一个 pi 包,将 OpenAI Codex Security 集成到代理会话中,用于漏洞扫描、分类和修复。

Stars

8

7 天增长

暂无数据

Fork 数

0

开放 Issue

0

开源协议

MIT

最近更新

2026-07-29

AI 仓库情报摘要
FR-AI / ANALYSIS

为什么值得关注

它将 AI 驱动的安全分析引入交互式代理工作流,使开发者无需离开 pi 环境即可扫描、审查和修复漏洞,并支持通过 SARIF 导出集成到 CI/CD 流水线。

适合谁使用

  • 使用 pi 编码代理的开发者
  • 执行代码审计的安全工程师
  • CI/CD 流水线维护者
  • 需要自动化漏洞修复的团队

典型使用场景

  • 扫描整个仓库的安全漏洞
  • 在提交前审查未暂存的更改
  • 自动修复扫描中的严重发现
  • 在 CI 中使用 CLI 基于严重性设置安全门禁

项目优势

  • 交互式扫描,带有流式进度和按严重性排序的发现
  • 多种扫描模式:标准、深度和基于差异的有针对性的审查
  • 生成机器可读的 SARIF 导出,便于集成到 GitHub 代码扫描
  • 通过自然语言命令教导代理对发现进行分类并提出修复建议

使用前须知

  • 依赖 Node.js 22+ 和 Python 3.10+
  • 首次使用前需要配置认证(ChatGPT 登录或 API 密钥)
  • 深度扫描模式可能较慢且 API 成本更高

README 快速开始

Usage

项目描述

A pi package that brings OpenAI Codex Security into your agent sessions: scan repositories for vulnerabilities, review severity-ranked findings, and fix them — all without leaving pi.

相关仓库与替代方案

根据分类、Topic 和编程语言匹配的相似项目。

makecindy
精选
makecindy GitHub avatar

cindy

Cindy is an open-source AI agent that runs locally on your machine, integrates multiple AI harnesses and models, and provides memory, skills, and automation to perform real work in your projects and apps.

AI 与机器学习大语言模型
958
deerwork-ai
精选
deerwork-ai GitHub avatar

deer-workflow

An open-source Dynamic Workflow runtime that combines deterministic TypeScript orchestration with replaceable Agent runtimes.

AI 与机器学习大语言模型
312
Jakubantalik
精选
Jakubantalik GitHub avatar

thinking-orbs

A React component library that renders six hand-tuned animated thought orb loading indicators on a plain 2D canvas, with two purpose-tuned sizes and automatic theme detection for AI and agent UIs.

AI 与机器学习AI 智能体
1,191