AI-Era Code Security Scanner - catches vulnerabilities AI coding assistants introduce
Project description
🛡️ hackmenot
AI-Era Code Security Scanner
Catches the vulnerabilities AI coding assistants introduce—and fixes them.
The Problem
Over 50% of AI-generated code contains security vulnerabilities. Copilot, Cursor, and Claude Code are transforming how we write software—but they're also introducing patterns that traditional SAST tools weren't built to catch.
hackmenot is purpose-built for the AI era: it detects these vulnerabilities, provides auto-fix suggestions, and explains why AI makes these mistakes so you learn as you secure.
Quick Start
Get scanning in 30 seconds:
# Install via pip
pip install hackmenot
# Or with Docker
docker pull ghcr.io/b0rd3aux/hackmenot:latest
# Scan your code
hackmenot scan .
# Scan with auto-fix
hackmenot scan . --fix
# Scan dependencies for hallucinated packages
hackmenot deps .
That's it. No config files, no setup, no API keys.
Features
Scan & Detect
100+ security rules purpose-built for AI-generated code patterns across Python, JavaScript/TypeScript, Go, and Terraform.
Auto-Fix
Don't just find problems—fix them. Interactive mode lets you review and apply fixes one by one.
hackmenot scan . --fix-interactive
Dependency Scanning
Detect hallucinated packages (dependencies that don't exist), typosquats, and known CVEs.
hackmenot deps . --check-vulns
CI/CD & GitHub Security
Native GitHub Action with SARIF support. Findings appear directly in GitHub's Security tab.
- uses: hackmenot/hackmenot@v1
with:
sarif-upload: 'true'
What It Catches
| Category | Examples | Languages |
|---|---|---|
| Injection | SQL injection, command injection, XSS, path traversal | All |
| Authentication | Missing auth decorators, weak sessions, hardcoded credentials | Python, JS |
| Cryptography | Weak algorithms, hardcoded keys, insecure random | All |
| Data Exposure | Logging secrets, verbose errors, debug mode in prod | All |
| Infrastructure | Open security groups, missing encryption, public S3 buckets | Terraform |
| Dependencies | Hallucinated packages, typosquats, known CVEs | Python, JS |
Installation
pip (recommended)
pip install hackmenot
Docker
# Pull image
docker pull ghcr.io/b0rd3aux/hackmenot:latest
# Scan current directory
docker run --rm -v $(pwd):/workspace ghcr.io/b0rd3aux/hackmenot scan .
From source
pip install git+https://github.com/b0rd3aux/hackmenot.git@v1.0.0
Requires Python 3.10+
Usage
# Basic scan
hackmenot scan .
# Scan specific path
hackmenot scan src/
# Set minimum severity (critical, high, medium, low)
hackmenot scan . --severity medium
# Fail CI on high+ findings
hackmenot scan . --fail-on high
# Output as JSON or SARIF
hackmenot scan . --format json
hackmenot scan . --format sarif
# Auto-fix all issues
hackmenot scan . --fix
# Interactive fix mode
hackmenot scan . --fix-interactive
# Preview fixes without applying
hackmenot scan . --fix --dry-run --diff
# Scan only changed files (great for CI)
hackmenot scan . --changed-since origin/main
# Dependency scanning
hackmenot deps .
hackmenot deps . --check-vulns
Documentation
| Guide | Description |
|---|---|
| Getting Started | First-time setup and basic usage |
| CLI Reference | All commands and options |
| Rules Reference | Complete list of 100+ security rules |
| Configuration | .hackmenot.yml options |
| CI Integration | GitHub Actions, GitLab, Jenkins, and more |
| Custom Rules | Write your own security rules |
| Contributing | How to contribute |
Support
If hackmenot is useful to you, consider supporting its development:
Contributing
Contributions are welcome! See Contributing Guide for details.
License
Apache 2.0 - see LICENSE for details.
Project details
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file hackmenot-1.0.0.tar.gz.
File metadata
- Download URL: hackmenot-1.0.0.tar.gz
- Upload date:
- Size: 69.4 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.7
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
4de910c0f04622435bd866bca805dcac1a4c0f89ddc43e5764d337d68735c11c
|
|
| MD5 |
7cbcc067bf5d587827c101bac2d1120f
|
|
| BLAKE2b-256 |
433a52f879f17d61f378e6a22e9e37cf9b58dbfa7468336e4ff503a2dd2ea0eb
|
Provenance
The following attestation bundles were made for hackmenot-1.0.0.tar.gz:
Publisher:
publish-pypi.yml on b0rd3aux/hackmenot
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
hackmenot-1.0.0.tar.gz -
Subject digest:
4de910c0f04622435bd866bca805dcac1a4c0f89ddc43e5764d337d68735c11c - Sigstore transparency entry: 885708170
- Sigstore integration time:
-
Permalink:
b0rd3aux/hackmenot@026103e798c925f653b9ce39e6d42559a4a8d7c5 -
Branch / Tag:
refs/tags/v1.0.0 - Owner: https://github.com/b0rd3aux
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish-pypi.yml@026103e798c925f653b9ce39e6d42559a4a8d7c5 -
Trigger Event:
release
-
Statement type:
File details
Details for the file hackmenot-1.0.0-py3-none-any.whl.
File metadata
- Download URL: hackmenot-1.0.0-py3-none-any.whl
- Upload date:
- Size: 128.2 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.7
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
4a1246f116a9337dd6141fa7906a0d8159c775b72aa2f48fe1f03c8c4c6ed899
|
|
| MD5 |
52270fdb9a9a6c9439a4674de12da7fb
|
|
| BLAKE2b-256 |
072ba1bceb88759c7c58d6b4ce792e4fa0b405ab0e2a48c3f93b108af0eb3a35
|
Provenance
The following attestation bundles were made for hackmenot-1.0.0-py3-none-any.whl:
Publisher:
publish-pypi.yml on b0rd3aux/hackmenot
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
hackmenot-1.0.0-py3-none-any.whl -
Subject digest:
4a1246f116a9337dd6141fa7906a0d8159c775b72aa2f48fe1f03c8c4c6ed899 - Sigstore transparency entry: 885708266
- Sigstore integration time:
-
Permalink:
b0rd3aux/hackmenot@026103e798c925f653b9ce39e6d42559a4a8d7c5 -
Branch / Tag:
refs/tags/v1.0.0 - Owner: https://github.com/b0rd3aux
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish-pypi.yml@026103e798c925f653b9ce39e6d42559a4a8d7c5 -
Trigger Event:
release
-
Statement type: