AI.CleanCode

Detection & Remediation

Identify complex vulnerabilities introduced by human developers or AI coding assistants, and apply a reviewed fix before the code leaves the workstation. Detection combines deterministic rules with model-based validation; the suggested fix is always shown as a diff you approve.

database.ts — AI.CleanCode Active
import { Database } from \'./db\';
import { env } from \'./config\';

export async function connectToDatabase() {
const url = "postgres://admin:secret123@db.prod.internal:5432/main";

const client = new Database(url);
await client.connect();
return client;
}

Vulnerability Detection

  • Deep Vulnerability CoverageDetects injection flaws (OS command, SQL), missing XSS protection, improper input handling, unsafe file handling, use of MD5, and weak cryptography.
  • Six Scan Types in One PipelineCombines SAST, DAST (dynamic testing), SCA (dependencies), Secrets scanning, Automated Pentest, and Fuzzing into a single unified analysis.
  • AI-Generated Logic FlawsIdentifies hallucinated API endpoints, insecure default parameters often generated by Copilot, and missing authorization checks.
  • Memory Safety (C/C++/Rust)Flags buffer overflows, use-after-free, and uninitialized memory access patterns.

Secret & Identity Protection

  • High-Entropy Secret ScanningIdentifies AWS keys, Stripe tokens, private SSH keys, and database credentials with near-zero false positives.
  • Custom Secret PatternsDefine internal token structures via regex to prevent proprietary credential leakage.
  • Auto-vaultingSuggests replacing hardcoded secrets with environment variables or references to your existing secrets-management pattern.

Supply Chain & Open Source

  • Dependency Risk DetectionFlags known-vulnerable and compromised versions from the OSV database, and catches packages an LLM invented but that do not exist — the entry point for slopsquatting. Findings can fail the build through the CI quality gate.
  • License Risk AnalysisFlags copyleft licenses (GPL, AGPL) entering the codebase to prevent IP contamination.
  • Automated SBOM GenerationContinuously updates a Software Bill of Materials (CycloneDX format) on every merged pull request.

Language Support

  • Eleven Supported LanguagesPython, JavaScript/TypeScript, Java, Kotlin, Go, C#, C/C++, PHP, Ruby, Rust, and Swift.
  • Language-Aware AnalysisEach language uses its own analysis toolchain, with model-based validation adding surrounding-code context.