Everyone's a security professional.

Secfoo turns any AI coding agent into a disciplined security reviewer.

Same standards, same report, every run. Point Claude Code, Cursor, Antigravity, or Gemini CLI at a target, pick your activity, and browse every result in one local dashboard.

secfoo run --skill security-architecture-review --agent claudeagentagygemini▍
8 Security activities in the catalog
4 Coding-agent CLIs supported
1 Local dashboard — no CDN calls while you read a report

How it works

01

Pick your activities

Choose one or more from the catalog — architecture review, threat modeling, SAST, SCA, secret scanning, and more. Run several together; they execute concurrently against the same target.

02

Point it at a target

A public GitHub URL, a local directory, plus optional Confluence links for extra context. Then choose which CLI runs it — Claude Code, Cursor, Antigravity, or Gemini CLI.

03

Browse the dashboard

Every assessment ever run, across every project, in one local web dashboard. Run secfoo serve and it's on your machine.

Minutes, not weeks

A safety check, automated

Secfoo works alongside the AI tools your team already uses, and produces a consistent, standards-based security report on a piece of software in minutes rather than the days or weeks a manual review takes.

Every report follows the same structure — issues found, how serious each one is, and a clear pass or fail — so results can be compared, tracked and audited over time.

Eight activities, one orchestrator

See the full catalog →
security-architecture-review

Security Architecture Review

Controls matrix, design-principles verdict, CSA CCM v4 conformance, and a Design verdict for milestone gating.

threat-modeling

Threat Modeling

STRIDE (+LINDDUN), attack chains, every threat dispositioned, and an explicit residual risk statement.

sast

SAST — Static Code Analysis

Code-level findings with taint paths, CWE/OWASP mapping, and illustrative fix diffs.

sca-reachability

SCA — Reachability & Upgrade Triage

Dependency inventory, a reachability verdict per risk, and a grouped upgrade plan.

secret-scanning

Secret Scanning

Exposed credentials across source, config, git history, and linked Confluence pages.

deployment-readiness

Deployment Readiness

Production security and operational readiness review before you ship.

Why teams choose Secfoo

Agent-agnostic

Claude Code, Cursor, Antigravity, or Gemini CLI — Secfoo drives whichever one is already on your PATH instead of adding a fifth tool to learn.

Local by default

Reports, the dashboard, and diagram rendering all run on your machine. No account to create before your first scan.

Honest about approximations

Program dashboards are built from what a report can actually state — where the data can't support a claim, Secfoo shows zeros or hatching instead of guessing.

Open source

MIT, no vendor lock-in. Read the skill definitions, the report contracts, and the dashboard code directly on GitHub.

Everyone's a security professional

Expertise built into the product, not required of the person running it

A developer with no security training gets the same quality of review a specialist would produce. Security stops being a bottleneck waiting on a small expert team and becomes something every engineer does as part of their normal work.

Built for your role

Security architects

Gate milestones with evidence

Design verdicts, CSA CCM v4 domain conformance, and a gate-decision mix (approve / with conditions / reject) you can point to at a review.

AppSec & threat modelers

Track disposition, not just findings

STRIDE coverage per asset class, an explicit residual-risk statement, and recorded risk acceptances that survive the next re-run.

Platform & DevOps

One CLI, no new SaaS to onboard

Deployment readiness and SCA reachability run the same way as everything else — secfoo run, then secfoo serve.

For larger organisations

One view across every team

A central portal gathers every team's results into a single view, so management can see risk and coverage across the whole business without chasing individual reports.

See Cloud & Enterprise editions →

Install in under a minute

pip, npm, a universal shell script, or Docker — pick whichever fits how you work. They're all the same tool underneath.

See install options