AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.
vulnhawk is easy to set up with trust notes worth reviewing. Check agent compatibility and use-case fit before adding it to your workflow.
gh repo view momenbasel/vulnhawk --webOpen the official repository or website.
Check the README for package manager, auth, and platform requirements.
Try it in a small test task inside your agent workflow.
Repository setup guidance
Strong trust signals; still review the README and permissions before production use.
Last commit was about 92 days ago.
81 GitHub stars indicate community interest.
0 open issues signal maintenance load.
NOASSERTION license detected.
1 security/trust notes recorded.
Setup difficulty is 2/5.
Local GitHub Actions runner for AI agents — test CI/CD workflows locally before pushing.
A CLI tool to create and hide GitHub comments using the GitHub REST API.
Suggests code changes via GitHub multi-line suggestions using reviewdog.
AI-powered GitHub automation for issue triage, PR review, labeling, and security scanning.
<p align="center"> <img src="docs/vulnhawk-banner.png" alt="VulnHawk" width="600"> </p> <p align="center"> <strong>AI-powered code security scanner that finds vulnerabilities Semgrep and CodeQL miss.</strong> </p> <p align="center"> <a href="https://pypi.org/project/vulnhawk/"><img alt="PyPI" src="https://img.shields.io/pypi/v/vulnhawk.svg?style=for-the-badge&label=PyPI&color=3775A9&logo=pypi&logoColor=white"></a> <a href="https://github.com/marketplace/actions/vulnhawk-security-
AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.
81
Stars
18
Forks
0
Issues
NOASSERTION
License
AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.
Developers
The setup section provides repository-level starting guidance, not a guarantee of an independently verified installation. Check the official README and release notes.
Treat findings as triage signals and do not expose private source code or CI credentials to external model providers.
Similar or complementary options to evaluate include Agent-CI, github-comment, action-suggester.
Aug 20, 2026