Security Guidance (Claude Code plugin)cloud costlicence
Claude Code plugin that hooks Edit/Write, end-of-turn, and git commit to flag ~25 dangerous code patterns and run LLM diff reviews for injection, XSS, SSRF, IDOR, and hardcoded secrets in generated code.
- Open ↗Semgrep Agent Skillslicence
Agent-Skills pack for AI coding agents, generated largely from open-source Semgrep rules: secure-coding guidance across 15+ languages, OWASP LLM Top 10 (2025) guidance, and Semgrep scanning plus custom-rule authoring.
- Open ↗
A Claude Code plugin marketplace of security-analysis, testing and development skills — smart-contract vulnerability scanners, C/C++ and Rust security code review, Semgrep and YARA rule authoring, constant-time and zeroization checks — loadable in Claude Code, Codex or a ChatGPT workspace.
Benchmarks
- Open ↗
An OpenSSF benchmark containing code and metadata for over 200 real-life CVEs, with tooling to evaluate Static Analysis Security Testing (SAST) solutions by measuring vulnerability detection rates and false positives against vulnerable/patched open-source code.
Security models
- In catalog →VulnLLM-R-7Bserved here
Apache-2.0 Qwen2.5 derivative specializing in source-code vulnerability detection and data/control-flow reasoning across C/C++/Python with CodeQL-assisted context.