All resources
Topic

source-analysis

12 resources across 4 kinds

Tools

  1. is-maliciouscloud costpassive

    MIT-licensed Node CLI that sends a project's selected source, config, build, and CI files to TypeSafe Jev and reports suspicious files and line ranges with probabilities; needs a TypeSafe API key and spends paid input tokens.

    Open ↗
  2. Jev Security Scancloud costhostedopt-inpassive

    MIT-licensed Python CLI and Claude Code/Codex skill that reviews Agent Skills, MCP config and source code for suspicious behavior before installation: offline by default, or nine-category Jev triage with a TypeSafe API key.

    Open ↗

Frameworks & agents

  1. Protect AI tool for finding vulnerabilities in Python source-available targets; authors note difficulty getting reliable structured output from current local/open models.

    Open ↗
  2. Vul-RAG, a knowledge-level retrieval-augmented-generation framework for LLM-based vulnerability detection: it extracts vulnerability knowledge from CVEs into a knowledge base and uses it to judge whether given code is vulnerable. Ships the LinuxVul benchmark (4,667 vulnerable/patched function pairs from 2,174 Linux-kernel CVEs across the top-10 CWEs); the authors report finding 10 previously-unknown kernel bugs, 6 receiving CVE assignments.

    Open ↗
  3. MIT Claude Code plugin bundling 62 slash-command skills across OWASP, STRIDE, PASTA, LINDDUN, MITRE ATT&CK and CWE Top 25, plus six red-team persona agents, for reviewing a codebase and generating fixes.

    Open ↗
  4. Claude Security (plugin)cloud costlicencepassive

    Claude Code plugin that runs a team of agents to scan a repository or diff for vulnerabilities, independently verifies each finding, and writes Markdown, JSONL and SARIF reports plus optional patch files left for review.

    Open ↗
  5. Claude Code plugin that hooks Edit/Write, end-of-turn, and git commit to flag ~25 dangerous code patterns and run LLM diff reviews for injection, XSS, SSRF, IDOR, and hardcoded secrets in generated code.

    Open ↗
  6. Agent-Skills pack for AI coding agents, generated largely from open-source Semgrep rules: secure-coding guidance across 15+ languages, OWASP LLM Top 10 (2025) guidance, and Semgrep scanning plus custom-rule authoring.

    Open ↗
  7. A Claude Code plugin marketplace of security-analysis, testing and development skills — smart-contract vulnerability scanners, C/C++ and Rust security code review, Semgrep and YARA rule authoring, constant-time and zeroization checks — loadable in Claude Code, Codex or a ChatGPT workspace.

    Open ↗

Benchmarks

  1. Large-scale benchmark for source analysis and PoC generation.

    Open ↗
  2. An OpenSSF benchmark containing code and metadata for over 200 real-life CVEs, with tooling to evaluate Static Analysis Security Testing (SAST) solutions by measuring vulnerability detection rates and false positives against vulnerable/patched open-source code.

    Open ↗

Security models

  1. VulnLLM-R-7Bserved here

    Apache-2.0 Qwen2.5 derivative specializing in source-code vulnerability detection and data/control-flow reasoning across C/C++/Python with CodeQL-assisted context.

    In catalog →