AI security analysis for your codebase, from your terminal.
CipherAI scans code for vulnerabilities and secrets, links findings into attack chains, generates SBOMs, and can apply fixes. The scanner runs locally without an AI key, and its measured results are published.
What CipherAI does
- Code review:
cipher-ai reviewmatches 20+ OWASP patterns and reports CWE, severity, confidence and a suggested fix. Output as terminal, JSON, SARIF or Markdown. - Secrets and dependencies:
secretschecks 25+ credential patterns.depsscans 7 manifest formats for known CVEs. - Attack chains and zero-day hunting:
attacklinks findings into chains.zerodaylayers anomaly, taint-flow and AI analysis. - Fixes:
fixproposes AI-powered fixes and can open a PR. - Pentesting (beta):
pentestruns an autonomous agent against a live target and reports only findings with a reproducible proof. - Policy and CI: gate only new findings at the thresholds you set, and run everything with
cipher-ai ci. - Private by default: code stays local. Only retrieved chunks go to the model you choose, or point it at a local endpoint for no data egress.
Real output
This is cipher-ai review on a 24-line Flask file with three deliberate bugs, run with no AI key (pattern scanner only). It is a toy file, not a benchmark. Output trimmed to the finding headers.
$ cipher-ai review --path .
[*] Pattern-based scanner found 3 potential issues
[CRITICAL] SQL Injection - String Concatenation CWE-89
app.py:13 row = db.execute("SELECT * FROM users WHERE name = '%s'" % name).fetchone()
[CRITICAL] Command Injection CWE-78
app.py:20 return subprocess.check_output("ping -c 1 " + host, shell=True)
[HIGH] Weak Hash Algorithm - MD5 CWE-328
app.py:24 return hashlib.md5(password.encode()).hexdigest()
Measured results
These come from the benchmark suites in the repo and are recomputed in CI. They describe the static review scanner on the pinned inputs below, not a general accuracy rate.
Honest limits
- It is a pattern and flow-based scanner, not a full dataflow engine. Tracking is mostly within a file.
- 11 of the 34 advisories are missed. They are listed by name in the repo.
- Precision was checked on 12 projects, with few findings outside Laravel, Jekyll, Rails, Gin and Django. Other stacks are not established.
- Three false positives are recorded and still reported.
Install
Prebuilt binaries ship with each release. The installer downloads the release's SHA256SUMS.txt and refuses to install unless the checksum verifies.
Linux and macOS
curl -fsSL https://raw.githubusercontent.com/sandeepannandi/Cipher/master/install.sh -o install.sh
sh install.shInstalls into ~/.local/bin. Linux needs glibc 2.34 or newer.
Windows (PowerShell)
Invoke-WebRequest https://raw.githubusercontent.com/sandeepannandi/Cipher/master/install.ps1 -OutFile install.ps1
powershell -ExecutionPolicy Bypass -File .\install.ps1Windows is not yet tested end to end. The installer passes CI against a stand-in release, but it has not been run against the published release.
First run
cipher-ai setup
cipher-ai review --path .Or build from source: see the quick start. All downloads are on the releases page.
AI providers
AI features work with Groq, OpenAI or Anthropic, or a local or gateway endpoint through CIPHER_AI_BASE_URL. The review scanner works without a key.
FAQ
Does CipherAI need an AI key?
No. The review scanner is pattern and flow based and runs locally without a key. AI features work with Groq, OpenAI or Anthropic, or a local endpoint.
Does my code leave my machine?
Code stays local by default. Only retrieved chunks go to the AI model you choose, or you can point it at a local endpoint for no data egress.
How accurate is it?
On the pinned benchmark it found 23 of 34 published advisory vulnerabilities at the exact line. 61 of 64 decided production findings on 12 projects were real. Eleven advisories are missed and three false positives are recorded. See the methodology.
Which platforms are supported?
Prebuilt binaries ship for Linux, macOS and Windows. The Windows installer is not yet tested end to end against the published release.
What license is it under?
MIT.