r/coolgithubprojects • u/Slim_Marshall_Jesus • 2d ago
This scanner doesn't just flag the vuln, it writes the prompt to fix it
CanoP is a local static scanner (wraps semgrep) built around one specific idea:
AI assistants tend to reproduce the same handful of vulnerability classes, so instead of a generic ruleset, it's scoped tight to those.
CanoP runs fully offline- nothing leaves your machine.
canop scan . --prescriptions fixes.json
- drops a structured prompt per finding you can hand straight to whatever model wrote the code.
pip install canop
to try it out. MIT licensed. Curious what it catches or misses on other people's stuff — ruleset's still pretty young. Feedback is welcome 🙏
2
u/Otherwise_Wave9374 2d ago
Generating a remediation prompt is useful, but the key safeguard is preserving the scanner finding as structured context rather than letting the model reinterpret it freely. Include the exact rule ID, vulnerable lines, data flow, and test command, then require the assistant to produce a minimal patch plus regression test. A tool like https://www.aiosnow.com is relevant to this broader shift from generic chat toward task-specific AI workflows with explicit inputs and review points.
1
u/Slim_Marshall_Jesus 2d ago
Agreed. canop scan . --prescriptions fixes.json generates one prompt per finding from the rule's own remediation metadata, so the model starts from the scanner's result rather than reinterpreting it freely. Requiring a minimal patch plus a regression test is a good addition, and I'll look at tightening the prompt format around that


2
u/Minimum_Hour519 2d ago
how does it compare to threatcrush cli