
Statische Analyse-CLI, die Codebasen auf LLM-Prompt-Injection, Datenextraktion, Jailbreak und unsichere Agenten-/Tool-Schwachstellen scannt. Läuft vollständig offline, integriert sich in CI/CD und gibt Konsolen-, JSON- und SARIF-Berichte aus.
Statisches Analysetool, das Ihre Codebasis auf LLM-Prompt-Injection- und multimodale Sicherheitslücken scannt. Läuft offline, keine API-Aufrufe erforderlich.
ContextHound ist in Ihrem gesamten Entwicklungs- und Browser-Workflow verfügbar:
| Tool | Funktion | Installation |
|---|---|---|
| CLI / npm-Paket | Scannt Ihre Codebasis auf Prompt-Injection-Sicherheitslücken. Integriert sich in GitHub Actions, gibt SARIF, JSON, HTML und mehr aus. | npm install -g context-hound |
| VS Code-Erweiterung | Inline-Ergebnisse während des Codierens, Code-Aktionen, Ausgabekanal, Statusleiste. | VS Code Marketplace |
| Browser-Erweiterung | Echtzeit-Scan-Button auf jeder AI-Chat-Oberfläche, DevTools-Panel für LLM-API-Traffic, Popup-Scanner. Chrome und Firefox. | Firefox: Kostenlos installieren · Chrome: in Prüfung · Quelle |
Da LLM-gestützte Anwendungen in Produktionscodebasen immer häufiger werden, hat sich Prompt-Injection als eine der ausbeutbarsten Angriffsflächen erwiesen; die meisten Sicherheitsscanner sind sich dessen nicht bewusst.
ContextHound bringt statische Analyse in Ihre Prompt-Schicht:
Es passt in Ihren bestehenden Workflow als CLI-Befehl, ein npm-Skript oder eine GitHub Action, mit null externen Abhängigkeiten.
| 95 Sicherheitsregeln | Über 14 Kategorien: Injection, Exfiltration, Jailbreak, unsichere Tool-Nutzung, Command Injection, RAG-Vergiftung, Codierung, Ausgabehandhabung, multimodal, Skills-Marktplatz, agentisch, MCP, Lieferkette, DoS |
| Numerischer Risikoscore (0-100) | Normalisierter Repository-Score mit niedrigen, mittleren, hohen und kritischen Schwellenwerten |
| Erkennung von Gegenmaßnahmen | Explizite Sicherheitssprache in Ihren Prompts verringert Ihren Score |
| 7 Ausgabeformate | Konsole, JSON, SARIF, GitHub Annotations, Markdown, JSONL-Streaming und interaktives HTML |
| GitHub Action inkludiert | Lässt CI bei hohem Risiko fehlschlagen und lädt SARIF-Ergebnisse automatisch hoch |
| Mehrsprachiges Scannen | Erkennt LLM-API-Nutzung in Python, Go, Rust, Java, C#, PHP, Ruby, Swift, Kotlin, Vue, Bash – nicht nur TypeScript/JavaScript |
| Regelfilterung | excludeRules/includeRules mit Präfix-Glob-Syntax (CMD-*); minConfidence-Filter |
| Inkrementeller Cache | .hound-cache.json überspringt unveränderte Dateien bei erneuten Läufen; --no-cache zum Deaktivieren |
| Plugin-System | Lädt benutzerdefinierte Regeln aus lokalen .js-Dateien über "plugins": ["./my-rule.js"] in der Konfiguration |
| Baseline-/Diff-Modus | --baseline results.json – nur Ergebnisse melden und bei Funden fehlschlagen, die nicht in einem vorherigen Scan vorhanden waren |
| Watch-Modus | --watch scannt bei Dateiänderungen erneut und zeigt Delta-Ergebnisse |
| Paralleles Scannen | Gleichzeitige Dateiverarbeitung (--concurrency <n>, Standard 8) |
| Vollständig offline | Keine API-Aufrufe, keine Telemetrie, keine kostenpflichtigen Abhängigkeiten |
Globale Installation – fügt den Befehl hound zu Ihrem PATH hinzu:```bash
npm install -g context-hound
**Projektweise Installation** — auf ein Repository beschränkt, läuft über `npx hound` oder ein npm-Skript:```bash
npm install --save-dev context-hound
Zero-install — keine Installation erforderlich, verwendet die gecachte npm-Registrierungskopie:```bash npx context-hound scan --dir .
## Schnellstart```bash
# Scaffold a config file
hound init
# Scan your project
hound scan --dir ./my-ai-project
# Or via npm script (scans current directory)
npm run hound
# Verbose output, shows remediations and confidence levels
hound scan --verbose
# Fail the build on any critical finding
hound scan --fail-on critical
# Export JSON and SARIF reports
hound scan --format console,json,sarif --out results
# GitHub Annotations (for CI step summaries)
hound scan --format github-annotations
# Markdown report with findings tables
hound scan --format markdown --out report
# Stream findings as JSONL (one JSON object per line)
hound scan --format jsonl | jq '.severity'
# List all rules
hound scan --list-rules
# Explain a rule (or a rule family by prefix)
hound explain INJ-001
hound explain PST --format json
# Fast PR gate — scan only files changed vs. origin/main
hound scan --diff
# Interactive HTML report (self-contained, open in browser)
hound scan --format html --out report
# Re-scan on file changes
hound scan --watch
# Parallel scanning (default is 8; tune for your machine)
hound scan --concurrency 16
# Disable incremental cache for a clean run
hound scan --no-cache
# Baseline mode — only report findings new since the last saved scan
hound scan --format json --out baseline # save a baseline
hound scan --baseline baseline.json # compare future scans against it
# Load a custom rule from a local plugin file
hound scan # plugin declared in .contexthoundrc.json "plugins" field
# Only run high-confidence rules
hound scan --config .contexthoundrc.json # set minConfidence: "high"
# Fail if any single file scores >= 40
hound scan --fail-file-threshold 40
Exitcodes:
| Code | Bedeutung |
|---|---|
0 | Bestanden – Score unter Schwellenwert, keine failOn-Verletzung |
1 | Nicht behandelter Fehler oder ungültige Argumente |
2 | Schwellenwert überschritten – Repository-Score ≥ Schwellenwert oder Datei-Schwellenwert überschritten |
3 | --fail-on-Verletzung – Fund der angegebenen Schwere gefunden |