Code Security Review Tool Karma Pro, an open-source Apache-2.0 macOS code security review tool, parses 14 languages and runs 4 independent engines — AST, heuristic, Bayesian classifier trained on software patches, and AI scanning — with each finding tagged by the engine that produced it. The tool generates dataflow diagrams from the open project, monitors pull requests on GitHub, GitLab, Bitbucket, Gitea and Forgejo by polling every 15 minutes, and scans only on an explicit Review action. It requires macOS 12.0 Monterey or newer, ships as a self-signed Karma.pro.dmg for Apple silicon and Intel, and connects to OpenRouter or local Ollama for AI-assisted fixes and scans. macOS · open source · Apache-2.0 The code security review tool Static analysis that reads your source, inter-procedural taint tracking over parse trees, a heuristic engine, a Bayesian classifier trained on software patches and AI scanning. Then the graphs, the flows and the entry points, from the same index. 14 languages parsed 4 independent engines Capabilities Findings Every finding says how it was found. A structural finding, a matched pattern and a model opinion are not the same claim, so the app never mixes them. Each row carries the engine that produced it, and a grade that weighs exploitability and reachability, not just severity. Critical, High, Medium and Low are assigned per finding. A model opinion is tagged AI and sits with the rest rather than in a separate list, so a reviewer sees the whole picture in one place. | Grade | Engine | |---|---| | Critical | AST | | Critical | AI | | High | Heuristic | | High | AST | | Medium | AI | | Low | AST | Diagrams Dataflows Every diagram is generated from the project you have open. Click a node and you are on the line. A flowchart per function, with cyclomatic complexity, branches and loops Every use of a variable, with callees expanded recursively Every untrusted input, grouped and tagged Remote or Local The caller chain walked to the top, ending Remote, Local or nowhere A pasted crash or stack trace resolved against the open project The class at the centre with every construction site beneath it What calls the function you clicked, in the same file Functions in source order against cyclomatic complexity Pull requests It watches the repos you point it at. The menu bar item keeps a list of repositories and the pull requests open on them, and tells you when changes. Monitoring stays switched off until you turn it on. Review is the only action that scans. Not Now and Ignore never do, so dismissing a notification can never start a scan on its own. GitHub, GitLab, Bitbucket, Gitea and Forgejo Polls every 15 minutes and compares against the previous poll Review only, Not Now and Ignore never scan Recognised by head commit rather than title, so a rewritten PR is not missed Changed files only, or the whole project when cross-file taint matters A saveable Markdown report and a side-by-side diff with the findings against it Read-only token in your Keychain, it never approves, comments or posts Assistant Ask about the code you reviewing. Connect OpenRouter, paste the key, press Connect, and pick any model: Claude, GPT-4o, Gemini, Llama, DeepSeek, Mistral. Or point it at Ollama and stay on the machine. The open project's path travels with every prompt in the system message, so the answer is about your code. Right-click any line for AI How to fix it , with the surrounding context sent along. The same connection also runs as a scanning pass, which is where the AI-tagged findings above come from. Keys are stored on your machine and remembered across launches. Models are listed live from OpenRouter, with a refresh button. You also need a valid token at the AI assistant in order to perform AI scans. Install Installation The release is self-signed, so macOS stops it the first time and asks whether you trust it. That is expected. Open it once, confirm, and it runs normally from then on. Needs macOS 12.0 Monterey or newer. Karma.pro.dmg Self-signed, ad-hoc macOS 12.0 Monterey+ Apple silicon, Intel If the Open option never appears, the quarantine attribute is still on the bundle. Clear it once with xattr -d com.apple.quarantine "/Applications/Karma Pro.app" Build Compile it yourself. One Swift package, one script. ./build.sh compiles everything in Sources/ and assembles Karma Pro.app in the repository root. Xcode 14 or newer, or Swift 5.7 and up. github.com/cphr/karmapro Swift 5.7 · Xcode 14+ x86 64-apple-macos12.0, arm64-apple-macos12.0 Karma Pro.app Ad-hoc Apache-2.0