Skip to main content

Critik

Security scanner for vibe-coded apps. Catch what Copilot ships and Snyk overcharges for.

pip install critik
critik scan .

What it catches

  • Hardcoded secrets — AWS keys, API tokens, database URLs, private keys (16 patterns)
  • SQL injection — f-strings and string concatenation in execute() calls
  • Command injection — eval(), exec(), os.system(), subprocess with shell=True
  • XSS vectors — dangerouslySetInnerHTML, document.write(), eval() in JS
  • Missing auth — FastAPI/Express routes without authentication middleware
  • Insecure config — DEBUG=True, CORS wildcard, insecure cookies
  • Exposed .env — real secrets in .env files, missing .gitignore entries

Usage

# Scan current directory
critik scan .

# Scan specific path
critik scan ./src

# JSON output (for CI/CD)
critik scan . --format json

# Only show critical and high
critik scan . --severity high

# Quiet mode (summary only)
critik scan . --quiet

Exit codes

  • 0 — No critical or high findings
  • 1 — Critical or high findings detected
  • 2 — Scanner error

Supported languages

  • Python (.py)
  • JavaScript (.js, .jsx)
  • TypeScript (.ts, .tsx)
  • Environment files (.env)
  • Config files (.json, .yaml, .toml)

Ignore patterns

Create a .critikignore file in your project root:

# Skip test fixtures
tests/fixtures/*
# Skip generated code
generated/*

GitHub Action

Add to .github/workflows/critik.yml:

name: Critik
on: [push, pull_request]
jobs:
  scan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: actions/setup-python@v5
        with:
          python-version: '3.12'
      - run: pip install critik
      - run: critik scan .

For GitHub Code Scanning integration (findings appear inline on PRs):

      - run: critik scan . --format sarif > critik.sarif
      - uses: github/codeql-action/upload-sarif@v3
        with:
          sarif_file: critik.sarif

Why Critik?

53% of teams that shipped AI-generated code discovered security issues that passed review. The vibe coding era needs a security scanner that's:

  • Fast — scans in milliseconds, not minutes
  • Offline — no API calls, no code leaving your machine
  • Free — open source, zero dependencies
  • Focused — catches real issues, not style nits

License

MIT

Metadata

Release files for critik 0.4.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for critik 0.4.0
File Size Uploaded
critik-0.4.0.tar.gz 34.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for critik 0.4.0
File Interpreter ABI Platform
critik-0.4.0-py3-none-any.whl Python 3 none any Details

Total release size: 79.3 kB

Release files / critik-0.4.0.tar.gz

Download URL critik-0.4.0.tar.gz
Size 34.1 kB
Tags Source
SHA-256 checksum
How to use checksums
779b9e86f5528c601f68dbb5a1de407c983ce66ed6bf259c3765145943e344be
BLAKE2b-256 checksum
How to use checksums
0cf0ae999ce46cced40292896e2296b1e3e4030322132afb46169e3a98c2cc3b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.12.3

Release files / critik-0.4.0-py3-none-any.whl

Download URL critik-0.4.0-py3-none-any.whl
Size 45.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
a0d046db55d157274ce7245188ebf2347b58edd342704e21f905ab0cf9f2ba83
BLAKE2b-256 checksum
How to use checksums
f7983db9425c005f9dc41d3b5d1e6aafbc1522342aae1744c268629aac252857
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.12.3

Release history Release notifications | RSS feed

This release

0.4.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page