@darrenjcoxon/codeguard
v1.2.0
Published
Scan code for security issues, get FIXES.md for AI agents to fix them
Maintainers
Readme
CodeGuard 🛡️
Scan your code for security issues. Get a FIXES.md file. Give it to Claude Code or Cursor to fix everything.
Install
npm install -g @darrenjcoxon/codeguardThat's it. CodeGuard automatically installs Semgrep and Gitleaks on first run.
Use
cd your-project
codeguardThis will:
- Auto-install any missing scanning tools
- Scan for security vulnerabilities, secrets, bad dependencies, code quality issues
- Create
FIXES.mdin your project - Tell your AI agent: "Fix all the issues in FIXES.md"
What It Finds
| Scanner | Issues | |---------|--------| | Semgrep | SQL injection, XSS, command injection, path traversal | | Gitleaks | API keys, passwords, tokens, secrets | | npm audit | Vulnerable dependencies | | ESLint | Code quality issues | | Complexity | Complex code, TODOs, debug statements |
Commands
codeguard # Scan current directory
codeguard /path/to/project # Scan specific path
codeguard setup # Manually install scanning tools
codeguard check # Check which tools are installed
codeguard --no-fixes # Skip FIXES.md generation
codeguard --ci # CI mode: exit 1 on high/critical issuesCI/CD
# GitHub Actions
- run: |
npm install -g @darrenjcoxon/codeguard
codeguard --ciLicense
MIT
