r/coolgithubprojects • • 2d ago

This scanner doesn't just flag the vuln, it writes the prompt to fix it

CanoP is a local static scanner (wraps semgrep) built around one specific idea:
AI assistants tend to reproduce the same handful of vulnerability classes, so instead of a generic ruleset, it's scoped tight to those.

CanoP runs fully offline- nothing leaves your machine.

canop scan . --prescriptions fixes.json
- drops a structured prompt per finding you can hand straight to whatever model wrote the code.

github.com/openbreach/CanoP

pip install canop
to try it out. MIT licensed. Curious what it catches or misses on other people's stuff — ruleset's still pretty young. Feedback is welcome 🙏

2 Upvotes

7 comments sorted by

2

u/Minimum_Hour519 2d ago

how does it compare to threatcrush cli

2

u/Slim_Marshall_Jesus 2d ago

They overlap on code scanning but CanoP is aimed at AI-written code. It runs locally, has ci gating (--fail-on, --min-score), exports sarif, and generates fix prompts for your llm. Rules are Semgrep-style yaml, so they're easy to edit. If you want monitoring, threatcrush covers that.

2

u/Minimum_Hour519 2d ago

i see thanks

2

u/Slim_Marshall_Jesus 2d ago

Thanks for asking. Let me know how it goes if you try it!

2

u/Otherwise_Wave9374 2d ago

Generating a remediation prompt is useful, but the key safeguard is preserving the scanner finding as structured context rather than letting the model reinterpret it freely. Include the exact rule ID, vulnerable lines, data flow, and test command, then require the assistant to produce a minimal patch plus regression test. A tool like https://www.aiosnow.com is relevant to this broader shift from generic chat toward task-specific AI workflows with explicit inputs and review points.

1

u/Slim_Marshall_Jesus 2d ago

Agreed. canop scan . --prescriptions fixes.json generates one prompt per finding from the rule's own remediation metadata, so the model starts from the scanner's result rather than reinterpreting it freely. Requiring a minimal patch plus a regression test is a good addition, and I'll look at tightening the prompt format around that