<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Karthick Subramanian</title>
    <description>The latest articles on DEV Community by Karthick Subramanian (@karthick_subramanian_3d7b).</description>
    <link>https://dev.to/karthick_subramanian_3d7b</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4174398%2F5b1d51b4-eef8-447d-b6f4-3f36d2b98adf.png</url>
      <title>DEV Community: Karthick Subramanian</title>
      <link>https://dev.to/karthick_subramanian_3d7b</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/karthick_subramanian_3d7b"/>
    <language>en</language>
    <item>
      <title>We built SecFoo so your AI coding agent can do a proper security review</title>
      <dc:creator>Karthick Subramanian</dc:creator>
      <pubDate>Sat, 10 Oct 2026 01:51:57 +0000</pubDate>
      <link>https://dev.to/karthick_subramanian_3d7b/we-built-secfoo-so-your-ai-coding-agent-can-do-a-proper-security-review-e48</link>
      <guid>https://dev.to/karthick_subramanian_3d7b/we-built-secfoo-so-your-ai-coding-agent-can-do-a-proper-security-review-e48</guid>
      <description>&lt;p&gt;Most teams already have an AI coding agent on their machines: Claude Code, GitHub Copilot CLI, Codex, Cursor or Gemini. These agents can read a whole codebase, follow data from an HTTP request down to a database call, and explain what they found in plain English.&lt;/p&gt;

&lt;p&gt;What they don't have is discipline. Ask one to "check this repo for security issues" twice and you'll get two different answers, in two different formats, with no idea what was actually checked.&lt;/p&gt;

&lt;p&gt;So we built &lt;strong&gt;SecFoo&lt;/strong&gt;: an open-source tool that turns the coding agent you already use into a consistent security reviewer, with the same standards and the same report shape on every run.&lt;/p&gt;

&lt;h2&gt;
  
  
  What we built
&lt;/h2&gt;

&lt;p&gt;SecFoo is a command-line tool plus a local dashboard. You pick three things:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;What to check.&lt;/strong&gt; We call these &lt;em&gt;skills&lt;/em&gt;: SAST, secret scanning, threat modelling, security architecture review, dependency (SCA) reachability, prompt review, deployment readiness and responsible-AI compliance.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;What to check it on.&lt;/strong&gt; A local folder or a GitHub URL, optionally with Confluence pages for design context.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Which agent does the work.&lt;/strong&gt; Claude Code, Copilot, Codex, Cursor, Gemini and others, or just a model API key if you don't use a coding agent.
&lt;/li&gt;
&lt;/ol&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;pip &lt;span class="nb"&gt;install &lt;/span&gt;secfoo
secfoo run &lt;span class="nt"&gt;--skill&lt;/span&gt; sast &lt;span class="nt"&gt;--skill&lt;/span&gt; secret-scanning &lt;span class="nt"&gt;--agent&lt;/span&gt; claude &lt;span class="nt"&gt;--target&lt;/span&gt; https://github.com/your/repo
secfoo serve
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Several skills run at the same time, and every result lands in a dashboard you open in your browser.&lt;/p&gt;

&lt;h2&gt;
  
  
  How it works
&lt;/h2&gt;

&lt;p&gt;Each skill is a carefully written brief, not a rules engine. It tells the agent exactly what to look for, how to rate severity, and the precise report format to return: an executive summary, a findings register, detailed findings with evidence, and a remediation plan.&lt;/p&gt;

&lt;p&gt;The agent then does what a human reviewer would do: it opens the files, follows the code paths and reads the git history. SecFoo's job is everything around that:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Running the agent safely and non-interactively.&lt;/strong&gt; Agents run in read-only mode where they support it, because a review should never change your code.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Parsing the report&lt;/strong&gt; into findings, severities and CWE/CVSS scores.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Tracking findings over time.&lt;/strong&gt; A SAST finding is keyed by the code it points at, not by how the model worded it, so a rescan doesn't turn one bug into "one fixed, one new" just because the wording changed.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Recording the cost&lt;/strong&gt; of each run, where the agent reports it.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  What you get
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;One case file per system.&lt;/strong&gt; Repeat scans of the same application build up a history instead of scattering into separate records.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;A local dashboard&lt;/strong&gt; across every project, with findings by severity, threat registers and architecture diagrams.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Risk decisions that are written down.&lt;/strong&gt; You can record an exception or accept a threat, with who approved it and when it expires, so "we know about that one" is documented rather than remembered.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;A real CI gate.&lt;/strong&gt; &lt;code&gt;--fail-on high&lt;/code&gt; and &lt;code&gt;--max-cost 2.00&lt;/code&gt; turn a scan into a pipeline check, and separate exit codes tell you whether the scan broke or the policy failed.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Local-first by design.&lt;/strong&gt; Everything stays on your machine unless you choose to connect it to your organisation's portal.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  What we learned building it
&lt;/h2&gt;

&lt;p&gt;Wrapping AI agents in security tooling taught us one lesson above all: &lt;strong&gt;a scanner must never report "clean" when it couldn't actually look.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;An agent can exit successfully while doing nothing. It might be blocked by its own sandbox, cut off by the operating system, or simply give up. If you trust the exit code, that becomes a scan with zero findings, which looks exactly like a healthy project.&lt;/p&gt;

&lt;p&gt;So we test SecFoo end to end against repos where we already know the answer: planted keys, planted SQL injection, planted command injection. If those don't come back, the run is a failure, however confident the report looks. Running these tests across agents and operating systems has caught real problems in our own code, and every fix comes with a regression test.&lt;/p&gt;

&lt;h2&gt;
  
  
  Try it
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;pip &lt;span class="nb"&gt;install &lt;/span&gt;secfoo
secfoo run &lt;span class="nt"&gt;--skill&lt;/span&gt; threat-modeling &lt;span class="nt"&gt;--agent&lt;/span&gt; claude &lt;span class="nt"&gt;--target&lt;/span&gt; &lt;span class="nb"&gt;.&lt;/span&gt;
secfoo serve
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;SecFoo is open source under the MIT licence on &lt;a href="https://github.com/secfoo-com/secfoo" rel="noopener noreferrer"&gt;GitHub&lt;/a&gt;. We'd love to hear how it does on your codebase. Issues and pull requests are very welcome, especially new skills and support for more agents.&lt;/p&gt;

</description>
      <category>opensource</category>
      <category>python</category>
      <category>security</category>
      <category>ai</category>
    </item>
  </channel>
</rss>
