I have spent a lot of time building Aqiron Security.
Then I realized something uncomfortable:
I know how it behaves on my machine. I don't know how it behaves in the hands of developers I have never met.
That's the part I want to change.
Aqiron Security is an open-source, local-first application security tool that currently runs as a VS Code extension, with an initial focus on Flutter workspaces.
The idea is simple:
Instead of making a developer jump between several security tools, output formats, terminals, and dashboards, Aqiron tries to bring the workflow into one place.
But the project is still early.
Scan
Findings
Generated pdf

and there goes.. the remaining images of the pdfs generated(sample) are one aqiron security repo README.md
And that's exactly why I'm writing this.
The security workflow I wanted
A typical project can involve completely different tools for:
static analysis
dependency vulnerabilities
leaked secrets
mobile security testing
custom security rules
AI-assisted analysis
reports
The problem isn't that these tools don't exist.
The problem is what happens between them.
Different output formats.
Different severity models.
Different workflows.
Different places to investigate a finding.
Aqiron's current architecture is built around a TypeScript core that the VS Code extension communicates with through a separate Node.js process:
VS Code Extension
↓
Core Client / Process Manager
↓
stdin/stdout IPC
↓
Aqiron Core
↓
Scanners → Findings → Correlation → AI/RAG → Reports
The goal is to keep the security runtime independent from the UI while giving developers a fast workflow inside VS Code.
What exists today
Aqiron can currently scan supported Flutter workspaces or individual files and expose findings through VS Code and the Aqiron interface.
The implementation includes native security rules plus optional integrations such as:
Betterleaks
OSV-Scanner
Semgrep OSS
Trivy
MobSF
It can normalize and correlate findings, build a relationship graph, maintain workspace intelligence through RAG, and generate JSON, SARIF, and PDF report artifacts.
There are also optional AI workflows through Ollama or OpenRouter.
The project is local-first, and those external scanners and AI providers remain optional.
I'm deliberately saying current because some ideas are still future work.
Then I rebuilt the interface
Recently I stopped adding features for a moment and asked a different question:
Would I actually want to use this every day?
The answer was not initially good enough.
So I redesigned the major workflows.
Scan
The Scan workflow now follows a simpler progression:
Workspace
↓
Target
↓
Scan mode
↓
Start scan
↓
Execution
↓
Results
Findings
The findings screen became a triage workspace instead of a basic list.
Search, severity, source, status, file/line context, evidence, remediation information, and finding actions are surfaced around the actual security result.
Reports
The reporting workflow now exposes PDF, JSON, and SARIF outputs alongside the assessment context and report history.
The PDF itself is intended to look like an actual security assessment rather than a raw export of scanner output.
Agent
The AI interface was redesigned as part of the same workspace instead of feeling like a completely separate feature.
Workspace and Settings
I also rebuilt the workspace-entry and Settings experience so configuring the project and security tooling feels like part of the same application.
But here's the problem
All of that is still mostly being developed by one person.
And that's dangerous for a security project.
A security tool can look polished while still having:
missing detection rules
false positives
false negatives
awkward developer workflows
scanner integration problems
weak tests
poor documentation
platform-specific bugs
assumptions that only make sense on the maintainer's machine
I can keep adding features.
That's not necessarily what Aqiron needs next.
It needs other developers trying to use it.
I don't want you to just star the repository
Honestly, a star would be nice.
But it isn't the thing I'm looking for.
I'd rather have someone open an issue and say:
"This workflow doesn't make sense."
or:
"This scanner should catch this."
or:
"I tried this on my Flutter project and found a bug."
or even:
"Why did you design the architecture this way?"
Those conversations are much more valuable than a silent star.
Where contributors could actually help
You don't need to understand the entire codebase before contributing.
There are several directions that would be useful:
Security rules
Find a vulnerability pattern Aqiron currently misses and propose or implement a rule.
Scanner integrations
Improve an existing scanner integration or help make another security tool fit into Aqiron's normalized finding model.
False positives
Take a finding that shouldn't have been reported and help make the detection more precise.
Tests
Add regression tests around scanners, finding normalization, workspace behavior, IPC, or UI workflows.
UI/UX
Try the extension like a real developer and point out where the workflow feels confusing, slow, or unnecessary.
Documentation
Improve setup instructions, scanner configuration, examples, or contributor onboarding.
You don't have to start by rewriting the core.
I'd actually prefer a small, focused pull request that teaches us something.
The part I'm curious about
The project started with Flutter because that's where I wanted to solve the problem first.
But I'm increasingly interested in a bigger question:
Can a developer-focused security workflow have one common security runtime while supporting multiple clients?
Today the main client is VS Code.
The architecture is intentionally moving toward a model where the security core can eventually serve other clients without making the core itself depend on VS Code.
That could eventually mean:
` Aqiron Security Core
/ | \
VS Code CLI Desktop`
But that's future architecture, not the current repository structure.
Right now, I want to make the existing system good enough that other developers actually want to use it.
So I'm opening the door
Aqiron Security is early.
That means there are plenty of things that can be improved.
It also means a contributor can have a real impact on the direction of the project instead of becoming one tiny commit in a repository with thousands of contributors.
I'm looking for developers interested in:
security + TypeScript + VS Code + Flutter + developer tooling + AI-assisted security
You can inspect the code, run it, criticize it, open an issue, improve documentation, add a test, add a rule, improve an integration, or send a pull request.
I want the project to become better because other developers used it and challenged the assumptions behind it.
Aqiron Security
GitHub: https://github.com/Aqiron-Security/aqiron-security
If you are interested, don't just tell me that the idea is cool.
Try to break something.
That's probably the most useful contribution you can make right now.





Top comments (2)
How does Aqiron preserve scanner-specific evidence after findings are normalized into one model?
That’s a good question.
The normalized finding is meant to provide Aqiron Security’s common fields for things like severity, location, rule/source, description, remediation, and metadata, but we don’t want normalization to erase the context that made the scanner useful in the first place.
The workflow is essentially:
scanner-specific result → normalization/enrichment → common Aqiron Security finding → UI/reporting
The finding still carries the evidence/source context that Aqiron Security can surface for investigation, while the common fields let us correlate findings from different scanners consistently.
One thing I’m still being careful about is how much scanner-specific raw output we should retain versus expose directly. I’d rather keep that boundary explicit than make the normalized model a dumping ground for every tool’s schema.
That’s actually an area I’d like to improve further, especially around preserving provenance/evidence across correlation and reports. If you have a particular scanner architecture in mind, I’d be interested in how you’d model that.
Note: Aqiron Security is the security project/product; Aqiron is the broader organization behind it.