Vigilo
Vigilo is a fast, zero-configuration static security scanner for Python. It detects exploitable vulnerability patterns (CWEs) in first-party code using AST traversal combined with local data-flow analysis to minimize false positives.
Runs across Linux, macOS, and Windows — either via pip or as a standalone binary with no Python installation required.
Why Vigilo?
- High-Signal over High-Noise: Traditional linters (like Bandit) flag safe string constants and standard library calls indiscriminately. Vigilo uses local data-flow analysis to distinguish harmless constants from untrusted dynamic inputs.
- Zero Configuration: Drop it directly into your workflow or CI pipeline with
vigilo scan .orvigilo .. No YAML rule authoring or database setup required. - Zero Runtime Dependencies: Built strictly on Python's standard library. Lightweight and instantaneous.
- First-Party Code Focus: While tools like
pip-auditscan third-party dependencies for CVEs, Vigilo scans your code for logic and injection flaws.
Installation & Quickstart
Option A: Install via PyPI (Python 3.10+)
pip install vigilo
Option B: Standalone Executable (No Python Required)
Pre-built standalone single-file executables are available for Linux, macOS, and Windows on the Releases Page:
- Linux (x86_64):
vigilo-linux-x86_64 - macOS:
vigilo-macos - Windows (x86_64):
vigilo-windows-x86_64.exe
Verifying Checksums
Every release includes a SHA256SUMS.txt file to verify binary integrity:
# Verify checksum on Linux/macOS
sha256sum -c SHA256SUMS.txt
Note on Antivirus Alerts: Standalone executables are bundled with PyInstaller. Some heuristic antivirus engines or Windows SmartScreen may occasionally flag newly published PyInstaller binaries as unfamiliar. This is a known false positive with packed binaries. You can verify the integrity using the SHA256 checksum or install via
pip install vigiloto run from source.
Usage
Scan the current directory:
vigilo scan .
Or use the shortcut alias:
vigilo .
Generate structured JSON output for CI/CD pipelines:
vigilo scan . --format json
Filter by minimum severity:
vigilo scan . --min-severity high
Include code correctness diagnostics (syntax errors, undefined names, unclosed resources):
vigilo scan . --correctness
# or run the dedicated diagnose subcommand:
vigilo diagnose .
Exclude specific directories or glob patterns:
vigilo scan . --exclude "tests/*" --exclude "migrations/*"
Python API
from vigilo import scan
# Security scan (default)
findings = scan("src/")
# Security + Correctness scan
all_findings = scan("src/", include_correctness=True)
for finding in findings:
print(
f"[{finding.severity.upper()}] {finding.detector.id} {finding.detector.name} ({finding.detector.category})"
)
print(f" Location: {finding.location}")
print(f" Fix: {finding.fix_hint}")
Supported Detectors
Security Vulnerabilities (Default)
| ID | CWE | Vulnerability | Severity | Target APIs |
|---|---|---|---|---|
VIGILO-001 |
CWE-89 | SQL Injection | HIGH |
db.execute(), cursor.execute(), text(), raw() |
VIGILO-002 |
CWE-78 | OS Command Injection | HIGH |
subprocess.*(shell=True), os.system(), os.popen() |
VIGILO-003 |
CWE-94 | Code Injection | HIGH |
eval(), exec(), compile() |
VIGILO-004 |
CWE-502 | Unsafe Deserialization | HIGH |
pickle.loads(), yaml.load(), marshal.loads() |
VIGILO-005 |
CWE-22 | Path Traversal | HIGH |
open(), os.open(), io.open() |
Code Correctness Diagnostics (Opt-In with --correctness or diagnose)
| ID | Issue | Severity | Description |
|---|---|---|---|
VIGILO-C01 |
Syntax & Indentation Error | HIGH |
Python parse failure or bad indentation |
VIGILO-C02 |
Undefined Name Usage | MEDIUM |
Use of unbound or misspelled variable/name |
VIGILO-C03 |
Unused Import / Variable | LOW |
Unused imported module or assigned local variable |
VIGILO-C04 |
Unclosed File Resource | MEDIUM |
Raw open() call without context manager (with) |
VIGILO-C05 |
Bare Except Clause | MEDIUM |
Blanket except: catch masking critical errors |
CLI Reference
usage: vigilo [-h] [--version] {scan,diagnose} ... [target] [--format {text,json}]
[--min-severity {low,medium,high}] [--exclude EXCLUDE] [--correctness]
[--no-color]
Commands:
scan Scan target directory or file for security vulnerabilities
diagnose Run code correctness diagnostics (syntax, undefined names, resources)
Options:
target Directory or file to scan (default: '.')
--format, -f Output report format: 'text' or 'json' (default: 'text')
--min-severity, -s Minimum severity threshold: 'low', 'medium', 'high' (default: 'low')
--correctness, -c Include code correctness diagnostics alongside security checks
--exclude, -e Exclude path matching glob pattern (repeatable)
--no-color Disable ANSI terminal coloring
--version, -V Show version and exit
--help, -h Show help and exit
Exit Codes
| Code | Meaning |
|---|---|
0 |
Clean — no vulnerabilities found at or above --min-severity |
1 |
Vulnerabilities detected |
2 |
Execution or path error |
Contributing
We welcome contributions! Please review our Contributing Guide, Code of Conduct, and Security Policy.
License
Distributed under the MIT License. Copyright (c) 2026 Sanjiv - Vigilo.
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file vigilo-0.2.1.tar.gz.
File metadata
- Download URL: vigilo-0.2.1.tar.gz
- Upload date:
- Size: 36.3 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
8871955f076f9aa7f3ec49114ea86810caf87cbbb4b9c6846e033079dd4071cd
|
|
| MD5 |
1e2882509bc49e52a5d58894a193960e
|
|
| BLAKE2b-256 |
4a1842d5a92fc853d987195048cacbce97c4df8569d47e900aa580339cd36b92
|
Provenance
The following attestation bundles were made for vigilo-0.2.1.tar.gz:
Publisher:
release.yml on Sanjiv215/VIGILO-Python-Package
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
vigilo-0.2.1.tar.gz -
Subject digest:
8871955f076f9aa7f3ec49114ea86810caf87cbbb4b9c6846e033079dd4071cd - Sigstore transparency entry: 2723921712
- Sigstore integration time:
-
Permalink:
Sanjiv215/VIGILO-Python-Package@94f8577f199a66260569712a657c48acfce0d401 -
Branch / Tag:
refs/tags/v0.2.1 - Owner: https://github.com/Sanjiv215
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@94f8577f199a66260569712a657c48acfce0d401 -
Trigger Event:
push
-
Statement type:
File details
Details for the file vigilo-0.2.1-py3-none-any.whl.
File metadata
- Download URL: vigilo-0.2.1-py3-none-any.whl
- Upload date:
- Size: 30.6 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
823247fbf0c913facb2b2e6ea6ffde8c9a0ce3ff9e7758d62c93e65c10fcd133
|
|
| MD5 |
c654426e81115da972d6b1e1eb1dd2ca
|
|
| BLAKE2b-256 |
e61456e628b9ef91d63237c79e7430a11e78af8bd2cfe7707fa82969057919c2
|
Provenance
The following attestation bundles were made for vigilo-0.2.1-py3-none-any.whl:
Publisher:
release.yml on Sanjiv215/VIGILO-Python-Package
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
vigilo-0.2.1-py3-none-any.whl -
Subject digest:
823247fbf0c913facb2b2e6ea6ffde8c9a0ce3ff9e7758d62c93e65c10fcd133 - Sigstore transparency entry: 2723921802
- Sigstore integration time:
-
Permalink:
Sanjiv215/VIGILO-Python-Package@94f8577f199a66260569712a657c48acfce0d401 -
Branch / Tag:
refs/tags/v0.2.1 - Owner: https://github.com/Sanjiv215
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@94f8577f199a66260569712a657c48acfce0d401 -
Trigger Event:
push
-
Statement type: