Critik
Security scanner for vibe-coded apps. Catch what Copilot ships and Snyk overcharges for.
pip install critik
critik scan .
What it catches
- Hardcoded secrets — AWS keys, API tokens, database URLs, private keys (16 patterns)
- SQL injection — f-strings and string concatenation in execute() calls
- Command injection — eval(), exec(), os.system(), subprocess with shell=True
- XSS vectors — dangerouslySetInnerHTML, document.write(), eval() in JS
- Missing auth — FastAPI/Express routes without authentication middleware
- Insecure config — DEBUG=True, CORS wildcard, insecure cookies
- Exposed .env — real secrets in .env files, missing .gitignore entries
Usage
# Scan current directory
critik scan .
# Scan specific path
critik scan ./src
# JSON output (for CI/CD)
critik scan . --format json
# Only show critical and high
critik scan . --severity high
# Quiet mode (summary only)
critik scan . --quiet
Exit codes
0— No critical or high findings1— Critical or high findings detected2— Scanner error
Supported languages
- Python (.py)
- JavaScript (.js, .jsx)
- TypeScript (.ts, .tsx)
- Environment files (.env)
- Config files (.json, .yaml, .toml)
Ignore patterns
Create a .critikignore file in your project root:
# Skip test fixtures
tests/fixtures/*
# Skip generated code
generated/*
GitHub Action
Add to .github/workflows/critik.yml:
name: Critik
on: [push, pull_request]
jobs:
scan:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-python@v5
with:
python-version: '3.12'
- run: pip install critik
- run: critik scan .
For GitHub Code Scanning integration (findings appear inline on PRs):
- run: critik scan . --format sarif > critik.sarif
- uses: github/codeql-action/upload-sarif@v3
with:
sarif_file: critik.sarif
Why Critik?
53% of teams that shipped AI-generated code discovered security issues that passed review. The vibe coding era needs a security scanner that's:
- Fast — scans in milliseconds, not minutes
- Offline — no API calls, no code leaving your machine
- Free — open source, zero dependencies
- Focused — catches real issues, not style nits
License
MIT
Metadata
Release files for critik 0.4.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| critik-0.4.0.tar.gz | 34.1 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| critik-0.4.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 79.3 kB
Release files / critik-0.4.0.tar.gz
| Download URL | critik-0.4.0.tar.gz |
|---|---|
| Size | 34.1 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
779b9e86f5528c601f68dbb5a1de407c983ce66ed6bf259c3765145943e344be
|
|
BLAKE2b-256 checksum How to use checksums |
0cf0ae999ce46cced40292896e2296b1e3e4030322132afb46169e3a98c2cc3b
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.12.3
|
Release files / critik-0.4.0-py3-none-any.whl
| Download URL | critik-0.4.0-py3-none-any.whl |
|---|---|
| Size | 45.2 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
a0d046db55d157274ce7245188ebf2347b58edd342704e21f905ab0cf9f2ba83
|
|
BLAKE2b-256 checksum How to use checksums |
f7983db9425c005f9dc41d3b5d1e6aafbc1522342aae1744c268629aac252857
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.12.3
|