9M6/vulnsink: A CLI tool that wraps SAST scanners and uses LLMs to filter false positives and automatically fix security issues.
github.com·1d·
Discuss: Hacker News
🔍Static Analysis
Preview
Report Post

VulnSink

A CLI tool that wraps SAST scanners and uses LLMs to filter false positives and automatically fix security issues.

Features

  • Run any CLI-based SAST tool (Semgrep, ESLint, Bandit, etc.)

  • Use AI to distinguish true positives from false positives

  • Generate and apply secure code fixes automatically

  • Terminal interface with:

  • Real-time progress indicators with spinners

  • Color-coded severity levels and confidence scores

  • Organized findings with all relevant details

  • Analysis includes reasoning and recommendations

  • JSON output for CI/CD pipelines

  • Automatic backups and dry-run mode

Installation

Install VulnSink globally from npm:

npm install -g vulnsink

Or use it directly with npx without installing:

npx vulnsink scan

Quick Start

Similar Posts

Loading similar posts...

Keyboard Shortcuts

Navigation
Next / previous item
j/k
Open post
oorEnter
Preview post
v
Post Actions
Love post
a
Like post
l
Dislike post
d
Undo reaction
u
Recommendations
Add interest / feed
Enter
Not interested
x
Go to
Home
gh
Interests
gi
Feeds
gf
Likes
gl
History
gy
Changelog
gc
Settings
gs
Browse
gb
Search
/
General
Show this help
?
Submit feedback
!
Close modal / unfocus
Esc

Press ? anytime to show this help