Deterministic Abstract Syntax Tree taint analysis combined with contextual OpenRouter AI verification, continuous AutoGrad offline self-learning memory, and zero-Docker pre-deployment infrastructure gates. Built as a privacy-respecting, zero-data-leakage alternative to commercial SaaS code reviewers.
npx github:kaunteyaarjun/code_inspection_tool scan .import { Request, Response } from "express";
import { pool } from "../database/connection";
// Insecure: Hardcoded sensitive secret in source tree
const JWT_SECRET = "sk-live-9941a80c9bfe412e84177d612e3";
export async function loginHandler(req: Request, res: Response) {
const { username, password } = req.body;
// CodeSentry AST Taint: Untrusted req.body concatenated directly into SQL sink
const rawQuery = `SELECT * FROM users WHERE username = '${username}' AND password = '${password}'`;
const result = await pool.query(rawQuery);
if (result.rows.length === 0) {
return res.status(401).json({ error: "Invalid credentials" });
}
return res.json({ token: JWT_SECRET, user: result.rows[0] });
}Untrusted variable 'username' flows from req.body into SQL statement without AST parameterized abstraction.
Hardcoded production credential literal detected by CodeSentry secrets scanner.
AutoGrad aggregates static AST syntax trees, OWASP taint propagation matrices, and algorithmic memory leak signatures into a continuous 0–100 score and letter grade (A+ through F).
Maintains commit-by-commit security velocity in ~/.codesentry/autograd-history.json. Flags pull requests that degrade overall codebase posture (▼ -2% degraded) or praise improvements (▲ +4% improved).
Stores accepted remediation diffs in ~/.codesentry/autograd-memory.json. When identical syntactic flaws reappear across microservices, AutoGrad synthesizes fixes with 0ms latency and 0 cloud API calls.
When a codebase is clean (0 static flaws), CodeSentry queries OpenRouter free models (poolside/laguna-s-2.1:free) to provide proactive architectural hardening suggestions exported to AI-SECURITY-SUGGESTIONS.md.
Pre-deployment readiness analyzer and CI/CD policy enforcer. Evaluates 0–100% deployment readiness and executes strict binary verdicts (PASSED, WARNING, BLOCKED).
:latest tags, and secrets in ENV/ARG.codesentry deployguard .CLI CommandSpecialized security engine engineered specifically for LLM applications, autonomous agent workflows, and RAG retrieval pipelines.
codesentry scan . --severity HIGHOWASP LLM Top 10$ codesentry scan .
┌────────────────────────────────────────────────────────┐
│ CodeSentry v1.2.0 • Deterministic AST & AI Engine │
└────────────────────────────────────────────────────────┘
✔ Scanned 128 source files across JS, TS, and Python (14,200 AST nodes)
✔ Taint Dataflow Solver: 0 CWE sink violations in production paths
✔ AutoGrad Score: 96/100 (Grade A+) [Trend: ▲ +4% vs last commit]
✔ Offline Memory: 3 patterns resolved via ~/.codesentry/autograd-memory.json (0ms)
➔ All Quality and Security Gates PASSED (Exit Code: 0)
name: CodeSentry Security Gate
on:
push:
branches: [ main, master ]
pull_request:
branches: [ main, master ]
jobs:
security-audit:
name: CodeSentry SAST Inspection
runs-on: ubuntu-latest
steps:
- name: Check out code
uses: actions/checkout@v4
- name: Set up Node.js
uses: actions/setup-node@v4
with:
node-version: 20
- name: Run CodeSentry Scan
run: npx github:kaunteyaarjun/code_inspection_tool scan . --severity HIGH
env:
OPENROUTER_API_KEY: ${{ secrets.OPENROUTER_API_KEY }}