AI code security review: an adversarial diff-audit engine and an agent-driven whole-repo review methodology, with security knowledge as rich rules
Project description
codejury
AI code security review, in two paths matched to their nature:
- Diff review (coded): audit a pull request's diff for newly introduced, exploitable risks. A single balanced LLM call, or an adversarial Finder/Challenger/Judge pass for higher coverage and fewer false positives.
- Whole-repo review (agent-driven): a methodology an interactive agent (Claude Code, Codex) runs to traverse a codebase from its API entrypoints, verify issues with a real PoC, and iterate over rounds with a persistent memory. Too large for a single LLM call, so codejury ships the methodology and scaffolds the workspace rather than running a pipeline.
Security knowledge lives in rich rules (codejury/data/rules/*.md, with
per-language vulnerable/secure examples), injected into the audit prompt, not
buried in code.
Install
pip install codejury # core
pip install "codejury[anthropic]" # or [openai] / [litellm] for a backend
Diff review
# audit a diff file
codejury audit --diff-file changes.diff
# audit a git range in a repo
codejury audit --repo /path/to/app --git-range origin/main...HEAD
# from stdin
git diff HEAD~1 | codejury audit
# adversarial mode: Finder + Challenger + Judge (higher coverage, lower FP, ~3x cost)
codejury audit --diff-file changes.diff --mode adversarial
# CI gate + SARIF
codejury audit --diff-file changes.diff --format sarif --fail-on high
Configure a backend with --provider/--model/--api-key/--api-base or the
CODEJURY_API_KEY / CODEJURY_MODEL / CODEJURY_API_BASE environment variables.
codejury dry-run exercises the engine with a mock provider and no key.
Whole-repo review
codejury full-review /path/to/your/repo
This scaffolds a review workspace (api/, issues/, analysis/, and a
security-review-memory.md), seeds the API inventory from a deterministic scan,
and prints the methodology. Run it with an interactive agent: it reads the
methodology and the rules, traverses the code from its API entrypoints, records
high-confidence issues with a PoC, and asks you to confirm credentials or false
positives along the way. Nothing runs against production.
Findings
Each finding carries a file and line, a severity and category, a concrete exploit scenario, a recommendation, and a confidence. A false-positive filter drops test/mock-path and low-confidence noise; the model is also told not to report dependency CVEs, style notes, speculation, or config-leak-only risks.
Extending
Add a vulnerability class by dropping a new codejury/data/rules/<class>.md with
the standard frontmatter (title, impact, tags, triggers) and vulnerable/secure
examples. It is data; no code change needed.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file codejury-0.13.2.tar.gz.
File metadata
- Download URL: codejury-0.13.2.tar.gz
- Upload date:
- Size: 51.1 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
a6f326113861d05fb2fef5ab9227b1196715681ba69b5a47467de3c887b1ce7d
|
|
| MD5 |
bca0b8d838b17828455b92e6a891a7c6
|
|
| BLAKE2b-256 |
ceb6a1e75862902fcf76fa9887f9fa0aa3c07bea4cd7ed603e79f36a75beebfb
|
Provenance
The following attestation bundles were made for codejury-0.13.2.tar.gz:
Publisher:
publish.yml on aiseclabs/codejury
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
codejury-0.13.2.tar.gz -
Subject digest:
a6f326113861d05fb2fef5ab9227b1196715681ba69b5a47467de3c887b1ce7d - Sigstore transparency entry: 1702756378
- Sigstore integration time:
-
Permalink:
aiseclabs/codejury@8eb032c7b5fa805ecfe3f3639ad06ad224dd363a -
Branch / Tag:
refs/tags/v0.13.2 - Owner: https://github.com/aiseclabs
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish.yml@8eb032c7b5fa805ecfe3f3639ad06ad224dd363a -
Trigger Event:
release
-
Statement type:
File details
Details for the file codejury-0.13.2-py3-none-any.whl.
File metadata
- Download URL: codejury-0.13.2-py3-none-any.whl
- Upload date:
- Size: 57.0 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
2e66afe78122ad32e0343bbb3711e2c44c123255cd90ff7c46c39e6ebf20205b
|
|
| MD5 |
0976d2559f6a1d708f6d5548d4cb78ae
|
|
| BLAKE2b-256 |
297b86f7e2d93ab0871f2c95e56a50478ab2480dda2925dea30181e66282857f
|
Provenance
The following attestation bundles were made for codejury-0.13.2-py3-none-any.whl:
Publisher:
publish.yml on aiseclabs/codejury
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
codejury-0.13.2-py3-none-any.whl -
Subject digest:
2e66afe78122ad32e0343bbb3711e2c44c123255cd90ff7c46c39e6ebf20205b - Sigstore transparency entry: 1702756448
- Sigstore integration time:
-
Permalink:
aiseclabs/codejury@8eb032c7b5fa805ecfe3f3639ad06ad224dd363a -
Branch / Tag:
refs/tags/v0.13.2 - Owner: https://github.com/aiseclabs
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish.yml@8eb032c7b5fa805ecfe3f3639ad06ad224dd363a -
Trigger Event:
release
-
Statement type: