SecFoo: AI security scanner invented vulnerabilities without seeing code
An open-source CLI tool SecFoo was found to send prompts with no file contents in its no-coding-agent mode, causing the AI to report fake vulnerabilities in non-existent files. The bug was reproduced on a 7-file folder, and the broken implementation has since been removed.
- The 161-line prompt contained no code, only a folder path
- The report cited SQL injection, XSS and path traversal in files that don't exist
- Another SecFoo mode correctly named all 7 files and found 0 issues
- The broken implementation has already been removed
Read next
Security