Secfoo is an open-source orchestrator for context-based security review — built so security work runs through the same coding-agent CLI your team already has open, instead of a separate portal.
The program dashboards are built from what a report can state at review time and the exceptions you record by hand — not a persistent findings-lifecycle system with manually-updated statuses. Where the data can't support a claim, Secfoo says so rather than guessing.
Secfoo is licensed under MIT. Reports and the dashboard run entirely on your machine — the mermaid diagram renderer, once vendored, serves locally too, so the dashboard never calls out to a CDN while you're reading a report built from a possibly untrusted repository.
Questions, feedback, or an activity you'd like to see in the catalog.
Questions, feedback, or an activity you'd like to see in the catalog. Goes straight to info@secfoo.com.
No account, no SaaS dependency — install it and point it at a target.
View on GitHub