Hackmenot – Security scanner for AI-generated code
Hackmenot – Security scanner for AI-generated code
Hey HN! I built hackmenot because I kept seeing the same security vulnerabilities in AI-generated code. The problem: AI assistants optimize for "code that works," not "code that's secure." They routinely generate SQL injection via f-strings, hardcode API keys, use os.system() with user input, and pick weak crypto like MD5. What hackmenot does: - 100+ rules purpose-built for AI code patterns - Python, JavaScript, Go, Terraform - Auto-fix mode (hackmenot scan . --fix) - Detects hallucinated packages (dependencies AI made up that don't exist) - Sub-second scans with caching - GitHub Action with SARIF support Install: pip install hackmenot It's Apache 2.0, no API keys needed, works offline. Would love feedback on the rules coverage and any patterns I'm missing. Happy to answer questions!
Share cardActual performance
Launch Intel predictions
Analyze your own launch →Correct prediction on native model
Similar products
Security scanner for AI-generated code
Security scanner for AI-generated code - find vulnerabilitie
Security Cards – Reducing insecure AI-generated code by 72%
VibeGuard – security linter for AI-generated code
AISlop, a CLI for catching AI generated code smells
Git-Blame for AI-Generated Code
Audit AI Generated Code with Go Std Lib
Govern AI-generated code before it ships
Catch risky AI-generated code before it hits production
Deff – Review AI-generated code changes