Most teams already have an AI coding agent on their machines: Claude Code, GitHub Copilot CLI, Codex, Cursor or Gemini. These agents can read a whole codebase, follow data from an HTTP request down to a database call, and explain what they found in plain English.
What they don't have is discipline. Ask one to "check this repo for security issues" twice and you'll get two different answers, in two different formats, with no idea what was actually checked.
So we built SecFoo: an open-source tool that turns the coding agent you already use into a consistent security reviewer, with the same standards and the same report shape on every run.
SecFoo is a command-line tool plus a local dashboard. You pick three things:
pip install secfoo
secfoo run --skill sast --skill secret-scanning --agent claude --target https://github.com/your/repo
secfoo serve
Several skills run at the same time, and every result lands in a dashboard you open in your browser.
Each skill is a carefully written brief, not a rules engine. It tells the agent exactly what to look for, how to rate severity, and the precise report format to return: an executive summary, a findings register, detailed findings with evidence, and a remediation plan.
The agent then does what a human reviewer would do: it opens the files, follows the code paths and reads the git history. SecFoo's job is everything around that:
--fail-on high and --max-cost 2.00 turn a scan into a pipeline check, and separate exit codes tell you whether the scan broke or the policy failed.
Wrapping AI agents in security tooling taught us one lesson above all: a scanner must never report "clean" when it couldn't actually look.
An agent can exit successfully while doing nothing. It might be blocked by its own sandbox, cut off by the operating system, or simply give up. If you trust the exit code, that becomes a scan with zero findings, which looks exactly like a healthy project.
So we test SecFoo end to end against repos where we already know the answer: planted keys, planted SQL injection, planted command injection. If those don't come back, the run is a failure, however confident the report looks. Running these tests across agents and operating systems has caught real problems in our own code, and every fix comes with a regression test.
pip install secfoo
secfoo run --skill threat-modeling --agent claude --target .
secfoo serve
SecFoo is open source under the MIT licence on GitHub. We'd love to hear how it does on your codebase. Issues and pull requests are very welcome, especially new skills and support for more agents.