SPEC // AST-DEVSECOPS-02•100% SELF-HOSTED & PURE NODE.JS
TEST SUITE: 97/97 PASSING (30 SUITES)

Zero-Dependency DevSecOps & AI Code Inspection Engine.

Deterministic Abstract Syntax Tree taint analysis combined with contextual OpenRouter AI verification, continuous AutoGrad offline self-learning memory, and zero-Docker pre-deployment infrastructure gates. Built as a privacy-respecting, zero-data-leakage alternative to commercial SaaS code reviewers.

ArchitecturePure Node.js (≥18)
Daemon DependencyZero Docker Daemon
Languages ScannedJS, TS & Python AST
Offline Memory0ms Repeat Pattern Hit
Clone on GitHub: kaunteyaarjun/code_inspection_toolLaunch Live SAST Simulator
$npx github:kaunteyaarjun/code_inspection_tool scan .
// 01 — INTERACTIVE INSPECTION SIMULATOR

Deterministic AST Taint Analysis.

SELECT SAMPLE TARGET CODEBASE BELOW
controllers/auth.ts
VULNERABILITY DETECTED
import { Request, Response } from "express";
import { pool } from "../database/connection";

// Insecure: Hardcoded sensitive secret in source tree
const JWT_SECRET = "sk-live-9941a80c9bfe412e84177d612e3";

export async function loginHandler(req: Request, res: Response) {
  const { username, password } = req.body;

  // CodeSentry AST Taint: Untrusted req.body concatenated directly into SQL sink
  const rawQuery = `SELECT * FROM users WHERE username = '${username}' AND password = '${password}'`;
  const result = await pool.query(rawQuery);

  if (result.rows.length === 0) {
    return res.status(401).json({ error: "Invalid credentials" });
  }

  return res.json({ token: JWT_SECRET, user: result.rows[0] });
}
ENGINE: PURE NODE.JS AST
AUTOGRAD TELEMETRYSTATUS: UNRESOLVED FLAWS
DGRADE
Security Invariant Score:38/100
Threshold: 85 (CI Gate)GATE: BLOCKED
DETECTED FINDINGS (2)
SQL Injection via Template Literal (AST Taint)CRITICAL
Line 11•CWE-89

Untrusted variable 'username' flows from req.body into SQL statement without AST parameterized abstraction.

Hardcoded Cryptographic Token LiteralHIGH
Line 5•CWE-798

Hardcoded production credential literal detected by CodeSentry secrets scanner.

ATTACKGRAPH EXPLOIT TRACECWE DATAFLOW SOLVER
01.Ingress: POST /api/v1/login (req.body.username)
02.AST Taint: Unsanitized string interpolation into rawQuery
03.Sink: pool.query(rawQuery) execution
04.Exploit: Bypass authentication with ' OR '1'='1
// 02 — CONTINUOUS RISK GRADING

AutoGrad & Offline Self-Learning.

CANONICAL SCORING INVARIANT
FORMAL CONTINUOUS RISK FUNCTION
S_AutoGrad = 0.40 · S_security + 0.25 · S_bugs + 0.20 · S_efficiency + 0.15 · S_resources

AutoGrad aggregates static AST syntax trees, OWASP taint propagation matrices, and algorithmic memory leak signatures into a continuous 0–100 score and letter grade (A+ through F).

Security Weight40% (OWASP Top 10)
Logic Bugs25% (CFG Solvers)
Efficiency20% (O(N^2) Bottlenecks)
Resource Leaks15% (Timers / Event Listeners)
01. Historical Trend Tracking

Maintains commit-by-commit security velocity in ~/.codesentry/autograd-history.json. Flags pull requests that degrade overall codebase posture (▼ -2% degraded) or praise improvements (▲ +4% improved).

02. 0ms Offline Self-Learning

Stores accepted remediation diffs in ~/.codesentry/autograd-memory.json. When identical syntactic flaws reappear across microservices, AutoGrad synthesizes fixes with 0ms latency and 0 cloud API calls.

03. Contextual OpenRouter AI Triage

When a codebase is clean (0 static flaws), CodeSentry queries OpenRouter free models (poolside/laguna-s-2.1:free) to provide proactive architectural hardening suggestions exported to AI-SECURITY-SUGGESTIONS.md.

// 03 — PRE-DEPLOYMENT GATES & LLM DEFENSE

DeployGuard & ModelShield.

COMPREHENSIVE SUBSYSTEM DEFENSE

DeployGuard Engine

INFRASTRUCTURE GATE

Pre-deployment readiness analyzer and CI/CD policy enforcer. Evaluates 0–100% deployment readiness and executes strict binary verdicts (PASSED, WARNING, BLOCKED).

  • ✦Container Security: Flags root users, unpinned :latest tags, and secrets in ENV/ARG.
  • ✦CI/CD Workflow Audits: Enforces immutable commit SHAs for GitHub Actions and blocks untrusted pull_request_target.
  • ✦Config Guard: Intercepts committed .env credentials, DEBUG=True flags, and permissive wildcard CORS.
codesentry deployguard .CLI Command

ModelShield Engine

AI / LLM / RAG DEFENSE

Specialized security engine engineered specifically for LLM applications, autonomous agent workflows, and RAG retrieval pipelines.

  • ✦Prompt Injection Defense: Flags un-sanitized user strings directly concatenated into LLM system prompts.
  • ✦Model Deserialization Protection: Intercepts insecure weight loading via pickle or unconstrained torch.load.
  • ✦Agent Sandbox Guards: Flags dynamic tool functions executing eval or shell commands directly on AI outputs.
codesentry scan . --severity HIGHOWASP LLM Top 10
// 04 — DEVELOPER WORKFLOWS & CLI

Interactive Terminal Experience.

ZERO INSTALL VIA NPX OR GLOBAL NPM
$ codesentry scan .
┌────────────────────────────────────────────────────────┐
│ CodeSentry v1.2.0 • Deterministic AST & AI Engine │
└────────────────────────────────────────────────────────┘
✔ Scanned 128 source files across JS, TS, and Python (14,200 AST nodes)
✔ Taint Dataflow Solver: 0 CWE sink violations in production paths
✔ AutoGrad Score: 96/100 (Grade A+) [Trend: ▲ +4% vs last commit]
✔ Offline Memory: 3 patterns resolved via ~/.codesentry/autograd-memory.json (0ms)
➔ All Quality and Security Gates PASSED (Exit Code: 0)
// 05 — CI/CD AUTOMATION

GitHub Actions Policy Gate.

FAIL PRS INTRODUCING SECURITY FLAWS
.github/workflows/codesentry.yml
name: CodeSentry Security Gate

on:
  push:
    branches: [ main, master ]
  pull_request:
    branches: [ main, master ]

jobs:
  security-audit:
    name: CodeSentry SAST Inspection
    runs-on: ubuntu-latest
    steps:
      - name: Check out code
        uses: actions/checkout@v4

      - name: Set up Node.js
        uses: actions/setup-node@v4
        with:
          node-version: 20

      - name: Run CodeSentry Scan
        run: npx github:kaunteyaarjun/code_inspection_tool scan . --severity HIGH
        env:
          OPENROUTER_API_KEY: ${{ secrets.OPENROUTER_API_KEY }}