SecFoo turns AI coding agents into consistent security reviewers
SecFoo is a new open-source CLI and local dashboard that turns Claude Code, Copilot, Codex, Cursor and Gemini into consistent security reviewers. It supports SAST, secret scanning, threat modelling, SCA reachability and more, installed via pip install secfoo.
- SecFoo works with Claude Code, Copilot, Codex, Cursor and Gemini
- Skills include SAST, secrets, threat modelling, SCA and prompt review
- Agents run read-only and findings land in a local dashboard
- CI gate via --fail-on high and --max-cost 2.00, MIT licence
Read next
Security