Same standards, same report, every run. Point Claude Code, Cursor, Antigravity, or Gemini CLI at a target, pick your activity, and browse every result in one local dashboard.
Choose one or more from the catalog — architecture review, threat modeling, SAST, SCA, secret scanning, and more. Run several together; they execute concurrently against the same target.
A public GitHub URL, a local directory, plus optional Confluence links for extra context. Then choose which CLI runs it — Claude Code, Cursor, Antigravity, or Gemini CLI.
Every assessment ever run, across every project, in one local web dashboard. Run secfoo serve and it's on your machine.
Secfoo works alongside the AI tools your team already uses, and produces a consistent, standards-based security report on a piece of software in minutes rather than the days or weeks a manual review takes.
Every report follows the same structure — issues found, how serious each one is, and a clear pass or fail — so results can be compared, tracked and audited over time.
Controls matrix, design-principles verdict, CSA CCM v4 conformance, and a Design verdict for milestone gating.
STRIDE (+LINDDUN), attack chains, every threat dispositioned, and an explicit residual risk statement.
Code-level findings with taint paths, CWE/OWASP mapping, and illustrative fix diffs.
Dependency inventory, a reachability verdict per risk, and a grouped upgrade plan.
Exposed credentials across source, config, git history, and linked Confluence pages.
Production security and operational readiness review before you ship.
Claude Code, Cursor, Antigravity, or Gemini CLI — Secfoo drives whichever one is already on your PATH instead of adding a fifth tool to learn.
Reports, the dashboard, and diagram rendering all run on your machine. No account to create before your first scan.
Program dashboards are built from what a report can actually state — where the data can't support a claim, Secfoo shows zeros or hatching instead of guessing.
MIT, no vendor lock-in. Read the skill definitions, the report contracts, and the dashboard code directly on GitHub.
A developer with no security training gets the same quality of review a specialist would produce. Security stops being a bottleneck waiting on a small expert team and becomes something every engineer does as part of their normal work.
Design verdicts, CSA CCM v4 domain conformance, and a gate-decision mix (approve / with conditions / reject) you can point to at a review.
STRIDE coverage per asset class, an explicit residual-risk statement, and recorded risk acceptances that survive the next re-run.
Deployment readiness and SCA reachability run the same way as everything else — secfoo run, then secfoo serve.
A central portal gathers every team's results into a single view, so management can see risk and coverage across the whole business without chasing individual reports.
See Cloud & Enterprise editions →pip, npm, a universal shell script, or Docker — pick whichever fits how you work. They're all the same tool underneath.
See install options