The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the SecHelix listing page.
Most AI security tools try to find more. SecHelix tries to prove itself wrong.
Every candidate finding goes to an independent verifier whose only job is to disprove it. The
report shows you what it refuted and why — and returns INCOMPLETE rather than a clean PASS when
it could not actually check.
Open source, Apache-2.0, for code you own or are authorized to test. Runs in Claude Code, Codex, Copilot and other Agent Skills-compatible agents; the Python runtime is optional.
It helps a coding agent:
A small multi-tenant API with two candidate issues. One is a real cross-tenant read that a scanner walks past, because the endpoint does have an authorization check — it just checks the wrong thing. The other is f-string SQL that every pattern matcher flags and that is not exploitable at all.
Walkthrough, root cause, the two-line fix and the regression proof: examples/expense-api.
Or take the same test in your browser — ten cases, three of them decoys, no signup: Can you tell the real bug from the decoy?
Recommended for Agent Skills-compatible coding agents:
Then open the repository you want to review in your coding agent. The skill installs instructions and data only — no executable code. The optional runtime below is a separate, explicit install.
A compact edition, sechelix-lite, is a single runtime-free review skill (about 200 lines plus
five references) for skill directories and hosts where a small context footprint matters. See
docs/distribution/awesome-copilot.md.
Copy this into your agent:
Use this before launching an AI-generated, agent-generated, rapidly prototyped, or vibe-coded application:
The launch profile covers practical pre-release failures around secrets, auth/authz, cross-user data, database/storage permissions, debug exposure, input validation, SQL/NoSQL injection, XSS/CSRF, uploads, traversal, SSRF, password reset, sessions/JWT, CORS, rate limiting, staging, default credentials, webhooks, payments/entitlements, IDOR/BOLA, sensitive logs, and production artifacts.
More copy-paste workflows: Command Cookbook.
| Goal | Ask for |
|---|---|
| Full repository review | complete security audit |
| Quick first pass | security triage |
| AI-built/vibe-coded app before launch | AI-Built App Launch Audit |
| Broken access control | authorization / IDOR / BOLA audit |
| Login and sessions | authentication / session / OAuth audit |
| Input handling | injection / XSS / SSRF / files audit |
| Payments and workflows | business logic / race / idempotency audit |
| Dependencies and CI | supply chain / CI/CD audit |
| LLMs, agents and tools | AI / Agent / MCP security audit |
| A code change | PR security review |
| Existing verified issues | Fix Mode |
| Release decision | release gate |
| Shareable output | security report |
You do not need to memorize special slash commands. SecHelix is primarily a skill: tell the coding agent what security job you want done.
A scanner match or model suspicion is treated as a candidate, not automatically as a vulnerability.
A strong finding should show the affected surface, attacker control or security boundary involved, reachability, impact, root cause, safe evidence, the fix, and regression/retest status.
PASS means the release-gate rules found no unresolved blocking
condition in what was reviewed, not that the software has no vulnerabilities.VERIFIED was one of the known defects
(report). Precision is NOT_MEASURED.LIKELY_BUT_UNPROVEN or HYPOTHESIS. It does not make a model see a bug it cannot reason
about.The Agent Skill works without the Python runtime. The runtime is optional and adds stored runs, coverage tracking, replayable evidence, reports, CI-friendly exit codes, and an MCP adapter.
Install it with:
uv tool install sechelix and python -m pip install sechelix are also supported.
| Command | What it does |
|---|---|
sechelix doctor | Shows available components and reasoning executors |
sechelix audit . --executor claude-code | Runs an audit using Claude Code as the reasoning executor |
sechelix audit . --executor gemini-cli | Runs an audit using Gemini CLI as the reasoning executor |
sechelix runs | Lists saved runs and checks their integrity |
sechelix coverage | Shows what previous runs did not examine |
sechelix report | Renders the latest saved run |
sechelix replay <run_id> | Replays a recorded run offline and checks consistency |
sechelix mcp . | Serves the local MCP adapter over stdio |
Example:
sechelix audit .with the default--executor noneintentionally does not pretend to analyze code. Reasoning nodes are blocked and the run remains incomplete until a real executor is configured.
For all CLI flags:
Advanced runtime guide: V4 Runtime Quickstart.
Outputs PASS, PASS_WITH_KNOWN_RISK, BLOCKED or INCOMPLETE, writes SARIF
for code scanning, and uploads the run as an artifact. The default
executor: none deliberately reports INCOMPLETE rather than a green check it
did not earn — configure a reasoning executor to get an actual review.
Full reference: GitHub Action.
Seven tools over a root you choose, no shell, no network. Six only read; sechelix_audit writes
only a run workspace inside that root. The root is the security boundary: point it at the
repository under review, not at your home directory.
Reference: MCP adapter.
| Mode | Use it for |
|---|---|
STATIC | Source, configuration and schema review without dynamic traffic |
LOCAL | Safe dynamic proof against a local app and fixtures |
STAGING | Explicitly authorized non-production testing |
PRODUCTION_SAFE | Bounded, non-destructive verification only |
Only test systems you own or are explicitly authorized to assess. See SECURITY.md.
Depending on the workflow and available runtime, SecHelix can produce:
PASS, PASS_WITH_KNOWN_RISK, BLOCKED, or INCOMPLETE.Start with the practical docs and use the deeper material only when you need it:
The repository also contains detailed schemas, catalogs, adapters, evaluation fixtures and research material. They support the framework; you do not need to read them to start using SecHelix.
Apache-2.0. See LICENSE.