foncki/Secure Review
Multi-model static security review on pull requests: LLM reviewers + SAST, with inline PR comments on changed lines.
View on GitHubTrust Signals
- Scorecard Score
- not yet scored
- Maintenance Recency
- Stale
- License
- None
Inputs
| name | description | required | default |
|---|---|---|---|
| config | Path to .secure-review.yml | no | .secure-review.yml |
| mode | Static review only. `fix` is a deprecated alias for `review` (multi-model audit + PR comments). For live target probes, ZAP, or Nuclei, use secure-review-runtime (https://github.com/sstaempfli/secure-review-runtime). | no | review |
| max-cost-usd | Cost ceiling for AI-backed static review (reviewers + writer if used elsewhere). | no | 20 |
Outputs
no outputs