cd /news/ai-tools/code-security-review-tool · home › topics › ai-tools › article
[ARTICLE · art-148694] src=reviewcode.org ↗ pub= topic=ai-tools verified=true sentiment=· neutral

Code Security Review Tool

Karma Pro, an open-source Apache-2.0 macOS code security review tool, parses 14 languages and runs 4 independent engines — AST, heuristic, Bayesian classifier trained on software patches, and AI scanning — with each finding tagged by the engine that produced it. The tool generates dataflow diagrams from the open project, monitors pull requests on GitHub, GitLab, Bitbucket, Gitea and Forgejo by polling every 15 minutes, and scans only on an explicit Review action. It requires macOS 12.0 Monterey or newer, ships as a self-signed Karma.pro.dmg for Apple silicon and Intel, and connects to OpenRouter or local Ollama for AI-assisted fixes and scans.

read3 min views1 publishedOct 10, 2026

macOS · open source · Apache-2.0

#

The code security review tool

Static analysis that reads your source, inter-procedural taint tracking over parse trees, a heuristic engine, a Bayesian classifier trained on software patches and AI scanning. Then the graphs, the flows and the entry points, from the same index. 14 languages parsed

4 independent engines

Capabilities

Findings

Every finding #

says how it was found.

A structural finding, a matched pattern and a model opinion are not the same claim, so the app never mixes them. Each row carries the engine that produced it, and a grade that weighs exploitability and reachability, not just severity.

      Critical, High, Medium and Low are assigned per finding. A model opinion is tagged
      **AI** and sits with the rest rather than in a separate list, so a reviewer sees the
      whole picture in one place.
Grade Engine
Critical AST
Critical AI
High Heuristic
High AST
Medium AI
Low AST

Diagrams

Dataflows #

Every diagram is generated from the project you have open. Click a node and you are on the line.

A flowchart per function, with cyclomatic complexity, branches and loops

Every use of a variable, with callees expanded recursively

Every untrusted input, grouped and tagged Remote or Local

The caller chain walked to the top, ending Remote, Local or nowhere

A pasted crash or stack trace resolved against the open project

The class at the centre with every construction site beneath it

What calls the function you clicked, in the same file

Functions in source order against cyclomatic complexity

Pull requests

It watches the repos #

you point it at.

The menu bar item keeps a list of repositories and the pull requests open on them, and tells you when changes. Monitoring stays switched off until you turn it on.

Review is the only action that scans. Not Now and Ignore never do, so dismissing a notification can never start a scan on its own.

GitHub, GitLab, Bitbucket, Gitea and Forgejo

Polls every 15 minutes and compares against the previous poll

Review only, Not Now and Ignore never scan

Recognised by head commit rather than title, so a rewritten PR is not missed

Changed files only, or the whole project when cross-file taint matters

A saveable Markdown report and a side-by-side diff with the findings against it

Read-only token in your Keychain, it never approves, comments or posts

Assistant

Ask about the code #

you reviewing.

Connect OpenRouter, paste the key, press Connect, and pick any model: Claude, GPT-4o, Gemini, Llama, DeepSeek, Mistral. Or point it at Ollama and stay on the machine. The open project's path travels with every prompt in the system message, so the answer is about your code.

            Right-click any line for **(AI) How to fix it**, with the surrounding context sent
            along. The same connection also runs as a scanning pass, which is where the AI-tagged
            findings above come from.

Keys are stored on your machine and remembered across launches. Models are listed live from OpenRouter, with a refresh button. You also need a valid token at the AI assistant in order to perform AI scans.

Install

Installation #

The release is self-signed, so macOS stops it the first time and asks whether you trust it. That is expected. Open it once, confirm, and it runs normally from then on.

Needs macOS 12.0 Monterey or newer.

Karma.pro.dmg

Self-signed, ad-hoc macOS 12.0 Monterey+

Apple silicon, Intel

If the Open option never appears, the quarantine attribute is still on the bundle.

      Clear it once with `xattr -d com.apple.quarantine "/Applications/Karma Pro.app"`

Build

Compile it #

yourself.

      One Swift package, one script. `./build.sh` compiles everything in
      `Sources/` and assembles `Karma Pro.app` in the repository root.
      Xcode 14 or newer, or Swift 5.7 and up.

github.com/cphr/karmapro

Swift 5.7 · Xcode 14+

x86_64-apple-macos12.0, arm64-apple-macos12.0 Karma Pro.app

Ad-hoc

Apache-2.0

── more in #ai-tools 4 stories · sorted by recency
── more on @karma pro 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/code-security-review…] indexed:0 read:3min 2026-10-10 · —