codescan — security grade SAFE, quality 75/100

Security audit verdict: SAFE · quality 75/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by codescan-ai · Agent Tool · ★ 65

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is codescan safe to install? View the security audit →

About codescan

CodeScanAI CodeScanAI utilizes a variety of AI models to scan your codebase for security vulnerabilities. It leverages powerful LLM models to identify risks and provide actionable remediation suggestions. The currently supported AI providers include: OpenAI, Google Gemini, and custom self-hosted AI servers (Ollama, etc.). It has been designed to integrate seamlessly into CI/CD pipelines like GitHub Actions, or can be used via a simple CLI command locally. Check out the detailed demo and setup and try it out today! What's new in v0.1.2 Pydantic-AI agent scanner: Files are now scanned one at a time by a structured AI agent, returning typed output instead of a raw markdown string. Inline PR review comments: When running a PR scan, findings are posted as inline review comments directly on the relevant line in the diff. Falls back to a regular issue comment for architectura

aiautomationcode-scanningsecurity-tools

Quick Facts

Stars65
Forks6
LanguagePython
CategoryAgent Tool
LicenseMIT
Quality Score74.9975763504957/100
Open Issues7
Last Updated2026-08-17
Created2024-08-25
Platformsgemini, python
Est. Tokens~8k

Compatible Skills

These tools work well together with codescan for enhanced workflows:

  • medusa — semantic(0.20)+complementary+rare_topics+same_lang+similar_pop+shared_platform (57%)
  • communitytools — semantic(0.20)+complementary+rare_topics+same_lang+similar_pop+shared_platform (57%)
  • mcp-audit — semantic(0.22)+complementary+same_lang+similar_pop+shared_platform (53%)
  • skill-security-scan — semantic(0.22)+complementary+same_lang+similar_pop+shared_platform (53%)

codescan alternative? Top 6 similar tools

Looking for a codescan alternative? If you're comparing codescan with other agent tool tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • sudocode by sudocode-ai · ⭐ 292

    Lightweight agent orchestration dev tool that lives in your repo

  • AutoRedTeam-Orchestrator by Coff0xc · ⭐ 263

    MCP-native security automation workbench (SDK + CLI + MCP) — authorized testing + static AI/MCP attack-surface

  • Awesome-AI-For-Security by AmanPriyanshu · ⭐ 145

    A curated list of tools, papers, and datasets for applying AI to cybersecurity tasks. This list primarily focu

  • code-pathfinder by shivasurya · ⭐ 140

    Static Code Analysis for security teams with Inter file taint analysis. Built for finding vulnerabilities, adv

  • clampdown by 89luca89 · ⭐ 98

    Run AI coding agents in hardened container sandboxes.

  • claude-emporium by Vvkmnn · ⭐ 82

    🏛 [UNDER CONSTRUCTION] A (roman) claude plugin marketplace

More Agent Tool Tools

Explore other popular agent tool tools:

View all Agent Tool tools →

Popular Python Agent Tools

Frequently Asked Questions

What is codescan?

codescan is CodeScanAI is an open source tool that utilizes powerful AI models (OpenAI, Gemini, and even self-hosted servers) to scan your codebase for possible security vulnerabilities.. It is categorized as a Agent Tool with 65 GitHub stars.

What programming language is codescan written in?

codescan is primarily written in Python. It covers topics such as ai, automation, code-scanning.

How do I install or use codescan?

You can find installation instructions and usage details in the codescan GitHub repository at github.com/codescan-ai/codescan. The project has 65 stars and 6 forks, indicating an active community.

What license does codescan use?

codescan is released under the MIT license, making it free to use and modify according to the license terms.

What are the best alternatives to codescan?

The top alternatives to codescan on Agent Skills Hub include sudocode, AutoRedTeam-Orchestrator, Awesome-AI-For-Security. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse Agent Tool tools