pr0h0
Security Tools

CodeGuardian

A local security auditing tool combining static analysis, existing security scanners, AI-assisted source review, vulnerability triage, and structured reporting.

CodeGuardian is a Docker-first local CLI for security-focused code review. It indexes a repository, stores structured findings in SQLite, runs established scanners, builds small context packs and can optionally ask an LLM to triage the evidence. Results are written as Markdown, JSON and SARIF reports.

It is deliberately scoped: it does not perform autonomous exploitation, remote crawling or unrestricted shell execution, and it never sends a whole repository to an LLM. Deterministic reports work without any API keys.

Key features

  • Scanner integration: Semgrep CE, Gitleaks, Trivy, OSV-Scanner and Bearer, run in Docker, plus built-in pattern, taint-lite and configuration checks
  • Optional AI triage with OpenAI, Anthropic, DeepSeek or OpenRouter, routing findings to low/medium/high model tiers and reporting token usage and cost
  • Reports with baseline diffs, fix-first ordering, CWE/OWASP metadata, dependency reachability hints and suppressions
  • Resumable workspaces for long static scans
  • Project configuration for focus paths, vulnerability classes, severity overrides and rules of engagement
  • Safety model: secrets and tokens are redacted, dynamic testing defaults to localhost, and state-changing requests require explicit approval