Skip to main content

AI code security review: an adversarial diff-audit engine and an agent-driven whole-repo review methodology, with security knowledge as rich rules

Project description

codejury

AI code security review, in two paths matched to their nature:

  • Diff review (coded): audit a pull request's diff for newly introduced, exploitable risks. A single balanced LLM call, or an adversarial Finder/Challenger/Judge pass for higher coverage and fewer false positives.
  • Whole-repo review (agent-driven): a methodology an interactive agent (Claude Code, Codex) runs to traverse a codebase from its API entrypoints, verify issues with a real PoC, and iterate over rounds with a persistent memory. Too large for a single LLM call, so codejury ships the methodology and scaffolds the workspace rather than running a pipeline.

Security knowledge lives in rich rules (codejury/data/rules/*.md, with per-language vulnerable/secure examples), injected into the audit prompt, not buried in code.

Install

pip install codejury                 # core
pip install "codejury[anthropic]"    # or [openai] / [litellm] for a backend

Diff review

# audit a diff file
codejury review diff --diff-file changes.diff

# audit a git range in a repo
codejury review diff --repo /path/to/app --git-range origin/main...HEAD

# from stdin
git diff HEAD~1 | codejury review diff

# adversarial mode: Finder + Challenger + Judge (higher coverage, lower FP, ~3x cost)
codejury review diff --diff-file changes.diff --mode adversarial

# CI gate + SARIF
codejury review diff --diff-file changes.diff --format sarif --fail-on high

Configure a backend with --provider/--model/--api-key/--api-base or the CODEJURY_API_KEY / CODEJURY_MODEL / CODEJURY_API_BASE environment variables. codejury review diff --dry-run exercises the engine with a mock provider and no key (it uses a built-in demo diff when you do not pass one).

Whole-repo review

codejury review repo /path/to/your/repo

This scaffolds a review workspace (api/, issues/, analysis/, and a security-review-memory.md), seeds the API inventory from a deterministic scan, and prints the methodology. Run it with an interactive agent: it reads the methodology and the rules, traverses the code from its API entrypoints, records high-confidence issues with a PoC, and asks you to confirm credentials or false positives along the way. Nothing runs against production.

Findings

Each finding carries a file and line, a severity and category, a concrete exploit scenario, a recommendation, and a confidence. A false-positive filter drops test/mock-path and low-confidence noise; the model is also told not to report dependency CVEs, style notes, speculation, or config-leak-only risks.

Extending

Add a vulnerability class by dropping a new codejury/data/rules/<class>.md with the standard frontmatter (title, impact, tags, triggers) and vulnerable/secure examples. It is data; no code change needed.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

codejury-0.14.0.tar.gz (52.2 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

codejury-0.14.0-py3-none-any.whl (57.5 kB view details)

Uploaded Python 3

File details

Details for the file codejury-0.14.0.tar.gz.

File metadata

  • Download URL: codejury-0.14.0.tar.gz
  • Upload date:
  • Size: 52.2 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for codejury-0.14.0.tar.gz
Algorithm Hash digest
SHA256 4a0440b85b827be970d92b2dc9effcb077a45f2a3ea832f6ef27c79e9f7360b4
MD5 9d4393f6606b556223c0e7fcc8005d0c
BLAKE2b-256 b063b8d9f9253033173cb1ab57d75ffc691e534810a856cccf2f4953a578330c

See more details on using hashes here.

Provenance

The following attestation bundles were made for codejury-0.14.0.tar.gz:

Publisher: publish.yml on aiseclabs/codejury

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file codejury-0.14.0-py3-none-any.whl.

File metadata

  • Download URL: codejury-0.14.0-py3-none-any.whl
  • Upload date:
  • Size: 57.5 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for codejury-0.14.0-py3-none-any.whl
Algorithm Hash digest
SHA256 94043b2396b6750b889724e6da116ad69e868e88d265f326e13973b479b13588
MD5 0a66bc37dae32fd5a45859b1ee5513b3
BLAKE2b-256 97082dab31a9983c1a276ff2eb3e1bc29ce7bdbce5dea689d1a16466583e03b2

See more details on using hashes here.

Provenance

The following attestation bundles were made for codejury-0.14.0-py3-none-any.whl:

Publisher: publish.yml on aiseclabs/codejury

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page