← All agents
Code Security Scan
Scans a snippet for hardcoded secrets, injection-prone patterns and unsafe APIs, with a concrete fix for each finding.
Free run returns your 3 most severe findings. No signup, no card.
Your code is analysed in memory and never stored, logged, or sent to a model provider. Don't paste live production secrets — if a key appears in a finding, rotate it.
What it looks for
- Hardcoded secrets — API keys, tokens, private keys, connection strings
- Injection risk — string-built SQL, shell and HTML sinks
- Unsafe APIs — eval, deserialisation, disabled TLS verification
- Weak crypto and insecure randomness for security-sensitive values
These are pattern checks over the text you paste, not a compiler or a taint analysis. They catch the mistakes that recur in review — they cannot prove the absence of a vulnerability, and a clean result is not a security audit. For that, talk to us.