Skip to main content

⚡ Emgena Repo Scanner (emgena-scan)

100% Offline Static AST Security & SRE Incident Scanner for Python & Cloud Infrastructure.
Zero Telemetry • Zero External Network Calls • Sub-0.15ms AST Analysis per Rule.

Python 3.9+ License: Apache 2.0 Zero Dependency


🚀 Quickstart

Run instantly with uvx (zero install):

uvx emgena-scan .

Or install via pip:

pip install emgena-scan
emgena-scan .

Or run via Python module:

python -m emgena_scan .

🔍 What It Scans (Top-10 Production Incidents)

emgena-scan uses Python's standard library ast module to perform real semantic static analysis (not brittle regex matches). It catches:

  1. RULE_FASTAPI_SYNC_CRYPTO (CRITICAL): Synchronous CPU-bound hashing (hmac, hashlib, bcrypt) inside async def routes, blocking the main event loop.
  2. RULE_BLOCKING_HTTP_IN_ASYNC (CRITICAL): Synchronous requests.get() or urllib inside async def, causing thread starvation under load.
  3. RULE_SQLALCHEMY_UNCLOSED_ASYNC_SESSION (CRITICAL): Leaked database sessions without async with or generator contexts, exhausting the QueuePool in minutes.
  4. RULE_REDIS_CLUSTER_CROSSSLOT (HIGH): Multi-key Redis commands (mget, pipeline) lacking hash tags ({...}), causing immediate CROSSSLOT cluster crashes.
  5. RULE_CELERY_SUBTASK_BLOCKING_GET (HIGH): Calling .get() on subtasks inside Celery worker functions, causing cascading prefork deadlocks.
  6. RULE_DOCKER_PRIVILEGED_SOCKET_MOUNT (CRITICAL): Containers mounting /var/run/docker.sock with privileged: true, violating CIS Docker Benchmark 5.3.
  7. RULE_SUBPROCESS_SHELL_TRUE_INJECTION (CRITICAL): Invoking subprocess with shell=True and formatted string variables (CWE-78 Command Injection).
  8. RULE_UNBOUNDED_DB_FETCHALL (MEDIUM): Raw .fetchall() on SQL queries without limits or chunk iteration, risking OOMKilled crashes.
  9. RULE_BARE_EXCEPT_PASS_SILENCING (MEDIUM): except: pass silencing critical infrastructure exceptions.
  10. RULE_THREADING_THREAD_UNBOUNDED_SPAWN (HIGH): Unbounded threading.Thread.start() in API handlers without bounded threadpools.

💻 CLI Options

emgena-scan [OPTIONS] [PATH]

Arguments:
  PATH               Directory or file to scan (default: current directory)

Options:
  --json             Output machine-readable JSON for CI/CD pipelines
  --quiet, -q        Only output summary line and exit code
  --ignore-rules     Comma-separated list of rule IDs to ignore
  --version, -v      Show version
  --help, -h         Show help message

Exit Codes for CI/CD

  • 0: Clean (no critical or high violations found)
  • 1: One or more violations detected
  • 2: Syntax or invocation error

⚡ Live Protection While You Code

Want to catch these issues in real time while typing in your editor?

Install the turnkey Emgena SRE MCP Guards for Cursor IDE & Claude Desktop: 👉 https://emgena.com/trainingslager

  • 100% Offline stdio MCP Engine
  • Real-time <thought> and AST diagnosis inside Cursor IDE
  • Instant Vorher/Nachher remediation diffs with 0 syntax errors

Metadata

Release files for emgena-scan 1.0.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for emgena-scan 1.0.0
File Size Uploaded
emgena_scan-1.0.0.tar.gz 13.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for emgena-scan 1.0.0
File Interpreter ABI Platform
emgena_scan-1.0.0-py3-none-any.whl Python 3 none any Details

Total release size: 25.9 kB

Release files / emgena_scan-1.0.0.tar.gz

Download URL emgena_scan-1.0.0.tar.gz
Size 13.1 kB
Tags Source
SHA-256 checksum
How to use checksums
ffeda4573ff3712f881aa50fb0d6fa29b2b685ba07ff9aed69104206ca9a3cef
BLAKE2b-256 checksum
How to use checksums
da40d285d8b0fecf277a6b7967cb3ff988ab68393ece7617fcdb5a3a02cddf42
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.10.20

Release files / emgena_scan-1.0.0-py3-none-any.whl

Download URL emgena_scan-1.0.0-py3-none-any.whl
Size 12.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
2e1441682745bc794243139b581762915110ddd1095689f89ad1cec67aab4f47
BLAKE2b-256 checksum
How to use checksums
c2ca852e9dd73e5033d3fbd294a1f55671026478a748a435af16ed4c9961f3db
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.10.20

Release history Release notifications | RSS feed

This release

1.0.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page