Skip to main content

AI code security review: an adversarial diff-audit engine and an agent-driven whole-repo review methodology, with security knowledge as rich rules

Project description

codejury

AI code security review, in two paths matched to their nature:

  • Diff review (coded): audit a pull request's diff for newly introduced, exploitable risks. A single balanced LLM call (the default), or an adversarial Finder/Challenger/Judge pass that trades roughly 3x the cost for extra recall on subtle, cross-cutting flaws.
  • Whole-repo review (agent-driven): a methodology an interactive agent (Claude Code, Codex) runs to map a codebase's attack surface, trace inputs to sinks across files, verify issues with a real PoC, and iterate over rounds with a persistent memory. Too large for a single LLM call, so codejury ships the methodology and scaffolds the workspace rather than running a pipeline.

Security knowledge lives in rich rules (codejury/data/rules/*.md, with per-language vulnerable/secure examples), injected into the audit prompt, not buried in code.

Install

pip install codejury                 # core
pip install "codejury[anthropic]"    # or [openai] / [litellm] for a backend

Diff review

# audit a diff file
codejury review diff --diff-file changes.diff

# audit a git range in a repo
codejury review diff --repo /path/to/app --git-range origin/main...HEAD

# from stdin
git diff HEAD~1 | codejury review diff

# adversarial mode: Finder + Challenger + Judge (extra recall on subtle flaws, ~3x cost)
codejury review diff --diff-file changes.diff --mode adversarial

# CI gate + SARIF
codejury review diff --diff-file changes.diff --format sarif --fail-on high

Configure a backend with --provider/--model/--api-key/--api-base or the CODEJURY_API_KEY / CODEJURY_MODEL / CODEJURY_API_BASE environment variables. codejury review diff --dry-run exercises the engine with a mock provider and no key (it uses a built-in demo diff when you do not pass one).

Choosing a model and mode

Detection quality is dominated by the model first, then the mode. On real-diff probes:

  • A strong model (Claude Sonnet tier) in standard mode caught every planted vulnerability with near-zero false positives. A weaker model raised false positives in both modes, so the model is the lever that matters most.
  • Adversarial mode did not lower false positives over standard on those probes and costs ~3x. Reach for it for extra recall on subtle, cross-file logic, not as a false-positive reducer.

Default to standard mode with a strong model (set it with --model or CODEJURY_MODEL). False positives are held down by the do-not-report list and the post-filter, not by the mode.

Use in CI (GitHub Actions)

Audit every pull request and surface findings in the code scanning tab. Copy examples/codejury-pr-review.yml into .github/workflows/, add a CODEJURY_API_KEY repo secret, and it will:

  1. diff the PR against its base (--git-range origin/<base>...HEAD),
  2. write SARIF and upload it with github/codeql-action/upload-sarif,
  3. fail the check on a HIGH or CRITICAL finding (--fail-on high).

The job makes one model call per PR (standard mode). The SARIF is uploaded even when the gate fails, so findings always show up on the PR.

Whole-repo review

codejury review repo /path/to/your/repo

This scaffolds a review workspace (entrypoints/, issues/, analysis/, and a security-review-memory.md), seeds the entrypoint inventory from a deterministic scan, and prints the methodology. Run it with an interactive agent: it reads the methodology and the rules, maps the attack surface, traces inputs to sinks across files, records high-confidence issues with a PoC, and asks you to confirm credentials or false positives along the way. Nothing runs against production.

Findings

Each finding carries a file and line, a severity and category, a concrete exploit scenario, a recommendation, and a confidence. A false-positive filter drops test/mock-path and low-confidence noise. The model is also told not to report dependency CVEs, style notes, speculation, or config-leak-only risks.

Extending

Add a vulnerability class by dropping a new codejury/data/rules/<class>.md with the standard frontmatter (title, impact, tags, triggers) and vulnerable/secure examples. It is data, no code change needed.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

codejury-0.17.1.tar.gz (57.0 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

codejury-0.17.1-py3-none-any.whl (62.3 kB view details)

Uploaded Python 3

File details

Details for the file codejury-0.17.1.tar.gz.

File metadata

  • Download URL: codejury-0.17.1.tar.gz
  • Upload date:
  • Size: 57.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for codejury-0.17.1.tar.gz
Algorithm Hash digest
SHA256 43adb0a8f5ebaf79b886b5c15e51477cd2394f8848206b1e3e828eb5876f3813
MD5 355a8f573db878d386e5ab82fbddd9d4
BLAKE2b-256 4bebe754e7691207f3bbc124dfa8410cbf96a8cb1f924f62c18994657badf2f2

See more details on using hashes here.

Provenance

The following attestation bundles were made for codejury-0.17.1.tar.gz:

Publisher: publish.yml on aiseclabs/codejury

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file codejury-0.17.1-py3-none-any.whl.

File metadata

  • Download URL: codejury-0.17.1-py3-none-any.whl
  • Upload date:
  • Size: 62.3 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for codejury-0.17.1-py3-none-any.whl
Algorithm Hash digest
SHA256 6ed0e4f6d8a675c24b23f752d353219b2cd1d63139ab223c25a2b2799d7fcb11
MD5 417db9a63f49fb8bd61da2861abe807e
BLAKE2b-256 c26492e09a6ea91c7dcf53c1197991e6e3d3d49d30edb8bc20193ba680edc96c

See more details on using hashes here.

Provenance

The following attestation bundles were made for codejury-0.17.1-py3-none-any.whl:

Publisher: publish.yml on aiseclabs/codejury

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page