Skip to main content
Back to all repositories

The open source taint analysis engine for the AI era. A formal dataflow analysis tool you can customize and self-host, built so AI agents drive your application security analysis without burning tokens on every scan. AI-ready open source alternative to Semgrep Pro and CodeQL.

151stars12forks2watchers/subscribers88issues
agentsai-securitycode-qualitycybersecurityhackingjavakotlinoffensive-securitysastsecuritysecurity-automationsecurity-toolsseqraskillsspringstatic-analysistaint-analysisvulnerabilitiesvulnerability-detectionvulnerability-scanners
Language
Kotlin
License
Apache License 2.0
Size
57.2 MB
Created
Sep 30, 2025
Last Updated
Sep 3, 2026
Last Pushed
Sep 3, 2026

Available Plugins

Loading plugins...

Evaluate before installing

  1. Review the source repository, recent maintenance, and license on GitHub.
  2. Read the marketplace manifest and plugin source files before running commands.
  3. Start with the smallest required permission set and validate behavior in a safe environment.