<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Amirthavarshini Marimuthu</title>
    <description>The latest articles on DEV Community by Amirthavarshini Marimuthu (@amir09).</description>
    <link>https://dev.to/amir09</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4169471%2Fb45690e2-f730-4121-88c7-e5d0f806d546.jpg</url>
      <title>DEV Community: Amirthavarshini Marimuthu</title>
      <link>https://dev.to/amir09</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/amir09"/>
    <language>en</language>
    <item>
      <title>SecFoo — I Caught Our Security Scanner Inventing Fake Vulnerabilities — Here's the Proof!</title>
      <dc:creator>Amirthavarshini Marimuthu</dc:creator>
      <pubDate>Wed, 07 Oct 2026 16:31:51 +0000</pubDate>
      <link>https://dev.to/amir09/secfoo-i-caught-our-security-scanner-inventing-fake-vulnerabilities-heres-the-proof-1hak</link>
      <guid>https://dev.to/amir09/secfoo-i-caught-our-security-scanner-inventing-fake-vulnerabilities-heres-the-proof-1hak</guid>
      <description>&lt;h2&gt;
  
  
  &lt;strong&gt;What is Secfoo?&lt;/strong&gt;
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://github.com/secfoo-com/secfoo" rel="noopener noreferrer"&gt;Secfoo&lt;/a&gt; is an open-source CLI that turns an AI coding agent into a disciplined security reviewer. Instead of building its own scanner, it hands your codebase and a specific review checklist to an AI agent you already have like Claude Code, Cursor, Gemini CLI, Codex, and few others - lets it actually read the code the way a human security reviewer would.&lt;/p&gt;

&lt;p&gt;You pick a target (a local folder or a GitHub repo), pick one or more checks to run, and Secfoo does the rest: renders the right prompt, runs the agent, and stores the results in a local dashboard you can browse in your browser. It can run 8 different kinds of review — architecture, threat modeling, SAST, SCA, secret scanning, prompt review, deployment readiness, and responsible AI compliance.&lt;/p&gt;

&lt;p&gt;Part of my internship on Secfoo was real simple: install it, use it like a real user would, and see if it actually does what it claims.&lt;/p&gt;

&lt;p&gt;One of its agent options broke that promise on the very first real test I ran. Here's exactly how I proved it, because "the AI made something up" is a big claim, and I wanted receipts, not a hunch.&lt;/p&gt;

&lt;h2&gt;
  
  
  &lt;strong&gt;The setup&lt;/strong&gt;
&lt;/h2&gt;

&lt;p&gt;Secfoo has a "no coding-agent CLI needed" option — give it an API key, and it talks straight to a model instead of needing Claude Code or Cursor installed. I pointed it at a small folder in Secfoo's own codebase and asked for a SAST (static code analysis) scan:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;secfoo run &lt;span class="nt"&gt;--skill&lt;/span&gt; sast &lt;span class="nt"&gt;--target&lt;/span&gt; src/secfoo/report &lt;span class="nt"&gt;--agent&lt;/span&gt; secfoo
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;It came back &lt;strong&gt;successful&lt;/strong&gt;, with 3 findings — 1 High, 1 High, 1 Medium. Confident-looking report, proper CWE IDs, CVSS vectors, even illustrative fix diffs.&lt;/p&gt;

&lt;h2&gt;
  
  
  &lt;strong&gt;The first red flag&lt;/strong&gt;
&lt;/h2&gt;

&lt;p&gt;Secfoo saves the &lt;em&gt;exact prompt&lt;/em&gt; it sends to the model, alongside the report. So before trusting the output, I checked what the AI had actually been shown:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="nb"&gt;grep&lt;/span&gt; &lt;span class="nt"&gt;-c&lt;/span&gt; &lt;span class="s2"&gt;"def &lt;/span&gt;&lt;span class="se"&gt;\|&lt;/span&gt;&lt;span class="s2"&gt;class &lt;/span&gt;&lt;span class="se"&gt;\|&lt;/span&gt;&lt;span class="s2"&gt;import "&lt;/span&gt; prompt.md
&lt;span class="c"&gt;# 0&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Zero. Out of 161 lines. The entire prompt was instructions and a single line:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;## **Target**
Inspect the codebase at: `/path/to/src/secfoo/report`
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;That's it. No file contents. Nothing. The model was told to review code it was never actually shown.&lt;/p&gt;

&lt;h2&gt;
  
  
  &lt;strong&gt;The proof it made things up&lt;/strong&gt;
&lt;/h2&gt;

&lt;p&gt;The report cited three "High/Medium" vulnerabilities, each with a specific file path:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;code&gt;db/query_handler.py:15&lt;/code&gt; — SQL injection&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;template/render.py:45&lt;/code&gt; — XSS&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;file_upload/upload.py:30&lt;/code&gt; — path traversal&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;None of those files exist. Anywhere in the project. I checked with &lt;code&gt;find&lt;/code&gt;. The folder I scanned only has 7 files, and not one of them is named any of those. The AI had nothing real to look at, so it generated the textbook example anyone would expect from "write me a SAST report" with zero actual input — and reported it with full confidence, including the line &lt;em&gt;"Confidence in this assessment is moderate to high."&lt;/em&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Ruling out "maybe the AI is just unreliable"
&lt;/h2&gt;

&lt;p&gt;Before calling this a tool bug rather than a model limitation, I ran the &lt;strong&gt;exact same skill, on the exact same folder&lt;/strong&gt;, through a different built-in option in Secfoo — one that actually reads files first. That one:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Correctly named all 7 real files in the folder&lt;/li&gt;
&lt;li&gt;Cited a real, specific line of code accurately — down to the exact syntax&lt;/li&gt;
&lt;li&gt;Found 0 issues and said so honestly, instead of padding the report to look thorough&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Same tool, same folder, same day. One option told the truth. The other one guessed and called it confidence.&lt;/p&gt;

&lt;h2&gt;
  
  
  &lt;strong&gt;Why this matters more than a normal bug&lt;/strong&gt;??
&lt;/h2&gt;

&lt;p&gt;A security tool's entire value is that you can trust what it tells you. A tool that invents vulnerabilities is worse than one that finds nothing — it burns your time chasing ghosts, or worse, gives you false confidence that a real issue doesn't exist.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The good news&lt;/strong&gt;: this is now fixed — the team removed the broken implementation. But it's a good reminder for anyone building on top of an LLM: "the run succeeded and returned a well-formatted answer" is not the same claim as "the answer is true." If your pipeline can check its own inputs the way I did here — just read the prompt you're about to log — do it. It's a five-second check that would have caught this before it ever shipped.&lt;/p&gt;

</description>
    </item>
  </channel>
</rss>
